Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

81–90 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#81

Earlier quoted context omitted.

Does the GDPR only apply to those selling personal information?

If your European friend tells you their phone number and you write it down on your refrigerator (or your public blog for that matter), the French government isn’t going to come fine you for violating GDPR.

Is that what it says, or are you just saying they're not likely to enforce it in that way, and now we have a rarely enforced law that everybody violates and therefore the government can use it as a pretext to undemocratically destroy anybody that government officials don't like?

Re: GDPR fines were meant to rock the data privacy world

#82

Earlier quoted context omitted.

If your European friend tells you their phone number and you write it down on your refrigerator (or your public blog for that matter), the French government isn’t going to come fine you for violating GDPR.

Is that what it says , or are you just saying they're not likely to enforce it in that way, and now we have a rarely enforced law that everybody violates and therefore the government can use it as a pretext to undemocratically destroy anybody that government officials don't like?

Yes, it's what the law says.

Re: GDPR fines were meant to rock the data privacy world

#83
post #63
post #55

Earlier quoted context omitted.

> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…

The EU even considers an IP address as personally identifiable information...

Of course.

Re: GDPR fines were meant to rock the data privacy world

#84
post #82

Earlier quoted context omitted.

Is that what it says , or are you just saying they're not likely to enforce it in that way, and now we have a rarely enforced law that everybody violates and therefore the government can use it as a pretext to undemocratically destroy anybody that government officials don't like?

Yes, it's what the law says.

Wait, so you're saying it allows anyone to store and publish the personal information of Europeans? Without doing anything like have some way for people to contact you and request what information you have on them?

Then what does it actually do?

Re: GDPR fines were meant to rock the data privacy world

#85
post #53

Earlier quoted context omitted.

But that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then the…

they can and they do enforce it. street vendors are much less common in china than they used to be.

Yes, in now richer cities. But they still thrive in lower gdp cities.

Re: GDPR fines were meant to rock the data privacy world

#86
post #82

Earlier quoted context omitted.

Yes, it's what the law says.

Wait, so you're saying it allows anyone to store and publish the personal information of Europeans? Without doing anything like have some way for people to contact you and request what information you have on them? Then what does it actually do?

It regulates specific, but broad classes of handling personal data.

Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".

Re: GDPR fines were meant to rock the data privacy world

#87
post #86

Earlier quoted context omitted.

Wait, so you're saying it allows anyone to store and publish the personal information of Europeans? Without doing anything like have some way for people to contact you and request what information you have on them? Then what does it actually do?

It regulates specific, but broad classes of handling personal data. Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".

Which would also likely be perfectly legal under GDPR, assuming the phone number was given freely to you, we can reasonably assume informed consent.

As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes.

And then the phone number is not shared with the public, but stored at a secure location (fridge) having organizational (family rules) and technical (locked doors, windows) policies in place to secure the information.

Given the required security level for a __single__ phone number I would say this would be a reasonable level of caution.

Re: GDPR fines were meant to rock the data privacy world

#88
post #55

Earlier quoted context omitted.

You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email…

> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…

I don't want to live in a world where inviting people over for dinner is practically illegal because of food safety regulations. And I don't want to live in a world where I'm not allowed to write down my friends' birthdays and phone numbers.

I'm not sure if we have passed the line of too many regulations, but I know it's out there.

Re: GDPR fines were meant to rock the data privacy world

#89
post #30

https://www.reuters.com/article/us-austrian-post-fine/data-p... Austrian Post sold voter preference data without having the right processes in place and was fined 10% of last years profits. Noyb.eu is also an interesting organization to watch. They are a non profit taking lawsuits against large incumbents with egregious privacy practices with the backing of the GDPR. They triggered the 50 million € Google fine.

Deutsche Wohnen, the much criticized apartment rental company from Berlin just got smacked with a fine of 14 Million EUR for collecting credit rating data after being warned several times.

Re: GDPR fines were meant to rock the data privacy world

#90

The effect that GDPR has as far as I'm concerned as a user is that many or even most sites accessed from EU come with a prominent banner warning about PII data collection for targetted ads, including a large portion of sites linked from HN. Maybe this isn't noticed on the other side of the pond, but it has a very profound effect on my usage, as I'm immediately turned away from such sites. OTOH, platform sites without…

All that I have seen is that now there is one more popup window obscuring the content I'm trying to view, which is especially egregious on mobile.

At this point, I might see one or two lines of text for a news article on initial load between their gommy sticky header, a couple of ads, and their "We're using cookies here, if you don't like it, go screw" popup. Of course that's assuming it's not paywalled.

The net effect of the GDPR, from my perspective as a user, has been to make the internet even shittier to use. There's also the developer side that I have to deal with, but to be honest, after an initial flurry a year or so ago, nobody even asks about whether the software we provide is GDPR compliant anymore.

Post reply on HN