39 ms·
How GDPR Will Change The Way You Develop
- wgdgx 9y agoIm surprised this place is called "hacker" news and iid actually filled with privacy conscious people but nobody bats an eye about not being able to delete comments. I have to create new accounts every so often to avoid being doxxed by the alt-right.
- fredsted 9y agoI'm kind of curious to find out what kind of comments you're publishing on Hacker News, of all places, that's making you a target to the alt-right.
- wgdgx 9y agoIt's not "hacker" news you monkey with a keyboard. If it were you'd be able to delete your comments. Also alt-right and Russia are everywhere and very dangerous
- tibu 9y agoTypo in the title: GPDR vs GDPR
- trothamel 9y ago"The extraterritorial nature of these two frameworks..." I've noticed that this is something the EU has tried to do lately, to just sort of push their regulations on the rest of the world. I don't see what sort of authority they'd have to impose this on citizens of other countries. I wonder if Europe pushes the issue, if this will be treated like libel tourism, where US citizens and companies without a Eurpoean nexus will be explicitly protected from judgements against them.
- dragonwriter 9y ago> I don't see what sort of authority they'd have to impose this on citizens of other countries. The authority they have is that delegated by the sovereign members of the EU, and the fact that the authority of a sovereign power is limited only by its own decisions and it's practical capabilities. (The US also imposes it's ruled extraterritorially when it feels like it.)
- wuliwong 9y agoI agree but I think a similar question would be: how would this ever be enforced on a US based company/website where it had a EU visitor. I wrote this in another comment but I think outside of just blocking your site in the EU, they would need a further agreement (or I guess precedent) with the US government to actually enforce a penalty on the US company.
- kuschku 9y ago> but I think outside of just blocking your site in the EU, they would need a further agreement (or I guess precedent) with the US government to actually enforce a penalty on the US company. The US has given lots of precedent cases for that. The usual approach the US takes is to force the banks the foreign site is operating with to seize all assets. The EU likely would do the same.
- izacus 9y agoHow is that different from US pushing their DMCA rules to us Europeans and removing our content from services with legal proof?
- deleted 9y ago[deleted]
- trothamel 9y agoIt isn't? European companies shouldn't be subject to the DMCA, unless they have a nexus in the US.
- breakingcups 9y agoIt's quite simple. If you want to do business in the EU or with people who reside in the EU, you need to comply with the EU's regulations. Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. They are not trying to "impose their regulations on the rest of the world", they're trying to protect the privacy of their inhabitants. That this leads to measures that need to be taken by companies doing business with (the data of) their inhabitants is a side-effect and only logical.
- mbesto 9y ago> Don't like it? Don't do business in/with the EU. Then you're free to ignore their frameworks, rules and regulations. So, should you just start blocking IPs from EU-based citizens?
- Tomte 9y agoYes, if you're not willing to comply, that's exactly what you should do. OTOH it just shows your remaining customers that you're willing to do shitty things to them, as long as America is trailing in privacy legislation.
- aleksei 9y agoGeoblocking IPs is not a solution, unless you're willing to let some people slip through and block people who you don't need to block. Also, not everyone connecting from a EU country is a citizen thereof.
- robin_reala 9y agoGDPR doesn’t just apply to citizens of EU countries, it also applies to residents and potentially people just passing through (e.g. changing flights at an EU hub).
- ChickeNES 9y agoGiven that the average small-to-medium sized business in the US is unlikely to do any business outside of the US, I think we'll be fine. :)
- sveme 9y agoIt's something that basically every big block is trying to do, the US has enforced DMCA and other stuff on other providers as well. Though in principle, GDPR only covers EU citizens - if you would be selling a product from Australia that exploded upon using it for the first time to an EU citizen, wouldn't you expect EU authorities to go after you as well?
- nihonde 9y agoThe GDPR applies to transactions with a nexus in the Union. If a US or Chinese traveler books a hotel in Germany, the GDPR protects their data. If a Chinese hotel chain offers a room to a German guest, the GDPR applies to processing of that guest’s data, even if the chain has no other presence in the Union. If that chain stays out of EU data protection agency reach, enforcement is a non-issue. But if Germany and China were to enter a bilateral agreement (as the US will), or if the Chinese hotel chain wants to establish a presence in Europe, then compliance is not optional. Fines are up to 4% of “global turnover”, which is a serious risk to take lightly.
- kazen44 9y ago> If that chain stays out of EU data protection agency reach, enforcement is a non-issue. But if Germany and China were to enter a bilateral agreement (as the US will). this is a very good point actually, GDPR will probably also be used in trade agreements as a requirement, in which the EU has a lot of leverage compared to most other nations/trading blocks across the world. In the end, the reason the EU can do it is simply because it has enough political leverage to make this happen. edit: To add to this, I think these kind of things will be good in the long run, especially when the EU starts more trading talks with smaller nations, which are usually very eager to get into a trade agreement with the EU, especially for african nations as it usually allows more ways for legal migration and includes foreign aid a lot of the times.
- pjc50 9y agoAs came up last time, this is the mirror image of the way the US treats anyone anywhere in the world running a gambling website.
- allendoerfer 9y agoIf you have ever opened a bank account in Europe, you have come across a checkbox, where you have to specify that you are not an American citizen. The US pushes their regulations on companies outside their jurisdiction, too.
- blibble 9y agothe result for banking is that European banks refuse to let Americans open bank accounts depending on the levels enforcement I suspect the same will be true of many popular online services for GDPR: you check the "EU citizen" checkbox and you're banned
- jamiepenney 9y agoIt's not just Europe, I've heard of banks here in New Zealand doing the same. The cost of compliance for them was more than the customer was worth.
- faitswulff 9y agoDoes anyone know of US companies implementing GDPR compliance?
- robgurley 9y agoAny multinational is working on mitigation right now (including my own company) since GDPR compliance is based on having customers in affected regions, not being located/headquartered in those regions.
