Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

71–80 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#71
Yeah, they were meant. Yet wherever I go on the web I am being asked to opt-out from tracking since default I am opted-in - this is clear violation of GDPR, however is seems nobody is trying to enforce this.

Opt-out is typically covered by a ton of shady UI patterns, so it is hard to do this. Another clear violation of GDPR is punishing those who does not agree for tracking by serving them crippled content or no content at all.

And just to make it clear: I am strongly against extraterritorial laws like GDPR or FATCA. US does not have any rights to enforce their regulations outside US, similarly EU does not have any rights to tell people outside EU how their websites should look like. This is clear abuse of the economic and military power that US/EU have.

GDPR has some good points (like PII data storage rules), however some of its regulations, like the once that force open forums to provide "right to be forgotten" for posts, are pure crap.

The unfortunate vagueness of this regulation does not help either - real live example from Poland: if school teacher takes home pupils copybooks, which are signed with a pupil first and last name, does this mean that GDPR rules apply to the teacher (getting consents, proper handling and storage for copybooks, etc.)? Some lawyers claim they does not, some say they does, some have no idea. As a result in some schools pupils are forbidden to sign anything that enters the school building with a full name... Overreaction? Probably. But you never know when some mean parent would want to use GDPR against the school.

Re: GDPR fines were meant to rock the data privacy world

#72

I am still convinced fines will, but big investigations take a long time. There's an ongoing case about Google's real-time ad auctions for example.

The data protection commissioners have their work cut out for them for the next decade.

It's just that the current privacy abuses of software companies are so complex and egregious that it takes a long time to sort things out.

Essentially every US company was doing things wrong for example. Just the other day I was reading LinkedIn's cookie notice which can be paraphrased as "accept our tracking commoner". And this is a bug company owned by MS, the new heroes of open source (and spyware).

It's the wild wild west out there.

Re: GDPR fines were meant to rock the data privacy world

#73

Earlier quoted context omitted.

That’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/

They paid the fines, but and what changed? Are users any better off now because those companies got fined? Did those companies stop collecting user data? Has online privacy improved because of those fines? Nope!

>Are users any better off now because those companies got fined?

Yes

>Did those companies stop collecting user data?

Maybe not google so much, but other companies certainly stopped or collect a lot less. And it's still early, and there is plenty of low hanging fruit for GDPR enforcement to hit.

>Has online privacy improved because of those fines?

The full effects remain to be seen, but yes, it has improved. Maybe not for you, but for me it certainly has, in particular with German businesses I use.

Aside from regulations, it also fueled and still fuels public discussion, especially in the tech space. Where half a decade back everybody would have ignored e.g. GitLab's email informing users and customers that they are going to roll out third party tracking, but this time around the backslash was so swift and hard GitLab went back to the drawing board (goof for them!).

On top of that, the EU inspired similar laws around the world including most the (somewhat lenient) California Consumer Privacy Act that comes into effect next year.

Re: GDPR fines were meant to rock the data privacy world

#74
post #71

Yeah, they were meant. Yet wherever I go on the web I am being asked to opt-out from tracking since default I am opted-in - this is clear violation of GDPR, however is seems nobody is trying to enforce this. Opt-out is typically covered by a ton of shady UI patterns, so it is hard to do this. Another clear violation of GDPR is punishing those who does not agree for tracking by serving them crippled content or no cont…

Have you considered that almost everyone was abusing your privacy before and it takes a long time to sort things out? At least now you know you're dealing with assholes.

I don't see why your example from Poland is bad. Teachers are now thinking about the privacy of their pupils - this is mandatory in today's world.

