Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cccbbbaaa
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
cccbbbaaa
3y ago
> so doesn't the app have reasonable implicit permission to make use of the user's storage? “Implicit permission” does not sound like “free, informed, specific and unambiguous consent”. Furthermore, the directive (ePrivacy, ar
92.
▲
by
cccbbbaaa
3y ago
Yeah, but these people typically target antennas, not 3 years old phones. And don't work for the ANFR. Source: french, living in a small town with its own anti-EM association.
93.
▲
by
cccbbbaaa
3y ago
I'd like to know which legal basis is used for this processing.
94.
▲
by
cccbbbaaa
3y ago
The cases you are referring to are Schrems I (which cancelled the Safe Harbor transfer agreement) and II (which cancelled the Privacy Shield). But, the commission ratified a new agreement between the EU and the USA in July, the DPF. So su
95.
▲
by
cccbbbaaa
3y ago
Some people, like Jancovici, suggested 4 flights in a lifetime per person.
96.
▲
by
cccbbbaaa
3y ago
It is possible; maybe you are mistaking it for other legal basis such as legitimate interest. Or maybe I get this wrong? But you are right that this is illegal, because just sitting in a car is not a “specific, informed and unambiguous ind
97.
▲
by
cccbbbaaa
3y ago
And, as the article says, this proposal is likely to be illegal under the ECHR and the CFREU.
98.
▲
by
cccbbbaaa
3y ago
Personal data has a very wide definition under GDPR: >‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly
99.
▲
by
cccbbbaaa
3y ago
> Spoken like a person who never even touched it even on a small project. You can find guidance or good advice online for all of your questions. > No cookies... so no language preferences. That is a profile cookie. This is one of the
100.
▲
by
cccbbbaaa
3y ago
The EU is not an uniform entity. Yes, you have citizens who sue Facebook, but then you have some members of the commission that wants to ban E2E encryption; but then, you have other members that absolutely don't want that, and the EDP
101.
▲
by
cccbbbaaa
3y ago
Oh, no, there's more. You must list all kinds of data processing you perform, find the appropriate legal basis (and data retention duration, etc.), make sure you only gather data you need (data minimization), know to who you transfer d
102.
▲
by
cccbbbaaa
3y ago
It's a loophole because enforcement is a joke, but I would agree to say the basis is too vague to be useful.
103.
▲
by
cccbbbaaa
3y ago
There is an audible “dual input”, which was triggered on this flight.
104.
▲
by
cccbbbaaa
3y ago
If you use a captcha to secure your service, they can be. See article 4 of the ePrivacy directive. This is also said in section 3.3 of the EDPB guideline. The issue of Google's reCaptcha, according to the CNIL at least, is that they
105.
▲
by
cccbbbaaa
3y ago
With all due respect, this is the kind of speculation I was complaining about earlier. >Almost nothing is strictly necessary to just serve content when a URL is accessed That's not what the law says. > 3. Member States shall ensu
106.
▲
by
cccbbbaaa
3y ago
Sessions IDs _are_ personal data, it's not even ambiguous if you read the definition in GDPR (article 4(1)). You even found it on the commission's website, it should give you a clear answer. About cookies, the relevant law is ePr
107.
▲
by
cccbbbaaa
3y ago
With a visitor session ID, you can identify a single user, so it's personal data under GDPR. Yes, even if you don't have a detailed profile of them. It's not even ambiguous, it's spelled in article 4(1).
108.
▲
by
cccbbbaaa
3y ago
I'm pretty sure a session ID is personal data since it can be linked to a specific user by the service provider (see GDPR article 4(1)), and can be processed under the “legitimate interest” legal basis (article 6(1)f). Cookies don'
109.
▲
by
cccbbbaaa
3y ago
>Although it took the view that “Pay or Okay” could be permissible in principle, it found that the approach taken by the news outlet didn’t comply with the law because it didn’t provide the option to specifically consent to certain purpo
110.
▲
by
cccbbbaaa
3y ago
About GDPR and protectionism–I already answered. Sorry if I misunderstood you, I did not pay attention to the DMA and that was not the subject of the article.
111.
▲
by
cccbbbaaa
3y ago
That's nice, but we're talking about the GDPR, a law with roots in the 70s. Not the DMA. And as I pointed out earlier, EU entities are getting fined and sued by regulators.
112.
▲
by
cccbbbaaa
3y ago
> US companies are also sued and fined in the US for breaking these laws. And European companies are also sued for breaking GDPR. Recently, the CNIL fined Criteo, a French adtech company, for 40M€. Multiple other fines in the 1M+€ rang
113.
▲
by
cccbbbaaa
3y ago
It's legal in France: https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/coo... https://www.cnil.fr/fr/cookies-et-autres-traceurs-le-conseil... https://www.dataguid
114.
▲
by
cccbbbaaa
3y ago
Graphics drivers, at least on unices, come in two parts: one in the kernel, another one in the userspace. The latter provides interfaces such as Vulkan. That said, ANV (Intel's driver) is part of mesa, and not bespoke like nvidia
115.
▲
by
cccbbbaaa
3y ago
Do they really get fined for this by a DPA or a court in Germany? Is it not one of these shady lawyers sending an invoice for “providing legal advice”? I (and people I “know”) reported countless uses of Google Analytics to our DPA, back w
116.
▲
by
cccbbbaaa
3y ago
Yeah, once again, disregarding the actual charges. I don't want to say you're wrong, just that looking at the fines is, in my opinion, not a good measure and doesn't give a good picture.
117.
▲
by
cccbbbaaa
3y ago
I don't think starting with a conclusion, only looking at the fines instead of the charges, ignoring factors that could influence the outcome (eg. EU companies being more familiar with EU regulations and regulators, for better or worse
118.
▲
by
cccbbbaaa
3y ago
Help yourself: https://competition-cases.ec.europa.eu/search?sortField=case...
119.
▲
by
cccbbbaaa
3y ago
You're right, but we see a lot of people saying EU wants to ban encryption with the CSAR proposal, using it to argue that they don't care about privacy. I wanted to bring nuance in the discussion, by posting sources to EU bodies (
120.
▲
by
cccbbbaaa
3y ago
Legitimate interest is the most fragile basis in GDPR and should not be relied upon, apart for server logs as suggested by recital 49. Contract (art. 6(1)b) may be better here, but keep in mind that art. 5(1)e still applies.
More ›