Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

661–670 of 833 posts

Re: GDPR: Don't Panic

#661

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

> has not cost me any money, only time It sounds like you don't value your time. In my universe (software development), time is money.

No, I definitely value my time. I actually (and maybe strangely) have appreciated the opportunity to review my data processes, privacy policies and security. I think my business is better for it. Also, getting compliant is mostly a one-time effort with little maintenance, whereas paying $1000+ every year for a EU representation service that will in reality probably do absolutely nothing is very irritating to me.

That said, your point is still fair. I sometimes spend my time less-than-optimally because it feels "free."

Re: GDPR: Don't Panic

#662
"Add filters keeping out children"

What are some methods for doing this? (aside from asking for birthdate, which is far from fool proof)

Re: GDPR: Don't Panic

#663
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

I was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full.

This seem explicitly allowed for in the law.

Re: GDPR: Don't Panic

#665

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

> My email signup forms are very clear about marketing use, and are double opt in, and subscribers can opt out with a single click. But my research suggests that this is still not GDPR compliant unless there is an explicit consent, which I believe will reduce email signup rates. But if it required user activity to register for those lists AND you explicitly identified them as for marketing purposes, that seems like y…

I'm not a lawyer, but my interpretation of GDPR and the research I've done suggests that my current lead magnet approach (which is at least in the US very common) gives me consent to use the email for delivering the lead magnet, but not for marketing unless there is an explicit opt in for subsequent marketing emails. I think (and I have read) that not getting the user to explicitly check a box for marketing emails is implicit consent and is not allowed under GDPR. Also, saying something like "you cannot sign up for getting this lead magnet unless you consent to marketing emails" is also not allowed. That said, I agree with you that I'm very clear. So maybe I and others are interpreting GDPR too strictly. Here is one article that takes GDPR very strictly: https://kerstinmartin.com/blog/gdpr-lead-magnets

I just found another article however with another solution which may be better. The article suggests instead of saying "Get this free ebook! And p.s. we will send you information and marketing emails about our product." you should say "Sign up for our newsletter to receive information and marketing emails about our product. Also we will send you a free e-book as a gift." It's not as good of a call-to-action, but changing the order does turn into explicit consent for marketing. Source: https://blog.mailrelay.com/en/2017/12/28/new-gdpr#_What_abou...

Re: GDPR: Don't Panic

#666
post #203

Earlier quoted context omitted.

I have actually seen government agencies complain about being deluged by FOI requests, the cost of dealing with them etc. They mostly get ignored because on inspection the "deluge" of FOI requests tends to be from journalists digging for stories, and that's sort of what we want them to do. Also because the high cost of FOI responses tends to reflect messy and disorganised internal information systems rather than anyt…

> But GDPR enforcement is incentivised by large sums of money, for an organisation that is technically bankrupt. What do you mean here? It seems to be about suggesting that GDPR is about getting the fine money? Elsewhere the law is quoted where it states the fine should be appropriate to be effective. So even if you don't trust this there's legal ground to back it up. Secondly, why is the EU technically bankrupt? Or…

What does "appropriate" and "effective" mean in the context of law? Put it like this - do you really believe the first targets won't be Google, Facebook, Apple, etc? Very rich companies in industries the EU has failed to compete in and which handle data all day? It's free money for the EU.

Secondly, why is the EU technically bankrupt? Or is this a theoretical organization?

Because its liabilities are greater than its assets, or put another way, it spends more than it receives and does so structurally.

http://bruegel.org/wp-content/uploads/2018/03/PB-2018_01_cor...

EU budget commitments exceed payments by about €10 billion a year, leading to an ever-rising volume of outstanding commitments, known as reste à liquider (RAL). RAL is expected to exceed €250 billion by 2020.

The EU is not a company, it's effectively a government, and so it simply doesn't allow itself to go bankrupt in a legal sense. It can violate contracts at will because it ultimately controls the courts. So when it doesn't have enough money to make payments it has committed to, it simply delays those payments. This results in an ever growing backlog of delayed payments that can't be made because the EU doesn't have sufficient funds.

Note that this behaviour is illegal under the treaties. The EU is not allowed to spend more than it receives. It does so anyway because it correctly believes the member states are too weak to enforce the rules. Also, the EU controls the ECB and ultimately the ECB is keeping many member states afloat via massive bond purchases. Whilst the EU Commission cannot legally just print money to fund its own operations, in practice that's what it's doing - the ECB prints money and uses them to buy the bonds of insolvent member states, which then turn around and hand some of that money back to the EU as part of its budget.

Re: GDPR: Don't Panic

#667

Earlier quoted context omitted.

It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…

Your comment led me to wonder if any businesses are considering raising prices for EU customers as a result of this law. I'm not so much wondering about the "we lost revenue because we can't sell your data anymore", but more along the lines of "complying with the regulatory environment in this region is expensive, and we pass the cost of compliance along to customers in the region". I recently learned about the AU wa…

Yes, it's being considered.

Re: GDPR: Don't Panic

#669
post #601

Earlier quoted context omitted.

As a fellow American, that sounds like you need to reconsider your news sources. Brexit was driven by propaganda, not some principled opposition to intractable problems. The “EUrocrats gone wild” stories are popular in certain circles but there’s an entire cottage industry debunking them: https://en.wikipedia.org/wiki/Euromyth

Both "stay" and "exit" sides were covered pretty well. But if Brussel's bureaucracy behaved more reasonably, UK would not run away from European Union.

Again, that's taking a talking point as a given. Some people cited that or hypothetical cost savings as a justification but the claims tended to be based on urban legends or outright wishful thinking rather than actual analysis.

Re: GDPR: Don't Panic

#670
post #425

Earlier quoted context omitted.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

The whole world has had TWO YEARS to be compliant. "It takes time" is not an excuse.

I didn't see the text TWO YEARS ago. Did you?
Post reply on HN