- deleted 9y ago[deleted]
- reynoldsbd 9y agoAbsolutely! Anybody who does business in Europe or even has users in Europe is subject to this law. The amount of effort being put into GDPR compliance within my organization is just staggering. It really makes me think about these kind of laws from a new perspective, because they cost businesses so much to implement. (I'm not saying whether GDPR is right or wrong! Just that it's expensive.)
- ryandrake 9y agoI would (maybe naively) think that the cost of GDPR compliance would be small if your company is already safeguarding user data and respecting user privacy. If a company’s cost is “staggering“ doesn’t that say a lot about its existing privacy practices?
- lostcolony 9y agoIt says a lot about the cost of privacy, period. The cost would be staggering whether they're modifying existing things, or creating new things, just in terms of ensuring "Yes, we're doing this correctly".
- ryandrake 9y ago
- jamestil0909 9y agoGDPR is the Paris Climate Accord of the technology world. It is a self-imposed handicap for European/Western (and American, by extension) technology companies that makes engineering and business significantly more complex and expensive. China will never impose such restrictions on her industry. Watch as Western firms continue to accelerate their loss of market share and innovation to communist China.
- lovich 9y agoWell shit, I guess we should go back to dumping industrial waste into rivers too. Who wants to win a race to the bottom?
- mfoy_ 9y agoDon't forget child labour! Clearly we're missing out on this great untapped pool of cheap workers!
- yread 9y agoIf Chinese companies want EU customers they will have to comply with GPDR as well. Also "communist" China? Have you been living under a rock for the past 30 years?
- matt4077 9y agoApart from the deserved mocking in the other answers, I'd like to point out that GDPR applies to Chinese companies doing business in the EU as much as US companies doing the same. It should also be said that China has far more onerous regulations of commerce than the EU and US, for example in regards to foreign ownership. But you actually know that, otherwise you wouldn't preface "China" with "communist". Which, however, isn't terribly accurate, because modern China really have much of all to do with communism.
- _o_ 9y agoI will show you another case, company that isnt "bitching" over laws that are good for all humans not just EU and does the right thing, you know backblaze, right? "The changes that are being made by companies such as Backblaze to comply with GDPR will almost certainly apply to customers from all countries. And that’s a good thing. The protections afforded to EU citizens by GDPR are something all users of our service should benefit from." https://www.backblaze.com/blog/gdpr-compliance/ https://www.backblaze.com/blog/gdpr-compliance/ Get it? It is shamefull what a couple of technological leeches did to basic human right for their profit, not to mention turning the whole internet into clickbait maze. Stop complaining, it is right thing to do, like it or not.
- pythonaut_16 9y agoIt's good to see Backblaze confirming that their GPDR compliance will benefit all of their users. That's definitely been a hope of mine as someone who doesn't live in the EU, so hearing that is encouraging.
- lostcolony 9y agoI suspect it will be the norm. For any greenfield development, why would we develop it twice? We have to solve every business problem we have for the EU; why would we solve it differently, to address the same problems, elsewhere? For non-greenfield development, why would we keep two codebases and sets of infrastructure around that we have to support? Better to consolidate. Especially given the positive word of mouth it would generate compared with "Yeah, we're not as careful about your privacy because you're not in the EU". The -only- case where it makes sense to do something different outside of the EU is if there's a key bit of value that we literally can't capture in the EU due to the GDPR, and we want to capture it elsewhere. Now, that's still alarming (in that we could have the privacy haves and have nots), but I just don't know how common that will be, or whether companies would find it worth doing.
- robin_reala 9y agoAnd remember that GDPR applies to EU citizens outside the EU too, so you’d need to confirm with the user upfront that they aren’t an EU citizen before capturing the information.
- jefe_ 9y agoI imagine most of it will boil down to this: Follow OWASP, encrypt in motion and at rest, use key-manager appliance, implement access logging and store separate from systems, backups of data, define lifetime of data, physical controls to data storage facilities, access controls in system, manage multi-tenancy as the situation requires, sensible password policies / multi-factor authentication, background checks on employees, train staff on security, perform regular scans, restrict ports, intrusion detection system, penetration testing, have plans for business continuity and disaster recovery and practice implementing them, be aware when third party libraries are being used and have a policy for applying software/os patches.
- paulsutter 9y agoI’d love to understand GPDR but this article isn’t helping. Can anyone suggest something more focused and direct?
- nleach 9y agoGDPR is so complex, but this helped my understanding a little bit: https://www.convert.com/gdpr/ab-testing-application-compliance/ https://www.convert.com/gdpr/ab-testing-application-complian...
- mcdowall 9y agohttps://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- _o_ 9y agoVery simplified, you can not use or give personal data to someone else without optin given consent (where you must state in non legal, non tech speech for what they will be used) and same goes for enabling others (ad networks, google,..) to get those data. Or you are breaking the law. Further, user must be allowed to view, change or delete those data and remove consent to use them in whole chain (your site, ad network used on your site,...) Furthermore the consent must be freely given (forget trackwalls).
- DanBC 9y agoIt would be useful if people downvoting this could say which bit is incorrect, or what it's missing.
- wastedhours 9y agoAnd also, there's also the slightly grey-area requirement that (if you're using it as your legal basis) consent should not be required in order to utilise your product, merely to utilise the feature set that requires the data. If you need everything, then you'll need to use "fulfilment of a contract" as the basis, and in that case, you probably need to make your ToS pretty tight too.
- esseti 9y ago[ads]If you by chance are storing health/sensitive data and want compliance with GDPR, we actually build https://www.chino.io https://www.chino.io for that. [/ads] For anything (eg. questions, feedbacks) i'm here.
- tephra 9y agoSo here in Sweden (and I imagine a couple other EU countries) there is the Patient Data Law (PDL) that regulates the use of health data. This will probably have to change a bit with GDPR but will still supersede GPDR when it comes to health data. Are you providing compliance with those laws as well?
- mfoy_ 9y agoThis article is all very well and good, my only concern is that, imagine in a few years someone wants to find the list of all the laws and regulations and frameworks and whatnot that they need to comply with to run a truly international website... where would they find that information?
