StreetLend.com shuts down, citing GDPR regulations
streetlend.com
streetlend.com
Thus, complying with something somewhat ambiguous like the GDPR is still an expense -- of time, money and risk -- that many small website owners won't be willing to spare.
Look, it's not hard to encrypt all personally identifiable information; there are ready-made frameworks that let you choose which DB columns you encrypt and how. You can generate a key for each user on creation and have their data encrypted with it. The problem is NOT that.
The problem is what happens if a legal firm or an agency targets you. Even if you adhered to the spirit of the law, they can dig up evidence that you didn't obey the letter of the law (since GDPR is quite loose and ambiguous).
Small tech owners can't fight such litigations. I am kind of baffled how this point evades so many people in this thread.
Defending even from bogus lawsuits is a huge expense of human energy for the non-experts (I'd wager that's 99% of the world's population).
Maybe as a countermeasure for abuse it's too small, but it's not a totally absent concern.
I suspect the DPA will start with a letter, where you will need to explain your current practices.
Then, nothing more happens (if you are mostly-complind and good-willed). Maybe you will get some written instructions to better yourself.
The authorities are not idiots, and have limited resources - they are only going to be chasing the true bad apples that are willfully infringing the GDPR.
if you’re so risk averse that any minuscule chance of GDPR noncompliance precludes you from running an online service... aren’t you already not running anything because of existing legal risk?
Can we just flat out assume the GDPR won't indeed be abused to scare away smaller players though? You are claiming they will be safe for years but what if bigger players want to make an example out of 5-10 smaller players and just report / sue them to hell and back?
I know I am reaching but this possibility can't be dismissed just like that. Historically, bigger players have exhausted smaller competition with legal fees and effectively drove them out of market. We cannot in good conscience claim GDPR won't ever be used like that.
I'll be happy to be proven wrong in several years time from now, but right now I am simply not sure if GDPR is gonna be used for or against the free market (competition). Not claiming either way, just saying the risk wouldn't be worth it for me for now.
That's what I'm afraid of, not getting randomly picked by the regulators.
The language of the GDPR makes frequent references to the scope of the processing activity and to its frequency. The law purposefully applies less to smaller controllers. The authorities have made their job harder for going after smaller controllers.
Moreover, the GDPR is done in the scope of the EU, which is not very litigious. Bigger players are unable to bring legal claims against smaller players in any way. The only way for them to game this system would be to fraudulently lodge complaints at the data protection authorities who would have to not notice what is going on and actually bring action against the smaller players.
My intent isn't malicious. I simply don't want to invest in more maintenance. Hence I'd block EU, yes.
Users of free services will just set their country to non-EU, and continue to consume the services. GDPR will gave achieved nothing in that case.
that seems simple enough - I think I'll add that to the projects I'm working on.
There is so much info I read on this today I closed the article but it said that their ticked-box consent and IP is not sufficient.
You need to be able to show the user agreed and what they agreed to exactly. A screenshot might do that but might also not be sufficient (if there is more text elsewhere on the signup process related to privacy)
https://www.mailjet.com/gdpr/consent/
Scroll to: How do I store consent under GDPR?
The record of the IP address, location and time at which someone submitted a consent form is insufficient without a screen capture of the form itself.
You welcome!
A screen capture is the easiest way to achieve compliance but the regulation leaves open other methods as long as you can show that someone gave consent and to what exactly. (IMO you could also store the HTML of the webpage they viewed at the time)
The law says you have to be able to prove the user ticked the box and provide an audit trail for it, IIRC some recitals mentioning that you should be able to reproduce the exact agreements the user made (ie, either in text or as a screenshot) so that you can later show the user and any regulatory body that asks what they agreed on.
This stems from the United States making their laws apply globally.
https://en.m.wikipedia.org/wiki/United_States_v._Elcom_Ltd.?
My company has no presence in EU, and neither myself, nor any one of my employees are going there.
What's the risk?
Some legitimate experts have concluded that this wording allows someone in the EU using a vpn they reports them as coming from outside the EU to be covered.
That seems like a low risk incident to me, but I’m not a lawyer & I can see where that interpretation comes from.
"Within" is a physical location, so arguing that IP block associated with request is a perfect proxy is at best a legal grey area. For example, an EU citizen could use a VPN to access your services and then send you a data request. See here for discussion: https://www.gdpr360.com/gdpr-ip-addresses-and-classification...
If this seems like a low risk incident, consider that there are litigious people inside the EU (as everywhere) that may actively explore the boundaries of the law.
Profiling data subjects in the EU is covered, regardless of where the processor/controller is located.
If you are processing personal data but not profiling and you are not established in the union it only applies if the processing is related to the offering of goods and services to data subjects in the Union.
For those who are not profiling, blocking EU IP addresses should help establish that they were not envisaging offering goods and services in the Union.
In fact, there are many ways someone might be profiling without knowing it. For example, precedent about when logging IP addresses constitutes PII is still evolving and seems to apply in cases that would be unintuitive to many US businesses: https://www.whitecase.com/people/tim-hickman. And there have been arguments that geolocating based on IP might itself be data enrichment that contributes to an argument that you are profiling!
Similarly, I haven't seen a clean interpretation of what constitutes offering (or clearly not offering) services to EU users, which determines application to a data processor. For example, if I offer a Portuguese translation of my site for Brazilian users, have I offered service to continental Portuguese?
IANAL but nobody knows exactly where GDPR will apply yet. I think the better takeaway for someone who is trying to respond with minimum effort is: IP blocking might help you build a defense, but it might matter how you implement it and it might not be sufficient.
Even if they could fight, why would they want to? There are lots of us with tiny things on the internet where the burden of maintenance is only slightly below the enjoyment we get making it available. Increase that burden and the costs are negative and things get shuttered.
Question, if I have a small thing and don't want to preemptively concern myself with GDPR, as a non-EU site operator can I tell an information requester "no"? Might I harm my ability as a person to travel to the EU? Ignoring the standard "if you do nothing wrong you have nothing to worry about" and "the GDPR is really easy to understand" arguments, and assuming I'm not wanting to do any real work, would it be wise for me to just add known EU subnets to my firewall?
Hobby or goodwill projects (==not turning a profit) just aren't worth that risk.
https://www.wileyrein.com/newsroom-newsletters-item-May_2017...
I got a couple of small details wrong, but not the main point: citizenship of the data subject is irrelevant.
However, IP blocks are still useless for the reverse reason: someone "in the Union" could be vpned through another country. (For example, I'm on vacation somewhere in the EU and VPN through my home computer to purchase something and have it delivered to my house in the US. By virtue of being in the EU at the time, at the least that specific information collected during my stay would be subject to the gdpr. How would said company ever know?
Examples they list: use of EU languages or currencies not used in the host country, use of EU domain names, specific wording addressing an EU audience.
This kind of nuance is where it's good that humans are the ones enforcing the GDPR, instead of needing a programmable rule.
a. The offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
b. The monitoring of their behavior as far as their behavior takes place within the Union."
This doesn't seem to discuss intent at all? I mean, we could mince words about what offering a service means, but that doesn't seem productive and unless there is some other part of the law redefining this, won't make me comfortable.
While that point of guidance won't have region-wide binding force of law unless the European Court of Justice rules that way, I'd be extremely surprised if any national supervising authority or court system would contradict such a document, since the official guidance's reading is clearly among the possibilities consistent with the text (admittedly not the only one) and predictability of this kind of law is key to achieving its goals. Even if they do, they wouldn't likely penalize people with more than a warning if they haven't announced their weird interpretation in advance.
Q: is it possible to be in violation of the gdpr in a situation where you could never know you needed to be compliant and have taken steps to avoid serving EU countries?
A, official: Yes.
A, unofficial: Most likely not if no one's having a bad day or has a bone to pick or is just being uppity.
Also, both answers are official and from the EU institutions. One is the law, and the other is meant to help interpret and apply the law. I'm not talking about third party compliance guides (except for the link I shared), of which there are many.
With all of that said... If you have both taken steps to avoid serving EU countries AND have also done things which they view as targeting EU countries, the answer would be murkier. For example, if you block European IP addresses but also use .de and .fr IP addresses and accept Euros, they might consider it to apply despite the IP block.
I'm also not sure what would happen if you took no explicit steps to target, but saw 80% of your customers coming from Europe on a sustained basis and did nothing to stop that.
Overall, the law will be interpreted with its own intent in mind: it should apply if you're engaging with Europe, but not automatically globally.
I understand if you want more certainty, but that's how computer programs operate, not laws.
The recitals do sound as if it applies to citizens, however the actual definition of a data subject for a company outside the EU is someone "in the Union".
Incorporate in the US?
An EU government could try to convince your own government to enforce their fine / injunction / extradition / whatever. I don't think the USA has any treaty or other law that would compel them to. I'd guess that Trump's administration would treat the request as something between a joke and an attack on American sovereignty, so I doubt that's a major risk here. Other countries may vary.
The easiest path for the EU to enforce is probably through your customers and vendors, probably starting with payment processors--like, require everyone who processes payments in the EU to transact only with people who transact only with GDPR-compliant companies. My personal guess is that everyone with a business model that depends on breaking the GDPR will move offshore, and the EU will play the same game of merchant account whack-a-mole that the USA does for online poker and such. I'd guess that the effort to enforce offshore will be big enough that only the most egregious violators will be worth the attention.
[0] http://ec.europa.eu/world/agreements/prepareCreateTreatiesWo...
Yes. This I think is a downside of the law. Some small owners are going to have a more difficult time.
But this is true for any regulation like food safety regulations, construction regulations, etc. They hurt more a small restaurant than a big chain. But in the end, these regulations are there to protect the customers. Small restaurants have closed and will continue closing for not following food safety regulations. But what is the alternative? Is business creation the final goal of our society? Or there are things more important?
In summary, small businesses are going to have to extend their insurances to also cover risks related to GDPR. But it's the price to pay for having safer data.
Status quo? Baby steps? Enforcement of existing statutes? Consumer education? Promotion/support of preferred alternatives? Codified small business leniency? Objective enforcement clarity?
For construction, you build your building to 'code', an inspector comes in and stamps the building and then your done. If your not code compliant, then you can correct without much penalty at all, not get a $million penalty and you don't have to go to court or get lawyers. Making your own shack in your backyard isn't an arduous process as far as code compliance goes.
Since most software is constantly modified and edited, I don't think the construction model really works. More the food safety one or a data fiduciary one.
But the GDPR works like this too? The $20 million fine is not automatically applied. Here's a flow chart which details the process of a GDPR breach: https://40uu5c99f3a2ja7s7miveqgqu-wpengine.netdna-ssl.com/wp...
from https://www.i-scoop.eu/gdpr/gdpr-fines-guidelines-applicatio...
If you breach the rules, a simple reprimand without a fine is possible too.
It actually doesn’t say that. This law has the effect of small business essentially needing a 20 million insurance policy to protect against the possible whims of an overzealous regulator? It’s either insure yourself for 20 million or risk losing your entire business over potentially a trivial matter.
When people in the UK have been jailed 8 months over traffic cameras or prosecuted and jailed for speech, I wouldn’t give a European government the benefit of any doubt. Willingly inviting an unelected regulator, accountable to nothing but the letter of a badly written law created by another unelected government body — that’s just foolish.
