Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

711–720 of 833 posts

Re: GDPR: Don't Panic

#711
post #257

Earlier quoted context omitted.

I'm starting to wonder if there's an active disinformation campaign about this somewhere. Are people getting their fears from Facebook again? Edit: If there is such a thing I bet it's Cambridge Analytica/"SCL group" involved, since they made their money from large scale nonconsensual abuse of political personal data, and have an arm dedicated to swinging elections with misleading Facebook adverts.

I mean part of the issue is that I literally cannot answer the question "are we GDPR compliant?". The amount of time we've spent figuring out whether we need to sanitize apache logs has been ridiculous. If you search for GDPR IP address you'll get 100 different opinions on what you need to do. That in my opinion is what makes this law ridiculous. How can companies be expected to comply with something this unclear? I'…

Regulators want to see that you thought about the issue and formulated a plan.

If they ultimately disagree with your judgments, they will tell you, and you'll have plenty of time to get a common understanding.

They will certainly not fine you just because you made a honest mistake.

They will maybe fine you if all you have to show is "I didn't want to find a plausible way myself, nobody spoon-fed me, it's not my fault".

Re: GDPR: Don't Panic

#712

Earlier quoted context omitted.

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.

This is, yet again, untrue.

https://gdpr-info.eu/recitals/no-23/

> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.

By blocking EU IPs the service is very clearly, unambiguously, not targetting EU residents.

Re: GDPR: Don't Panic

#713

Earlier quoted context omitted.

LOL! I'll shed many tears for those poor people whose only fault was that they've built a business on unsolicited collection of personal data :'(

Because those businesses don't employ anyone? I assume you've never had to work a job you don't care for.

Tobacco companies and drug cartels employ plenty of people too, yet I would be happy if all of them went bankrupt. I know, I’m such a horrible person!

Re: GDPR: Don't Panic

#714

I think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)

Yes, because being against a law that is both reasonable and the right thing to do doesn't make any sense when you're a real live human being. The hysteria about businesses imploding under legislation is classic internet outrage at a phenomenon not very well understood. If you actually took the time to read the source material, you could very see that it's reasonable and made to protect you. At the same time, you wou…

This is a law with good intent that was very poorly written and is very ambiguous. Most of the people with your view posting here aren’t experts in this regulation or the law in general, but just armchair lawyers who scanned this regulation and like the intent so they argue that it’s simple.

Ironically, if you asked 10 different people with that position about basic facts about this law, you’d all have different answers. Maybe if it’s so simple you could all take a few mins to get your story straight on how it works?

Re: GDPR: Don't Panic

#715
post #556

Earlier quoted context omitted.

Do you actually think the only way to respect users privacy is to comply with GDPR? That is an absurd and narrow minded opinion. Do you also actually believe that the entire regulation is reflected in your two line comment? Listen, you’ve said higher up the thread that you are plan to spread FUD about all companies that don’t comply with GDPR as a marketing strategy for your own product. I don’t see how anybody here…

> That’s not true, and for many companies this is just a simple business decision. But likely based on incorrect advice. You haven't said why you think your company isn't compliant with GDPR, and it's possible your company is compliant with GDPR, or would require only minor tweaks to privacy policies to make it compliant.

If you ask US-trained lawyers (especially those with exposure to the tech or financial sectors) to perform an impact assessment of a European regulation, don't be surprised to receive a full-on Chicken Little response.

The reality is that the law is not a programming language and compliance is about alignment with principles, not blindly following a set of rules.

Re: GDPR: Don't Panic

#716

Earlier quoted context omitted.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith? Sounds like a win for the GDPR to me, we know rigid checkbox-ticking is ineffective. Apart from that, NIST 800-53/800-171 are catalogs of "security controls and associated assessment procedures" for "Federal Information Systems and Org…

> So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith?

Yes, because if I’m supposed to comply with something, I want to know exactly what I’m complying with.

Right now I think I’m already doing everything in good faith, but the enforces of the GDPR may think different.

This is why we have laws- so we can be held accountable exactly.

Re: GDPR: Don't Panic

#717
post #386

Earlier quoted context omitted.

I don't think that's fair. I rather think it gets a lot of hate because it leaves a lot to the discretion of the regulators. Overall, the SMEs I talk to don't have a problem with regulating data (most think it will pop the gangrenous ad-tech bubble). It's the lack of predictability that bothers them.

The "lack of predictability" is a good thing. "You're making efforts to comply with the regulations, but could you have a look at how you're storing this and that?" vs "You're not compliant with the regulation so we have to impose a fine" Are you really saying you'd prefer the second?

No its not. And you have the wrong comparison there. It’s more like:

“You’re making efforts to comply, but even though this isn’t spelled out, we need XYZ done”

vs

“You’ve complied with all the requirements that have been spelled out”

Re: GDPR: Don't Panic

#718

Earlier quoted context omitted.

I liked the aisle, but have a lot of issues with it. This is one of my main ones: IP addresses and information security. Quoting you: > Storing an IP for a limited time for security reasons is fine. Have rules in place for how this data is used and when it is deleted. Don't keep it longer than nessescary. How long is necessary? What does limited mean? Does a regulator now get to determine what sort of algorithms I ca…

> How long is necessary? As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified. > What does limited mean? The same. Long enough to serve its purpose, and no longer (without justifiable exc…

That is silly. IP addresses should not be covered. I should be able to keep IPs for years. They change often anyway.

IP addresses being covered is one of my big issues with GDPR.

Re: GDPR: Don't Panic

#719

Earlier quoted context omitted.

If 10% of the members of my website request a GDPR, then my website will no longer exist. The processing time for that would be a decade.

As said below, this can be automated. If you can't or won't comply, then your website shouldn't exist.

Or we just avoid the EU altogether.

It shouldn’t even be possible to request anyway.

Re: GDPR: Don't Panic

#720
post #53

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

>there's a whole two hundred post debate around here whether ip are or aren't pii on their own. Largely pointless. EU courts have in the past ruled that IPs are personal data because they can be tracked back to a person. End of story. >there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). was largely already covered by the previ…

> Largely pointless. EU courts have in the past ruled that IPs are personal data because they can be tracked back to a person. End of story.

They are wrong. IPs are not personal data. End of story.

Post reply on HN