Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

741–750 of 833 posts

Re: GDPR: Don't Panic

#741
post #693

Earlier quoted context omitted.

To be honest I know nothing about law enforcement in the EU, but the one thing I have heard about in recent memory is that guy who made a video of his girlfriend's dog saluting hitler, and was subsequently tried for a hate crime, convicted, and was charged with a pretty hefty 800 GBP fine after being found in violation of the Communications Act of 2003[1]. Seems like a pretty poor example of principles-based regulati…

The actual ruling was that him saying 'Gas the Jews' tens of times during the video was calculated to offend, rather than the dog thing

Oh okay, I actually misremembered what I had seen, I thought it was just the saluting thing. I just checked the original again[1], and that being said I still don't see how this isn't a ruling that is overblown; he's saying "wanna gas the jews" in a playful way to his dog over and over, and the dog responds when this is said.

The ruling was that this was a hate crime, because it was "menacing, anti-Semitic and racist". I have trouble seeing how a Nazi pug that responds to "gas the jews" is anything other than silly bit of absurd comedy. I can't realistically see this video actually advancing any legitimate hatred, or having any negative consequences other than some people laughing at how silly it is, and some people just thinking it's kind of stupid.

[1] https://www.youtube.com/watch?v=5rdWlVyN9es

Re: GDPR: Don't Panic

#742

Earlier quoted context omitted.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and y…

I would argue there are several sections in the GDPR that appear to allow for a 3rd party to request data on behalf of the data subject. For example: A20(2): In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible. A12(3): ... Where the data subject makes…

[deleted]

Re: GDPR: Don't Panic

#743
post #741

Earlier quoted context omitted.

The actual ruling was that him saying 'Gas the Jews' tens of times during the video was calculated to offend, rather than the dog thing

Oh okay, I actually misremembered what I had seen, I thought it was just the saluting thing. I just checked the original again[1], and that being said I still don't see how this isn't a ruling that is overblown; he's saying "wanna gas the jews" in a playful way to his dog over and over, and the dog responds when this is said. The ruling was that this was a hate crime, because it was "menacing, anti-Semitic and racist…

At a guess you didn't have any family and you don't know anybody that has family that ended up in a gas chamber?

Re: GDPR: Don't Panic

#744

Earlier quoted context omitted.

Not necessarily. It might consist of user IDs (integers, UUIDs) or hashed values of something that can be mapped to the user...

User ID's are considered PII though. If it can be mapped to the user, it's by definition identifying information

Identifiers that have no meaning outside of your system are not PII.

Re: GDPR: Don't Panic

#745

Earlier quoted context omitted.

Because those businesses don't employ anyone? I assume you've never had to work a job you don't care for.

Tobacco companies and drug cartels employ plenty of people too, yet I would be happy if all of them went bankrupt. I know, I’m such a horrible person!

Ads != drug cartels.

I don't think you are a horrible person.

Re: GDPR: Don't Panic

#746

Earlier quoted context omitted.

John Doe says company has personal information on him and doesn't want to delete it. Shows email exchange with the company and company is stating they don't have his personal data, so there is nothing to delete. How do they judge the case has a merit? Let's say a group forms on xchan type of site and flood company and "clearing house" with such claims.

Unless Doe can provide any actual reason for believing they have his data, and as long as the data handling process of the company is sound, the regulator will just close the issue. At least that's my experience. Remember that the Data Protection Directive, which already allows citizens to ask companies if they have data on them and to correct incorrect data, has been around from 1995, yet there hasn't been any mobs…

What reason could anyone provide? (even that a company like fb still has your data) Or that a company sold it illegally? Or that random targeted ads you are seeing are the result of data from any particular company?

Re: GDPR: Don't Panic

#747
post #741

Earlier quoted context omitted.

Oh okay, I actually misremembered what I had seen, I thought it was just the saluting thing. I just checked the original again[1], and that being said I still don't see how this isn't a ruling that is overblown; he's saying "wanna gas the jews" in a playful way to his dog over and over, and the dog responds when this is said. The ruling was that this was a hate crime, because it was "menacing, anti-Semitic and racist…

At a guess you didn't have any family and you don't know anybody that has family that ended up in a gas chamber?

I know several people who fit that criterion. I didn't say it wasn't rude, crass, impolite, or ignorant. I said that I don't think it counts as a hate crime, and that it doesn't fit the criterion for "menacing" society. How many people do you think fear for their personal safety because of that pug?

For what it's worth, I grew up in a town that was roughly half jewish, reflected in my circle of friends. When I was younger, extremely crass jokes that made light of historical tragedies were made at everyones expense, including ones that historically affected my family. It was clear that the intent of these was not to instill terror or provoke hatred. It was more of a pissing contest, to see who could say the most absurdly offensive thing.

Were these the types of situations where we should have had more sensitivity to the real weight of these tragedies? Sure.

Were these hate crimes? Absolutely not. When someone commits a hate crime against you, you probably wouldn't regularly invite them over to your house for the next several years...

Re: GDPR: Don't Panic

#748

Earlier quoted context omitted.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and y…

I would argue there are several sections in the GDPR that appear to allow for a 3rd party to request data on behalf of the data subject. For example: A20(2): In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible. A12(3): ... Where the data subject makes…

I don't buy that that allows you to send random requests to parties that you have no way of knowing the requester has a relationship with. That is an unreasonable burden to place on the recipient of such a request. Essentially you will be sending them on a wild goose chase which is against the intent of the law, which is to give people control over their data, not for people to harass random companies, even more so to do this in an automated way.

You can of course go and approach this from a legalistic point of view but that's usually not how things work in the EU, if you are going to split legal hairs to see how you might be able to get away with something then you will be in for a surprise.

But don't take my word for it, feel free to build and launch the service and we'll see if it flies. For $40 I'll pass :)

Re: GDPR: Don't Panic

#749

Earlier quoted context omitted.

(1) the service is not explicitly allowed for because data subjects (and not data processors acting on their behalf) would be the ones to file such requests. (2) you would be filing a lot of requests to companies that have no data in the first place and which you could reasonably have known about had you queried the data subject. I see such a service as acting in bad faith and would file a complaint against you and y…

You could maybe provide your users with a pre-filled request form for various companies they indicate they're a customer of, and have them send them directly. IIRC there are services along those lines for various 'contact your $REPRESENTATIVE' political and activism lines. I vaguely recall something about how the US has specific laws allowing certain requests to be ignored (or maybe even criminalising the sending of)…

That sounds like a much better idea.

> I vaguely recall something about how the US has specific laws allowing certain requests to be ignored (or maybe even criminalising the sending of) generated or form-letters, due apparently to this sort of abuse.

Exactly, and it is abuse. There are so called 'mass letter writers' here in NL that keep on sending FOI requests and other letters to local government effectively DDOSing the services and they too can be - and have been - slapped down.

Re: GDPR: Don't Panic

#750
post #521
post #502

Where is the form on this site that claims to be GDPR compliant to get my IP removed from the server logs?

Keep reading the rest of that paragraph: > Well, this website is fully compliant with the law, so at least in this particular case it seems to work. Why? Because I don’t store any information about you. That’s a conscious choice on my part which I made long before the GDPR was even talked about in public. But if your situation is more complex then you too can be compliant, or at least - and this is key - you could tr…

Ok but we have to trust this person that they don't store IP information. There is no way of knowing for sure. And there is no obvious way to detect a lie on this.
Post reply on HN