17 ms·
> Forcing a “duty of care” responsibility on organisations which operate online will not only drown small and medium sized companies in administrative tasks and
by Permit 5y ago
> Forcing a “duty of care” responsibility on organisations which operate online will not only drown small and medium sized companies in administrative tasks and costs, it will further accentuate the existing monopolies by Big Tech.
I often wonder about this. I mean, just the other day there was an article[1] here about sending GDPR requests to a health non-profit in order to sequence your genes for free.
The costs of each individual piece of legislation are small, but internet legislation only ever trends in the direction of "more of it". As more small costs are added (GDPR, cookie notifications, right to be forgotten, removal of Safe Harbor etc.) these costs will start to play a factor in who can run a web service and who cannot.
[1] https://news.ycombinator.com/item?id=27146975 https://news.ycombinator.com/item?id=27146975
- iso1631 5y agoInteresting. I don't send cookies or keep personal data, so why do I need to worry about them? The only time I've got into issues was with an american firm using an american law (dmca) to attack me (a non-american) and my hosting company (a non-american hosting company)
- Permit 5y ago> I don't send cookies or keep personal data, so why do I need to worry about them? Can you share your website/service?
- frockington1 5y agoCommenting to follow up later. I'm really interested in the use case. The only thing I can think of would be a website similar to mid-2000s youtube to mp3 converters.
- iso1631 5y agoAlas they are all behind ssl authentication so you wouldn't be able to access them, but the stuff I currently have open includes a switch port mapper (every 20 minutes all my switches are scanned and reports generated on what's plugged in where), a firewall config interpretor (a list of current port forwards is generated), and a logging server showing me what But if you want an example of a fully featured public site which doesn't need cookies https://news.ycombinator.com/ https://news.ycombinator.com/ Load that in lynx, which asks for every cookie, and none are set. Now sure, if you choose to log in, then functionally you need to accept the login cookie, but that cookie isn't spammed out to you. Under GDPR, a website doesn't need to ask for permission to have necessary cookies which enable core functionality such as security, network management, and accessibility.
- Permit 5y ago> Under GDPR, a website doesn't need to ask for permission to have necessary cookies which enable core functionality such as security, network management, and accessibility. I am not convinced this is true. See: https://law.stackexchange.com/a/32157 https://law.stackexchange.com/a/32157 Also note that HN is likely in violation of this since there is no "Remember Me" checkbox when logging in. There is no indication that logins will be persistent.
- Mediterraneo10 5y agoCommon CMSs send cookies by default. Even if you are one of those tech-inclined people using a static site generator for your own website, this is not the case for millions and millions of other websites.
- nfoz 5y agoThen let's replace those CMS's. [edited with less anger]
- maxrev17 5y agoReplace them? You need cookies for a tonne of reasons. It's really difficult to justify replacing half the web because some people abuse it. That's like replacing cars with walking because some people drink drive.
- deleted 5y ago[deleted]
- iso1631 5y agoWhat reasons do you need the types of cookies you need to ask permission for under the GDPR?
- TheManInThePub 5y ago*sigh* Here we go again. The GDPR has no problem AT ALL with cookies. Use as many as you like with no need for popups. However, if you are using cookies to track or personally identify me, then you need to ask my permission to do so. And so you should. The amount of misinformation (some of it wilful) circulating about the GDPR on HN (a technical forum!) is shocking. If you consider yourself a professional developer then I strongly suggest you read a GDPR primer. There is no excuse not to. Following the GDPR will simply make your code safer when handling personal data.
- ryukafalz 5y agoCookie notifications? You have to be actively tracking your users for those to even be relevant. You could literally do less work and avoid the need for them altogether.
- daenney 5y agoGDPR, or CCPA, isn't all that costly as long as you stop thinking of user data as something for you to harvest, mine, resell and profit from. If you instead treat user data like a security liability, system designs and trade-offs will flow from there. They'll help ensure you design systems that minimise collection and anonymise things early, remove data promptly when no longer needed, and make it easy to audit what data you do hold which in turns makes supporting GDPR requests easy. The largest cost of GDPR is making that shift for existing companies. If GDPR ends up killing a few companies because of that, I personally don't mind. And if a startup doesn't end up seeing the light of day because it's not possible for them to operate under the conditions that GDPR imposes, then from my point of view the GDPR is doing what I'd like it to do.
- anshorei 5y agoIt's possible for you to be in violation of GDPR without "thinking of user data as something for you to harvest, mine, resell and profit from". If it's "killing a few companies" and "a startup doesn't end up seeing the light" then "GDPR is doing what I'd like it to do." That's a pretty shitty opinion to hold. What did those companies and startups do wrong? I'm as tired of stupid startups as the next person, but I won't cheer for their failure unless they actually do something wrong.
- 3np 5y agoHow about adding third-party analytics integrations that compromise your visitors, tracks them around the web, and fail to protect that data properly as the analytics company gets acquired by another entity? Stop saving PII for profit/exploitation reasons and you're in the clear.
- account42 5y ago> What did those companies and startups do wrong? Well for one, they ignored users and the authorities asking them to stop their illegal data collection. No company is getting "killed" or even fined at all when they are not actively refusing to get compliant.