Live data from Hacker News

GDPR Feels Useless

medium.com

1–10 of 35 posts

Re: GDPR Feels Useless

#2
>This is so broad and vague that basically if I generate a random number to identify you on my website it becomes your personal data.

That's cool. If something can identify me uniquely then it's personal data.

Re: GDPR Feels Useless

#3
GDPR is a fundamental step towards controls of data as a basic human right. It does not define clicking on banners or cookie disclaimers. He's mad that the world hasn't already matured their adherence and that's reasonable but don't throw the baby out with the bathwater.

GDPR is a great step towards empowering consumers. Give the industry and regulators more than 1 year to change it's behaviors and set new standards.

Re: GDPR Feels Useless

#4
Don't read this. There's so much misunderstanding in this article, I'd be surprised if any good discussion came from it. And refuting it would take ages.

For example:

> And apparently typing your name, age and other information is not consent. How is this supposed to work by the way? I give you my name but I don’t consent to you using it or remember it?

The way it's phrased is misleading. If you need the data and are going to use it in the obvious way, e.g. for shipping a parcel to my address, legitimate interests works fine. If you're a scumbag marketer or data broker/reseller (etc), then yeah, it's going to impact you. That was the idea.

So instead of bikeshedding arbitrary scenarios, let's do something more productive with our day.

Re: GDPR Feels Useless

#5
I don't view GDPR to be quite as useless as the author does, but the point about the user having to protect their data themselves is spot on. GDPR only protects you against good actors that are under EU jurisdiction. Everyone else could very well be doing whatever they want with the data you leak. The EU can't fine a Chinese company if the Chinese company has no presence in the EU.

Another thing the author doesn't mention is that GDPR sets a minimum amount of cost/effort to run a website that's way beyond the actual hardware cost and the cost of making the website itself. It requires every website operator to be familiar with how GDPR works, because you need to know whether you're collecting personal data (you probably are) and how you need to handle it. Furthermore, if you are collecting personal data then you must respond to emails of users who request to know what data you know about them within a set amount of time. In the case of a small website, such as a forum or blog, I would consider the cost imposed by GDPR to be greater than the cost of making the website itself and renting hardware to run it. I think it disproportionately impacts smaller sites. It essentially leads to small sites simply breaking the law and hoping that nobody complains about them.

Re: GDPR Feels Useless

#7
post #2

>This is so broad and vague that basically if I generate a random number to identify you on my website it becomes your personal data. That's cool. If something can identify me uniquely then it's personal data.

Totally agree! Especially, if you keep the link between the number and user, which is very often the case. But even without that direct link one would have to demonstrate a certain level of k-anonymity. Maybe GDPR wasn't detailed enough to describe k-anonymity

Re: GDPR Feels Useless

#8
post #6

All I see is a lot of websites with a cookie notice that I agree to.

maybe ... just a thought .. but, don't agree to them?

it should be just as easy to agree as to decline. if not, then they are likely not adhering to the regulation, and eventually someone will/could alert them or whatever authority.

Re: GDPR Feels Useless

#9
post #8
post #6

All I see is a lot of websites with a cookie notice that I agree to.

maybe ... just a thought .. but, don't agree to them? it should be just as easy to agree as to decline. if not, then they are likely not adhering to the regulation, and eventually someone will/could alert them or whatever authority.

Do you mean that if I declined I should still be able to see the content?

Re: GDPR Feels Useless

#10

Don't read this. There's so much misunderstanding in this article, I'd be surprised if any good discussion came from it. And refuting it would take ages. For example: > And apparently typing your name, age and other information is not consent. How is this supposed to work by the way? I give you my name but I don’t consent to you using it or remember it? The way it's phrased is misleading. If you need the data and are…

Couldn't agree with you more. Just another Medium post, presented as factual news, steadily leading me to just... Never read posts from Medium.
Post reply on HN