Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

671–680 of 833 posts

Re: GDPR: Don't Panic

#671

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

First of IANAL, I'm a European citizen within IT that has to deal with GDPR in my professional role. I believe there is a lot of hysteria and FUD around GDPR. Anyway, this is how I would handle your problems. 1. In the same article[1] that you reference, the following paragraph might apply to your business: >27.2 The obligation laid down in paragraph 1 of this Article shall not apply to: >processing which is occasion…

Thanks mjewtoo, I appreciate the feedback.

Re #1: To be exempt you must fit all 3 criteria: 1. processing is occasional 2. does not include, on a large scale, processing of special categories of data (e.g. religious, political, criminal backgrounds, sexual orientation, etc.) AND 3. unlikely to result in a risk to the rights and freedoms of natural persons I collect a number of emails on my website and apps every day, so I don't think my processing is "occasional". If I collected emails once a year or even once a month, sure I could argue that processing is occasional. But collecting 10-20 email signups per days doesn't seem occasional to me.

2. Thanks for this opinion on this. I think I agree your assessment.

3. Again, I think I agree with you - thanks for you opinion.

Very helpful, thanks!

Re: GDPR: Don't Panic

#672
post #358

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

This law may be not a big deal and not heavily regulated and not impact US small businesses at all - but many don't want to be the first to find out. After the dust has settled for a few years, then I'll make a conclusion if it has been applied fairly.

Re: GDPR: Don't Panic

#673

Earlier quoted context omitted.

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

I was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full. This seem explicitly allowed for in the law.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests.

(2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject.

I see such a service as acting in bad faith and would file a complaint against you and your service if such a frivolous request would land in my inbox. Better hold on to the $40, you might need to spend them on a lawyer.

But kudos for trying to see the GDPR as an opportunity, now try to do so in a more constructive way. And - funny - you would be mailing yourself since you would be sure to hold PII on the party making the request in order to be able to authenticate the request as being a genuine one, which in turn would make you required to be in compliance.

Re: GDPR: Don't Panic

#674

As a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non…

I suspect you’re going to get the predictable response here that you should do the most conservative things possible, and if that tanks your optin rates and email list and ultimately your business, then obviously you’re a filthy scammer and your business deserved to die. The lead magnet thing is such a good example. It’s a clear and voluntary trade-off: you can have this free resource if you join my list, from which…

Thanks for your feedback. I have heard from some of my friends who also run small businesses that they also plan to do nothing. I think for a purely practical perspective, it's extremely unlikely that EU regulators will go small software, app or web businesses in the US – I'm sure they have bigger fish to fry. That is, unless the small business does abuse their customers data and privacy resulting in a large number of complaints to EU regulators. Still, I think almost all of GDPR is pretty reasonable and not very costly (time or money) to implement (at least to me).

Re: GDPR: Don't Panic

#675
post #358

Earlier quoted context omitted.

> A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR Come on, this is just scaremongering. Newsflash: If you run a business, you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. But you don't see people running around screaming that the world is ending, because they know that the laws will generally be applied f…

Which other violation could cost me a 20 million dollar fine ? Sure, they will probably don't give that fines, but they could, what if I run a small business that interferes with the activity of some other business run by for example someone that is friend or can corrupt the people in charge of doing the fines ? They will fine me for 20 million dollars, sure I can appeal, a normal trial in my country lasts at least 5…

In order for prevent the law from becoming feckless, there had to be an element of discretion on the part of the enforcers. It’s there to cut the bullshit of companies who use blatant trickery/loopholes to make themselves seem like a smaller company in order to reduce their potential fines.

But as I already said, the stability of the EU’s economy depends on fair application of the law. If the EU levies a 20 million Euro fine on a company with 20 million/year in revenue, the chilling effects of that action would cause much more than 20 million in damage to the EU economy. That should be blatantly obvious. Despite propaganda to the contrary, the EU has a very good record of behaving as a reasonable government entity, moreso than most. They’ve championed quite a few consumer-friendly pieces of legislation that have managed to not destroy the applicable sectors.

If you think this is a valid concern, I can only assume you’re just as worried about other outcomes that have insane, struck-by-lightning levels of unlikelihood, in which case you are not going to have the spare cycles to be able to successfully run a business anyway.

Re: GDPR: Don't Panic

#676
post #59

I can't help but love the turmoil GDPR is causing in the adtech "industry". Like wasps buzzing around the exterminator who's about to destroy their nest.

When people losing their jobs due to government overreach makes you happy, check your motivations.

People keeping their jobs is not the most important thing one should strive for with no regards to anything else. Especially not in tech, where it's more than likely that it won't really hurt them.

Re: GDPR: Don't Panic

#677

Earlier quoted context omitted.

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…

[deleted]

Re: GDPR: Don't Panic

#678

Earlier quoted context omitted.

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.

I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…

Because they don't know anything about EU authorities and have no reason to trust that they have the interests of US small businesses at heart? To them, this could potentially be a money grab with no pain to their constituents. It's already playing out to some extent with their new tech taxes.

Re: GDPR: Don't Panic

#679
post #538

Earlier quoted context omitted.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

This argument makes about as much sense as "if you have nothing to hide, you have nothing to fear" in support of surveillance laws. Presumption of guilt is a terrible rule to live by.

Actually your argument makes no sense because it amounts to : I am honest therefore there is no need for laws. Thousands of years of human history suggests you are wrong.

Re: GDPR: Don't Panic

#680

I can tell you that GDPR is going to cause issues with block based backups. Many hosting providers don't separate customers on different block devices. When you back up a block device you have snapshots that have many different organizations data on them. Part of making good backups is knowing that the backup can't change. The only solution now is to add paths to go back and modify those backups to remove customer da…

The solution is to keep a list of "things to exclude" if a backup is ever restored. This is reasonable. Rewriting old backups is not reasonable.

Would such a list not by nature consist of PII?
Post reply on HN