41 ms·
GDPR Hysteria Part II, Nuts and Bolts, Actionable Advice
- helpme420 8y agoThanks for the series of articles. I can't wait to see the rest of the world(especially the US) catch up with the visionary EU regulations. It's sad that so many Americans/Anglos dislike regulations so much.
- baxtr 8y agoI, too like more data privacy, but think for a second about this: who can afford more regulation? The giant corporations like FB, Google etc. The small alternatives will suffer. EDIT: take a look at that slide, google invested 40 human years for assessment alone https://twitter.com/winfriedveil/status/995951301132537857?s=21 https://twitter.com/winfriedveil/status/995951301132537857?s...
- deleted 8y ago[deleted]
- Nursie 8y agoThe big players are flagrantly disregarding this stuff and have been for a long time. This seems to me like an opportunity for smaller players to be better, and to build in privacy from the ground up.
- dsfyu404ed 8y agoThe small players can more easily pivot their business to not be burdened by the GDPR
- matthewmacleod 8y agoI don't think this is true at all. Compliance in large organisations will be harder than small ones – small organisations should already be fairly well aware of where their data is, and how to handle it. Larger organisations tend to have mountains of uncontrolled user data which nobody is in charge of.
- tzs 8y agoThe costs could be a big deal for small businesses. Take a business about as far away from data as you can imagine. For instance, a business that makes replacement knobs for antique radio restorations. They have a website with an online catalog and a shopping cart where you can order replacement knobs, pay online, and they ship the knobs to you. They collect your name and address for shipping, your email address to contact you if there are any questions or issues with the order and to give you order processing updates, and payment information. If this business is offering their goods to people in the Union, that data collection falls under GDPR, and they have to have a designated representative in the Union. I've not been able to find anything so far on (1) how some random small business in the US goes about finding someone to be their designated representative in the EU, and (2) what they will have to pay that person to take do so.
- jacquesm 8y agoThe chances of such a shop running their own shopping infrastructure is very small, most likely they will use some kind of partner for the whole shop setup, up to and including fulfillment and they'll be happy doing what they're good at: making knobs. And if they do run their own shopping infrastructure they obviously will have to deal with all the ins and outs of that, including operations, keeping the whole thing up-to-date and secured as well as compliance with the law.
- tzs 8y agoHow about customer support? Even if a small business has someone else run their cart, and handle order fulfillment, there is still a good chance they deal directly with customer support, which usually includes collecting and storing customer information. Won't that mean they are still under GDPR and still need to have a designated representative?
- jacquesm 8y agoYes, in that case they would have to have a designated representative. I'm working on that particular angle at the moment but it is a rather complex affair and I don't want to commit to this before I'm all lawyered up and read up on the responsibilities and the risks.
- josteink 8y ago> I, too like more flight safety/healthcare hygiene/safer cars, but think for a second about this: who can afford more regulation? As an end-user/customer, I’ll have the regulated version every single time, thank you. You can reframe this either way you like, but what it will come down to is that IT has so far been one of the few completely unregulated industries, with only its own merits to show for why such regulation shouldn’t be needed. So far it’s not doing a very good case for itself. People like Alan Kay has warned about this. If we don’t start taking our profession seriously (like doctors take not killing their patients seriously), someone else will. And then the future of programming will be legislated. If that’s how it all will turn out, that’s because we as a industry has deserved it. The GDPR is merely about basic decency and should only be considered a taste of what the future holds. Unless we ourselves show that we can act responsibly without further regulation. Edit: Ofcourse if you are the world’s biggest privacy-violater with 100s of thousands of employees worldwide working every day to mine and AI even more shit out of you, ofcourse trying to get GDPR-compliant will take some effort. That’s the whole fucking point. Smaller businesses treating user-data decently and with respect won’t have any such issues or conflicts of interests.
- jacquesm 8y agoThe people that feel that the GDPR is a terrible thing are going to be really upset if and when software liability will be targeted. This has to be the only industry where it is the norm to charge the customer to fix a defect that we ourselves created.
