Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation.
Every complaint about it shows that you don't respect others and you dont care about them. And this is the reason it became legislation.
GDPR is a wonderful idea that will be insanely expensive to comply with, act as a continuous drag on developing new technologies, and end up offering only nominal protection to end users. This is just going to be another way for EU regulators to smack around Google and Facebook. They probably deserve it, but the potential fallout for the rest of us is really going to hurt.
Don’t get me wrong, treating user data with respect is the right thing to do. But we’re all going to be paying for this overly broad and under specified legislation for years to come.
Any and all of them? Because of anonymized IP addresses in server logs? I wouldn't even buy that when it comes to the web, but certainly not to mention talking about computers and software in general, or even "tech in general", whatever that would be.
If, however, a company is storing IP addresses to identify users without their consent and are found to be specifically targeting them without their consent, then that is a misuse of data.
You are right that companies will be paying for this for a long time and it does take effort to comply, but if that's what it takes to protect user data, increase security across the board to prevent data breaches and kill off the players that never should be in the business to begin with then I'm all for it.
By my reading, information becomes personal —and therefore subject to GDPR— when it can be used to identify people. If you've got login timestamps, IP addresses and user records, for legitimate reasons, any other logging that includes IPs is tainted because it takes anybody with that data two minutes to munge them together.
Intent, and actual business use-case play second fiddle to the worst-case, or "what could that data be used for?".
The classification of data of personal data is likely beyond dispute but you are then under obligations on how you actually make use of that data.
Entities should have in place relevant protective measures to ensure that if you have only collected data for a limited purpose, it should not be used for purposes beyond that.
IP addresses are subject to GDPR, but that just means that you have to have either a legitimate business need for keeping them or to have the user's consent to keep them and you need to disclose to the user that you are keeping them and for how long.
You probably do have a legitimate need to keep IP address logs for some period of time to allow troubleshooting and possibly for a longer period of time to allow for fraud detection. As long as you are disclosing to the user that you are collecting that information and are abiding by the retention period that you are disclosing to users, then you will be allowed to collect logs of IP addresses.
I’m not familiar with the referenced Nintendo case, but mens rea is usually only considered in criminal cases. Unless you’re prosecuting someone for illegally downloading copyrighted material or some such thing, intent wouldn’t be considered (it can increase liability in civil cases, though).
One other interesting thing to keep in mind is that GDPR does not exempt public, government organisations. It will be interesting to see what happens with that, if anything.
wat.
Standard log formats capture IP, and have ~forever. Who claims this is an ethical quandary?
And since the recent European court decision, I suppose it is settled: yes, illegal.
IP logging is not ethically ambiguous in any way. It's 100% okay. You chose to connect to that IP. If you don't want your IP logged don't send an IP packet to that address. It's very simple.
This is beyond ridiculous. The entitlement I see here is cancerous in the literal sense.
Why do you need to log ip? To prevent abuse? That's ok. For how long? That's up do you to decide, but it must be motivated and documented.
What's so hard to understand? How is this not perfectly reasonable already? Why are you entitled to not respect other's personal data?
Why is it somehow reasonable to compel me to forget that interaction existed?
It's not ok to take a picture of everyone that walks in front of your house, timestamped and on top of that you search their picture on Facebook (supposing you could do that) and keep all that info forever
Why not? It's certainly not obvious why this is the case.
1. If the by-passers where to discover what you've done they might feel violated. This is why there are laws against stalking. Thus in this example it would be all about intent.
2. What if your database leaks? Have you considered that event, the probability of it happening, and the impact? How can you minimize the risk? Is it encrypted? How long do you need to store it for? Can it be anonymized? Do you even need to look up name? Is the potential privacy intrusion proportional to the purpose of collecting the data?
To be GDPR-compliant you must have answered all those questions and documented it.
2. I understand what it's about.
If you want to make tracking people and linking things together illegal, great.
However, my argument in response to the OP intended to illustrate that recording information about someones actions, particularly when it's a party who is part of the interaction creating the recording, does not seem to have some preexisting moral expectation or attached to it.
Hence, to me at least, the GDPR's directives are not objectively reasonable or obvious in some way as suggested by the OP.
I also think forbidding certain uses of the data is more reasonable than to regulate its collection and storage. But yes, that's probably riskier and harder to enforce.
I don't see this as a bad thing. For far too long, we've not cared at all about user data and privacy.
Can you expand on that?
Also, I can't help but notice that currently there is a hell of a lot of money being bet on immutable public ledgers.
But you generally cannot build a system that intentionally does not have a certain capability and then successfully claim that laws don‘t apply to you, because your beautiful system does not accomodate them.
The more specific answer is:
git config --global user.name "Your Name Comes Here"
git config --global user.email you@yourdomain.example.com
Also, looking up, you can undo a rebase with reflog, so even editing commits with an interactive rebase may not be enough to purge a git repo of identifiable information that people have entered.
I've been pondering the same thing. You have to be extremely careful about building a new product on blockchain technology, because, depending on what you're building, you may be required to delete stuff from it in the future.
The tricky situation is when someone puts personal data not about themselves, but about a third party into a public ledger...
I'll need to figure out to handle this on the data I'm responsible for at the moment. It's boring and it doesn't help the product, but it's not supposed to. In idlewords' terms, I feel like I'm finally purging toxic waste: http://idlewords.com/talks/haunted_by_data.htm
In practice, you can achieve this by simply refreshing your derived data frequently (ever ~30-60 days), and for aggregated data k-anonymity is a good way to enforce this privacy constraint.
So you must delete them and also keep them.
