21 ms·
I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would tr
by _o_ 9y ago
I really don't think (and I am developer, I will need to comply) that anything in GDPR is hard to understand. Treat data from others in same way as you would treat (and you are treating) yours. You are not selling your personal details to 3rd parties, you are not keeping painfull pictures of yourself climbing to garbage bin and doing diving completely drunk, you are not storing them into pastebin or unsecured databases. You edit them if they are wrong, you delete them if you don't like them. You dont photo yourself if you dont want to be. You change the passwords if you suspect someone stole them. The only thing that GDPR wants from you is to handle others data with same RESPECT as you handle yours.
Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation.
- amelius 9y agoYeah, but isn't it possible to trivially and inadvertently combine a bunch of systems S1 ... Sn which are all respecting the GDPR into a new system which doesn't?
- _o_ 9y agoWe will see, new regulation is coming after GDPR and I bet they will plug the missing holes there. There was a cookie law that everyone circumvented. Now the same people are complaining about GDPR. The next round is going to put even more restrictions, and the regulation is going to be blamed. But the ones to be blamed are the ones who abuse it.
- amarkov 9y agoI'm not sure what you mean by "holes". It seems like it's a fundamental and intended feature of the GDPR that you can't achieve compliance-by-default. You have to explicitly audit every interaction between every system you have, to ensure that either no personal information is present or the interaction complies with GDPR standards.
- Spearchucker 9y ago"...you have to explicitly audit every interaction between every system..." But would you though? If you're a large co. you'd have a configuration management system where you just pull the specs/data rather than do an audit. If you're a small co. you'd know already, and if not you'd just go look. Right? My experience is that anyone complaining about the amount of work GDPR is causing is a. not compliant anyway (and knows it) and/or b. has terrible or no IT governance.
- amarkov 9y agoNot right; you can't just review the specs of each system. It's very easy to accidentally combine compliant systems in a way that isn't compliant. Just to pick one example I've seen in practice, system A might have an integration bug causing system B to periodically emit error logs, containing data which system A knows is personal but system B does not.
- michaelmrose 9y ago"has terrible or no IT governance" So planet earth then. Consequences must be understood in terms of how things actually are even if the rules are ultimately for the best.
- LoSboccacc 9y agoThat’s an extreme oversimplification. The law applies to business entities so it will go and cover every piece of infrastructure they run retroactively. Imagine having a dev with contributions and commits in a dozen projects calling github to exercise his newfound right of removing all personal identifiable information from the system.
- f137 9y agoThe problem is you are required to prove that you follow the rules, which would take your effort and your money. This is a "guilty until you prove you are not" thing.
- calcifer 9y ago> The problem is you are required to prove that you follow the rules Yes, because the "just don't do creepy shit" approach to privacy didn't go so well. If the carrot doesn't work, the stick comes out.
- Romanulus 9y agoIsn't this, like, the cornerstone of bad reasoning; acting/enforcing on a few one-offs?
- calcifer 9y agoWhat do you mean one-offs? Pretty much every company with an engineer on staff is collecting as much data as they can with zero regard to the user's expectations of privacy. The regulation exists to stop an epidemic, not to act on a few one-offs.
- freeone3000 9y agoIf the user wanted privacy, they wouldn't be giving data to our services. It's a bit ridiculous to punish us for keeping what users freely give us.
- SahAssar 9y agoIt's not given freely unless consent is given, which in most cases it isn't.
- freeone3000 9y agoYou're referring to express consent. However, the user is granting implied consent - they're the ones visiting our website, they're the ones requesting our images and executing our javascript, and they're the ones filling out our forms. We're not forcing them to do any of these things.
