Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

821–830 of 833 posts

Re: GDPR: Don't Panic

#821

Earlier quoted context omitted.

No. That is just plainly wrong. GDPR allows for tracking without opt in. It just needs to enable you to opt out of being tracked with for example a link to opt out in the privacy policy page. Something I still plan to make more visible (in the footer or something like that), but is already there [0]. These so called cookie layers are not necessary for tracking. They are not even necessary for first party on site adve…

First of all i did not mean to make you change your blog site - I was just pointing out that the law applies to everything no matter how small. Second, are you sure about this? My understanding is that if you use third-party tags such as analytics you need to get consent from users and not to use them if they don't consent. One other thing that is not clear to me is if we need cookie prompts, and how can we implement…

I am sure. At least in Germany the respective privacy protection agencies (federal system so multiple agencies have their say) already stated, the "pure" analytics and "pure" advertising is ok without opt-in, only an opt-out needs to be provided.

If you do linking of such stuff (like Google Analytics with DoubleClick) you need an opt-in. Only then the opt in cookie banner is really necessary.

Please excuse the late answer - was on holiday.

Re: GDPR: Don't Panic

#822
post #803

Earlier quoted context omitted.

Fair enough. As an implementer at a company, I can understand that sentiment. But the GDPR isn't for companies, it's for users. Laws and regulations tend to stick around for longer than expected, and they're static. Technology and "cyber criminals" are dynamic. For better or worse, the GDPR acknowledges this. I think that's a testament to the Article 29 Working Party, in a world where most politicians are clueless ab…

> Fair enough. As an implementer at a company, I can understand that sentiment. But the GDPR isn't for companies, it's for users. You're absolutely right! GDPR is wonderful for users as a ringing and clear statement of human rights. Unfortunately, it also needs to be for companies because it affects companies just as much as users. I would go so far as to say GDPR rests almost entirely on companies to turn this stirr…

GDPR protects nobody's legitimate rights. It only infringes rights of server owners.

Re: GDPR: Don't Panic

#823
post #377

Earlier quoted context omitted.

Under the GDPR, consent must be revokable, at any time, and as easy to withdraw consent as to give it. So you could sign that. Then 5 minutes later withdraw consent. Additionally consent must be "freely given". If you would be punished (e.g. expelled from school) then you haven't given consent, so they can't use it.

"freely given" is not a very clear concept in these circumstances. Parents do not want to antagonise the school and/or put their child at some kind of disadvantage, so they sign. Is that still "freely given"? It looks like GDPR is being used (as an excuse?) to make parents sign things which otherwise they might not. I hear you say that that is not the problem of GDPR and you can withdraw your consent later but how ma…

> Parents do not want to antagonise the school and/or put their child at some kind of disadvantage, so they sign. Is that still "freely given"?

That's a good point, and there might be a court case about that. I agree that the parent probably doesn't have enough free choice. If the law was to say "That isn't freely given", then the school doesn't have consent, so they can't use the images!. That's the beauty of it. It's a different legal viewpoint than "signed contract uber alles". DPA should look at if you had real consent.

> it is clear that this would be viewed as being antagonistic towards the school and its interests.

Good? The whole point of the GDPR & EU data protection law is to push the pendulum the other way, because it's gone too far. If someone can come up and force them to reprint everything, and then someone else force them to reprint everything, well maybe they should collect less personal data? If they didn't collect personal data, they wouldn't have this risk. EU law is trying to discourage massive data collection.

Re: GDPR: Don't Panic

#824

Earlier quoted context omitted.

And rules-based regulation means you commit 3 felonies per day https://www.wsj.com/articles/SB10001424052748704471504574438...

Principles-based regulation means you're still committing the same number of crimes per day if you somehow anger the wrong people. If the local police don't like you, then principles-based laws can be used to single you out and target only you.

They don't need regulation to do that, though

Re: GDPR: Don't Panic

#825

Earlier quoted context omitted.

