Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

691–700 of 833 posts

Re: GDPR: Don't Panic

#691
post #405

Earlier quoted context omitted.

> If your company can not show the candidates why they were not hired, you are doing a very bad job. You sound like you've never had to deal with telling a candidate they weren't chosen for a position. There's a reason rejection letters are usually canned responses - it's not that HR teams are unanimously evil people, it's because any bit of information could open up the potential for a law suit, even if in good spir…

That is the usual stated justification, and may actually be the motivation where it's become accepted as conventional wsdfom, but it's implausible on its face as a real justified concern, because it's just as easy for a rejected subject to infer ill intent from a refusal to explain as from an innocuous explanation. The real reasons for such policies send to be a combination of: (1) Regardless of organizational polici…

> because it's just as easy for a rejected subject to infer ill intent from a refusal to explain as from an innocuous explanation.

Sure, you can infer all you want, but I'm talking about whether there is grounds for legal proceedings. There is a higher probability that a defense lawyer would take a case where the rejection letter says "you weren't a good culture fit" vs "you didn't get the job". Companies simply do not want to even open themselves up to litigated, even if they've done nothing wrong. Further, there is no commercial incentive to tell the candidate anything other than "you didn't get the job", so why bother?

> People attempting to give honest explanations will sometimes explain things poorly in a way which indicates a prohibited

That's precisely my point. It's very difficult to explain to someone that they've been rejected for a position even in the most sincere and nicest way possible.

Re: GDPR: Don't Panic

#692

Earlier quoted context omitted.

That's what we've chosen to do. The reality is that most businesses outside the EU will wind up blocking EU traffic, simply because they don't want the liability.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

One could read this as you're being dodgy with your user data. If you were reasonable with the data in the first place, then compliance costs nothing.

Re: GDPR: Don't Panic

#693

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

To be honest I know nothing about law enforcement in the EU, but the one thing I have heard about in recent memory is that guy who made a video of his girlfriend's dog saluting hitler, and was subsequently tried for a hate crime, convicted, and was charged with a pretty hefty 800 GBP fine after being found in violation of the Communications Act of 2003[1]. Seems like a pretty poor example of principles-based regulation. Maybe it's just an outlier though, idk.

[1] https://en.wikipedia.org/wiki/Mark_Meechan

Re: GDPR: Don't Panic

#694

One question that I have thought about is how are foreigners supposed to learn about the GDPR's existence? If it wasn't for the fact that I spend more time on HN that I should I would never have heard of it. I doubt there are many businesses here in Australia that know about it.

[deleted]

Re: GDPR: Don't Panic

#695
I spent two hours today at our campsite working on my web sites to make them reasonably compliant. One problem area is that I serve my blog on Google Blogger. With pained reluctance I turned off comments and stopped showing my followers. I also linked to Google’s own GDPR info page. I used to use Jekyll and maybe I should go back to doing that.

Any suggestions?

Re: GDPR: Don't Panic

#696
post #622

Earlier quoted context omitted.

Who defines what is a legitimate business purpose? Let's say I comply with all that, but someone makes a complaint and particularly bitter civil servant judges that the collection is not legitimate, because he doesn't like the content of the website?

That’s like arguing that we shouldn’t have laws in case a cop is having a bad day and follows you around writing tickets. This is a legal process like anything else: your standard should be what you’re comfortable defending in court. Being able to show a good faith decision process, compliance with common industry practice, etc. are going to help the case that any lapse was unintentional. If your angry ex is hired by…

But appeal might take forever and by the time it is resolved you file for bankruptcy because the fine ruined the cash flow. I've seen in it many times in the EU, for example in Poland. Civil servants are immune from taking responsibility and if you manage to get any compensation you'll find yourself spending years in courts.

Re: GDPR: Don't Panic

#697
post #637

Earlier quoted context omitted.

Every institutions have targets to prove their existence is of benefit to the tax payer.

That doesn't have to be in money raised, that would be rather unlikely in this case. It could be percentage of problems "fixed" whether that be by sharply worded letter or by court proceedings (the former is far easier and cheaper for the authority), or by the time it takes the authority to investigate a problem.

You don't know that, depending how mad is the person in charge. Take into account that it might be good for a couple of years but the power it gives might be tempting to shut down sites that are against EU agenda.

Re: GDPR: Don't Panic

#698

Earlier quoted context omitted.

That's what we've chosen to do. The reality is that most businesses outside the EU will wind up blocking EU traffic, simply because they don't want the liability.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

In most industries, US consumers spend far more than consumers anywhere else in the world.

Not any more. China's citizens spend twice as much on international tourism as US citizens do. The EU has 508 million people. The US has 325 million.

Re: GDPR: Don't Panic

#699
post #646

Earlier quoted context omitted.

It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.

I am having a hard time seeing how EU judgements will be enforceable in the US?

Probably they will not be - but there are cases of extradition of EU citizens to the US for various crimes like hacking. Who knows, maybe it will happen the other way around or some people will have to take holidays in the EU off the list.

Re: GDPR: Don't Panic

#700
post #693

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

To be honest I know nothing about law enforcement in the EU, but the one thing I have heard about in recent memory is that guy who made a video of his girlfriend's dog saluting hitler, and was subsequently tried for a hate crime, convicted, and was charged with a pretty hefty 800 GBP fine after being found in violation of the Communications Act of 2003[1]. Seems like a pretty poor example of principles-based regulati…

The actual ruling was that him saying 'Gas the Jews' tens of times during the video was calculated to offend, rather than the dog thing
Post reply on HN