Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

721–730 of 833 posts

Re: GDPR: Don't Panic

#721
post #199

Earlier quoted context omitted.

No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person). THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.

And you’re wrong Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo... Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.

No you are wrong. I don’t care what some silly EU court said. IPs are not personal data. They can apply to a range of people.

Re: GDPR: Don't Panic

#722
post #193

Earlier quoted context omitted.

> How do you ask user for a permission Why do you think permission is required?

Because that is personal information that is being stored and processed.

If you're doing lawful processing, you don't need consent.

Have you even read the legal text you are complaining about?

Re: GDPR: Don't Panic

#723
post #521
post #502

Where is the form on this site that claims to be GDPR compliant to get my IP removed from the server logs?

Keep reading the rest of that paragraph: > Well, this website is fully compliant with the law, so at least in this particular case it seems to work. Why? Because I don’t store any information about you. That’s a conscious choice on my part which I made long before the GDPR was even talked about in public. But if your situation is more complex then you too can be compliant, or at least - and this is key - you could tr…

But I should be able to hold on to IP addresses for as long as I want, since they aren’t PII.

Re: GDPR: Don't Panic

#724
post #193

Earlier quoted context omitted.

> How do you ask user for a permission Why do you think permission is required?

Because that is personal information that is being stored and processed.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

https://gdpr-info.eu/art-6-gdpr/

> Processing shall be lawful only if and to the extent that at least one of the following applies:

Consent is one:

> the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

Here are all the others (see especially the last one):

> processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

> processing is necessary for compliance with a legal obligation to which the controller is subject;

> processing is necessary in order to protect the vital interests of the data subject or of another natural person;

> processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

> processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Re: GDPR: Don't Panic

#725
post #556

Earlier quoted context omitted.

> That’s not true, and for many companies this is just a simple business decision. But likely based on incorrect advice. You haven't said why you think your company isn't compliant with GDPR, and it's possible your company is compliant with GDPR, or would require only minor tweaks to privacy policies to make it compliant.

Sounds like he analyzed if very closely, so probably not base on incorrect advice. And I’m guessing he can’t share too much about why since he has said its based on architectural decisions, which might reveal business secrets. The biggest reason I don’t like complying with GDPR is the IP address situation- I’m going to continue to track them and I’m not going delete them because somebody requested.

> I’m not going delete them because somebody requested.

Why do you think you need to delete them when requested to do so? Can you point me to the bit of the regulation that makes you think that's a requirement?

Here's the Right to Erasure: https://gdpr-info.eu/art-17-gdpr/

Which bit do you think applies?

Re: GDPR: Don't Panic

#726

Earlier quoted context omitted.

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.

There is a difference between complying with GPDR and caring about privacy. I completely and utterly care about privacy, but things like not tracking IP address and allowing people to request removing them are a bridge to far. I can’t comply with that. I treat my customers important PII (names, addresses, etc) very delicately. But the cost of complying GPDR is too must.

> I completely and utterly care about privacy

and

> allowing people to request removing them are a bridge to far.

Are dissonant. You will have to pick the one or the other but you can't both care about privacy and not allow people to request removal of their data. That should be fairly obvious.

Re: GDPR: Don't Panic

#727

Earlier quoted context omitted.

> How long is necessary? As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified. > What does limited mean? The same. Long enough to serve its purpose, and no longer (without justifiable exc…

That is silly. IP addresses should not be covered. I should be able to keep IPs for years. They change often anyway. IP addresses being covered is one of my big issues with GDPR.

Then you're going to love HIPAA. That's a US law by the way.

Re: GDPR: Don't Panic

#728

Earlier quoted context omitted.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

In most industries, US consumers spend far more than consumers anywhere else in the world. Not any more. China's citizens spend twice as much on international tourism as US citizens do. The EU has 508 million people. The US has 325 million.

The GDP, the consumer spending market and the consumer spending per household is all higher in the US than the EU. You can cherry pick out a few industries where other countries spend more than the US, but it's still the most valuable market by far in most industries.

Re: GDPR: Don't Panic

#729

Earlier quoted context omitted.

> How long is necessary? As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified. > What does limited mean? The same. Long enough to serve its purpose, and no longer (without justifiable exc…

That is silly. IP addresses should not be covered. I should be able to keep IPs for years. They change often anyway. IP addresses being covered is one of my big issues with GDPR.

what value do you get from keeping them for years? Are you actively analysing and re-analysing them for any particular purpose, or is it more of a 'well, you never know...' sort of deal?

"they change often" is arguably a good reason for not keeping them. What advantage do you get from knowing that 10 years ago $IP was sending you spam if it's been though 20 different re-allocations and tens of thousands of 'actual owners' since then?

Imagine if google or cloudflare were logging every since query to their public DNS and correlating it with other access logs or google analytics or whatever. They'd be able to relatively trivially deanonymise huge numbers of actual people's identities and browsing history (beyond what they can obtain already).

Re: GDPR: Don't Panic

#730
post #626

Earlier quoted context omitted.

> If a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. No, the GDPR is clear that it is applicable if you are offering goods or services to Europeans. The fact you are speaking French in Quebec isn't relevant. > Or what if you fly to speak at a conference in Europe – is that "marketing"…

> the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertaine…

> So you can't just run your business from Canada with no special emphasis on EU and call it a day.

You really can, it says that it may make it apparent.

Does your use of English make it apparent that you are intent on selling to the UK? No. Italian, might I suppose. French wouldn't if you were based in Canada.

Post reply on HN