- yxhuvud 8y agoI'd rather think it is the opposite - that generally people will pay for fixing defects unless it can be proven that it was sold in an intentionally misleading way. "Oops, did that airport take three times the money compared to expectations to build? Time to pony up more or end up with a half built airport".
- baxtr 8y agoThat’s an interesting view. Do you own a business where you had to implement GDPR or is this theoretical? Oh, and did you know that GDPR also affects the work of teachers, solo entrepreneurs, doctors and the like?
- m-localhost 8y agoWhat I see is geofencing and consolidating of power (google, faceboo etc).
- frockington 8y agoAs an American I hope it never does. Governments stifling competition through regulation gives me an uneasy feeling. I think it may be a cultural difference. Europeans value safety more than innovation and vice versa. Possibly due to the extreme behavior we saw after '08 over here
- jacquesm 8y ago> Europeans value safety more than innovation and vice versa. This is quite funny considering you are writing this on the WWW, which runs on top of the TCP/IP stack. The WWW came out of CERN, the TCP/IP stack came out of DARPA. The web is at its roots a pretty global affair. This is not about 'stifling competition', this is about privacy.
- arcbyte 8y agoSeconded.
- scrollaway 8y agoExcellent post Jacques. This was well needed. Wish I had it a few weeks/months ago to point several people towards it... GDPR feels like the opposite of Y2K. Unheard of by most until very shortly before the deadline, underplayed by those who haven't researched it, and overplayed by many of those who have.
- tzs 8y agoNote that the requirement to have a designated representative does not apply to: "processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or". (See Article 27). Anyone know what counts as "occasional"? Also, the regulation says the representative must be in one of the member states where the data subjects are located. I know of some non-EU businesses that have just a handful of customers in the EU, scattered among a few member states. They slowly get new customers, and slowly lose old customers. Whatever member state they put their representative in, there is a decent chance that in a year or two all the customers in that member state will be gone. Do they have to keep changing representatives?
- jacquesm 8y agoOccasional: Not re-occuring regularly. So once per year but every year is not occasional. Once and then never again is occasional. In between: consult a lawyer, and if you can't afford that err on the side of caution. As for the whole designated representative thing I'm looking at solving that in a somewhat creative way, but this will take some time and preparation.
- thinkulum 8y agoWould you say a personal blogger in the US needs an EU representative if they're running a WordPress installation on a shared web host? I've been debating with myself whether I need to move my content somewhere like wordpress.com to avoid that requirement. The personal information I process comes from comments and web server logs, and I'm not sure that counts as occasional. On the other hand, I look at Article 3, and I'm not sure posting content on a personal blog counts as offering goods and services. Or do blog comments count as a service?
- downandout 8y agoSee recital 23 of the GDPR [1]. You do not need to comply with GDPR unless ”it is apparent that [you] envisage offering services to data subjects in one or more Member States in the Union”. The test for this is: ”Whereas the mere accessibility of [your] website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that [you] envisages offering goods or services to data subjects in the Union.” In English: Do not translate your site to EU-only languages (Italian, German, etc.), use an EU based domain extension, or create content or services that would be especially appealing to EU users, and GDPR will not apply to you. [1] https://gdpr-info.eu/recitals/no-23/ https://gdpr-info.eu/recitals/no-23/
- mercurialuser 8y agoEdge case, eu based travel agency serving eu citizens. They need to book an hotel in a far away country, in the middle of nowhere, asking for a kosher lunch (religion) or wheelchair (health)... legal basis is contract fullfilment, article 49.1.b and .c seems to cover this cases but to me it is still very muddy situation.
- deleted 8y ago[deleted]
- jacquesm 8y agoBefore you get into edge cases I'd focus on the bulk. That's a far more productive way to spend your budget.
