3 ms·
I 100% agree. The problem is that practically rights have to be reasonably respectable (able to be respected) by people at little cost to them. Like, it's not d
by epicmellon 8y ago
I 100% agree. The problem is that practically rights have to be reasonably respectable (able to be respected) by people at little cost to them. Like, it's not difficult for me to not steal something from you. Erasing everything I ever wrote down about you is difficult.
But also:
> Seems like Europe has decided that privacy and control of data personal data is something they want.
The problem here is that governments allow people to claim rights without bearing the cost of that claim (or at least hiding the cost).
- grive 8y ago> Erasing everything I ever wrote down about you is difficult. It is not difficult to avoid storing data you don't need. You don't need a user phone number? Easy, don't ask for it. Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this argument. Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.
- jimmaswell 8y ago>It is not difficult to avoid storing data you don't need. Access logs for one thing are pretty unreasonable to force people to avoid storing. >Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry. Can you point out a specific example of somebody suffering actual damages from this "abuse?"
- Dylan16807 8y ago> Access logs for one thing are pretty unreasonable to force people to avoid storing. Store them for a limited time, it's not hard.
- jimmaswell 8y agoNot "hard" for us, no, even if an unnecessary burden. Now go make some small veterinary clinic with no "computer person" on hand, with a small website they had set up years ago that lets you schedule appointments, figure all this out. They'll probably either stay uncompliant or have to drop the website.
- Dylan16807 8y agoThat's a shame, but it's a side effect of anything ever that requires an update. Any small business commissioning a site in 2019 will get something that's compliant, so it's not like this is a permanent drain. Sometimes it's important to update regulations, despite the inertia of existing implementations.
- jimmaswell 8y agoThis attitude reminds me of a quote: "Some of you may die, but it's a sacrifice I am willing to make."
- Dylan16807 8y agoBetter than the idea that we can never change any law because someone will have to adjust to it.
- xevb3k 8y agoRunning a single server for a small business is hard anyway they’re occasionally going to need support. As the first offense only seems to result in a warning, they have a chance to figure things out. Then is asking their webdev to schedule a cron job to delete logs really such a burden?
- grive 8y agoCambridge analytica is a good example. I guess considering this abuse may be different from a US customer point of view, but for my european sensibility, this is definitely abuse. Furthermore, that Facebook could harvest ghost profiles that could be used in this manner is problematic. I think it is certainly possible to find cases of identity theft resulting from PII that were leaked in security breaches, made easier by overreaching data collection.
- DanBC 8y ago> Erasing everything I ever wrote down about you is difficult. Why do you think this is required by GDPR? Here's the actual bit of law. Note how many exceptions there are. https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/ It's not surprising you fear it so much if you think it forces you to do all the stuff you've said. What is surprising is that almost everything you've said isn't in GDPR or has been exagerated beyond recognition.
- xevb3k 8y agoYour statement makes it sound like the GDPR applies to individuals doing everyday activities (or draws an equivalence). Just for clarity, I looked it up and it doesn’t appear to: “This Regulation does not apply to the processing of personal data: (...) by a natural person in the course of a purely personal or household activity;" So, it really only applies to companies, or if you’re processing a large amount of user data for a hobby project. That being the case, it doesn’t feel like the bar to being able to respect the law is so very high. But I’d be interested in counter examples.