8 ms·
Another big recent achievement of the European Parliament is the "General Data Protection Regulation" (GDPR) [1], which comes into effect in May 2018 and stipul
by CyberThijs 9y ago
Another big recent achievement of the European Parliament is the "General Data Protection Regulation" (GDPR) [1], which comes into effect in May 2018 and stipulates that companies can be fined up to 4% of their worldwide turnover when they fail to protect/process the data of EU-based customers in a proper manner.
For example: say that LinkedIn was to experience a new data breach, and they fail to inform the authorities or their customers in time, then they can be fined for up to 120 million USD (based on a revenue of 5 billion USD)!
I'm surprised that it's so little known here, as the impact will be massive.
[1] https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- halflings 9y agoYep, and it does much more than that: it forces companies to actually wipeout your data when you ask them to (not just flip some bit and still keep that data, like facebook infamously does), and also set strict TTLs (Time To Live) for any derivative data that the user cannot explicitly delete.
- 3pt14159 9y agoHow do I follow conflicting laws? One country says "keep all data for 90 days to aid law enforcement" the other says "delete it immediately" which is it?
- kough 9y agoYou ask your team of lawyers who can make a good decision for your company based on your business goals and the relative values of complying with each of the competing laws, along with the relative risks associated with failing to do so.
- harperlee 9y agoI would guess that one solution is to keep EU citizens' data in the EU to avoid it being subject to other laws. And possibly having separate companies by country. As an analogy, if I recall correctly banks have very stringent laws to follow regarding data export and money export to other countries. The solution they choose is to have a bank per country, not a global bank.
- strictnein 9y ago> I would guess that one solution is to keep EU citizens' data in the EU to avoid it being subject to other laws. This is exactly what is being done by the large corporations that can afford to do it. European datacenters staffed by Europeans. Americans are not allowed to view any PII for any European (at least with the company I work at). Russia requires the same thing, although they just want the servers in their country so they can put a SORM-3 alongside it and intercept whatever data they want. https://en.wikipedia.org/wiki/SORM https://en.wikipedia.org/wiki/SORM
- dmoy 9y agoAh yeah 242-FZ, definitely a different purpose in Russia
- CyberThijs 9y agoOne of the goals of the GDPR is to consolidate all the data protection laws of the EU member states. So within the EU this shouldn't pose a problem. For the US, I assume this is covered by the EU-US data shield. I assume a similar construct will be necessary for GB once it leaves the EU.
- AndyMcConachie 9y agoThere is no easy answer to this question. For example, what happens if US courts demand data you have stored on Irish servers,[1] but an EU citizen asks that you destroy this data? Do you destroy the data and risk being charged with destruction of evidence in the US? Or do you keep it and risk being non-compliant with the GDPR? [1] https://www.theguardian.com/technology/2014/apr/29/us-court-microsoft-personal-data-emails-irish-server https://www.theguardian.com/technology/2014/apr/29/us-court-...
- alexeldeib 9y agoJust FYI, this case was reversed on appeal (i.e., against the government). I recall there being some buzz with the government potentially pushing for further court action, but as far as I know that's the current status.
- throwawaymanbot 9y agoI would imagine, since the EU is where the Data resides, and the EU is the legal jurisdiction, that the EU would take precedence. Its monumental nationalistic and legal hubris to think that American law takes precedence anywhere in the world, let alone with an ally as large as the EU.
- luma 9y agoBe that as it may, there is nothing to stop US authorities from charging US companies with crimes if they were to comply with EU laws. They are in direct conflict, and any internet-based company operating on nearly any scale is in danger of running afoul of these sorts of issues. This isn't a Google/Facebook only problem, this is a problem for any web service that might store user data.
- deleted 9y ago[deleted]
- louhike 9y agoCompany may have to treat the data differently according to where the user lives (yes, it can be a mess). For EU countries, the EU law has priority (except for the constitution).