- farazbabar 9y agoI have thought about a natural language understanding (NLP/NLU) based startup to do exactly this. So much to do, so little time.
- s73v3r_ 9y agoSame place you'd go for any questions about the law: an expert. Just like if you thought you had cancer, you'd go see a doctor.
- kelnos 9y agoI think that problem will in some ways solve itself. Ideally you want to consult with a lawyer to ensure you're in compliance. Certainly that's what we're doing where I work (we have dedicated in-house legal staff dedicated to privacy issues who have been taking point on this), but when you're smaller that can be prohibitively expensive. Within a couple years, though, I expect any serious commercial or open source platform available that deals with data to have GDPR-related features. It's already starting to happen, and hopefully GDPR compliance won't be something you have to go out of your way to do; it'll just be a normal part of doing business that everyone understands. The transition period will likely be rocky, and it's my hope that the EU will be initially lenient dealing with honest mistakes that companies work to quickly fix once discovered.
- mfoy_ 9y ago>GDPR will require developers to know the legal and policy landscape of their profession. (This has been the norm for other fields for centuries: how embarrassing for us.) Favourite takeaway.
- aeorgnoieang 9y agoI thought that was needlessly snarky. I'm pretty sure other fields rely on lawyers to know the relevant legal landscape just like we do.
- mfoy_ 9y agoNo. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.
- aeorgnoieang 9y agoA lot of what you might call 'avoiding recklessness' is demonstrably bad for some people so it's not clear that the current tradeoffs are optimal. And it's not at all obvious that, overall, regulation does much more than protect incumbents in a given field or industry at the expense of everyone else. Based on my own experience, I've 'known' about regulations that governed the industries with which I've worked. I'm not sure what evidence specifically you or the author have that leads you to believe software developers should be embarrassed.
- dkersten 9y ago> A lot of what you might call 'avoiding recklessness' is demonstrably bad for some people And? Making sure that the bridge will hold under the weight that its required to is demonstrably bad for my profits (if I were the construction company). That doesn't mean that we should loosen the regulations or whatever. We don't owe anyone the right to profits, regulations are meant to protect us and keep the playing field fair. Of course that will always negatively affect someone.
- setra 9y agoIn this article the author states: "The latter definition is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerprints, RFID tags, MAC addresses, cookies, telemetry, user account IDs, and any other form of system-generated data which identifies a natural person.". This information does NOT automatically qualify as personal data. Information being unique is not the same as personally identifiable. A random cookie sent by the browser is not PII. A cookie stored in conjunction with say an email address could be. Certain information can be classified as PII if it possible to cross reference it with other stored information to identity a user. For example a European court in a recent ruling stated that a full IP address could be considered PII because an ISP would have a record of IP address and time with a persons name.
- robin_reala 9y agoAre you mixing up ‘personal data’ and ‘personally identifiable information’ (a US legal concept that differs from the EU definition of personal data)?
- setra 9y agoNo, I am simply using shortened text not the USA PII legal concept. GDPR has many more restrictions than the USA concept of PII.
- _o_ 9y agoTo me it seems quite simple, if the information can be used to identify user it is personal information and you need explanation why you need it and opt in. If this is a problem for you, maybe avoid collecting what you don't need. The idea of "collect everything and audio & canvas fingerprint them, maybe I will need it later" wont pass, you will never get consent. Collect only what you really need.
- deleted 9y ago[deleted]
- gnfurlong 9y ago
- aeorgnoieang 9y agoWhat's troubling to me is that it's very unclear what specifically is required. I know the linked post isn't legal advice, but in the page about 'privacy by design' linked to by the origin link, they list "Minimize the amount of collected data" as as an item (supposedly to be achieved to be in compliance with the law). What's the minimum amount of data? Who decides that? Is it dependent on context? I'd hope so! Can any site just 'do an end run around' the law by requiring their users to agree to allow them to collect whatever data they collect now or that they've already collected? If so, that seems like it'd be likely as helpful as current terms of service. Another item mentioned is "Where possible, pseudonymize personal data.". What's a practical example of that? Yet another item – "Don’t enable social media sharing by default.". Is the thinking that user's shouldn't be able to share something via social media without first explicitly enabling that option? That just seem unfriendly. Or is the idea that doing so protects someone from doing so accidentally? This seems a lot like the 'cookie law', itself an annoying mandated nagging that probably backfired (because everyone was effectively trained to just do whatever necessary to get rid of the corresponding notification on every site they visited). Again from the privacy-by-design page: > There is no checklist of ready-made questions that will get you there; General Data Protection Regulation requires developers to come up with the questions as well as the answers. That's a really unsettling description of a law.
- robin_reala 9y ago> Can any site just 'do an end run around' the law by requiring their users to agree to allow them to collect whatever data they collect now or that they've already collected? No: a consent from a user must be for granular information with a specific listed purpose.
- aeorgnoieang 9y agoHow granular? Every field? Every character? Every bit?
- robin_reala 9y agoYou’re thinking about it in terms of pieces of information, but GDPR thinks about it more in terms of the uses of that information. You wouldn’t expect to ask a user “Can we store your email address?“. The granular action for storing the email address is “Can we email you from time to time product offers?”. Once the user consents then that email address (and potentially full name, etc etc) can only be used for that consented action.
- cimmanom 9y agoCan any suggest accessible resources or courses for GDPR training for software developers and product managers?
- Azeralthefallen 9y agoI am curious, if you offered a service that allowed users to post their own data to your service. How do you protect against customers posting data that violates the GDPR. I.e. peoples personal information being posted in plaintext? Is this type of case covered by the GDPR? Also how are things like access logs supposed to handled according to the GDPR? Our software records all requests made to our API, they log your userid, ip address, and what you were trying to do. We have clients who are in the US who required the above feature for auditing purposes.
- everdev 9y agoTypically, privacy violations are instances where the user has not consented to sharing the information. In the scenario you describe, if someone willingly posts their own personal information they have forfeited their right to privacy. The law is meant to protect people from companies rather than people from themselves.
