Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

81–90 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#81
post #59

Earlier quoted context omitted.

If you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.

>If you're careful about how you store personal data in the first place Unfortunately this is a really big "if" looking at typical businesses. They have no idea about how compliance should work and they also hire barely qualified people to marketing teams (often interns), who may accidentally add some privacy-breaking stuff. To prevent that they hire an external DPO and then deal with the paperwork for that DPO, who…

Yeah, compliance for people who weren't careful before indeed is harder than for the rest. I think this works as expected?

Consider if wire fraud wasn't illegal before, but next week there is a new law coming into effect that makes it illegal. Of course all the companies who were doing wire fraud since before will struggle to be compliant, some might not even be feasible to run anymore if their core business becomes illegal.

Again, sounds like it works as expected, compliance for organizations who been ignorant for a long time is expected to be more cumbersome.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#82
post #81

Earlier quoted context omitted.

>If you're careful about how you store personal data in the first place Unfortunately this is a really big "if" looking at typical businesses. They have no idea about how compliance should work and they also hire barely qualified people to marketing teams (often interns), who may accidentally add some privacy-breaking stuff. To prevent that they hire an external DPO and then deal with the paperwork for that DPO, who…

Yeah, compliance for people who weren't careful before indeed is harder than for the rest. I think this works as expected? Consider if wire fraud wasn't illegal before, but next week there is a new law coming into effect that makes it illegal. Of course all the companies who were doing wire fraud since before will struggle to be compliant, some might not even be feasible to run anymore if their core business becomes…

I think you did not understand my comment.

1. It is a problem for greenfield projects too. Not everyone has sufficient expertise to be fully compliant from the beginning. The accidental non-compliance is possible and there's usually a cost to prevent it.

2. It may work as expected from EU charter perspective, but current implementation is adding extra to an already high bureaucratic workload. My point is, it can be better than that.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#83
post #27

Earlier quoted context omitted.

> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

I spent months implementing GDPR compliance with a set of EU-based lawyers. Most businesses are not actually GDPR compliant, even to this day. I assume this is a big reason the EU is willing to take another look at what is required for compliance.

From my experience, companies taking months to get GDPR are ones that want to tick the box, but don't want to follow the law, so they have to go through the trouble of justifying gathering unnecessary data for themselves and their 873 trusted partners. They usually end up noncompliant anyway because GDPR is a pretty sensibly written law that you can't just work around with a crappy popup, but enforcement has unfortunately been lacking.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#84

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

The cookie banners aren't worthless. The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). As an EU citizen, I'm not concerned about your need to observe my behaviour or to prevent ad-click fraud. What I care about is websites sharing my navigation histor…

> The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login).

There's quite a lot between "engaged in spyware shit" and "service that the user expects".

For example if I want to add first party analytics to my site, the data from which I will use solely internally to try to figure out what pages people like and which they do not like, it is not "spyware shit" if I explain what I'll be using the data for and get permission from the user--and getting that permission needs a cookie banner.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#85
post #54

I think the title is clickbait'y. The EU proposes to simplify the law rather than abolish it, which makes sense to me.

And in the world of bureaucracy, "simplification" doesn't mean what you'd think it should mean. "Simplification" consists in adding exceptions, which are in effect additional rules and special cases. Simplification actually means everything gets more complex.

Not necessarily.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#86
post #84

Earlier quoted context omitted.

The cookie banners aren't worthless. The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). As an EU citizen, I'm not concerned about your need to observe my behaviour or to prevent ad-click fraud. What I care about is websites sharing my navigation histor…

> The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). There's quite a lot between "engaged in spyware shit" and "service that the user expects". For example if I want to add first party analytics to my site, the data from which I will use solely interna…

Are cookie banners really a requirement in that case? I think as long as you don’t share the data with a third party you’re in the clear?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#87
post #67
post #60

Earlier quoted context omitted.

No. The reason it exists is businesses get guidance from legislators and existing case law on what prevents you from running a foul of GDPR and the cookie banner is what we ended up with. If those banners did nothing, companies wouldn't include them. They are there as the lowest effort legal defense.

