Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

691–700 of 710 posts

Re: How GDPR Will Change The Way You Develop

#691
post #634

Earlier quoted context omitted.

No, it does not. A company in PA, USA does not give two cents about EU VAT. It charges EU customers in the US and provides services in the US and tells EU to shove it. Actually, it does not even do that. It simply ignores everything that EU does.

Like I've said if you are small enough to avoid any interest, it's ok - but selling electronic services to EU residents without VAT in the EU is not legal. Overall VAT is taxation on the consumption, the consumption is within the EU member state, the state receives the tax. Summary: When US companies encounter European VAT: When doing business in the territory of the EU a company will deal with VAT: when selling some…

This is not at all what I’ve encountered at several jobs, and the auditors have confirmed.

The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU.

Conversely, I have bought many items and services online from EU companies who don’t have presence in the USA. Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.

In short, my experience is you’re just plain wrong. A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.

Re: How GDPR Will Change The Way You Develop

#692
post #328
post #293

Earlier quoted context omitted.

> Sounds like you have a legitimate interest in logging IP addresses for security purposes, it is an effective measure and that your legitimate interest on balance outweighs the interests of the data subject. If that is the case you could probably rely on the “legal basis” called legitimate interest and do not need consent or anything like that. Assuming you are right, that answers part of my question. Yet, I would p…

See GDPR recital 24 ( http://www.privacy-regulation.eu/en/recital-24-GDPR.htm ): [...] In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to…

Predicting and profiling for the purposes of security defense is then illegal? It’s not a legitimate interest?

Then every system implementing fail2ban or email tarpitting (so everyone running Ubuntu or MS exchange in default configs) is automatically violating GDPR.

Never mind the built-in catch-22 where you can’t store any identifiers of persons who have opted out, so you cannot remember they opted out and have to ask them repeatedly!

This law is completely unenforceable, and that is the worst kind of law. It results in inconsistent, politicized and malicious enforcement.

Re: How GDPR Will Change The Way You Develop

#693

Earlier quoted context omitted.

You're referring to express consent. However, the user is granting implied consent - they're the ones visiting our website, they're the ones requesting our images and executing our javascript, and they're the ones filling out our forms. We're not forcing them to do any of these things.

Implied consent is not consent.

It certainly is, and any reasonable person would agree.

If you send me an email, am I allowed to keep your email address in my mail logs, archives, and inbox? Hell yeah I am, you gave me implied consent to do that by sending me email.

Am I allowed to spam the email address you gave me? Of course not. But I can keep it.

Placing an automatic and extreme burden on the recipient of a communication like a website visit or email, which is exactly what the GPDR does, is just plain bananas.

Re: How GDPR Will Change The Way You Develop

#694
post #332

Earlier quoted context omitted.

If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulator…

"act as a continuous drag on developing new technologies" I don't see this as a bad thing. For far too long, we've not cared at all about user data and privacy.

Yes, this shifts things to privacy first, instead of second/never.

Re: How GDPR Will Change The Way You Develop

#695
post #672

Earlier quoted context omitted.

I don't want to torture this metaphor any further, but you're kinda proving my point that software developers do not consider the energy and environmental impact of their work. Software that uses significant CPU time uses more electricity and is worse for the environment. Misuse of personal data is a problem. Wasting electricity is a problem. Online harassment is a problem.

If wasting electricity becomes such a big problem for the society as misuse of personal data already is, sure, let's introduce regulations on that, too. In some European countries, there are regulations already on how to insulate new buildings to avoid energy waste.

> If wasting electricity becomes such a big problem for the society as misuse of personal data already is, sure, let's introduce regulations on that, too.

Sure, what could go wrong there? Regulator, "We're going to need to look closer at that for-loop to see if it complies. And you do realize that n+1 queries are a violation of EU law?"

Re: How GDPR Will Change The Way You Develop

#696
post #332

Earlier quoted context omitted.

If only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulator…

When stuff like this comes up it always seems so weird to me that with all the work that regulators put into this, why can't they at least scratch the surface of providing some specific examples? Of course there are legal documents, and maybe some "for dummies" versions written up about it. But would it be so crazy for these regulators to hire someone who knows something about commonly used open source software and b…

> But would it be so crazy for these regulators to hire someone...to help provide a little bit of actionable technical advice?