- woolvalley 9y agoYour joe blogger using somesmallwordpresshosting.com and you have a freeform comments page. People post 'private' comments of others. Who is responsible for what? How the fuck do you know if its of an 'EU citizen' if that isn't made obvious? Can you get fined literal millions because you fucked up some detail for your blog newsletter's email list?
- realbarack 9y agoI am not a lawyer nor a security expert but we've decided at the place where I work that unstructured fields which are unlikely to contain personal data—but might in edge cases where a user chooses to enter it—don't fall under the GDPR purview. An extreme example of this is in hosted email—if Alice writes an email to bob@gmail.com with some of Charlie's personal information, it would be absurd if Charlie could ask Google to remove the email. (Although maybe reasonable if Charlie could request to not have his data used by Google to target him or anyone else with ads.)
- 9y ago
- tzs 9y ago> A Privacy Impact Assessment (PIA), which is required under GDPR for data-intensive projects [...] What is a "data-intensive" project?
- BjoernKW 9y agoIt's probably safe to err on the side of caution and assume that any application that stores personal data in permanent storage is a data-intensive application.
- aidos 9y agoHow are people planning on implementing GDPR at the DB level? What about DB backups?
- kelnos 9y agoWith a documented data retention and deletion policy. You don't need to keep your DB backups forever, and a request to delete someone's data comes with some reasonable amount of leeway as to how long it takes you to delete it. Obviously you can't drag that out for a year, but from what I've been hearing, a month or two isn't unreasonable. If you're doing DB backups daily, expiring backups after a month (or even, say, two weeks), should be no problem and not an operational risk at all.
- dvlsg 9y agoYou also have to consider whether or not you accidentally restored a deleted user's information if you restore one of those backups.
- jcadam 9y agoPurging a user's data is probably a matter of writing a short SQL/Python/Bash script for most databases (don't forget the audit tables, though it kind of defeats the purpose of audit tables, but whatever). It's something I'd only do on request (I'd expect it to be a rare occurrence), certainly not going to automate that sort of thing. I'm not about to go risk corrupting my backups trying to scrub old customer data out of them. Perhaps only keep the last X days of backups and let the paranoid customer's data attrit out naturally?
- jandrewrogers 9y agoThis is a great question that unfortunately doesn't have a good answer. Ignoring the question of backups, GDPR's requirements have the implication of imposing a workload on database engines that, in most modern architectures, is either pathologically expensive or not currently possible. Some companies are approaching this from a "best effort" standpoint rather than conforming to the spirit of the regulation because the technology simply isn't there to make it feasible for some cases. I've been working on this problem for the last year and this is (IMO) a major gap in the regulation; it presumes that something is possible that isn't for existing applications that are otherwise universally viewed as harmless and permissible. Scalable database engines that can support the letter of the GDPR in terms of data handling don't really exist. This is not a problem that can be trivially solved by patching an existing database engine; the requirements of strict GDPR data handling violates fundamental design assumptions of common database architectures. If you look at, for example, high-assurance databases which have a similar set of requirements for data handling as GDPR, they are never used when at all possible because their performance and scalability is terrible. (These databases are conventional architectures with GDPR-like data handling controls added.) A database engine capable of strict conformance with GDPR while maintaining vaguely comparable performance and scalability relative to what we are used to would require a comprehensive new database engine design from first principles. This is something only a small number of people are capable of designing and implementation would be a very substantial engineering effort. Possibly a business opportunity -- one of the reasons I've been thinking about it, having worked on high-assurance databases in the past.
- tempodox 9y agoI built an app that displays geolocations of tweets on an OpenStreetMap. That data is publicly available from Twitter and users share their location willingly, I presume. Will an app like that become illegal, as far as European tweeters are concerned?
- s73v3r_ 9y agoWhat? Of course not. This law doesn't make apps "illegal". What the law does is put regulations around what kind of personal data you can collect and store from your users, require you to explain what you're doing with that data, and allow your users to opt out of having that data collected.
- x0x0 9y agoIt's unclear. The GDPR definitely covers personal data even if publicly available, so just because you grabbed it from twitter doesn't make it kosher. That said, realistically, I'd have a hard time imagining you would have too much difficulty as long as you allowed people to delete their data upon request. If they post something to twitter, the obvious intent is to make it very public.
- draugadrotten 9y agoFor a real life example, there is a group of people that collect Facebook posts and process them through a ML filter which judges if the post contains hate speech, and if it does, it reports the post to the police, supposedly after manual review. Does this processing comply with GDPR? I'm pretty sure none of the people would allow this processing to take place if they were asked for permission.
- x0x0 9y agoMy best guess is they will be able to shut this down hard, unless there is some alternative processing basis to be leaned on. See (6)1 for a list of potential bases. So no. Not GDPR compliant in the slightest.
- PeterisP 9y ago
- s73v3r_ 9y agoGood. We've needed a change in how we do things for a long time now.
- AndrewKemendo 9y agoI've been digging into GDPR for the last year or so and the major conclusion I came away with was that, in effect, it is a massive effort to educate the population about data collection and processing online while also beefing up guarantees for data security. As in, it's not illegal to to do most of the same things we do now with data, however we now need to educate our users on what data we are using and exactly how we are using it, in a way that is understandable to the average user. With all due respect to the average user, I cannot fathom how anyone doing anything with user data more complicated than a basic record will explain it simply enough to be in compliance.
- ecesena 9y agoTypo in the title: GPDR -> GDPR
- whack 9y agoSuppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important things to focus on, because there's nothing that the EU can realistically do to you anyway.
- woolvalley 9y agoArrest when you have a layover in the EU for some reason, on purpose or because of an emergency. And a default judgement.
- jacquesm 9y agoNot a chance. The only country that has a history of such actions is the United States.
- woolvalley 9y agoSo if I ignore a law in Canada or the EU (extradition request, default judgement, etc) as an officer of a corporation, I wouldn't get arrested when I show up on the border? Really?
