Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

811–820 of 833 posts

Re: GDPR: Don't Panic

#811
post #643

Earlier quoted context omitted.

A bunch of companies are going to do this and then regret it when they notice that their competitors really didn't have to do much work to become compliant. Then they'll try to come back... after their EU user-base was kicked out and forced to find alternatives.

That’s assuming that a competitor can make it cost effective. If the original business couldn’t, its unlikely the competitor could. I know in my business I’m shutting off EU sales.

> If the original business couldn’t, its unlikely the competitor could.

Considering amount of FUD spread about fines, even here, with fairly educated readership - I don't think you can really trust other people's cost / benefit analysis, even when they happen to have same variables with same values.

People are often wrong even in much clearer cases . . .

Re: GDPR: Don't Panic

#812

Earlier quoted context omitted.

This is it. Thank you, I commented about my local experiences with government in Europe and US/Canada but did not know the correct terms and you're right, I think this is the big difference and a driver of fear outside of the EU. In Canada I found the police, by-law enforcers, and almost any official are essentially rules based robots, very much different to my experience in the UK. Thank you for teaching me about ru…

Why should we trust the EU? The EU’s digital commissioner said in 2015 that the EU should use regulation to "replace today’s Web search engines, operating systems and social networks" with EU companies.[1] And they've passed or proposed ridiculous laws like cookie warnings and link taxes. We have reason to be suspicious of their intentions. 1: https://www.wsj.com/articles/eu-digital-chief-urges-regulati...

You have to keep in mind that the EU is not as integrated as the US on a political level. You need diplomatic leeway to get everyone to agree to do anything: instead of saying "this is what we'll do", it's "this is more or less what we do, everyone gets to fill in the details on their own". Without that level of flexibility and autonomy for individual countries, they would block the legal process even more than they are now.

As for the link tax: I would blame the publishers pushing for it, not the EU.

Re: GDPR: Don't Panic

#813
post #692

Earlier quoted context omitted.

One could read this as you're being dodgy with your user data. If you were reasonable with the data in the first place, then compliance costs nothing.

That doesn’t compute. There is a difference between what GDPR says is okay with user data and what is actually okay with user data. We may be reasonable with user data, but either disagree with a portion of GDPR (like IP addresses) or do not have the time or money to very we comply.

Still don't understand the issue. IP addresses are being kept private like with all the other user details right? You still can have web logs with ip addresses without needing consent.

And also (as stated in numerous places) that you won't get hit with fines. If you aren't compliant (and it would take a big violation to get their notice) you are given ample time to comply. Or you could in your case if you really are violating it flagrantly then you could just block access to EU. But you would have to a big violater.

So if you look at a prisoners dilemma outline you've got:

- you are violating / you block EU: outcome is no market access to EU - you are violating / you don't block EU: you have access to the market and if you are caught violating you got ample time to change or you can just block EU and you're in the same boat as before - you aren't violating / you block EU: you just blocked access for no reason and losing out on a market - you aren't violating / you don't block EU: You have access to the market

So if you don't know you're violating or you wonder about the IP address and weblogs issue which is minor, then the prisoners dilemma show that best go with continue as normal. There is no case were you would be hit with big fines.

Re: GDPR: Don't Panic

#814

Earlier quoted context omitted.

If you ask US-trained lawyers (especially those with exposure to the tech or financial sectors) to perform an impact assessment of a European regulation, don't be surprised to receive a full-on Chicken Little response. The reality is that the law is not a programming language and compliance is about alignment with principles, not blindly following a set of rules.

Huh? The entire thing is a set of rules that must be blindly followed.

Not exactly in the EU, see the principles vs. rules debate above

Re: GDPR: Don't Panic

#815

Earlier quoted context omitted.

At a guess you didn't have any family and you don't know anybody that has family that ended up in a gas chamber?

