Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

791–800 of 833 posts

Re: GDPR: Don't Panic

#791
post #641
post #392

Earlier quoted context omitted.

GDPR doesn't apply to personal projects unless those are commercial projects.

Do you have a source for this?

https://gdpr-info.eu/recitals/no-18/

> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.

Re: GDPR: Don't Panic

#792
post #783
post #326

Earlier quoted context omitted.

The document you link to has this interesting statement: > The law protects personal data regardless of the technology used for processing that data – it’s technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). It also doesn’t matter how the data is stored – in an IT system, through video surveill…

I believe the answer is embedded in the quote that you provided. Can you use the net to go back from weights to data? If not, then it's irreversible. On the other hand, as parent noticed, hashing IPs is not effective as it's possible to reverse it (the IP space is small).

> On the other hand, as parent noticed, hashing IPs is not effective as it's possible to reverse it (the IP space is small).

What if you are using IPv6?

Re: GDPR: Don't Panic

#793
post #386

Earlier quoted context omitted.

The "lack of predictability" is a good thing. "You're making efforts to comply with the regulations, but could you have a look at how you're storing this and that?" vs "You're not compliant with the regulation so we have to impose a fine" Are you really saying you'd prefer the second?

It is the converse of the second that worries people. Look at an ironically US example of Slingbox forwarding TV antennas to other locations in a 1:1 fashion specifically to not count as rebroadcasting. That took a Supreme Court case and much legal maneuvering to sink something that was legal because they didn't like it. People are rightfully worried about "you followed the law completely but we don't like it so mass…

I don't get it.

You make reference to a legal system that precisely defines what is or isn't legal, and then give an example of a company who were legal, but who got prosecuted / sued anyway, and who lost.

Law is not just the acts and statutes, it's case law too. We have strong guiding principles in GDPR, and we have mostly clear direction for what is or isn't acceptable. And now we wait for regulation to happen.

> so massive fines!".

No. "We don't like it, so here's a letter telling you what we don't like, with suggestions for current best practice". At that point you either change to come into compliance, or you write back and explain why you think you are in compliance. European regulators (at least the ones in the UK) try to avoid fines. The UK's ICO has never used their maximum fine, and there have been some serious data breaches in the UK.

Re: GDPR: Don't Panic

#794
Hi thanks for his very interesting,

What I think is a big problem this stuff about requiring consent. This is a big issue at the moment for website owners and app developers who have on line advertising from vendors such as Google (Admob/Adsense) and use e.g. Google Analytics for development support. These guys do not record individual user details and have no interest in doing so.

Specifically for such people there is an issue where personalised advertising (according to to Google and others) needs an opt in, fine but for app developers and web site owners they don't have any user details other that maybe ip address so if they put up a pop-up and record consent how do they know who the user is if they don’t have any other users info.

This is leading to absurd discussions re for example Google Analytics used by millions of websites and apps. There is something called client id which GA uses to identify unique "users” or website visitors. Now apparently as it is unique this is personal data so should require consent according to some experts I have read. But as it anonymous how can it be identified who it “is”. If a user demands to know what data a website/app has and mentions the client id info well who knows for sure what any client id represents in the real world ?

More to the point what is the likely legal/financial consequence if a user claims that the website id did not ask for consent for this client id to be recorded (how would they be able to prove which one it was that was theirs anyway) ?

Would they be able to sue ? I presume not. So is the IC going to be interested in this apparent breach ? And if the developer/website owner had a data breach where they GA account was compromised would they have to inform all the Client ID individuals ? Again obviously not but you see how these discussions are going !

Re: GDPR: Don't Panic

#795
post #792
post #783

Earlier quoted context omitted.

I believe the answer is embedded in the quote that you provided. Can you use the net to go back from weights to data? If not, then it's irreversible. On the other hand, as parent noticed, hashing IPs is not effective as it's possible to reverse it (the IP space is small).

> On the other hand, as parent noticed, hashing IPs is not effective as it's possible to reverse it (the IP space is small). What if you are using IPv6?

I assume you mean you use only IPv6? Unfortunately I'm away from the real computer but I guess you could run a simulation like that (try to build rainbow table and see how fast it goes).

Re: GDPR: Don't Panic

#796
post #734

Earlier quoted context omitted.