- ambicapter 9y agolol you think people treat others they way they'd like to be treated...(pardon my childish language)
- shkkmo 9y agoCan you point me to a definitive source as to what websites that have access log that include IP addresses (which is pretty much everyone) have to do to be compliant? If there are steps that must be taken, who has to taken them? I've been looking, and I have found a bunch of contradictory explanations. My best guess is that if you have a disclaimer that says you log IP addresses for security purposes, you can keep your access logs indefinitely. (see: https://community.spiceworks.com/topic/2041760-access-logs-impossible-to-be-compliant https://community.spiceworks.com/topic/2041760-access-logs-i...) This seems like the sort of concern that should be clearly addressed with an official answer before the regulation takes effect.
- x0x0 9y agoHAHAHAHA, there is no such guide. Again, the GDPR isn't really a set of rules per say. It's some rules (eg on consent), plus some frameworks (legitimate interest balancing test). The country-specific privacy orgs are figuring out the balancing tests and are promising final guidance, like, totes any day now. Meanwhile, the deadline is 25 May.
- Silhouette 9y agoBackups of various kinds are in a similar position. The reason GDPR is a bad law is that its real effect is so ambiguous. Read literally, it imposes significant burdens on data controllers, particularly because of things like the right to erasure. Those burdens may be disproportionate particularly for smaller organisations that only handle a limited amount of data in the first place. The alternative, which I've noticed GDPR's defenders tend to favour as understanding has grown, is something to the effect that regulators won't actually enforce the rules in a draconian fashion and will only go after serious infringement in practice. But that's a dangerous position to adopt in legal matters, because ultimately it means if you go too far in complying when others don't then you are at a disadvantage, but if you don't go far enough then you are subject to being punished at any time, and there is no objective standard for how far we're talking about either way.
- shkkmo 9y ago> The alternative, which I've noticed GDPR's defenders tend to favour as understanding has grown, is something to the effect that regulators won't actually enforce the rules in a draconian fashion and will only go after serious infringement in practice. But that's a dangerous position to adopt in legal matters, because ultimately it means if you go too far in complying when others don't then you are at a disadvantage, but if you don't go far enough then you are subject to being punished at any time, and there is no objective standard for how far we're talking about either way. Exactly this. As a consumer, I really like most of the protections that GDPR provides and I want them to be widely followed and enforced. As a freelancer who works with mostly small clients, I really wish that there was clear, official communication on what sorts of common practices need to change (or not) and examples of solutions that small businesses can implement to be compliant. Just telling them to not worry because they're too small for enforcement actions isn't a good solution since it limits privacy protection and compliance to large companies.
- mfoy_ 9y agoSoftware development needs some sort of Iron Ring (https://en.wikipedia.org/wiki/Iron_Ring https://en.wikipedia.org/wiki/Iron_Ring) to remind us to be humble.
- magic-chicken 9y agoAs you can see in the article, it already exists in Canada. Some engineering schools like École de technologie supérieure (ÉTS) offers a 4 year Software Engineering program that enable you to become a member of the Ordre des ingénieurs du Québec. It's a self-regulatory body that governs Quebec's professional engineers. There is a ceremony where they give you an iron ring, mostly to remind you to be humble and to always consider the public interest first when making decisions. Can software engineers become P.E. in the U.S ?
- freeone3000 9y agoYes, but there's little point to it. There's a secondary exam, and unless you're going into a field involving safety-critical applications, they don't need P.E.s.
- tjohns 9y agoSoftware Engineers can theoretically become PEs, but it's very recent. Practically speaking, it's difficult right now. NCEES recently created a PE exam for software engineers in 2013, in collaboration with IEEE and IEEE-CS. However, it's up to state engineering boards whether or not to administer the exam. California does NOT yet the administer the Software Engineering PE exam.