- Animats 8y agoGoogle and Facebook will now directly control most Internet advertising. All those intermediary organizations that live under a rock, passing tracking data around, have a big problem - they have no connection to the user. So they can't ask for permission to do anything. They have no way to do so. Google has made some big changes in how they deal with third parties in the advertising chain.[1][2] Third party trackers are being cut off, and advertisers are being encouraged to dump them and switch to Google Ads DataHub. Google is frantically trying to get user consent for tracking, popping up a deceptive message on every Google search result page. That popup asks you to "log in" to Google. They just assume everyone has a Google account. Without that permission, Google can only serve you "non-personalized ads". [1] http://www.thedrum.com/news/2018/05/01/publishers-hit-out-google-s-imposing-gpdr-policies http://www.thedrum.com/news/2018/05/01/publishers-hit-out-go... [2] https://adexchanger.com/platforms/google-sharply-limits-doubleclick-id-use-citing-gdpr/ https://adexchanger.com/platforms/google-sharply-limits-doub...
- x0x0 8y agoThe iab has a CMP proposal to create consent dialogs on page load. See eg http://advertisingconsent.eu/ http://advertisingconsent.eu/ and an implementation by Quantcast https://www.quantcast.com/gdpr/quantcast-choice-self-serve/ https://www.quantcast.com/gdpr/quantcast-choice-self-serve/ . I don't actually expect this to help much, but they're trying. I also think you will see some acquisitions of crappy publishers with lots of pageviews so that advertisers can get an end-user touch point.
- jacquesm 8y agoThere will be some places where this will have a huge impact. For instance in the cases of real time bidding on advertising through open exchanges based on data about the user. I think it is also an opportunity though, we might be able to roll back some of the more annoying ad-tech and get users to selectively switch off ad blockers again. Another option is that more parties will switch to advertising space sold directly to media buyers without all those intermediaries (much like it used to be until we started to track everything and anything). Once you are logged in to Google you can turn off the targeting of the ads through this link: https://adssettings.google.com/authenticated https://adssettings.google.com/authenticated Slide the slider at the top right of the page to the left and confirm the change, targeted ads gone. This takes about 10 seconds or so if you are already logged in to Google.
- ocdtrekkie 8y agoAfter reading a large number of GDPR-related articles and summaries, I've generally come to the belief that if you are doing the right thing with user data, it is unlikely GDPR is going to cause you to suddenly start suffering. If you aren't selling user's data, you keep it reasonably secure, and they can delete their account, you are probably good. Most of the services you use will already be GDPR (and Privacy Shield) compliant, and it is easy to list your cloud and payment providers and link to their statements of compliance. And almost everything a user could ask for, if you don't have an automated solution to, you can generally comply with by checking your email and responding accordingly, so for small userbases, this is hardly really even an issue. Furthermore, as far as actual enforcement goes, the EU is not going to shut you down or put you out of business on a technicality. They are going to take you out if you show flagrant disregard for your users. This is going to hit the Unroll.me's of the world, not your average web forum.
- zerostar07 8y ago> If you aren't selling user's data I am curious when people mention this: Who literally sells user's data ?
- ocdtrekkie 8y agoUnroll.me literally sold Uber data about Lyft receipts in people's Gmail boxes.
- Animats 8y agoAn innocent. Go watch this video from the Internet Advertising Bureau.[1] [1] https://www.youtube.com/watch?v=-Glgi9RRuJs https://www.youtube.com/watch?v=-Glgi9RRuJs
- zerostar07 8y agoI know how advertising works, but i don't see 3rd party ads as directly "selling the data of the users". You include an ad that is visible inside the page. At most, you are sharing the page view with an ad company, but you are not communicating any of the data you have collected to the ad server. It's up to them to create a profile/track. "Selling access to your audience" is not the same as "selling your own data to an ad company".
- hartator 8y ago> There are countless examples a short search away of such violations, I’m not going to catalogue them here [...] I think it's important to cite precise examples. If we're asking developers of small websites to give up a significant amount of their time to be compliant, we have to be rock solid into the why it is a good regulation. For example, most of the recent privacy violations in the news - FB leaks, Snowden leaks, etc. - seems untouched by GDPR.
