Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

771–780 of 833 posts

Re: GDPR: Don't Panic

#771

Earlier quoted context omitted.

And you’re wrong Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo... Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.

No you are wrong. I don’t care what some silly EU court said. IPs are not personal data. They can apply to a range of people.

I agree ip can address multiple persons. What is common sense matters little. Ip were enshrined in law as personal information and that’s that. It’s stupid, but it’s not something you can just argue away with reason and logic, you have to argue it with lawyers in courts, and given precedents you gonna lose, and that’s what matters.

Re: GDPR: Don't Panic

#772
post #712

Earlier quoted context omitted.

It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.

This is, yet again, untrue. https://gdpr-info.eu/recitals/no-23/ > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, p…

Not sure why downvotes. If you block EU IP, EU resident accessing a website on holiday outside EU will not know that the website is not meant to offer services to EU residents. Solely blocking EU IPs is not sufficient. What would do probably is to have a banner on the website, where user is informed that website doesn't allow EU resident visitors with "Leave" button. Now the problem is if the EU resident confirms that he/she is not an EU resident. Then controller or processor is still processing protected data, but unknowingly.

Re: GDPR: Don't Panic

#773

Earlier quoted context omitted.

i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.

Well. I know that I have GTM, GA with DC integration (currently) still active on my blog. DC integration will be dropped and the privacy page will be updated to describe, what I am tracking and how long data is being stored. As needed to comply with GDPR/DSGVO. As I am still having 7 days to go and that is just a personal blog, I plan on using my free time to do that (would just take 3 - 5 minutes to disable everythi…

> the privacy page will be updated to describe, what I am tracking and how long data is being stored. As needed to comply with GDPR/DSGVO.

I thought the GDPR required users to opt-in to tracking (if consent is used as the lawful basis for processing), and if they choose not to opt-in, you must disable the tracking while still providing the service. Are you sure just updating your privacy page is enough?

Then there are the requirements to allow users to download or delete their data.

Re: GDPR: Don't Panic

#774

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

This is it. Thank you, I commented about my local experiences with government in Europe and US/Canada but did not know the correct terms and you're right, I think this is the big difference and a driver of fear outside of the EU. In Canada I found the police, by-law enforcers, and almost any official are essentially rules based robots, very much different to my experience in the UK. Thank you for teaching me about ru…

Why should we trust the EU?

The EU’s digital commissioner said in 2015 that the EU should use regulation to "replace today’s Web search engines, operating systems and social networks" with EU companies.[1]

And they've passed or proposed ridiculous laws like cookie warnings and link taxes. We have reason to be suspicious of their intentions.

1: https://www.wsj.com/articles/eu-digital-chief-urges-regulati...

Re: GDPR: Don't Panic

#775

Earlier quoted context omitted.

That, and the fact that a good chunk of present day Europe was under the Soviet boot for 40 odd years and the people there got to see up close how dangerous data is in the wrong hands (in that case: the government).

Unfortunately your reasoning is not correct here. Hungary and Poland were under the Soviet boot, but a generation later they are going back to undemocratic and authoritarian governments. Eastern Germany was under the Soviet boot and they have far more neo-nazism than Western Germany who wasn't. So the 40 years seem to have made some long lasting damage instead of fostering as strong "never again" attitude. On the oth…

Countries are made up of individuals and not all individuals have the same mental make-up. Yes, there are quite a few worrisome developments but there still (maybe not much longer) is an institutional memory of these things that is for the moment exerting a positive influence in this particular domain.

Re: GDPR: Don't Panic

#776
post #735

Earlier quoted context omitted.

That, and the fact that a good chunk of present day Europe was under the Soviet boot for 40 odd years and the people there got to see up close how dangerous data is in the wrong hands (in that case: the government).

In that case and now, in this case, too.. the government will have a legal monopoly on the data.

There is nothing that will magically transfer corporate data to the government.

Re: GDPR: Don't Panic

#777

This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…

'Doing business' requires two steps: 1. Invitation to treat: that is offering services for consumption 2. Offer to contract: fulfilling the invitation by making a contract of terms If you drop a potential customer at step 1, e.g. having your web-server decline the connection based on GeoIP, would that not constitute reasonable effort? We don't have case law regarding GDPR yet but I would certainly argue that it shows…

I think it probably would but there are 2 major issues there (under some interpretations):

- the IP, under GDPR, is personal data. You need consent or a legitimate interest to process it.

- it is very murky regarding EU persons abroad. So if I operate with a German citizen originating in Hong Kong, I may be subject to the law.

Personally, I think that you'll be fine blocking EU IPs as long as you aren't doing anything more with them, but that doesn't change the philosophical problem.

Someone else, through proactive work on their part, came to my site (say hosted outside of the EU), even though I did not want them to and I am on the hook for a law I had no agency in creating.

Again, largely a thought exercise and not a real problem for real businesses, but it does beg the question...are websites liable for every law in the world? Do we just fall back on the 'well they can't enforce it' model of evaluating website legislation?

Re: GDPR: Don't Panic

#778

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

GDPR fundamentally cannot tell whether storing of IP addresses is OK - because it's the processing of personal data for a specific purpose that can be lawful or not, and there's infinite number of possible processing purposes.

For example, if you're a CDN business, and naturally need to fight DDOS attacks, then storing exact IP addresses for all requests for a few weeks easily falls under "legitimate interest" (GDPR 6.1.f). On the other hand, if you're a political news site, then storing IP addresses and URL for the purpose of determining political preferences of people without their consent is very clearly illegal, taking into account that IP address can often be static and so identify specific person.

Yes, it means that you have some decisions to do yourself, and the regulator might disagree with your decisions, but that's true about pretty much every new law, no?

Re: GDPR: Don't Panic

#779
post #712

Earlier quoted context omitted.

This is, yet again, untrue. https://gdpr-info.eu/recitals/no-23/ > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, p…

Not sure why downvotes. If you block EU IP, EU resident accessing a website on holiday outside EU will not know that the website is not meant to offer services to EU residents. Solely blocking EU IPs is not sufficient. What would do probably is to have a banner on the website, where user is informed that website doesn't allow EU resident visitors with "Leave" button. Now the problem is if the EU resident confirms tha…

If you block EU IPs but your business is not targeting Europeans who are on holiday you don't need to comply with GDPR.

If you block EU IPs but your business is targeting Europeans who are on holiday - well, you probably still don't need to comply with GDPR because you've demonstrated attempts to actively avoid European residents.

The test in GDPR is not "does any European ever use the service?" but "are you targeting them?"

Re: GDPR: Don't Panic

#780
post #163

https://pawelurbanek.com/gdpr-compliance-blog-rails My take on GDPR compliance from a solo developer perspective without a legal team to back him up.

> IP addresses collected by Google Analytics Why should this be your headache? It's collected by Google, not you.

You are the data controller because you decided that people who visit uour site would also load GA scripts. You decide what is done with their PII. GA is just a data processor.
Post reply on HN