This sounds like the Investigatory Powers Act in the UK, though I haven't heard of similar laws in other liberal democracies.
GDPR blows up a lot of assumptions we make about writing software and managing servers.
https://www.privacy-regulation.eu/en/article-17-right-to-era...
Similarly credit agencies aren't required to comply with deletion requests either. You can't simply GDPR your way out of a bad credit score.
But it's a total mess, when you read the GDPR it's clear that it's written by people with limited understanding of IT. Of cause it has to be extremely strict, otherwise you'll end up with a Cookie-law 2.0. The cookie law from the EU was read by the industry in a way that clearly wasn't intended. It made zero different to user tracking, we just got a bunch of pop-ups stating that the site uses Cookie. If you read that law as I believe it was intended, the idea would be that you could say yes to cookies or no. If you choose no, the site would disable the use of tracking cookies. But was to much work, so people just slapped a cookie pop-up on their sites.
1) if you have a legitimate reason that allows you to process the data without consent (which would be the expected scenario; if not, then any sane organization would likely just choose to don't have that data in their logs at all), then none of the following applies, and you can refuse the request;
2) if you had a legitimate reason but "the personal data are no longer necessary", then you must comply.... but that's just duplication, you should not have had that data anymore since if you're compliant, you should have cleared the data out already. E.g. if you believe that you need (and are allowed) to store data for 6 months for purpose X; then you'd ignore the request for 5 month old data as you need it, and ignore the request for 7 month old data as you already purged it as a routine operation.
3) if you didn't have a legitimate reason and actually needed consent, then you follow the same process as you do for scrubbing references to all IP addresses which didn't give you consent. If you're compliant with the other requirements (which is tricky in this case), then the deletion request doesn't add anything meaningfully different.
Actually, it's more like a giant gift to Google and Facebook: GDPR borders on regulatory capture, with only the giants really having the resources to comply properly. This will hurt startups and smaller firms far more than it will the big dogs with their armies of compliance lawyers.
I attended a GCP event and I could practically see the hipsters pupils dilate/mouth foaming as they went in the hisper frenzy "this GDPR is a huuuge opportunity".
Max Schrems (who's case killed Safe Harbour) has set up an org None of your Business (https://noyb.eu) to do exactly this.
But would it be so crazy for these regulators to hire someone who knows something about commonly used open source software and building web apps, to help provide a little bit of actionable technical advice? For instance, the majority of the internet is running on Apache or Nginx, why not have an official, EU-sponsored blog post explaining "here's how to set up a LAMP stack, or nginx and rails on a linux server, that complies with GDPR". Of course they can't cover every obscure language or framework, but it would be a starting point. And it would probably end up a lot cheaper than having to investigate and/or penalize people who didn't read the fine print of the law and/or didn't understand how it translates to actually running software.
Because despite how "simple" this post is saying these laws are, there still seems to be quite a bit of confusion on this thread, among smart developers, about questions like whether or not we're allowed to keep collecting webserver logs in the default format or not.
Say our landing web page contains an intercom chat widget and google analytics tracking.
At that point we have collected the user ip at most, which would become sensitive only if connected with data from two other businness entities.
What the heck am I supposed to write into the damn thing now?
https://gdpr.report/news/2018/02/01/gdpr-google-analytics-2/
If I were you, I would add my own chat (there is bunch of them on github) and use piwik instead of google analytics.
(By the rule of the thumb, for each 3rd party provider, ask them about gdpr compliancy and purge all the data you are not getting user consent - GDPR is retroactive)
You have to assess each use to which you put any personal data and determine the correct processing basis for that usage. Often there are more relevant bases than consent.
I do appreciate that the definition of 'consent' in this regard is often thought of in different terms though. When I think of consent I think of the narrow data protection consent, whereas I think often in layman's terms it has a broader definition which is often linked to disclosure requirements in relation to privacy policies etc.
Technology is something which constantly changes. From the point of view of the legislator, legal text that is too concrete will stagnate innovation and progress by "locking" people into current technological assumptions. The text becomes inappropriate/outdated when the next wave of technologies come along.
Thus legislators try to document the spirit behind a legislation and try to stay away from concrete implementation details as much as possible, in order to give people maximum freedom to decide how they should implement things, and maximum freedom in technology choices.
So yes, to us implementors it is a hassle because we have no idea what we should concretely do. But we can also see this as freedom to explore how to best implement an idea.
I expect that in the next few months/years, domain experts such as us will debate and decide on implementation best practices.
But this one comes with massive, company destroying fines attached.
If you and other domain experts debate and decide on a best practice, and then some EU commissioner disagrees and destroys your company with a fine you cannot pay, will you be so sure that vague laws are a good idea then? Will it seem like freedom to explore, or will it seem more like walking through a minefield?
The EU wants to regulate the precise details of data handling in software firms. It can do that. But it's trying to have its cake and eat it - micromanaging the tech industry at the same time as refusing to be precise about what it wants. It just expects everyone to intuit what they want, on pain of corporate death if you fail.
They are not company destroying for large companies though. By raising fixed cost (and risk) of doing business, regulations of this kind are an absolute godsend for large companies.
But the European Commission does gives examples: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
This is of course no nginx configuration. But the thing is.. there is no one size fits all example configuration. The situation depends on: 1) What do you use the data for? 2) How long do you really need it? 3) Can you securely handle it? 4) Has the user consented?
Saving ip adresses in log files can be fully complaint IF you only use them for legal reasons (sue an attacker, ...), have severe access restrictions on the files, delete them as fast as possible and get consent from the user prior to saving the logs.