- Asooka 8y agoQuestion: What if a US company puts up a clickthrough agreement on their site that reads "It looks like you're accessing this site from the EU. This site is not compliant with EU law and cannot be accessed from within the EU. If this is an error and you do not reside within the EU, please read the following: ... very long legalese about claiming that you are definitely not an EU citizen and the EU-seeming IP address is in fact a VPN or proxy, so you are definitely not subject to EU law. In case this agreement is signed fraudulently, damages will be ascertained by $US_STATE court (wherever company HQ is) ... [ ] I agree, under penalty of perjury, that the above applies to me. In the case that this agreement is signed fraudulently, I agree to pay the damages awarded by $US_STATE court and waive my right to sue within the US." Can this company continue doing business as usual, given that any EU user who tries to invoke GDPR will subsequently be fined and potentially deported to the US for hearing?
- Animats 8y ago"Consent: If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding."[1] So, no. [1] https://gdpr-info.eu/art-7-gdpr/ https://gdpr-info.eu/art-7-gdpr/
- Asooka 8y agoI'm not saying the GDPR won't apply, the company will still have to spend resources on complying with GDPR requests. However, any user who invokes the GDPR will be in violation of the CFAA and face very seriouos consequences. The question is more "can we engineer a MAD situation where users won't dare invoke GDPR in fear of the consequences"?
- Animats 8y agoNo, because the user can both have a government agency do it for them, and delegate the right to apply the GDPR to a nonprofit advocacy organization.
- hartator 8y ago> Data that is not associated with a particular individual is not ‘in scope’ when it comes to the GDPR unless that data can be re-associated with that individual. I wonder if that make the ETH and BTC blockchains illegal to have nodes in Europe from now on. Like if I post a series of transactions that are linked to me, can I ask all the EU nodes to remove this information?
- narrator 8y agoAlso, what if a person engaging in illegal activity wants their data removed? Can they just have their financial transaction history erased and subsequently unavailable to the authorities? GDPR almost seems designed to allow for destruction of evidence and coverups.
- salvar 8y agoFinancial transaction history no, precisely because there is a legal requirement to retain these. Other data? Of course they can. You shouldn't even concern yourself with why that person wants their data removed. It's their data.
- trendia 8y agoI would like to know how this will affect Microsoft. I run a Pi-Hole [0] to redirect all advertising-related queries to a black hole. When tracking the most-blocked domains, Microsoft is at the very top [1]. For instance, when I enter "Office" into the start menu, Microsoft immediately sends a ping to bing.com and Microsoft's telemetry servers. That is, Microsoft is sending all of the data entered into the start menu to Microsoft's servers, even when using the 'Pro' version and with 'full' telemtry off. When it was first detected that Microsoft was adding telemetry calls to all compiled programs in Windows [2], Microsoft said it was mostly for event debugging for programmers. Now I'm not so sure -- look at your Microsoft account privacy settings to see that Microsoft tracks when you open applications. (They say on the page that not all data is shown there). Unforutnately, there is no way to opt out of this. You can "disable" full telemetry, but you still have to opt into "Basic" telemetry, which still sends your advertiser ID, the programs you run, and the queries you put into the start menu. I'm concerned that Microsoft is not going to stop here. They have a real incentive to capture as much data about you as they can -- they currently earn about $1 billion in advertising through Bing.com search queries. Unlike Google or especially Facebook, however, it's much more difficult to opt out of Microsoft's tracking -- so many people depend on Microsoft Office or other Windows programs that I can't fully switch to Linux. I don't know how this is acceptable through GDPR. There are so many problems with what Microsoft is doing: 1. There is no way to opt out of telemetry 2. There is no way to see all of the data that Microsoft has collected 3. Microsoft has severe lock-in because so much software is written for Windows-only 4. Microsoft has an incentive to increase their telemetry, not decrease it. [0] https://pi-hole.net/ https://pi-hole.net/ [1] https://imgur.com/a/MbjtYJe https://imgur.com/a/MbjtYJe [2] https://old.reddit.com/r/cpp/comments/4ibauu/visual_studio_adding_telemetry_function_calls_to/ https://old.reddit.com/r/cpp/comments/4ibauu/visual_studio_a...
