Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

801–810 of 833 posts

Re: GDPR: Don't Panic

#801
post #741

Earlier quoted context omitted.

Oh okay, I actually misremembered what I had seen, I thought it was just the saluting thing. I just checked the original again[1], and that being said I still don't see how this isn't a ruling that is overblown; he's saying "wanna gas the jews" in a playful way to his dog over and over, and the dog responds when this is said. The ruling was that this was a hate crime, because it was "menacing, anti-Semitic and racist…

At a guess you didn't have any family and you don't know anybody that has family that ended up in a gas chamber?

I have family that suffered at the hands of communists. Many were deported and exiled, some were sent to gulags. Some of them made it back, some died there, because the conditions in Siberia were horrible. Do you think it would be reasonable to start fining or jailing people who make jokes about "being sent to the gulag"?

I think you're simply appealing to emotion here to justify an unjust ruling and an unjust law.

I think the person you're replying to has a point in saying that some laws in Europe are pretty ridiculous. However, the difference is that that's a local law in the UK and not one that affects the entirety of Europe. Nor is it a widespread law in other European countries.

Re: GDPR: Don't Panic

#802

Earlier quoted context omitted.

What you dub principles-based regulation others call trust-based regulation, or randomly-enforced regulation, or we-know-it-when-we-see-it-based regulation. Some don't appreciate this type of regulation. I think the unfortunate thing is that, when the previous/existing incarnations of these protection laws were/remain unenforced, many assumed it was because of lack of "teeth". But those of us familiar with how these…

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

Principles-based regulation means you're still committing the same number of crimes per day if you somehow anger the wrong people. If the local police don't like you, then principles-based laws can be used to single you out and target only you.

Re: GDPR: Don't Panic

#803

Earlier quoted context omitted.

If I'm going to be fined or penalized for not being compliant then yes, explicit would be nice. Checkboxes sound great.

Fair enough. As an implementer at a company, I can understand that sentiment. But the GDPR isn't for companies, it's for users. Laws and regulations tend to stick around for longer than expected, and they're static. Technology and "cyber criminals" are dynamic. For better or worse, the GDPR acknowledges this. I think that's a testament to the Article 29 Working Party, in a world where most politicians are clueless ab…

> Fair enough. As an implementer at a company, I can understand that sentiment. But the GDPR isn't for companies, it's for users.

You're absolutely right! GDPR is wonderful for users as a ringing and clear statement of human rights.

Unfortunately, it also needs to be for companies because it affects companies just as much as users. I would go so far as to say GDPR rests almost entirely on companies to turn this stirring declaration of human rights into rights said humans can actually make use of. In this regard, it's a collection of opportunities for improvement of awe-inspiring proportions.

You're right. Technologies and threat landscapes change. Regulation needs to acknowledge this or be worse than useless. Yet, perhaps there are ways to deal with this that don't rest largely on handwaving away critical questions of what compliance actually might look like with weasel-words like "reasonable".

Does that seem possible?

Re: GDPR: Don't Panic

#804
post #542

I personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyon…

> For instance, I run a small community website (~30 people). I receive no income, and I know everyone involved You may be able to ignore GDPR compliance in your situation, as per article 2: > This Regulation does not apply to the processing of personal data: [...] by a natural person in the course of a purely personal or household activity; [...] There is some more information in recital 18, that says > This Regulat…

> So if you're not making money, and you're not established as a business you should be okay.

I've got a shared hosting service where I run WordPress for a blog. As such I have no direct control over the web server, nor what my hosting provider might decide to record of information, nor do I have time to audit what WordPress changes for each update.

Since I'm a programmer by trade, and my blog deals with programming, it's reasonable to assume someone might consider my blog "professional or commercial activity". Maybe I'm saved by some hard criteria defining "professional or commercial activity", but to be frank, it's not worth my time going through the entire GDPR to find that out.

As such I'm not going to take the risk of being in violation and will be shutting down my blog. Instead I'll likely be reverting to posting on Google+ or Facebook, if I bother posting more at all.

Re: GDPR: Don't Panic

#805

Earlier quoted context omitted.

You are advertising that your handling of personal data is so haphazard that GDPR compliance would be expensive. You are admitting that you aren't good enough for the EU, and therefore that you aren't very good in general at whatever you do. I expect that, at least in some obviously global markets like most e-commerce, GDPR compliance (as opposed to throwing the towel like you) will be treated like a certification of…

I’m sorry, but this is simply the naive opinion of somebody that has clearly never had to deal with compliance before on a meaningful level. My customers are all happy with my privacy policy, and not a single one outside of the EU has expressed any interest at all in the GDPR. We are actually compliant with a majority of the regulation, however there are some areas where we would have to re-architect to gain full com…

I'm arguing from the point of view of a customer, not "slandering". Customers are going to have a choice between GDPR-compliant companies and USA-only ones and (if they care) they are going to assume the worst about why the GDPR can make a company retreat from the EU market.

