8 ms·
I can't honestly agree. (re: ambiguity of interpretation, and cost being limited only to privacy-violating business models) Two reasons. 1. HN discussions the
by existencebox 8y ago
I can't honestly agree. (re: ambiguity of interpretation, and cost being limited only to privacy-violating business models) Two reasons.
1. HN discussions themselves. Literally EVERY TIME this comes up, you see a massive back and forth from various crowds of GDPR; some of whom swear that it's perfectly comprehensible even as significant portions of the conversation are interpreting the same points in a variety of ways. (Are IPs PII? What exceptions can be allowed? What falls under "security requirement"? What forms of data are associated PII? What sort of deanonymization is sufficient? IS it sufficient? are some common questions I saw in the past, not even getting into the wonderful world of third party data processors.) This seems like enough pragmatic evidence that a (to give the benefit of the doubt) educated and professional community hasn't reached consensus, so to say there's a variety of interpretation seems very fair.
2. I implemented GDPR for a small corner of a notable BigCo. I do not consider myself an expert, but I certainly got my marching orders from experts, (The legal teams who interpreted the document and evaluated the implementation methods) and the sheer amount of horsepower put behind finding an interpretation we believed and were confident in was staggering. Granted this is something where we _really wanted to get it right_ but if it were really trivial to interpret I question if the process would have been as intensive as it was. (To preempt the inevitable; our (my team's) business model has _literally nothing_ to do with your data, but we had many of the same confusions/questions that I saw from companies who did, so I'd be hesitant to say that the burden isn't somewhat widespread.)
- JumpCrisscross 8y ago> The legal teams...and the sheer amount of horsepower put behind finding an interpretation we believed and were confident in was staggering You shouldn't be getting down voted. I just went through a GDPR compliance review. We have a service model which is incredibly serious about customer confidentiality. We don't sell ads and, to my recollection, have never even bought them. Still required an army of lawyers. Two top London law firms ended up agreeing to disagree on major points, ultimately concluding the Polish data regulator would probably rule one way and the French the other. Complying with the spirit of a law doesn't mean complying with the statue of it. With GDPR, it's the latter that's a pain in the ass.
- hotdog97 8y ago> Two top London law firms British lawyers using this situtation to squeeze money from nervous US companies. Yeah, that sounds completely implausible.
- jsendno 8y agoWhat were the major points?
- derefr 8y ago> Complying with the spirit of a law doesn't mean complying with the statue of it. With GDPR, it's the latter that's a pain in the ass. I've never understood why people try to comply with the text of a new law that doesn't have case-law under it yet, rather than the spirit. Surely, the first time anyone gets sued for noncompliance of the text of GDPR, when they are compliant with the spirit under which GDPR was issued, case-law will be created that "bends" the interpretation of the text more toward the spirit?
- JumpCrisscross 8y ago> I've never understood why people try to comply with the text of a new law that doesn't have case-law under it yet Continental Europe uses civil law [1]. Case law is less relevant than it is in the U.K. or United States. More broadly, people try to "comply with the text of a new law" to avoid becoming the precedent. (Even if you prevail, it's distracting and expensive.) > Surely, the first time anyone gets sued for noncompliance of the text of GDPR, when they are compliant with the spirit under which GDPR was issued, case-law will be created that "bends" the interpretation of the text more toward the spirit? Surely? Based on what? For anyone with material revenue, that basis will be legal advice. [1] https://en.wikipedia.org/wiki/Civil_law_(legal_system) https://en.wikipedia.org/wiki/Civil_law_(legal_system)
- Mirioron 8y agoBecause SMEs can't afford a legal case.
- sfifs 8y ago
- dijit 8y agoYou've had sizeable replies and I've yet to read them, so forgive if I'm reiterating something here. But as for 1): IPs are distinctly /not/ PII (AKA: PD). They're identified /by name/ in the regulation, unless you sell that info. Anyone who brings this up as a topic has not actually read the regulations.. or they have and are trying to create uncertainty for some objective. It sounds like you've done enough of reading the regulation to actually know this, it's part of your job and you've spoken to legal experts (as I have).
- jiveturkey 8y ago> IPs are distinctly /not/ PII. They're identified /by name/ in the regulation. Anyone who brings this up as a topic has not actually read the regulations.. or they have and are trying to create uncertainty for some objective. Have you yourself read the regulation? You are wrong. The regulation makes a single reference (by name) to IP addresses. In recital 30. In that recital, it specifically declares IP address to be PD (GDPR doesn't use the term PII at all). Not to confuse the matter, but if you stopped there, and decided IP addresses were PD, you would have stopped short. It requires deeper analysis. Here are two good ones: https://gdpr-info.eu/issues/personal-data/ https://gdpr-info.eu/issues/personal-data/ https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-... The soundbite-sized answer is: it depends.
