24 ms·
GDPR: Don't Panic
- zaarn 8y ago>Don’t Panic That's thoroughly good advice. Panic reduces efficiency and the capability to react rationally. >Becoming compliant with this law will cause my business to go under >If becoming compliant with the law will cause your business to go under that is more or less the same as saying that your business is built on gross privacy violations. So if that’s your busines model then good riddance to you and your company Hmm, I would nitpick on that, Google Adsense has been ass about getting GDPR compliant, they don't offer any method of serving ads without storing consent including their tracking-free ads. This is not something that affects me personally but I know people running larger websites that rely entirely on ad revenue (premium model is hard since they drive visitors with UGC, most people don't have an account, they don't want to paywall anything or ask money from the people that drive traffic). The site itself is already fully compliant and with exception of very minor changes (minimum age 13 -> 16, adding a "download everything" button) was compliant in the past. I blame Adsense on that one, not GDPR though. The ad industry has to adapt, pushing the work on the website operators won't help and is not appropriate. IMO Adsense should either offer a fully consent-free ad experience in compliance with the GDPR or operate the consent dialog for the website owner in a non-intrusive manner. Maybe this means there will be an opening for a GDPR-compliant adnetwork in Europe
- kimberlychen 8y agoA GDPR-compliant adnetwork would be interesting. It might be a good chance for both sides (platform/website owners and users) to calibrate their perspectives on data privacy and free-platform use.
- maxk42 8y agoHow does this affect people who aren't based in Europe?
- halflings 8y agoI think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).
- tlamponi 8y agoAnd as so often the EU will be the initiator of a world wide adoption of (semi) unified rules, as it was for USB charging, among other things. It will naturally get a lot of flack and a few people/companies will make it their scapegoat as to deflect from them as usual, but that's - sadly - almost normal now. Is it all good: no! Is it a good start: yes! Is it IMPOSSIBLE to comply: heck no, I'm working at a small Austrian company and we had to change almost nothing, as lo and behold, we have no desire to be a data kraken and tried to held the privacy of our customer and users always on a reasonable level. As we'd wish that others do with our data and use of service...
- vidarh 8y agoA few years from now I predict people will deny that the EU had anything to do with instigating this, the way people often insist the manufacturers just suddenly decided USB charging was the way to go and ignore that it first happened after the EU threatened them.
- drstewart 8y agoI'm curious as to how much time you've taken in researching and implementing specific privacy laws of non-EU countries, since you don't seem to find it burdensome to comply with such regulations. Do you know for a fact you're in compliance with South African, Sri Lankan, or Australian privacy laws?
- adventured 8y ago> I think many (most?) companies will implement these privacy policies across all of their users In terms of percentages, exceptionally few businesses outside of the EU will implement GDPR. The rest of the world will overwhelmingly entirely ignore it. There are 20 million businesses in the US. 500,000 new businesses are created each year. 0.1% or less will comply with GDPR. Why? Because very few US businesses ever do business with the EU. A small clothing retail shop from Texas or Florida or Michigan is not going to concern itself with complying with GDPR just because they took three orders from the EU. They're going to ignore GDPR and continue doing business as they always have. And the EU is going to find it entirely impossible to enforce compliance for those types of small instances due to the scale & tracking required to do so. If by chance they develop a larger EU business, then they'll comply. Further, how do you force compliance on a US clothing shop from Florida, that sells 27 items per year into the EU, and violates GDPR (while having zero presence in the EU)? They can't, unless the EU develops a Chinese firewall. The extremely majority of small businesses in India and China also do not do business with the EU. They will not be worried about GDPR. That's true about nearly all the rest of the businesses around the globe.
- raquo 8y agoThe problem of multiple ambiguities in GDPR hasn't really been addressed here. Also, must be nice to live in a country where the regulator is as benevolent and reasonable as is described in this article. I think it's ok for foreigners to be skeptical of this promise, as the article implies that this reasonableness is not encoded in law.
- gcthomas 8y agoThe regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.
- wott 8y ago> The regulators have been running for two decades, Exactly 4 decades in France (it started in 1978).
- repolfx 8y agoBut that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privacy policy. CNIL were happy to be involved and taken so seriously, they were satisfied with the changes and even praised them in private. After the company announced the change, some journalists saw an opportunity to make some noise and did so. CNIL then immediately changed their mind and dished out a fine, despite having previously agreed to it. What a farce. That's at the national level. I can give many examples of cases where the EU has been anything but reasonable. The entire argument Jaques presents here boils down to his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future. As pointed out in the other thread, this belief is itself unreasonable, because the nature of the GDPR means that even in the unlikely even it's true today, if in 10 years a new Commission arrives and changes their mind they can retroactively decide that things previously allowed were actually illegal. The GDPR says virtually nothing about anything so they'd certainly argue such a thing was merely a "clarification" and not a retroactive change to the law. There are plenty of examples of governments doing this sort of thing over time, including the EU, like with Apple's tax situation. Mr Mattheij appears to just write this possibility off entirely.
- merinowool 8y agoThis is just an author wishlist and not the reality. I especially find the "clearing house" fantasy amusing. How he thinks this house of bureaucrats will be able to judge that John Does complaint has any merit?
- deleted 8y ago[deleted]
- orcdork 8y agoI recognized your user name from the other thread (https://news.ycombinator.com/item?id=17095217 https://news.ycombinator.com/item?id=17095217), it looks like you've made up your mind (to the point where your comments where ridiculous enough to be deleted) and no amount of argument will even get you to consider any other options. Why don't you tell us how you really feel?
- zone411 8y agoAnd the author of this article, who was also very active in the same thread hasn't made up his mind?
- merinowool 8y agoI am only trying to understand why people feel so easy about it. I read hundreds of articles on the topic and nobody really has a clue what is going to happen. That my comments were deemed ridiculous and deleted is the symptom how crazy this whole thing is.
- rnnr 8y agoPlus it gives easy access to the government to peek at your data without any significant clause. Your data are theirs too now.
- icebraining 8y agoThat's not how it works. They don't send a guy to look at your databases.
- StreamBright 8y agoExactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).
- merinowool 8y agoIt is easy if they believe particular person's interpretation. But that doesn't mean they are right. People have huge problems with interpreting written word if it is not written without a room for interpretation and if you add to the mix bureaucrats that have targets to meet you'll see it will not be easy at all.
- dtf 8y agoWhat targets? Where have you heard something about targets?
- merinowool 8y agoEvery institutions have targets to prove their existence is of benefit to the tax payer.
- desas 8y agoThat doesn't have to be in money raised, that would be rather unlikely in this case. It could be percentage of problems "fixed" whether that be by sharply worded letter or by court proceedings (the former is far easier and cheaper for the authority), or by the time it takes the authority to investigate a problem.
- merinowool 8y agoYou don't know that, depending how mad is the person in charge. Take into account that it might be good for a couple of years but the power it gives might be tempting to shut down sites that are against EU agenda.
- Malarkey73 8y agoHear hear...
- willvarfar 8y ago> If you’re Mark Zuckerberg however I would definitely advise not to ignore this, however the chances of Mark reading this blog post are nil. As this is top of HN, perhaps there is a good chance he will read this because of the his FB staff who read this and can't resist telling him? :)
- xtrapolate 8y agoThere's currently no case law surrounding GDPR. Moreover, some elements of the GDPR are up for interpretation. People are rightfully concerned. > "This post is an attempt to calm the nerves of those that feel that the(ir) world is about to come to an end" This post is actually a single person's viewpoint, a mere speculation of how things may or may not turn out to be. Your mileage may vary.
- SomeGermanGuy 8y agoOn what experiences with EU bureaucracy do you base your statement?
- xtrapolate 8y agoStop spamming every single comment on this thread. Your question is irrelevant and misdirected - I've literally started my argument by saying that "there's currently no case law surrounding GDPR".
- tinus_hn 8y agoYour argument is that there is no case law so you get to claim whatever imaginary consequence you want. That’s fine but then other people may debate your conclusions. You’re also claiming people are rightfully concerned. Where is that right coming from? From past experience? Or is they just baseless concerns?
- xtrapolate 8y ago> "Your argument is that there is no case law so you get to claim whatever imaginary consequence you want." No, that's not my argument at-all. That's just your personal interpretation of my words. > "You’re also claiming people are rightfully concerned." I'm not "also claiming". That was the sole claim from the very start. > "Where is that right coming from? From past experience? Or is they just baseless concerns?" It's literally in the comment: (1) Some elements of the GDPR are up for interpretation. (2) There's currently no case law surrounding GDPR. If you take both of these facts into account - it is perfectly plausible for people to be concerned, as there's no telling how things will play out in a court of law.
- AnabeeKnox 8y agoI was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" people. This is not how the legal system or legal compliance works.
- SomeGermanGuy 8y agoOn what experiences with EU bureaucracy do you base your statement?
- AnabeeKnox 8y agoOn what experiences with EU bureaucracy do you base your question?
- vidarh 8y agoI don't know about them, but I agree with questioning your original comment, based on 17 years of dealing with data protection issues in the UK and other EU countries.
