Live data from Hacker News

GDPR and Google Analytics

adactio.com

91–100 of 130 posts

Re: GDPR and Google Analytics

#91
post #49
post #36

Earlier quoted context omitted.

Imagine you’re living in a country which allows you to sell drugs freely, then it’s clear that you can sell them in a country where they are banned. I don’t really think this is different regarding privacy. You have to obey to the law where you run your business. It’s up to you wether you change your business or leave the market. Your argument that it’s weird that you have to “adhere to their laws” is a fallacy. Your…

While I agree with most of what you said, where my perspective differs is this - The WWW is called the World Wide Web for a reason. A platform to showcase your service globally, without borders. Suddenly, the EU thinks "Oh, if you have a website that is accessible from the EU, then you need to display X". Sorry, then what was the point of WWW? And more important, why should I update my code? It costs me money and you…

World Wide Web as a borderless, lawless place is only a long gone dream of cyber anarchists of early nineties.

Re: GDPR and Google Analytics

#92
post #17

Earlier quoted context omitted.

Yet it is fundamentally incorrect. I'm not an EU citizen, so I have zero reason to care about their laws. I will simply ignore them, and the EU has no recourse, other than possibly mandating that their ISPs block me or something. Which I also do not care about.

If you want to do business with EU citizens, you have to follow EU law. Before the internet, you had to open a shop here, or send your goods over the border. The only thing that has changed is the fact that you provide a virtual service over the internet.

No, if I want to have a physical presence in the EU I have to follow EU law. But if I'm residing entirely in another country, and EU citizens want to do business with me over the internet, I could care less what EU law says. And no amount of whining on this thread will change the fact that the EU has no leverage over me.

Re: GDPR and Google Analytics

#93
post #86
post #62

Earlier quoted context omitted.

I have no business assets connected to any EU countries, and I don't have any desire to cross any EU borders. So I will continue to enjoy life in my home country and ignore your provincial laws.

So why are you so nervous? Just ban all those 500 millions "provincial" users and feel free to ignore GPDR. It's nothing new that countries extend protection for their citizens and business entities well beyond its borders, for example, US routinely extradites foreign citizens that have nothing to do with USA for DMCA violations, hacking and whatnot.

Nervous? Not at all. My point is, it isn't my responsibility to ban them or take any other action on my end. That's a problem to be resolved between the EU's governments and its citizens.

Re: GDPR and Google Analytics

#94

I got a speeding ticket in Germany last year. I want them to delete my record. I own the data, they just tracked me over-speeding.

And sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping) This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order.…

The GDPR isn't as good as you think it is. It's going to turn into one of those laws where small software startups / or normal small businesses are just going to be in constant violation, because the amount of resources required to do it properly requires a team of 5 or 10 expensive software engineers. It's going to be a great way to nip small companies in the bud and consolidate this kind of stuff into bigger companies.

It gets even worse with it's extraterritoriality, because you can still be under it if your dealing with a person who lies that they are an EU citizen and they are using your service in your own non EU country as a resident of the non EU country. It's like data FATCA.

And there are other loopy catch 22 ambiguities, like if you want to delete someone from your audit log, do you delete their personal info (which is fairly expansive definition under GDPR) from the audit log too? Then how can you show you deleted the person's info if they are also deleted from your audit log?

Read this to see more from the small company side and how much of a mess it is:

https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...

Think of this theoretical situation. If your an EU citizen vacationing in a developing nation who has a medical emergency, could that hospital just decide to reject you because the hassle & cost of dealing with GDPR is too great? Remember, it's a developing nation, they can choose to just refuse service to you.

Kind of like how a lot of americans get rejected by non US banks because dealing with FATCA is just too much of a pain ass today?

Re: GDPR and Google Analytics

#95
There's a ux problem here, because Google needs to be able to determine if it can save the data and the company using google analytics might also have a requirement to notify the user they are saving other types of data.

Too many notices, requests for confirmation will be a problem. So I expect the company should be able to instantiate analytics with a parameter saying that they asked for confirmation and what the response was.