It depends on your goal, workflow and abilities if you are allowed to store this data, and you must decide for yourself. If in doubt.. don't store it.
You do not need consent for saving the IP, user agent and URL (including GET values) in Apache logs because, as someone said above, you have a "legitimate interest to combat fraud and maintain information security".
Legitimate interest and consent are only 2 of the 6 legal bases under which you can collect and store (process) personal data. Art. 6 contains all 6 https://gdpr-info.eu/art-6-gdpr/ .
Didn't you know? They do. Large corporations are always happy to help regulators write laws in such a way as to benefit them to fend of those pesky innovators. [1] Raising compliance costs as high as possible is highly desired by large companies.
Or foster new technologies around privacy and user management.
Why? You have a legitimate interest (one of the six legal bases under the GDPR) to combat fraud and maintain information security. That's the primary reason you have those IPs in your logs in the first place.
If you're using those logs for analytics purposes, things get slightly murkier, but if you're just using IP addresses to enrich your log data with GeoIP, you should be fine. You might even be able to get away with more granular third-party databases, but the more detailed you get, the closer you get to profiling (which is not where you want to be, if you want to minimise your legal fees).
More to the point, I don't understand all this talk about web logs being illegal. If people have collected and processed personal data without thinking about the whys and wherefores, isn't it just a good thing this makes one think about what one is logging and what it's used for? Granted, IP addresses are far from sensitive (depending on your threat model), but I've seen things in technical logs that make me happy about reliable automated retention policies. Also, granted, it's a hassle - that's the price you pay for privacy.
I'd still be glad if nginx et al shipped with more GDPR-compatible defaults.
If people are creating software that burns fossil fuels without thinking about the whys wouldn't it be a good thing to have a law that regulates how we use electricity? Shouldn't an EU regulator have input on whether you can release your new blockchain app? You should be fine if its purpose falls into one of the covered categories...
People are creating online communities that enable abuse of members. Do we need statues and regulations to mandate abuse protections in online interactions and punish platforms that allow users to abuse other users?
They aren't. Only hardware burns fossil fuels, and computing hardware doesn't inherently do so, for the most part, only if you choose to hook it up to a fossil fuel power plant rather than something else; the software isn't the thing directly to address.
OTOH, the personal data use you are drawing a poor analogy to is the direct point of concern.
Misuse of personal data is a problem. Wasting electricity is a problem. Online harassment is a problem.
In some European countries, there are regulations already on how to insulate new buildings to avoid energy waste.
Sure, what could go wrong there? Regulator, "We're going to need to look closer at that for-loop to see if it complies. And you do realize that n+1 queries are a violation of EU law?"
Fire safety regulator: "we're going to need to look closer at that door seal glue component to see if it complies...". Nobody complains here about a regulator looking into details.
I seriously don't get what's the huge deal about this. Of course it sucks but it's not THAT hard to implement.
AS per the GDPR I see no possible solution for the “reasonable measure to verify the identity of a data subject” against an IPv4 IP and thus to reliably act on IPv4 related data subject access/deletion requests.
Also per the GDPR, providing data to the wrong person could “affect the rights and freedoms of others” in which case you shouldn’t provide the data.
You need retention policies and if you use the web logs for (let's say) detection malicious behavior or troubleshooting, you are in the clear.
Of course in reality nothing is that simple, but it can be done, and it can be done automatically. I am sure there will be GDPR nginx plugins/configs available soon.
(Brute force of few billion hashes in the days of crypto currencies is a walk in the park)
It's not like you couldn't say the same thing x1000 with respect to finance laws.
However, the devil's in the details, specifically in how these principles are supposed to be implemented. Some of these details are not quite clear yet. It's almost impossible to navigate these issues without getting at least some basic legal advice and investing a fair bit of time.
Unfortunately, as often is the case with EU regulations these seem to be targeted mainly at larger companies or corporations, which can easily afford this because they have legal departments anyway.
As a company that uses third-party services for data processing (which includes almost every piece of SaaS-type software) you have to sign a data processing agreement with each of those, which can mean considerable effort.
Some suppliers unfortunately are not as well-prepared yet as they should be.
Therefore now a company's processes continuing to run smoothly might depend on some third party getting their internal affairs in order. It's true they should've done this long before and one shouldn't continue to work with them if they fail to do so. Still, it's a problem you have to deal with.
I agree that GDPR makes sense and it's a good idea to follow through with these measures. It won't be easy in each and every case though and it might be a bumpy ride at first, which is why I sincerely hope that in the beginning authorities will be lenient with parties that act in good faith.
Small businesses have been specifically and routinely targeted by dubious law firms for not complying with certain regulations like legal notice requirements or disclaimers on websites.
The EU and local as well as member state authorities also often are oblivious to problems smaller companies might have.
At least for SaaS it's pretty clear-cut. For freelancers, contractors and consultants the situation is way more confused.
AFAICT I need a data processing agreement with every client, even if I only log into their servers once a month to update WordPress and check their logs, because I am now deemed to be processing personal information.
These details need talking about, and I've yet to see industry bodies doing so.
Either they have the organizational capacity to handle private information properly, or they should not do it at all.
There's no reason for every company to get a data processing agreement with every SaaS they use as long as they're not putting private data of other people inside; and in most cases (except CRM and payment systems) they should not do so. There's no reason for every random company to get a data processing agreement with the contractor maintaining their WordPress site if that site doesn't contain any private information, and it probably should not. On the other hand, if it does, then giving full access to that data should be more difficult than simply giving the keys to a random contractor; the company is fully responsible for whatever you do ("Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."), so that includes vetting you, being able to supervise what you've done, and probably some liability requirement. On the other hand, if that's a standard service you're providing, it all means that your standard agreement form just needs a few extra paragraphs to cover that data processing part.