- LoSboccacc 8y agoso you're just around baiting with the same copy pasted comment?
- AnabeeKnox 8y agoIt's a strategy an EU bureaucrat would be proud of!
- orwin 8y agoDo you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a bad run with them. So if you have contradictory experience, please share them. Until then, i'll still take all this "GDPR will kill tech companies" articles from people who only experienced the US legal system as jokes.
- deleted 8y ago[deleted]
- SomeGermanGuy 8y agoThanks for this article. I wholeheartedly support your stance of: > In that case please shut down or do not serve EU customers
- Malarkey73 8y agoHere in UK I have been receiving about 5-10 emails a day from various companies - most of whom I don't remember - telling me I need to sign up again so they can keep my details and keep spamming me. Fantastic.
- SomeGermanGuy 8y agoI have the same experience. All those forgotten accounts. Now I can just go on and delete them. Super basic stuff.
- vidarh 8y agoI'm loving that too. It's amazing just how many mailing lists I'm on that I either haven't signed up for myself or have forgotten about.
- Malarkey73 8y agoIndeed. I was reading a tragic article about the energy cost of bitcoin and I started to wonder how much energy, bandwidth,HD space is totally wasted on sending everybody spam, junk, messages every day that they will never read. And keeping info for the same. I wonder if it is a reasonably large chunk of the total energy and infrastructure of the whole web? Maybe we could power a big Chinese city just by getting ourselves deleted from gym mailing lists (weirdly a gym in Cardiff sends me spam mail -- I have never been to Cardiff???).
- akerro 8y agoSame here, finally recruitment agencies will unsubscribe me from jobs offers that I'm totally not interested in. I used to get a few emails per week asking me if I'm interested for relocation and work in [insert programming language I have no experience in]. I asked them many times to stop emailing me this crap, they never did until this week :)
- Cakez0r 8y agoI will be interested to see if the same companies do actually stop emailing me and delete my information after I ignore their request to opt in!
- tlrobinson 8y agoIs the system of warnings and increasing fines described in the post a part of the law, or does one need to rely on the "spirit of the good natured enforcers" if they are unable (or unwilling) to immediately comply fully?
- riffraff 8y agoIt is, but in a vague way, see article 83[0], where to choose what fine to apply you must consider, amongst other things: (f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement If an authority did not go this way any fine could be voided by an appeal. [0] http://data.consilium.europa.eu/doc/document/ST-5419-2016-INIT/en/pdf http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...
- LoSboccacc 8y ago> I was actually surprised by how easy it is to read it there's a whole two hundred post debate around here whether ip are or aren't pii on their own, with the wast majority holding the wrong position. there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). you also need a privacy policy if you are receiving phone calls. did you know that? there's a whole bunch of implication on how liable you are about holding unwanted personal information, including unwanted medical personal information i.e. "hi I saw your gazebo renting service, I'm organizing an event but I am unable to walk due a permanent disability and requiring a ramp is present to access your gazebo, is that so?" there is a huge surface area for uncertainty, up and including 'best practices' that are a constantly shifting target. edit: to clarify the calendar part: if you have a meeting with someone, that links an identity with a location. that's why it's an issue, even without considering the address book, which is another issue by itself.
- zaarn 8y ago>there's a whole two hundred post debate around here whether ip are or aren't pii on their own. Largely pointless. EU courts have in the past ruled that IPs are personal data because they can be tracked back to a person. End of story. >there's a whole branch of gdpr that people aren't considering, which is not related to software but to your business (i.e. your mail calendar). was largely already covered by the previous EU privacy law and the german privacy law. Courts largely agree that calendars for appointments are fine as long as you keep them reasonably secure and don't throw them around in public. >you also need a privacy policy if you are receiving phone calls. did you know that? Yes I did. I informed myself when I registered as a small business.
- LoSboccacc 8y ago> Largely pointless. IPs are personal data I know. I'm on that side. Can link you to dozens threads where the comment stating ip are pii are downvoted to hell asunder and false myths spread like wildfire. > Courts largely agree that calendars for appointments are fine yes, but for online calendars the provider is a processor and need to be listed as such. and when a customer exercise the right of being forgotten, you'll need to go back and delete the meetings. all new stuff I'm quite sure the majority forgot to consider. > Yes I did. I informed myself good for you, doesn't mean there are a lot of business that didn't, and considering the false myth spread around here, this board needs to hear as much as possible about these things.
- hitechnomad 8y agoGDPR is just good data protection practice.
- ealexhudson 8y agoI'm not sure about the point regarding the DPD. EU Directives themselves don't have teeth, but they're supposed to be transposed into national laws - e.g. the DPA in the UK - and would be enforced nationally. A regulation comes into law across the EU, but is still often transposed, and the enforcement mechanism (to begin with) is still basically the same. He's right that the DPD was not well-adhered to, though.
- gcthomas 8y agoThe problem with the laws stemming from the DPD was that there were different laws in each EU country, and the enforcement options were too weak for slippery international corporations. One critical change in the GDPR is the mandatory reporting of significant breaches. Before, it was entirely optional, so reports could come out years after the even once the material surfaced online.
- ealexhudson 8y agoSure, it wasn't consistent, but the argument about lack of enforcement really comes down to the national regulators not taking their jobs seriously enough or being given sufficient resources. The ICO in the UK has only ever issued pretty small beer fines. The problem with self-regulation in this area is that there is significant competitive advantage to be gained by not being particularly careful. In that sense, I think GDPR evens the playing field.
- deleted 8y ago[deleted]
- mrleiter 8y agoThe GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.
- zerostar07 8y agoI think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.
- sdoering 8y agoAnd that is a good thing. This >23 different trackers and adservers just to read crappy news content BS is so nice to be shaken. I really love the GDPR for just making the life for such business models way harder. Implementing data, analytics, tracking and stuff in a way that is compliant with GDPR (or its local equivalents) is doable and from an architectural point of view even interesting imho. I love building GDPR conforming data architectures with my clients right now.
- zerostar07 8y agoi suggest you remove the 3 trackers from your blog, or at least let me see it without them. I m not trying to be snarky, just pointing out that removing everything is often very hard.
- def_true_false 8y agoThe site linked in their profile works just fine with all JS disabled.
- 8y ago
- abraae 8y agoThis doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There are also possible business models that might incentivize technology players to deliberately ramp up GDPR requests. For example, unsuccessful candidates applying for a job at a company could forward their rejection email to a bot. The bot parses the details and fires a GDPR access request in to the HR department. The candidate gets back a formatted dump by email of all sorts of recruitment data, including interview notes, etc. There are obvious ways to monetise a service like this, hence incentive for someone to do it. Recruitment at a large company means engaging with thousands of people and then rejecting them. It is natural for people to have bruised feelings, and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc. Naturally GDPR requests like this won't flood a company on the first day of GDPR. But the internet is a turbulent place.
- AnabeeKnox 8y agoI agree, and there seems to be a lack of conversation around this! Next week could be ground-zero for all sorts of unintended consequences. Especially, a flashmob of GDPR requests could sink a company.
- Marazan 8y agoIf it is difficult and time consuming for you to answer a GDPR request then your data handling practices are bad and you should feel bad.
- cbg0 8y agoIt is highly unlikely that a lot of requests will "sink" your company. As per the GDPR, you have a month to respond to requests and you can extend this period by two more months by telling the user that you need more time to process their request. (See article 12 for reference)
- frereubu 8y agoFor those of you understandably intimidated by the GDPR regulations themselves, here's a good summary in plain English: https://blog.varonis.com/gdpr-requirements-list-in-plain-english/ https://blog.varonis.com/gdpr-requirements-list-in-plain-eng... The UK's ICO also has a good structured summary: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/ https://ico.org.uk/for-organisations/guide-to-the-general-da... In general I agree with the sentiments in this article. I've probably spent a total of three to four days reading around the GDPR and I don't really see what's special about this law other than it's imposing decent standards on what was in effect a wildly unregulated industry in people's personal data. If you have a broad distrust of any government activity then I suppose any new laws with "fines up to €X" might feel like "I run a small site on a Digital Ocean droplet and I'm at risk of a €2m fine out of the blue." But that doesn't make it true.
- cbg0 8y agoThat Varonis link gets posted quite a bit, but it drastically over simplifies things and even tries to poke fun at some aspects of the legislation. The ICO site is a much better read for this.
- Sverigevader 8y agoPardon me but, what does ICO site mean in this context?
- tonfa 8y agoThe link to ico.org.uk in the comment above.
- matthewmacleod 8y agoThe Information Comissioner’s Office site, as linked in the grandparent post.
- tomw2005 8y agoInformation Commissioner's Office: https://ico.org.uk/about-the-ico/ https://ico.org.uk/about-the-ico/
- tzahola 8y agoI can't help but love the turmoil GDPR is causing in the adtech "industry". Like wasps buzzing around the exterminator who's about to destroy their nest.
- whataretensors 8y agoWhen people losing their jobs due to government overreach makes you happy, check your motivations.