- mywittyname 9y ago> Can software engineers become P.E. in the U.S ? Yes. Most CS/CE/SE programs in the USA are part of the school's engineering college and are ABET accredited, which is the governing body of professional engineering in the USA. To become an PE in the USA, one needs to first graduate from an ABET program, take the Fundamentals of Engineering exam, work for at least four years in their field of study, then they make take the PE exam. Now, almost nobody does this right now. Only 32 people took the Oct 2017 exams in Software, and Computer & Electrical Engineering. For reference, about 4000 people took the various Civil Engineering exams. There's really no incentive to become a licensed engineer the USA. I've never seen a job posting mention one at all. So I think the exercise would be purely academic (though, I'd love to hear from someone who has a license and uses it).
- 77pt77 9y ago> The only thing that GDPR wants from you is to handle others data with same RESPECT as you handle yours. Plus a minimum of 20M€ fine in case they don't think your "common sense" is good enough. For a one man shop that is not working under the legal protection an LLC or equivalent provides, this can be deadly!
- huwdiprose 9y ago€20mil is the maximum, and there are lower tiers for lesser infractions. That is a figure used to bring non-European companies who wish to trade in the EEA but not comply to the negotiating table. We rarely see the largest tier of fines here in the UK, I'd expect little to change there too. Reputational damage should be a focus of anyone concerned with risk here.
- _o_ 9y agoNot really true :) $20mil or 4% global revenue whichever is higher. $20mil is nothing for ggl/fb/... This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
- 77pt77 9y ago> I doubt some small local shop will ever get max punishment Why? It's selective prosecution, plain and simple. These things have a history of being selectively used to punish institutions for other reasons that are not easy to do using the law To the people downvoting, imagine the following scenario: Website promotes ideas the EU finds problematic. The EU wants to silence it but can't because of free-speech laws or any other constraint. All they have to do is find something trivial under this law and punish them for it, bankrupting the company. All of these "I hope the law will be applied reasonably" are dangerous because they give the state too much power.
- klokoman 9y agoNobody believes the legislators have ill intent. Then they find themselves ruined but waking up then is hard too.
- BjoernKW 9y agoIn principle, yes. The intention behind and the principles outlined by the GDPR are good. However, the devil's in the details, specifically in how these principles are supposed to be implemented. Some of these details are not quite clear yet. It's almost impossible to navigate these issues without getting at least some basic legal advice and investing a fair bit of time. Unfortunately, as often is the case with EU regulations these seem to be targeted mainly at larger companies or corporations, which can easily afford this because they have legal departments anyway. As a company that uses third-party services for data processing (which includes almost every piece of SaaS-type software) you have to sign a data processing agreement with each of those, which can mean considerable effort. Some suppliers unfortunately are not as well-prepared yet as they should be. Therefore now a company's processes continuing to run smoothly might depend on some third party getting their internal affairs in order. It's true they should've done this long before and one shouldn't continue to work with them if they fail to do so. Still, it's a problem you have to deal with. I agree that GDPR makes sense and it's a good idea to follow through with these measures. It won't be easy in each and every case though and it might be a bumpy ride at first, which is why I sincerely hope that in the beginning authorities will be lenient with parties that act in good faith.
- jopsen 9y agoOPs point is that if you act responsibly in good faith you'll probably avoid any issues, and likely be warned before they target you for maximum fines :)
- BjoernKW 9y agoI hope so. Unfortunately, that won't necessarily be the case. Small businesses have been specifically and routinely targeted by dubious law firms for not complying with certain regulations like legal notice requirements or disclaimers on websites. The EU and local as well as member state authorities also often are oblivious to problems smaller companies might have.
- x0x0 9y agoThat's heavily dependent on the regulator in question, and there's 30-ish of them. Since American companies are very unlikely to have a lead regulator, you will need to comply with conflicting rulings from each. In half a dozen languages.
- boredatwork 9y agoSure I delete files that I don't like, but I don't typically rewrite all my old backups to purge them from there too.
- SahAssar 9y agoA file does not really exist unless it is backuped, and it's not really deleted unless it is not backuped.