Re: GDPR fines were meant to rock the data privacy world

#75
post #71

Yeah, they were meant. Yet wherever I go on the web I am being asked to opt-out from tracking since default I am opted-in - this is clear violation of GDPR, however is seems nobody is trying to enforce this. Opt-out is typically covered by a ton of shady UI patterns, so it is hard to do this. Another clear violation of GDPR is punishing those who does not agree for tracking by serving them crippled content or no cont…

> if school teacher takes home pupils copybooks, which are signed with a pupil first and last name, does this mean that GDPR rules apply to the teacher

I don't see how you could possibly claim that this is a kind of automated processing or a structured filing system.

So it's another example of fear without knowing the basic principles of the GDPR.

Re: GDPR fines were meant to rock the data privacy world

#76

Earlier quoted context omitted.

> Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food" But that's exactly what we do. The health inspector doesn't come to your home to verify that you wash your cutting board, even on the day you have a dinner party to entertain business clients. Depending on…

I believe your being down voted because it is common knowledge that food service legislation only applies to those selling food, and therefore intentionally doesn’t apply to dinner parties.

Does the GDPR only apply to those selling personal information?

Re: GDPR fines were meant to rock the data privacy world

#77

Earlier quoted context omitted.

Fines for larger companies are either too small to matter or will be negotiated down. Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. This can be seen by the constant consent popups on every website. Users click yes on the major sites, then deny the rest.

> Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. I feel the opposite may be true. When the law came to pass, I took some time to review my privacy options on Google and Facebook, since they are a big impact for me. On the other hand, when I click on a link on HN to some random news paper, and get presented with a five-…

[deleted]

Re: GDPR fines were meant to rock the data privacy world

#79

Earlier quoted context omitted.

I believe your being down voted because it is common knowledge that food service legislation only applies to those selling food, and therefore intentionally doesn’t apply to dinner parties.

Does the GDPR only apply to those selling personal information?

If your European friend tells you their phone number and you write it down on your refrigerator (or your public blog for that matter), the French government isn’t going to come fine you for violating GDPR.

Re: GDPR fines were meant to rock the data privacy world

#80

Earlier quoted context omitted.

You're assuming that treating data carefully and complying with the law are the same thing. You can easily do the former and not the latter. More to the point, you can easily have already been treating data carefully and still have the compliance burden of paying lawyers to verify that fact put you out of business. So what you're really saying is, if a company cannot afford to stay in business while navigating a lega…

The same goes for any other kind of regulatory compliance. No small company has to pay lawyers to validate that they are complying with GDPR. It’s just that if it turns out they weren’t, the fines for violations can be quite steep, so a risk-averse company is going to be proactive about it. There are many types of regulations which are much stricter with more up-front costs than GDPR, which companies of every size ma…

> The same goes for any other kind of regulatory compliance.

I don't think anybody disagrees with that. All regulatory burdens harm small businesses -- which is why they should all be minimized to the greatest extent possible.

> No small company has to pay lawyers to validate that they are complying with GDPR. It’s just that if it turns out they weren’t, the fines for violations can be quite steep, so a risk-averse company is going to be proactive about it.

And investors are risk-averse, so investors want to see compliance, so they're forced into the choice between going out of business due to the compliance burden or going out of business as a result of an inability to get investment without showing compliance.

> There are many types of regulations which are much stricter with more up-front costs than GDPR, which companies of every size manage to cope with (or sometimes don’t, and go out of business).

Two wrongs don't make a right. Nor do a hundred.

> The technology industry has just gotten used to not being held accountable when it harms people, so now that some sensible consumer protection regulation comes down (some) people are freaking out.

The technology industry is Intel and Samsung. Chips rather than bits. Plenty of regulation there -- environmental, patents, government contracts, etc.

But now we're talking about regulating information. It's not a particular industry, it's a thing all people do all day long. It's regulating people talking and writing stuff down. The number of people subject to whatever burden you impose is effectively everybody, so the burden inherently has to be small or when you multiply it by everybody everywhere it becomes an absurdity. If it's too complicated then either nobody complies with it and it's useless (and dangerous) or you crash the world by making everybody try to.

Post reply on HN