The maximum fine is a cap, not a guideline.
That's one of the funniest statements I've read today. Or annoying, I'm not sure. Definitely meaningless.
Article 83 (including related recitals)
And in food or construction if you willfully break the law then that can be criminal and you will face severe fines and/or jail. It's all about your intent.
Work in best interest of your users and you will be compliant. I don't think that this is harder than food safety regulations.
By the way, the technology is changing fast and a strictly defined law with "do" and "don't"s would be downplayed in weeks. that's why GDPR is conceptual (and thats why everyone is pissed off, as they can't downplay it - how many sites have you seen that are giving you a fair cookie choice?)
Companies have failed to regulate themselves since the dawn of time, this is how the world works.
I'm not sure how it's "easy to avoid sharing identifiable data"?
TalkTalk lost 150k peoples information (including bank account numbers, sort codes, dates of birth, etc - people who later then received scam phone calls with people who knew their details) due to extremely basic security failings. They were fined £400k (a record fine). They then did it again and paid £100k.
Properly securing the site and the data over many years could easily cost more than that, added to the chance you'll not get hacked or fined and it is perhaps even a financially sensible position to not put the effort in.
> That makes more sense as it doesn't invalidate 90% of standard tools processes in technical marketing for example.
Can you explain in more detail?
Stronger restrictions on what data you can hold without good reason or consent means that inevitable breaches become less important.
It’s a false dichotomy to compare the risk of DEATH from bad food safety to the annoyance of getting a targeted ad whilst enjoying an online newspaper article for which you didn’t have to pay.
Elevating data obtained while surfing the internet to the level of food safety or building codes is ridiculous.
Companies worldwide have consistently failed to safely store and process personal data. There are new data breaches every day. Irresponsible processing of data has a direct negative effect, and that’s not related to the idea that it’s misused for advert targeting.
Minimising the incompetence we’ve seen worldwide by treating it as “just some data collected while surfing” is baffling to me.
There's a huge chunk of the web that is filled with niche web tools, mostly made as a hobby, running for free. I myself own 2-3 such sites. Now, I'm forced to spend my hobby time adding a bunch of new features on a site that already loses money? I'm sorry but the couple thousand people that depend on this tool will have to find someplace else I guess.
HN sure loves to worry about AMP killing the internet, well to me this is far more dangerous. Can't wait for larger troll companies bullying small devs with lawsuits and killing all their competition using GDPR.
If not, then why do you expect the EU to go after the equivalent site with a few thousand users?
Does this apply? [1]
[1] http://fortune.com/2017/07/21/five-year-old-fine-lemonade-st...
* the fine has been cancelled and the council has apologised
* this is such a rare occurrence to be worth news reports
I'm going to say it validates the point.
> why do you expect the EU to go after the equivalent site with a few thousand users
You are saying that they DO that, but then will (probably) apologize afterwards. Some website owners consider that an unacceptable risk.
What new features do you think you need to implement to comply with GDPR?
`id, name, email_address`
You could simply blank out everything apart from `id`.
Regarding logs, it might be worth thinking about whether you actually need them to contain personally identifying information (e.g. IP addresses, usernames) - if not, just don't log them.
The alternative is to let consumers fend for themselves, and if government is going to help, limit that help to investigating and punishing fraud, enforcing contract law, and providing free information resources to help consumers make better informed decisions.
Yes business creation should be the highest goal of society. New businesses are what counteract income inequality and drive innovation.
We need innovation to solve the already existing problems in society, that claim tens of millions of lives every year. There is no zero risk path open to society.
1. This regulation is specifically (deliberately?) anti small business. If your revenue is less than €20m their fine is up to €20m, i.e. can be 100% of your revenue, meaning bankruptcy. If your revenue is greater than €500m, your fine is capped at only 4% of your revenue, i.e. an acceptable fluctuation. It's worse than a regressive tax.
2. China also has many regulations. Instead if trying to extend their jurisdiction to foreign sites, they simply block them. I thought about this and I actually prefer the Chinese non-expansionist model: I would rather outsource due diligence to the Chinese government than hire expensive EU lawyers and then implement EU specific blocks.
FYI we do not collect any data other than for spam and DDoS attack mitigation, but apparently if you have any third party code in your site like ads you have to subject all of that to this expensive audit.
Well meaning regulation like this written by people who have never created anything pratical in their lives other than regulations illustrates why entrepreneurship in modern Europe is nearly impossible.
That is easily one of the more absurd statements I've seen this month.
> Well meaning regulation like this written by people who have never created anything pratical in their lives
And websites whose customers advertising agencies, and whose product is people, create something? Attempting to track and then monetize everything everyone does online is _creating_ something now?
This is snarky, and intentionally simplifies things down to a dumb level. Here's a list of things that "create something" while relying on an advertisement model for revenue: - Gmail - Facebook - YouTube - StackOverflow - Reddit (to some extent) - Yahoo - Miniclip - Neopets
I can find a hundred other examples that are ad-revenue supported by create immense value.
It's a difficult balance to strike, and while not perfect, this model has allowed us access to so many good services that would otherwise not exist. Saying that none of them "create something" is just wrong.
Hell of a way to defend the most absurd and overreaching displays of censorship we see on the modern web.
And you prefer China's policy of censorship over the EU's policies of protecting consumer's privacy. Well that's interesting.
I am pro small business, and I am against censorship.
I see however historically opposite trends over the last 20 years: China is getting more free speech and is getting more pro small business, and Europe is the opposite. And it's not a coincidence. I think eventually the censorship curves of China and EU will cross. Small business friendliness curves crossed perhaps 15 years ago.
The GPDR might end up being bad regulation, but we we're already getting bad results for the average citizen. If the industry wasn't going to regulate itself, and it's hurting citizens, are governments supposed to just stand back and hope it works out for the best? Maybe in a libertarian paradise, but no national government is currently running on that paradigm
Edit: also free speech != No regulations. Companies aren't people and they shouldn't be getting the same rights as people. You can't just do whatever you want to make a dollar and then try and claim free speech protections
Should a union be denied freedom of speech? Because a union is a corporation as well. What about the Sierra Club? Should they be silenced? They too are a corporation. Should a teachers union be allowed to speak, but Khan Academy denied the same right? Should organizations advocating free WiFi be allowed speech, but Comcast be denied the same right?
The “companies are not people” tripe being parroted since Citizens United is a naïve and dangerous road down which people are attempting to travel. At the core of the issue is the right of free association. Free association is fundamental to free speech and a free society. Profit motive is irrelevant because profit is just as valid of a goal as “better schools” or “better public policy” or whatever the cause might be.
Governments are people who have joined together for the common purpose of governing. Does that make a government indistinguishable from an individual person, which is basically just a cell?
Is there a difference between one kid running across your lawn and 10,000 kids organized for the purpose of running across your lawn?
I upvoted you and I am seeing this on HN more often now. That people would use downvote as a signal of disagreement.
A corporation is a piece of paper registered for $100 that can be destroyed without penalty. It is a tool for achieving an objective, just like a computer. Many people join together to make Wikipedia, but we don't grant that website free speech...
That's just not true. The West hoped that would be the case when Xi took charge, but it's gone in the opposite direction since then. How many chat apps can you use where the CCP isn't listening in on your conversation? They practice wide scale censorship on their own social media, Western social media sites are blocked, and important sources of information like Wikipedia and the New York Times are blocked too.
https://freedomhouse.org/report/freedom-world/2018/china
> China’s authoritarian regime has become increasingly repressive in recent years. The ruling Chinese Communist Party (CCP) is tightening its control over the media, online speech, religious groups, and civil society associations while undermining already modest rule-of-law reforms.
As I posted elsewhere, this is NOT true.
>The $20 million fine is not automatically applied. Here's a flow chart which details the process of a GDPR breach: https://40uu5c99f3a2ja7s7miveqgqu-wpengine.netdna-ssl.com/wp...
>from https://www.i-scoop.eu/gdpr/gdpr-fines-guidelines-applicatio...
Some people just accept it when someone says they won’t do something that they totally can.
I know, it doesn’t really make sense. If someone tells me “well it says that we can do that if you go by what’s on paper, but we wouldn’t actually do that”, then change it so that it says on paper that you won’t, or I’m inclined to think that you totally will, because you totally can.
These rules look at whether your company has infringed before, whether you've notified the state on your own, etc. pp.
The current Information Commissioner Office system has a similar system in place. Out of 17,300 cases reported in 2017, 16 resulted in a fine. Source: https://www.infosecurity-magazine.com/opinions/gdpr-timebomb...
Edit: to those downvoting this (and all of my other comments) - this comment contains only facts. So please show me where it says that there are circumstances under which they must fine you less than the maximum. Otherwise there is nothing to downvote.
The big number max fines in GDPR are there to deal with companies like Google and Facebook who can write of $5m as a rounding error.
People who have been fined at all under the existing DPA, being enforced by the very same people as GDPR, have been negligent, repeat offenders. I don't believe anyone has ever received the maximum fine in the existing regulations. That just isn't how UK law works
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
Note: proportionate
In the EU you tend to trust your bureaucrats to make a "Fair and Just" application of the law
In the US we tend to expect our bureaucrats to be vindictive, corrupt, petty, and generally impose fines and penalties not based on the law but based on their personal feelings about the target of their "legal action"
Thus such open ended wording like you posted being classified as a "rule" scares the shit out of most Americans
And the differences in the legal systems specifically. I think this is why a lot of HN commentators are finding the GDPR vague. In the US rule based regulations are the norm. For better or worse this tends to allow those with clever lawyers to search for loopholes. UK law is much more principle-based, which means trying to abuse the exact wording is not going to save you from a fine, and equally a technical-breach of wording is not going to get you prosecuted. It's not just the civil servants that we trust with this, it is the judges too.
There's at least twenty years of regulation under existing DPA law, where the maximum fine has never been asked for nor applied.
Rubbish, this is just spreading FUD.
From the UK ICO: "It’s true we’ll have the power to impose fines much bigger than the £500,000 limit the DPA allows us. It’s also true that companies are fearful of the maximum £17 million or 4% of turnover allowed under the new law.
But it’s scaremongering to suggest that we’ll be making early examples of organisations for minor infringements or that maximum fines will become the norm."
Look at the track record of the UK ICO - how many small businesses and side gigs have been fined £500k? How many businesses of any type have been fined the current maximum of £500k?
So where does this ludicrous assumption that everyone is always going to be hit with the maximum fine from here on in come from?
He wasn't 'almost jailed' - he was fined £800. And the video involved him saying 'Gas the Jews' over and over again to his dog, to which the dog reacted.
[1] https://www.washingtonpost.com/amphtml/news/the-intersect/wp...
https://en.m.wikipedia.org/wiki/Twitter_Joke_Trial?wprov=sfl...
Even TalkTalk were only fined £400k for the most ridiculous incompetence leading to 4 breaches in 18 months and failing SQL injection 101. They make profit in the tens of millions yet still didn't hit the maximum (They should have in my opinion). I think at the time that was the largest penalty yet issued.
Same goes for other data protection bodies across the EU - there will be few instances of maximum penalty under current data protection. I'm sure some countries have never imposed the current maximum.
nb It's not a ridiculous law - I'm fully in favour of it, as are many others over here.