- ncallaway 9y agoThis is my biggest question about HIPAA and GDPR about deleting specific user records and data. How are others planning on deleting data from all backups. It seems like any automatic process that modifies all existing backups has the potential to accidentally corrupt all backups in the process. Is there any safe way to safely delete a record out of my prior database snapshots, or is there a reason I don't actually need to do this?
- leesalminen 9y agoThis has been the insurmountable issue for us, thus far.
- com 9y agoEncrypt the data element using a nonce, encrypt the nonce using a public key whose private key will be purged from your HSM/SCD/key management system on a scheduled basis. You will need to retain metadata about the key ID too. Don’t leak private keys, so you should generally use a decryption service if you need access to the data record. Handy to prove access too! That works and survives fairly intense audits at least in my experience.
- lawik 9y agoDo you maintain your database backups indefinitely? If they rotate out after a month or so you will likely be inside the realm of what GDPR considers reasonable compliance. The live data is removed ASAP and the data will rotate out from the backups in a reasonable time frame. At least from the legal advice we've had. We have no plans to retroactively fix our backups. But we will have to make damn sure that if we need to use a database backup we do not reintroduce user data that we've purged. For that purpose we will have to maintain a list of which users have been purged until the backups rotate out. According to the advice we've had, this is acceptable.
- pfarnsworth 9y agoThis is very self-righteous. At my company, we respect our customer's data immensely. What happens is that some non-PCI data (but still PII like email addresses) data leak naturally into our log files, and I've been told his means that we need to clear our logs of that as well. We use this for debugging and data analytics, and email address is our primary username, so it's a huge undertaking for us to make this shift. I've been told this requires us to clear tape backups as well. So it's not anything to do not respecting our customer data, it has everything to do with not seeing the unintended consequences.
- deleted 9y ago[deleted]
- njl 9y agoIf only it was that easy. A reasonable reading of GDPR makes standard web server logs (which contain IP addresses) a punishable offense, even if you don’t have a nexus in Europe. GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulators to smack around Google and Facebook. They probably deserve it, but the potential fallout for the rest of us is really going to hurt. Don’t get me wrong, treating user data with respect is the right thing to do. But we’re all going to be paying for this overly broad and under specified legislation for years to come.
- wglb 9y agoI don't think it is quite that bad. It is certainly less than going full ISO 27001, and less than a major breach.
- musage 9y ago> a continuous drag on developing new technologies Any and all of them? Because of anonymized IP addresses in server logs? I wouldn't even buy that when it comes to the web, but certainly not to mention talking about computers and software in general, or even "tech in general", whatever that would be.
- aeorgnoieang 9y agoWhat's an anonymized IP address? As others have pointed out, there is a sufficiently small number of IP (v4) addresses that any hash function output of them can be easily brute-forced nowadays. So the only 'anonymous' IP address is the one you never collect in the first place.
- deif 9y agoOnly without consent from the user. Previously it was an ethically grey area to be logging IP addresses anyway. If you are preventing malicious use, then that is allowed as long as you are not using that data outside of the bounds of the user's consent. If, however, a company is storing IP addresses to identify users without their consent and are found to be specifically targeting them without their consent, then that is a misuse of data. You are right that companies will be paying for this for a long time and it does take effort to comply, but if that's what it takes to protect user data, increase security across the board to prevent data breaches and kill off the players that never should be in the business to begin with then I'm all for it.
- cortesoft 9y ago> Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation. Ok, that is just silly. This sounds so much like the 'Why do you want privacy if you have nothing to hide?' arguments. It is very reasonable to both have a company that handle customer data responsibly AND have issues with the GDPR. Imagine if every time you walked down the street, the police stopped you and made you prove that you hadn't murdered anyone that day. You might get get annoyed at the 10 minutes it takes to prove our innocence. If you complained about the extra time and intrusion, would a fair response be "Every complaint about this check shows you don't care about murder" No, you can both agree with a goal of a regulation and disagree with the mechanism that they implement it. It is certainly NOT the case that 'the only thing GDPR wants from you is to handle others data with the same RESPECT as you handle yours'... they want you to DEMONSTRATE this in a particular manner. Those particulars are important, and we can disagree on them without it being some sort of moral conflict.