The log/IP address issue has technical solutions - you can use logrotate in combination with gnupg to ensure that logs are available if you need to analyze them, but are encrypted and not available to everyone logging on that server.
While I admire the intent here, in the world at large it seems that multinationals and governments fail at this one with monotonous regularity and Blanche's final line - 'Whoever you are, I have always depended on the kindness of strangers', has been adopted by the computer security industry as the unofficial motto.
Of corse not. What will happen instead is that behind a consent box a lengthy disclaimer will ask consent for every piece of information and blanket every length of scope, triggering a cascade across providers and contractors.
And this is the reason: https://www.paypal.com/ie/webapps/mpp/ua/third-parties-list
This might help:
Of course they need to share data with payment providers (like a bank), or else they won't be able to get or deposit your money.
Of course they need to share data with auditing firms, or else they won't be able to do business in certain countries.
Of course they need to provide customer service.
Of course they need to check for fraud.
etc.
What do you expect Paypal to do in those cases?
Consent is mostly relevant to all the marketing and customer analysis activities, which aren't essential to the service, so can be refused, and would be severely curtailed as users stop consenting to these uses of their data.
They are already profiting from the service they provide but they still give (Sell! I bet they can use a different terminology but essentially this is it) the users data to other companies.
Those are the companies that brought GDPR on all of us, and those are the parties that should be punished with 4% global revenue, multiple times.
I bet everyone will be shocked what the companies are doing with our data, from our banks, credit card companies, insurance companies,... i think that everyone (or most) will stop complaining about GDPR and want it for their country too.
Just an example, what gets delivered just for Facebook: "Advertising ID and device ID to segment user groups based on app behaviour, encrypted e-mail address associated with PayPal users (without indicating account relationship), IP Address, Anonymous ID generated by cookies, pixel tags or similar technologies embedded in webpages, ads and emails delivered to users. Mobile advertiser ID, IP Address and other metadata via Facebook SDK in mobile apps."
Encrypted e-mail address? Why encrypted, not hashed? IP? Why the FB needs my IP on connecting to paypal? And the list goes on and on. If GDPR will stop this the whole world will benefit.
If you have the same use case of private data but have technical changes (i.e. a different subcontractor handling the processing) then you do not need a new consent.
If you have a new use case, then yes, you get to use only the data of those users who agree to it. Which will not be all users anyway, as consent must be freely given, i.e. with an opportunity to refuse consent but keep the service.
The expected result of "a consent box a lengthy disclaimer will ask consent for every piece of information and blanket every length of scope" would be the TL;DR reaction - since all of that must be opt-in, the user would just click "Continue", keeping the default settings that don't give you any consent.
That is not how some are reading it. It's not how I've understood Article 28(2) either, though getting new consent each time is nuts (e.g. I change from Mailgun to Postmark and have to ask all SaaS customers for consent).
Some discussions: https://seqlegal.com/blog/article-28-gdpr-problems-processor... https://seqlegal.com/blog/gdpr-sub-processors-and-authorisat...
This makes sense from the user's perspective. Maybe they trust Mailgun but do not trust Postmark. If they have explicitly agreed to you sharing their personal data with one company you shouldn't be able to start sending that customer's personal data to another company without their consent.
If you sign up for my service and I ask for consent to send specific data to SecuriCo for "user analytics and tracking" I shouldn't be able to change that to sending the data to the NSA without telling you. The whole point is that the user should be in control of what businesses are doing with their personal information.
If a company legally holding private data (i.e. a controller) gets a different subcontractor (a processor), they do not need new consent from the user; and the controller is still fully responsible for the data privacy.
In your example, you're a processor who operates the data with controller's authorization (let's avoid the word "consent"; this is a quite specific term in context of GDPR with a different meaning) - and they are responsible for ensuring that you will safeguard this data properly, so they can't transfer data to you if they don't have solid guarantees about what you'll do and not do with the data they're responsible for.
And the particular situation seems reasonable to me. You do not need to ask all SaaS customers for some action; as your links directly quote ".. or general written authorisation of the controller" i.e. your agreement can specify (if your customers are okay with that) that you're allowed to use other processors and change them. You do have to inform them about such changes (just as you informed them about the current subcontractors touching their data before they signed up, right?). If you change from Mailgun to Postmark, all you have to do is to send a notification to all your SaaS customers, and nobody is going to cancel over that. On the other hand, if you change from Mailgun to NigerianPrinceMailings Inc., then they might reasonably want to decline, so that's why the notification is required.
Ok, that is just silly. This sounds so much like the 'Why do you want privacy if you have nothing to hide?' arguments. It is very reasonable to both have a company that handle customer data responsibly AND have issues with the GDPR.
Imagine if every time you walked down the street, the police stopped you and made you prove that you hadn't murdered anyone that day. You might get get annoyed at the 10 minutes it takes to prove our innocence. If you complained about the extra time and intrusion, would a fair response be "Every complaint about this check shows you don't care about murder"
No, you can both agree with a goal of a regulation and disagree with the mechanism that they implement it. It is certainly NOT the case that 'the only thing GDPR wants from you is to handle others data with the same RESPECT as you handle yours'... they want you to DEMONSTRATE this in a particular manner. Those particulars are important, and we can disagree on them without it being some sort of moral conflict.
Plus a minimum of 20M€ fine in case they don't think your "common sense" is good enough.
For a one man shop that is not working under the legal protection an LLC or equivalent provides, this can be deadly!
