Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

91–99 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#91
post #87
post #86

Earlier quoted context omitted.

It regulates specific, but broad classes of handling personal data. Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".

Which would also likely be perfectly legal under GDPR, assuming the phone number was given freely to you, we can reasonably assume informed consent. As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes. And then the phone number is not shared with the public, but stored at a secure location (fridge)…

> Which would also likely be perfectly legal under GDPR, assuming the phone number was given freely to you, we can reasonably assume informed consent.

So what happens if you got the phone number from your friend's sister? Or off of caller ID?

> As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes.

There are lots of things you can do with a phone number other than phoning someone. There are services that effectively use phone numbers as usernames, you could give it to them to see if your friend is on that service. When your new girlfriend asks who this number on the caller ID is you can tell them who it is (disclosing it to them). You could store it on your computer which gets backed up to some random cloud service in the US. That's all common human behavior.

> And then the phone number is not shared with the public, but stored at a secure location (fridge) having organizational (family rules) and technical (locked doors, windows) policies in place to secure the information.

The scenario is that it's also being posted to a public blog.

> Given the required security level for a __single__ phone number I would say this would be a reasonable level of caution.

Is it more common for a person to know a __single__ phone number, or have an address book full of them?

You're looking for the case where by coincidence it happens to not be a violation. Even if you find it, that doesn't help anything if accidental violations remain widespread.

Re: GDPR fines were meant to rock the data privacy world

#92

Earlier quoted context omitted.

Not really - you need a way to scrub user data on demand from backups and they should also have limited duration.

You do not require a way to “scrub user data on demand from backups”. This is just untrue; please don’t spread it.

What are you talking about? Part of GDPR is deleting personal data on demand.

Re: GDPR fines were meant to rock the data privacy world

#93
post #56

Earlier quoted context omitted.

> 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. Except that foreign companies won't have this same limitation. The end result is…

You're getting downvoted because you're incorrect: it doesn't matter where a company is from, if they're conducting business with people in the EU, they're bound by it. Which is why several non-EU companies have paid fines and plenty are implementing GDPR-based privacy measures (and I speak from experience here).

Foreign companies paid fines because they still wish to operate in the EU. If they were willing to give up on that then they wouldn't have to pay anything. Eg a Chinese company could collect and abuse as much data as they wanted. Once they get caught the EU can levy fines on them, but the company can just choose not to pay, because the EU can't reach into China.

The EU can't force a foreign company to pay, just like China can't force an American company to pay. Or am I mistaken and there's some international agreement that allows the EU to force them to pay up?

Re: GDPR fines were meant to rock the data privacy world

#94
post #37

Earlier quoted context omitted.

> 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. Except that foreign companies won't have this same limitation. The end result is…

I recently did a stint as a contractor at one of Australia's "big 4" banks. I can assure you that they are so active in the privacy space, and foresee more and more GDPR-like regulations, that they've created their own privacy framework based on GDPR plus likely similar frameworks to come in other jurisdictions. It is one of the biggest funded projects in that bank (it helps that Australia recently had a negative spo…

GDPR might apply and the EU can levy fines on foreign companies, but that doesn't mean that a foreign company has to pay like a European one. The EU can't force a Chinese company to pay if they are willing to give up their EU business. That's the problem - you can't enforce it where you have no legal jurisdiction.

Or do I have it wrong and that there is an enforcement mechanism that can make a Chinese company do things the EU says?

Re: GDPR fines were meant to rock the data privacy world

#95

Earlier quoted context omitted.

You do not require a way to “scrub user data on demand from backups”. This is just untrue; please don’t spread it.

What are you talking about? Part of GDPR is deleting personal data on demand.

You have misunderstood the requirements of the GDPR. CNIL, for example, has made it explicitly clear that so long as an effective retention policy is in place then PII does not need to be removed from backups on demand.

Re: GDPR fines were meant to rock the data privacy world

#96

Earlier quoted context omitted.

But that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then the…

But I don’t think McDev above was talking about a software startup in the poorest part of the world. I have implemented GDPR in a small non profit open source SaaS business. A funded startup should have no issue doing the same.

But I wasn't talking about poorest parts of the world either. China is richer than some EU countries, eg Bulgaria.

Re: GDPR fines were meant to rock the data privacy world

#97
post #63
post #55

Earlier quoted context omitted.

> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…

The EU even considers an IP address as personally identifiable information...

If you remove "IP" and it still seems like a bad idea... i just dont understand what your problem is.

Re: GDPR fines were meant to rock the data privacy world

#98
post #39

Earlier quoted context omitted.

Of course not. There is no law requiring cookie notice popups, there never was.

There was before gpdr. I think it’s obsolete now.

No, storing cookies needed to make your site work was always needed.

Sending tracking information to third parties required a notice of some kind, no matter if it was in the form of cookies or some other mechanism.

So, no there was never a EU cookie law, it was just a major FUD operation and a lot of people put up completely unneccessary cookie consent popups without understanding why.

Re: GDPR fines were meant to rock the data privacy world

#99

Earlier quoted context omitted.

What are you talking about? Part of GDPR is deleting personal data on demand.

You have misunderstood the requirements of the GDPR. CNIL, for example, has made it explicitly clear that so long as an effective retention policy is in place then PII does not need to be removed from backups on demand.

If by that you mean backups need to be deleted after a certain period then it's effectively the same thing.
Post reply on HN