9 ms·
How do you handle developer computers with possible client data on them, even semi-anonymized? Or when communicating issues on the live server, you might transf
by datamingle 8y ago
How do you handle developer computers with possible client data on them, even semi-anonymized? Or when communicating issues on the live server, you might transfer client information to other stake holders to debug issue. Are you tracking that communication. Where does the communication data reside, perhaps on a server outside of the EU?
There is a lot of complications that arise if you think about the second order/third order consequences of the law.
- gerdesj 8y agoI have keyed in and deleted so many efforts at an answer to your question that I have given up and find myself merely asking: "Have you actually read the regs?" http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679 http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... My reading of them finds no second/third order anything. The regs are surprisingly clear. I forgot to mention that unless you are trying to abuse EU citizens in some way then you have no problems. A useful side effect of the internet is that deciding whether someone is an EU citizen or not is tricky. That means that most companies have decided to treat all citizens in nearly the same way: For you as a private individual, a foreign power now provides you (indirectly) with way more "rights" than you might have had in the past on the internet. Have a read of the regs, please. The first few paras are a bit "we the people" but then, that is what is required. Then go through the articles. Read them as a person first and then consider them as a company or whatever you do later.
- sebleon 8y ago> surprisingly clear This is an 88 page document with extremely dry language. Just confirming your assertion will be time consuming. No wonder many American services would rather shut out EU users than comply.
- bardworx 8y agoThis is a silly and downright crude comment. My mortgage contract was 56 “dry” pages and I found time to read/understand it, to the best of my ability. If you own a business, the cost of reading this document is about 2 days (with consideration for googling terms). To disenfranchise a whole continent because you are inconvenienced is ridiculous. Put it a different way: are you too busy to read docs/specs of the technology you are using or will you abandon it because specs are too dry? American services are just busy because they are doing their best to keep the lights on. Within a week, the handful of companies will comply. They’re just cautious because they have to pay folks and don’t want to make a silly mistake that will shut down their business. Edit: structure
- gerdesj 8y ago"This is a silly and downright crude comment" - easy mate. My ISO 27001 docs are a bit dry as well and I wrote the bloody things as well as the sob ISO 9001 ones. In my opinion you absolutely hit the nail on the head with this: "If you own a business, the cost of reading this document is about 2 days"
- sebleon 8y agoHa, I actually thought the comment was relevant for an article on blocking EU users with Cloudflare. This regulation calls for legal expertise, trusting google to save on fees seems risky for a business. In all seriousness, biz owners should shell out for expert advice for compliance, or stop doing business in the EU. Google and Fb have already seen litigious groups claim $9.3B in fines on the first day[1]. There will certainly be a cottage industry of lawyers going after online businesses that have erred with GDPR. [1] https://www.cnet.com/news/gdpr-google-and-facebook-face-up-to-9-3-billion-in-fines-on-first-day-of-new-privacy-law/ https://www.cnet.com/news/gdpr-google-and-facebook-face-up-t...
- lovich 8y agoThose groups don't get to keep the fine money? What is with all the disinformation about people sueing companies for GPDR violations like it's a civil court issue and one side gets damages? People can refer an issue to the regulators claiming that the GPDR has been violated. The regulators will determine if they believe the regulations have been violated and whether it's a large enough violation to enforce. If fines are levied they go to the government and are intended to be punitive, hence the percentage of revenue as the max fine so that you can't just ignore the regulation by being rich. No individual or group other than the government is going to make money off of this, and the government has to balance the loss in taxes and cost to enforce against any gain from a fine. This whole kerfuffle about the GPDR has just shown that american companies will lose their fucking mind if they have to follow anyone else's rules and can't just lobby the US government to force their laws on everyone else.
- deleted 8y ago[deleted]
- anonymouz 8y agoAre there no laws in the US?
- lovich 8y agoNot if you are rich, and a many small business owners labor under the delusion that they will be the next Gates or Zuckerberg
- gerdesj 8y ago"This is an 88 page document with extremely dry language" It starts along these lines after the usual intro: "The processing of personal data should be designed to serve mankind The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality" I'll grant you that lacks a certain something but the language is compatible with another well respected charter of rights that you should be more familiar with. FFS, do you not notice the similarities!
- bcoates 8y agoI'm guessing you're hinting at the Universal Declaration of Human Rights? It's not well-known or well-regarded in the US.
- mcguire 8y agoDon't forget the brilliant and deeply meaningful paragraph 37: "A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings."
- Marazan 8y agoEven without any context that seems pretty clear.
- CaptainZapp 8y ago"No wonder many American services would rather shut out EU users than comply." Good bye and good riddance. And I don't really care if the door hits you in the ass. If Instapaper, to name an example, wouldn't do shady shit with user data, there would be no reason at all to forgo the European market.
- closeparen 8y ago>I forgot to mention that unless you are trying to abuse EU citizens in some way then you have no problems. Half of commenters are making this assertion; the other half are asserting it's a damn good thing that small companies will be eviscerated for insufficient seriousness, whether or not they are doing anything abusive. Some of you are necessarily wrong.
- matwood 8y agoI could argue that not protecting my data constitutes abuse.
- Spooky23 8y agoI don’t know GDPR inside and out, but I have worked at places (not military) where I could be held criminally liable for misuse or negligent disclosure of PII. The answer to “How do you handle...” is that you get your shit together. Separation of duties, build and configuration standards, no customer data on random laptops. When I was in high school, I worked at a sandwich/coffee shop. The precious commodity in that store was cash. We didn’t leave cash on a counter, or on a roll in our pockets it was in a locked register. When there was more than $500, we withdrew down to $250 and put the cash in a safe. At the end of the night, we put the cash in a locked pouch and two of us walked to the bank and put it in a dropbox. Data is no different, just more complex.
- gerdesj 8y ago"The answer to “How do you handle...” is that you get your shit together." Yes it is
- fanzhang 8y agoAnd if getting your "act together" is a substantial cost for small companies, no matter? The word choice almost presumes the conclusion, that data privacy rules are obvious, and cheap, and akin to just washing hands after using the toilet. Every regulation has costs and benefits. I also would love to have better worldwide privacy at no or little cost, but the fact that people are blocking the EU shows that some companies just don't see this to be the case. And they're voting with their feet. EU citizens should accept the fact that if they support the law, they will further data privacy protections, which are good, and they will face the music if some innovation leaves or whatever compliance costs may come with it.
- Spooky23 8y agoData privacy isn’t trivial, but the core concepts are pretty straightforward. Like cash, data is both an asset and liability. The business model of tech insulates the investors completely from liability, so there is no incentive to self-police. The contempt shown for us collectively as users and people is what triggered the regulatory backlash. The 2016 electron demonstrated that better than anything why this is important.
- jholman 8y agoIf you have developer computers with client data on it, semi-anonymized or not, I want you fined until you stop. What the hell is wrong with that hypothetical business? It's like restaurants putting the toilet in the kitchen. Shut the business down!