- _o_ 9y agoOh, so in construction business, you don't need to prove your plans are statically safe, you just build a bridge and no one cares until it colapses? Don't worry, you are far safer here, no one will ask you anything until it collapses. But after it does, you will need a proof it didn't happen becoase of you. That you did all you could. Is there something wrong?
- x0x0 9y agoIndeed, capturing IP addresses in logs is exactly like a bridge collapsing and killing people.
- cortesoft 9y agoI have lost 3 family members to logged IPs.
- jcranmer 9y agoActually, you don't need to do that proof. The construction plans need to be signed off on by certified (government-accredited but still fully private practice, not even necessarily a different company) engineer. But the government doesn't look at those plans and check your work. What happens instead is that you need to be inspected by the government before it's allowed to be occupied or put into use. And if it ever should happen that it does collapse, then the structural engineer who signs off on the plans faces criminal liability particularly in extreme cases (Kansas City Hyatt is the most memorable experience).
- timothycaldwell 9y agoIt's not easy at all to understand. I'm a developer and have spent 40+ hours in meetings with lawyers because the interpretation of the law isn't easy at all. There is a whole team of lawyers looking into this. 40% of my team is working on GDPR implementation. Just figuring out if users are allowed to use my service is hard. There is a different age of consent in different EU countries, and apparently some haven't even decided on an age of consent yet. What happens if I am in a country that has age of consent of 14, but then they vacation and use the app in a country that has age of consent of 16? We are required to offboard users if they aren't of the age of consent. What is the support flow for letting those users back into the app if they accidentally said they were born in 2016? What if the company owns multiple apps, and the user users the same OAUTH account to login into each app? If in one app they enter their birthdate as underage, now I have requirements to delete the user from all apps. My default mindset is to avoid collecting any data that I don't need so my app stores almost no info about where users are located. But EU regulations have told me I need delete all EU user accounts who don't agree to the new terms in X days after May 25th. Does this mean I have to go delete all user accounts who haven't logged in since a certain date since I can't differentiate EU vs non-EU? Those users aren't going to be happy. Some users log in through email so we are able to email them, but other users use phone number login where we can't contact them. We are potentially deleting huge numbers of accounts. We host our help center site using a third party service. Does that third party service happen to store IP address in the logs? Now I have to care about that as well. Lets say my company built an Apple TV or Xbox 360 app two years ago. There is a small group of dedicated users but it doesn't make us any money and we haven't updated it. Now we have to go build an interstital making them agree to new terms before they can use the app. None of the developers who built the app are still around, I guess we need to just delete the app now. It turns out that there were a bunch of Russian accounts who tried to manipulate the election and we only found out months later. Good thing this happened before GDPR. After GDPR all they have to do is claim they are in the EU, and then delete their account, and there data won't be completely unaccessible 30 days later. I am a big advocate for privacy and a member of the EFF for a decade. Maybe my company just already has good privacy practices, these regulations are making development much slower, without providing additional privacy benefits. If you want to see some change, I would think massive fines for data breaches would be the way to go.
- jcranmer 9y agoSentiments like yours are the reason why GDPR is problematic. One of the things that legal experts quickly realize is that there are as many definitions of common sense as there are people in the room. As this thread shows in great detail, there is wide variation in understanding what it's meant to cover. The real problem is that the regulatory agencies, in response to this confusion, are essentially refusing to issue any clarifications in guidelines. The GDPR is at risk of becoming a law that says "You have to follow my rules, but I'm not going to tell you what they are," which is counterproductive to its own ends.
- tensor 9y agoI certainly don't create a long living policy document for my own personal data though. There seems to be additional paper and process requirements above and beyond the technical aspects, at least according to the article.