5 ms·
> so when you say a crazy way of making laws, you mean the way that laws basically get made? I think what's being characterized as crazy is that the laws as wr
by Kalium 4y ago
> so when you say a crazy way of making laws, you mean the way that laws basically get made?
I think what's being characterized as crazy is that the laws as written are at best vague. It takes years to find out what they actually mean in implementable detail. This makes it very difficult to comply.
Have you read through GDPR? I have. It talks a lot about "reasonable measures" and includes vast swaths of other laws while being very light on details. Compare to, for example, electrical codes. Those tend to be quite specific and clear with sharply limited room for interpretation.
With this in mind, I can see why someone might regard this as an insane way to create laws.
- Macha 4y agoReasonable is a common term in laws, see for example the "reasonable person test" which is widespread in US civil law. Laws are not written like electrical codes in the most part because such specific laws either explicitly enumerate what is permissible (which is more ok for something like "acceptable methods of wiring a house" than "acceptable uses of data") or are rendered obsolete by the first thing the law writers didn't foresee ("Oh, the law bans tracking with cookies? Well we just have a server side database for UA+IP address combinations, so we don't need to comply" - in fact the first EU attempt at privacy law arguably failed for this reason)
- Kalium 4y agoIt is, but generally reasonableness comes with useful legal context to help you understand what it means. In the context of GDPR? I was left guessing what a regulator in Brussels might consider reasonable when their path to career advancement might run through my employer. Coupled with being uncertain what various national regulators (or empowered industry bodies) might add in, as they were allowed to do so until quite literally the last second. It left a person with no good way of judging what might be considered reasonable, only nervous paranoia. It was a distinctly unpleasant experience and one I was left thinking was both anticipated and avoidable.
- ElKrist 4y agoDon't we have to use broad terms to avoid abuse of edge cases? Should we have avoided writing a constitution because "freedom of speech" is extremely vague? GDPR is a radical step forward considering how poor the situation was. We're talking about a fundamental right to privacy. It was absolutely expected that it would shake some businesses, that's why it was announced years before implementation. Also, the courts don't come suddenly stab companies in the back out of nowhere. There was and there is a lot of pedagogy around it and usually the cases escalates gradually with warnings. The ones getting fines are clearly the ones who are still trying to do it the old way.
- CogitoCogito 4y agoIt sounds like the recent decisions are making the laws less vague are they not? Shouldn’t that make everyone happy (other than those who are invested in other legal realities)?
- deleted 4y ago[deleted]
- pyrale 4y ago> This makes it very difficult to comply. It is really not hard at all to comply with GDPR. Don't collect private informations you don't need, and don't share them. Now what's hard is to build a system that complies with GDPR's letter _and_ breaks GDPR's intent. And you know what? That's intended.
- LegionMammal978 4y ago> It is really not hard at all to comply with GDPR. Don't collect private informations you don't need, and don't share them. The problem is, not all personal data corresponds to the intuitive notion of "private informations". For instance, I, as a U.S. citizen, would be violating the GDPR if I operated a dumb HTTP server that stores request logs indefinitely and does no other processing, such as "python3 -m http.server". (IP addresses are personal data, and U.S. authorities can make me turn over my logs; thus, I cannot store the logs for however long I want.)
- Kalium 4y agoCan you define "private informations" and "need" in unambiguous ways, please? In my experience it's shockingly hard to do so once you get beyond the basics. Even when you have clear legal obligations to collect a bunch of private data, you still have to figure what reasonable measures to protect it are. What's a reasonable measure when you're obligated to keep seven years of financial records about your customers in a way that lets you produce ready reports for regulators? Complete with mandatory personal identifiers for tax purposes?
- robin_reala 4y agoI’m not sure what you mean with your second point. A legal need to collect and process personal data is a valid GDPR basis. You don’t need to get consent there.
- Kalium 4y agoYou don't, but obligations under GDPR include taking "reasonable measures" to protect the private information you're obligated to collect. The point I was making is that this underscores is how difficult it is to define "reasonable measures" because not collecting private information is not always an option. GDPR is not just about being obligated to ask for consent. Its requirements go a great deal further. Probably. Maybe. Depending on what someone unknown with an unknown background considers reasonable based on unknown factors. I'm sure that will be easy to write requirements around. Right?