4 ms·
Why do you participate in discussion about the GDPR when you clearly know nothing about it? Of course a "like" or any kind of data that is core to the service d
by simongray 4y ago
Why do you participate in discussion about the GDPR when you clearly know nothing about it? Of course a "like" or any kind of data that is core to the service doesn't infringe the GDPR. The illegal part is about processing or forwarding personal data of users to third parties, when users haven't agreed to that aspect of the "service".
You usually see the distinction between "functional" and "advertising" cookies in those annoying banners, where you of course can't disable the former as that data is core to the functionality of the website. And guess what, if you don't do any shady stuff with user data you don't even need to display any banner (the banner is for getting explicit permission from the user to potentially do shady stuff).
- JumpCrisscross 4y ago> Of course a "like" or any kind of data that is core to the service doesn't infringe the GDPR I’ve heard many “of course X or Y” pertaining to GDPR that turned out wrong. Because it’s a law interpreted by twenty-seven separate DPAs. GDPR’s aims are good. But there is legitimate criticism in its design.
- simongray 4y agoIf you work in a European company that has a web presence and/or collects data, you should be familiar with what is/isn't personal data by now. I don't blame Americans or others for not knowing this, but the amount of bad takes about the GDPR by Silicon Valley people in particular is so ridiculous. Every single comment section about a GDPR topic on HN has a bunch of Americans talking about how Europe is some backwards, regulatory hellhole, always talking from a position of total ignorance.
- JumpCrisscross 4y ago> you should be familiar with what is/isn't personal data by now Again, I hear this sort of thing all the time. Then you ask lawyers and lobbyists and get a host of opinions, many of which stick depending on which DPA one approaches or complains to. As a competitive stick, it’s dangerously dynamic.
- whimsicalism 4y ago+1 and what the GP is stating is not how any multinational I work with considers GDPR compliance. Properly managing "likes" and other member activity are absolutely key to compliance.
- JumpCrisscross 4y ago> managing "likes" and other member activity are absolutely key to compliance As is keeping an eye on competitors, particularly lightly-capitalised ones, and noting when they stray into grey areas. Bonus points if you can get multiple DPAs to issue simultaneous requests in obscure languages.
- deleted 4y ago[deleted]
- whimsicalism 4y agoI literally work in this field and can tell you that "likes" are regulated under GDPR just like any other personal data. If someone asks us to delete under GDPR, we have to delete these as well.
- timlod 4y agoAre you sure about this? Being roughly familiar with GDPR, I would be reasonably certain that you could keep a like as long as the identity it's attached to is deleted. Much in the same way as you may see reddit posts that just show a [deleted] user.