No, in fact, most people get served with nothing more than a formal caution or a £90 fine. This is normal - this is how the law works in this country. Anyone who doesn't understand this hasn't even been paying attention to the lowest-common-denominator newspapers, which are constantly screeching about how people usually don't get anything close to maximum sentencing.
That's the most interesting thing about the GDPR. While some developers are picking up their ball and huffing off home, others are actually 100% behind the regulation.
It says something when tech-savvy people agree to sacrifice time and effort and probably profits to protect their users from their own software.
I'm fully behind the GDPR. It might not be perfect, but I've read the law and it's surprisingly straightforward and sane.
Why is it sane to assume data I've sent to a service is my data to control?
Or the competitors' software.
Consider some business that was doing what GDPR requires already: users could delete their data, they could request a complete copy of it as well as an explanation what it is used for, and it was only used for defined purposes that the user signed off prior anyway.
Sadly, that reduces flexibility somewhat, but they're doing it because they consider it the right thing.
For them, GDPR levels the playing field and makes sure that they never have to stray from this conduct just to remain competitive with companies that aren't so nice to their users.
Nothing about the gdpr solves the problems of companies having insecure systems that _leak_ user data. I also don't believe that data about me is data I own. To me, the gdpr feels ineffective at the real issues causing me harm (leaked info) and also a giant burden on companies that fundamentally changes how the industry has worked, but in a way that quite frankly, doesn't make any sense to me. The data about my order isn't my data to control.
It doesn't directly prevent insecure systems, but discouraging companies from storing information they don't need and transferring it on to third parties for whatever reason they feel like massively reduces most people's exposure to this risk.
>The data about my order isn't my data to control.
If you believe people have a right to privacy, then you believe they have a right to decide who gets to know what information about them.
That's not even remotely true. A right to privacy does not mean I get to control the actions of others.
Nothing restricts what others can do with them, they just have to state it so I can decide whether that's ok for me or not.
The lack of this clearly defies the right to privacy, just consider the extreme case of "I'll dump your data on GitHub next week"
If I place a camera in my house so that it's recording what's going on in your bathroom- is that data you would like to be kept private, or not?
Requiring disclosure of a breach within 3 days of it happening, as opposed to the several months that is commonplace now, is a big help.
"I also don't believe that data about me is data I own."
Everyone disagrees on this point. Right now, Europe says the opposite.
"also a giant burden on companies that fundamentally changes how the industry has worked"
Good. Currently the industry is geared to suck up every last bit of user data like a vacuum, regardless of whether it's actually needed, so they can sell it. This has gone on for far too long, and I'm glad to see the industry hopefully move away from it.
GDPR increases maximum penalty to be high enough that it could be a penalty to a Google or Facebook for a serious, wilful, breach of regs, in an environment where the tiniest fraction of reported cases get any fine at all (16 of 17,300 reports for 2017 in the UK) let alone the maximum. Internet now certain that one man software companies and hobbyists with non-commercial regex sites will receive £17m fines, every time and it will be used as a stick to beat one's political enemies with or, most comically of all, pay for local infrastructure improvements.
I don't understand why - the regs seem reasonable and not especially difficult to meet unless your business is built on wilful abuse of personal data. Just a reasonable effort to enhance DPA taking into account new techniques and misuses of data. Deletion for everyone, not just a minority - thanks to FB et al feeling it's fine to never delete, and run shadow profiles on all. The highest penalty will be saved for the most offensive cases involving multi-nationals. It will be interesting in a few years to see how many maximum fines have been levied. My bet is none at all, once or twice if there's an especially egregious breach from an Amazon or Google.
I've little doubt that just as I feel more should have attracted fines under DPA I'll feel more should have got GDPR fines.
My intuition is that the people who complain are that fraction of developers who actually care about their profits more than their users' privacy.
For us in Europe 20 years of DPA must help - I doubt there's many here would want to go back to pre-data protection.
When a corporation is compliant and only has minor infractions, they will (most likely) write a sternly worded letter.
But if you're constantly and repeatedly or willfully ignoring or breaking the regulation they definitely won't leave it at a simply tap on the fingers.
Plus, I don't think any regulatory body is looking for bankrupting a corporation. They will obviously size the fine according to how much the corporation has in turnover or profit.
If you have minor infractions caused accidentally and you cooperate I have doubts that any regulatory body for the GDPR will go beyond sending a simple letter asking you to fix a problem.
And unlike you say the law does say the regulatory body for the GDPR has to consider the business needs of smaller businesses and adjust their fines accordingly if they even hand them out.
There is a good flowchart in this thread too, I recommend to study it.
I am hopeful that the US will pass legislation exempting US firms from enforcement of fines under GDPR on US soil, but I am not optimistic. Under current law, it is likely that they can be enforced. Either way, the net result will be that EU residents will have access to a far smaller universe of content and services. Most businesses just won’t take the risk.
What would be the mechanics of enforcing the GDPR against a US company with no EU presence? I'd understood the opposite, and that the EU's best options to enforce were probably indirect (via customers, vendors, etc. with EU presence).
https://community.spiceworks.com/topic/2007530-how-the-eu-ca...
> "While we don’t yet have U.S.-EU negotiated civil enforcement mechanisms for the GDPR (and it is unknown whether we ever will), there is still the application of international law and potential cooperation agreements between U.S. and EU law enforcement agencies, which have been increasing in recent years."
That sounds pretty murky to me, more a statement that she expects regulators to cooperate than one that current law provides a clear path. Not that I can find a more confident article in the other direction, of course...
If the US court doesn't decide that, the EU will have to resort to indirect measures (Google AdSense will probably stop working since Google doesn't want the EU courts on their butts for making business with someone who violates the EU law and other measures)
https://www.privacyshield.gov/article?id=How-to-Join-Privacy...
So how does that affect companies that don't elect to join Privacy Shield?
Agreed that AdSense will probably start indirectly enforcing the GDPR at some point. Someone will probably make a lot of money picking up the traffic they lose, in exchange for never changing planes in Frankfurt again...
I guess we'll have to wait and see what happens in that case, if the US court system is willing to enforce GDPR fines on their side, that would be a win for the EU (the US has been doing this for ages)
We both contributed to a conversation where you made the same point, a few days ago:
https://news.ycombinator.com/item?id=16888026
Back then, I was not convinced that you had a clear idea of how such a money-grabbing scheme could be implemented. I would kindly ask whether you have a clearer understanding of the relevant procedures now.
The people saying how easy it is don’t know what they are talking about.
By "28 different interpretations I assume you mean those of different member states. It would actually be 27 now that the UK is leaving, but even so, the GDPR is a regulation (General Data Protection Regulation) and not a directive, partly in order to eliminate inconsistencies in national laws. To clarify, as a regulation, the GDPR does not need to be passed into national law.
Additionally, this reduces the burden on companies that would previously have to deal with multiple local authorities, in the context of the Data Protection Directive.
Further, there are provisions for the consistent application of the GDPR across all member states, particularly a European Data Protection Board.
This is from an article I quoted earlier:
Coordination and Consistency
Under the Directive, there has been a certain level of coordination in interpretation and enforcement. Apart from informal contacts among authorities, there has been a succession of non-binding opinions issued by the “Article 29 Data Protection Working Party,” an advisory committee comprised of representatives of the national supervisory authorities (commonly termed “data protection authorities” or DPAs), along with the European Data Protection Supervisor appointed by the European Commission. Under the Regulation, that group will become a more independent and powerful regulatory body called the European Data Protection Board, tasked with ensuring “the consistent application” of the GDPR. An entire chapter of the Regulation (Articles 55-63) is devoted to cooperation and consistency, with procedures for multiple DPAs to coordinate investigations and promulgate consistent decisions and policies reviewed by the Board and reported to the European Commission.
One feature of coordination that should be helpful for multinationals is a provision for companies to work with a “lead supervisory authority” in the country where the company has its “central administration.” That authority will then coordinate with the authorities in other countries where the company operates, attempting to achieve consensus on issues that affect all of them.
https://www.infolawgroup.com/2016/05/articles/gdpr/gdpr-gett...
Generally, I have no idea why you say that the GDPR will be nearly impossible or actually impossible to comply with. Different member states have different regulations for drug use, for instance, but that is never used as an excuse to violate drug laws "becuase they are impossible to comply with" due to different national interpretations.
I am not one to say "trust the EU government, it is good". But the intent of the legislator is obviously not to kill businesses willy nilly, it is to punish certain behaviours, they have no reason to willingly cause a business to shut down, which is why the GDPR explicitly accounts for collaboration.
In the end, it is up to you to decide not to abide to the law. There have been local regulations forever, this won't change much.
Note that, in parallel to the EU regulation, the statutory maximums can be enacted(ever since Booker judges can use their discretion again), but in reality most judges rule within the sentencing guidelines.
Yet. Wait until the company is another political organization that is identified as an enemy or competition. Then these laws become tools for shutting down dissenters with selectively applied fines, even to companies outside of the EU.
What part of this is a problem for you?
(And for that matter it was his girlfriend's dog).
But yes, I agree with you - you have no control over the Court's decision if found guilty.
There's no good way to frame this for a small business. Are you seriously suggesting that the mere benevolent feelings of a judge or board and how their mood is that day is the only thing standing between a startup and bankruptcy? If you're saying a small business should never be fined that much, why isn't that the letter of the law? Why does the court even have the option to completely destroy a startup like that?
> So where does this ludicrous assumption that everyone is always going to be hit with the maximum fine from here on in come from?
Where are you getting this ludicrous assumption that the law won't apply the maximum fine? If you don't think they should be able to, why isn't the law simply sensible, and should apply a lesser fine?
Supposing 100% of the startup's revenue comes from GDPR violations and they've been doing so for, say, 5 years, then the fine should really be 500% of annual revenue. Or even multiply that by 2 or 3 for punitive purposes. It may or may not destroy the startup, depending on how well funded they are. They could be breaching privacy for reasons other than revenue.
The only place and time where the concept of punitive damages and GDPR overlap is the United Kingdom between May 25, 2018 and March 29, 2019.
[edit: and Ireland. They might want to reconsider, given that they host many of the European HQs of US companies.]
> Where are you getting this ludicrous assumption that the law won't apply the maximum fine
They have never yet applied the maximum in 20 years of the current DPA, why presume they're itching to start next month? This makes no sense to me.
Under the DPA 1998 the largest fine was issued in 2016, to a multi million pound company. £400k, so still only 80% of the maximum. Look to precedent across the entire EU.
https://techblog.bozho.net/gdpr-practical-guide-developers/
The penalty isn't meant to be something you afford. It's a penalty. (It's a feature, not a bug.) I'm having a really hard time not being sarcastic right now but compliance with the law might also end up being an economical option worth looking into. Cheaper than lawyering-up for being sued by shysters for non-compliance, and cheaper than being penalized for non-compliance.
Mind you, taking whatever-it-is off the internet is fine too. I totally understand. What I don't like is all the whiny sanctimony and martyrdom. "Yes I'm taking my thing off the internet, but first I'm going to make a big deal about what a tragedy it is for the world." Um no. The fact that your thing is a "small business" means few people care about it. (Sad to say. More people care about Facebook than about you. That's why they're the big incumbent.) And it emphatically doesn't mean for example, that you're some hallowed, heroic underdog who deserves protection, especially when you won't even afford the same to your own users and their data.
