Earlier quoted context omitted.
Does the GDPR only apply to those selling personal information?
If your European friend tells you their phone number and you write it down on your refrigerator (or your public blog for that matter), the French government isn’t going to come fine you for violating GDPR.
GDPR fines were meant to rock the data privacy world
81–90 of 99 posts
Re: GDPR fines were meant to rock the data privacy world
#82Earlier quoted context omitted.
If your European friend tells you their phone number and you write it down on your refrigerator (or your public blog for that matter), the French government isn’t going to come fine you for violating GDPR.
Is that what it says , or are you just saying they're not likely to enforce it in that way, and now we have a rarely enforced law that everybody violates and therefore the government can use it as a pretext to undemocratically destroy anybody that government officials don't like?
Re: GDPR fines were meant to rock the data privacy world
#83Earlier quoted context omitted.
> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…
The EU even considers an IP address as personally identifiable information...
Re: GDPR fines were meant to rock the data privacy world
#84Earlier quoted context omitted.
Is that what it says , or are you just saying they're not likely to enforce it in that way, and now we have a rarely enforced law that everybody violates and therefore the government can use it as a pretext to undemocratically destroy anybody that government officials don't like?
Yes, it's what the law says.
Then what does it actually do?
Re: GDPR fines were meant to rock the data privacy world
#85Earlier quoted context omitted.
But that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then the…
they can and they do enforce it. street vendors are much less common in china than they used to be.
Re: GDPR fines were meant to rock the data privacy world
#86Earlier quoted context omitted.
Yes, it's what the law says.
Wait, so you're saying it allows anyone to store and publish the personal information of Europeans? Without doing anything like have some way for people to contact you and request what information you have on them? Then what does it actually do?
Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".
Re: GDPR fines were meant to rock the data privacy world
#87Earlier quoted context omitted.
Wait, so you're saying it allows anyone to store and publish the personal information of Europeans? Without doing anything like have some way for people to contact you and request what information you have on them? Then what does it actually do?
It regulates specific, but broad classes of handling personal data. Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".
As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes.
And then the phone number is not shared with the public, but stored at a secure location (fridge) having organizational (family rules) and technical (locked doors, windows) policies in place to secure the information.
Given the required security level for a __single__ phone number I would say this would be a reasonable level of caution.
Re: GDPR fines were meant to rock the data privacy world
#88Earlier quoted context omitted.
You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email…
> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…
I'm not sure if we have passed the line of too many regulations, but I know it's out there.
Re: GDPR fines were meant to rock the data privacy world
#89https://www.reuters.com/article/us-austrian-post-fine/data-p... Austrian Post sold voter preference data without having the right processes in place and was fined 10% of last years profits. Noyb.eu is also an interesting organization to watch. They are a non profit taking lawsuits against large incumbents with egregious privacy practices with the backing of the GDPR. They triggered the 50 million € Google fine.
Re: GDPR fines were meant to rock the data privacy world
#90The effect that GDPR has as far as I'm concerned as a user is that many or even most sites accessed from EU come with a prominent banner warning about PII data collection for targetted ads, including a large portion of sites linked from HN. Maybe this isn't noticed on the other side of the pond, but it has a very profound effect on my usage, as I'm immediately turned away from such sites. OTOH, platform sites without…
At this point, I might see one or two lines of text for a news article on initial load between their gommy sticky header, a couple of ads, and their "We're using cookies here, if you don't like it, go screw" popup. Of course that's assuming it's not paywalled.
The net effect of the GDPR, from my perspective as a user, has been to make the internet even shittier to use. There's also the developer side that I have to deal with, but to be honest, after an initial flurry a year or so ago, nobody even asks about whether the software we provide is GDPR compliant anymore.