Again, the cookie banners have nothing to do with GDPR, where are people getting this misinformation from?! Was there a popular article saying we have those cookie banners because of GDPR, or what? The banners are the result of much earlier directives that predate GDPR by a lot...

It's not misinformation. Yes ePrivacy predates GDPR but it had no teeth. The reason your replies are full of people saying, "Our lawyers told us to implement it for GDPR" is because it was a minimal thing you could do to meet GDPRs emphasis of receiving consent from users for data stored in cookies. Basically the fear of fines from not being GDPR compliant forced companies add them.

I agree with you these cookie banners are not sufficient by the text, but in practice unless EU commission and courts make lawyers believe these banners are worthless, EU legal teams will still recommend them.

> What these two lines are stating is that cookies, insofar as they are used to identify users, qualify as personal data and are therefore subject to the GDPR.

https://gdpr.eu/cookies/

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#88
post #81

Earlier quoted context omitted.

Yeah, compliance for people who weren't careful before indeed is harder than for the rest. I think this works as expected? Consider if wire fraud wasn't illegal before, but next week there is a new law coming into effect that makes it illegal. Of course all the companies who were doing wire fraud since before will struggle to be compliant, some might not even be feasible to run anymore if their core business becomes…

I think you did not understand my comment. 1. It is a problem for greenfield projects too. Not everyone has sufficient expertise to be fully compliant from the beginning. The accidental non-compliance is possible and there's usually a cost to prevent it. 2. It may work as expected from EU charter perspective, but current implementation is adding extra to an already high bureaucratic workload. My point is, it can be b…

> It is a problem for greenfield projects too. Not everyone has sufficient expertise to be fully compliant from the beginning

Saying it's complicated because of missing experience or knowledge is like saying creating a CRUD application is difficult. Yes, it might be difficult if you've never done it before, but that doesn't mean the thing itself is complicated, just that you potentially lack experience.

Instead, I'd say it would be complicated if it's hard even if you have experience and knowledge about it. And for GDPR and safely storing data, it isn't difficult in a greenfield project if you have experience with it.

> but current implementation is adding extra to an already high bureaucratic workload

As someone who've helped SMEs become GDPR compliant, in terms of engineering, there really isn't a high bureaucratic workload unless you were already very careless with how you stored data. For the ones who considered how personal data was stored for more than half a second, becoming GDPR compliant was mostly about confirming things rather than having to shift things around.

Few companies though, had huge problems as they 1) were revenue dependent on selling user data or 2) never considered how they were storing or protecting personal data at all.

If you're speaking from the experience of those last companies, then again I think it works as expected.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#89
post #86
post #84

Earlier quoted context omitted.

> The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login). There's quite a lot between "engaged in spyware shit" and "service that the user expects". For example if I want to add first party analytics to my site, the data from which I will use solely interna…

Are cookie banners really a requirement in that case? I think as long as you don’t share the data with a third party you’re in the clear?

Matomo for example has an explanation how to gather data without having to display a banner: https://matomo.org/faq/new-to-piwik/how-do-i-use-matomo-anal...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#90

Earlier quoted context omitted.

It's easy as long as you're a corporation. It's onerous for a human person. Like the EU's excellent Digital Markets Act, GDPR should be altered to only apply to corporations. It'd be better if like the DMA it only applied to very large corporations, but just corporations is still way better than the status quo.

It's also easy if you simply stop trying to track users and only store the most necessary data. Like, no one ever seem to consider this. Meanwhile, this same community a few days back were discussing the idea of trying to abolish advertisement. That's truly bluesky thinking if we're still justifying user tracking in 2025.

I only "store" my webserver's logs and user submitted comments. But someone can still put the legal pressure on me, a random person, to force me to do work to turn over those logs/etc. It's wild. Like having a security camera, hosting a BBQ for the neighborhood, and having a neighbor demand access to the recorded video with legal threats. This whole thing really only makes sense in the context of for-profit incorporated persons. It should not apply to me, a random human person.
Post reply on HN