- tzahola 8y agoLOL! I'll shed many tears for those poor people whose only fault was that they've built a business on unsolicited collection of personal data :'(
- whataretensors 8y agoBecause those businesses don't employ anyone? I assume you've never had to work a job you don't care for.
- tzahola 8y agoTobacco companies and drug cartels employ plenty of people too, yet I would be happy if all of them went bankrupt. I know, I’m such a horrible person!
- whataretensors 8y agoAds != drug cartels. I don't think you are a horrible person.
- seba_dos1 8y agoPeople keeping their jobs is not the most important thing one should strive for with no regards to anything else. Especially not in tech, where it's more than likely that it won't really hurt them.
- peterburkimsher 8y ago> Do you know a good GDPR consultant? >> Yes. > Can you tell me their email address? >> No.
- tinus_hn 8y agoMy DPO didn’t allow me to store that kind of personal information /s
- dnomad 8y agoThe GDPR hysteria demonstrates that: 1. Many people (even "rational hacker-types" ha-ha!) do not take the time to research, analyze or understand the regulations and laws that affect them. 2. Many people, even though they don't understand said regulations, will have an extreme negative reaction to the new regulation especially when they see big scary numbers like numbers like "$20M Euro". This is true even of regulations like the GDPR which most anybody should be able to read and understand in a couple of hours. 3. Many people don't understand where regulations come from or how they work. They have no understanding of scope, process, judegement criteria or enforcement vectors. This leads to terrifying visions of "EU cops" waiting at airports to arrest people the moment they get off the plane. Frankly, the whole situation speaks to the profound ignorance and fear that lies at the heart of the modern nation state. Citizens do not understand the government, they have no understanding of how or why it does what it does, all they really understand is that the government can and will completely ruin them should they violate one the tens of thousands of laws and rules and regulations and decrees that modern governments impose on their domains. This ignorance has real consequences and costs. You can see this now particularly in Britain where many people are now learning how their country actually works after voting to tear down their current regulatory and economic framework. But you can also see it in all the fear and the moaning and the teeth gnashing every time some new regulation is proposed. (The funny thing here is that even the most hardcore libertarian economists are coming to understand that regulation does not impede economic growth [1]. Indeed there's ample evidence that regulation, by imposing best practices on firms and increasing trust within the market, is a significant driver of economic growth.) The reason I point this out on HN is because I think, at the end of the day, being an entrepreneur or an investor is all about learning how the world really works and then changing the world to work for you. And while most people can perhaps afford to plod along with all sorts of misguided notions about how the world works because their jobs do not require them to have any real understanding of the big picture, entrepeneurs and investors absolutely cannot. Buffet says it best: "Risk is not knowing what you're doing." The sites shutting down in the face of the GDPR out of fear and ignorance are making the most basic mistake, they literally do not know what they're doing. [1] https://marginalrevolution.com/marginalrevolution/2018/02/federal-regulation-not-cause-declining-dynamism.html https://marginalrevolution.com/marginalrevolution/2018/02/fe...
- 8y ago
- pilsetnieks 8y ago> • The GDPR will enable anybody to be able to sue me, even from abroad > The GDPR does not have this effect, but you may be interested to know that anybody can sue you or your business for whatever reason strikes their fancy. This is a direct consequence of doing business and has nothing to do with a particular law. What the GDPR allows private individuals to do is to contact their regulators and to complain if you decide to ignore their requests. That's not exactly correct. Art. 79 of the GDPR allows people to sue directly for violations of GDPR although it's very non-specific.
- cbg0 8y agoPeople in Europe are not extremely litigious by nature and will likely resort to calling upon their supervisory authority instead of suing directly. What is however very interesting is article 80, which will allow a data subject to mandate a not-for-profit body to seek judicial or non-judicial remedy on his/her behalf. This will give quite a bit of power to non-profit organisations built for this purpose and will likely add quite a bit of pressure to large companies that don't comply with the law.
- glogla 8y agoThere's no hysteria. There's just FUD disinformation campaign - businesses who make a lot of money thanks to privacy violations are very unhappy with this and they have a lot of voices.
- horseLOGIC 8y agoI'm unhappy with this because now I have to do a lot of extra work verifying that I'm not breaking some law, then implement changes in both code and license agreements, then get all the users to agree. I've had zero profit from user data so far - to the contrary. If everyone could be billed just with some cryptocurrency, totally anonymous, that would be great.
- krageon 8y agoThe only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.
- horseLOGIC 8y agoIt's not inconvenient, it's costing me money. I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer, but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need to pay. I need to set prices to keep my bottom line. If I can't keep my bottom line, I'll eventually stop providing the service, because I'm not providing it for fun. That's for paid services. Now, some companies don't even charge you, they provide (aggregate) data about you to advertisers, who are then willing to pay more for their ads. It only makes sense, how much would you pay for an ad for a piece of specialized software that gets shown to the wrong audience 99.99% of the time? What's going to happen if that kind of data usage becomes infeasible? Those companies need to start charging, or go out of business. There will be less free services. I suppose that helps companies who do charge, but it hurts people who can't pay and don't care about data collection. I'm not providing such a service, but if I was, you would be paying me with your "privacy". If "respecting your privacy" means you don't want to pay, you can get lost, because you're only costing money. The definition of "customer" is that you compensate the other side.
- muro 8y ago> I don’t want to end up being arrested for GDPR violations when I go on a holiday in Europe (yes, I really saw that one) The US did it recently: https://www.theguardian.com/business/2017/dec/06/oliver-schmidt-jailed-volkswagen-emissions-scam-seven-years https://www.theguardian.com/business/2017/dec/06/oliver-schm...
- pjc50 8y agoI got into digital rights when Dmitry Sklyarov was arrested in the US for writing a PDF reader sold from Russia. https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.
- thrillgore 8y agoAnd the OP articles response to this risk was to dismiss it. Great resource. I'm gonna take the advice of my employers Law department.
- Angostura 8y agoI just wanted to register my appreciation for this post, it's a breath of fresh air.
- therealmarv 8y agoThis is no hysteria. Depending on where your company is located the sueing risk is really high. E.g. in countries like Germany there is a whole industry which lives from sueing companies and people and I can imagine that GDPR will open a whole new sueing market there. In other countries like Austria you get first warned and then sued on big GDPR violations which is a much better solution. So it all depends.
- weavie 8y agoAs per the article, GDPR does not enable you to sue the company. > What the GDPR allows private individuals to do is to contact their regulators and to complain if you decide to ignore their requests. The individual will not receive a payout from a GDPR violation.
- sfifs 8y agoNot as per the law. The law explicitly states that option for judicial remedy exists. The article is the opinion of a lawyer based on current practice, but this is not what the law actually says.
- Grollicus 8y agoFrom a German perspective not much has changed: The core concepts "as minimal data collection as possible" & opt-in for more, the right to ask which data a company has about you and the right to make them delete it are established law in Germany since at least 2009 if not 1983.
- deleted 8y ago[deleted]
- jstanley 8y ago> As soon as you do business abroad you will have to comply with the laws of those countries. But are you doing business abroad, just because you're on the internet? Is it not the customer who is coming to you to to do their business abroad, while you do your business in the country you live in?
- adventured 8y agoThe author claims that local law compliance has always been the case. That is in fact incorrect and is a glaring mistake in the article. For the first 20 years of the Web's popular usage globally, you in fact mostly did not have to comply with local laws when it came to commerce online - there were few laws, and most jurisdictions had yet to flesh out how they were going to regulate and apply their laws or not. You simply opened up shop and sold to anyone from anywhere that wanted to buy from you, and you did not need to give a second thought to anything else. Coming next is a global compliance nightmare. If you want to sell globally, you'll have to comply with dozens of unique local approaches. Small businesses won't stand a chance of being able to deal with that. An army of fee charging middle-men will spring up offering solutions, extracting fees accordingly.
- BjoernKW 8y agoThere's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been routinely asked in recent months and there isn't always a clear, dependable answer: - How will I be able to operate my small company website in the future in a legally compliant manner? Some companies even consider shutting down their websites completely and - of all things - only using a Facebook page in the future. Hence, ironically we might very will see GDPR actually benefitting companies like Facebook at the detriment of small companies that consequently won't have complete ownership of their content anymore. - How exactly does a privacy policy have to be worded so I don't get sued on day 1? - In which way will I still be able to store address data for contacting my existing customers? - Will I still be able to use anti-spam and security plugins for my website? These tools might store users' IP addresses, which in some jurisdictions are considered personal data. - Can I still load resources like Google Fonts from CDNs or do I now have to host those myself?
- AstralStorm 8y ago1) Respond to requests about removal of personal data, do not sell data, inform about data leaks and handle them, if outsourcing, check compliance. 2) Any item that is not legal there will be just void in court. You cannot be sued about an invalid legal policy, but only after breaking the law. The policies do not subsume law. About the only thing you need to publish is which data is collected, how it is processed (and by whom if outsourced), for how long (if applicable) and how to remove it. 3) Uh, as usual complying to the law for PII handling? 4) Yes, if they are GDPR compliant. Make sure to put them in you privacy policy. 5) Yes, if the source is GDPR compliant.