Going on a bit of a tangent here, I am becoming concerned with how we discuss these things. You're completely either for or against it. And if you're against one way you are automatically for the other. If you think one thing is bad, obviously you need to be corrected that other thing is bad too. And then you'll get extreme examples showing it. Call it whataboutism, appeal to emotion, whatever. Every time these GDPR…

I think this is a situation where it's easy to see the mote in someone else's eye. I tried to provide a summary using the standard terms for both approaches (in practice, making it clear I preferred a principles-based approach); you jumped up to rebut (in practice, by trying to find the most derogatory synonym for "principles-based regulation" and accusing opponents of "frothing at the mouth"). And then both of us ar…

Thank you for bringing this up. I never knew PB law was a thing. I thought it was just poorly written. Being a yank, I just assumed they forgot the corner cases. I am anti authoritarian by nature so I tend to view authorities as Djinn that must be tightly constrained by wording lest they find a way to misbehave. I would have thought PB would have a higher risk of regulatory capture and corruption of regulators than RB. What is a small business owner's recourse if a regulation is being selectively enforced to favor a competitor? To they need to find funds to retain legal representation? What if the competitor is much larger?

Edit: I realized this might sound passive aggressive. I like the idea of human judgement in regulation, but I really want to know what checks are commonly used to account for all actors involved potentially being malicious.

Re: GDPR: Don't Panic

#826
post #542

I personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyon…

> For instance, I run a small community website (~30 people). I receive no income, and I know everyone involved You may be able to ignore GDPR compliance in your situation, as per article 2: > This Regulation does not apply to the processing of personal data: [...] by a natural person in the course of a purely personal or household activity; [...] There is some more information in recital 18, that says > This Regulat…

That's an interesting statute. The problem is it can be interpreted in many ways. Your interpretation is how some may see it, however there are others as well.

For instance:

> by a natural person in the course of a purely personal or household activity

First off, this isn't purely personal nor household activity. I serve others, not myself.

> and thus with no connection to a professional or commercial activity.

If the goal of the community is to help people develop professional skills (writing, for instance), couldn't that have a connection to professional activity? Also, I use this website as an example on my resume to bolster my own professional competence as a coder. That could qualify.

As always, laws are words that generally end up with the best paid lawyer's interpretations winning in court. It's a roll of the dice, that statute is not clear at all.

We're still debating the meaning of nearly all statutes in the US constitution 242 years later. Some in the legal community have declared "consensus" by case law, but even those end up getting changed and overturned all the time.

Re: GDPR: Don't Panic

#827
post #573

Earlier quoted context omitted.

That's a myth, and the article you posted is an op-ed piece with no substance to back up the claim it makes.

The source is the book of that name, written by an US lawyer. There's some discussion and better sources on Google.

Here's a debunking: https://skeptics.stackexchange.com/questions/22530/does-the-...

Re: GDPR: Don't Panic

#828

Earlier quoted context omitted.

Why should we trust the EU? The EU’s digital commissioner said in 2015 that the EU should use regulation to "replace today’s Web search engines, operating systems and social networks" with EU companies.[1] And they've passed or proposed ridiculous laws like cookie warnings and link taxes. We have reason to be suspicious of their intentions. 1: https://www.wsj.com/articles/eu-digital-chief-urges-regulati...

You have to keep in mind that the EU is not as integrated as the US on a political level. You need diplomatic leeway to get everyone to agree to do anything: instead of saying "this is what we'll do", it's "this is more or less what we do, everyone gets to fill in the details on their own". Without that level of flexibility and autonomy for individual countries, they would block the legal process even more than they…

The corpse doesn't care who held the knife.

Re: GDPR: Don't Panic

#829
post #754

Earlier quoted context omitted.

> I said that I don't think it counts as a hate crime That's curious given your background. I know a couple of people that still have the tattoos on their arms and one guy who literally has no family at all and it pains me to see that people think that this is just a matter of bad taste. "Gas the Jews" is not a joke, my sense of humor is pretty broad but it does not stretch that far.

To be clear, I'm not arguing that it wasn't a horrible atrocity that completely destroyed many peoples lives, and and I'm not arguing that the genocide itself was in any way funny . The joke isn't that the event itself is funny, it's the absurdity of context in which the statement is being made that's funny. I can't even count the number of comedy central stand-up specials I've seen that casually make jokes about abs…

Funny simply isn't relevant. If you bludgeon someone to death in a funny way, it's still a crime.

Re: GDPR: Don't Panic

#830

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…

Considering Europe's history of bloody nationalism, and the recent resurgence in that nationalism, as a non-European I don't trust Europe to refrain from using GDPR to persecute non-European companies.
Post reply on HN