4 ms·
To be fair there are no experts able to guarantee their advice is good. They often disagree as the law is incredibly vague. And the EU DPAs are not ready to app
by zerostar07 8y ago
To be fair there are no experts able to guarantee their advice is good. They often disagree as the law is incredibly vague. And the EU DPAs are not ready to apply the law. Relevant laws have not even passed in many EU countries: https://www.reuters.com/article/us-europe-privacy-analysis/european-regulators-were-not-ready-for-new-privacy-law-idUSKBN1I915X https://www.reuters.com/article/us-europe-privacy-analysis/e...
- ryanwaggoner 8y agoI am the first to agree that this is a terrible law, incredibly vague, overly broad, poorly written, etc. The difference between actual experts and people like Jacques is that credible experts recognize the complexity and will be honest about it. Granted, it’s in their interest to do so, but still, at least the better ones won’t lie and tell you it’s simple just because they wish it was. Not to mention accusing you of bad intent and doing shady things if you don’t quickly agree that the law is perfectly clear and simple and that any compliance costs are worth it if you’re honest. After all, only an evil person would avoid the EU market with the stated reason that the compliance costs seem too high or the law too vague, because random blogger Jacques already cleared that up for us :)
- jimnotgym 8y ago> terrible law, incredibly vague, overly broad, poorly written, Or it could be a well meaning law, that has been drafted in good faith to incrementally extend an existing directive, one that IMHO has worked rather well up to the point that organisations outside of the EU have felt they can ignore it, even when acting in EU countries. GDPR is certainly making overseas firms take our laws seriously now... It has been mentioned a number of times, but EU law is principles-based not rules-based like in the US. I can see how it might appear vague to US eyes, but to my eyes I see a flexible law that will live on while the technology changes. I also felt it was written in plain, straight-forward language, and not poorly-written at all, I personally can live without 'here-on-ins'. I guess if I lived in the US and had a similar law, and had US prosecutors I might be scared, but the law of European countries has survived on being principle based rather longer than the US has existed. I once had to compare and contrast both systems for an exam, and of course they both work in practice! I note however that Europe is a much less litigious place than the US, and I personally prefer that.
- ryanwaggoner 8y agoI actually agree with almost 100% of this. The EU should pass laws however they want according to whatever legal framework they want. And companies wishing to do business there should comply. I still think it’s a poorly written and vague law, but perhaps that’s just my distrust of bureaucracy speaking. My real issue with the law is primarily that the EU thinks that it can assert that it has global jurisdiction with regard to the GDPR. This is so undemocratic and dangerous, it boggles my mind that fans of the GDPR can’t see it. Just because you like the intent of the law doesn’t mean you can admit that it goes too far, or sets bad precedent, or is likely to be abused. If Saudi Arabia passes anti-blasphemy laws and says they apply globally if a citizen of theirs visits your website, should anyone care? GDPR is being taken seriously by firms with enforcement exposure. My hope is that every other organization in the world just ignores it. It’s a dangerous precedent. And then there’s my issue with the fans of the law who will read the above and come back with the vapid response: “well, if you’re not going to comply then clearly you’re shady and I hope you do go out of business.”
- henrikschroder 8y agoIt doesn't assert global jurisdiction, what makes you think that? If you have a legal or business presence in the EU, you will be affected, because that puts you inside the EU jurisdiction. Note that Facebook/Google/Apple/Microsoft/Amazon/Samsung/etc have a substantial presence in the EU; employees, offices, shops, data-centers, customers, which is why they are affected by the GDPR, and the EU is giving them the choice to either comply, or pull out. If you have a small business in the US, you can safely ignore the GDPR, because there are no avenues of enforcement against you, because you're not inside the jurisdiction. Non-US companies get sued in US courts all the time, and nothing comes of that either. > If Saudi Arabia passes anti-blasphemy laws and says they apply globally if a citizen of theirs visits your website, should anyone care? Everyone doing business with Saudi Arabia should care. Is this not self-evident to you?
- ryanwaggoner 8y agoIf you have a legal or business presence in the EU, you will be affected, because that puts you inside the EU jurisdiction. If only this were true. Under the GDPR, an EU resident sending their info to me anywhere else in the world apparently constitutes me doing business in the EU in their eyes. That’s their claim of global jurisdiction. Fortunately, they can’t actually enforce this, so I’ll be ignoring it, just like I would for Saudi Arabian anti-blasphemy laws.
- oldcynic 8y agoMost of us in Europe don't find it especially vague, poorly written or overly broad. I think most of us are firmly in favour of it, and not especially concerned by the effect on our companies, especially when we've already been doing some of this under current data protection. Personally I think it's an excellent attempt to bring some sanity back to our online privacy. It's perfectly readable and understandable by an individual. Though of course it's not perfect. What is? It's been fascinating and extremely educational to see in the numerous HN discussions how many from the US are managing to view it from entirely the opposite point of view.
- zerostar07 8y agoWrt to vagueness i have to respectfully disagree. Perhaps an opinion poll would help, but from what i 've gathered from Q&A forums that are frequented by europeans in the past weeks, it's freaking vaguety vague. to the point where it's not clear how broad it is at times. Maybe it reads fine if you are a "data subject" (i hate this term btw) , but if you actually need to comply its hard, even for the simple stuff that every website has. E.g. cookies, advertising, backups I 'm not even sure if the data subject can figure out what to expect from GDPR. E.g. Is HN compliant? Can you tell if a website you visited today is compliant?
- ryanwaggoner 8y agoMost of us in Europe don't find it especially vague, poorly written or overly broad. Yes, you all keep saying that, often while tripping over each other with contradictory explanations of when it applies and how to interpret it. Yes, truly well-written and not vague at all.