- dijit 8y agoSorry, was going on the case of "if you're not an ISP" IP, when tied to other data becomes the scope of personal data. However, removing the other data renders it no longer personal data. This firmly puts it in the "it's not personal data" camp. Since it's the other data that is personally identifiable that gives it context. It's only relevant for ISPs really, but really good job on proving my "creating confusion for no reason" point. In the context of online accounts (in video games, where I work) it can't be used to identify real world people because we don't ever link to a real world identity. In cases where you log details about people individually (as in- a bank) you just don't log user details beside access logs and you're set. IP on it's own is not personally identifiable, and is out of scope for GDPR.
- neffy 8y agoHere it is: https://www.eugdpr.org/the-regulation.html https://www.eugdpr.org/the-regulation.html Hands up. Who has actually read all of it? Speaking as somebody who actually has - was teaching computer security last term - I found it relatively easy to read (as legal documents go) - but it still took a weekend. I will guarantee you, that not all of the high powered lawyers whose job it is to read it, have done that. True story: back in the days when libraries still stamped your book with the date it was due back, I took out a copy of Keynes General Theory from the main library where I lived. It's not that thick of a book, and according to the date stamps it had been borrowed at least 20 or so times. About half way through the pages hadn't been cut. It was a few years before the significance of that finally dawned on me. As in many things in life, HN discussions on the GDPR are a wonderful example of nobody actually reading it, and everybody having an opinion of it.
- bmer 8y agoI am just seeing a couple of scrolls worth of text---definitely not weekend-long reading material. Am I reading the right thing, or is your link mis-pointed?
- deleted 8y ago[deleted]
- duxup 8y agoI'm only seeing a very short summary too.
- erik_seaberg 8y agohttps://ec.europa.eu/info/files/regulation-eu-2016-679-protection-natural-persons-regard-processing-personal-data-and-free-movement-such-data_en https://ec.europa.eu/info/files/regulation-eu-2016-679-prote... is some fifty thousand words (i.e., a novel worth of legalese).
- duxup 8y ago"https://www.eugdpr.org/the-regulation.html" https://www.eugdpr.org/the-regulation.html" Well now I read that link, but I don't think that's the actual law...
- rcheu 8y agoYeah, I’m willing to bet the people that think this is easy and clear are not trying to implement it. I have not met anyone working at a large internet company (these companies have high likelyhood of being sued so it’s very important the law is followed as accurately as possible) that thinks the law is clear.
- krageon 8y ago99% of the people screaming here that it's incomprehensible either very clearly haven't read the source material or just don't understand how the law works in the EU (I guess they are from somewhere else and didn't bother to look anything up before forming an opinion). Regarding your point about consensus, that's fair - however this has not been my experience. Most parties that you would ask for advice on the matter have a pretty good handle on what the different terms mean. Your second point is mostly evidence (to my mind) of large corporations trying to get away with as much malicious compliance as they can possibly manage. You really do have to put a lot of effort in that, as you cannot assume the agency checking you will see good faith (which is, as far as I understand it, one of the requirements for not being slapped with fines very quickly).
- Fradow 8y ago"It is difficult to get a man to understand something, when his salary depends upon his not understanding it!" The law is pretty clear (not 100% clear, obviously, there is going to be loophole and unclear things), and it's easy to decide about unclear spots by following the spirit of the law, and by understanding that any unclear technical requirements really means "what a sane engineer would do, that you could defend against a jury of your peer". To answer a few of your questions (obvisouly IANAL): - are IPs PII? Yes, there are legal case about that, your lawyer should have a more detailed answer. - what exceptions can be allowed? When you have a case you could defend that doesn't go against the spirit of the law - what falls under "security requirements"? You should be able to defend your choices securiy-wise against a jury of your peer, using your internal documentation. If you have unsalted passwords hashs for example, you are in trouble - what sort of deanonymization is sufficient? Best practices at the current date. Technical details aren't going to be in the law, because the goal of a law is to not be outdated every year. Laws are enforced by humans, not by computers. Your company should be prepared to defend its interpretation of the law (that's your lawyer job) and your technical choices (that's your job). Edit: obviously, that's a simplified vision, and you should always consult your lawyer. The biggest your company is, the more important it is to try your best to be compliant.