- jacquesm 9y agoFor ignoring the GDPR as a small business owner operating on the internet the chances of individual consequences are nil. High profile cases would have a much higher risk and companies that went out of their way to advertise the fact that they are going to break the law would run a significant risk. Show me just one example of a company located outside the EU without a legal presence inside the EU that had an executive detained upon entry for breaking an EU law that does not normally result in criminal prosecution.
- 9y ago
- tekism 9y agoThis is a bit confusing, I have a website and I log IP addresses in my web server log and I use google analytics, what do I need to do?
- Jakob 9y agoThe legal ramifications of storing IP addresses didn’t change with GDPR. You should already have them anonymized since they count as personal data: Google Analytics (https://developers.google.com/analytics/devguides/collection/analyticsjs/ip-anonymization https://developers.google.com/analytics/devguides/collection...): ga('set', 'anonymizeIp', true); Web server (here nginx, https://stackoverflow.com/a/45405406 https://stackoverflow.com/a/45405406): map $remote_addr $remote_addr_anon { ~(?P<ip>\d+\.\d+\.\d+)\. $ip.0; ~(?P<ip>[^:]+:[^:]+): $ip::; default 0.0.0.0; } Only if you store more data about your customers/users you need to act further.
- ahoka 9y agoYou can also irreversibly hash sensitive data it so you can still use it for debugging.
- emilfihlman 9y agoIPV4 is only 4 bytes. Hashing through all 4 milliard is trivial.
- NullPrefix 9y agoAnother reason for IPv6.
- pdkl95 9y ago> ga('set', 'anonymizeIp', true); Note that this doesn't actually provide any useful anonymization. That feature is a placebo designed to give minimal compliance with privacy policies and pre-GDPR data protection requirements. https://news.ycombinator.com/item?id=13639921 https://news.ycombinator.com/item?id=13639921
- woolvalley 9y agoWill the GDPR eventually make bitcoin or other immutable public distributed databases illegal in the EU? Do you have default judgements on thousands john doe node operators around the world? Will EU ISPs be required to censor any kind of blockchain node eventually when someone has a GDPR complaint for that network? Will we arrest teenagers for running ethereum miners on their gaming computers after all of this?
- wglb 9y agoWill any information that enables identification of the individual (or the other ancillary information spelled out in the article and regulations) be in the blockchain? If not, doesn't sound like it. Here is one way to think of this. Any EU citizen has a "right to be forgotten". If there is nothing in your records to identify that person, the you don't need to provide that ability.
- ebcode 9y agoOK, but what the parent is suggesting is that someone might store someone's personally identifiable information on "the blockchain", thus making the entire bitcoin network in violation of GDPR. It's a fairly on-point criticism, IMO.
- chii 9y agoit's not Bitcoin network that's in violation, but the company that owns the transaction in which the data is in. let's say I'm a shop and i allow btc payments, but I include the customers info in the transaction or something to such an effect. then I'm in violation, and must pay a fine (since I can never delete that info). The network has nothing to do with this, and nobody else on the network is party to the violation.
- emilfihlman 9y agoSo just paying a fine is enough to make the issue go away and the users privacy is bought out legally? Now we have a way to estimate the cost and we can just put that on top of the cost of using the service. Boom, privacy bought. You don't realise how absurd GDPR is?
- _o_ 9y agoOne more interesting thought. If you are using ad provider/tracker/data reseler X/... located in USA which is GDPR compliant and is doing bussiness with EU, and you are feeding them with toxic information you didn't get consent for, the EU can pick on them. As you have damaged their bussiness they can sue you. In USA.
- jimnotgym 9y agoI have been through a number of GDPR resources and seminars and I am still of the opinion that there is nothing in it to worry people who are acting in good faith with their customers data. The organisations fined under existing laws seem to have been breathtakingly negligent or just deliberately callous.
- Eridrus 9y agoQ: would I still be able to keep session logs of user journeys through my site without explicit consent? If not, this seems like huge issue for ecommerce analytics. If I need to obtain explicit consent, that the user isn't required to provide to continue accessing the site then I don't see how these technologies are not basically dead in the EU. Can you even legally do a customer churn analysis under the GDPR without explicit consent? One of the biggest complaints I have about this is that the uses for data keep growing, and legally, you can't even test a hypothesis before getting consent, which you won't be able to do frequently because users hate being asked about anything. My intuitive response to this law is to want to split my data into EU/non-EU parts, do all my work on the non-EU parts and hope that the insights gained there can be applied to EU users.
- ec109685 9y agoNo, put up a “trap” page, tell the user you need to collect certain data to operate the site and make the user clicks Accept before they can use your it.
- Eridrus 9y agoI think the GDPR explicitly forbids that; if your site doesn't need the data to keep functioning, it can't just stop working.
- jimnotgym 9y agoYes you can keep session logs, it is a 'legitimate interest'. Are you just trying to see which deals interest people (zero issue, but you could annonymise this) or profiling the customer based on the logs and offering different prices (you are going to have to be more careful and transparent). > Can you even legally do a customer churn analysis under the GDPR without explicit consent There a lots of ways to look at churn with anonymised data. I do it with account ID's. If you are looking at churn rate of Asian people vs Afro-Caribbean then GDPR is going to be amongst your problems,
- agar 9y agoWhile this article is interesting, I strongly encourage anyone - from CEOs, to managers, to individual developers - to actually read the text of the GDPR. This is not written in unintelligible legal-ese. It is very approachable, understandable by a layman, and organized such that relevant Articles are easy to find. It might take an hour or two, yet may have a fundamental impact on how you approach your job for the foreseeable future. Time very well spent. Here is an accessible version of it: https://gdpr-info.eu/ https://gdpr-info.eu/ EDIT: for clarity, that site is accessible from an organizational point of view (i.e., broken out by articles, not one long string of text). I do not know if it is accessible by screen readers or alternate input devices.
- rrix2 9y agoThe documents published by the Article 29 working party[1] are also very useful and digestable: http://ec.europa.eu/newsroom/just/item-detail.cfm?item_id=50083 http://ec.europa.eu/newsroom/just/item-detail.cfm?item_id=50... [1]: https://en.wikipedia.org/wiki/Article_29_Data_Protection_Working_Party https://en.wikipedia.org/wiki/Article_29_Data_Protection_Wor... WP29 is "an advisory body made up of a representative from the data protection authority of each EU Member State, the European Data Protection Supervisor and the European Commission."