- BjoernKW 8y ago1.) That "if outsourcing, check compliance" part isn't trivial, though. Some suppliers still don't provide data processing agreements. For example, as of now it seems like I won't be able to use DocuSign for digitally signing contracts anymore because they seem to not understand what the new laws implies for them and consequently don't provide a DPA. The last time I checked competitors didn't do so either. It's good that companies have to check their processes for privacy compliance but if that disrupts a company's operations with no real remedy other than falling back to paper-based processes that's definitely a problem (admittedly in this case not one that could be solved by legislative bodies) 3.) No, unfortunately it isn't that easy. Some people - lawyers even - argue that merely someone contacting you via email or handing you a business card doesn't necessarily constitute legitimate interest on your part to process their contact data for the purpose of contacting them in the future. I disagree with that opinion but that people are even arguing about this shows that this isn't just business as usual. 5.) You could argue that this has the potential for breaking how the web has worked until now. If you now have to check for legal compliance first each time before merely linking to an external resource (because that might reveal the user's IP address) that simply doesn't scale. Linking to and drawing upon external resources arguably is what makes the web the web.
- michaelsjoeberg 8y ago>Every company and every project or hobby ever has to be compliant with the law. wrong. if everyone always followed the laws, earth would still be considered flat (at least until more recently).
- DanBC 8y ago> and every project or hobby ever But, in particular, that's wrong because personal projects are exempt.
- nextlevelwizard 8y agoIf you stop doing business because of GDPR who the fuck cares? Stop crying and lose business. There are competitors willing to fill the gap (if such ever existed)
- sandrobfc 8y agoWhat really annoys me about GDPR is that, given all the confusion surrounding the law, a lot of GDPR professionals are popping up everywhere. There are a lot of people making money by providing GDPR-compliant-solutions. To avoid this, all that had to be done was to write a clear text with everything everyone had to do to be compliant, instead of pilling up some big and dubious words that no one really knows what they mean. Concerning the law itself, it's a lot of fireworks. Give it a few months and no one will care about it again.
- tobyhinloopen 8y agoGDPR: Don't sell/leak/publish customer data you're fine :)
- lol-lol 8y agoDont panic. Panic when you get something like this. https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis https://www.linkedin.com/pulse/nightmare-letter-subject-acce... Bottom line, DONT store/sell/mangle with personal data of your users unless you are able to fulfill this. I was thinking a bit about having an online store: - make login as it is on Hacker News, you dont need email - once user has selected and payed the goods, request sending address and contact (phone/email/whatever) - ship it, print the requested / store into cold store (it is not that hard, you do it for bitcoins, right?), delete everything except username and password (and maybe the attached goods) from server The described process will pass the GDPR Nightmare Letter in 10 minutes (to write a general reply) that you sent to everyone requesting. This is what traditional "physical" stores do, not the large chains, the traditional, one employee, family store. And it works. For everything else require consent, including tracking, but think very hard if you need anything else as it will complicate your business progressively. I really dont understand all the fuss about the GDPR, if you explain (and prove) this to ICO, I would really like to see who will punish you for that.
- flatfilefan 8y agoThis is actually a great boilerplate for a response. Somebody should create a product that collects this information inside your company and formats it for sending it to any and every GDPR requester. End of story.
- tezza 8y ago> this particular one has the interesting side effect of causing mass hysteria in the otherwise rational tech sector. * Y2K * Dot Com hysteria * Dot Com crash hysteria * AWS outages * Will robots replace us ? * Will Microsoft crush me ? * Will Google crush me ? * I just raised £30M series A, where my Aeron at * Nosql means I can throw away everything I knew about databases * Web first * Mobile first * XML everywhere * OO everywhere * Javascript everywhere * AI everywhere Where is the evidence for rational behaviour ?
- pjc50 8y agoY2K is one rare example where all the panic actually got the problem fixed. The dotcom crash was definitely real with huge job losses too.
- horseLOGIC 8y agoI chuckled at that sentence as well. It's not that the tech sector is rational, it's that a lot of the people working in it are desperate to maintain a self-image of being a rational, scientific-minded person. Then, if some evidence collides with that self-image, we just blame it on management. Problem solved!
- whataretensors 8y ago> in the spirit of the good natured enforcers at the various data protection agencies in Europe Is this serious? Why would we assume enforcers to be good natured if they benefit from fines. Or to assume they would stay good natured, even if you have the most perfect humans there now. It's far more likely that the EU is creating tools to prevent disruption and manipulate markets. The template will likely be followed elsewhere, effectively elevating the state's data collection abilities over all other organizations. Note, Bitcoin does not seem compatible with their laws.
- depr 8y agoYes I'm sure enforcers are looking to fine Bitcoin.
- whataretensors 8y agoI'm not making that argument. It's a reflection of how the law is about expanding government power without considering technology.
- pawurb 8y agohttps://pawelurbanek.com/gdpr-compliance-blog-rails https://pawelurbanek.com/gdpr-compliance-blog-rails My take on GDPR compliance from a solo developer perspective without a legal team to back him up.
- dingo_bat 8y ago> IP addresses collected by Google Analytics Why should this be your headache? It's collected by Google, not you.
- pawurb 8y agoI am afraid it is not so simple. There is a thing with data collector, and data controller in GDPR I don't full understand yet. It's not like you're not responsible for data collected by services that you hook up to your application.
- isbvhodnvemrwvn 8y agoYou are the data controller because you decided that people who visit uour site would also load GA scripts. You decide what is done with their PII. GA is just a data processor.
- TekMol 8y agoThis is how I understand the GDPR: You cannot store a users personal data like IP or cookie id unless you have consent from the user. I expect that nobody will comply with this. Smaller companies seem to think GDPR is something they can fix by changing the legalese in their impressum and privacy policy. "Yet another trip to the impressum generator". Bigger companies seem to pretend they misunderstand the GDPR. I got emails and popups from Facebook, Twitter, Instagram etc informing me about all kinds of nonsense about how they changed their policies and asking me all kinds of unrelated questions about what kind of ads I want to see. Not a single company asked me for permission to store my personal data.
- AstralStorm 8y agoWhy not just not store these things at all? If you have accounts, you get to directly comply anyway. Stop being drunk on cookies. If you're talking about tracking cookies from an ad company, you better mention them in the privacy policy.
- richmarr 8y ago> You cannot store a users personal data like IP or cookie id unless you have consent from the user. This isn't right. Consent is just one of six legal bases through which you can lawfully process data under GDPR. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- pjc50 8y ago> You cannot store a users personal data like IP or cookie id unless you have consent from the user. This isn't true; there's a list of reasons you can keep information and "with consent" is one of them, "legitimate business need" another: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/ https://ico.org.uk/for-organisations/guide-to-the-general-da... But: "However, an individual always has the right to object to processing for the purposes of direct marketing, whatever lawful basis applies." So: you can store IP addresses as part of your information security needs, but not turn round and use them for direct marketing. (I'm not sure if web advertising counts as "direct marketing" here)
- Radim 8y agoClearly an emotional topic. The fact remains, GDPR is a well-meaning but fuzzy law, with implications that cannot be foreseen at this point in time. To remove some of the uncertainty and automate some of the compliance steps, we built a data discovery AI tech that scans corporate data to answer: * "Do we even store personal information?" * "Where do we keep it?" * "How do we make sure PII is consistently stored only in the designated places?" This may seem trivial to a micro-business that runs on a handful of database tables, which I think is where the author is coming from. But for larger companies, even understanding what's where and why (backups? emails? cloud storages?) is a highly non-trivial—if ultimately rewarding—endeavour.
- emiliobumachar 8y agoNice post. Typo: "food safety laws" is listed twice in the bullet points for the lemonade stand.
- jonathanoliver 8y agoI was wondering if that was a joke, for added emphasis, or a mistake.
- jacquesm 8y agoIt was a mistake, thank you both, it has been fixed.
- zitterbewegung 8y agoThanks for this post. I appreciate that you took the time to write this guide.
- dorkusmcgavin 8y agoI personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyone involved. Everyone is in the United States. Is it open to the world? Yes, technically. What happens when an EU resident signs up? Well, I'll continue to do exactly the way things are currently set up. How does this situation play out long term? First, I'll tell whomever contacts me that I am in compliance with US law, and I'm a US citizen. I do not have to follow their laws because it's not within my jurisdiction. Second, they will order me to block EU citizens from my site, which I will not do because it's a mandate of work on me for no reason by a foreign country. So what happens in this situation? The only recourse for the EU is the internet version of "sanctions", to block my website from the EU. Now they've set a really interesting precedent. How do they now enforce these blocks? Technical issues aside, are they going to do a whitelist or a blacklist? Regardless, they are setting up the equivalent of the Great Firewall for the purposes of maintaining the GDPR. So why does this matter? It's only an isolated incident that will likely never occur, right? Wrong. One community website like mine with one EU citizen that decides to file a GDPR complaint means that somehow this situation occurs. It can even be an intentional, "sign up, file complaint" immediately to trigger this legal situation. Think there aren't any foreign governments that wouldn't flood a system like this to censor the EU citizens in various mild ways? Think some random anarchist activist will not decide to monkey with the system by finding and reporting all the small violators? The end product is a curation of the internet for EU citizens by EU government. Hopefully your leaders are benevolent, and nothing crazy happens in the democratic process. I remember being told during the Bush and Obama administrations that my views against government surveillance due to potential for abuse were unjustified because we could never have a horrible president and that our presidents will always be benevolent, so the policy would never change toward the worse. How did that play out? How do people think democracy functions, honestly? Again, I really don't care too much. They can self censor if they want, but it really seems like GDPR is a win for Russian and Chinese meddling.