I have family that suffered at the hands of communists. Many were deported and exiled, some were sent to gulags. Some of them made it back, some died there, because the conditions in Siberia were horrible. Do you think it would be reasonable to start fining or jailing people who make jokes about "being sent to the gulag"? I think you're simply appealing to emotion here to justify an unjust ruling and an unjust law. I…

Who is talking about jailing, the guy just got a fine. It was pretty big (still less than one paycheck, no?), but if that is the worst case you can find, I think you can make fun of anything.

And fwiw I do think Europe is oversensitive about Nazis-related stuff. But for good reasons.

Re: GDPR: Don't Panic

#816
post #788

Earlier quoted context omitted.

I'm not sure what you mean by this. No magic is required, only sufficient desire by those in power. That wasn't my point, though. It was that now only governments are allowed to gather and keep this data. Granted, the breadth of what's available to them may not be as great if they're mainly recording traffic with no access to corporate servers, but even that access can be periodically arranged given sufficient desire…

> It was that now only governments are allowed to gather and keep this data. That just isn't true.

That's a pretty extraordinary claim, requiring extraordinary evidence.

There have been enough leaks that the public knows even European governments spy on their own citizens.

Re: GDPR: Don't Panic

#817
post #644

Earlier quoted context omitted.

It's a meme passed around the right-o-sphere based on deliberately misreading laws and/or constructing insane scenarios. It has no statistics behind it, just made-up stories.

Remind me to tell Aaron Swartz how abusive & capricious prosecution is just a figment of his imagination...

That's not anywhere close to what we're talking about, and fuck you for making light of his death.

Re: GDPR: Don't Panic

#818

Earlier quoted context omitted.

Yes, but you cannot check whether a person is a resident unless you explicitly ask them. There are no "public" API. It's much easier and safer to just assume someone who's in Europe is a resident, rather than figuring out if they really are. GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU. Say, a EU citizen is on holiday in The U.S. In such case the EU citizen is not protected…

But this is only your assumption and not a fact. Person on holiday is still EU resident and enjoys protection of GDPR. Do you have a source that says that GDPR doesn't apply to IP outside of EU?

It's not by my assumption. I work with GDPR implementations. Read the GDPR yourself if you want a source.

Re: GDPR: Don't Panic

#819
post #359

Earlier quoted context omitted.

Yes, but you cannot check whether a person is a resident unless you explicitly ask them. There are no "public" API. It's much easier and safer to just assume someone who's in Europe is a resident, rather than figuring out if they really are. GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU. Say, a EU citizen is on holiday in The U.S. In such case the EU citizen is not protected…

> GDPR only applies to EU residents, yes, but not if they're on ex. holiday outside of EU. While this is an interesting way to interpret it, it's likely that the law may be clarified in the future to state that if at the time of collecting their data the user is in the EU, the protections shall apply to said data regardless of where the user is now.

That is true, which is why it's really difficult to special case a lot of things related to this, because the behavior could change to match the special cases.

Re: GDPR: Don't Panic

#820

Earlier quoted context omitted.

I do not believe that the vast majority of companies which are significantly impacted by the GPDR were storing data in a reasonable manner, no. Having to spend some effort to make sure you are in compliance with a huge new piece of regulation is expected and I understand that people complain about having to do it. However, after the initial bring-up pains any business which continues to have a problem with the GPDR m…

I do not believe that the vast majority of companies which are significantly impacted by the GPDR were storing data in a reasonable manner, no. If that's your personal belief then obviously you're entitled to your opinion, but have you seen any actual evidence that that is the case? However, after the initial bring-up pains any business which continues to have a problem with the GPDR most likely has a business model…

> If that's your personal belief then obviously you're entitled to your opinion, but have you seen any actual evidence that that is the case?

I can't speak for that other person but I've seen lots of evidence to that effect. I look at ~40 companies / year at the moment and a large percentage of those has issues. Usually not because of malice, mostly because of lack of resources or unfamiliarity with regulations.

Post reply on HN