Didn't you know? They do. Large corporations are always happy to help regulators write laws in such a way as to benefit them to fend of those pesky innovators. [1] Raising compliance costs as high as possible is highly desired by large companies.

[1] https://en.wikipedia.org/wiki/Regulatory_capture

Re: How GDPR Will Change The Way You Develop

#697

Earlier quoted context omitted.

> When stuff like this comes up it always seems so weird to me that with all the work that regulators put into this, why can't they at least scratch the surface of providing some specific examples? Technology is something which constantly changes. From the point of view of the legislator, legal text that is too concrete will stagnate innovation and progress by "locking" people into current technological assumptions.…

That doesn't work though. Sure, if it was some industry initiative then a broad statement of intent and people figure out the details as they go would be OK. But this one comes with massive, company destroying fines attached. If you and other domain experts debate and decide on a best practice, and then some EU commissioner disagrees and destroys your company with a fine you cannot pay, will you be so sure that vague…

> company destroying fines

They are not company destroying for large companies though. By raising fixed cost (and risk) of doing business, regulations of this kind are an absolute godsend for large companies.

Re: How GDPR Will Change The Way You Develop

#698
post #634

Earlier quoted context omitted.

Like I've said if you are small enough to avoid any interest, it's ok - but selling electronic services to EU residents without VAT in the EU is not legal. Overall VAT is taxation on the consumption, the consumption is within the EU member state, the state receives the tax. Summary: When US companies encounter European VAT: When doing business in the territory of the EU a company will deal with VAT: when selling some…

This is not at all what I’ve encountered at several jobs, and the auditors have confirmed. The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU. Conversely, I have bought many items and services online from EU companies who don’t have presence in t…

>The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU.

If you import goods (receive them via mail), there is a customs clearance required + VAT for prices over N euro (where N varies on the country but usually less than 25e). Indeed that's a direct responsibility of the receiver.

>Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.

Please don't mix the laws in different jurisdictions. VAT is quite different than sale/use tax. Try and buy goods from USA (even ebay suffices) and receive it within the EU w/o paying VAT (unless explicitly exempt from the tax)

Electronic services have no customs clearance or physical presence and what I explained above (VAT number, etc.) applies.

>A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.

Proof by authority ain't cool. VAT does apply to the end user (companies can receive it back, etc.), so I am unaware if your employers used to sell to end users directly. If selling services was that easy, registering outside EU would so temping as pricing ~20% less would be great. As proof goes: I consulted an accountant about US offered services to a local EU member state. (didn't have to pay anything)

Examples of not being able to sell services to US residents are forex and gambling. Non-US companies practically can not take US customers. Selling services online ain't that easy even to US.

Re: How GDPR Will Change The Way You Develop

#699
post #698

Earlier quoted context omitted.

This is not at all what I’ve encountered at several jobs, and the auditors have confirmed. The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU. Conversely, I have bought many items and services online from EU companies who don’t have presence in t…

>The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU. If you import goods (receive them via mail), there is a customs clearance required + VAT for prices over N euro (where N varies on the country but usually less than 25e). Indeed that's a direct…

> Proof by authority ain't cool.

Appeal to authority isn’t a logical fallacy when the authority is an expert in the domain.

Re: How GDPR Will Change The Way You Develop

#700
post #619

Earlier quoted context omitted.

You knock on my door and I write down that you visited me. Why is it somehow reasonable to compel me to forget that interaction existed?

Because 1) your analogy is off. People forget, a machine does not 2) GDPR is about privacy; tracking people's behaviour, linking things together without explicit consent is not allowed according to GDPR.

1. If I am writing it down, as my analogy suggests, it is not forgotten.

2. I understand what it's about.

If you want to make tracking people and linking things together illegal, great.

However, my argument in response to the OP intended to illustrate that recording information about someones actions, particularly when it's a party who is part of the interaction creating the recording, does not seem to have some preexisting moral expectation or attached to it.

Hence, to me at least, the GDPR's directives are not objectively reasonable or obvious in some way as suggested by the OP.

I also think forbidding certain uses of the data is more reasonable than to regulate its collection and storage. But yes, that's probably riskier and harder to enforce.

Post reply on HN