5 ms·
To push back on the premise a little: The intention behind the GDPR is good, but it still hasn't gone into effect yet, and it remains to be seen what the long-
by chimeracoder 9y ago
To push back on the premise a little:
The intention behind the GDPR is good, but it still hasn't gone into effect yet, and it remains to be seen what the long-term effects of it are. It's really premature to draw any conclusions about its effectiveness, and history provides us with countless examples of far-reaching regulation that either failed to have the desired outcome, or in fact ended up exacerbating the very problems that it aimed to solve.
With a law as massive as the GDPR, it's going to take several years to really get a sense of what steady state will look like, and there are all kinds of ways it can backfire. I hope it won't, but there definitely is a strong, unfounded bias in discourse towards assuming that the GDPR will succeed in the goals that have been projected onto it.
- p49k 9y agoWhile I don’t disagree, I wonder how much harm we should allow our own citizens to endure in terms of the abuse of their data while we wait for someone else’s experiment to conclude.
- briandear 9y agoCould you point me to some examples of actual harm that people have endured for abuses of their data? Preferably not just single-instance anecdotes, but actual data on the harm that is occurring? Theoretically “protecting” people is good, but protecting them from what specifically? Health records are already covered by HIPAA, so other than health, what needs more protections? For example, collecting MixPanel or Google Analytics data from a blog — what’s the actual risk of that data? Very interested in real examples and not just hypothetical fears.. What problem is the EU law solving? Have people on Europe been suffering harms until now?
- jimnotgym 9y ago> Google Analytics data from a blog This is not covered by GDPR, it is a fair use and anonymous. HIPAA is not a widespread standard outside of the US People have lost out due to credit card details having been stolen. PCI compliance is a contract between merchant and bank, and not statute law, and therefore we have seen colossal breaches (like Talk Talk ISP) that are hard to punish. The cost of these breaches currently falls on other merchants who have to lose out to fraudulent car use. Next big co that looses thousands of cards, I really hope they get the top fines, as it is other companies that have to pick up the bill for their actions.
- _red 9y ago>I wonder how much harm we should allow our own citizens to endure in terms of the abuse Those same citizens that voluntarily agreed to the EULA? Do you also support the 'War On Drugs' on the same premise?
- icebraining 9y agoIf the GDPR was a War on Drugs, it would be one in which neither the users or the small time dealers/employees have anything to fear, only the gang leaders/shareholders. I'd support that War on Drugs.
- jimnotgym 9y agoYou can't opt out of the law in a EULA (under UK and AFAIK European law) Much of what is in GDPR was already illegal under the 1995 regulation, just hard to enforce on US companies
- stordoff 9y agoSeems like somewhat of a false equivalence to me. People (largely) know the risks of drugs, and are knowingly taking the drugs. Data is often gathered unknowingly, or used for unknown purposes, and people don't know the risks/potential uses of that data. It also doesn't remove the ability to agree to the use of data (it just must be actual consent to the purposes of use), so it's more akin to a War on Drugs that targets the supply of impure substances, but allows the supply where the user knows exactly what they are getting.
- phicoh 9y agoI'm not a lawyer, but it my impression that the main thing that is different with the GDPR is the threat that it will actually get enforced. In discussions about the GDPR I see things that are part of Dutch law for years, in some cases dating back to the 1970s. In practice nobody cared. In extreme cases the data protection authority would say something. But they were mostly understaffed.
- icebraining 9y agoI don't know about the Netherlands, but here in Portugal, they're pretty responsive. After someone complained, one of my neighbors got fined for posting PII in the building's lobby.
- jimnotgym 9y ago> I'm not a lawyer, but it my impression that the main thing that is different with the GDPR is the threat that it will actually get enforced I think you are dead right. GDPR is an incremental modernisation of the 1995 EU regulation. There have been a number of cases recently that have shown that Facebook, for instance, have been breaking the current EU law, but the national governments (Germany, Belgium recently) have had a hard time enforcing it in any meaningful way. GDPR will allow national governments to enforce their existing laws. If you are a US company who was breaking, for instance, the UK's Data Protection Act 1998 then I have very little sympathy if GDPR now breaks your business model. Breaking the law, but exploiting jurisdiction is not the kind of competitive advantage I will stand up for. BTW you can't opt out of the law in a EULA.
- avar 9y agoHow will the GDPR allow EU member states to enforce pre-GDPR law? How was it simultaneously law and unenforceable before?
- stordoff 9y agoAs I understand it, the existing Directive has to be implemented by member states in domestic law. This makes it difficult for one member state to enforce action against a company incorporated in another. As a Regulation, the GDPR is directly binding and can be enforced at the EU level, rather than just at the national level. In some ways, it makes it easier to comply, because you just have one set of rules rather than multiple national implementations of the Directive.
- sbuk 9y ago> but it still hasn't gone into effect yet Actually, it’s been in effect since April 2016, the information commissioners across the EU will be enforcing the regulations from 25 May of this year.
- kd5bjo 9y agoAll of the discussion I've seen has been around the right to erasure. The disclosure provisions could have a large effect on employer-employee (or potential employee) relations, or none. I'm not sure what, if any, of interview notes, performance reviews, or discussions about who to let go in a redundancy are "personal data" of the employee. I'm also not convinced anyone else does either.
- TheCoelacanth 9y agoI think it's pretty clear that they are the personal data of employees. What is less clear is to who has a legitimate need to have that data and for how long (and hence who can keep that data without consent).
- kd5bjo 9y agoIf they're all the employee's personal data, then the employee has a right to a copy. So companies can't legally keep this kind of thing secret anymore -- you're entitled to know what interviewers said about you to management before you weren't hired for a job, what your coworkers said about you that factored into your performance review, email threads about their side of your salary negotiation, etc?
- M2Ys4U 9y agoThat is already the law, under the 1995 Data Protection Directive.