- ec109685 9y agoIf you work for a big company and are not a lawyer, you should listen to your lawyers and not try to interpret the law yourself. There are pitfalls and misunderstanding you will run into otherwise. If your company is large enough, they should meet with privacy regulators and work with them to show them implementation decisions and make sure the regulators are in alignment with the approach taken.
- drraid0 9y agoIt seems that since the gpdr requires deletion of data upon user request, companies will not be able to send recall notices when, say, a medical device starts killing customers.
- cheschire 9y agoAnd that warning should be made blatantly clear when the customer of a medical device requests their data be deleted.
- Xylakant 9y agoThe GDPR does not require deletion of all user data on request. There’s still data that can and must be preserved, for example business records, thus records of sale. A recall should be possible with those records. The customer might request that these records cannot be used for unrelated purposes, though.
- drraid0 9y agoWhat if the user requests to be put on a do-not-send list (for email newsletters, etc)? Is that data that can and must be preserved?
- Xylakant 9y agoYou’re generally allowed to keep data that is required to provide a service. So in my understanding, yes, if you provide such a service and the user requests that, you should generally be allowed to keep that info _for exactly that purpose_ You can’t use it for anything else though.
- Radim 9y agoFunnily, one of the common fears our clients (https://gdpr-tools.eu https://gdpr-tools.eu) have with regards to GDPR is not about the general public. It comes from disgruntled employees ratting on the company. Employees know best where personal data is stored (and often no one else in the company does), so they can really do some surgical damage by reporting their employer to the "authorities". GDPR introduces a whole new dynamic.
- vkou 9y agoThis is the case for every law. A disgruntled[1] employee at a coffee shop that has mold growing on the kitchen ceiling can, after being ignored by management for weeks, rat on the company. (And then get shitcanned, with no recourse, because none of their co-workers will testify to the truth on their behalf, because they are cowards who don't want to lose their jobs. Understandable, but sad.) This doesn't mean that we don't need food health and safety inspection laws. It does mean that you actually need to run your business in a way that respects your customers. Stop running your company with the attitude of "It's fine, as long as I can get away with it." I have no sympathy for that. [1] You can be a disgruntled employee, and also be 100% in the right, if your boss is behaving illegally.
- _o_ 9y agoI really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databases. You edit them if they are wrong, you delete them if you don't like them. You dont photo yourself if you dont want to be. You change the passwords if you suspect someone stole them. The only thing that GDPR wants from you is to handle others data with same RESPECT as you handle yours. Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation.
- amelius 9y agoYeah, but isn't it possible to trivially and inadvertently combine a bunch of systems S1 ... Sn which are all respecting the GDPR into a new system which doesn't?
- _o_ 9y agoWe will see, new regulation is coming after GDPR and I bet they will plug the missing holes there. There was a cookie law that everyone circumvented. Now the same people are complaining about GDPR. The next round is going to put even more restrictions, and the regulation is going to be blamed. But the ones to be blamed are the ones who abuse it.
- amarkov 9y agoI'm not sure what you mean by "holes". It seems like it's a fundamental and intended feature of the GDPR that you can't achieve compliance-by-default. You have to explicitly audit every interaction between every system you have, to ensure that either no personal information is present or the interaction complies with GDPR standards.
- Spearchucker 9y ago
- chacham15 9y agoIs it just me or does this article manage to give advice while saying nothing at all about what is required? For example: > The first half is the General Data Protection Regulation (GDPR), which becomes enforceable across Europe on 25 May 2018. This is an overhaul, modernization, and replacement of the existing framework, the Data Protection Directive of 1995 (yes, 1995.) > All of the existing principles from the original Directive stay with us under GDPR. What GDPR adds is new definitions and requirements to reflect changes in technology which simply did not exist in the dialup era. It also tightens up requirements for transparency, disclosure, and process: lessons learned from 23 years of experience. It's talking about the new definitions and requirements, but says nothing about what they are!
- jacquesm 9y agoYou could simply go and read the GDPR text. It's actually ok. Compared to say the Verified-by-VISA spec :)
- e12e 9y agoAye. There's a nicely formatted (non official, hosted by a consulting company) at: https://gdpr-info.eu/ https://gdpr-info.eu/ I also suggest reading a report that's helped inform the text of the GDPR: "Privacy and Data Protection by Design": https://www.enisa.europa.eu/publications/privacy-and-data-protection-by-design https://www.enisa.europa.eu/publications/privacy-and-data-pr...
- shkkmo 9y agoDoes this make Apache access logs illegal? 1) There isn't any way to "opt-in" to them 2) You would need to have a tool to remove every entry for an IP address when requested?
- shkkmo 9y agoIt looks like the answer is yes: https://www.ctrl.blog/entry/gdpr-web-server-logs https://www.ctrl.blog/entry/gdpr-web-server-logs
- kuschku 9y agoIf you store the full IP address forever, that’s already today illegal if you have German users. Hashing (only useful for IPv6) or truncating is recommended.
- 77pt77 9y agoHow would this be enforceable for companies that have their headquarters only in the USA even if they have european users? Will this also apply for citizens of a EU country living outside the EU?
- e12e 9y agoTrade agreements.
- danieltillett 9y agoTrade agreements don’t enforce laws, they just mean the countries are supposed to draft local laws that cover the action. This assumes that the GDPR is covered by trade agreement.
- danieltillett 9y agoThe EU is going to send over its army and force you to comply. My understanding is the GDPR applies to residents of the EU, not just citizens, and it also applies when they are outside the EU. In practice this means it is impossible to determine if it applies unless you gather far more information than you really need from your users - “sorry we have to invade your privacy to protect your privacy”.
- 77pt77 9y agoSo a US company providing services to a US naturalized citizen in the US that is also a dual citizen of a country in the EU makes the company liable to follow these regulations? That makes no sense. This sounds unenforceable.
