17 ms·
I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-
by tquinn 8y ago
I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document
http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679 http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
just blocking them doesn't seem like that bad of an idea, especially with the fines involved.
I think the things that bother me is:
1) A College student working on a side project with no revenue are treated the same as some massive multi-national.
2) It's a foreign requirement that feels like a violation of sovereignty. Most business/startup owners complain about there being too much domestic regulations, now we have to worry about things outside of our own countries -- that also can come into conflict with our domestic tax authorities on things like data retention. An international agreement would be entirely different.
3) The GDPR requires clear and concise language, but have done nothing of the sort when writing the regulations. For most websites outside of the EU, could they not have produced a concise 1-2 page infographic produced by the regulators themselves?
- Tomte 8y ago> A College student working on a side project with no revenue are treated the same as some massive multi-national. And why not? The result/harm is the same. It doesn't matter a bit whether a company's web site is handing its visitors' data over to Facebook or a "private site" does. The side project or the private site always have the option of not participating in the adtech frenzy. But of course they want to participate (free money!), even if they find out much later that almost no money is coming their way.
- manigandham 8y agoNo, it's not the same. The lack of proportionality is precisely why the UK/EU is such a hard place to conduct business. These rules don't stop anything about ads, they just make them less targeted. Not a big deal, but it will increase the costs of serving users and thus decrease the total amount of commercial projects started.
- Tomte 8y agoI find it funny to claim that the US could be more proportionate than the EU. Less targeted ads are exactly what we need. That's what the regulation aims for! Your argument is like claiming that unfortunately, due to car dafety regulations, we cannot enjoy as many fatal accidents as we once did. And to make my point of view clear: not all businesses deserve to exist. We as society decide which business models and behaviours are okay. "Decrease the total amount of commercial businesses started" cannot ever be a persuasive argument.
- manigandham 8y agoThis issue isnt about privacy... Nobody reasonable is arguing that it's a bad idea to let customers control their data. The actual issue is that the rules are vague and thus create a lot of confusion and waste that affects all companies, while not providing any real protection against the massive conglomerates that abuse data in the first place.
- knuththetruth 8y ago>The #1 complaint about ads is that they are not relevant, so this does nothing but increase that problem. The #1 complaint about advertising is that in 2018, it has evolved into a shadowy, insecure brokerage of surveillance data that it obtains using all kinds of under-handed tactics. If the GDPR curbs this in the slightest, it will be a net positive for people of Europe.
- manigandham 8y agoIt will not curb it. Facebook and Google who control 90% of the ad industry will already have consent from billions of people by the end of the day, and the increased regulation will only increase their market share as the safe and reliable avenue for advertisers and further strengthen their monopolies and data activities.
- Tomte 8y ago
- solomatov 8y agoIt's not the same. There're companies which intentionally collect and exploit private data. There're companies which are just behaving negligently with users data. There should be different penalty for intentional and negligent violation.
- askmike 8y agoAnd there is! The law applies to all but fines/punishment are handled on a case by case basis.
- solomatov 8y agoAnd there's a lot of room for choosing the fine/punishment. There should be some rules, i.e. fines for intentionally violating privacy of millions of people should be very different from fines for unintentional violation of privacy of 10 people.
- takeitto 8y ago> It's a foreign requirement that feels like a violation of sovereignty. Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws. EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local companies were forced to respect privacy. Respecting privacy is just not very competitive/profitable at the moment. Your viewpoint pushed to the extreme (sorry if you don't recognize your original view): China selling counterfeit goods or unsafe toys to the US, and feeling like any push-back is messing with their sovereignty of lax copyright -, trademark -, and health laws.
- eli 8y agoWhat does it mean for a website to "cater" to just my home country? The internet doesn't know political boundaries and most sites cater to all visitors on some marginal level.
- takeitto 8y agoThe internet doesn't know, but e-commerce/data business pretty darn well knows where their customers/users are situated. The old web was mostly static websites. We spoke of visitors. The new web is app-ified/interactive, walled off to logged-in agreement-abiding geolocated users, and even a single logged-out "visit" broadcasts this to 100s of trackers who will remember your every move online.
- eli 8y agoOdds are whatever you were using on the old web to measure visitors would be a data processing activity under GDPR.
- ForHackernews 8y agoIf you aren't collecting and storing PII, you have nothing to fear from the GDPR. Even if you are, you're fine as long as you only collect what you legitimately need to offer your services.
- black_puppydog 8y ago> It's a foreign requirement that feels like a violation of sovereignty. It must feel horrible, now that the US is on the receiving end of this for a change... ;)
- ShroudedNight 8y agoNotwithstanding any opinions of the contents of the directive itself, as Canadian citizen, the schadenfreude of the United States getting its comeuppance is not nearly worth another foreign federal government imposing its will on our domestic activities.
- takeda 8y ago> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information into that. The treatment of privacy is one of issues where it's pretty much impossible for individual protect from, GDPR tilts the scale in favor of individuals.
- spullara 8y agoWeb servers are non-compliant out of the box because they all by default log and store IP addresses of visitors.
- oneplane 8y agoThere is nothing non-compliant about that. You seem to misunderstand essential vs. data hoarding for advertisement purposes. If you were to keep that data forever, sell it to third parties or profile users based on that logging data, not tell them about it, then yeah, you'd be violating the GDPR. For normal operation system logging is pretty much a requirement for essential operation. That includes most properties of a connection like IP, UA, date, time, URI etc.
- Semiapies 8y agoWhich is the answer I see all of 50% of the time. Then, I see "Well, actually it is non-compliant because yadda yadda". My company isn't going to hire international compliance experts to review the operations of every public website we run, and we don't have any that need European visitors. So, best to just block them.
