Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

91–100 of 833 posts

Re: GDPR: Don't Panic

#92
post #37

The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.

Law is by its nature open to interpretation and based on precedent. Otherwise there wouldn't be courts of appeal and supreme courts. What's so special about GDPR that makes you think it will be abused more than other laws?

The "special" part is that it prescribes very specific things in very ambiguous terms.

You have to change what you're doing to be compliant, but you don't know how. And for some aspects, no one knows how.

And GDPR actually has teeth. It's ripe for selective enforcement and other bureaucracy failures.

Re: GDPR: Don't Panic

#93
post #58

There's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.

I guess we should only enact new laws which already have established case law. /s

> "I guess we should only enact new laws which already have established case law. /s"

I disagree with the author's lenient and dismissive take on people's genuine concerns. Interpret it as you will.

Re: GDPR: Don't Panic

#94

> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you k…

> you also need a privacy policy if you are receiving phone calls. did you know that? You mean your website needs to have a note next to your phone number saying something like "we will not record your phone calls", and if there isn't, you're liable to be fined?

that or a mention directly at the start of the conversation.

Re: GDPR: Don't Panic

#95

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

Reminder: you have to legally comply with every letter of the GDPR, not just the TLDR version. Saying "but we implemented the TLDR version" is not a legal defence.

Re: GDPR: Don't Panic

#96
post #80

Earlier quoted context omitted.

The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

Furthermore, it imposes unbelievable costs on companies that in the end must be passed on to consumers. This is completely unnecessary legislation that will probably have no measurable positive effect at all. Bureaucracy and politics at its best.

Re: GDPR: Don't Panic

#97
post #48

This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…

I agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.

If it is difficult and time consuming for you to answer a GDPR request then your data handling practices are bad and you should feel bad.

Re: GDPR: Don't Panic

#98
post #37

The problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.

Law is by its nature open to interpretation and based on precedent. Otherwise there wouldn't be courts of appeal and supreme courts. What's so special about GDPR that makes you think it will be abused more than other laws?

What you're describing is the way common law works. Most European jurisdictions work under a civil law system.

Re: GDPR: Don't Panic

#99
post #78

Earlier quoted context omitted.

If you don't have a talent pool, one should remove all candidate data after rejection. It's probably better to outsource talent pools.

Outsourcing your talent pools - literally the future of your company - would be an extreme step just to ensure GDPR compliance.

Talent pool as a Saas and the company needs to manage GDPR - you still have acces to your data. Still open how you monitor the company as required by GDPR, but at least you can redirect angry candidates.

Re: GDPR: Don't Panic

#100

For those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around th…

The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.
Post reply on HN