Aside from that I think there might end up being a performance benefit from the GDPR. The difficulty of keeping permissions to track across different adtech providers becomes onerous, and big media companies start throwing out a bunch of them.

Re: GDPR and Google Analytics

#96
post #81
post #74

Earlier quoted context omitted.

Yeah, but what would you do if the EU decides that you cannot sell your product in the EU?

I would continue to do nothing special to support the EU's provincial laws. If EU citizens want to send me money, fine. If the EU decides to block its citizens from doing so, that's also fine. But I will take no actions on my end to implement EU laws, and it's laughable that some people in this thread imagine the EU has the power to coerce me to do so.

Will you be traveling to an EU country at any point in your life? Imagine fines are levied against you or your company and you refuse or ignore them and continue to operate as before. Could cause you trouble at the border

Re: GDPR and Google Analytics

#97
post #84

I got a speeding ticket in Germany last year. I want them to delete my record. I own the data, they just tracked me over-speeding.

Data retention policies in GDPR specifically address the case, if there is a legal reason to keep the data it should take precedence. That's it you can't tell that you wish your 10k euro bank credit to be forgotten. Accounting logs might need to be kept up to seven (in some cases 10) years, so the data related to them should be kept. The data is sort of field based and some might need to be able to be forgotten earli…

So if another country says it's not legal to comply with the GDPR in their country, they get off scot free? :P

Re: GDPR and Google Analytics

#98

Earlier quoted context omitted.

And sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping) This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order.…

The GDPR isn't as good as you think it is. It's going to turn into one of those laws where small software startups / or normal small businesses are just going to be in constant violation, because the amount of resources required to do it properly requires a team of 5 or 10 expensive software engineers. It's going to be a great way to nip small companies in the bud and consolidate this kind of stuff into bigger compan…

You might have noted that I have refrained from giving an opinion on how good or bad I think that the GDPR is. I just pointed out that it does not at all apply to the case that the GP pretended to have a problem with. By all means, there's enough to criticize about the GDPR, but do it with an argument that has merits, but not by attacking a strawman. (Your hypothetical case is a strawman, too, since the hospital doesn’t do business in the EU and is most likely required to keep records by law, which is a specific exemption clause)

Re: GDPR and Google Analytics

#99
post #47

Earlier quoted context omitted.

It might be an unpopular opinion here, but I'm not entirely sure that the GDPR is going to be a good thing. It seems strange to me to have this enforcement of policies from countries that are not my own just because my website is accessible from those countries. I see your point, but a large majority of web sites are extremely misbehaving, since they allow Google (any typically a bunch of other analytics firms) to tr…

Maybe I’m misunderstanding GDPR, can you explain how tracking your users through logs is OK within the GDPR, but Google Analytics isn’t Ok.

IANAL, so this is not legal advise!

First: I think it is ethically better, because you are not giving your user's data to a large company that builds profiles of your users for their own purposes.

Second: if you pass the data to an analytics company, you share responsibility in ensuring that that data is processed according to the GDPR. Article 83 states on imposing/determining fines:

the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them

It is up to you (as the controller) to ensure that you use a data processor that is GDPR-compliant (Article 28):

Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.

(By the way, it seems from the same article that you also need a written contract with the data processor that specifies exactly what data is provided, for which period, etc.)

---

tl;dr: it seems much easier to fulfil the obligations of the GDPR when you do not involve third parties.

Re: GDPR and Google Analytics

#100
post #81
post #74

Earlier quoted context omitted.

Yeah, but what would you do if the EU decides that you cannot sell your product in the EU?

I would continue to do nothing special to support the EU's provincial laws. If EU citizens want to send me money, fine. If the EU decides to block its citizens from doing so, that's also fine. But I will take no actions on my end to implement EU laws, and it's laughable that some people in this thread imagine the EU has the power to coerce me to do so.

Well, if they really really wanted it, they might be able penalize you. How about everytime you travel, make sure the country won't extradite you. How about your employees? Is that risk acceptable and fair to them?

I don't like what is happening here, but when people want a particular outcome strong enough, they tend set aside more principled concerns.

Post reply on HN