Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
grabeh
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
grabeh
8y ago
https://ico.org.uk/for-organisations/guide-to-the-general-da... The above link contains a sample Excel template with details of the various information a record of processing should contain. If you are only processing
32.
▲
by
grabeh
8y ago
You could just remove parts of the IP address so it could no longer be used to identify a unique individual. For example, if you removed the last 3 digits, it could no longer be used on IP lookups (presumably), or an ISP would not be able t
33.
▲
by
grabeh
8y ago
There is no reason why terms should not be written in plain English and indeed under European consumer protection laws, you should be writing the terms in plain English because it means the user has a better chance of understanding them, an
34.
▲
by
grabeh
8y ago
I would make a few points: - I don't think legalese is the issue. Even if you wrote terms in plain English they would still be at a similar length if you wanted to capture the same content of the base terms, and people would still not
35.
▲
by
grabeh
8y ago
I'm sorry, I don't follow why the plain English version is severely misleading, or couldn't be supplemented to capture the full extent of Imgur legalese. Why do you think this is the case?
36.
▲
by
grabeh
8y ago
Funnily enough even the tightest drafted legalese is actually often subject to a range of ambiguity and loopholes. I feel it can be a quality inherent in certain language regardless of whether it's plain English or legalese, particular
37.
▲
by
grabeh
8y ago
You're in luck at least when it comes to privacy in the EU! The GDPR makes various references to the creation and use of standardised icons to give a meaningful overview of the intended data processing. I know, I know, another GDPR ref
38.
▲
by
grabeh
8y ago
Ok, my apologies for not picking up on the fact you are in the EU. Is it the cost that is stopping you from making a subject access request today under existing laws? Apologies also - I took Citizens' Advice in the narrow sense of the
39.
▲
by
grabeh
8y ago
> What are you even trying to say here? If I don't live in the EU, have no legal presence in the EU I have no means through which I must comply with the GDPR. I was responding to your point that there were zero channels to help non-
40.
▲
by
grabeh
8y ago
Just to be clear, there is little to no risk of someone running a simple blog getting fined by a data protection regulator. In the UK for example the ICO who regulate data protection matters concluded 17,300 cases, in which only 16 of them
41.
▲
by
grabeh
8y ago
Laws are not always crystal clear in each case because to do so risks making them capable of being worked around (and of course in some cases they are just badly drafted - but I don't see this so much with GDPR). Laws are then subject
42.
▲
by
grabeh
8y ago
It would be a shame to take down your old blogs as I'm sure people get value from them. My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely a
43.
▲
by
grabeh
8y ago
The threshold for determining establishment is a low threshold however there will still be various factors taken into account in determining whether that establishment is there (for Art 3(1), and indeed whether goods and services are being
44.
▲
by
grabeh
8y ago
Article 3 is clear about the scope of the regulation when an entity is outside the EU. It states that it will apply where that entity is offering goods/services or is monitoring data subjects in the EU. Enforcement is a separate matter
45.
▲
by
grabeh
8y ago
Yes there are two separate bases for processing of data, but the point is that consent cannot be bundled and made a precondition to another form of processing i.e. to provide a service. Put another way, Facebook should not make the provisio
46.
▲
by
grabeh
9y ago
The distinction stems partly from the US-EU divide. US use the term personally identifiable information (PII). This has a narrow definition and relates to that which connects your real identify. However, 'PII' is not a concept und
47.
▲
by
grabeh
9y ago
Sure, I see where you're coming from. I guess we'll just have to wait and see whether data protection authorities start dropping 20 million Euro fines on people from day 1 for breaches of the law. My view and instinct is that this
48.
▲
by
grabeh
9y ago
Sure, maybe it probably doesn't need to be but Article 29 guidance is clear that as a matter of good practice, you should look to document the balancing test you have undertaken to determine legitimate interests is appropriate. Yes, qu
49.
▲
by
grabeh
9y ago
Option 4) - adopt a risk-based approach to compliance, and look to assess whether any aspect of your service, and the way it makes use of data in its current form is an egregious breach of GDPR. If that is the case, you're likely in br
50.
▲
by
grabeh
9y ago
The main processing basis for many entities will be straightforward processing to provide service under Art 6.1.b. Legitimate interests like consent should generally be avoided wherever possible due to the additional burden it places on org
51.
▲
by
grabeh
9y ago
Any exceptions to the regulation will inevitably be subject to a narrow interpretation particularly if it is clear that someone is looking to do something which is outside the spirit of the regulation.
52.
▲
by
grabeh
9y ago
If you need to retain information for a particular reason, for example to provide a service, or to retain for legal reasons, or legitimate reasons in connection with your business, then in many cases that will trump the right to be forgotte
53.
▲
by
grabeh
9y ago
You would not use legitimate interests to cover off your processing of data in connection with letting a user log in to your site, if it is a requirement of using the service that you are logged in, for example to authenticate who you are.
54.
▲
by
grabeh
9y ago
What makes you say that there's no agreement as to what it means? It feels like I see this sort of view expressed quite frequently. My guess is that it's primarily because people want a reason not to look to comply in lots of case
55.
▲
by
grabeh
9y ago
There are several grounds on which you can legally process data in addition to consent, so it is unhelpful to talk in general terms about purging data where you are not getting user consent. If you are using data to provide a service, then
56.
▲
by
grabeh
9y ago
If you are looking to derive aggregated insights from data then you need to be clear on your anonymisation processes and understand whether or not you any derived dataset is capable of identifying individuals whether in isolation or through
57.
▲
by
grabeh
9y ago
Your intention and how you actually use the data are critical to an entity's compliance with the GDPR. If I am only using IP addresses for legitimate purposes of monitoring/protecting my network then that is very different to usin
58.
▲
by
grabeh
9y ago
I think the main issue that I see is that whilst GDPR doesn't massively expand the scope of what is personal data beyond that under existing data protection law, it does expand the territorial reach of data protection law. US companies
59.
▲
by
grabeh
9y ago
If you want a practical example of psuedonymisation then consider a case where you have two internal systems that serve different purposes (say one is used as a CRM, the other is used for business reporting). The CRM database is copied over
60.
▲
by
grabeh
9y ago
The GDPR, as with existing EU data protection law requires technical & organisational measures in place to protect data. The GDPR specifically calls out (Article 32 if you're interested) encryption as one measure that entities shou
More ›