- flukus 8y ago> and the queries you put into the start menu. I've long suspected this but couldn't prove it. Aside from the privacy implications I've found it makes windows unsable. Basic operations can take several seconds and if you're on an intermittent connection (which developers never test on) the menu can be frozen for over a minute. > however, it's much more difficult to opt out of Microsoft's tracking -- so many people depend on Microsoft Office or other Windows programs that I can't fully switch to Linux. This comes up a lot but I think we need to change how we think about it. Yes there will be pain and yes there will be things you could do before but can no longer do, but we need to treat it like ripping off a bandaid and embrace the pain rather than hope to mitigate it.
- hartator 8y ago> not from the perspective of those that happen to come in posession [sic] of data on those subjects. Their interests are legitimate, but secondary. Until EU reaches mass debt and mass unemployment, and wonders why every tech startups are in the US, or in Asia.
- kazen44 8y agoif you think the economy is entirely based on VC's and startups i have news for you... also, being GDPR compliant gives companies a competitive edge. I'm utterly shocked at the HN bubble about what constitutes a proper bussiness model.
- frockington 8y agoIt absolutely does not give companies an edge. If you are a small company, the fine itself could cripple you before you even factor in the legal time, money and effort
- jacquesm 8y agoYou are still stuck in the 'small companies will get fined millions of euros for small infractions' mindset.
- _rpd 8y agoYou make such strong statements with great certainty. Are you going to be paying people's fines when they rely on your advice?
- jacquesm 8y ago> Are you going to be paying people's fines when they rely on your advice? Following my advice will substantially reduce the chances of people having to pay fines. That's a public service. If you want me to assume liability for that then you are clearly asking for more than I can give you. But rather than trying to play word games with you I'd like to point to the track record of the various EU data protection entities and you'll see that on the whole they are doing a very good job. Finally, as for paying people's fines, if you break the law you are liable for the fine, long before you will be fined (unless you are really making a mess of things) you will be warned so that you are able to come into compliance. If you ignore that and then you are fined you really have only yourself to blame.
- Tharkun 8y agoBeen wondering about this for a while now, maybe someone in this thread can shed some light on this? What about processing httpd access logs to count visitors? Most tools use IP addresses to count unique visitors. Does that mean this now qualifies as "processing personally identifiable data"?
- jacquesm 8y agoThat's just fine. You are collapsing the IP addresses into a count and that count can not be reversed back in to the IP addresses you started out with. And then, after you're done with your log analysis (and any security related work you need to do with them) you can dispose of them. There are some instances where it may make sense to have a very long log history but I'd be careful to properly document the need for that unless that need is an obvious one and easily explained. Anything longer than a year would be outright wrong and anything shorter than 30 days will definitely be ok.
- hartator 8y ago> ignore requests for deletion, correction or insight from your users This is an obvious slippery slope, and it's probably going to be challenged by the U.S. 1st amendment. It's already an issue with the previous "right to be forgotten" law which was way more limited in scope. [1][2][3] [1] http://www.dailymail.co.uk/news/article-3156779/More-280-000-people-ask-Google-right-forgotten-request-MILLION-pages-wiped-search-engine-s-results.html http://www.dailymail.co.uk/news/article-3156779/More-280-000... [2] https://www.telegraph.co.uk/technology/google/10833894/Politician-paedophile-and-GP-claim-right-to-be-forgotten.html https://www.telegraph.co.uk/technology/google/10833894/Polit... [3] https://www.wired.com/2014/07/google-right-to-be-forgotten-censorship-is-an-unforgettable-fiasco/ https://www.wired.com/2014/07/google-right-to-be-forgotten-c...
- jacquesm 8y agoWhy are you polluting threads about the GDPR with countless low quality top level comments?
- hartator 8y agoI am replying to your arguments, I think you don't realize how evil a law like GDPR is. Many small projects will get killed while privacy abusers will just find a way to avoid the law. You still have to point to one example where this law will make someone's life better.