- kbart 9y ago"How do I follow conflicting laws? One country says "keep all data for 90 days to aid law enforcement" the other says "delete it immediately" which is it?" GDPR is EU wide regulation that trumps national privacy laws. It doesn't even need to be approved by individual members, so when it goes into effect on 25 May 2018, it will be working EU-wide on the same day. Furthermore, it affects companies all over the world that serves EU citizens. There's much skepticism on how EU will enforce this law worldwide, but for now it was quite successful dealing with big companies, remember: Microsoft vs EU (paid €561 million fine), multiple cases of Google vs EU (right to be forgotten, Ireland tax rulling, ongoing case vs Android), Facebook/WhatsApp vs EU (€110 million fine) etc. To answer your question: no, there will be no conflicting laws - if you serve EU citizens, you must follow GDPR. From my personal perspective, GDPR is one of those not-so-often moments that I'm proud of EU.
- tajen 9y agoMicrosoft vs EU yielded €2bn fines. I had made the calculations myself in 2013, I can't find the source, but here's most of the details: https://www.neowin.net/news/since-2004-the-eu-has-fined-microsoft-304-billion-dollars https://www.neowin.net/news/since-2004-the-eu-has-fined-micr...
- wav-part 9y ago> Furthermore, it affects companies all over the world that serves EU citizens. No gdpr applies if companies target EU citizens [1][2]. My personal opinion of the law is that its as useless as cookie law but way more costly and unpredictable. [1] (122), Pg 22, https://docs.google.com/viewer?url=http%3A%2F%2Fec.europa.eu%2Fjustice%2Fdata-protection%2Freform%2Ffiles%2Fregulation_oj_en.pdf https://docs.google.com/viewer?url=http%3A%2F%2Fec.europa.eu... [2] Pg 13, https://docs.google.com/viewer?url=http%3A%2F%2Fwww.linklaters.com%2Fpdfs%2Fmkt%2Flondon%2FTMT_DATA_Protection_Survival_Guide_Singles.pdf https://docs.google.com/viewer?url=http%3A%2F%2Fwww.linklate... The mere accessibility of your website by individuals in the Union or use of the languages of one of the Member States in the Union (if the same as the language of your home state) should not by itself make you subject to the Regulation. However, the following factors are a strong indication that you are offering goods or services to individuals in the Union and so are subject to the Regulation: > Language - You are using the language of a Member State and that language is not relevant to customers in your home state (e.g. the use of Hungarian by a US website). > Currency - You are using the currency of a Member State, and that currency is not generally used in your home state (e.g. showing prices in Euros). > Domain name - Your website has a top level domain name of a Member State (e.g. use of the .de top level domain). > Delivery to the Union - You will deliver your physical goods to a Member State (e.g. sending products to a postal address in Spain). > Reference to citizens - You use references to individuals in a Member State to promote your goods and services (e.g. if your website talks about Swedish customers who use your products). > Customer base - You have a large proportion of customers based in the Union. > Targeted advertising - You are targeting advertising at individuals in a Member State (e.g. paying for adverts in a newspaper).
- s_dev 9y agoThere won't be conflicting laws -- the GDPR is a EU wide policy and supersedes any laws on the books in that nation.
- yammajr 9y agoExcept that not every country belongs to the EU. If you have customers globally, you'll still have to deal with conflicting requirements.
- abandonliberty 9y agoUntil we have One World Government we'll have to respect the laws of the countries we do business in. This is an example of why some local services are winning out against global competitors. Respect for and knowledge of their specific niche.
- kodablah 9y agoSo on my ad-supported site that does not ask users where they are from, I will have to put a geo-ip filter to keep EU people off in order to avoid fines? Otherwise, do we accept that statements like "we'll have to respect the laws of the countries we do business in" is a bit generic and over-reaching in a global medium? I have not read the proposed law and I trust this situation is covered, but I am still annoyed at every region having so many of it's own internet rules (not EU specific, goes with them all). Granted explicit business w/ explicit customers giving explicit monies in nation-backed currencies does make it easy to follow this law, but not everyone's business is like this.
- ForHackernews 9y agoDo you collect a lot of data about your users and not offer them any way to delete it?
- kodablah 9y agoThis is a hypothetical, so let's say yes. So, do I need to filter out my users to avoid fines? That may seem noble and great in this particular case, but it's a slippery slope. The more regionally-specific regulations that are introduced causing more work for companies, the more the ROI per customer in that region may reduce. Once it gets below 0 with the threat of fines for a company, the users might be cut off. It seems all good for this specific policy because most of us agree with it globally. But data protectionism and/or extreme regional deviations/regulations in law will reduce the globalism everyone shares. Other options (such as educating the populace or encouraging competition) can be more effective than restrictions. This is something to think about as the EU grows smaller, not larger. Even today, small companies with fewer EU users may stop and think about providing access at the cost of, e.g., building a portal for them to manage cookie settings.