- danieltillett 9y agoYep. It is worse that it can be a EU resident (non-citizen) visiting the the USA using a USA only service and the law as currently written still applies. Good luck. The next fun job is working out how to remove the data from all your backups when you get a removal request. I have taken the approach that I will comply with the general intent of the GDPR (which I did long before it existed), but not try to apply the ridiculous parts.
- flavio81 9y agoInteresting, i live in a third-world country and we already have a "General Data Protection Regulation" law in place.
- gaius 9y agoIt won’t change the way I develop because I was never a data-stealing sleazebag in the first place. But I hope it drives Google and Facebook out of the UK/EU for good.
- mark_edward 9y agoWholehearted thanks for people like you!
- elcapitan 9y agoI wonder if we will see a kind of dual universe privacy in implementations once countries like China become equal as a market for internet services, and they create some sort of a reverse GDPR law. Then for all customers from the EU you will have to completely anonymize and protect all data to the last bit, while for Chinese customers you'll have to implement the most rigid and total tracking possible?
- s73v3r_ 9y agoPerhaps separate subsidiaries for the EU, which does respect the GDPR, and one for China, which tracks everything that could be tracked?
- PeterisP 9y agoHow would that be useful to you? The EU subsidiary would not be legally able to use any of that data (it can't take it from the China subsidiary in any way whatsoever); and the China subsidiary would not be practically able to use any of that data, since they don't have any users/customers in EU.
- s73v3r_ 9y agoThe China subsidiary would be able to use the data in China, to advertise and acquire more Chinese customers. Of course, I suggested that more for the situation where the EU had data privacy laws, and China required intense tracking of customers.
- PeterisP 9y agoYou don't need subsidiaries for that. GDPR would apply if an EU company would track people in China (Article 3 section 1); it would apply if an multinational company tracks people in EU when offering goods or services to them (Article 3 section 2); but it wouldn't apply when that same multinational company tracks people in China. I.e. Facebook can be fully GDPR compliant if it applies the privacy requirements only to people in EU and gratuitously violates the privacy of everyone else. Furthermore, if China has a legal requirement for intense tracking of customers (I'm not sure what their legal requirements are), then GDPR would allow an EU company to do that without consent. (Article 6, 1c : "Processing shall be lawful [..] if ... processing is necessary for compliance with a legal obligation to which the controller is subject")
- __ka 9y ago>Online identifiers ... is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerprints, RFID tags, MAC addresses, cookies, telemetry, user account IDs, and any other form of system-generated data which identifies a natural person. What if one exclusively collects telemetry IDs (unique per application), with which usage stats are sent. To what extent is this personal data? On who does the burden of proof for 'being able to identify a natural person' fall?
- maximexx 9y ago> Not having a PIA is not an option. Nice one for the indie developer. It looks like the PIA can take more time to get right than your actual program..
- chasb 9y agoGDPR has a lot of parallels to HIPAA and SOC 2. Many developers here have worked with companies subject to HIPAA, or that do SOC 2 reporting. One big difference is that the material scope of GDPR is so extremely broad: it regulates any PII that can be touched by EU law. That's important because it means that all of your SaaS vendors that touch this data may be in scope, not just your hosting stack. If you're marketing or selling in the EU, your entire growth/CRM/customer success stack will be regulated. If you have EU employees or contractors, all of their HR data is covered. I'm not sure if most companies realize this. It may be less of a problem for B2B, we'll see. Questions to ask yourself: What is the scope of GDPR personal data across your business? Are you marketing in Europe? Are you selling into Europe? What business processes touch that data?
- klokoman 9y agoUnable to direct attack freedom of expression, the spread of informations and small business, the EU developed another bureacratic layer on top all the bureaucratic layers already in effect. This layer is pretty hard to comply with, and requires a lawyer always on retaneir for peace of mind, ensuring that publishing online is de facto reserved to few players. Every other interpretation of the law is naive, just like with the cookie law, if they really wanted to stop the abuses of the big players they could have done so. Instead they're ruining normal people, because that's the real objective.
- jakeogh 9y agoThe US withdrawing from the TPP was a (very) good thing: https://www.taylorwessing.com/globaldatahub/article-the-tpp-take-on-personal-data.html https://www.taylorwessing.com/globaldatahub/article-the-tpp-... The EU's war on memory is concerning. It will be used as cover for their social engineers. Misinformation campaign didn't work out? Ah, delete it!
- h1boo 9y agoHow is this law okay with international trade agreements? Why doesn't US say that this (rather fuzzy law) is meant to hurt tech companies which is disproportionally based there? In retaliation couldn't they come up with some law that impacts EU businesses?
- PeterisP 9y agoIt doesn't breach current international trade agreements. In the long run, however, we'd expect to see international trade agreements attempting to harmonize these requirements worldwide, and likely include some mechanism that makes cross-border enforcement easier.
- dingo_bat 9y agoAs always EU regulations are efficiently point out why Europe will always be an inferior place to do business compared to America. I guess at least Brexit is making more sense now.
- NullPrefix 9y agoUK will also comply with GDPR.
- Bizarro 9y agoEither these laws or will be ignored or more and more business will move out of European countries to abide by this law, which Europe really can't afford. I'll happily ignore this law.
- romanovcode 9y agoAs an EU citizen I will have no problem not using your company if it cannot even provide basic privacy for me as a user.
- Bizarro 9y agoYou can make your own decisions about who you want to trust with your data without that law being in place. The only thing that law does is wall off Europeans from the rest of the world. This is the just the beginning of "protection" laws from bureaucrats in Brussels. You can believe that these laws are there to "protect you", but the rest of us know better. Stop letting politicians run your lives, and you'll be better off.
- mycall 9y ago> concept of privacy as a fundamental human right enshrined in law, a situation which has no U.S. equivalent. We do have something about that in the U.S. Constitution.
- balefrost 9y agoThat deals with your interactions with the government, not your interactions with other citizens.
