How does this affect people who aren't based in Europe?
How do you check if someone is an EU resident?
GDPR: Don't Panic
71–80 of 833 posts
Re: GDPR: Don't Panic
#72This is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?
I recognized your user name from the other thread ( https://news.ycombinator.com/item?id=17095217 ), it looks like you've made up your mind (to the point where your comments where ridiculous enough to be deleted) and no amount of argument will even get you to consider any other options. Why don't you tell us how you really feel?
Re: GDPR: Don't Panic
#73Earlier quoted context omitted.
I think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).
And as so often the EU will be the initiator of a world wide adoption of (semi) unified rules, as it was for USB charging, among other things. It will naturally get a lot of flack and a few people/companies will make it their scapegoat as to deflect from them as usual, but that's - sadly - almost normal now. Is it all good: no! Is it a good start: yes! Is it IMPOSSIBLE to comply: heck no, I'm working at a small Austr…
Re: GDPR: Don't Panic
#74This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…
Re: GDPR: Don't Panic
#75Earlier quoted context omitted.
This sounds like the arguments that organisations make against freedom of information laws. There is that risk, but what is the alternative? There doesn't seem to be a middle ground to me - either people can make subject access requests or they can't.
FOI laws apply to governments, not corporations. And yes, civil servants did use those arguments to try and stop FOI. They lost because ultimately they pay themselves out of tax revenues, and when you force people to buy something the bar for denying them information about how that money is used is a lot higher. This doesn't apply in the case of companies and especially not job candidates.
Re: GDPR: Don't Panic
#76The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.
The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.
Exactly 4 decades in France (it started in 1978).
Re: GDPR: Don't Panic
#77How does this affect people who aren't based in Europe?
Perhaps something similar to the supersuccesful EU "cookie law" where a website could ask you on your first visit if you are an EU citizen. Wait, or is it EU residents and not just citizens? Be sure to get that correct.
Re: GDPR: Don't Panic
#78This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…
If you don't have a talent pool, one should remove all candidate data after rejection. It's probably better to outsource talent pools.
Re: GDPR: Don't Panic
#79For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…
Re: GDPR: Don't Panic
#80The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.
The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.
I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privacy policy. CNIL were happy to be involved and taken so seriously, they were satisfied with the changes and even praised them in private. After the company announced the change, some journalists saw an opportunity to make some noise and did so. CNIL then immediately changed their mind and dished out a fine, despite having previously agreed to it. What a farce.
That's at the national level. I can give many examples of cases where the EU has been anything but reasonable.
The entire argument Jaques presents here boils down to his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future.
As pointed out in the other thread, this belief is itself unreasonable, because the nature of the GDPR means that even in the unlikely even it's true today, if in 10 years a new Commission arrives and changes their mind they can retroactively decide that things previously allowed were actually illegal. The GDPR says virtually nothing about anything so they'd certainly argue such a thing was merely a "clarification" and not a retroactive change to the law.
There are plenty of examples of governments doing this sort of thing over time, including the EU, like with Apple's tax situation. Mr Mattheij appears to just write this possibility off entirely.