8 ms·
I feel the same. The GDPR appears super difficult to comply with, even impossible in some cases, and very restricting. I just hope negative effects of (in my o
by pheggs 2y ago
I feel the same. The GDPR appears super difficult to comply with, even impossible in some cases, and very restricting.
I just hope negative effects of (in my opinion) overregulation wont hurt the EUs economy too badly, but that wont be visible for another couple of decades
- aebtebeten 2y agoThe GDPR is trivial to comply with: don't track (let alone process) personal data.
- pheggs 2y agoYes I agree its a good idea to not track personal data, but thats by far not the only rule in GDPR
- mtts 2y agoCorrect, but “not tracking personal data” is in fact not a rule in the GDPR. “Only store personal data you really need” is, qualified with “and don’t share it with others”. Cookie walls exist because companies insist on handing over their visitor data to external ad networks.
- tyfon 2y agoWhat other rule do you find impossible? Data portability? The users right to delete data? Data processing agreements? Data security? Article 30? They are all fairly trivial unless you do shady stuff really. Step one if is really looking at what you process as stipulated by article 30, a lot of the other stuff is much easier after that. One of my roles is as a DPO in a bank in Europe, and it's far from impossible to comply.
- davidgerard 2y ago> What other rule do you find impossible? you will never get specifics out of these guys. They will lead you down a circuitous thread of unspecified fears until it's clear that their business model is to abuse customer data even as they'll avoid actually saying so.
- userbinator 2y agoThe users right to delete data? In practice that becomes the "right to rewrite history". Which should never be a good thing, for obvious reasons.
- gravescale 2y agoIt's not a universal rule that you have to delete personal data on request. If there's a "legitimate interest", you don't need to delete it even if asked to. But you will need to have that legitimate interest documented. What exactly do you envision being the bad outcome here where you are asked to remove personal information and don't have a legitimate interest to keep it for?
- GeoAtreides 2y ago> The users right to delete data? Hacker news, please, think about being GDPR compliant! You're breaking the law, hacker news!
- pheggs 2y agoI understand you are an expert on the field, and I am sure it's trivial for you. IMO the complexity arises from the many small things, imagine a smallish startup without having someone hired full time to deal with it. I am not an expert on the field, I tried a couple of times to get into the topic but found it difficult to navigate and left me with more questions than answers personally. What exactly does deleting user data mean? Do I have to search the weblogs for the users IP? Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate? Am I in breach if an ISP decides to route internet packets through the US? If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach? What if my mail provider decides to replicate their servers to another country? If you have resources to read up on this and how to handle all of it, I would really appreciate it! Happy to be convinced that it actually is trivial
- gravescale 2y agoThere is a ridiculous amount of material to read online and you can answer all those questions fully in about 30 minutes of searching and you could have relevant the policies written up by lunchtime. > Do I have to search the weblogs for the users IP? No, because you don't keep web logs with any PII in them longer then you have to, right? The time you need to keep them for is a legitimate interest that you need to be able to justify. Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate? Write an Email Retention Policy, there are templates. Follow that. Am I in breach if an ISP decides to route internet packets through the US? Isn't it encrypted? If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach? You said it yourself: it's a data leak, so yes, it is (assuming this is some bulk email list). Depending on the sensitivity of the list, you may need to disclose the leak to the affected parties. If you want to profit from being a data controller you really should already have done this homework, even before the GDPR and friends required it by law. A responsible company would already be taking care of it's customers' (and employee) data and at most just needs make sure the existing processes are documented. Demonstrably, companies don't do this, through laziness, incompetence or malice, and that's how we end up with these regulations. Just like how companies injuring people in unsafe workplaces is how you get H&S regulation. And really all you have to do is just actually make a decent effort. If you find that extremely onerous it's usually because you actually want to use the data for something that you know deep down is not something the information owner would want you to use it for.
- wnolens 2y agoIt applies to all data. So it amounts to building a force delete and export feature to any platform you build. I've worked on a few data platforms where the product is literally.. customers give you data, you store it and process it for then. It's not hard to comply, but it does cost quite a bit of money which if you're small you might not have.
- mtts 2y agoNot only is the GDPR not difficult to comply with (just use only the personal data you need to provide your service - and don’t share it with others), it’s also nothing new: it’s just a bunch of previously existing privacy laws bundled together. Not all those laws applied to all EU countries before, but, basically, if you were doing business across the entire EU all the laws that you had to conform to together looked a lot like the GDPR.
- mackwic 2y agoIt's not that hard for any competent organization: document what PII you store, who has access to it, and what you do with it. Also have an internal procedure to scramble someone's PII on request. If you have a direct or indirect contractual relationship with the person whose PII you are storing, there is nothing more to do. If you don't, ask for permission and store the timestamp of the authorization. That's all. Really it's that simple.
- pheggs 2y agoI must say you really do make it sound simple, and I generally like it. I think the part where I struggle most are the details though. > document what PII you store that part seems doable, the hardest part here are probably figuring out what PII is, and then take care of numerous services logging IP addresses. That's PII, isnt it? What about IPs of phone calls over IP? Or phone numbers stored in phones of numerous employees? Do companies delete those, or is it not necessary? > who has access to it I personally try to self-host as much as possible with as little third-parties involved as possible. But I think here are edge cases too, a lot of people might not think about, such as time tracking tools, calendaring, accounting software etc. What happens if employees just use online tools the employer doesn't know about? I am sure it's defined, but it's not entirely clear to me > what you do with it that's probably the easiest part, if you do something with it you probably know it > Also have an internal procedure to scramble someone's PII on request. I think that sounds good. It's just not entirely clear to me what that procedure should look like? How deep do we go with that? I could be nitpicking and say that physically information can not be destroyed. What if a SQL Server uses MVCC and doesn't delete data but just marks it as such? What about event sourcing architectures with kafka that rely on keeping the data? Or how about backups? Probably no deletion needed, but how to handle cases where backups are restored and previously deleted data reappears? I just think a clear set of rules would be great here, and a lot of people like to oversimplify things (or me, overcomplicating things here, probably)
- deadlocked 2y agoThe answer to most of these is the same: companies have to show that they are making a reasonable, good faith attempt to comply. If they can show that they have policies, that they have processes to implement the policies, and that their users have read the policies, understand the processes, and are aware of their own responsibilities then there's a strong likelihood that they will not run afoul of the directive.
- davidgerard 2y agoUK sysadmin here. I assure you that the GDPR is not hard to comply with at all - unless your business is to abuse your customers' data. The main technical thing is that all data stores containing Personal Data must be redactable. For years I've read bizarre GDPR fanfic from panicked Americans claiming that the world will end if they have to pay the slightest attention to data protection. I assure you literally from personal experience that this is not the case. I wrote this up several years ago: https://reddragdiva.dreamwidth.org/606812.html https://reddragdiva.dreamwidth.org/606812.html
- gravescale 2y agoGDPR is mostly only excessively onerous when the business model involves gathering and processing information of people who haven't actually consented to what you want you do with it, or you don't have secure storage for the information. If a business can only survive by extracting and processing against the wishes of the owner, or by storing it unsafely, maybe that's not actually a desirable business.