- intrasight 9y agoWhat really strikes me is the fact that we spend so many years getting good at remembering things, and now we have to get good at forgetting things. Seems to me that forgetting is way easier than remembering. But I could be wrong. Was just reading this article which I found very informative: http://www.davidfroud.com/does-right-to-erasure-include-backups/ http://www.davidfroud.com/does-right-to-erasure-include-back...
- kerng 9y agoWhat I like about GDPR is that it might help change the mindset that storing customer data is purel an asset - it should be a liability. Hopefully other countries will ratify similar laws. Then something like the Equifax breach could go unpunished!
- YetAnotherNick 9y agoWhat about things explicitly designed in a way that there is no option to be forgotten. What about commits in version control sites? What about mailing lists? From skimming over the spec, it seems that politicians haven't thought about any other sites than social networks or some other profit making sites. Even in that case, if some ML system is trained on the data of the customer, do they have to re-train after anyone invokes right to be forgotten.
- qwerpoiu 9y agoA thought I had that I haven't heard elsewhere: this is the EU equivalent of the Great Firewall - an immensely powerful tool for governments to use against "foreign" companies that don't have the proper values. The EU would love to have a tech company that could be compared to Google, Facebook, or Tencent, but its attempts to create one by fiat (Quaero, for example) have fallen flat. The mechanism (legal rather than technical) and the claimed ideals (privacy rather than anti-pornography) are different, but the effect will be the same. Depending on your perspective, this represents a tremendous opportunity for EU-based startups. Your government will almost certainly make things very difficult for your foreign competitors. Cozy up to your local Party officials!
- Oomroo 9y agoI can't find a definition of "erasure". Do these count as erasure?: 1) copying a subset of items Y from a set X stored at location A to a new location (e.g. a new disk or another computer) B, then deleting location A (e.g. reformatting disk A) 2) storing all information encrypted with per-person keys, then deleting a person's key Also how does one prove erasure ? https://gdpr-info.eu/art-4-gdpr/ https://gdpr-info.eu/art-4-gdpr/
- _petronius 9y agoI think the key here is to think of this in obvious terms: can you (easily) recover the data? Are you trying to trick customers/regulators into thinking you got rid of the data, but really have a secret copy for later? Did you make a good-faith effort to comply with the law? If your answers are no, no, and yes, you’ve got nothing to worry about. Law isn’t, despite what TV would have you believe, a game of pure technicalities (especially outside the US).
- Oomroo 9y ago"can you (easily) recover the data" This rules out encryption+key-deletion as erasure because while you may not be able to (easily) recover the data, someone with more computing power could (now or in the future) What about old magnetic disks and tape backups ? Even if you erase them they could possibly be recovered by someone else with the right resources
- Thiez 9y agoThere literally isn't enough energy in the solar system to run a counter from 0 to 2^256. Computers may still get faster for some time, but in the absence of new cryptographic weaknesses, 256 bit symmetric encryption can be considered to be safe from brute-force attacks forever. There is some trick using quantum computers that could help, but doubling the key size counters that, putting your encryption beyond the reach of brute-force once again.
- emilfihlman 9y agoI see this as a huge blow to privacy. Every service will now just have a clear "give us all the rights or gtfo" and publish everything to public encrypted. The user has allowed their private data to be published and the service has no obligations anymore.
- tekknik 9y agoI don’t see this helping at all. The big companies will just get consent and then it’s business as normal. Sites that can’t comply due to lack of resources will just block EU access. Really this is just a bullet point for the big guys and stifling for the small guys.
- JPSchoolSports 9y agoThere is a fundamental truth that no one seems to accept. But it is the truth, and the majority of the planet's ignorance of this fact makes it no less true. (I am not arguing about what is legal or not, or proposing any illegal behavior, rather just observing that many things legal in the past were absurd/ wrong or still are in certain places on the planet - eg - women not being allowed to drive in certain countries. ie. I repeat, I am not arguing about what is legal or not, I am arguing about the disconnect between reality and the law). The hard truth: There is no such thing as privacy - it was just not so apparent until now. I can know whatever I want, you cannot stop me from knowing the color of your shirt, your bank pin, or seeing pictures of you naked if they exist. I am free to know whatever I want, and so is everyone else. When everyone understands that this is in fact the case, then the world will be a better place. There are lots of interesting topics and conversations that arise from this (sometimes people call them counter arguments, or try and tell me that what I am calling for is wrong). I am not calling for anything, and I understand the ramifications. But most importantly, I am not talking about how I want to world to operate. I am observing how the world DOES operate. Einstein did not invent relativity (I am not comparing my (probably far far lower) IQ to that of Eintein's like you will deflect to as I use this analogy to get my point across). Einstein merely observed what was there for anyone to observe, and his observation made the world's societies of people a better place (because humanity increased it's understanding of existence). I repeat privacy is a fallacy. I can and will know whatever I want to know. So will others. Currently people in power have an unfair advantage because they can know anything about anyone and the rest of us go to jail if we also know it. The way to level the playing field is to realize this fact, remove the laws (in theory, that is my proposal, but I don't know how), realize everyone has a naked version, has been bad, can be taken out of context. In the end, the importance of context will return and the novelty of nudity (and all other things (location that abductors can find you, etc) and intimate knowledge will reduce. But we will all be better off because the difference between the person who knows your bank pin and the person who steals your money will be clearly understood. Currently this is not the case. My observation is correct. Although you will not agree, and be played as a sucker, continuing to fight for privacy, being ashamed of your past while making yourself more and more at the mercy of the bullies (I mean governments and information curators like wikipedia, fb, twit,goog - they are nothing more than storers of user generated content) that make laws and use them against you. Another observation that you will dislike me for, but that I ask you to, at the least, just meditate on, repeating in your head a few times, before dismissing it: Laws are a cheap substitute for understanding.
- cloudadic 9y agoI think more there developers; it is operational burden for companies. GDPR discuss about the lifecycle of customer data and trying to draw boundaries who, how, when, where the user data is going to used. Our product https://www.StegoSOC.com https://www.StegoSOC.com helps in automating cyber threat detection. That is also one of requirement for GDPR.