- frockington 8y ago
- danieltillett 8y agoOne question that I have thought about is how are foreigners supposed to learn about the GDPR's existence? If it wasn't for the fact that I spend more time on HN that I should I would never have heard of it. I doubt there are many businesses here in Australia that know about it.
- PebblesRox 8y agoI first learned about it when I did a google search to figure out why I was getting so many “we’ve changed our privacy policy” emails.
- deleted 8y ago[deleted]
- cbg0 8y agoI've been doing a bit of consulting work on the GDPR and for the most part small sites aren't going to have a lot of headache dealing with the GDPR requirements. Typical, simplified, workflow (varies): 1) Review what data you collect and why 2) Document these in an updated privacy policy along with third parties you share data with and why 3) Update all forms on your site collecting personal information 4) Update your cookie policy and the way you handle cookies, for some of these you might need consent, for some there might be exemptions 5) If you expect this to be an issue, set up automated means of handling requests pertaining to data subject rights, otherwise process them as they come via email While some smaller sites are getting around the need for an EU rep by claiming that they are only processing data occasionally and not on a large scale (whatever that means, as it's not defined by the GDPR) there is a big problem with getting an EU rep, because as opposed to a DPO, which doesn't have liability, your EU representative "should be subject to enforcement proceedings in the event of non-compliance by the controller or processor." making that natural or legal person liable, so you won't be able to easily outsource this. If you have set up shop in the EU, then it's pretty easy to handle the aspect of an EU rep. Also, if you're transferring data between your EU and US offices/datacenters, you can self-certify under the privacy shield, starting from ~$250 per year to not have to deal with binding corporate rules or standard contractual causes, so that you can effectively make these transfers "safe" under the GDPR, along with various technical safeguards, of course.
- tchock23 8y agoPrivacy Shield starts at $500 per year for the smallest company, and that’s before you contract with a mediator (lowest cost there is $50/year if you use the EU options). Unless I’m missing the option for $250/year on their website?
- cbg0 8y agoI was referring to https://www.privacyshield.gov/Program-Overview https://www.privacyshield.gov/Program-Overview where single framework (EU-U.S.) for companies with between $0-$5 million the yearly fee is $250. If you want to add Swiss-U.S. privacy shield as well, then $375 per year for both.
- gregknicholson 8y ago> If becoming compliant with the law will cause your business to go under that is more or less the same as saying that your business is built on gross privacy violations. So if that’s your business model then good riddance to you and your company. Hear hear!
- deleted 8y ago[deleted]
- dingo_bat 8y agoRemember guys, while you are stressing over how to work with GDPR, Facebook literally listed all their existing data collection items and forced everyone to consent. Total increase in privacy: 0
- rsj_hn 8y agoPeople can now remove that consent whenever they want and force their data to be deleted at any time. This is a win. There are other wins, too.
- MatthewWilkes 8y agoMy (EU) clients fall into two camps. Those who haven't had to do a single thing to be GDPR compliant because they were already following the various data protection and privacy laws, and the ones panicking. The latter group say things like "this is ridiculous, they're making us change so much" but never have an answer to the fact that they're already violating PECR or the Data Protection Act.
- zerostar07 8y agoThere is no need for hysteria. On the other hand many people from the EU (me included) will want to keep using HN after May 25.
- nabla9 8y ago> The GDPR will require me to hire people and my entity is too small to be able to afford this Q: Does my business need to appoint a Data Protection Officer (DPO)? A: DPOs must be appointed in the case of: (a) public authorities, (b) organizations that engage in large scale systematic monitoring, or (c) organizations that engage in large scale processing of sensitive personal data (Art. 37). If your organization doesn’t fall into one of these categories, then you do not need to appoint a DPO. source: https://www.eugdpr.org/gdpr-faqs.html https://www.eugdpr.org/gdpr-faqs.html
- zerostar07 8y agoThere is a legitimate question here, where does "large scale" begin? There are a lot of similar questions that nobody can personally guarantee they know the answers for.
- nabla9 8y agoIn the GDPR draft it was "250 employees or with 5000 records." but 5000 records was dropped. Now it says: http://data.consilium.europa.eu/doc/document/ST-5419-2016-INIT/en/pdf http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN... >The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10. Basically small firm that is just holding minimum amount of customer/user information and data and where the business model is not centered around profiling and processing user data.
- cbg0 8y agoThe piece of text you're quoting is referring to obligations of keeping "Records of processing activities", and is not the definition of large scale, which is undefined in the GDPR.
- mingodad 8y agoDo what I say do not do what I do. Today I've been asked by a library of "Junta de Anadalucia - Spain" to accept it's terms and conditions to use the wifi internet connection provided for it's users and it's a clear violation of the GDPR by a government body, basically they're asking for a blank check to do whatever they want without boring to ask/inform the user. Translation by translate.google: ==== The Telecommunications Corporate Network of the Junta de Andalucía reserves the right to monitor and collect information while the user is connected to the Service. This information can be used at the discretion of the Telecommunications Corporate Network of the Junta de Andalucía and can even be shared with the State Security Bodies, their associates or suppliers. Likewise, the Telecommunications Corporate Network of the Junta de Andalucía reserves the right to revise this agreement at any time. The user must accept the General Conditions of Access each time they use the service and, it is your responsibility to review it each time the Service is accessed in case there has been any change. The Telecommunications Corporate Network of the Junta de Andalucía, reserves the right to withdraw the Service, modify the specifications or forms of use thereof, as well as change access codes, users, passwords and other security elements necessary to access the Service . IF YOU DO NOT AGREE TO THESE TERMS, INCLUDING ANY MODIFICATIONS, DO NOT ACCESS OR USE THIS SERVICE. ====
- tincholio 8y agoWell, presumably you can report them to the relevant regulator, then. That's the point of the law.
- LaundroMat 8y agoI applaud the GDPR for automatically unsubscribing me from mailing lists I bothered to take the time to unsubscribe from.
- kasey_junk 8y agoThis article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if some less reasonable entity attempted to regulate in this way?
- drtillberg 8y agoGDPR lacks clear and unambiguous limiting principles and attempts to impose costs--a tax if you will-- on what you know. From a u.s private person perspective, that looks like a significant overreach. Yes, GDPR reigns in a data industry run amok. Great. But GDPR does not clearly stop there, and for the rest of us GDPR seems to hint ominously that if you know anything about anyone, that may be a problem. So overtly cut ties with Europe or forget what you know. Are we to become know-nothings? New-age luddites? Whatever happened to liberty, representation, and the freedom to learn about the world? The commentary largely focuses on online data, ips and such, but GDPR is not limited to such things. This has the flavor of regulation written by foreign bureaucrats in consultation with big business, having little concern for the significant risk of mystifying and annoying literally anyone else in the world. It's a negative development for interconnectivity and international comity.
- pjc50 8y ago> This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. Other countries have already had to deal with the US on this front. If you are a US national you may find it extremely hard to get a bank account in a non-US country, for example; non-US gambling services also have to be very careful about US users (PokerStars et al) https://en.wikipedia.org/wiki/United_States_v._Scheinberg https://en.wikipedia.org/wiki/United_States_v._Scheinberg There are also things like the Magnitsky Act and various other bits of human rights law that allow extremely serious crime and crimes against humanity to be pursued internationally. The one we'll have to watch out for are Chinese censorship laws going global. There's already some weird side effects of "One China".
