Earlier quoted context omitted.
As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?
GDPR and “not spying on your users” are not even remotely related. GDPR is a massive regulation requiring significant resources that most small businesses simply don’t have.
GDPR: Don't Panic
681–690 of 833 posts
Re: GDPR: Don't Panic
#682Earlier quoted context omitted.
The solution is to keep a list of "things to exclude" if a backup is ever restored. This is reasonable. Rewriting old backups is not reasonable.
Would such a list not by nature consist of PII?
Re: GDPR: Don't Panic
#683Re: GDPR: Don't Panic
#684The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.
Hate? Try to think of it from a business in the US perspective that wants to know why they have to (for lack of a better way to put it) bogu to an entity that does not represent them in any way. And the fact that you might sell something or service customers in Europe does not mean you should have to answer to any rules that they setup either. Should the town that I live in and operate a web site out of be able to have rules in place and then go after citizens in the EU for not abiding by them?
And actually it's one step further since many of the procedures and rules are being taken broadly and universally even against entities (businesses and us persons) that aren't even covered by the GDPR.
And no it's not like 'oh if you want to sell a car in Europe you need to certify this and that' that is not the same thing. Why? Well for one thing the golden rule. If you want that car allowed through the port you need to do what they tell you to do or they have a right to not allow it on their land. In this case their citizens are utilizing US websites and therefore it's on them to determine if they feel the service or product they are getting is fit.
I am referring to US businesses that don't have an office or physical presence in Europe. To those that do the 'golden rule' applies.
Re: GDPR: Don't Panic
#685You missed a key question here. As a business owner, what on earth do I need to do next?? Do I need to email all my users giving them an opt-out option?!
This whole sequence was sparked through a discussion about the GDPR on HN a few weeks ago and I've been working on it off-and-on hoping to get it done before the law becomes enforceable.
Re: GDPR: Don't Panic
#686Earlier quoted context omitted.
So because you don’t have many in-scope systems, you believe that the cost of compliance is going to be the same for every company in the world? And what did I say that gave the impression that I don’t respect my users or their data? Our application is a financial one, so I’d say it’s reasonable to assume that it ends up with a lot more in-scope PII than yours does. In spirit, we also comply with almost all of the GD…
> However, that’s not how we manage risk. I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph. Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation. Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat exces…
In Europe, because of classification systems surrounding IBM and Nazis, have chosen to be very proactive about the dangers of having too much data. It may be used right now in a good way, but the data can easily be used for very evil things.
The GDPR reminds me of a Target (chain retailer) advertisement where a 17 year old girl was being profiled and send pregnancy, maternity, and baby ads. The father was angry at Target sending his daughter this, until the daughter fessed up that she was indeed pregnant. How did they determine this? Shopping purchase records. The GDPR may not have stopped the first occurrence, but would have provided sufficient "bite" to ever stop this from ever happening again.
https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
Re: GDPR: Don't Panic
#687Earlier quoted context omitted.
> EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. You have to trust someone. Either the vast expanse of companies clearly mishandling your data, or the "benevolent" body which so far at least has a fairly good track record. It's not perfect. It's dangerous to give them too much power because you don't know how they will change in…
A fairly good track record in which its own member states are constantly threatening to leave and one has already successfully left. As an American lokoing in from across an ocean, it does not look like a stable region that I would put trust in
Anti-EU sentiment is generally driven by national politicians who somehow always seem to cast blame on the EU when things go bad and take credit themselves when things go well. Even going so far as taking credit for implementing laws they were actually forced to implement by the union.
Re: GDPR: Don't Panic
#688I can tell you that GDPR is going to cause issues with block based backups. Many hosting providers don't separate customers on different block devices. When you back up a block device you have snapshots that have many different organizations data on them. Part of making good backups is knowing that the backup can't change. The only solution now is to add paths to go back and modify those backups to remove customer da…
The conventional solution to that problem I’ve heard for the last couple decades is to use encryption so the backup doesn’t need to be altered ahead of your normal rotation schedule as long as you can probably drop a customer’s key on demand.
Post hosting providers, or anybody really don't create new volumes for each customer. They would simply have a directory per client. Onces you start needing to know more about the file system then you sort of waste all the benefits block based backups provide.
By block based I mean volume based, were we simply copy the allocated blocks of the file system that changed between each backup.
Re: GDPR: Don't Panic
#689Earlier quoted context omitted.
If the court seals the record its nearly impossible for anyone but government agencies to discover
> If the court seals the record its nearly impossible for anyone but government agencies to discover No, it is not, because background check and other third-party intelligence firms aren't purely reactive now, they have and use tools to proactively vacuum up public records and maintain their own DBs. After-the-fact sealing of arrest records or expunging of convictions has no effect on data that is already in third-pa…
Re: GDPR: Don't Panic
#690Earlier quoted context omitted.
> However, that’s not how we manage risk. I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph. Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation. Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat exces…
I think the underlying idea here, is that data is "radioactive". Quite a lot of data can be fed into classifier systems to accurately identify people (not just computers), their trends, their shopping habits, and other much more private things. In Europe, because of classification systems surrounding IBM and Nazis, have chosen to be very proactive about the dangers of having too much data. It may be used right now in…