Compliance depends on how well your understanding of of a bunch of fuzzy terms like "legitimate interest," "level of security appropriate to the risk," "necessary in relation to the purposes for which they are processed," "no longer than necessary," etc. align with 28 different regulators and judiciaries. That's as far from "trivial" as it gets. Bozho.net is not a lawyer, not your lawyer, and even if here were your top-tier lawyer specialized in data privacy he wouldn't have a clue what courts were going to take these things to mean in the context of GDPR, because there aren't any judgements yet. Security and minimization standards are also about "taking into account the state of the art" - do you know what the state of the art is, and is your organization capable of implementing it? An entirely plausible outcome here is that only the most advanced engineering organizations have technology that meets these standards.
Horeshit. There is nothing advanced about storing only the data you need. However, if you've been hoarding like crazy and weighed down with technical debt, and haven't used the last two years, then yeah, might be hard.
Yes, it's a new law, yes, in practice it will be defined by judgments. How is this different from any other new law, other than this one impacts IT harder?
And let me guess what the alternative is: do nothing.
Consider also that European law is different to US law. We draft laws and contracts in a conceptual/abstract way, whereas in the US where everything has to be exhaustive, explicit, and over-worked; just in case anybody dare sues.
GDPR recognises one-size-fits-all won't work. Yes, that means it has some vague terms. Yes, you might have to show you thought about the implementation, and that you erred on the side of privacy.
It's funny how everybody always talks about the maximum fines, not the other sanctions that the GDPR can impose. Guess that's just more sensational.
We won’t take our services off the Internet. We’ll simply block you and your overbearing friends in the EU from accessing them. You might not miss one of us, but you’ll likely miss hundreds of thousands of us. Enjoy Facebook. That may be the only site you still have access to when the dust settles.
Compliance is trivial
Since you are saying that, I can guarantee that you haven’t actually read the law or been in charge of trying to make a website compliant. That is an absurdly incorrect statement. Billions are being spent around the world on attempts to comply with it.
I'm a hobby developer. I once made a tool mostly for myself, but decided to put it online. A couple thousand people use it, and it runs at a loss but I keep it up mostly because it's useful to some people out there. My tiny website isn't hurting anyone or breaking the internet the way Facebook or Google may be. To claim that having to spend my hobby time implementing a bunch of extra features is just "complying with the law" is bullshit, I'm sorry. In terms of scale, it's basically as if I forced you to do full safety test on a toy car you made for your kid, just because GM cars had safety issues.
And I'm not special. There are plenty of other small devs like me with thousands of small niche web tools out there, most of which are ran purely as a hobby, out of our own pocket. I may not make a blog post and get it to the top of HN, but devs like us have 0 incentive to keep our sites online.
HN loves to complain about things like AMP killing the web, but to me this is orders of magnitude worse.
If what you're doing could cause a problem I'm pretty sure I'd rather you didn't without the ability to deal with it.
It takes 30 seconds to find out whether your identifier violates a trademark. Your content is trivially not a copyright violation if you created it yourself. Hobby projects are not debating the finer points of fair use and whether the conflicting name is for a sufficiently different kind of business to avoid confusion. But every HTTP server handles personal data, and a web-based tool with a database backend especially so, so all the subtlety of GDPR is in play.
But not all of them have a good reason to log it. /dev/null
Essentially, all you have to do is tell your users what data you are collecting and how you will use it.
Also, if a user asks for their data, you give it to them, and if a user asks for their data to be deleted, you delete it. I imagine if either of these things were to happen today, you would do as they wished GDPR or not.
It's not even remotely okay to use random people's blog posts as a compliance strategy.
> It's not even remotely okay to use random people's blog posts as a compliance strategy.
Then use the simple, human friendly guide from the body who will be enforcing it in the UK. I did. I thought it was simple.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
How about asking and recording a persons birthday when really all you need to know is if they are the age of majority? A birthday is more information than needed which seems like a violation GDPR when interpreted strictly with my cursory knowledge. Seems unlikely though that any regulator would enforce such a distinction though.
> The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if:
there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual. [1]
So once the account info is deleted, that link is broken. This another piece of DP legislation that has been subject to a great deal of FUD since most of the headlines just went with ‘court confirms IP address are PII’ and omitted ‘in some cases’. TBH, this was already pretty explicitly obvious from the legislation defining Personally Identifiable Information (hint: clue’s in the name).
[1] https://www.whitecase.com/publications/alert/court-confirms-...
Makes sense.
Given the above still seems like a potential issue to not delete the ip logs.
1) Bob signs up for a service and is logged
2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained.
3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account.
Weather the data processor can relink the two records with reasonable probability in step 3 depends on the particulars of the circumstance.
I assume cases like the above will be judged, at least in part, based on the data processor following best practices, and operating in good faith(not actively trying to unmask individuals and actively try to prevent unmasking).
Currently I would not let the GDPR stop me from going forward with any web services plans, however my casual reading of GDPR articles on HN and beyond have not made it obvious how cases like the above will be handled.
Nothing. Anything. This regulation assigns huge amounts of legal and financial risk to any hobbyist and will likely be selectively applied.
I really think some people are just completely blowing this up into something it's not, probably because the only thing they've read about it is others scaremongering.
As a business owner that cares about privacy, I was basically compliant already - all I had to do was reword my privacy policy a bit to make it more human-readable.
How do you deal with user requests? You need at least somehow be able to gather the data, pack it into an user underdstandable format, and delete database entries, also from your backups.
gather data: select * from every table that has userId
pack it into understandable format: every language i have used makes json, xml, csv pretty darn easy
delete: delete from....
backups: i am surprised your hobby project takes backups. perhaps have a table with userIds that were deleted, and when you make your new backup, remove all their data?
Ah yes, and then all of my data has holes in it that I need to deal with. "Hmm, we only have 5 orders for this, but we're missing 6". "hmmm, we charged this credit card, but there's no order for it and I'm not sure if we ever shipped anything?" "hmmm, how do I delete this tracking number from the postal systems' records?"
Will regulators agree with what I "must" keep?
Regarding backups, realistically you are not going to be required to delete from them as it's completely impractical to delete a single user's data from backup. You just need to be straight with your users - tell them that their data will be removed from your live system immediately, but that some data will remain in archive, securely encrypted, until the end of your defined retention period.
I found the ICO's guide[1] fairly straightforward to understand though.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
It is by far best GDPR presentation and explanation of lots of misconceptions. Please report back what you think about GDPR when you finish, I am curious it you will still feel threatened.
From the presentation: "guilty until proven innocent". How can you NOT feel threatened?!
Guilty... is really not something special, IRS anyone? ;) Did you catch something else? Something useful maybe? About borrowing a car for instance? :)
The GDPR is actually late, I have a few IoT devices and I verify them by isolating them on network and sniff out communication (mitm on wifi and old school 10 port hub (yeah, the one screaming everything to all ports) for wired. It is a sad sight, even if they have absolutely no need to contact outside servers (I would never have a device like Siri in my home) they still do, another case would be broadcom drivers on android calling home. Someone has to stop this madness.
I know a lot of people are pissed off due to GDPR, but I will gladly ask them again in 10 years. I think they will change their mind.
Your argument boils down to "I don't want to take special measures to protect your personal data, so I shouldn't have to".
You can continue running all hobby tools you want.
100% agree. And your situation applies to millions of hobbyists, personal websites, projects, startups, and small businesses around the world.
GPDR appears to be intentionally burdensome, a classic regulation strategy aimed at protecting large incumbents while stifling small business, innovation, and newcomers, or even side projects like your own.
Isn't that besides the point?
You can be 100% compliant and still be sued by somebody. And you'd have to pay some lawyer a lot of money to make it go away.
That risk already existed before the GDPR (anybody can sue anyone for whatever reason they can come up with), but GDPR is high profile enough to make people scared.
About a decade ago, I ran a website that made heavy use of user uploaded GPS data. I didn't sell any data. The only ad income was Adsense.
If I had bothered to restore the server from backups after a HD crash, I'd probably take it down now. Just not worth the potential trouble.
No, someone can report you to a member state's compliance organisation.
I fail to see how GDPR makes that new. You can be sued for any reasons already, being in the right or not.
E.g. 99% of useful websites violate some patents (that shouldn't ever have been issued), actual predatory suing about this issue happens, yet no one closes his website because "the patent situation makes it too uncertain".
Indeed it is: the first 100 pages of the text detailing what compliance means are a manual for how to read the remaining 5000 pages, and a warning that there will be per-country variants of the law, which I'm sure will all be very clear, made easily available and not at all weird or objectionable, or require being well-versed in the legal intricacies of said member state at all !
/sarcasm
Here is a set of (easily available) interactive tools, explainers and guidelines from ICO in the UK which explicitly outline what compliance looks like and what steps you can take to achieve and demonstrate it [2]. It’s available as a 162 page PDF, if you insist on counting pages, but much of it relates to the processing of sensitive data or data relating to children which the majority or orgs can skip.
[1] http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
[2] https://ico.org.uk/for-organisations/guide-to-the-general-da...
With the amount of creativity observable for inventing tax-avoiding business structures, I'm sure if the minimum clause weren't there, big players would quickly find a way to spread their revenue over dozens of small entities, each looking like a "small business" on paper.
So I'm not sure it would be even possible to make a regulation "with teeth" that explicitly exempts small players.
No, it is not.
"Well meaning regulation like this written by people who have never created anything pratical in their lives other than regulations illustrates why entrepreneurship in modern Europe is nearly impossible."
No, it doesn't. It demonstrates that far too many "entrepreneurs" are people who want to play fast and loose with regulations, and not be held accountable for anything.
The higher you turn the knob, the harder it becomes to (compliantly) do things. Also (if the regulations are working as they should), the less the things that people do produce bad side effects. But the "harder to do things" part mean that fewer things get done - fewer new products and services get created. As the knob goes higher, not all of the things that don't get done are things that the regulations are designed to prevent. Some are perfectly fine things, but the burden of proving it is too much for the single person tinkering in their apartment to ever try to turn their idea into releasable reality.
GDPR applies to you if a EU citizen signs up from somewhere outside EU as well, but since you don't have any physical or online presence in EU I don't think they will do anything.
I’m confident that compliance is:
- Straightforward for any non-tech firm;
- More complex but not that hard for most tech firms that handle data;
- Far more complex for large organisations than small ones;
- Basically only a real problem for fly-by-night tech companies that want to operate by reselling personal data.
I’m not sure what your motivations are it making it seem disproportionately burdensome to comply with, but I don’t think they’re good.
- What did you do about logs? Things like request logs will at least contain ip address which is PII. Now logs can be cleared after a fix interval but the time for honoring the data delete request is a month I guess. If you want to keep logs for a period more than that, what do you do? If you anonymize IP , it makes other analysis on top of those logs useless.
- What did you do about data backups? - What did you do about external error reporting services? - What did you do about analytics services?
Regarding backups, realistically you are not going to have to delete data from them, as it's completely impractical to delete only data for a particular user from archive. If a user requests their data to be deleted, delete it from the live site and be open with them that some data will remain in archive - securely encrypted and untouched - for your defined retention period.
