4 ms·
Quite a few companies have been fined for violating the law, and we are seeing positive effects for privacy because of it. The cookie stuff, yes, it's annoying
by llarsson 6y ago
Quite a few companies have been fined for violating the law, and we are seeing positive effects for privacy because of it.
The cookie stuff, yes, it's annoying for us end users. I get it.
But take how H&M were fined for violating the privacy of their employees. That they had to stop doing that is a Good Thing, right?
https://www.bbc.com/news/technology-54418936 https://www.bbc.com/news/technology-54418936
- fguerraz 6y agoNo, it is not a good thing. GDPR is a highly complex piece of legislation that is very hard to navigate and therefore only established companies with big bucks to spend on lawyers and extra engineering can profit from the ecosystem while everybody else is put at risk. Complex legislation and regulations is the best way to keep monopolies in place. Same goes for the financial sector, telecoms, etc. It's nearly impossible for new players to emerge. This complex frameworks are put it place so that big companies that do nasty things can get away with it because they will be able to demonstrate that they have complied with the regulations while emerging players will break their teeth on it. Instead of regulating _how_ data collection and processing should be done, we should penalise _what_ is done with the data in simple clear terms, and make _people_ (CEOs, etc.) responsible not just giving fines to companies. Basically, reintroduce skin in the game.
- matsemann 6y agoGDPR is sooo easy to follow as a startup. Just gather the data you need and not everything else,and ask for consent. If anything, it was the big players getting work to do. Thousands of people on mailing lists with no control of how they got there. Asked and kept insane amounts of not necessary data. Data floating in hundreds of database tables spread over various services and third party vendors and data centers with no control. Cleaning up that was a huge job.
- speleding 6y agoIt really isn't that easy. Something like an IP address is considered personally identifiable information, and most web servers and frameworks log that by default. If you really want to comply it takes quite a bit of effort you are not accidentally logging IP addresses somewhere. You can argue you need that info for the operation of your site, but it's been established that you would still need to ask permission in that case, did you do that? Of course, they are unlikely to come after a startup for an infringement like that, but the point is that they could if they wanted to.
- skinkestek 6y agoSpeculation here, but informed speculation: I highly doubt you as a non shady actor will be punished because of your server logs as such. Start selling or otherwise sharing them with ad companies, directly or indirectly and you deserve and should expect a GDPR fine as soon as they can if you are in a jurisdiction where GDPR applies. Same if you involuntary leak data because of gross negligence: passwords in cleartext, unnecessary data collected and stored and later leaked etc etc In many cases I understand authorities will even contact companies first and try to guide them toward a compliant solution first instead of fining tjem right away. That said I wish there were some clarifications given wrt to server logs and IP addresses; running without is in many cases gross negligence in itself. Basic logging is first year defense against black arts curriculum.
- anang 6y agoI don’t think the only factor considered is whether or not something is PII, rather even the intent is considered. If you were storing IP addresses to track and market to users, you need consent. If you’re using them for logging and security purposes, I think that falls under legitimate interest.
- speleding 6y agoJust Google "IP addresses GDPR" and you will see several different conclusions. I actually looked at the site of the enforcement authority in my country and they say you can only store the first 3 bytes of an IP address. But enforcement authorities in other countries may claim differently. My point is: it's really not that easy. It should be easy to get clear guidance on something straightforward like this, and not have to resort to Stack overflow answers.
- tinus_hn 6y agoIt’s hard to follow if you are an old business built on gathering and selling your customers data. I can see how it’s a though pill to swallow that that was exactly the point.
- Silhouette 6y agoGDPR is sooo easy to follow as a startup. Just gather the data you need and not everything else,and ask for consent. Clearly we're not going to ask for consent to track someone who is systematically probing our site for vulnerabilities, or someone who is attempting to use us to validate presumably stolen credit card details, or a group who are obviously sharing a password to gain unauthorised access in violation of our terms of service. Also, the purpose(s) of data processing matter, not just the data itself. It's not as simple as only gathering what you need. You also have to ensure that what you gather is used appropriately, and that you have the means to respond to the various rights that subjects have by law. Thousands of people on mailing lists with no control of how they got there. Actually, that was one of the tricky areas when the GDPR came in, and something almost no-one got right despite good intentions. Specifically, the widely accepted best practice for managing a mailing list had long been to use double opt-in, thus verifying that the subscriber really did intend to receive the messages, and to provide a simple, automated unsubscribe facility. However, unless you had kept all the confirmation replies, under the GDPR you might not have met the required standard for evidence of each list subscriber actively opting in to receive your mails. That led to a wave of messages being sent out to mailing lists asking subscribers to confirm they still wanted to receive the mails. This was particularly ironic because if those subscribers hadn't already intended to consent then those messages were probably themselves in violation of existing law in much of the EU even before the GDPR came in. The difference was that before, no-one was seriously worried that a legitimately operated mailing list with double opt-in was going to be targetted for business-crippling penalties, but with all the ambiguity around the GDPR and the uncertainty around how it was going to be enforced, a lot of people panicked.
- Thiez 6y agoI don't recall having ever seen a mailing list following that best practice. It's always a [] keep me informed about products checkbox hidden somewhere in a purchase form, often pre-checked even though that's illegal. Recently I was somehow added to the mailing list of a car dealership after getting my car checked up there, and can't even unsubscribe without creating an account on their website. I'm sure there are some legitimate mailing lists out there, but there are so many others that are scummy and in flagrant violation of the law. It's hard to shake the feeling that making things harder for mailing lists in general is going to be a net win for consumers.
- erik_seaberg 6y agoIs every startup hiring a lawyer who specializes in data protection laws? Publishing an impact assessment and waiting 8±6 weeks for permission to deploy? GDPR is the size of a novel and adds a lot of bureaucracy beyond not doing bad things. I think everyone in other jurisdictions needs to consider whether revenue from serving EU users covers compliance costs and risks.