Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

631–640 of 833 posts

Re: GDPR: Don't Panic

#631
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

> The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. Interview notes would not have to be turned over to the candidate. They are personal opinion of the interviewer even if they mention the candidate. GDPR protects that data: you may not disclose it because it would violate the rights of the interviewer.

I work in recruitment within the EU and you are completely wrong.

Probably you can redact it so that it doesn't include the actual names of which interview panellist said what.

Re: GDPR: Don't Panic

#632
post #627

Earlier quoted context omitted.

Oh man, the rest of us are so sorry that you are now required to responsibly handle personal information. To quote the author: > Then automate it. If you could automate the collection of the data in the first place then you definitely can automate the rest of the life cycle. There is no technical hurdle companies won’t jump through if it gets them juicy bits of data but as soon as the data needs to be removed we’re s…

I am happy the author is fighting the power. However since most of us live in society we generally would prefer less chaos. The difference between investment to collect data and investment to protect dat is there is no ROI for compliance (in any compliance domain) so the capital is not easily available. Instead of punishing companies for existing in the universe and subject to the laws of thermodynamics, the most eff…

The ROI for compliance is you get to do business with EU citizens and businesses.

What EU security directive are you thinking of, regarding IP addresses?

Re: GDPR: Don't Panic

#633
post #358

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

Which other violation could cost me a 20 million dollar fine ?

Sure, they will probably don't give that fines, but they could, what if I run a small business that interferes with the activity of some other business run by for example someone that is friend or can corrupt the people in charge of doing the fines ? They will fine me for 20 million dollars, sure I can appeal, a normal trial in my country lasts at least 5 years, in this time I will probably go out of business...

The fact that they could it's a big problem, they should have specified a proportion between the size of your company and the maximum allowed fine.

Re: GDPR: Don't Panic

#634

Earlier quoted context omitted.

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.

I read the article, and I found it more than slightly dismissive of this option, particularly because the article (and other commentors, it seems), in effect, makes the inference that the main goal of avoiding compliance is a continuation of some nefarious behavior.

Re: GDPR: Don't Panic

#635
post #183

Earlier quoted context omitted.

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

If this is such a serious concern, you should automate this process as much as possible. You don't necessarily need to respond manually to these requests if you put in place the required features on your website which will allow your EU data subjects to benefit from their rights. Realistically, how hard is it to automatically grab some data from a database and export it as JSON, as well as remove data from your datab…

Depends on your system. We have an automated process that produces a PDF, which a human will then go through and redact so we're not leaking through the non-relevent PII of other people if one of our users isnt using the system quite properly.

Re: GDPR: Don't Panic

#636
post #627

Earlier quoted context omitted.

I am happy the author is fighting the power. However since most of us live in society we generally would prefer less chaos. The difference between investment to collect data and investment to protect dat is there is no ROI for compliance (in any compliance domain) so the capital is not easily available. Instead of punishing companies for existing in the universe and subject to the laws of thermodynamics, the most eff…

The ROI for compliance is you get to do business with EU citizens and businesses. What EU security directive are you thinking of, regarding IP addresses?

Go look up what CPMs are for the EU. Having your website in the EU will simply not mske you much money, why even bother?

Re: GDPR: Don't Panic

#637
post #13

Earlier quoted context omitted.

What targets? Where have you heard something about targets?

Every institutions have targets to prove their existence is of benefit to the tax payer.

That doesn't have to be in money raised, that would be rather unlikely in this case.

It could be percentage of problems "fixed" whether that be by sharply worded letter or by court proceedings (the former is far easier and cheaper for the authority), or by the time it takes the authority to investigate a problem.

Re: GDPR: Don't Panic

#638

Earlier quoted context omitted.

I think this is a situation where it's easy to see the mote in someone else's eye. I tried to provide a summary using the standard terms for both approaches (in practice, making it clear I preferred a principles-based approach); you jumped up to rebut (in practice, by trying to find the most derogatory synonym for "principles-based regulation" and accusing opponents of "frothing at the mouth"). And then both of us ar…

Meh, I'm less concerned with disagreement (or the words used) than I am with deflection. To be clear, and brief, I am not saying one approach to law is better than another (though I too have my preferences and of course corruption anecdata abound). In this case, I think neither legal approach is preferable with such a large statute. But if we are resigned to this option, one could argue that the size/scope of the leg…

> I could talk about my suggestions for days

This sounds like it would make an interesting blog post!

Re: GDPR: Don't Panic

#639

Earlier quoted context omitted.

Are you claiming that most companies are not storing data in compliance with current law today? There's a meme about how all businesses are trying to exploit personal data mercilessly at any cost, yet among the small businesses around here and the people I know who work there, none of us is in that line of work, nor I suspect would any of us want to be.

I do not believe that the vast majority of companies which are significantly impacted by the GPDR were storing data in a reasonable manner, no. Having to spend some effort to make sure you are in compliance with a huge new piece of regulation is expected and I understand that people complain about having to do it. However, after the initial bring-up pains any business which continues to have a problem with the GPDR m…

I do not believe that the vast majority of companies which are significantly impacted by the GPDR were storing data in a reasonable manner, no.

If that's your personal belief then obviously you're entitled to your opinion, but have you seen any actual evidence that that is the case?

However, after the initial bring-up pains any business which continues to have a problem with the GPDR most likely has a business model directly in conflict with the spirit of the law.

Perhaps, but as you say, what we know now is that there are some initial compliance costs for everyone. If nothing else, we all have to understand the new regulations and our obligations under them, and we will now have to allow for additional subject rights and stronger and more specific documentation and notification obligations, which generally apply retrospectively as well.

I admit that part of my concern here is not specific to the GDPR, but rather to the general practice of creating ever more rules governing businesses. Every time some new regulation comes along, the costs of running a business go up. Not only does that impose some level of overhead on established businesses, it also has a chilling effect on new businesses starting up, and on paths to growth like starting a side business that can expand to something full time and later to take on additional employees. If a new regulation is necessary to achieve some positive effect, then those overheads might be justified as well, but I remain to be convinced that this is the case for most of the new rules and regulations that have come in over the decade or so that I've been doing this now. The GDPR is just the latest example of something perhaps well-intentioned but poorly implemented.

Re: GDPR: Don't Panic

#640

Earlier quoted context omitted.

When people losing their jobs due to government overreach makes you happy, check your motivations.

LOL! I'll shed many tears for those poor people whose only fault was that they've built a business on unsolicited collection of personal data :'(

Because those businesses don't employ anyone? I assume you've never had to work a job you don't care for.
Post reply on HN