- weehobbes 8y agoAs a solo business owner based in the US, I’ve been spending the last couple weeks learning about GDPR and getting compliant. While it has not been a fun process, I do think in general the regulation is quite reasonable and overall good for the world in general. So far, GDPR compliance has not cost me any money, only time. There are three problems however that I have with GDPR and I’d love to hear how other small non-EU businesses are dealing with this. First is the requirement to have EU representation (Art. 27). Since I don’t have any physical presence in the EU, GDPR requires the appointment of a representative. It would appear that a new industry has been created selling non-EU businesses GDPR representation in the EU which in my brief Google searching can cost $1000 per year or more. Are other small businesses owner out there paying for this? Or how else to deal with this requirement? Not a lawyer but this is the only part of GDPR I am tempted to ignore. Second is the common practice of using lead magnets to collect emails for marketing. My email signup forms are very clear about marketing use, and are double opt in, and subscribers can opt out with a single click. But my research suggests that this is still not GDPR compliant unless there is an explicit consent, which I believe will reduce email signup rates. Also, while Mailchimp has a GDPR form, but it is quite large and doesn’t work embedded in web page headers, sidebars or popups. I’ve only seen one of these Mailchimp GDPR signups in the wild and they opened a new browser tab to present the hosted Mailchimp GDPR form which to me isn’t ideal. How are others handling email marketing signups? Disclosure and checkbox for consent seems a reasonable compromise but I haven’t seen this very often in the wild, at least not yet, that may change come May 25. Not a lawyer but I’m tempted to keep my current forms until I see more websites make changes. Third, I have a medium sized mailing list (less than 10,000) mostly US based emails which is important for my business. Are people running consent campaigns (as suggested by Mailchimp?) I’m concerned that I will lose a substantial part of my list due to non-response. Again, the list is double opt in and I am very reasonable with my marketing emails. (Not a lawyer) but my thought is to segment my list into EU and non-EU customers and run a consent campaign only on EU emails. Has anyone run a consent campaign and how did it work out for you? Any thoughts or suggestions from other small and solo business owners would be much appreciated.
- ryanwaggoner 8y agoI suspect you’re going to get the predictable response here that you should do the most conservative things possible, and if that tanks your optin rates and email list and ultimately your business, then obviously you’re a filthy scammer and your business deserved to die. The lead magnet thing is such a good example. It’s a clear and voluntary trade-off: you can have this free resource if you join my list, from which you can unsubscribe at any point. It can obviously be done in a scammy way, but you’re clearly not doing that. But some people think you should have to provide that resource without any restriction. Or that forcing people who already opted in to do so again is fair, because if they don’t reconfirm, then they must not have wanted to be on the list. This is like a SaaS company calling every customer periodically to ask them if they might want to cancel. It makes no sense, but the pro-GDPR crowd on HN in particular is very hostile to marketing in general and email marketing in particular. No one here who likes the GDPR gives a shit about your business. They’ll be happy to give you bad advice based on how they wish the world was, and if it costs you dearly, that’s not their problem and you probably deserved it anyway. I’m doing some of the same activities as you, and I personally will be changing basically nothing for GDPR. I’ve always treated customers fairly and I’ll continue to do so. Governments that have no jurisdiction or enforcement mechanisms against my company can pound sand.
- Krisor103 8y agoThe UK ICO will not push to fine if disclosure is provided within 14 days OR there is evidence to show attempts were made to secure data. GDPR should only strike fear if the organisation/individual actively harvested data to sell without a Privacy Policy or market without an opt-out request. The ICO also offers a free advisory service that anyone can petition for help in conforming to GDPR alongside training docs already mentioned in comments.
- raverbashing 8y agoThank you (the author) for this.
- commenterx 8y agoI'm a EU citizen and proud of EU actually, something I don't feel very often btw, for being in the forefront in law-making that protects the privacy of individuals. My vocabulary has been enriched with a new word: PII. I like it. It simplifies when thinking about GDPR. I expect one or two years from now I'll know the important parts of GDPR like the back of my hand. But right now every person in the world running a multinational company needs to understand a new piece of legislature that threatens 4% of their annual revenue. You have better things to do and so I understand everyone's anger. But is it wrong to force business-runners to learn about GDPR, stuff that's pretty close to human rights, like "don't track any of my PII without telling me exactly what you plan to do with it"? Is it wrong to now have to learn this, as a web/app developer? I'm sooooo sick of being tracked. It has definitely made me exit the social media world all together, six months ago. Even though it is detrimental to my career I even asked Linkedin to erase my data. I truly hope my career isn't screwed just because I refused to give Microsoft a detailed description of 30% of my person, my whole work life that they can connect to an email address (some people even give them their phone number), IP, tracking cookie, thus a Facebook profile, real or shadow, thus to the most detailed graph of PII there is, probably in the whole universe. Hopefully in the whole universe otherwise civilizations on other planets took a wrong step somewhere. I hope GDPR leads to PII being treated as gold by the market because it's so rare. Because isnt' it better to skip all this tracking-business that having to deal withstuff like GDPR? No cookies for me please. Ans I'm also sick of having to run javascript.
- ryanwaggoner 8y agoI think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)
- oblio 8y ago> It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Hey, from my viewpoint the rabidly anti-GDPR crowd is from the US :p
- skummetmaelk 8y agoYeah what a surprise? Imagine a global paparazzi law banning photos of celebrities from being published without explicit consent. Celebrities would be happy. Paparazzis and magazine readers not so much.
- frockington 8y agoAmerica innovates, the EU regulates. It's been the story for decades now and there will always be a naturaul tension between innovators and regulators
- krageon 8y agoYes, because being against a law that is both reasonable and the right thing to do doesn't make any sense when you're a real live human being. The hysteria about businesses imploding under legislation is classic internet outrage at a phenomenon not very well understood. If you actually took the time to read the source material, you could very see that it's reasonable and made to protect you. At the same time, you would see that there will not be any world-ending fines handed out for literally no reason (on a slight tangent I don't understand why it is so impossible to grasp that this isn't something that happens in the EU).
- ryanwaggoner 8y agoThis is a law with good intent that was very poorly written and is very ambiguous. Most of the people with your view posting here aren’t experts in this regulation or the law in general, but just armchair lawyers who scanned this regulation and like the intent so they argue that it’s simple. Ironically, if you asked 10 different people with that position about basic facts about this law, you’d all have different answers. Maybe if it’s so simple you could all take a few mins to get your story straight on how it works?
- tannhaeuser 8y agoDoes anybody know if it's required to remove CDN links (such for Google fonts, cdnjs, etc.) and host all assets locally instead unless consent is given? Assets from CDNs are required for a site to function; what's not required is to send `Referer:` so maybe it's sufficient to set a referrer-policy.
- domakidis 8y agoI wonder the same. Would I need the web visitor's consent for loading a reCaptcha to verify they're indeed human? Google fonts is just one of the many font libraries. For example, most web font licenses at myfonts.com don't permit webmasters to self host them. Bypassing the HTTP referer download protection, downloading them and then self hosting the font files could lead to significant legal problems.
- spacenick88 8y agoI don't think it's really that simple. especially the deletion requirements. There are just so many IT systems that really don't support deletion. An absolute worst case I can imagine is GitHub being asked to delete an account which had commits in multiple large projects. Are they going to alter those projects source code?
- madeofpalk 8y agoThis is already a “solved problem” though. If you post copyrighted material to Github, Github will have to remove it. If you’re posting users information to a public repo, then you fully deserve whatever impacts you’ll face when you have to delete it.
- spacenick88 8y agoI'm not talking about copyrighted or otherwise shady stuff pushed to GitHub. My concern is what's supposed to happen when a GitHub user requests GitHub to delete their entire account and all the personally identifying information they have on them. Clearly GDPR calls for this to be possible, yet that would mean that GitHub would have to delete this user's commits (which usually contain full names and mail addresses). Clearly they can't reasonably do that though.
- aeorgnoieang 8y ago> If you’re posting users information to a public repo Like their name and email address in every commit they submit? I've already seen a notice from GitLab requiring me to consent to waive my rights to have that info deleted if, e.g. I were to contribute to the GitLab open source project. But I'm not sure that that's even enough for GDPR.
- jhurewitz 8y agoThe waiver is only one aspect of it. Waiver only applies when consent is required. Article 6 of GDPR also allows for the use of personal information when "processing is necessary for the performance of a contract to which the data subject is party..." Consent is not required when it is a necessary part of performance under a contract. GitLab's updated terms state that as part of the agreement to voluntarily contribute to GitLab projects, contributors acknowledge and agree that their personal information will become part of the repository as part of the Git functionality. Therefore, their personal information will not be deleted and will remain in the repository so as not to impact the code base. This only applies to those who contribute to GitLab projects. This does not apply to general use of the software. There is still much that is unclear regarding GDPR but we are doing our best to comply and protect individuals' privacy. An important function of this waiver and acknowledgement is to provide transparency to our contributors. If an individual does not want their information to be maintained, they have the option not to contribute.
- grigjd3 8y agoWhatever one thinks about the subject matter, the writing in this piece is awful. You can get the substance of what the writer is saying by skipping 90% of the content. Moreover, the tone is talking down at the audience - unless that audience is already excited about gdpr. This comes across as not being interested in convincing anyone but in cheerleading their position.
- eleitl 8y agoIt ain't hysteria if you're in Germany, and a private individual or a nonprofit (e.V.). Due to specialities of German law third parties can serve you legal writs for hundreds or thousands of EURos. Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.
- DanBC 8y agoGDPR doesn't apply to personal projects unless those are commercial projects.
- aeorgnoieang 8y agoI've read contradictory claims. Another commenter mentioned changes to their personal blog to be compliant.
- acejam 8y agoDo you have a source for this?
