Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

651–660 of 833 posts

Re: GDPR: Don't Panic

#651

Earlier quoted context omitted.

There is a bigger problem with GDPR compliance. Say I use a DDoS prevention service (like cloudflare). They get my user data, and also have to be under scope of GDPR as well. And since IP isn't indicative of EU citizenship status, a company had better apply GDPR to everything rather than just a subset. In the end, this law makes a "We respect the privacy of your data" subset of providers, and provides a great way for…

a company had better apply GDPR to everything rather than just a subset And that's what Cloudflare chose to do. We are treating all customers the same regardless of location. "Of the companies I spoke with for this story, both Cloudflare and Mozilla will be GDPR compliant no matter where their customers are located." https://www.fastcodesign.com/90171699/what-is-gdpr-and-why-s...

I'm absolutely glad to heard that (about CloudFlare).

The GDPR is becoming a "I'm doing the right thing" checkbox. At least with the European rule, we data-drained Americans can rely that these services might cost more, but we retain our rights.

Lack of will have to be scrutinized. Smaller places may make the determination based upon reasonable answers, or be malicious. Facebook/Google/Etc wouldn't exist in their current forms if there was strong privacy rules in place.

Re: GDPR: Don't Panic

#652
post #644

Earlier quoted context omitted.

The source is the book of that name, written by an US lawyer. There's some discussion and better sources on Google.

It's a meme passed around the right-o-sphere based on deliberately misreading laws and/or constructing insane scenarios. It has no statistics behind it, just made-up stories.

Remind me to tell Aaron Swartz how abusive & capricious prosecution is just a figment of his imagination...

Re: GDPR: Don't Panic

#653

Earlier quoted context omitted.

I think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).

And as so often the EU will be the initiator of a world wide adoption of (semi) unified rules, as it was for USB charging, among other things. It will naturally get a lot of flack and a few people/companies will make it their scapegoat as to deflect from them as usual, but that's - sadly - almost normal now. Is it all good: no! Is it a good start: yes! Is it IMPOSSIBLE to comply: heck no, I'm working at a small Austr…

I'm curious as to how much time you've taken in researching and implementing specific privacy laws of non-EU countries, since you don't seem to find it burdensome to comply with such regulations. Do you know for a fact you're in compliance with South African, Sri Lankan, or Australian privacy laws?

Re: GDPR: Don't Panic

#654
post #491
post #358

Earlier quoted context omitted.

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

> you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. Source please? > If you are going to crank the anxiety to 10 every time a situation like this occurs, you probably shouldn't be running a business or handling others' data in the first place. I'm not running one right now. It's not the situation that give me anxiety, it's just that it no longer seems interest…

> > you are already responsible for adhering to hundreds of other laws in which the fines could reach millions.

> Source please?

Tax laws come to mind for one.

Re: GDPR: Don't Panic

#655

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

This sort of explanation has been very popular by people who are trying to reduce the overall concern level of the community. You're not wrong. You very well could be right and this could be how it will work. Let me give a view as to why it doesn't matter. The problem with this approach is if you run a large or small company or are a sole proprietorship or simply have a hobby site, you can't write off legitimate fear…

That's a fair assessment and in line with the proportionality of the costs associated with becoming compliant with the GDPR, it sounds as if the company you are working for is smack in the middle of the range where the turnover:compliance costs is at its worst. This is unfortunate but I don't see any way in which that could have been avoided. For trivial companies the cost is negligible because the costs are small or nil, for large companies the cost is negligible because their turnover is huge (unless they are misbehaving on purpose, then the cost might be very large), for companies in the middle it hurts the most but it is still worth doing it and doing it right for all the reasons you listed.

As for this part of your comment:

> If this law is "no big deal" or "so easy to implement" or any other version of the arguments proposed this week, it would not be causing so much concern. It's neither an unreasonable ask or a trivial one. People are being impacted in large ways.

It's no big deal if you already had a user centric approach to privacy, if that's novel then you will probably have to change lots of procedures and some software too in order to get things right, even so I've seen far worse from a compliance point of view, look into fintech or healthcare compliance for examples.

Re: GDPR: Don't Panic

#656
post #629

Earlier quoted context omitted.

A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in

Which one has successfully left?

UK left European Union.

Re: GDPR: Don't Panic

#658
post #601

Earlier quoted context omitted.

A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in

As a fellow American, that sounds like you need to reconsider your news sources. Brexit was driven by propaganda, not some principled opposition to intractable problems. The “EUrocrats gone wild” stories are popular in certain circles but there’s an entire cottage industry debunking them: https://en.wikipedia.org/wiki/Euromyth

Both "stay" and "exit" sides were covered pretty well.

But if Brussel's bureaucracy behaved more reasonably, UK would not run away from European Union.

Re: GDPR: Don't Panic

#659

Earlier quoted context omitted.

I get the impression I am misunderstanding EU law (not necessarily a surprise) when folks say things like "Civil law vs. Common Law" or "legal context." If a law is on the books, it can be enforced in the EU, right? I understand there is precedent but precedent is not law, it's merely the common understanding of that law in that particular context. Precedent is overturned all the time (not to mention ignored when con…

That is a fine analysis but I'm not sure what your question is. All laws exist in a legal context and analyzing them while being ignorant of that context is futile. That's all I was saying. I think almost all the people armchair-analyzing the GDPR in a hyperbolic manner would be equally useless at analyzing their own laws, in their own countries, for what it's worth. (someone in another comment said something contras…

I thought the article was well written, rational, and measured, and with the right leaning toward not capturing data to avoid worrying about the GDPR.

That said, I would've liked to see a bit more healthy skepticism about the ability of any sort of government or organization to avoid mis-using laws with a wide breadth when it suits them, especially if things slide toward tech-protectionism.

Re: GDPR: Don't Panic

#660

Earlier quoted context omitted.

Go look up what CPMs are for the EU. Having your website in the EU will simply not mske you much money, why even bother?

Sorry, I don't even know what CPMs are. Could you provide a link?

Cost per thousand people. It is an advertising metric.
Post reply on HN