Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

731–740 of 833 posts

Re: GDPR: Don't Panic

#731

Earlier quoted context omitted.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith? Sounds like a win for the GDPR to me, we know rigid checkbox-ticking is ineffective. Apart from that, NIST 800-53/800-171 are catalogs of "security controls and associated assessment procedures" for "Federal Information Systems and Org…

> So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith?

What if my opinion of what is ethical differs from what regulators decide? Opinions are notoriously inconsistent, subject to bias, and easily used to discriminate.

Re: GDPR: Don't Panic

#732

Earlier quoted context omitted.

I was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full. This seem explicitly allowed for in the law.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and y…

You could maybe provide your users with a pre-filled request form for various companies they indicate they're a customer of, and have them send them directly.

IIRC there are services along those lines for various 'contact your $REPRESENTATIVE' political and activism lines. I vaguely recall something about how the US has specific laws allowing certain requests to be ignored (or maybe even criminalising the sending of) generated or form-letters, due apparently to this sort of abuse.

Can't remember what the exact context was that I saw it, but it might have been FOI or something data- related

Re: GDPR: Don't Panic

#733

Earlier quoted context omitted.

Would such a list not by nature consist of PII?

Not necessarily. It might consist of user IDs (integers, UUIDs) or hashed values of something that can be mapped to the user...

User ID's are considered PII though. If it can be mapped to the user, it's by definition identifying information

Re: GDPR: Don't Panic

#734
post #642

Earlier quoted context omitted.

> However, that’s not how we manage risk. I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph. Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation. Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat exces…

I think the underlying idea here, is that data is "radioactive". Quite a lot of data can be fed into classifier systems to accurately identify people (not just computers), their trends, their shopping habits, and other much more private things. In Europe, because of classification systems surrounding IBM and Nazis, have chosen to be very proactive about the dangers of having too much data. It may be used right now in…

Your response seems to completely ignore what I said, which had nothing to do with data. It's as if you're just making an appeal to emotion.

I keep smelling this false dichotomy: either you're complying with the GDPR or you're doing something nefarious.

Others may be arguing against the spirit of the law, the extent of the protections, the tradeoffs between data and privacy, or any of those topics actually related to data or its storage. I'm not, nor is the GP.

I'm arguing that businesses can make perfectly valid decisions regarding risk with respect to regulation that have little to do with the compliance in spirit.

Re: GDPR: Don't Panic

#735

Earlier quoted context omitted.

I think the underlying idea here, is that data is "radioactive". Quite a lot of data can be fed into classifier systems to accurately identify people (not just computers), their trends, their shopping habits, and other much more private things. In Europe, because of classification systems surrounding IBM and Nazis, have chosen to be very proactive about the dangers of having too much data. It may be used right now in…

That, and the fact that a good chunk of present day Europe was under the Soviet boot for 40 odd years and the people there got to see up close how dangerous data is in the wrong hands (in that case: the government).

In that case and now, in this case, too.. the government will have a legal monopoly on the data.

Re: GDPR: Don't Panic

#736

Earlier quoted context omitted.

Yes, it's being considered.

Do you think companies will/should make explicit the cause of higher/differential pricing? On the one hand, it could anger consumers. On the other hand, it would provide transparency so that consumers would understand where the price increase came from.

Honestly, it's not my call to raise prices or not, but it doesn't seem like they intend to hide it, should it happen.

Re: GDPR: Don't Panic

#737
post #206

Earlier quoted context omitted.

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

Is that a GDPR issue, or a copyright/"release" issue? (note that privacy and GDPR issues apply differently for children) > natural rights to their data which they would otherwise have This is not a thing. Data has traditionally "belonged" to the entity doing the recording of the data.

That's a US-ism. Somewhere between many and most countries have a "natural rights" concept that considers certain creator/subject rights to be inalienable and neither belonging to recorders or permanently assignable to them.

Re: GDPR: Don't Panic

#738
post #712

Earlier quoted context omitted.

It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.

This is, yet again, untrue. https://gdpr-info.eu/recitals/no-23/ > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, p…

No, this is only not targeting people accessing internet using EU IP addresses, it doesn't exclude EU residents.

Re: GDPR: Don't Panic

#739
post #642

Earlier quoted context omitted.

So because you don’t have many in-scope systems, you believe that the cost of compliance is going to be the same for every company in the world? And what did I say that gave the impression that I don’t respect my users or their data? Our application is a financial one, so I’d say it’s reasonable to assume that it ends up with a lot more in-scope PII than yours does. In spirit, we also comply with almost all of the GD…

> However, that’s not how we manage risk. I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph. Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation. Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat exces…

I think you've hit the nail on the head regarding the bias of this particular forum. As a group, it seems obvious that HN would be less risk-sensitive than the average.

For the sake of the topic however, I'd say that in this case the greatest risk is in not pushing to become compliant for the sake of future-proofing against legislation of this type. The mood of consumers and legislators worldwide is becoming increasingly pro-privacy and security.

Essentially, many businesses not looking to adopt GDPR compliant are winning the economic mini-game while getting beaten in the metagame.

Re: GDPR: Don't Panic

#740

Earlier quoted context omitted.

I was thinking a solid new business plan is to register gdpr.me (or whatever) and offer a service. $40, fill out a form, and I will send a GDPR request to every company in the world on your behalf. The data coming back is then offered back to you with the ability to create further requests (deletion for example) selectively or in full. This seem explicitly allowed for in the law.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and y…

I would argue there are several sections in the GDPR that appear to allow for a 3rd party to request data on behalf of the data subject. For example:

A20(2): In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.

A12(3): ... Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.

Even in the case it didn't work out to directly query, as another has suggested, just making it easy to fill out as many forms as possible in an automated fashion has value. Use their email to send from.

Also, how does the data subject or gdpr.me know that your company hasn't hoovered up some PII of the data subject?

I've read it several times and unless more clarity comes down on questions like this I'm quite afraid of abuse. I've read 8% of UK citizens intend to (ab)use GDPR for spiteful reasons.

EDIT:

Ok - I believe this absolutely supports my point, straight from the horse's mouth... This is from WP29-2017-4-data-portability-guidance:

"Data subjects should be enabled to make use of a personal data store, personal information management system (PIMS) or other kinds of trusted third-parties, to hold and store the personal data and grant permission to data controllers to access and process the personal data as required."

This is immediately after saying businesses should create API's to allow data portability and GDPR requests.

Post reply on HN