6 ms·
> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are sim
by hekfu 8y ago
> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every website using social media buttons and GA.js, I don't think it matters in the slightest.
> It feels like all these tiny companies, one-man shops, and early-stage startups are going to be collateral damage to a regulation designed to stop facebook and google from knowing a horrific amount about everyone. In fact, it feels like a regulatory moat that will do very little to impede any big tech company while forcing me to do twice as much work for any side project I try to develop.
If you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights
> There's so much smugness about the GDPR being a "good reflecting moment", etc. which makes me think that people who support the GDPR believe that there's no way detractors could disagree with it in good faith or for good reasons.
I think it's mainly a difference in viewpoint: this is my data for me. Not yours. GDPR makes it easier for me to enforce that. From my perspective I don't care about you violating my rights "in good faith", just like most people don't cares if you trespass on my property and steal something "in good faith".
- strken 8y agoIf you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights The problem is not the work that the GDPR requires, the problem is the work I'll have to put into understanding the GDPR. I think it's mainly a difference in viewpoint: this is my data for me. Not yours. This is the part that I don't understand. If I own a shop, and you come in and buy something, you have absolutely no right to demand that I forget your face and your purchase. In the real world, it's not your data, it's my memory. If I go home and write in my diary that today hekfu bought lots of broccoli, you don't have the right to come to me in five years and demand that I remove all mention of you from my diary at my own cost. I don't understand the concept of data ownership, because it does not align with how I understand the real world to work.
- powvans 8y agoIf I go home and write in my diary that today hekfu bought lots of broccoli, you don't have the right to come to me in five years and demand that I remove all mention of you from my diary at my own cost. I asked this question in a comment [1] here on HN a few weeks ago. There were affirmative responses that yes, the shopkeeper should in fact be held to account for keeping notes on who came into his store. [1] https://news.ycombinator.com/item?id=16509598 https://news.ycombinator.com/item?id=16509598
- Spivak 8y agoThis is largely because the law doesn't care about implementation details. If a grocery store had a system which meticulously logged every customer that came into their store, when, and what they bought (i.e. loyalty card profiles) then we have to deal with issues related to privacy and data protection. Doing the same thing with pen and paper won't be seen as a meaningful difference.
- ryanwaggoner 8y agoMany of these people would happily give their government the power to wipe your memory if the technology to do so existed. It's insane.
- henrikeh 8y agoWhat makes you think that? Why do you intentionally spread absurdities?
- lagadu 8y ago> you don't have the right to come to me in five years and demand that I remove all mention of you from my diary at my own cost. I hate to break it to you but yes I do: by doing business within the EU market you're accepting that. In fact you're accepting that the very same way that you're accepting that you can't store all your clients' credit card/cvv numbers that are used on your store.
- 8y ago
- Bizarro 8y agoYou can't have a legitimate opinion on whether GDPR is a good thing or not, because you don't event understand what data is.
- JoshuaEN 8y ago> If you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights A server 'processing' (which seems to include using it in any way, not just storing [1]) your IP address appears to fall under the GDPR[1], and said server would be in violation of the law unless its processing falls under one of the exemptions. The main exemption appears to be getting the user's explicit consent, though there's also this super vague exemption: "for your organisation’s legitimate interests, but only after having checked that the fundamental rights and freedoms of the person whose data you’re processing aren’t seriously impacted." [2] In general, it seems very hard to avoid the GDPR because what is considered 'personal data' is extremely broad. Maybe I'm misunderstanding something. --- [1] https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-constitutes-data-processing_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [2] https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/legal-grounds-processing-data/grounds-processing/when-can-personal-data-be-processed_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- jdlshore 8y agoYeah, you're putting too much emphasis on consent. It's only one of six lawful bases for processing data, and in fact the one with the most stringent rules. I used "legitimate interest" as my lawful basis for logging IP addresses and website usage information. From the UK ICO's guidelines [1]: "It is likely to be most appropriate where you use people’s data in ways they would reasonably expect and which have a minimal privacy impact, or where there is a compelling justification for the processing." There's a three part test: 1. Identify the legitimate interest: ensure the security and stability of my systems. 2. Show that processing is necessary to achieve it: need to know when and how the site is used in order to troubleshoot problems and detect abuse 3. Balanced against individuals' interests: We pseudonymize logins so usage information is not obviously related to specific individuals. There is no sensitive data on the site that can be revealed by usage data. The retention period is short which further limits what can be revealed. Now, people here on HN might nitpick my logic, but fortunately they're not the regulators. I'm confident that, in the very unlikely event that a regulator even notices my little businesses, that I'll be able to correct any mistakes before fines come into play. [1] https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- mcguire 8y agoI have a blog. No ads. No revenue. 1. I have been using Google analytics for their entertainment value. I assume that's verboten now. 2. I assume the IP addresses in my logs are PII. Should I shut off logging?
- YtvwlD 8y ago1. No, but you shouldn't need to store PII. Simply disable cookie usage and enable IP address anonymization in Google Analytics. 2. You can simply exclude IP addresses from logging.
- zenhack 8y ago(standard IANAL disclaimers) 1. yeah, probably. 2. There's a comment elsewhere in the thread to this effect, but short-term logging for the usual purposes of managing stability/security of a system almost certainly qualifies as legitimate interest. Don't keep the logs indefinitely, but I figure nginx's defaults with a week's retention period is quite reasonable. The relevant authorities also have a track record of giving people warnings and time to fix things, so especially for something so trivial, I'd basically just make a good faith effort and not stress about it.
- closeparen 8y ago> PII GDPR has no concept of PII. Personal data is anything relating to a natural person. It's not just an identifier like an address or phone number.