- hamilyon2 9y agoEncrypt it with key that only the law enforcement has. Keep actual encrypted data on a medium outside of coutry where it is illegal.
- em3rgent0rdr 9y agoSeems like it will be extremely difficult and expensive to guarantee all copies are deleted. Also, replication is necessary for caching and reliability. I worry about how such seemingly well-intentioned laws can have adverse unintended consequences.
- splouk 9y agoIf I ask Facebook to delete my data, it should be deleted. Why does caching or reliability have anything to do with that?
- Spivak 9y agoWould you be satisfied with, "this data will be deleted once the deletion filters though the caches and backups?"
- calcifer 9y agoIf "once" is a reasonable time (as defined by the regulation) then yes, I'd be satisfied.
- em3rgent0rdr 9y agobut I doubt the average user will be comfortable with such an experience.
- calcifer 9y agoI doubt the average user needs anything more than "as per EU regulations, your data will be deleted in X days" when they delete their account.
- em3rgent0rdr 9y agoIt is not just the deletion when closing your account. It is the keeping track of all the copies that have to be made during regular operation (including packets in temporary buffers, periodic backups, cached version, redundant copies to hedge against data loss) just incase one day the user decides to delete.
- BearGoesChirp 9y agoWill it also have to be removed from backups?
- dmoy 9y agoAlmost certainly yes. Otherwise it's not actually removed.
- BearGoesChirp 9y agoI've seen court ordered removal before and no one even considered backups and the impact on backup integrity had it been removed from backups. Especially when considering off site backups that the company will often not have immediate access to.
- yellow_postit 9y agoDo smaller companies get less onerous requirements? This is achievable for mid and large companies to comply with but may further stifle EU innovation. I think this is a good set of data protections and hope there are ways to make compliance incredibly low friction.
- Piskvorrr 9y agoNope. This is an upcoming requirements nightmare that people seem to ignore in the vain hope that it will ignore them.
- jessah 9y agoWhy is the GDPR an requirements nightmare? It's one ruleset for the whole EU instead one ruleset for each EU state. And the GDPR seem to be not more complicate than the individuel laws where before.
- sqeaky 9y agoIf it just then 4% of revenue fine could well be 0 for startups. I presume they have some provision to prevent 0 euro fines, does anyone know about that provision?
- jdcarter 9y agoFrom the wikipedia page: "fine up to 20,000,000 EUR or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater" So yea, a 20M EUR fine could destroy a startup.
- Piskvorrr 9y ago"This ruleset you have? Oh, just merge it with the old ruleset; the old laws are not being repealed. Merging is easy, right?" In other words, it's not a replacement: it is an additional set of rules to keep (although most of it would be a superset of various national laws).
- tomp 9y agoIt's good that this idea (fine as a percentage of revenue) is finally becoming mainstream, but it's sad that the percentage is so low... 4% is just cost of business, like taxes etc. It should be about 30% if we really wanted to incentivise the companies (or their CEOs/shareholders).
- marcoperaza 9y agoFour percent of revenue is a massive fine. That can easily wipe out a company's profit margin.
- jcmoscon 9y agoThat's what you do when you hate capitalism and hate the power to destroy it.
- AndyMcConachie 9y agoIt's called regulators with teeth, and it's what makes the EU livable for its citizens. As an EU and US citizen this is exactly why I choose to live in the EU.
- vsl 9y agoThat's not how I'd put it, as a citizen of an EU country. The overregulation is suffocating for both business and individuals (who lived in socialism and value liberty, anyway). Just this year, EU regulations destroyed my LTE data plans, hugely increased my cost of Swiss travel (the same) and ruined my hobby because terrorism.
- stass 9y agoIt is sad that EU is slowly moving back towards the over-regulated and bureaucratic regimes of the past. This will further push the EU economy down the drain and prevent people from innovating. I just hope it does not lead to jail sentences and labor camps for people accidentally leaking the data as some in this thread are arguing for. The history does not provide much hope here unfortunately. I don't see how this law benefits anybody except filling up the EU budget by collecting fines. The companies are already careful with their data as any leak would affect their image extremely negatively. If one needs a good example of why Brexit happened, here it is.