As far as the public understands that complying with a new law is expensive, and why GDPR compliance in particular is expensive, it is obviously more expensive for "bad" companies: don't expect the same compassion and tolerance with which other types of customer disappointments (e.g. raising prices) are received. Your competitors who do not retreat from the EU are obviously caring more for customer privacy, and/or better organized, and/or less reliant on excessive data collection. They are not going to be considered stupid because they spend more than they should on doing the right thing.

You admit bad organization ("there are some areas where we would have to re-architect to gain full compliance"): not trying to comply with the GDPR is clearly not a "rather simple business decision", it's a decision to accept failure instead of losing even more money, and you aren't going to look good even if it's the rational choice in your situation.

Re: GDPR: Don't Panic

#806
post #112

> I don’t want to end up being arrested for GDPR violations when I go on a holiday in Europe (yes, I really saw that one) The US did it recently: https://www.theguardian.com/business/2017/dec/06/oliver-schm...

And the OP articles response to this risk was to dismiss it. Great resource.

I'm gonna take the advice of my employers Law department.

Re: GDPR: Don't Panic

#807

Earlier quoted context omitted.

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.

There is a difference between complying with GPDR and caring about privacy. I completely and utterly care about privacy, but things like not tracking IP address and allowing people to request removing them are a bridge to far. I can’t comply with that. I treat my customers important PII (names, addresses, etc) very delicately. But the cost of complying GPDR is too must.

GDPR does allow you to record IP addresses in access logs and whatnot. And I'm not so sure people can actually ask you to remove their IP addresses; they'd have to demonstrate use of that IP over the relevant time interval, which is beyond most people. So I think while GDPR requires you to have a good reason to collect IP addresses, it doesn't meaningfully impose an obligation to be able to expunge them in removal requests.

Re: GDPR: Don't Panic

#808
post #734

Earlier quoted context omitted.

Your response seems to completely ignore what I said, which had nothing to do with data. It's as if you're just making an appeal to emotion. I keep smelling this false dichotomy: either you're complying with the GDPR or you're doing something nefarious. Others may be arguing against the spirit of the law, the extent of the protections, the tradeoffs between data and privacy, or any of those topics actually related to…

> I keep smelling this false dichotomy: either you're complying with the GDPR or you're doing something nefarious. It certainly doesn't appear to be a false dichotomy to me. If your company has a European presence, you will be required to follow the GDPR. But for my purposes, companies that say they will support the GDPR globally will absolutely get my business before those that do not. And there are plenty of areas…

> It certainly doesn't appear to be a false dichotomy to me.

That's the problem. What you seem to be espousing is exactly "my way or the highway" (where "my way" is the GDPR) or "you're either for it or against it", the very epitome of false dichotomy.

Why not actually address the middle ground that has now been clearly explained multiple times? In what way does that non-compliance equate to nefarious conduct?

> And there are plenty of areas where my data is used against me

And here, again, is the appeal to emotion. Where's the data in this case, not those other cases?

Re: GDPR: Don't Panic

#809
post #793

Earlier quoted context omitted.

It is the converse of the second that worries people. Look at an ironically US example of Slingbox forwarding TV antennas to other locations in a 1:1 fashion specifically to not count as rebroadcasting. That took a Supreme Court case and much legal maneuvering to sink something that was legal because they didn't like it. People are rightfully worried about "you followed the law completely but we don't like it so mass…

I don't get it. You make reference to a legal system that precisely defines what is or isn't legal, and then give an example of a company who were legal, but who got prosecuted / sued anyway, and who lost. Law is not just the acts and statutes, it's case law too. We have strong guiding principles in GDPR, and we have mostly clear direction for what is or isn't acceptable. And now we wait for regulation to happen. > s…

>European regulators (at least the ones in the UK) try to avoid fines.

The heart of the issue is that you're talking about trends rather than what's actually written in the law, i.e. legally binding.

Many of us are not comfortable staking our livelihoods on trends.

Re: GDPR: Don't Panic

#810
post #788

Earlier quoted context omitted.

There is nothing that will magically transfer corporate data to the government.

I'm not sure what you mean by this. No magic is required, only sufficient desire by those in power. That wasn't my point, though. It was that now only governments are allowed to gather and keep this data. Granted, the breadth of what's available to them may not be as great if they're mainly recording traffic with no access to corporate servers, but even that access can be periodically arranged given sufficient desire…

> It was that now only governments are allowed to gather and keep this data.

That just isn't true.

Post reply on HN