Regarding analytics, we use Google Analytics, which uses IP addresses to guess location, but doesn't make them available in the admin site - so GA doesn't actually give us any PII. As such, we simply reworded the privacy policy to be more easily readable, so it's completely clear what data we collect and why. The forthcoming Privacy and Electronic Communications Regulation (aka ePrivacy Regulation) should provide some clarity if anything else is required, but it seems likely that simply having cookies enabled in your browser will count as consent.
I wonder how people from other parts of the world are understanding this and how do they look to the site like that? I mean, this legislation that is designed to protect people and their data is making them such a problem to rather block roughly 500 milion people. I personally would have a huge trust issue, but this is not about me, what do non EU, who don't run any site (conflict of interest) guys think?
I would for instance rather put a huge mark on all pages "GDPR compliant, protecting data even for non EU visitors" or something like that and try to get some money out of that. But that is just me.
All websites provide services to users in all countries unless they take positive steps not to. Framing this as a conditional, or a counterpoint to parent's claim about enforcement outside EU borders, is bizarre.
Transactions do not have to involve money and in fact, the very topic of this entry on HN is about a website that was free, with transactions that did not involve money.
Really? If it's a currently established practice, what are some prior examples of countries punishing foreigners on foreign soil over websites with no payments component?
Maybe each jurisdiction should be the business of regulating locally-accessible websites, not just locally-hosted ones, but that's a fundamental shift in the nature of the internet. "Not available in your country" is currently an anachronism. In that world, a prudent web publisher would start out local and enable specific countries for cross-border traffic only as its legal team expands. Internet communities like this one would splinter as people get tired of clicking links they can't follow.
The countries currently regulating available web content do so with network blocks, not extraterritorial enforcement actions against publishers.
Free doesn't mean you are exempt from complying with law, that is all I'm saying. I did not comment on how this one applies to EU citizens even for foreign services.
In this regard though, it is similar to US law requiring foreign banks to go through special steps when they are dealing with US citizens so that's not anything new either. Money being involved or not in my opinion is not really significant (I actually think that private data is more important and needs more protection than money) but that was not the point of my comment.
It doesn't, but free on the internet has so far meant you're only on the hook for your own jurisdiction's laws.
What about companies like Alibaba?
> It has Google Analytics
There's a real issue, you've been bundling spyware with your application for years.
The Berlin-based clue comes to mind, they were offering period tracking, estimation and other features. One day you get a full-screen pop-up saying that they changed their privacy policy and they share your intimate data with so and so and there is no way to access the app and your data any more without accepting.
Most apps nowadays aren't tools, they're sophisticated scams designed to steal people's information.
I'm afraid that in your overreacting rush, you might have removed your app from European countries that are not within the European Union.
Though if you are collecting more data on your users than you need (why would you need personal data at all for this app?), you might have been doing them a favour anyway.
Besides, who said it will never happen? What can you be sure will "never happen"
Can I use your crystal ball?
Because there are ~25 existing sets of laws on the same topic [based on GDPR's predecessor framework, but evolved in different ways] that GDPR normalized into a single, common modern framework. Nothing horrible happened with those old laws.
Except this isn’t really true. Streetlend made its money by selling your privacy data to advertisers through Amazon. So when you put up a power drill for lend, people would see power drills for sale at local shops, based on their online presence harvested through stuff like their Facebook account.
The really ironic thing about that this is that streetlab imagined itself “ethical” when it’s entire business model was selling your data...
The GDPR isn’t really that hostile to small business and it doesn’t require an understanding of law. You can hire a data protection officer at a legal firm for almost nothing, and as long as you follow their advice on how to pass audits, you’re really not in trouble.
That being said, the GDPR is really hostile toward startups trying to make money the same way Facebook and Google does. You need to have a massive legal department to do that, and Streetlend obviously did not. But is that really so terrible?
It may call for a new business model for the internet, and that may seem impossible right now. But do you remember when the EU outlawed environmentally shitty lightbuilbs and everyone said we were going dark because it was impossible to do anything else? Today 95% of lightbuilbs are LEDs because of that.
Startups will find a way to make money that isn’t selling your data.
Google and Facebooks manoeuvring to adapt to the GDPR give a clear road map of the legal requirements. Bluntly, they're not that bad, and they're better for a new startup who can adapt to them from the ground up than an established venture who has to find new ways to make money.
The reporting requirements of the GDPR can be large, but for most companies most of the time you're dealing with a relatively unchallenging piece of legislation. Most of the requirements are just to be able to explain what happens with user data and handle sporadic deletion requests. Loosely connected, separately stored, IDs are the solution to this (pseudonymization). It's a different style of development, but far from tricky. That's systems development, not legal.
This is a legitimate threat to startups reselling user data and overly friendly web-tracking solutions, yeah. To them I say "boo-hoo". For the rest of us? IT regulation with legal teeth is a promising indicator for IT companies. There are more of "them" than there are of "us", and if our legal issues are getting play that means our salesmen will also get play.
I know you didn't intend to, but you've nailed the problem: the ambiguity and doubt. Most (<100%) * most (<100%) is a fraction times a fraction, never a good equation if the upside is low.
I doubt the StreetLend dude made much cash out of this project, so why bother? It was likely just a convenient excuse to kill a side project that had little value that sucked a lot of time, but still, the ambiguity no doubt helped push him towards this outcome.
This doesn’t feel particularly onerous, especially as any good business plan will include getting public liability insurance for inevitable occasional serious mistakes.
Even though we never resell, mine nor monetize data, the increased risk of legal action was not acceptable to us.
Have you ever filed a claim on an insurance policy? Your premium will certainly go up next time that policy is up for renewal.
It’s unfortunate for our users. They’re quite upset that we’ve decided to drop all EU customers. But, we’re not willing to take on any additional risk for such a small revenue source.
https://cybercounsel.co.uk/data-subjects/
1. A Data Subject under GDPR is anyone within the borders of the EU at the time of processing of their personal data. However, they can also be anyone and anywhere in the context of EU established Data Controllers an Data Processors.
2. If the Data Subject, moves out of the EU border and say becomes an expat, or goes on holiday then their personal data processed under these circumstances is not covered by the GDPR and they are no longer a Data Subject in the context of the GDPR, unless their data is still processed by an organisation “established” in the EU.
Luckily, my organization is not “established” in the EU.
I don’t think you’re going to disrupt Google or Facebook without trying something new, and the GDPR certainly forces startups to think different.
Its only the end-user-is-product companies that have to have armies of lawyers, and that is no bad thing surely?
Note that you're on a site pretty much dedicated to the ongoing viability of end-user-is-product companies, hence the backlash here. My experience, same as yours, is that anyone who provides a service for money isn't having any difficulty at all complying with the GDPR.
The law is needed, otherwise everyone would continue to abuse users' data more and more. So that's clearly not the solution. The ideal solution is fining both Google and Facebook for all the money they've made from that abuse from at least the past 5 years, to level the playing field.
People say that capitalism is the "worst economic system, except for all the others", and that's true. But one of the main issues with capitalism and why it gets to be so broken in the end, is that when companies abuse their powers, the punishment almost never fits the crime. If it did, I think capitalism would be a much more optimal economic system. I think this is by far the biggest issue.
As an example, Intel made tens of billions from anti-competitive moves against AMD, and it was only fined $1.4 billion, a fine that's still under dispute even a decade later (Intel has yet to pay it).
Samsung, and other memory makers have been caught at least once in the past, and now again, doing price fixing. But the fine was and likely will be again much smaller than the profits they made.
Then we have the big banks, which also made a ton of money from screwing people over, and again they were fined at "record levels" but still much less than they made in profits.
This is how the incumbents keep getting ahead of the others, even when stronger regulations pass - they never have to truly pay for the crime they did in the past, and they get to keep 95% of their profits from that crime. That isn't how things should work - the governments should take all of the profits they made from the crime and the fine should be added on top of that. If a company grows 10x in size in a decade from abusing some law and consumers, then the governments should absolutely take back 90% of its size when it's punished later. That's the deterrent.
Now in regards to privacy, the laws weren't that strong before, and I don't really believe in punishing people or companies for laws that didn't exist, which is why governments need to be much more vigilant from the birth of new industries, and not wait until they are mature and most damage has already been done.
Maybe my solutions are a little too extreme, but I do believe more needs to be done compared to what governments are doing now. We can't just let companies get away with almost all the profits they made from abusing consumers.
Also, there need to be stronger anti-merger laws. That's for sure. We almost never need to let companies merge, and if they do merge, that almost always ends-up not being in the consumers' favor. If some companies can't compete on their own anymore, then so be it - let them go bankrupt. The rest will either become stronger, or new entrants will appear. I think that's still preferable over allowing them to "survive" under a bigger company. Let the creative destruction flourish in the market, as it's supposed to.
Alas, many people make money off of loose regulation and they are thus biased.
I am afraid we won't see any improvement anytime soon.
Users have been giving away data to google and facebook to use their services. What exactly do you mean have been abused about that.
Calling that stolen is mixing your personal opinions with facts.
Probably not far enough. You need to outright shut them down, put them in a prison of sorts, fine them, and then let them continue operating after their term is up. Do not let them sell, do not let them split. But people will lose jobs, ads will be taken out to fight it, and it will be held up in court for far too long. Google and such have ingrained themselves in a way that to properly punish them for their actions is not politically tenable, because the only fitting punishment would destroy these companies and cause significant economic harm.
The best moves liquidates Facebook and google.
This is an unviable move.
The next best move is to build laws which enforce behavior.
This always results in additional complexity which cuts into the profit profile of firms.
The same way that health regulations hurt many fly by night operators, and force standards on bigger firms.
This is the only outcome in the game which is acceptable to all parties.
It is the rational move.
>Startups will find a way to make money that isn’t selling your data.
It's hard to argue with statements like that. What if they don't? There are plenty of startups providing extremely valuable or fun services (like flightradar24 for example) that are supported by ads. After GM, Ford and Chrystler there were basically no successful auto startups in the US for 70 years. This regulation makes life for startups disproportionately harder than for Google and FB that already have an army of EU lawyers on payroll.
This is not true. The US has parallel regulation that encourages the phase out of incandescent bulbs [1]. True to form it's a lot weaker than the EU regulation but it sends the same message.
> This regulation makes life for startups disproportionately harder than for Google and FB that already have an army of EU lawyers on payroll.
This is not true. In fact the GDPR makes it clear that for small businesses (<250 employees) most of the control burden is relieved.
[1] https://www.epa.gov/cfl/how-energy-independence-and-security...
I also found some LED bulbs that have simulated filaments inside clear bulbs for an old-fashioned look, and again the incandescent color temperature.
I've even found cheap LED replacement bulbs for the various interior lights in my car that look just like incandescents.
So I think it's kind of passé to be debating LEDs at this point.
Failed reality check.
A Data Protection Officer, especially from a law firm, is not in any way imaginable "almost nothing" regards the cost.
I can't imagine it's a cost less than five figures.
when did that happen?
Founder here. Streetlend never passed personal data to Amazon. It used the search term eg “ladder” and showed ladders on sale from Amazon. No personal data was passed.
Unless you're doing something shady with user data (and you _know_ if you are) the GDPR essentially comprises having _some way_ of giving a user all the data you store on them, and _some way_ of deleting that data.
