4 ms·
If you're not collecting any information "interfacing with the regulator" means replying to their email by saying "we're not collecting any information". (Assum
by aninhumer 8y ago
If you're not collecting any information "interfacing with the regulator" means replying to their email by saying "we're not collecting any information". (Assuming they even got that far, given that they'd likely take a look at your website and notice you aren't collecting any information.)
I'm not sure what's risky, expensive or time consuming about that.
- JumpCrisscross 8y agoConsumer says “I think you’re lying” and forwards to their national data regulator. (This is as simple as writing an e-mail.) Data regulator now asks you questions. You must respond. Hopefully they agree with you. But maybe not! Twenty-eight regulators appointed by different political groups are a complex system. You will need to gain expertise on them or hire someone with it. All I’m saying is that time and money might be better used elsewhere. Particularly by someone just making side projects.
- aninhumer 8y ago> Twenty-eight regulators appointed by different political groups are a complex system. You will need to gain expertise on them or hire someone with it. All I’m saying is that time and money might be better used elsewhere. Particularly by someone just making side projects. If you're not collecting data, then all of this is irrelevant. You just say "I'm not collecting data". There's no nuance here.
- JumpCrisscross 8y ago> There's no nuance here This is your interpretation. Many prominent lawyers disagree. In any case, convincing a regulator that you are not, in fact, collecting data could be harrowing, distracting and expensive. The risk of incurring those costs probably isn’t a smart one to take for a hacker or very early-stage start-up.
- aninhumer 8y agoSo in this hypothetical scenario, for some reason the regulator looks at your website, which presumably has no personal information inputs, no tracking analytics etc. and which you have asserted collects no personal information, and they decide that you're still somehow collecting information, and for some reason hounding your low traffic website is the best use of their limited resources.
- JumpCrisscross 8y agoTaking that risk (of a regulator mis-interpreting something and needing clarifications, again and again, or worse, mis-interpreting something and getting hostile) across the EU’s twenty-eight members is a good one for Facebook. Probably not for a hobbyist.
- aninhumer 8y agoWhat exactly is the risk to a hobbyist here? Even if we assume a completely bizarre and pathologically incompetent regulator that somehow ends up zeroing in on some tiny website which exhibits no evidence of violation, the hobbyist might have to... delete their website?
- JumpCrisscross 8y ago> What exactly is the risk to a hobbyist here? Have you ever responded to a regulatory enquiry?
- tome 8y agoIf you have then perhaps you could share your experience more explicitly. It would be helpful to clarify your point of view.
- hartator 8y agoSo, we’re hoping bureaucray will save ourself from itself by its innefiency?
- hartator 8y ago> If you're not collecting data, then all of this is irrelevant. You just say "I'm not collecting data". There's no nuance here. How do you prove you are not collecting data? If your use default configs of Apache, or Nginx, your access.log is probably infringing GDPR. It’s impossible to prove you’re not collecting this without an extensive audit.
- RasputinsBro 8y agoIsn't this true for literally all regulations and laws on the planet? Which bit is specific to GDPR? If you're accused and you're unlucky enough that the regulators/police follow up on the accusation, you're going to have to answer to them. Exercise some critical thinking please.
- JumpCrisscross 8y ago> Isn't this true for literally all regulations and laws on the planet? No, it’s not. Comparable statutes in the U.S. are HIPAA or the Securities Act is 1933. Most laws require, to kick off an expensive process, someone to (a) pony up to start a lawsuit or (b) convince a public prosecutor to take on the case. Dedicated regulators are established where (a) and (b) aren’t working. Most dedicated regulators consider consumer complaints. But the response rates are reasonably low and not mandated by law. (The best complain-and-investigate regulatory regimes avoid their incumbency-promoting effects by limiting oversight of new entrants. This incumbency bias was not taken into account in the GDPR’s drafting.) If GDPR looks identical to other laws, in the EU or U.S., to you, you may want to speak with your lawyer about it.
- RasputinsBro 8y ago> Most laws require, to kick off an expensive process, someone to (a) pony up to start a lawsuit or (b) convince a public prosecutor to take on the case. Seems like a lot of red-tape just to enforce some laws. Why wouldn't you want to lower friction for law enforcement? > If GDPR looks identical to other laws, in the EU or U.S., to you, you may want to speak with your lawyer about it. Don't worry about my lawyer, mind your own business.
- dang 8y ago> Exercise some critical thinking please. That breaks the site guidelines by crossing into incivility. Could you please not do that? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- jasonlotito 8y ago> I'm not sure what's risky, expensive or time consuming about that. "replying to their email" https://jacquesmattheij.com/so-your-start-up-receive-the-nightmare-gdpr-letter https://jacquesmattheij.com/so-your-start-up-receive-the-nig...
- aninhumer 8y agoThe article is about someone who is collecting data. If you're not collecting data, you can just reply saying you don't have any data about them.