- DanBC 8y agohttps://gdpr-info.eu/recitals/no-18/ https://gdpr-info.eu/recitals/no-18/ > This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
- gomox 8y agoCan you point me to a more detailed source on this issue? I have heard Germans concerned about getting sued by third parties for minor website legalese issues. I'm not fluent in German so I wasn't able to fully understand the situation.
- draw_down 8y agoCome on. The penalty for operating your lemonade stand incorrectly is not 20 million. I think people should be glad about this in the long run, it shows the law has teeth. Some things are going to shut down as a result of this, that is a normal result of added regulations. If nothing changed it would prove the law didn’t do anything. There are plenty of food businesses that just never start because of the regulations involved. Our societies have decided that’s okay- but it’s still something we decided, because you can’t have it both ways. People who take one look at it and say “nah, not worth it” are not necessarily overreacting. It’s petty to paint it that way, and certainly unhelpful.
- emilfihlman 8y agoAs an European (Finnish), Fuck The GDPR. It is literal cancer. It is a stepping stone to arbitrary enforcement laws: "Trust us, we do no harm". This is not how laws should be written. This goes 100% against anything that is fair in this world. Either you write laws that apply (and are enforced) the same to everyone or you just fucking don't. If you can't do that you shouldn't be writing laws that affect milliards of people.
- losvedir 8y agoAs someone more on the hysterical side, good post, thanks. Can you clarify one part for me? Take this bullet: > The GDPR is going to expose me to fines of up to 20 million Euros for even the slightest transgression > No, the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers at the various data protection agencies in Europe they will first warn you with a notice that you are not in compliance with the law, give you some period of time to become compliant and will - if you ignore them - fine you. That fine will be proportional to the transgression. You can of course ignore the fine and then ‘all bets are off’ but if you pay the fine and become compliant you can consider the matter closed. What if you get warned and decide at that point to just shut the site/app/business/project down? Or is it the case that once you begin operating under the GDPR era, you'll have to handle those "good natured" enforcement warnings, delete data, etc? I get that I'm probably compliant, and probably wouldn't have any complaints against me. I just don't know if it's worth waiting it out to see if there's an issue, or if now is my only chance to easily not deal with it by just blocking EU users.
- losvedir 8y agoIt's like if a new law were introduced requiring a license in order to ride a bike, to make sure people don't hit pedestrians or bike dangerously in the road. The license is free, it just takes a weekend to go take a written test and demonstrate that you can safely ride a bike. Some people who would pass but can't be bothered to give up a weekend would instead choose to just stop biking. It's an unavoidable consequence of introducing a friction where there wasn't one, and there's no way to carefully target or wordsmith the requirement so that this doesn't happen. I think people miss that there is a very large qualitative difference between "no law" and "law". Even a very carefully targeted law will still have the effect, on the margin, of preventing or stopping compliant activities. But in the case of something like privacy, or control of data about you, maybe that's worth it in order to stop the noncompliant activities. On a non-hypothetical topic: does anyone have a good resource on the requirements with regard to backups? That's one of the larger technical sticking points for me - do we have to delete from our backups as well on such a request?
- Tomte 8y agoThat‘s all true, but quite boring, isn‘t it? Because the reverse also hold: if we remove the need for driver‘s licenses for cars, more people will be able to drive. The fallacy is IMO that many people always consider the status quo ante as the perfect balance. Because we have gotten used to driver‘s licenses. So the argument that new regulation stifles some non-harmful behaviour is a truism, but doesn‘t really contribute anything, unless it comes with numbers.
- myWindoonn 8y agoIt's not like that at all; some of us are small business owners who don't have to take any action, because we already were not mishandling PII and already had a PII-handling section in our data-handling policy.
- mbrumlow 8y agoI can tell you that GDPR is going to cause issues with block based backups. Many hosting providers don't separate customers on different block devices. When you back up a block device you have snapshots that have many different organizations data on them. Part of making good backups is knowing that the backup can't change. The only solution now is to add paths to go back and modify those backups to remove customer data when asked too. That is my plight anyways.
- highesttide 8y agoI've seen a lot of people talk about having a separate table for ids that should be removed when you restore a backup. It seems like a plan pretty viable solution, at least from what I've seen.
- icedchai 8y agoThe solution is to keep a list of "things to exclude" if a backup is ever restored. This is reasonable. Rewriting old backups is not reasonable.
- badwolf 8y agoWould such a list not by nature consist of PII?
- megaman22 8y agoConstantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason. It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal information, plus a considerable magnitude more hemming and hawing and trying to figure out if, how and to what extent the regulations apply to us, and how the customers that we sell our products interpret the regulations and what features they require for their interpretation of compliance. It's a big headache, especially where we are also dealing in industries that have conflicting data retention requirements. If we didn't have EU-based customers with sufficient sales to justify the effort, there are a thousand and one other things that we could have better spent that time and energy on.
- nhf 8y agoOne might argue that your company doing the "custodial" data work over the past few weeks and building in the mechanisms in order to handle that data in a more nuanced way is something that should have been done beforehand, and that the fact that you had to take time out to look at it means the law is doing exactly what its drafters wanted it to do.
- jonathanyc 8y agoOh man, the rest of us are so sorry that you are now required to responsibly handle personal information. To quote the author: > Then automate it. If you could automate the collection of the data in the first place then you definitely can automate the rest of the life cycle. There is no technical hurdle companies won’t jump through if it gets them juicy bits of data but as soon as the data needs to be removed we’re suddenly back in the stone age and some artisan with a chisel and hammer will have to jump into action to delete the records and this will take decades for even a small website. Such arguments are not made in good faith and in general make the person making them look pretty silly after all nobody ever complained about collecting data, in fact there are whole armies of programmers working hard to scrape data from public websites which is a lot more work than properly dealing with the life cycle of that data after it has been collected. So yes, it is a burden, no, the burden isn’t huge unless you expressly make it so but that’s your problem.
- hartator 8y ago> The GDPR is going to expose me to fines of up to 20 million Euros for even the slightest transgression > No, the GDPR has the potential to escalate to those levels but in spirit So, yes, but maybe no?
- hartator 8y ago> The EU regulators see their job as ensuring compliance, not as creating a source of income. I thought one of the objective of EU is to make US social media pay their fair share. Citing same article: > European holdings or that use the EU to avoid paying taxes rightly worry about this particular aspect So, what is it?
- donatj 8y agoWhere is the form on this site that claims to be GDPR compliant to get my IP removed from the server logs?
- acdha 8y agoKeep reading the rest of that paragraph: > Well, this website is fully compliant with the law, so at least in this particular case it seems to work. Why? Because I don’t store any information about you. That’s a conscious choice on my part which I made long before the GDPR was even talked about in public. But if your situation is more complex then you too can be compliant, or at least - and this is key - you could try to be compliant. For instance, one oft heard argument is that no webserver (or even any internet service) is going be able to be compliant because all web servers log IP addresses, and IP addresses are PII. But that argument does not hold water. There are several reasons for that, the major ones being: webservers only log IP addresses if you configure them to do so. Almost all webservers have a formatting option that determines what exactly is logged and you could configure your webserver to not log the whole address but just the network portion. You also have the option to log the address and to disclose that you do so in your privacy policy, but then you will have to allow for the removal of that data on request, which you may find burdensome (or not, that depends on the volume of such requests). Finally, you may have a legitimate reason to log the IP address, provided you delete it after you are done with whatever use you collected it for in the first place. There is enough room in the GDPR to hold on to the address for 30 days with a possible extension of another 60 days after which an automated reply to the user can tell them their IP address was purged and you’d be in compliance. That’s one of the reasons why I think the GDPR is a surprisingly good law, most of the times when legislation is written that impacts technology the end result is absolutely unworkable, in this case most scenarios seem to work well for all parties involved.
- apple4ever 8y agoBut I should be able to hold on to IP addresses for as long as I want, since they aren’t PII.
- taysic 8y ago
- frockington 8y agoAnyone know if it is easy to block any user from the EU in AWS? It's been determined that Google Analytics has a greater value than Europe.
- hartator 8y ago> As soon as you do business abroad you will have to comply with the laws of those countries. Serving a webpage is not doing business though.
- hartator 8y ago> There are several reasons for that, the major ones being: webservers only log IP addresses if you configure them to do so. That’s not true. Apache and Nginx default logs IPs. Maybe OP should check his Nginx logs.
- frockington 8y agoWhat is stopping competitors from burying each other in legal work? Just start commenting names and addresses on various pages and submit complaints
- SomeGermanGuy 8y agoWhat does competitors stop doing that now? No business is 100% compliant in any law. If they want they can just for the sake of it bury you in legal work already. See Google vs Oracle. Apple vs Google.