That is a figure used to bring non-European companies who wish to trade in the EEA but not comply to the negotiating table.
We rarely see the largest tier of fines here in the UK, I'd expect little to change there too.
Reputational damage should be a focus of anyone concerned with risk here.
This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
Why? It's selective prosecution, plain and simple.
These things have a history of being selectively used to punish institutions for other reasons that are not easy to do using the law
To the people downvoting, imagine the following scenario:
Website promotes ideas the EU finds problematic. The EU wants to silence it but can't because of free-speech laws or any other constraint.
All they have to do is find something trivial under this law and punish them for it, bankrupting the company.
All of these "I hope the law will be applied reasonably" are dangerous because they give the state too much power.
As for IPs. Any website could claim they need IP addresses for analyzing malicious use. So either it'll be a new cookie law in which they all use the vagueness of the new rules to loophole themselves out, or the EU will decide that this is only "reasonable" sometimes. The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
Here's what will really happen to HN - nothing. But Google will get huge fines for doing exactly the same thing, and everyone will be left wondering if they're next.
Which they explicitly choose to do
> some use their real names as their username
Which is not required to use the site
> the site asks for email addresses
But you don't have to give one. If you do give one it is only used for password resets. Write that in your privacy policy and keep the email safe.
> Any website could claim they need IP addresses for analyzing malicious use
Yes they can, and the law allows it. Don't sell them to data aggregators and put it in your privacy policy why you are keeping it. If you don't want to then send the logs to /dev/null
> or the EU will decide
The courts will decide.
> The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
What do you want from the EU? A law that references the internet protocol explicitly, and every possible use of it? What happens when the protocol changes, or someone invents a new protocol, or a new way of exploiting it? Pass another law that says the same thing? Laws in the EU are generally principle based for exactly this reason, they age much better.
> Here's what will really happen to HN - nothing
Because they are doing nothing wrong!
I'm genuinely curious.
However, it is a lot more likely that the LLC is owned by those with no nexus to Europe it is extremely unlikely that EU can do anything to punish this company. Hell 99% of web forums have European users.
Maybe it will have teeth against Google/Facebook/Tinder/Match/etc because those companies actually have assets in Europe but it won't be effective against companies with no nexus.
[0] https://en.wikipedia.org/wiki/List_of_United_States_extradit...
These laws have to be implemented in each of the member countries, so you'd be violating the law of one of those countries.
If there is a tax agreement between a specific member state (EU) and the US, IRS can show interest in Joe. If there are like a thousand sales in a specific member state (the taxation is not EU wide global), no one will show interested, so if Joe is small - it's very likely Joe is safe.
Operating w/o the VAT could also spring money laundering interests -- the institutions concerned with anti-money-laundering cases tend to have rather long reach.
Overall VAT is taxation on the consumption, the consumption is within the EU member state, the state receives the tax.
Summary:
When US companies encounter European VAT: When doing business in the territory of the EU a company will deal with VAT: when selling something, the company will have to charge the customer with VAT... [0]
Also: The EU’s VAT law considers everything that is not a good (generally a tangible property) as a service. Services can include everything from the licensing for intellectual property to downloadable software to consulting – to name but a few examples. The VAT requirements for services depend on the final customer
U.S. Foreign Commercial Services for U.S. Companies [1], [2]
[0]: https://www.rsm.global/insights/tax-news/europe-how-european... [1]: https://2016.export.gov/europeanunion/eg_eu_030910.asp [2]: https://www.export.gov/article?id=European-Union-How-the-EU-...
You are confused. Selling services to EU residents without VAT is perfectly fine if the company has no nexus to EU. Just like it is perfectly fine for a company that has no nexus to the United States to sell services to residents of New York City without collecting NYC sales tax. Not only is this done all the time, it is a standard tax minimization strategy peddled by the likes of DT and BDO.
The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU.
Conversely, I have bought many items and services online from EU companies who don’t have presence in the USA. Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.
In short, my experience is you’re just plain wrong. A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.
If you import goods (receive them via mail), there is a customs clearance required + VAT for prices over N euro (where N varies on the country but usually less than 25e). Indeed that's a direct responsibility of the receiver.
>Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.
Please don't mix the laws in different jurisdictions. VAT is quite different than sale/use tax. Try and buy goods from USA (even ebay suffices) and receive it within the EU w/o paying VAT (unless explicitly exempt from the tax)
Electronic services have no customs clearance or physical presence and what I explained above (VAT number, etc.) applies.
>A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.
Proof by authority ain't cool. VAT does apply to the end user (companies can receive it back, etc.), so I am unaware if your employers used to sell to end users directly. If selling services was that easy, registering outside EU would so temping as pricing ~20% less would be great. As proof goes: I consulted an accountant about US offered services to a local EU member state. (didn't have to pay anything)
Examples of not being able to sell services to US residents are forex and gambling. Non-US companies practically can not take US customers. Selling services online ain't that easy even to US.
Appeal to authority isn’t a logical fallacy when the authority is an expert in the domain.
I've been looking, and I have found a bunch of contradictory explanations. My best guess is that if you have a disclaimer that says you log IP addresses for security purposes, you can keep your access logs indefinitely. (see: https://community.spiceworks.com/topic/2041760-access-logs-i...)
This seems like the sort of concern that should be clearly addressed with an official answer before the regulation takes effect.
The reason GDPR is a bad law is that its real effect is so ambiguous.
Read literally, it imposes significant burdens on data controllers, particularly because of things like the right to erasure. Those burdens may be disproportionate particularly for smaller organisations that only handle a limited amount of data in the first place.