I think the underlying idea here, is that data is "radioactive". Quite a lot of data can be fed into classifier systems to accurately identify people (not just computers), their trends, their shopping habits, and other much more private things. In Europe, because of classification systems surrounding IBM and Nazis, have chosen to be very proactive about the dangers of having too much data. It may be used right now in…

Your response seems to completely ignore what I said, which had nothing to do with data. It's as if you're just making an appeal to emotion. I keep smelling this false dichotomy: either you're complying with the GDPR or you're doing something nefarious. Others may be arguing against the spirit of the law, the extent of the protections, the tradeoffs between data and privacy, or any of those topics actually related to…

> I keep smelling this false dichotomy: either you're complying with the GDPR or you're doing something nefarious.

It certainly doesn't appear to be a false dichotomy to me. If your company has a European presence, you will be required to follow the GDPR. But for my purposes, companies that say they will support the GDPR globally will absolutely get my business before those that do not.

And there are plenty of areas where my data is used against me. Look no further than the recent cell phone location leaks, or facebook, or google.. The time for their siphoning every last shred of data is done.

> I'm arguing that businesses can make perfectly valid decisions regarding risk with respect to regulation that have little to do with the compliance in spirit.

And I, a customer, can make a very easy choice of "If you assert that you follow the GDPR globally, I will buy from you." I think of it like California Emissions, or other 'Better than average certifying bodies'.

Re: GDPR: Don't Panic

#797

Constantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason. It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal infor…

Of course there are 1001 things YOU deem more important. All that says to me is that your interests and priorities are not aligned with how people in the EU want their data handled.

The WHOLE POINT of GDPR is that many companies have continually pushed PII data handling down their list of priorities. As a result, the EU has decided to step in and use a law to bring it back up the list.

Re: GDPR: Don't Panic

#798

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.

And in your mind there is absolutely no possibility that a reasonable explanation would exist why a company would pull out because of it?

How about cost of compliance? For example, just the fact that you need to figure out whether you are compliant or not costs money. If you ask for user consent, then you must be able to later show that you got said consent from the user to work that data. You also have to take into account the risk of fines if something somewhere goes wrong. We, as software developers, should be intimately aware of how things can go wrong despite everyone trying their best.

All of these things cost money. If the cost is greater than what the business from the EU brings in, then it's not worth it. The fact that there are people who immediately and only jump to the thought they don't care about privacy is very worrying.

Re: GDPR: Don't Panic

#799

Earlier quoted context omitted.

We’ve got a great privacy policy, and don’t abuse our customers data in any way. However compliance would be very expensive for us, largely due to some of our early architecture decisions. The liability is also insane, and we don’t want anything to do with it. When we looked at how little our EU customers were worth to us, it was a very easy decision to simply abandon them.

>compliance would be very expensive for us Care to expand on this? What would you need to do that you weren't doing already?

I'm not the person you're asking this from, but any regulation tends to require extra work to be done. Just the fact that you need to know that you're compliant requires work. Then you have requirements such as being able to prove that users gave you this consent, being able to prove that you did delete all the user data in all the possible places (including back ups, VMs, crash dumps on developer machines etc) when requested etc.

You also have to take into account the risk of the fines. The fines are enormous and there are no guarantees that the regulators will not slap you with the highest fines "to make an example of you" or because you just rubbed them the wrong way. Even if you try your hardest to comply and think you have all the bases covered, it could very well be that you are not compliant because something was overlooked or there's a bug somewhere or something else entirely. You can never be certain about this.

Now you add up all of these costs and compare it to how much the EU market offers you. If the costs to comply exceed the income, and there's no near-future opportunities for large growth, then it would make a lot of sense to just pull out of the market.

Re: GDPR: Don't Panic

#800

Earlier quoted context omitted.

Insurance to cover the liability of GDPR fines, massive legal fees, and development time to name a few.

Surely you already had "cyber" coverage on your general liability policy, right, since you are handling users' data? I haven't been notified of any changes in premium for our policy related to the new regulations, fwiw. Massive legal fees for what, exactly?

>I haven't been notified of any changes in premium for our policy related to the new regulations, fwiw.

I don't see how you can legitimately believe that there is not going to be an increase in costs. Either the insurance company was overcharging you before, they're lowering their margins or the price goes up. Anything else would require that the risk would be basically non-existent. The price might not increase right now, but it might increase next year or the year after that or the service might get worse.

>Massive legal fees for what, exactly?

To deal with situations that you didn't expect to happen, but did happen anyway. Even if you try your best, mistakes can happen.

Post reply on HN