7 ms·
It's fun when people complain about having to handle personal data properly and not to collect more than they need. Bad luck, be responsible.
by mellett68 8y ago
It's fun when people complain about having to handle personal data properly and not to collect more than they need.
Bad luck, be responsible.
- virmundi 8y agoI’m interested in how the vagraties of the law plays out. I’m working on software that won’t use ads or CDNs. All traffic terminates with my system. I will use cookies. I have no intent on putting up one of those cookie notification banner. All data I collect is to run the site. While that is valid under GDPR, I bet the EU will come a knockin for a fine if the site gets big enough
- ginko 8y ago>While that is valid under GDPR, I bet the EU will come a knockin for a fine if the site gets big enough Why would you think so?
- icebraining 8y agoYeah, has the EU actually fined any company that wasn't playing fast and loose with people's data? There's someone keeping a list[1], and they seem pretty reasonable to me. [1] https://www.nathantrust.com/gdpr-fines-penalties https://www.nathantrust.com/gdpr-fines-penalties
- virmundi 8y agoI don't trust the EU. They seem to go after companies with deep pockets when they need money. Look at the Google Android controversy lately. Nokia, any EU phone creator (are there any?), any EU phone creator that wants to get in the market can all create a phone that is not Android. Google traded the OS for install preference rather than money. It's called bartering. The EU let this go for years. Now Alphabet has money and no one in the EU stepped up to take on Android, so the EU wants its pound of flesh. Will my project run afoul of the 3rd party rules? No. May I have to spend money on legal protection from the EU when they erroneously come asking for money? Maybe. This is my issue. I don't know. The EU says it has policing power across the globe. If an EU citizen steps foot in the sovereign territory of another country, the EU says that all their privacy laws apply.
- icebraining 8y agoIf an EU citizen steps foot in the sovereign territory of another country, the EU says that all their privacy laws apply. That's not true. The GDPR doesn't apply to citizens of the EU, but to people in the EU or services performed there.
- sbr464 8y agoIf I read correctly, GDPR does apply when non-EU companies market services specifically to people from the EU. For example a US based hotel deploying a targeted marketing campaign in the EU. I could be wrong.
- icebraining 8y agoYes, you're right; the distinction I was making is that it's about their presence in the EU, not their citizenship. In fact, an American citizen living in the EU is also covered, whereas an EU citizen living in the US is not. An in fact, it's even less than that: the site only has to care if they target people in the EU (not necessarily exclusively) or if they're tracking behaviours. Simply being accessible online doesn't mean it has to comply, whereas e.g. accepting Euro payments probably does.
- sbr464 8y agoThat's interesting, didn't know that about foreign citizen coverage.
- dasil003 8y agoI find it shocking how quick some people are to denounce government intervention these days. Are you seriously not concerned about Google’s market clout and the amount of data they have? Thank god the EU is there to temper their entitlement a bit. Meanwhile you’re sitting here daydreaming about how your startup is going to be so big EU regulators are going to come after you. Well that would be an excellent problem to have, in actuality you are far more likely to be killed by Google sucking the oxygen out of your market.
- ndnxhs 8y agoThe cookie banner is only needed for 3rd party cookies.
- upofadown 8y ago... and persistent 1st party cookies which are then allowed to stick around for up to a year.
- virmundi 8y agoThat’s my issue. If I have a cookie for a refresh token, I have to now have a banner saying the site uses a cookie. I have to have a page that explains why. All the while I have the site now looking shady because the banner is synonymous with stealing your data and selling it to ISIS.
- deleted 8y ago[deleted]
- upofadown 8y agoIf the refresh token is only being used for authentication and expires in a reasonable time for the application then you would not need prior consent so you would not need a banner. You would still have to explicitly disclose what you are doing on some sort of easy to find cookie policy page. Some good discussion here: * http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
- cartep 8y agoThe main defense against tracking used to be (in addition to more modern anti-tracking features) to configure the browser to remove cookies when exiting it. With the big dialogs that one systematically finds at websites now, in practice you are being forced to accept those cookies, if only to avoid seeing those monster dialogs again. So in practice the EU is massively driving people to accept permanent cookies. That's IMHO a valid reason to complain about GDPR.
- lagadu 8y agoThe cookies dialogs have nothing to do with GDPR.
- cartep 8y agoThose dialogs are about GDPR consent. You do not know what you are talking about.
- dang 8y agoOn HN, please don't cross into personal swipes, regardless of how ignorant another comment may be or seem. It's enough to provide correct information. If you'd review the guidelines and follow them when posting here, we'd be grateful. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- cartep 8y agoMy comment essentially says the same that the comment that I was replying to; just a bit more obvious (and unlike the other comment, I'm explaining why I'm stating that). Yet the only downvoted comment is mine. Do not worry about my future comments here: I'm not interested in using a site that is so friendly to vigilantes. That's my last HN comment (unless somebody replies here).
- TimTheTinker 8y ago
- deleted 8y ago[deleted]
- BurningFrog 8y agoThis comment assumes GDRP is a perfect and fair legislation that achieves its stated goals with no averse side effects.