The alternative, which I've noticed GDPR's defenders tend to favour as understanding has grown, is something to the effect that regulators won't actually enforce the rules in a draconian fashion and will only go after serious infringement in practice. But that's a dangerous position to adopt in legal matters, because ultimately it means if you go too far in complying when others don't then you are at a disadvantage, but if you don't go far enough then you are subject to being punished at any time, and there is no objective standard for how far we're talking about either way.
Exactly this. As a consumer, I really like most of the protections that GDPR provides and I want them to be widely followed and enforced.
As a freelancer who works with mostly small clients, I really wish that there was clear, official communication on what sorts of common practices need to change (or not) and examples of solutions that small businesses can implement to be compliant. Just telling them to not worry because they're too small for enforcement actions isn't a good solution since it limits privacy protection and compliance to large companies.
As a freelancer/consultant, I wish there was official guidance on when we are a data processor for our clients, and when we're not. Which employment situations make a difference (if any do).
It's not just our industry; anyone who's self-employed is in the same position if they see any personal data from their clients' businesses.
- Make a link to a privacy policy clearly accessible (eg on your website footer) and make sure it contains all of the required elements of information (see Article 13)
- Do not store the data longer than reasonable
- Do not worry too much about logs/backups etc as long as what you do is reasonable and you do have a reasonable delete schedule - no lawyers I have met seems to worry about this.
- Worry instead about for what purposes you actually use data you collect (what other orgs do you share data with, why, what do you do with the data that produces an effect on the data subject (eg marketing) etc)
Assuming you are right, that answers part of my question. Yet, I would prefer to see this detailed by an official source.
The other part of my question still remains unanswered. The GDPR limits who qualifies as providing goods/services, but I don't see any limitation on who qualifies under "the monitoring of their behaviour as far as their behaviour takes place within the Union."
It seems like this create a legal liability for every single website with an access log unless it displays a privacy policy.
[...] In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.
It appears like monitoring is closely related to profiling, defined in Article 4 as:
‘profiling' means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
If you are trying to eg. predict preferences of data subjects by collecting the logs you are probably monitoring their behavior.
If you are doing this it should be pretty clear to you from the purposes you are collecting information for. Security purposes (such as preventing DDoS attacks) are probably not purposes of monitoring data subjects behavior or profiling.
> potential subsequent use of personal data processing techniques
Not a lawyer, but doesn't every access log with IPs and urls have the /potential/ to be parsed to aggregate a profile of site usage?
Even if you aren't actually doing or intending to do any profiling, the potential still exists.
You may well be correct about all this (and I suspect you are). I'm specifically trying to push back against the assertion: "I really don't think ... that anything in GDPR is hard to understand"
“Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes“
If a company starts collecting IP addresses for DDoS protection purposes, and then figures out that the data could also be used for marketing - that is most certainly in violation with this principle and therefor forbidden.
A “lawful basis” for the marketing purpose will not save you from this principle.
This is also where the public privacy policy/notice plays a role - for the company to be able to prove that the IP addresses where also originally collected for marketing purposes and fair information was given about this purpose at the point of collection.
In terms of GDPR’s territorial scope I guess at the point in time you start to use the DDoS prevention IP logs for profiling you come into GDPR scope. You would also be immediately be in violation of the purpose limitation principle if it is for marketing purposes.
Charitably, I think your sentence is just unclear. It seems much more reasonable that someone just thinking or realizing "that the data could also be used for marketing" isn't legally prohibited. Right?
Someone would actually need to use the data, in some concrete specific way, for something illegal to have taken place.
Right?
There is a lot of more behind the articles in GDPR since it is partly based on legal instruments on data protection from 1981(!), “Convention 108” and EU legislation from 1995. Case law, opinions from data protection authorities etc. are important.
In general though, I would not be worried about big fines or anything as long as you try to follow GDPR and you are not doing things the data subjects does not want you to do with their data.
In general, the best GDPR compliance test is how it feels in your gut, after learning the principles.
At the point in time you process personal data against the interests of the data subject (for example building marketing profiles, sharing data with third parties w/o request from the data subject, etc) it is time to start worrying and make sure you cross the i’s... GDPR is pretty permissive in general IMO but make sure you know the details.
Then every system implementing fail2ban or email tarpitting (so everyone running Ubuntu or MS exchange in default configs) is automatically violating GDPR.
Never mind the built-in catch-22 where you can’t store any identifiers of persons who have opted out, so you cannot remember they opted out and have to ask them repeatedly!
This law is completely unenforceable, and that is the worst kind of law. It results in inconsistent, politicized and malicious enforcement.
European legislation demands this in fact. You have to keep the logs for a few months.
Apparently no longer in effect (overthrown)
Same thing for IRC or xmpp servers
It was actually quite broad.
Beyond that, why store them?
[ed: incidentally you're kinda sorta in the area GDPR wants to combat: "it'd be nice to know what x want to buy next, and where - for logistical and marketing purposes. Why can't we just store a full profile of everything x does, where and when?]
I am supportive of the intent of the GDPR and we have always gone out of our way to minimise the data we collect, but as currently written the law has a whole lot of very negative downstream effects.
Really the law seems to have been written to catch a few bad players and has ended up netting everyone in the world.
Can't argue with the fact that storing less and corner grained data will make certain ad hoc queries harder.
That's kinda the point.
Yes it was only because I had the logs was I able to do this analysis. The issue is not over these sort of analyses which I am sure nobody would object to, but that GDPR casts such a wide net.