In this case both of those appear trivial to automate, and even more trivial to just do if somebody actually wants those things. Shit, dropping email login and only accepting federated auth would get you there in one step, unless you're doing things you're not saying.
Clearly you have no understanding of any legal system in the world works if you believe only people that are guilty of violating the law are sued and ruined by the law.
Because the GDPR is extraordinarily ambiguous.
Patent, Copyright and Disability Access laws in the US are to examples commonly Abused laws for this type of behavior
The problem is the legal system in most nations are setup in away that gives the guilty and the wealthy an advantage over the innocent with limited resources
Laws and Legal Systems should be
1. Very Specific and not open to interpenetration
2. Have options for "settlement" as this rewards the guilty, and harms the innocent
3. Have more public resources for people with limited resources. Law firms and Large corporations use Legal Expenses has a weapon in Civil Courts over smaller companies due to the high costs and generally no public resources for Civil access
4. All Civil Cases must have to show Actual Damages not Theoretical Damages
that would be a start
Except with GDPR all you could do is report them to the member states governing body. So no trolling.
> Very Specific and not open to interpenetration
Except this makes them inflexible and leads to them having to be constantly redrafted. So no use to the world of the HN.
> Have options for "settlement" as this rewards the guilty, and harms the innocent
GDPR is between you and the regulator, they already do this work and the whole aim of the process is to stop you doing bad things. A fine is a late step in the process for organisations who wont listen.
> Have more public resources for people with limited resources. Law firms and Large corporations use Legal Expenses has a weapon in Civil Courts over smaller companies due to the high costs and generally no public resources for Civil access
Is off topic when it comes to GDPR, see my previous answers
> All Civil Cases must have to show Actual Damages not Theoretical Damages
Again off topic with GDPR, but in the UK that is how damages works already, isn't it?
I've been running websites and doing IT for a long time. I've spent least 10 hours on my employer's dime reading about GDPR and trying to figure it out. There's a lot of ambiguity. We're in the US, we don't do a lot in Europe, so we're at less risk, and my conclusion was that we're small enough (while MUCH bigger than streelend) that we're not going to be a target while some of the ambiguities get worked out in courts. This poor guy has no protections.
I'm not faulting the person, I'm just saying the response doesn't seem founded in firm reasoning, but in (self-admitted, by the link!) "I need to look into this but I haven't, so we're shutting down". This isn't a newsworthy event or "proof the GDPR ruins businesses".
This is, again, because the legal text is ambiguous.
> This isn't a newsworthy event or "proof the GDPR ruins businesses".
It is anecdote that complying to a far reaching and ambiguous law has real consequence.
I posited this to our counsel when discussing what to do about GDPR. He cautioned that he’s seen investigations start due to a nosey bureaucrat.
I don’t know if your product is public facing, but if it is, all it takes is a single sufficiently powerful government employee to get curious about your business and start asking questions.
Even if you’re not doing anything wrong, having to engage counsel to respond to the government could get pricey.
So many contradictions in one paragraph.
The reality is that almost all businesses are small businesses, and most businesses are microbusinesses. These sorts of organisations don't have full time resources watching out for potential legal hurdles coming down the line in a few years. Many of them don't have full time resources at all.
It's ironic that a law where one of the main effects is to dramatically increase notification requirements has resulted in barely any media coverage and no notification from any official sources to any of my businesses yet. What media coverage there has been mostly seems to have been prompted by people being surprised by the sudden wave of privacy-related emails. So, how is this not going to be a surprise move for millions of small businesses if no-one did anything to tell them about it?
If you run a business and were not aware of GDPR then you incompetent or employ people who are feeding you bad information.
Seems like these businesses who are not "aware" of it are exactly the type that would have other bad practices that will leak personal data of their customers.
Why? Most businesses are very small and don't have any sort of in-house legal team, and won't go actively looking for expensive external legal advice if they aren't aware that they have a need to.
Seems like these businesses who are not "aware" of it are exactly the type that would have other bad practices that will leak personal data of their customers.
That is an entirely unfounded assumption. There is literally no relationship between being technically competent in protecting personal data, having a positive attitude towards respecting privacy, and being aware of new laws coming out of the EU.
You most likely already had one and are now paying them to do this as well
In the UK the ICO is the governing body, and they say I don't need one. From their guidance linked below
>The GDPR introduces a duty for you to appoint a data protection officer (DPO) if you are a public authority, or if you carry out certain types of processing activities.
I am neither a public authority or carry out those certain types of activity.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Again, part of the problem is that it's not clear what does and doesn't constitute a violation.
I can tell you as someone who is working in an old school retailer/wholesaler we are not, and neither is anyone we are talking to through various trade bodies, employing lawyers to do GDPR.
Lawyers can't help you with ambiguous laws very much as it takes precedents to make sure what the words mean.
That is COMPLETELY IRRELEVANT to what people are saying. If someone complains about me, am I obliged to defend myself? If I don't, am I subject to ruinous penalties? If I do and am victorious is the complainer required to compensate me for all of my costs?
GDPR punishes the vast majority of businesses that do not have business models reliant on selling user data in favor of trying to catch the ones that do.
Unfortunately, I fear this regulation will do absolutely nothing to stop the bad actors from selling data as they do now.
But I'm completely in favour of it anyway.
If you mean he just slapped some Amazon ads on his site to support his side project, then accusing that guy of "selling your privacy data" requires quite a bit of mental gymnastics and is a pretty dishonest description of the facts.
The blame here is wholly with the users for putting their data online in the first place (really, you can go a very long way with my.fake.name@gmail.com!) and especially Facebook for providing the framework that enables this all.
*edited for grammar
"But it's such a small site/ the person's side project" all the more reason to stay away from this. Having a code of ethics where you end up using the most profitable option anyways is not a real code of ethics
The point of ethical judgement is that it's _not_ the best choice by other factors
He's not making a profit. Meaning he's actually paying out of pocket to allow neighbours to lend stuff to each other. Yet he's abandoned his code of ethics?
But many ads are those that track you across pages and use many of the same stuff as Facebook to show you products. So if you're uncomfortable with that, it's important to put pressure on that.
If he were just throwing up Google AdWords /FB ads or whatever he would be participating in an ecosystem that is unethical for many. It's helping to support a good cause, but wouldn't it be nice to get good things without contributing to an unethical system in the process?
But likely in complete compliance with GDPR... As Adwords and FB Ads would be in compliance.
That is the entire point of laws like GDPR, it has nothing to do with User privacy and everything to do with Ensure their can be no competition to Adwords or FB in the future.
Blaming users for providing their personal data is strange -- if the implication is that nobody should provide their personal data because it can be abused then is it not obvious that the use of personal data should be regulated?
If the majority of banks lost your money regularly, would you blame customers of the bank for using banks -- or would you say that banks should have stricter regulations to stop people from being screwed?
As for the Amazon bit, I think you're underselling it. Amazon tracks users in arguably unethical ways (due to the lack of consent, and the scope, and the inability to opt-out) and display their ads is inflicting that on your users. If you care about your users privacy (which is what GDPR is trying to enforce) then you would know that "just slapp[ing] some Amazon adds on [your] site" is not the correct approach to handling users' personal data. I do agree it's not trivial to handle GDPR if you don't have a lawyer (though you can get a data officer from a legal firm), but complying with laws is part of doing business.
I honestly thought this kind of reasoning was a right-wing caricature. No, it is not obvious that choices with risks attached should always be regulated away.
Disclosing information in proportion to trust is a basic life skill. I understand that many in the tech community are frustrated to see the general public failing to exercise this discipline, and maybe regulation is the best way to protect them from themselves, but that's not obvious.
>If the majority banks lost your money regularly, would you blame customers of the bank for using banks -- or would you say that banks should have stricter regulations to stop people from being screwed?
False dichotomy. You want a spectrum of financial products that depositors can choose from according to their risk tolerance. It's essential that we have stable, regulated, insured checking accounts. It's also essential that we have self-directed brokerage accounts.
>"just slapp[ing] some Amazon adds on [your] site" is not the correct approach to handling users' personal data.
A site sending your browser Amazon ads does not oblige it to execute or display them. And this isn't some secret backend upload. If someone is willing to use a site with this revenue model, why is that your business?
The assumption is that all users are actively making a choice. Many are not aware of the choices they are making, and I think it's wrong to punish them for it -- when companies profit off this lack of literacy and people rush to their defense whenever people start talking about regulation.
I don't want companies like Google and Amazon to be able to hoard massive amounts of personal information about a large portion of the world's population, and not have to respect the rights of the people whose information they have acquired.
> You want a spectrum of financial products that depositors can choose from according to their risk tolerance.
If effectively everyone of importance just uses Amazon (or Google) ads then you don't get a "spectrum" and there's no choice involved. You have an option to either use or not use a majority of the internet. Yes, you can use ad-blockers but that's not a long-term solution.
> A site sending your browser Amazon ads does not oblige it to execute or display them. And this isn't some secret backend upload. If someone is willing to use a site with this revenue model, why is that your business?
Most users are not aware of how these things work. I agree that if everyone knew how to block those ads and what the actual problems are with them, then things like GDPR might be less necessary (though the right to retract consent is something that should be enforced).
But even then, ad-blockers are a defense against an industry that is over-stepping ethical boundaries every day. At which point do you say that companies which inflict systemic violations of ethics on billions of people should be held accountable? Or is it always the fault of the people because they didn't care enough about their personal information?
What ethical boundaries do you think are being overstepped through advertising?
I could imagine a major ad campaing where this question is posted all over the city:
"What ethical boundaries do you think are being overstepped through advertising?
Think for yourselves, don't let the government tell you what to think!
Sincerly, your friends the advertising business"
That's a hard fucking question for me to answer concisely, so I wont do that. Sry.
Are you going to stop using all these services that track you some way or another?
Most digital companies wouldn't exist if they weren't allowed to use the data.
So instead of just blanket calling it something it isn't and something that certainly isn't unique to FB or Google why not actually discuss the fundamentals rather than scapegoting someone just because they are some of the most successful.
> Most digital companies wouldn't exist if they weren't allowed to use the data.
GDPR does not deny you the right to use user data, it regulates usage. This is such a ridiculous strawman that it doesn't even classify as a fallacy, it's just simply a lie.
> Are you going to stop using all these services that track you some way or another?
(I have stopped using many of the services you mentioned, but you're actually touching on the reason why regulation is necessary.) It is unreasonable to tell the general public they should stop using the internet if they want to maintain their privacy and dignity. And that's why there need to be regulations to provide protections for the general public when using a technology that is so central to the modern world.
You are still using them one of the biggest users of personal data your ISP and that's a service you pay for.
Don't pretend you are stating facts when you are just stating you personal opinion.
This is a statement you're not possibly able to prove, and you've even left "the data" open, so you can quibble about the definition in future replies (despite the GDPR clearly giving one).
Terminating replies here due to the gross intellectual dishonesty; have a great night.
The current state of data privacy doesn't even include the spike.
As you point out, education is a fine idea, but it isn't going to work if there is a major industry based on it not working.
I had the impression that this is rather clearly regulated by the GDPR. A user has to consent to each use of her data. And you have to explain the use in an understandable way, no legalese. Just make a list where you explain in simple words how you want to use the data and add a checkbox to each item (default not checked). I don’t see how this could hurt any ethical business model.
