Earlier quoted context omitted.
And you’re wrong Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo... Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.
No you are wrong. I don’t care what some silly EU court said. IPs are not personal data. They can apply to a range of people.
GDPR: Don't Panic
771–780 of 833 posts
Re: GDPR: Don't Panic
#772Earlier quoted context omitted.
It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.
This is, yet again, untrue. https://gdpr-info.eu/recitals/no-23/ > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, p…
Re: GDPR: Don't Panic
#773Earlier quoted context omitted.
i suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.
Well. I know that I have GTM, GA with DC integration (currently) still active on my blog. DC integration will be dropped and the privacy page will be updated to describe, what I am tracking and how long data is being stored. As needed to comply with GDPR/DSGVO. As I am still having 7 days to go and that is just a personal blog, I plan on using my free time to do that (would just take 3 - 5 minutes to disable everythi…
I thought the GDPR required users to opt-in to tracking (if consent is used as the lawful basis for processing), and if they choose not to opt-in, you must disable the tracking while still providing the service. Are you sure just updating your privacy page is enough?
Then there are the requirements to allow users to download or delete their data.
Re: GDPR: Don't Panic
#774Earlier quoted context omitted.
I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…
This is it. Thank you, I commented about my local experiences with government in Europe and US/Canada but did not know the correct terms and you're right, I think this is the big difference and a driver of fear outside of the EU. In Canada I found the police, by-law enforcers, and almost any official are essentially rules based robots, very much different to my experience in the UK. Thank you for teaching me about ru…
The EU’s digital commissioner said in 2015 that the EU should use regulation to "replace today’s Web search engines, operating systems and social networks" with EU companies.[1]
And they've passed or proposed ridiculous laws like cookie warnings and link taxes. We have reason to be suspicious of their intentions.
1: https://www.wsj.com/articles/eu-digital-chief-urges-regulati...
Re: GDPR: Don't Panic
#775Earlier quoted context omitted.
That, and the fact that a good chunk of present day Europe was under the Soviet boot for 40 odd years and the people there got to see up close how dangerous data is in the wrong hands (in that case: the government).
Unfortunately your reasoning is not correct here. Hungary and Poland were under the Soviet boot, but a generation later they are going back to undemocratic and authoritarian governments. Eastern Germany was under the Soviet boot and they have far more neo-nazism than Western Germany who wasn't. So the 40 years seem to have made some long lasting damage instead of fostering as strong "never again" attitude. On the oth…
Re: GDPR: Don't Panic
#776Earlier quoted context omitted.
That, and the fact that a good chunk of present day Europe was under the Soviet boot for 40 odd years and the people there got to see up close how dangerous data is in the wrong hands (in that case: the government).
In that case and now, in this case, too.. the government will have a legal monopoly on the data.
Re: GDPR: Don't Panic
#777This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…
'Doing business' requires two steps: 1. Invitation to treat: that is offering services for consumption 2. Offer to contract: fulfilling the invitation by making a contract of terms If you drop a potential customer at step 1, e.g. having your web-server decline the connection based on GeoIP, would that not constitute reasonable effort? We don't have case law regarding GDPR yet but I would certainly argue that it shows…
- the IP, under GDPR, is personal data. You need consent or a legitimate interest to process it.
- it is very murky regarding EU persons abroad. So if I operate with a German citizen originating in Hong Kong, I may be subject to the law.
Personally, I think that you'll be fine blocking EU IPs as long as you aren't doing anything more with them, but that doesn't change the philosophical problem.
Someone else, through proactive work on their part, came to my site (say hosted outside of the EU), even though I did not want them to and I am on the hook for a law I had no agency in creating.
Again, largely a thought exercise and not a real problem for real businesses, but it does beg the question...are websites liable for every law in the world? Do we just fall back on the 'well they can't enforce it' model of evaluating website legislation?
Re: GDPR: Don't Panic
#778The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.
It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…
For example, if you're a CDN business, and naturally need to fight DDOS attacks, then storing exact IP addresses for all requests for a few weeks easily falls under "legitimate interest" (GDPR 6.1.f). On the other hand, if you're a political news site, then storing IP addresses and URL for the purpose of determining political preferences of people without their consent is very clearly illegal, taking into account that IP address can often be static and so identify specific person.
Yes, it means that you have some decisions to do yourself, and the regulator might disagree with your decisions, but that's true about pretty much every new law, no?
Re: GDPR: Don't Panic
#779Earlier quoted context omitted.
This is, yet again, untrue. https://gdpr-info.eu/recitals/no-23/ > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, p…
Not sure why downvotes. If you block EU IP, EU resident accessing a website on holiday outside EU will not know that the website is not meant to offer services to EU residents. Solely blocking EU IPs is not sufficient. What would do probably is to have a banner on the website, where user is informed that website doesn't allow EU resident visitors with "Leave" button. Now the problem is if the EU resident confirms tha…
If you block EU IPs but your business is targeting Europeans who are on holiday - well, you probably still don't need to comply with GDPR because you've demonstrated attempts to actively avoid European residents.
The test in GDPR is not "does any European ever use the service?" but "are you targeting them?"
Re: GDPR: Don't Panic
#780https://pawelurbanek.com/gdpr-compliance-blog-rails My take on GDPR compliance from a solo developer perspective without a legal team to back him up.
> IP addresses collected by Google Analytics Why should this be your headache? It's collected by Google, not you.