The complication is that I have a client-based fallover where when one server becomes overloaded the client is switched automatically over to a different server (client based load balancing). This make it hard to sort out where the load is coming from without looking at the IP address.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Either the old IP addresses can be tied to a specific individual, which means they are potentially useful for legitimate security purposes such as helping to identify someone who has previously tried to scam you, or they can't, in which case what is the risk of keeping them around anyway?
GDPR wants you to think differently about it: if you want to keep data, ensure that you actually need it. Do not treat data as an asset but as a liability.
I think it's important to remember that GDPR itself doesn't want anything. GDPR is not a person, it's a set of legal regulations. What matters most about laws is what they actually say. Intent, as has been demonstrated countless times, is secondary.
Now, the people who wrote the GDPR might have wanted people to change their minds or think differently about privacy issues. However, that doesn't make the GDPR itself any less dangerous, and as I've argued elsewhere in this discussion, essentially those same authorities do have form already for being heavy-handed in other areas of EU law, and have caused real damage to plenty of businesses as a direct result.
But you can never guarantee that someone else won't do. The biggest issue to user's privacy has traditionally been data breaches. So even if you don't want to do something shady, a data loss might still be highly problematic for users.
I agree that IP addresses are unlikely to be the biggest concern here however.
I'm not convinced that's true, but let's assume it is for the sake of this discussion.
In that case, wouldn't a better approach be to mandate reasonable safeguards to protect against data breaches, and to penalise those who are seriously negligent in that respect?
Otherwise again I think you're aiming at the wrong target. Deleting stale data might have some marginal benefit in terms of privacy in the event of a breach, but the risk and consequences are surely much greater for the organisation that has only recent data but uses admin:admin for their root credentials. Meanwhile, the overheads of updating long-standing logging or backup systems where that older data might lurk to fully isolate everything could easily be among the highest practical costs for compliance, particularly for a lot of smaller organisations.
Peoples lives and most intimate details is going to be stored as bits. Get used to it.
Whether for targeting purpose (Facebook) or personal reasons (Strava). Whether stored on remote servers or home. It wont affect likeliness of data breaches. Focus on good software designs and let programmers design such systems in peace.
All this needed was fine for data breaches. Not the mess called GDPR.
Changing that is nontrivial, since it requires changing the behavior of everyone handling this data - so, something that can be done only by law. It will restrict Facebook, it will restrict Strava, it will restrict data stored on remote servers and home. While it won't affect likeliness of data breaches, it will affect the impact of data breaches - realistically speaking, many of the breached companies should not have had most or even all of that private data in the first place.
A data breach can't reveal information that you don't store; so a push to ensure that less companies are storing sensitive data, and those who do are storing less of it - that's something long overdue. GDPR is not designed to have people do X, Y and Z so that they can keep doing business as before; it's designed to ensure that many (most?) places where private data is used simply stop doing so.
So if the rationale for GDPR to reduce data breaches or to deny private data to future rouge govt, then it fails. Private data will still exist even if its not commercialzed. Its irrelevent who control it (user or company) as long as its connected to internet, there is risk of data breaches.
Unless you propose to go back to storing actual photos in actual albums. ITT im not sure.
That's different per legal system. In some the text is more relevant. In various others the intend behind the law is very much relevant. I highly suggest to not follow your advice!!
Pattern: propose easily misused overly broad law. When people express concern claim that the law is only to deal with problem foo and would never be used to do what it says in plain language. Proceed to do what it says you are allowed to do.
It could possibly be expressed as don't accept intent and goodwill in place of plainly expressed limits on government or regulatory power.
In which EU or EU member state jurisdiction is that not the case, please?
Again, the GDPR isn't really a set of rules per say. It's some rules (eg on consent), plus some frameworks (legitimate interest balancing test). The country-specific privacy orgs are figuring out the balancing tests and are promising final guidance, like, totes any day now. Meanwhile, the deadline is 25 May.
NCEES recently created a PE exam for software engineers in 2013, in collaboration with IEEE and IEEE-CS. However, it's up to state engineering boards whether or not to administer the exam. California does NOT yet the administer the Software Engineering PE exam.
Yes. Most CS/CE/SE programs in the USA are part of the school's engineering college and are ABET accredited, which is the governing body of professional engineering in the USA. To become an PE in the USA, one needs to first graduate from an ABET program, take the Fundamentals of Engineering exam, work for at least four years in their field of study, then they make take the PE exam.
Now, almost nobody does this right now. Only 32 people took the Oct 2017 exams in Software, and Computer & Electrical Engineering. For reference, about 4000 people took the various Civil Engineering exams.
There's really no incentive to become a licensed engineer the USA. I've never seen a job posting mention one at all. So I think the exercise would be purely academic (though, I'd love to hear from someone who has a license and uses it).
Nationwide, there's only 27 Software Engineering programs accredited by ABET. So graduates of those programs could sit for it but until graduates from top programs qualify, no one is going to require it.
Wait, are you sure about this? When I was in school, they pushed CS/CE students to take the FE Electrical and Computer exam. I never signed up, but why would the school nag students to do something they weren't allowed to do?
Undergrad engineering culture elevates the ring into a mythical embodiment of the deliverance that is graduating. Then, naturally, the moment you have it on your pinky, it's a status symbol – you're 23 now, old enough to act real casual about it, but man, shit feels like you're 13 and just emptied a can of Axe spray on yourself. The noble humility is very shortlived, in my experience.
Somehow those in medicine seem to be doing a bit better, with their Hippocratic oath. Maybe it's a maturity thing. But yeah, I think actually teaching these kinds of practical ethics more would have a bigger effect.