- jacquesm 8y ago> I think you don't realize how evil a law like GDPR is. I've read the law end-to-end several times, I do not think it is evil. > Many small projects will get killed while privacy abusers will just find a way to avoid the law. This is Europe, not the United States. > You still have to point to one example where this law will make someone['s] life better. It's already making my life better. For instance, this email I just received: -- Let's stay in touch! As many of you know, the new General Data Protection Regulation ("GDPR") requirements go into effect on 25 May 2018. Your privacy is very important to us, so please consent by clicking the button below if you would like to continue receiving updates from YouPic on announcements, insights and potential opportunities. Yes, let's stay in touch! Sent with from YouPic Viktor Rydbergsgatam 14, Gothenburg, Sweden -- From a company that I've never done business with, that has absolutely no right to spam me and that I've tried many times to get them to stop spamming me with zero result. So no, let's not stay in touch, fuck off with the spam, the targeted advertising, the profiles, the retargeting, the selling of profiles, the stealing of contact lists and so on.
- syntheticnature 8y agoIn my not-so-copious free time, I help maintain the online back-end for a membership organization (about 1500 members). I've found little guidance on GDPR for a volunteer-based membership organization, but have managed to piece a good bit together. I was feeling pretty good about the work done versus compliance, hand-wringing from other officers notwithstanding, e.g. if we delete old member records, someone might rejoin and get a different member number, and what if they wanted to keep the original? Now, though I'm wondering about the discussion e-mail lists we have and if we need to auto-prune archives. They have folks' real names and such in them, after all, from participating in discussion. (I also wonder how this affects big email lists, e.g. linux-kernel)
- beberlei 8y agoYou are not excluded from the law as volunteer organization. As far as deleting old member records and public archives, it depends on what consent members have given before. Membership information, especially receipts for subscription must be kept usually for 10 years for bookkeeping purposes. As for public posts, unless the members withdraw their consent (Excercise Right to be Forgotton) i don't see why. They knew then that the posts are public? edit: you must formalize this with a privacy policy though, what data you keep, what type of consent (article 6) and for what reason you need it, if you haven't done so yet. Then ask every member for approval of the policy.
- deleted 8y ago[deleted]
- syntheticnature 8y agoNot excluded indeed, figured that out late but not too late. The lists are not public, but only visible within the organization. I think part of my concern is not knowing how easy it would be to rip a given set of messages out of the archive in Mailman. I don't expect it is likely Right to be Forgotten will be exercised, but it sounds to be a bear if it does get exercised.
- alkonaut 8y agoI was under the impression that GDPR did not differentiate between offline and online data. If that’s true, then the recommendation about backup in the article doesn’t work (you can’t store PII on offline backup media in the basement and not comply with erasing the data there too on request). It also means that deletion requests can’t easily be automated. Chasing down records on archive media is likely going to involve physical labor. It’s even the case that for write-only media it’s impossible to delete, you’d have to re-write a backup without the offending data. All this of course suggests this isn’t the case, that offline data must be out of scope. But why isn’t this clearer?
- jacquesm 8y agoStoring data offline is not meant as a way to get the data 'out of scope' but simply to reduce the effect of a breach. It shows that you have taken active measures to reduce the impact of a breach which will definitely get you points for trying. As for backups, I am going on the assumption that they are properly encrypted, I will update the article to that effect.
- diaz 8y agoGdpr completly applies also to offline data. Companies are being required and have lawyers going over inside data on physical cabinets and educating and auditing who has access, how, when and proper measures of protection to all of it. I personally know lawyers involved in the process and companies going over that auditing effort. I'm very glad they are being forced to think on how to deal with my data even for the case when they are mh employer and have my very personal data round on physical paper.
- DanBC 8y agohttps://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/ > The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: > the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; > the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing; > the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2); > the personal data have been unlawfully processed; > the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject; > the personal data have been collected in relation to the offer of information society services referred to in Article 8(1). I think this means your backups are ok, unless the data was for a child under the age of 16. But I also think that if you have encrypted your backups, and you make robust attempts to remove the <16 year old's data when you restore the backup, that the regulators are going to be satisfied.
