4 ms·
"The vast majority of internet services" I haven't seen a single service preparing to explicitly tell EU users to go somewhere else, except random comments on H
by tedeh 8y ago
"The vast majority of internet services" I haven't seen a single service preparing to explicitly tell EU users to go somewhere else, except random comments on HN claiming so. Also the EU economy is about the size of the US so can't easily be ignored fortunately.
Also, why does a company or anyone else "own" personally identifiable information in the first place? The logic is completely inverted and we seem to have all been OK with it in the first place. Why does a company like Facebook "own" what is mine from the beginning — is it just because it is in a row in their database? Is it because I once clicked OK on a TOS? Now I can revoke this consent and Facebook and others have to comply. Previously they could just tell me to FO. Sounds like a great win for users!
- downandout 8y agoAgain, large companies will have no problem implementing it. They have multi-million dollar budgets for lawyers etc. At first, most smaller companies won't turn away EU traffic, nor will they comply with GDPR. But as more companies become aware of the regulation and the extraordinary financial liability that comes with EU traffic, most outside the EU will simply turn away that traffic. It might take a few years or even a decade - but it will happen. It won't take too many horror stories about how small companies were destroyed by huge fines out of Germany, for example, to turn the blocking of EU traffic into standard operating procedure. The issue isn't really even about any desire on the part of companies to abuse personal data. It comes down to the many ways that even companies with the best of intentions can violate this regulation.
- AstralStorm 8y agoYou seem to be forgetting that small companies have small databases. Getting removed from a manually handled filling cabinet is easy. Add is from a manually managed database, even when it is backed up regularly. It is also trivial to enforce a routine manual scrub of small amounts of private data. The only people who might have trouble are "small" data resellers having millions of accounts of personal data. It is good they will have to comply.
- downandout 8y agoDeletion is one tiny part of this terrible law. I suspect that most of the trouble will come from undisclosed third party trackers that the site may not even know is there. For example, imagine a company uses an image from an image hosting company like imgur on some of its pages, and at some point the image host decides to start sending its own cookies. That completely innocent scenario could result in millions of dollars in fines for the site under GDPR. Because of this singular issue, all forums that have ever allowed users to post images from third party sites (which most do) will likely run afoul of the GDPR, simply because they will be causing tracking cookies to load that they don’t even know about - and this is just one of hundreds of examples of issues that will put massive swaths of sites in violation and make them subject to fines by revenue-hungry EU member states.
- AstralStorm 8y agoIf you did not know the breach has occurred, you're legally in the clear. Once you do know, you have some obligations. For bigger companies, you have to appoint a data protection officer who is supposed to know. (This includes big as in amounts of data too.) If you're using a third party service, you will have to use it with prejudice. No more randomly including J. Random noncompliant Ad Agency as a middle man illegitimate handler and washing hangs of it. Also URLs are perfectly fine as you're not processing the data. The thing that changes is that you have to specify which third party service you use and that it is externally managed. Probably link to their privacy policy and they also have to be compliant with GDPR. This will make it possible to actually get rid of the images and protect your privacy.