Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

81–90 of 833 posts

Re: GDPR: Don't Panic

#81

Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).

There is no "TLDR" of the GDPR. It has to all be read, understood and complied with. This is basic legal compliance, and is not at all easy for a small business.

It's especially hard for a small sized business where all your clients are either departments of the government or leasing companies.

Re: GDPR: Don't Panic

#82

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

> you also need a privacy policy if you are receiving phone calls. did you know that?

You mean your website needs to have a note next to your phone number saying something like "we will not record your phone calls", and if there isn't, you're liable to be fined?

Re: GDPR: Don't Panic

#83
post #47

I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…

Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…

You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!

Re: GDPR: Don't Panic

#84
The GDPR hysteria demonstrates that:

1. Many people (even "rational hacker-types" ha-ha!) do not take the time to research, analyze or understand the regulations and laws that affect them.

2. Many people, even though they don't understand said regulations, will have an extreme negative reaction to the new regulation especially when they see big scary numbers like numbers like "$20M Euro". This is true even of regulations like the GDPR which most anybody should be able to read and understand in a couple of hours.

3. Many people don't understand where regulations come from or how they work. They have no understanding of scope, process, judegement criteria or enforcement vectors. This leads to terrifying visions of "EU cops" waiting at airports to arrest people the moment they get off the plane.

Frankly, the whole situation speaks to the profound ignorance and fear that lies at the heart of the modern nation state. Citizens do not understand the government, they have no understanding of how or why it does what it does, all they really understand is that the government can and will completely ruin them should they violate one the tens of thousands of laws and rules and regulations and decrees that modern governments impose on their domains.

This ignorance has real consequences and costs. You can see this now particularly in Britain where many people are now learning how their country actually works after voting to tear down their current regulatory and economic framework. But you can also see it in all the fear and the moaning and the teeth gnashing every time some new regulation is proposed. (The funny thing here is that even the most hardcore libertarian economists are coming to understand that regulation does not impede economic growth [1]. Indeed there's ample evidence that regulation, by imposing best practices on firms and increasing trust within the market, is a significant driver of economic growth.)

The reason I point this out on HN is because I think, at the end of the day, being an entrepreneur or an investor is all about learning how the world really works and then changing the world to work for you. And while most people can perhaps afford to plod along with all sorts of misguided notions about how the world works because their jobs do not require them to have any real understanding of the big picture, entrepeneurs and investors absolutely cannot. Buffet says it best: "Risk is not knowing what you're doing." The sites shutting down in the face of the GDPR out of fear and ignorance are making the most basic mistake, they literally do not know what they're doing.

[1] https://marginalrevolution.com/marginalrevolution/2018/02/fe...

Re: GDPR: Don't Panic

#85
> • The GDPR will enable anybody to be able to sue me, even from abroad

> The GDPR does not have this effect, but you may be interested to know that anybody can sue you or your business for whatever reason strikes their fancy. This is a direct consequence of doing business and has nothing to do with a particular law. What the GDPR allows private individuals to do is to contact their regulators and to complain if you decide to ignore their requests.

That's not exactly correct. Art. 79 of the GDPR allows people to sue directly for violations of GDPR although it's very non-specific.

Re: GDPR: Don't Panic

#86

Earlier quoted context omitted.

On what experiences with EU bureaucracy do you base your statement?

on what experience about gdpr case law is the linked article basing his statement? all those claims about warning shots and leniency and goodwill of the regulator are completely unfounded. the linked article makes the claim, the linked article should substantiate the claims, and we maintain a healthy right to remain skeptical of those claims until some meat is added to them.

The DPA (Datatilsynet) in Denmark operates in the exact way stated in the article. I've fairly sure it's the same in Sweden, Germany, UK, and most of the EU. It is in stark contrast to the US.

I'm not going to link cases, because they're in Danish. They are available from their webpage, and the most resent ones are linked on the frontpage. The last few cases large companies was not in compliance and the didn't get a fine, but they are expected to address the issues, and if they don't then they will get a fine.

Re: GDPR: Don't Panic

#87

Earlier quoted context omitted.

On what experiences with EU bureaucracy do you base your statement?

Stop spamming every single comment on this thread. Your question is irrelevant and misdirected - I've literally started my argument by saying that "there's currently no case law surrounding GDPR".

Your argument is that there is no case law so you get to claim whatever imaginary consequence you want. That’s fine but then other people may debate your conclusions.

You’re also claiming people are rightfully concerned. Where is that right coming from? From past experience? Or is they just baseless concerns?

Re: GDPR: Don't Panic

#88

Is the system of warnings and increasing fines described in the post a part of the law, or does one need to rely on the "spirit of the good natured enforcers" if they are unable (or unwilling) to immediately comply fully?

It is, but in a vague way, see article 83[0], where to choose what fine to apply you must consider, amongst other things:

(f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement

If an authority did not go this way any fine could be voided by an appeal.

[0] http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...

Re: GDPR: Don't Panic

#89

I'm not sure about the point regarding the DPD. EU Directives themselves don't have teeth, but they're supposed to be transposed into national laws - e.g. the DPA in the UK - and would be enforced nationally. A regulation comes into law across the EU, but is still often transposed, and the enforcement mechanism (to begin with) is still basically the same. He's right that the DPD was not well-adhered to, though.

The problem with the laws stemming from the DPD was that there were different laws in each EU country, and the enforcement options were too weak for slippery international corporations. One critical change in the GDPR is the mandatory reporting of significant breaches. Before, it was entirely optional, so reports could come out years after the even once the material surfaced online.

Sure, it wasn't consistent, but the argument about lack of enforcement really comes down to the national regulators not taking their jobs seriously enough or being given sufficient resources. The ICO in the UK has only ever issued pretty small beer fines.

The problem with self-regulation in this area is that there is significant competitive advantage to be gained by not being particularly careful. In that sense, I think GDPR evens the playing field.

Re: GDPR: Don't Panic

#90
post #60

I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…

I think this is a very distinct difference between the EU with the scaremongering removed, and e.g. the US: My experience of the EU has been that they've consistently looked out for my interests. Even in the face of the local government (I live in the UK) that have kept fighting for positions I find abhorrent (e.g. UK governments keep complaining about having to abide by EU human rights regulations for example). Yes,…

You are transposing your like of certain EU institutions (human rights regulations) and grafting them onto this legislation. This isn't how it works, not least because there has been no case-law yet, so we have no idea how it will be interpreted. Therefore a legal compliance unit has no choice but to follow GDPR the letter, which is hugely difficult and bureaucratic. The notion that they are "good-natured" is meaningless in a legal sense.

It seems many commentators here are confusing criticism of the GDPR with criticism of the EU itself. Surely people are sophisticated enough to understand that they are 2 hugely different things, and that a robust criticism of regulations and laws are part of a healthy democratic society.

Post reply on HN