- caffeine5150 8y agoI'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I also agree that the authorities aren't going to be handing out 7 figure fines like candy, both because it's not their historical approach and because they don't have the resources to fight too many of those battles. I want to say I read that the Irish authority's annual budget is around $9M. Theirs is higher than most and Ireland is where most of the US tech giants are established due to tax laws. That said, I think to say that GDPR compliance is simple because it's text is fairly readable or that EU data protection law is simply a matter of transparently respecting people's personal data and not being a bad actor as to privacy is an overstatement. For example, the ePrivacy Directive, most known for prompting all those cookie consent banners, can be incredibly complex to comply with. Each member state has implemented that Directive in different ways. Look at this example https://ico.org.uk/media/action-weve-taken/mpns/2013732/mpn-honda-europe-20170320.pdf https://ico.org.uk/media/action-weve-taken/mpns/2013732/mpn-... where Honda sent out emails to its 350k database simply trying to confirm continued interest in being on their list and got a 13k euro fine for their troubles. I don't know all the facts, but from the document, it doesn't appear that Honda got the fine because they were recalcitrant or being terrible actors. And if the fine is proportionate to the offense (not to the size of the violator), then 13k euro might be levied against a small company for whom it is a significant penalty (not to mention costs, legal fees, etc. in dealing with it).
- charleslmunger 8y agoThe Honda case actually seems pretty reasonable to fine - Honda had an issue where consent from dealer events and other sources wasn't correctly recorded. So they have a large list of emails, where consent falls into three categories: * Person did not consent, they left the form blank * Person consented, but it was not recorded * Person actively denied consent ( wrote "no") Honda then sent commercial email to this set of users, to "confirm" their preferences. In my view, that's not reasonable - if I leave a "would you like to receive email" item in a form blank, that is not permission to send me email.
- hartator 8y ago> So if that’s your business model then good riddance to you and your company. That’s the best way to ensure EU will never have a decent startup scene.
- mychael 8y agoI'm a citizen of the United States, which is a sovereign nation. I will never pay the EU "internet transgression fees", no matter how well intentioned they are. Full Stop.
- AndrewKemendo 8y agoGDPR puts into jeopardy the business model that almost every consumer internet business has run on, post internet bubble: advertising. That's what is at jeopardy here and nobody is willing to just say it. Don't agree with the concept of tracking users to serve them ads? Great, make the case that GDPR ends the scourge of advertising subsidized applications as services. Let's not ignore it though. The reality is, a lot of internet companies that consumers use and like, rely on either selling advertisers access to their market or sell user contact data outright, because there is no other way to make money. If the argument is that this is an unethical and harmful way to keep services alive then we need to agree that the bulk of the last 20 years of startups business models are broken and what the implications for future internet business models are.
- SomeGermanGuy 8y ago> we need to agree that the bulk of the last 20 years of startups business models are broken I agree. If a startup is build on selling my data, I am more willing to pay a fee then to have them sell my data. If we could go back to WhatsApp having a fee instead of Facebook using and selling my (meta)data, I would switch anytime. If Telegram starts raising a fee for using their messenger without anybody reading my messenges/location/... I am all in.
- vbezhenar 8y agoHow can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?
- cbg0 8y agoIf you actively choose not to pursue compliance, you should make it clear in your own privacy policy that the site is not for use by EU/EEA citizens and also use IP geolocation to block their requests.
- bowlofpetunias 8y agoThis is what pisses me off the most about all the hysteria and whining: "The law has been in effect for over two years at this point, and the DPD, the European Data Protection Directive has been in effect for over two decades. So no, this law was not sprung on anybody, though it is very well possible that you only became aware of it a few weeks or months (or days?) ago. If that’s the case do not panic, you too will most likely be fine." Nevermind the fact that the underlying privacy laws are much older, and so many practices were already essentially illegal but went unchallenged so far.
- aeorgnoieang 8y ago> > The law has been in effect for over two years at this point So what's this whole thing that's going to happen soon? It's going into double effect or something?
- SomeGermanGuy 8y agoThe law was made public two years ago, to give companies time to get compliant. It actually goes into effect next friday.
- SomeGermanGuy 8y agoBecause nobody gave a duck, because there was no fine (or they were laughable). Now that we have a single law for a 500 million customer market with a substantial fine, things start to shift to the better.
- robotdan 8y agoFor a lighter take on a Friday, read how Site-Lokd™ brewery technology solves GDPR crisis: https://www.inversoft.com/blog/2018/05/16/site-lokd-brewery-technology-solves-gdpr-crisis/ https://www.inversoft.com/blog/2018/05/16/site-lokd-brewery-... Enjoy.
- chx 8y ago> This in no way should be read as you, the small business operator will face a fine of 20 million for each and every infraction that could be found. Thank you, random stranger on the Internet! However, that is not the law. And even if you are right? As I posted yesterday, half of the employers in the USA has 1-4 employees and make $387,200 on average yearly. Even if they get fined to 1% of the maximum, they are completely wiped out. So no, it's not hysteria, it's plain business sense for them to slap an IP ban on it and move on.
- yani 8y agoGDPR is a beautiful thing.
- andrewla 8y agoI find this confusing: > Note that the 20 million Euros or 4% of global turnover is the maximum fine, the specific language is ‘a fine up to €20 million or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater’, so that’s the maximum of the fine that’s being set by the 20 million or the 4%, and this bit is there to ensure that even the likes of Facebook and Google will not simply ignore the law and pay the fine to be able to continue as they have so far. This in no way should be read as you, the small business operator will face a fine of 20 million for each and every infraction that could be found. Saying that this is intended to be aimed at the Facebooks and Googles is all well and good, but that's covered by the "4%" criterion. The €20 million figure is aimed at companies that have a global turnover of less than €500M, not the Googles and Facebooks. That's why it's scary.
- Reedx 8y ago"Add filters keeping out children" What are some methods for doing this? (aside from asking for birthdate, which is far from fool proof)
- marichards 8y agoNot sure what "it will ensure that the public will not be able to use the GDPR to harass businesses" as GDPR explicitly empowers individuals to seek compensation. https://gdpr-info.eu/art-82-gdpr/ https://gdpr-info.eu/art-82-gdpr/
- thisismyusernam 8y agoYou missed a key question here. As a business owner, what on earth do I need to do next?? Do I need to email all my users giving them an opt-out option?!
- jacquesm 8y agoWorking on that, there will be a second installment on Monday and - possibly, if I can find the time - a third with a number of case studies. This whole sequence was sparked through a discussion about the GDPR on HN a few weeks ago and I've been working on it off-and-on hoping to get it done before the law becomes enforceable.
- mark_l_watson 8y agoI spent two hours today at our campsite working on my web sites to make them reasonably compliant. One problem area is that I serve my blog on Google Blogger. With pained reluctance I turned off comments and stopped showing my followers. I also linked to Google’s own GDPR info page. I used to use Jekyll and maybe I should go back to doing that. Any suggestions?
- adambrenecki 8y ago> ... it may not be possible for you to lock Europeans out reliably enough... Here's a fun little example of this: If one of your parents was a British citizen, then you're a British citizen 'by descent'—not merely eligible to become a British citizen after you fill out a form, you're an automatic British citizen by default unless you renounce your citizenship. (This has caught out at least one member of the Australian parliament, where dual citizens aren't allowed to serve.) This means that you can have someone who's an EU citizen (for the time being, at least), who doesn't live in the EU, has never set foot on EU soil, and maybe isn't even aware that they're an EU citizen themselves.
- jacquesm 8y agoYour example is interesting but the fact that it is such a remote edge case means that if such a person were to raise an issue with their local DPA they will find that no such institution exists so you are safe to ignore that situation for all intents and purposes. Even so it would be common courtesy to honor a removal, update or insight request from that individual as well as from all other individuals that your service caters to.
- davidcd 8y agoHi thanks for his very interesting, What I think is a big problem this stuff about requiring consent. This is a big issue at the moment for website owners and app developers who have on line advertising from vendors such as Google (Admob/Adsense) and use e.g. Google Analytics for development support. These guys do not record individual user details and have no interest in doing so. Specifically for such people there is an issue where personalised advertising (according to to Google and others) needs an opt in, fine but for app developers and web site owners they don't have any user details other that maybe ip address so if they put up a pop-up and record consent how do they know who the user is if they don’t have any other users info. This is leading to absurd discussions re for example Google Analytics used by millions of websites and apps. There is something called client id which GA uses to identify unique "users” or website visitors. Now apparently as it is unique this is personal data so should require consent according to some experts I have read. But as it anonymous how can it be identified who it “is”. If a user demands to know what data a website/app has and mentions the client id info well who knows for sure what any client id represents in the real world ? More to the point what is the likely legal/financial consequence if a user claims that the website id did not ask for consent for this client id to be recorded (how would they be able to prove which one it was that was theirs anyway) ? Would they be able to sue ? I presume not. So is the IC going to be interested in this apparent breach ? And if the developer/website owner had a data breach where they GA account was compromised would they have to inform all the Client ID individuals ? Again obviously not but you see how these discussions are going !
- SARAJACOB 8y agoI am so happy “that. “boyfriend is back” he left me 6 months ago. but with the help of dr_mack@ (yahoo.) com“ my relationship was restored instantly.—–“ NEW YORK.UNITED STATES
- SARAJACOB 8y agoI am so happy that Dr_mack@ yaho o. com was able to save my marriage after 3 years of heartbreak, my husband is mine again...Loved