- oneplane 8y agoBut what about national compliance experts, do you hire those? Because you have a lot more national compliance on your plate than international...
- viraptor 8y agoI don't get the complaints about how hard GDPR is and having to understand it all. If you're based in the US, have you read the actual DMCA document? CFAA? California S.B. 1386? TWEA? ADA? Or at least any interpretations of them and validated that you comply? If not, then worrying about GDPR which is mostly not enforceable in the US sounds disingenuous.
- themacguffinman 8y agoWho are you arguing with that thinks DMCA was a great idea but GDPR isn't?
- viraptor 8y agoNot saying anyone thinks it's a good idea. I'm saying I haven't seen that many comments, annoyed people, and general discussion about other laws, which actually impact US people and can be enforced there. I'm guessing they also ignore those laws, because of posts like this one. If you're running a business complying with regulations, you likely already know how to block a country. I mean, you keep track of the current embargoes and block relevant countries, right?
- themacguffinman 8y agoBecause this is a thread about GDPR, and the GDPR is not the same as the DMCA in either impact or scope. Take your whataboutism elsewhere.
- oneplane 8y ago> " It's a foreign requirement that feels like a violation of sovereignty." How about you look at what bs comes out of the US gov't? That is the worst foreign requirement and violation of sovereignty so far, and it keeps on giving.
- ajuc 8y ago1. when you open a restaurant nobody cares you're a collage student. You have to have all the checks and permits to serve people food. It's not because somebody hates small businesses, it's because the right not to be poisoned is more important than the right to do business hassle-free. Why should internet be different? 2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency worldwide, and argues in length for years whether wiretapping its citizens is OK, because everybody agrees wiretapping others is perfectly fine. USA forces poor half of the world to follow ridiculous copyright law, including software patents and art becoming public domain after a century or more. There's no good will earned there, so don't expect a free pass cause of your feelings. Want to serve customers from other countries - have to obey the law there. 3. they probably could. Still - I'm sure there will be "GDPR as a service" soon. Maybe some libraries, frameworks and standards how to handle personal data will finally be created? This should have been done decades ago.
- SimbaOnSteroids 8y agoEquivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.
- ajuc 8y agoMost of the time there will be no poisoning. Most of the time they will only collect e-mail address. The law is designed to cover pessimistic case. You can get sick because of food poisoning, you can be robbed because your identity was stolen. I don't think my comparison was dishonest.
- hk__2 8y ago> Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison. Nobody’s saying both are treated equally under the GDPR. The law stays the same, the way it’s enforced is adapted to the case, like any juridiction. Whatever the situation, you always get a warning before being fined.
- Sangermaine 8y ago>1) A College student working on a side project with no revenue are treated the same as some massive multi-national. If the side project uses personal user data, then there is no reason to treat them differently.
- andrepd 8y agoYou are speaking as if the European Union spit out this legal document and nothing else, when in fact loads of supplementary material have been released, for consumers as well as for enterprises. Of course, the actual act must be written in formal legal language. EDIT: Example: https://ec.europa.eu/justice/smedataprotect/index_en.htm https://ec.europa.eu/justice/smedataprotect/index_en.htm
- philipodonnell 8y ago> 1) A College student working on a side project with no revenue are treated the same as some massive multi-national. I hear you, but the argument is that the data doesn't care who caused the leak. A college side project leaking an SSN does the same amount of damage as a multinational leaking an SSN, so the law is going to want them to treat them equally seriously.
- baryphonic 8y agoMy understanding (I could be wrong - IANAL and I haven't read the 80 pages) is that GDPR takes a somewhat countervailing view. SSN data breaches would be treated the same way as, say, whether someone likes the Beatles. The problem with GDPR from my perspective is its Draconianism. This is by the way the same problem with the various restaurant analogies. It makes some sense for the health department to inspect large restaurants. It would make no sense for them to subject neighborhood cookouts to the same degree of scrutiny. GDPR seems to be based not on actual harm that could occur based on invasive, sketchy or otherwise bad data storage practices; instead, it seems based on a subjective idea that people have "fundamental rights" to various forms of state-mediated protection in relation to technology. Rights are unequivocal and almost entirely uncompromising.
- cm2187 8y agoA college student working on a side project probably shouldn’t hoard personal information if it doesn’t care to protect it.
- geocar 8y ago> I think the things that bother me is: > > 1) A College student working on a side project with no revenue are treated the same as some massive multi-national. That's false. The GDPR repeatedly refers to evaluating the risk with regards to various decisions. The ICO even has separate guidance for small businesses and big businesses. > 2) It's a foreign requirement that feels like a violation of sovereignty. Most business/startup owners complain about there being too much domestic regulations, now we have to worry about things outside of our own countries -- that also can come into conflict with our domestic tax authorities on things like data retention. An international agreement would be entirely different. This one I can appreciate, but perhaps look at it from our point of view: You're violating our laws that protect our citizens. Why would we possibly have any sympathy for that? > 3) The GDPR requires clear and concise language, but have done nothing of the sort when writing the regulations. For most websites outside of the EU, could they not have produced a concise 1-2 page infographic produced by the regulators themselves? The GDPR is easier to read than many US laws, and you don't have to read it anyway. The ICO has written extremely high-quality guidance for most businesses which will suffice. It should take no more than a few hours to determine how your business would be affected. https://ico.org.uk/for-organisations/business/ https://ico.org.uk/for-organisations/business/
- oliv__ 8y ago"You're violating our laws that protect our citizens. Why would we possibly have any sympathy for that?" No one forced your citizens to come to my website.
- geocar 8y agoAnd in the situation that it’s no more complicated than a EU citizen visiting a website that doesn’t sell to European businesses, that’s probably fine. But when you want to trade with Europe, you have to abide by our standards for human rights.