- josecastillo 8y agoSince there seem to be a lot of knowledgable folks in these threads, I have a question about GDPR's impact on decentralized or federated social networks like Diaspora[1]. On these networks, users can create a profile on any server, and be connected with users on any other server via a federation protocol[2]. All the ideals of user control and data portability are there and central to the Diaspora project; but technically, the underlying protocol involves passing users' posts and comments from one server to another. This seems like it would fall afoul of guidelines against passing data to third parties, and the same technical constraint seems to be fundamental to other federated services like Friendica[3] and Mastodon[4]. I'm really curious how the GDPR would affect services like this, especially as someone who's quit Facebook and is looking at decentralized networks as an alternative. [1] https://diasporafoundation.org https://diasporafoundation.org [2] https://diaspora.github.io/diaspora_federation/ https://diaspora.github.io/diaspora_federation/ [3] https://friendi.ca https://friendi.ca [4] https://joinmastodon.org https://joinmastodon.org
- narrator 8y agoBlockchain is also a problem.
- jacquesm 8y agoThat's a good point and I will research this because I also would like to know exactly how this influences such networks. I consider them a positive development, and as such would like to know exactly what the impact is. From the top of my head it would require the software to implement the various GDPR principles, and it would be wise for operators of servers to verify that they are not exposed. Better yet if EU residents connect to EU servers and let the federation take care of the connections across legal boundaries. That's smart for a variety of non-GDPR related reasons too.
- btilly 8y agoOne challenge is that everyone's reading is different. What reading will regulators have? And what reading will they have in 6 months vs now? For example in this article it is assumed that everyone needs a data protection officer - the only question is whether you want someone full-time, or you want to share one with several other companies. However when I read https://gdpr-info.eu/art-37-gdpr/ https://gdpr-info.eu/art-37-gdpr/ it seems that most companies don't fall under 1.a or 1.c. The question mark is 1.b, the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale. If you're just recording transactions, clearly you are not monitoring them. If you're running a data broker, clearly you are monitoring them. If you're running queries against your transactional data to decide who to send a marketing email to..is that monitoring? "Find all people who put something into a cart yesterday and then didn't complete the transaction." I don't think of that query as monitoring, but I can see how someone else might.
- BinaryIdiot 8y ago> One challenge is that everyone's reading is different. Really? I haven't heard of people who have vastly different opinions in what specific pieces of GDPR means. Do you have any links? > For example in this article it is assumed that everyone needs a data protection officer What? Where is that assumed? The first thing it talks about are the reasons you may need one and nothing about assuming everyone needs one.
- zerostar07 8y ago> Do you have any links? check reddit.com/r/gdpr. Every other question has been answered with both a yes and a no.
- btilly 8y agoSearch for the phrase, "Do I need a (dedicated) Data Protection Officer?" You will see that the only two options that he discusses are having a dedicated Data Protection Officer versus a designated Data Protection Officer. With the difference being whether they are your full time employee doing nothing else, versus a part time responsibility. Neither in the article nor in his comments here does he admit the possibility that it might be a role that you don't actually need filled.
- nick45674748 8y agoMany years ago the world figured out that "Medical school is a requirement for a doctor career" [1]. Somehow our ancestors did not have the brilliant idea to just put a fine to any hospital that breaches medical protocols and send patients to death. The first web browser was released in 1993. Any computer science professional born before 1970 had not seen a web browser as a student (because it did not exist). 25 years after 1993 the EU decided that a law that regulates the profession with fines (GDPR) is enough. Good luck EU! [1] https://www.learnhowtobecome.org/doctor/ https://www.learnhowtobecome.org/doctor/
- chx 8y agoI already commented on the previous post feeling the author has no idea what he is talking about but this nails it: > What’s important with any law is - besides the letter of the law - what the spirit of the law is, the laws intent. This very conveniently forget the GDPR will not be interpreted by a single authority in Brussels but rather by the relevant authority in every single EU country. Whatever the lawmakers intended, who gives a hoot? I can pretty much guarantee the Hungarian NAIH will see this as a fantastic cash grab opportunity. (I am a dual Canadian-Hungarian citizen, I know my birth country all too well.) Despite all this "pah-pah, it'll all be fine" there is not even a guidance much less any law describing who shall be fined for how much. Spirit of the law protecting you from Hungarian bureaucracy , good luck Chuck. The courts will eventually curb this madness and set some best practices but meanwhile those who got fined excessively will stay bankrupt. Don't be the patsy. At this time, unless you are a big enough company to have a sizable legal department do not do business with the EU. This is not hysteria, this is just good business sense.
