6 ms·
> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum. And yet, when GDPR tries to address th
by DCoder 8y ago
> If I give a company my data, and they lose it, oh well. I wish all personal data was treated like HIPAA, at a minimum.
And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".
- greglindahl 8y agoIt's almost as if the issue is more complicated than the solution represented by the GDPR. I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.
- hodgesrm 8y agoThe question though is what's the alternative? The IT industry has failed spectacularly in protecting citizens' personal data. I'm not a fan of EU bureaucracy, but it looks as if they are on the right side of history on this one.
- JumpCrisscross 8y ago> what's the alternative? Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss. A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--list. If you want to get fancy, create a regulator who can add things to the list after a public hearing. (The specificity avoids GDPR's "what's personal data?" mess. The public input mitigates the risk of unintended consequences and corruption.) [1] http://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004 http://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
- scarlac 8y agoThat's basically what GDPR does. It broadens the scope of what is considered sensitive info and slaps a fine on people PRIOR to a breach. If a breach is found, then any breach of GDPR means EU can come after that company and hurt them seriously.
- brobdingnagians 8y agoA fine and a lawsuit are very different things, especially with 340M people involved [even a $340M fine would only be $1/person]; fines don't usually go to the people injured by it, which would make sense with personal data being leaked. A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules.
- kuschku 8y agoMany european countries (including Germany) have no class action lawsuits, so unless you want 340 million separate lawsuits, you’ll have to either use fines, or accept that this will go unpunished.
- roel_v 8y agoJust because there are no class action lawsuits doesn't mean you can't take collective legal action. It's been a long time since I lived in Germany, so I can't cite any recent examples, but 20 years ago there were lawsuits in Germany of broad groups.
- geocar 8y ago> fines don't usually go to the people injured by it, Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services. > which would make sense with personal data being leaked. My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens. > A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways. What example are you thinking of? The GDPR is quite broad and open to interpretation by both sides. > If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules. That's what the GDPR does. Requiring people to lawyer up to make the company responsible is far weaker.
- greglindahl 8y agoI'm suggesting that the alternative is a modification of the GDPR. It has a lot of great aspects, and some aspects that are kinda terrible.
- herewegoagain90 8y agoIt seems like the biggest issue with GDPR is that it’s comes from Europe and not the US? Historically speaking, Europe has in many issues come to agreement on technically solutions and industrial standards many years ahead of the US. For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard. I think it will be the same with regards to GDPR. You (US) will discuss this for years and come up with a different law.
- greglindahl 8y agoThat's not the biggest issue that I have with the GDPR. In fact, I'm totally OK with someone doing a better job than the US at regulating privacy. However, I have some complaints about the GDPR, and there isn't very much discussion about the details; most people appear to think about it as "all or nothing" or "Europe good, USA bad" or "everything looks clear to me so what's the problem?" instead of discussing the details. You can see all of these opinions in this very discussion.
- geocar 8y ago> I have some complaints about the GDPR, and there isn't very much discussion about the details There has been an enormous amount of discussion. It's been law for years and it's the amalgamation of various European countries individual DPR. What exactly is your snowflake complaint that you think hasn't been discussed yet?
- nolok 8y agoYou're creating or contributing to the problem you say exists, parent above was not refusing discussion and literally asked you what alternative you have in mind, so he was open to them. But after going several answers deep you still haven't listed any specific complaints and instead complain that nobody discuss them. This really make no sense. So, feel free to explain what specific things you dislike, why, and how else you would have done it, and then people would be able to discuss them with you and exchange opinion. Saying "it's not possible to talk about x" when you don't even try to really isn't the way.
- cyberpunk0 8y agoThe issue isn't complicated at all. Regardless of any country's laws. Don't use my personal information for anything other than verifying my identity or record keeping. Don't give it to anyone, don't sell it to anyone, don't use it for marketing bullshit, dont analyze it to find out how to sell me things, or how to trap me in targetted advertising (which I block anyway because you have no right to spam me with them or waste my bandwidth) or filter bubbles. If you can't do that when fuck off, there's no reason I should do business with you.
- notyourwork 8y agoAs someone who owns services which had to provide our data for customers as part of GDPR I was super happy to oblige. The work sucked, but I was more than happy to help our customers get their data from us.