This is a misunderstanding. Consent is only one acceptable legal basis for processing personal data under the GDPR. Almost everyone is going to use it as little as possible in future because of all the extra red tape involved. Ironically, that probably means a lot of organisations will now be straining to justify processing on some other basis and to minimise use of data subjects' explicit consent and exposure to the associated subject rights.
Just make a list where you explain in simple words how you want to use the data and add a checkbox to each item (default not checked).
It's not that simple, because for example organisations may have legal obligations or legitimate interests in processing data about someone even though it may not be in that person's interest. Consider these:
[ ] I agree that my bank may keep records of the money I owe them.
[ ] I agree that the car rental firm may keep a record of me borrowing their vehicle.
[ ] I agree that the school where I'm applying for a job may do a background check before trusting me to look after kids.
Obviously there are many issues like this where consent for the data processing can't be voluntary and independent of everything else that is going on.
I'm actually pro-GDPR but this needs to be kept in mind.
If I refuse tracking for ads, then a newspaper can’t refuse me access to their articles.
Even better, it requires the use to say “yes”.
This arbitrarily limits the range of businesses that can exist. For the sake of people who value their privacy having nothing denied to them, it reduces the services available to everyone.
they can. a business does not even need to do business with you. it's not a right that a business needs to service you. and btw. this is german law.
heck they can even rely on other laws to cancel your service any time they want.
in the next years GDPR will change nearly nothing. except that it will kill some smaller businesses.
GDPR is not strongly enforceable, if people think they have a right to something they still need to go to court.
the only thing which might change is that it will be easier to delete accounts and data (which is a good thing).
It won’t. It will just replace the common “no one reads but clicks” TOS. And the user can change her mind anytime she wants.
> The amount of "no clue what this is" among non technical people I know is 100%.
If you can’t explain a non engineer or scientist how personal is collected and used it’s probably not a bad idea to outlaw this practice.
> But the EU pats itself on the back cause they're tackling privacy issues. It's a joke.
It’s certainly not enough but a step in the right direction.
Speaking of false dichotomies...
I think you'll find that self-directed brokerage accounts have more regulations than checking accounts because they provide more opportunity to commit fraud.
See, I disagree with this very premise. Why is it true? It's _not_ my data; it's data about me. Even things like pictures, once shared, are no longer under my control. I actually feel it's fundamentally dangerous to make users think they actually control data they don't.
> If you care about your users privacy (which is what GDPR is trying to enforce)
I also disagree with this. The GDPR doesn't do anything to make companies handle my data more carefully or responsibly.
If I share a photo, it’s still my photo, I still own the copyright to it, and as an American I’ve used the DMCA to revoke access to photos when tech companies wouldn’t remove my photo when asked politely. The rest of my data is no different. I own my data and the data about me, not them.
GDPR gives users the controls and governance over their data that should have always existed, but that tech companies gaslighted users into believing doesn’t exist.
At the very least, my original statement was overly broad.
It requires the entity to give you the ability to delete your personal data, which means a contract where you grant a service a permanent and irrevocable right to data about you in exchange for a service is illegal.
It also requires the entity to provide an equivalent service to any site visitor that chooses to not grant their data to the entity, thus making the business model of trading even revocable access to one's data for a service unviable in the long run.
It makes it illegal to offer a service in exchange for data that is stored without end-user retrievability. Therefore, it makes a contract where you grant a service irretrievable data about you in exchange for a service is illegal.
All of these reduce the range of possible voluntary interactions. It's anti consent.
And it is bonkers to imply that something that requires you to actually get affirmative consent from the user is "anti consent". You know what's really anti consent? 10 page TOS listings written in 10pt font that hide what's actually being done with data deep inside.
>>You know what's really anti consent? 10 page TOS listings written in 10pt font that hide what's actually being done with data deep inside.
I agree that it is anti-consent. I don't have a problem with laws requiring more legible consent forms.
My problem is the many limitations on the range of voluntary interactions that two parties can enter into that are found in the GDPR, a few of which I listed, and which you totally ignored.
No, you didn't. You gave a list of one-sided transactions where the user has no freedom or really consent at all in the matter.
"My problem is the many limitations on the range of voluntary interactions that two parties can enter into that are found in the GDPR, a few of which I listed, and which you totally ignored."
No, you didn't. All you did was post a list of "transactions" where the company has all the say, and the user really has no input whatsoever. No one is going to miss those transactions.
If you truly, honestly are concerned with "consent", then you should be applauding this law, as it does require actual, informed, affirmative consent. Not the "Here's a great wall of text, agree to give us every little bit of data with no recourse whatsoever for you or don't get any access to the service at all" form of "consent".
I'm sorry, but I cannot take seriously the idea that "if you can't sell yourself into slavery, you aren't free".
I have difficulty responding to such an immature mischaracterization of what I listed.
I listed a set of contractual arrangements that are now illegal. All of them could be entered into completely consensually, and cannot be reduced to being categorically one sided, given we don't know what the value of the service the user gets in exchange for their personal data will be in every instance that said contract is used.
You're infantilizing people when you claim they're not capable of consenting to the sale of their personal data. In fact, no court of law would ever agree with you that these contracts are non-consensual ipso facto what the user offers, which is why the only way these kinds of contracts could be categorically disqualified is to circumvent the courts' purview of establishing consent, by resorting to statutory interventions like GDPR.
And you're vastly over-simplifying the world, and overestimating your understanding of it, when you claim that such contracts could never be in the interest of the user.
What you're doing is absolutely reckless.
>>I'm sorry, but I cannot take seriously the idea that "if you can't sell yourself into slavery, you aren't free".
Selling your personal data to someone is not slavery. Slavery is a permanent condition, affecting your future self.
Personal data sold at one point in time only covers the data generated to that point in time, and does not forfeit data that is generated by your future self.
And in that set, you predicated that the user could not revoke consent. That means that it is not a free contract.
>And you're vastly over-simplifying the world, and overestimating your understanding of it, when you claim that such contracts could never be in the interest of the user.
A contract in which one can not revoke consent is a contract in which one can never truly give consent. If I am unable to revoke my consent, then it can never be in the interest of the user, because my interest may change in the future.
>What you're doing is absolutely reckless.
No, what was absolutely reckless was the attitude of this industry that they should be entitled to suck up every last piece of data they could.
>Selling your personal data to someone is not slavery. Slavery is a permanent condition, affecting your future self.
Which is what you're pushing for. You don't want me to be able to withdraw consent later, thus my selling of data WILL affect my future self.
>Personal data sold at one point in time only covers the data generated to that point in time, and does not forfeit data that is generated by your future self.
It still affects your future self.
Once again, you have twisted this idea of "freedom" so badly, that you are claiming that it is anti-freedom for the user to have the freedom to withdraw consent! You should be ecstatic that you will now be able to exercise greater freedom than you could before. You will have that most basic of freedom to evaluate whether or not something is still in your interest, and if it's not, withdraw, without the other party still benefiting off of your information.
No I didn't. I said that these contracts enable the user to sell their personal data. If a personal data sales contract includes a clause allowing you to 'revoke consent' AFTER 'selling' your data, then you are renting your data, not selling it.
By making contracts without such clauses illegal, you are reducing the space of contractual interaction, in making it impossible to sell one's personal data.
>>That means that it is not a free contract.
Again, I have difficulty responding to such immature mischaracterizations of reality.
Selling your personal data is a 100% "free contract".
>>No, what was absolutely reckless was the attitude of this industry that they should be entitled to suck up every last piece of data they could.
You obviously don't care to debate this issue based on rational arguments and facts. You're debating in bad faith. You've already made up your mind and are more than willing to mischaracterize the situation, and people's position, to push your views.
>>It still affects your future self.
Everything you do affects your future self, but this particular type of sale does not cover data genereted by your future self. It only covers what you have already generated.
It's absurd and totally dishonest to compare it to selling oneself into slavery. It's nothing more than hysterical fearmongering about the free market, in support of government limiting people's contractual rights.
>>Once again, you have twisted this idea of "freedom" so badly, that you are claiming that it is anti-freedom for the user to have the freedom to withdraw consent!
You're once again mischaracterizing the ability to re-voke a sale, after the fact, as "withdraw consent".
When you sell something to someone, you no longer have a claim to that something, and thus the other party no longer needs your consent to maintain ownership of it.
That I really need to explain the semantics of ownership to you, and explain how allowing retroactive and unilateral reversals of sales makes it impossible to sell something, shows just how completely delusional and dishonest you're being.
All the changes are to "consent", which is the naive consent of clicking "I accept".
You can still do anything with a proper, considered, contract.
I don't see why the new rules couldn't have been limited to those of this sort, which ensure that users are providing considered agreement.
I'm sorry, but it's not. Full stop.
> If I share a photo, it’s still my photo, I still own the copyright to it, and as an American I’ve used the DMCA to revoke access to photos when tech companies wouldn’t remove my photo when asked politely.
I didn't say you don't own the photo, I said you don't have control over it. Those are two very different things.
> The rest of my data is no different.
Exactly, you have no control over it.
> I own my data and the data about me, not them.
No, you don't _own_ your data.
> GDPR gives users the controls and governance over their data that should have always existed
No, on all accounts. There is no reason at all that you need to delete accounts or force anyone to delete any information about you. That's all just silly.
> but that tech companies gaslighted users into believing doesn’t exist
That's also silly. If you don't control something, you don't control it. Full stop. I don't understand why you don't understand that.
No, control is only one thing: the ability to constrain the actions of another. You can _never_ prevent your ex from sharing nudes of you; you can only recover damages.
> Save your apologies
I'm not appologizing for anyone.
> regulation is coming to fix the deficiencies in data rights and protection
No, regulations are coming to give users a false sense of empowerment at the cost of everyone else.
What are you actually trying to say here?
If anything, the anomaly here is that inappropriately using or sharing personal data about someone is in most cases still only a regulatory or at most civil matter and not a criminal offence. Obviously such an act can potentially cause far more harm to that individual than many physical acts of violence that do carry jail time.
Actually, this isn't true, for the purposes of this analogy.
You can only lock up people who are in your country and under the control of your legal system. If your ex flees to Russia and sends out these photos from there, good luck prosecuting them and putting them in jail.
This is the internet we're talking about. An EU law doesn't apply outside the EU, in places like Russia, the US, China, and many other locales. What's the EU going to do when sites in those other countries refuse to take down pictures based on this EU law?
I actually cannot think of a single instance where someone has "control" over something and the law exists purely as a way of exercising that control, and I can think of hundreds of examples where laws exist to stop people from doing things they may be physically capable of doing but would produce a negative effect on society if permitted. Maybe there is such an example, but it'd be an outlier.
On the one hand, the other guy is legally correct - gdpr's purpose is to legally give individuals control over data about them (pictures they upload, addresses they input, whatever). That control is responsible on a site to site basis - if a person's naked picture is leaked online, every single IP address that hosts it must take it down if requested, or violate gdpr.
You're making a functional argument - if a person's nudies are leaked online, they don't functionally have control over that data. Morals and laws be damned, that picture is staying on the internet.
You can both disagree about the morality of this but simply restating both of your points with more "full stops" is pointless. If you're both really having trouble understanding each other's positions, step back and try to defend the opponent's decision.