- jacquesm 8y agoYes, I saw your previous comment. If you feel that you can discard a whole article because you find one line in it that confirms your prior belief then that's fine with me. But I've been in this business for long enough and have seen EU regulators at work often enough that there is no mystery to me about how this will play out. What will happen is that the small fry will be ignored unless they cross the lines in very visible ways. Larger companies and companies with more risky models will be more at risk of having the regulators take an active interest in them. Large companies because there is a large chance of complaints to the regulators, companies with more risky models because they will be acting against the spirit of the law even if they will do everything they can to comply with the letter. If you don't believe that's how it will work that's entirely fine with me but about 30 years of data confirm my point of view.
- chx 8y ago> If you feel that you can discard a whole article because you find one line in it that confirms your prior belief then that's fine with me. The entire spirit of these articles are completely misguided because the adverse reaction to GDPR is not hysteria. Here's the unique nature of this which makes it a recipe for disaster: 1. Every business interacting practically any way with European citizens is affected 2. The potential fees for breaching a very complex regulation are unprecedentedly high. 3. Determining the actual fees for each breach is in the hand of every EU country, including some which today wouldn't be admitted into the EU.
- venning 8y agoThere are a couple mentions in this article that reference marketing emails and consent and the GDPR affecting them. I'm pretty sure this is wrong. The Privacy and Electronic Communications Regulations (PECR) govern marketing communications, not the GDPR. Wired did a good breakdown of how these two are getting confused recently: http://www.wired.co.uk/article/pecr-gdpr-emails http://www.wired.co.uk/article/pecr-gdpr-emails
- deleted 8y ago[deleted]
- justinator 8y agoPECR is merely a directive. It's not law, it's not enforceable.
- DanBC 8y agoWhat does the R in PECR and GDPR stand for, and why do you think these are different? PECR is the implementation of http://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32002L0058 http://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:320... which is European law. There are a number of regulatory actions available to eg ICO if companies are violating PECR. https://ico.org.uk/about-the-ico/what-we-do/taking-action-privacy-and-electronic-communications-regulations/ https://ico.org.uk/about-the-ico/what-we-do/taking-action-pr... > There are a number of tools available to the Information Commissioner’s Office for taking action to change the behaviour of anyone who breaches the Privacy and Electronic Communications Regulations (PECR). They include criminal prosecution, non-criminal enforcement and audit. The Information Commissioner also has the power to serve a monetary penalty notice imposing a fine of up to £500,000. > These powers are not mutually exclusive. We will use them in combination where justified by the circumstances. I'd agree that the lack of enforcement of PECR certainly makes it feel like just a suggestion.
- justinator 8y ago> I'd agree that the lack of enforcement of PECR certainly makes it feel like just a suggestion. If it's not enforced, then what was its point? I think it's best to think of the GDPR as its replacement, rather than thinking of them side by side, to be honest. Wired getting something wrong is... believable.
- anfogoat 8y agoSlightly off-topic: Is there a short history of the GDPR somewhere? History might be an odd word choice given that it isn't even in effect yet, but I'm simply referring to something that documents and chronicles what parties or individuals set the regulation in motion, the public discussions around the regulation, and what third parties were consulted in the process etc. As an EU citizen, I'd like to know what or whom I should direct my ire towards.