8 ms·
GDPR is a good thing
- DamonHD 9y agoYes, if we can't stop shops insisting on details of our sex lifes before selling us a pair of jeans then we need more GDPR and its ilk. I would not complete the transaction if that data was requested without very good reasons, and have already point-blank refused to take up 'incentives' for superfluous data. Leaves a very bad taste. Can we parade the marketing dept naked on TV, "just so we can send them a gift on their birthday?"
- jacquesm 9y agoI'm definitely not going to complain about the GDPR and while I expect 2018 to be mild when it comes to enforcement I'd hate to be the company they are going to use to make an example out of in 2019 or so given the per instance fines. That can put even large players instantly out of business, so better take it serious. The GDPR, unlike its predecessor, does not require per-country ratification and it has some pretty serious teeth.
- jdmulloy 9y agoGDPR stands for "General Data Protection Regulation". The author should have written this somewhere at the beginning of the article instead of just assuming all readers know what it is.
- zaphodX 9y agothank you much. Was frustrating try to read the article without knowing what it is about
- johnchristopher 9y agoI find that many comments on HN relies on knowledge of acronyms that are really close to insider knowledge (GDPR not being one though).
- Fnoord 9y agoWhen I filled GDPR (I was only familiar with the Dutch acronym equivalent, AVG) in Duck Duck Go (non-bubble search engine) I easily figured the meaning. No offense intended.
- ocdtrekkie 9y agoFor what it's worth, the author's target audience appears to be folks who create enterprise CRM (customer relationship management) solutions, who would all almost certainly already know what GDPR stands for. Your comment here is useful for the general HN reader, but the author may have been correct not spelling it out for his intended audience.
- digitalbase 9y agoAuthor of article here. Just added it to the top of the article + a link to a short summary what GDPR is
- ceedan 9y agoIf you're going to write an entire article on GDPR, might want to explain what GDPR stands for. just 2 cents from a GDPR pleb
- josteink 9y agoBasically EU (finally!) coming up with some formal regulations for how companies can manage you and your privacy data. With some serious fines for non-compliance. Because businesses has shown us that the market does in no way lead to self-regulation, but rather the opposite. I fully support it.
- ceedan 9y ago100% behind it. Thanks for the info
- icebraining 9y agoThe EU already had regulations, in the form of the Data Protection Directive from 1995. The GDPR improves and expands on it.
- digitalbase 9y agoceedan, you are right. I assumed my target audience knew about it. Just updated the post
- solomatov 9y agoGDPR solve two problems: * Businesses which collect whatever data they can put their hands on, and sell it to the data brokers. Users formally allow it, because they hide permission to collect whatever they wanted in the TOS, which users accept without reading it. Examples of such businesses are creators of browser extensions, which collect all your browser history, or mobile apps which collect all your movements. Users often don't understand what's done with their data or that it's collected. * There's a very large incentive for companies, especially Google and Facebook, to provide only ad supported versions. The more person, well off, the more expensive their clicks are. GDPR substantially changes it, allowing people to control their data.
- noir_lord 9y agoI explained this and the potential ramifications to my boss the other day, We are going to do a full audit of all the data we possess (mostly business to business and very little PII) before next year. It will likely mean some development work as well as we are going to need a reliable auditable way of wiping data. Despite it making work for us all I can say is about damn time.
- polack 9y agoWhat do you mean with "auditable way of wiping data"? Just that there will be a log that the data was wiped, but the actual data is gone forever? The reason I ask is that all "Big Four" auditors has been on my company that we need to be able to wipe customer data, but at the same time there are other laws saying we must keep a record of all data (financial) for many years. None of them can say what law will rule over the other one though since they are not compatable...
- noir_lord 9y agoIn our case it will likely mean that we have a defined documented procedure in place to remove the customers data within the specified period. In terms of technical implementation it'll be a bastard (or result in us holding backups for a shorter period), dumping your DB backups will mean that you still have the data outside of the period (for a lot of places). It's going to be interesting.
- mbrookes 9y agoIt's not just that you can no longer hold backups for an extended period as a form of pseudo archive, but that for those backups you do keep for operational restore purposes, you have to ensure that data that was deleted or redacted under the GDPR right to erase is not subsequently restored during a routine recovery, or is immediately deleted / redacted after the data set is recovered. This (slightly ironically) will require keeping a record of what data has been deleted from production systems in response to "right to erasure" requests.
- LaundroMat 9y ago
- KanyeBest 9y agoThe author implies that there was a real public opposition against the GDPR. Is this really the case? All I've seen is praise.
- jbreckmckye 9y agoThe only grumbling I've heard is from people whose careers involve ever-cleverer ways to sneak marketing analytics past unwitting users.
- k-mcgrady 9y agoThere are only two types of opposition I’ve heard: 1. Now I have to be responsible about the data I collect. 2. GPDR doesn’t go far enough and we should fix it now as it’ll be harder once it’s been enacted.
- kobeya 9y agoThe GDPR does not, as far as I'm aware, have safe harbor clause for startups and other small companies that end up collecting some personal information incidentally as part of whatever they are trying to do but don't have the resources to properly manage it. Lack of such a provision could really hurt innovation.
- jtmcmc 9y agothough GDPR is making more work for me I am glad to see it!
- amelius 9y agoI'm still thinking how I'm going to remove all that sensitive data from my old backups.
- Spivak 9y agoI'm going to assume that as long as you have a clearly defined backup policy and don't keep backups unreasonably long or indefinitely then telling your users that "Your account has been deleted. Once the deletion filters though our backup system in 30 days all your information will be gone forever." would be in compliance.
- digitalbase 9y agoAwesome comment. Yes I believe that is the case
- davidgerard 9y agoGDPR is also a useful thing for geeks, in order to kill terrible ideas. "You'd like to keep this data from this forever? Certainly! Now if your business unit is committing to GDPR responsibility for maintaining this data, we'll notify the DPO and ... oh, you want to delete it? Done. Cheers!" I am enormously pleased to say that the techies in our organisation are absolutely onside with this, even as it will be work. Because it's clearly the correct idea.
- noso 9y agoI found this GDPR Whiteboard helpful: https://www.teachprivacy.com/gdpr-whiteboard/ https://www.teachprivacy.com/gdpr-whiteboard/
- grahn 9y agoFrom the article: GDPR applies to all companies storing information on EU citizens. Those citizens should be allowed to know what data is held, where it is being stored and who has access to it. This is not correct, as far as I am aware. A bit of a nit, but depending on context it can be important: The GDPR applies to all companies with legal presence within the EU storing information on any person, regardless of whether they are EU citizens or not. So even if you only store personal data on foreign (e.g. US) citizens, you still need to follow the regulation.
- mbrookes 9y agoYou're correct, but for avoidance of doubt, it's both: "Who does the GDPR affect? The GDPR not only applies to organisations located within the EU but it will also apply to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location." http://www.eugdpr.org/gdpr-faqs.html http://www.eugdpr.org/gdpr-faqs.html The first point is covered in article 14: "The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data." The second in article 23: "In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment." http://data.consilium.europa.eu/doc/document/ST-5419-2016-INIT/en/pdf http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...
- PeterStuer 9y agoWe find there is a core tension between GDPR's principle of data minimization (take no more than strictly necessary), and SaaS practice of data driven innovation (collect everything, then try to figure out what is useful)
- mementomori 9y agoIs there a similar initiative to protect consumer data privacy in the US?
- lokedhs 9y agoI am an EU citizen, but live in a non-EU country. Does the GDPR regulation apply to data about me?