So it's not anything to do not respecting our customer data, it has everything to do with not seeing the unintended consequences.
Just figuring out if users are allowed to use my service is hard. There is a different age of consent in different EU countries, and apparently some haven't even decided on an age of consent yet. What happens if I am in a country that has age of consent of 14, but then they vacation and use the app in a country that has age of consent of 16? We are required to offboard users if they aren't of the age of consent. What is the support flow for letting those users back into the app if they accidentally said they were born in 2016? What if the company owns multiple apps, and the user users the same OAUTH account to login into each app? If in one app they enter their birthdate as underage, now I have requirements to delete the user from all apps.
My default mindset is to avoid collecting any data that I don't need so my app stores almost no info about where users are located. But EU regulations have told me I need delete all EU user accounts who don't agree to the new terms in X days after May 25th. Does this mean I have to go delete all user accounts who haven't logged in since a certain date since I can't differentiate EU vs non-EU? Those users aren't going to be happy. Some users log in through email so we are able to email them, but other users use phone number login where we can't contact them. We are potentially deleting huge numbers of accounts.
We host our help center site using a third party service. Does that third party service happen to store IP address in the logs? Now I have to care about that as well.
Lets say my company built an Apple TV or Xbox 360 app two years ago. There is a small group of dedicated users but it doesn't make us any money and we haven't updated it. Now we have to go build an interstital making them agree to new terms before they can use the app. None of the developers who built the app are still around, I guess we need to just delete the app now.
It turns out that there were a bunch of Russian accounts who tried to manipulate the election and we only found out months later. Good thing this happened before GDPR. After GDPR all they have to do is claim they are in the EU, and then delete their account, and there data won't be completely unaccessible 30 days later.
I am a big advocate for privacy and a member of the EFF for a decade. Maybe my company just already has good privacy practices, these regulations are making development much slower, without providing additional privacy benefits. If you want to see some change, I would think massive fines for data breaches would be the way to go.
I'm not complaining. I'm just saying it's not basic or simple. I often see the attitude that, "Oh that should be easy" when someone hasn't implemented something.
This essay covers it well: Reality has a surprising amount of detail https://news.ycombinator.com/item?id=16184255
It reminds me of people who have taken the programming 101 class telling me, creating Amazon is easy, its just a webpage. Or I could completely run Twitter off of just 4 machines.
Oh, and when asked for a date of birth, they don't know what to put because it's a company account and not a person.
So they put the founding date of their company.
Which is often less than 13 years old. So now the account is locked because they need "parental consent". Or maybe they're trying to create an account, in which case they need to be locked out from creating an account because they "lied" about their age. But they aren't logged in, so how do you do that?
The already existing account doesn't have a parent of course. And it's owner is already an adult. No problem, you think, the owner will just have to prove they're an adult and it's OK.
But COPPA specifies precisely how you can check if someone is an adult, and it was written by a bunch of US regulators who don't appear to know much about life outside the USA. For instance one acceptable age verification mechanism is a credit card, but lots of people around the world don't have credit cards. Everyone having 5 cards is a US thing. So that doesn't work. You could also do a video conference with them, but good luck hiring enough people to do that at anything like a workable cost (per user margins are ultra thin). And so on. Pretty quickly you realise there's no way to recover that is both cheap enough to be deployed, and globally usable. That ignores the fact that some techniques hurt privacy far far more than any website ever normally would e.g. demanding and verifying government ID.
So people just lose their business email.
I've never seen a government pass data related regulation that wasn't a complete disaster. All such laws I'm aware of are riddled with contradictions, collateral damage and total absence of evidence that it actually helped anyone, anywhere.
Yes, because the "just don't do creepy shit" approach to privacy didn't go so well. If the carrot doesn't work, the stick comes out.
As the operator of the website it becomes your duty to properly inform the user of what you are doing with their data and why.
If you send me an email, am I allowed to keep your email address in my mail logs, archives, and inbox? Hell yeah I am, you gave me implied consent to do that by sending me email.
Am I allowed to spam the email address you gave me? Of course not. But I can keep it.
Placing an automatic and extreme burden on the recipient of a communication like a website visit or email, which is exactly what the GPDR does, is just plain bananas.
How are others planning on deleting data from all backups. It seems like any automatic process that modifies all existing backups has the potential to accidentally corrupt all backups in the process.
Is there any safe way to safely delete a record out of my prior database snapshots, or is there a reason I don't actually need to do this?
Don’t leak private keys, so you should generally use a decryption service if you need access to the data record. Handy to prove access too!
That works and survives fairly intense audits at least in my experience.
We have no plans to retroactively fix our backups. But we will have to make damn sure that if we need to use a database backup we do not reintroduce user data that we've purged. For that purpose we will have to maintain a list of which users have been purged until the backups rotate out. According to the advice we've had, this is acceptable.
This is the approach we've generally taken as well.
I hope I was helpful :)
But would you though? If you're a large co. you'd have a configuration management system where you just pull the specs/data rather than do an audit. If you're a small co. you'd know already, and if not you'd just go look. Right?
My experience is that anyone complaining about the amount of work GDPR is causing is a. not compliant anyway (and knows it) and/or b. has terrible or no IT governance.
Just to pick one example I've seen in practice, system A might have an integration bug causing system B to periodically emit error logs, containing data which system A knows is personal but system B does not.
So planet earth then. Consequences must be understood in terms of how things actually are even if the rules are ultimately for the best.
The law applies to business entities so it will go and cover every piece of infrastructure they run retroactively.
Imagine having a dev with contributions and commits in a dozen projects calling github to exercise his newfound right of removing all personal identifiable information from the system.