- hellbanner 9y agoYes, but important will be how selective they are enforcing.
- ust 9y agoFor my work, I'm working on the impact of the GDPR on the research, and how will the GDPR work in scientific communities. I'm not a lawyer, of course, so my interpretation might be a bit off (so disclaimer, IANAL, this is not a legal advice, and etc.). Anyway, these are just some of my thoughts on the subject. Well, GDPR is a big topic, and it not yet clear how all the provisions will be implemented. It is not that different from the (currently valid) Directive, but it does clarify certain points, and makes much more stringent penalties, as mentioned in parent post (the fine is actually 4% of the global revenue, or 20M Euro, whichever is greater). The changes in respect to the Directive are, in short: • GDPR applies to the processing of personal data by controllers and processors in the EU, regardless where it takes place • Penalties – up to 4% of annual global turnover or 20M€ (whichever is greater) • Consent – conditions are strengthened (clear and plain language, explicitly related to the processing, easy to withdraw) • Breach notification • Privacy by design • Right to be forgotten • Data Protection Officers • Right to access Now, as mentioned in another comment, the right to be forgotten and erasure of data is not really wipeout, the data controller and data processor are supposed to do it using "industry standards" and "reasonable effort" (controller, e.g. should flag that the processing the data should be restricted). Also, there are exceptions (legal claims, public authorities, free speech, etc.). Different comment points out that the Regulation, unlike Directive, makes GDPR valid in all EU countries, and this is true. However, the EU states are free to implement their own data privacy laws, which of course, need to be in line with the GDRP. This may potentially introduce legal inconsistencies across the EU for certain points. Also, one should not underestimate the legitimate interest of the service provider, or controller, to retain the data, even if the user has asked for the data to be removed. The data may also be retained by the request of relevant public authorities, etc. One comment has suggested what will happen if the EU citizen requests the removal of it's data, while the US public authorities asks for access to this data. In this case, the relevant EU public authorities may request for the data to be kept (or not, I guess this will be decided on case by case, also the provider may have a legitimate reason to keep the data..). And of course, the biggest problem, the transfer of data to non-EU countries. For this, there are several ways to do it, one is mentioned already, i.e. user consent (which must be clear and unambiguously given, and can be revoked at any time). Then, of course, there are contracts, binding corporate rules, etc. For EU-US transfer, there is Privacy Shield for transfer of data to US (which is a replacement for the Safe Harbor, stricken by EJC), but this is mostly for commercial services (so it does not work for academic environments..). There are some other interesting aspects to GDPR, but this post is already getting a bit long. For more info, these links are interesting: [1] https://aarc-project.eu/aarc-infoshare/ https://aarc-project.eu/aarc-infoshare/ -- for academic environments.. [2] https://iapp.org/resources/article/top-10-operational-impacts-of-the-gdpr/ https://iapp.org/resources/article/top-10-operational-impact... [3] https://www.whitecase.com/publications/article/unlocking-eu-general-data-protection-regulation-practical-handbook-eus-new-data https://www.whitecase.com/publications/article/unlocking-eu-... There are multiple WP29 interpretations on various points (some of them are actually human readable, not just legal talk..), etc. In any case, it will be interesting to see all these developments in the future. [Edited for mistakes..]
- oulipo 9y agoThis is for those reasons that EU companies are innovating in the privacy, for instance doing AI assistants which are private by design with https://snips.ai https://snips.ai
- usgroup 9y agoAgreed. I was initially reluctant about the GDPR thinking it'll be more rubbish to have to take into account but was really pleasantly surprised. It actually and seriously implies better rights over collected data and privacy. I think soon enough, privacy is going to become a serious competitive advantage for Europe because it'll translate into consumer confidence and business confidence .
- k-mcgrady 9y agoI wish we had more European based alternative services that I could switch to. With email the standard response to dumping Gmail seems to be FastMail (non-EU) and I haven't seen anything high-quality within the EU. Same goes for lots of other services. If anyone reading has some suggestions for EU based alternatives to popular websites/apps I'd love to hear.