Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

621–630 of 833 posts

Re: GDPR: Don't Panic

#621

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

I don't know, EU members seem perfectly willing to toe literal rules for perverse outcomes in some areas. Open market gamesmanship, for one, such as the proliferation of national standards as a way to exclude 'single' market products.

Maybe they are trying a kind of best of both worlds approach?

Re: GDPR: Don't Panic

#622

Earlier quoted context omitted.

Some entity runs a webserver. This entity has a legitimate business purpose in retaining access logs for e.g. 3 months for e.g. spam and security reasons. This entity just has to document that. This entity can allow a 3rd party service to access these logs so that 3rd party can do whatever needs to be done if it is within the reasons the entity gave for having the data. What neither can do is go use that data for any…

Who defines what is a legitimate business purpose? Let's say I comply with all that, but someone makes a complaint and particularly bitter civil servant judges that the collection is not legitimate, because he doesn't like the content of the website?

That’s like arguing that we shouldn’t have laws in case a cop is having a bad day and follows you around writing tickets. This is a legal process like anything else: your standard should be what you’re comfortable defending in court. Being able to show a good faith decision process, compliance with common industry practice, etc. are going to help the case that any lapse was unintentional.

If your angry ex is hired by a regulator you’d appeal it but there’s no reason to think that’s a common problem.

Re: GDPR: Don't Panic

#623

Earlier quoted context omitted.

Going on a bit of a tangent here, I am becoming concerned with how we discuss these things. You're completely either for or against it. And if you're against one way you are automatically for the other. If you think one thing is bad, obviously you need to be corrected that other thing is bad too. And then you'll get extreme examples showing it. Call it whataboutism, appeal to emotion, whatever. Every time these GDPR…

I think this is a situation where it's easy to see the mote in someone else's eye. I tried to provide a summary using the standard terms for both approaches (in practice, making it clear I preferred a principles-based approach); you jumped up to rebut (in practice, by trying to find the most derogatory synonym for "principles-based regulation" and accusing opponents of "frothing at the mouth"). And then both of us ar…

Meh, I'm less concerned with disagreement (or the words used) than I am with deflection. To be clear, and brief, I am not saying one approach to law is better than another (though I too have my preferences and of course corruption anecdata abound). In this case, I think neither legal approach is preferable with such a large statute. But if we are resigned to this option, one could argue that the size/scope of the legislation can only happen with vagueness and trust. In general I think we could arrive at a GDPR-level statutes (at a global level no less) after working up to it. And I don't believe the regulatory bodies' failures themselves justify doubling down on those same failure-causers. I could talk about my suggestions for days, but in general a good set of first steps would be simple transparency requirements for specific uses and tangible enforcement.

Re: GDPR: Don't Panic

#624
post #537

How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?

If you actively choose not to pursue compliance, you should make it clear in your own privacy policy that the site is not for use by EU/EEA citizens and also use IP geolocation to block their requests.

It seems that it's easier to comply for small projects :) Thanks.

Re: GDPR: Don't Panic

#625

Earlier quoted context omitted.

The GDPR regulation directly applies in all member states, and does not need individual states to do anything at all to enact it. If national courts decline to enforce it then it can escalate to the Eu courts. It is also international in that it applies to EU citizen date no matter which country it is held or processed in.

That’s not true. It’s implemented by each data regulation agencies in each country. The CNIL in France for example. There is no EU GDPR agency.

It is true — you need to read the actual GDPR rather than online summaries.

The GDPR creates some new criminal offences that can be prosecuted through courts without the regulatory authorities being involved in Clauses 162 & 163.

Article 82 allows individuals to sue in court for compensation if breaches of GDPR rules cause harm.

The regulatory activities are on top of this.

Re: GDPR: Don't Panic

#626
post #137

Earlier quoted context omitted.

OTOH - Scope outside of Europe – e.g. if a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. Too bad for Quebec I guess. Or what if you fly to speak at a conference in Europe – is that "marketing" to residents of EU? Depends on your slides? Or not? Who knows. - Consent – does X fall under…

> If a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. No, the GDPR is clear that it is applicable if you are offering goods or services to Europeans. The fact you are speaking French in Quebec isn't relevant. > Or what if you fly to speak at a conference in Europe – is that "marketing"…

> the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects

> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union

> factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union

https://gdpr-info.eu/recitals/no-23/

So you need to "offer" services, not "supply" them, and "to data subjects in the EU", not "within the EU".

So you can't just run your business from Canada with no special emphasis on EU and call it a day.

Or if you're advocating blocking European IPs, well that's exactly the "hysteria" the article argues against.

Re: GDPR: Don't Panic

#627

Constantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason. It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal infor…

Oh man, the rest of us are so sorry that you are now required to responsibly handle personal information. To quote the author: > Then automate it. If you could automate the collection of the data in the first place then you definitely can automate the rest of the life cycle. There is no technical hurdle companies won’t jump through if it gets them juicy bits of data but as soon as the data needs to be removed we’re s…

I am happy the author is fighting the power. However since most of us live in society we generally would prefer less chaos.

The difference between investment to collect data and investment to protect dat is there is no ROI for compliance (in any compliance domain) so the capital is not easily available.

Instead of punishing companies for existing in the universe and subject to the laws of thermodynamics, the most effective compliance regimes help transition companies proactively to lower the pain which will lower the cost to GDP and thereby angst from human beings.

The GDPR body won’t even answer basic questions like whether IP addresses need to be retained or not because of the competing requirement of the EU security directive.

They have had 23 years too to prepare for this change. And they own the privacy directives. You’d expect them to be better prepared themselves. But they are being kind of arrogant and unhelpful. I suspect because they know they did not make a perfect law and they will figure it out in case law later. This capriciousness is also super annoying.

Re: GDPR: Don't Panic

#628

Constantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason. It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal infor…

I don't think he whitewashes that it's a burden. But he does try to address some of the panic and hysteria.

I care about privacy. Perhaps Mattheij does as well, and that's why this is important to him. If you agree with the spirit of the legislation, then I think you should also consider this a great opportunity to do the right thing, instead of a hassle.

Re: GDPR: Don't Panic

#629

Earlier quoted context omitted.

> EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. You have to trust someone. Either the vast expanse of companies clearly mishandling your data, or the "benevolent" body which so far at least has a fairly good track record. It's not perfect. It's dangerous to give them too much power because you don't know how they will change in…

A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in

Which one has successfully left?

Re: GDPR: Don't Panic

#630
post #513

Earlier quoted context omitted.

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income. Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you…

> I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US For the rest of your life? Source please? You can be put temporarily into a cell for plenty of stuff but that's temporary. A fine is pretty permanent and when it can be millions, well that's probably the end of your business too. > There's nothing that says IRS won't prosecute you if someo…

nothing requires you to be let out of those cells. All those people in Guantanamo are going to die there.
Post reply on HN