Which is my point. You no longer retain any control over it. A law saying you have control over it is silly, because it's worse than worthless: it makes me think I have control over something I don't have control over.
Laws cannot magically manufacture things which cannot ever be created.
Moreover, the gdpr doesn't prevent any of the problems that have caused data breaches in the past. The way that Target and Equifax (both of which could easily claim the data they had was essential to their business: Target with credit cards and Equifax being used by banks to coordinate information) are both equally likely under the gdpr and both equally unpublishable.
As for Facebook and Cambridge Analytica, how would this have been prevented? Facebook can just ask you to opt in to their usage of your info to use their service. Facebook can share information with other entities that claim to be gdpr compliant. Other entity then shares information with other people outside of Facebook's control.
I just don't see how the gdpr changes a fundamental fact: you no longer control something someone else has. Laws cannot change that. Laws can give you recourse, but they cannot change it. I actually believe that it's dangerous to believe that I have control over things I don't: it's a false sense of security.
Also there's the fact that companies can end up sharing data to other parties, or a company can be acquired and change their mind about what the data will be used for (which is allowed because of the originally nebulous scope of their T&C which was specifically designed to allow for expansion without asking for user consent explicitly when usage changes). GDPR provides methods for users to be protected in both of those cases -- while just enforcing education does not.
Not to mention that if education was mandatory, then the same companies complaining about GDPR today would be complaining about educating users how their services abuse their dignity. Cutting Google/Amazon/Facebook/etc slack for making hundreds of billions from users' personal data and creating "Big Brother"-esque profiling systems for their billions of users doesn't really seem rational to me.
If I owned a site I would not have a problem to delete someone's personal data.
Also your sugguestion is that if you want to keep your data protected then you should not be using anything on the Internet or make any deals because once you have ordered something on Amazon it can sell your data to everyone else? Or when you rent an apartment, realty agency should be allowed to share your name, SSN, bank card number and address with everyone? No, I don't think it should be this way.
If I find the person that owns the server hosting my data, and I put a gun to his head, and I say, "remove my data," do I now control that data?
What if I instead pay someone else to go around putting guns to the heads of server owners? If I build an army?
What if instead of that I communitize my resources into a legal system that doesn't put guns to people's heads, but will take their money away and put them in jail if they don't follow the laws?
Don't get me wrong, I'm with you in the hacker-culture sense: fuck the system, man, if Google wanted to it could probably blackmail individual US government officials to the point that it took the country over. I get that. I guess we can get deep into a political science debate about governments and social contracts.
Put it this way: Is your sense that you can walk to work without getting mugged a false sense of security? If not, the only alternative is homesteads with militias (not walking to work anymore), or, arming entire populations (putting the burden of self-defense on the people). In the past, this has been tried, and led to gang rule.
If we "give up" on legal systems, we have ample evidence for what happens. When you apply those lessons to the digital space, maybe it's not 1:1, I guess some countries will be learning that for us, while others will try things like GDPR.
It's all a journey for human civilization. People like you that promote self-defense are great because we get amazing government-agnostic tools out of the deal. People that support GDPR are also great because we can test out "social contract" methods.
What's wrong with dancing around both sides of the aisle?
The gdpr makes people think that they don't need to think about what they share and with whom. Do you really think companies are going to significantly change just because of this? I highly doubt it. Sure there will be some things, but in the end many of the same patterns and uses will emerge.
You keep writing as if everyone has a meaningful choice about who gets data about them, but clearly that is not always the case. Someone may obtain data about someone else from a third party, and you can't avoid sharing a certain amount of data and still function as a normal member of society.
The idea of absolute, black-and-white privacy, where either you share personal information or you keep something completely to yourself, isn't very useful in the modern world. Our conventions must be more nuanced than that, and in practice that means what really matters is who gets access to data about you and what they're using it for.
That means basically don't share them with anyone, don't sign any contracts, don't work and live in the street. Because even your employer or real estate agent can sell them to anyone else in your model.
Aside from the "nuh uh; uh huh" nature of this exchange, I really don't understand what your position.
> I didn't say you don't own the photo, I said you don't have control over it. Those are two very different things.
I'm not sure what youre definition of "control" is, but based upon the arguments you've made about "control" above, I assume you mean it in some absolute sense.
Ownership definitely implies control. He can use DMCA to compel a third party to stop publishing his photo, for example. How is that not "control"?
Your definition of control seems to be somehow about capability or power, rather than normative ethics or legal right. Which is a rather absurd way of talking about this issue.
In that sense of control, I don't even control my own body. Someone who is stronger than me can hurt me; can rape me; can even kill me. I have no control.
Of course, for normative reasons, we make laws against other people controlling me in certain ways even though they have the power to do so.
Data privacy is no different. The discussion is not about what degree of control a party is physically capable of exerting. The discussion is about what degree of control the government should grant to each party.
The fact that someone somewhere is capable of hoarding my data, does not imply that this outcome is just or optimal. Your position is a textbook example of the naturalistic fallacy.
So if I investigate you, take your picture, etc. have I stolen from you?
I actually hadn't considered it before, but I imagine that being a PI in e.g. Germany must be a veritable legal minefield.
This is where it becomes murky for me.
If you send me that photo via email, should you subsequently be able to revoke my access to that photo. If so, by what means?
If you used a closed messaging system (say Facebook's messaging system, or Apple's Messages), should you be able to revoke access?
If you follow the argument a hop, skip and a jump away, what happens if I submit a photo to a publication and they run it on their website? Can I revoke access? What if that publication has published that photo in a physical form?
ie, where is the line where a reasonable person should expect that the data they have willingly shared/published has slipped beyond their control?
All other rights are reserved. Would it change the dynamic to be able to revoke access to assets in a private messaging system? For sure. But copyright law (at least in the US) supports this right of the copyright owner. The inability to revoke access is a failing of the tool or the product, not the law.
> The inability to revoke access is a failing of the tool or the product, not the law.
Does the law need to change? Or (in the case of email) is it fine as is because the reasonable person realizes that once you hit 'send', the content is out of your control?
https://en.wikipedia.org/wiki/Personally_identifiable_inform...
This is similar to some other laws, you can be as slanderous as you want to someone in private but if that slander makes publication then you open yourself up to a lawsuit. You may own copyrights to the image you take of someone in public, but you cannot use their image in your merchandise despite owning the copyright to that image. If someone is doxed in an email, and the email hosting provider used is compromised and has their emails linked to the public, the person who was doxed has just as much right to request that the publicly available emails be removed from search engines, etc.
Why do we protect any rights by law? Usually it's because some harm is likely if the right is not protected and the potential victim cannot effectively protect themselves due to some imbalance of power.
Reasonable people can debate how far privacy rights should be protected and where the balance lies between protecting the data subject and allowing data processors to do useful things. Maybe the GDPR doesn't strike the ideal balance here and favours one side too much at the expense of the other.
However, it makes no more sense to argue that someone can't have any legal control over how personal data concerning them is processed than to argue that, for example, someone can't have any legal control over whether their physical property remains in their possession. Many social conventions have proven to be useful, and we codify them in laws so that everyone can see what is considered acceptable behaviour and so that people who try to undermine those norms for their own benefit at the expense of others can be dealt with.
No, it's more like making it a crime to break or lose something lent to you. At most it's a civil matter handling damages, not an extension of control over the item lent (baring any contractual agreement).
Put another way, how is protection of privacy by restricting what someone may lawfully do with personal data any different to protection of physical property by restricting when someone may lawfully use or remove it? Typically you can't physically stop someone from sending your email address to someone else once they have that information, but then typically you also can't physically stop someone from stealing your TV while you're out once they have a big sledgehammer and access to your front window.
I think most of us would still say that we have legal control over our possessions, and most of us would still say that theft is unacceptable behaviour and should be punished. In Europe, where perhaps we tend to have stronger feelings about privacy than in some parts of the world, a lot of people similarly feel that they should have the ability to restrict how data about them is being used and shared, and that some things that some organisations have been doing until now are unacceptable behaviour and should be punished if they continue to do them.
"To have legal control over your PII" and "To have legal control over your possessions" are similar in nature. The fact that such purposes are implemented in different ways, for mostly technical reasons, does not diminish the argument.
The main technical reason is that, right now, loss of control over PII is widespread, and individually processing each claim would likely overload the judicial system of EU countries which usually don't have class action lawsuits. GDPR simulates a class action lawsuit using regulatory bodies, to be triggered by refusal to comply with a significant number GDPR requests.
(not perfect control, but that is the same in every area where law is broken, e.g., there are burglars, but still I think you would consider being in control of your personal belongings, and nobody would argue that we should stop prosecuting burglary because many burglars will always get away with it)
GDPR attempts to fix that.
That might be the theory, but there may be unintended consequences in practice.
As others have said, introducing regulation always has a cost. In this case, the cost appears to be that a small side business that has been providing a useful service to the local community for several years will no longer be available.
It doesn't matter whether the business was actually violating the GDPR. It doesn't matter if the person running it misunderstood the new regulations and formed an exaggerated view about the potential risks. The end result is still that his service isn't there any more.
The level of risk and profit is going to adjust to the correct balance over time.
It apparently wasn't running at a profit even before these new overheads. It was essentially being provided as a gift to the community by the person running it, and that person is not prepared to accept what he perceives to be a lot of extra risk just for doing people a favour. Why then is it reasonable to assume that someone else will step in and be willing to provide the same benefit to others despite the additional overheads?
The level of risk and profit is going to adjust to the correct balance over time.
Again, why should we make such a strong assumption in general? Previous ill-judged regulation of tech industries by the EU hasn't gotten any better with time. They still haven't fixed the "cookie law", which must be on the short list for most useless and widely ridiculed law in history! More seriously, they still haven't fixed the VAT mess, which finished too many microbusinesses and caused significant damage to many more slightly larger ones.
Intentions and effects do not always align. The effect of GDPR is to make any business model where a user trades their personal data for a service illegal.
Business models involving voluntary exchange should not be prohibited.
The fact is, the free market already gives users control over their data. They are not obligated to use any service that requires private information from them.
And by mandating an option to remove your data, it makes a contract where a user gives a permanent grant of their data to a service provider, in exchange for a service, illegal.
they could have alredy fined current privacy abusers under the existing law framework. this will be used to stromgarm independent news sources.
Yeah, I'll just get a small loan from my father.
At it's core it is the most ethical a free service can make money (aside from donations). He isn't selling the data or showing personally targeted ads. (Of course it could be using some amazon plugin that does it anyway for convenience or from ignorance, but he can do it without it through amazon apis)
What? Define almost nothing. For small businesses it is a wishful thinking they can hire anybody from a legal firm. They probably don't even have a lawyer or a legal department as they can't afford such luxury.
And now we are finding out LED lights are bad for our eyes and our sleep, so we may go blind sooner and die sooner.
Ok that might be a bit extreme, and besides there is an efficient incandescent tech that will probably come back and save us (and you can argue the EU helped that too)... but my point is the EU has good intents but their creations seem polarised into either extremely preemptive or extremely reflexive and are often premature and poorly thought out, fighting for something for the people but often without thought for how they will directly hurt the people.
For tech the EU isn't exactly unique in this respect though, the UK for instance recently tried to inact some pretty rediculous laws that undermine basic technologies that make the internet work.
Out of touch with reality much?
They can take some credit for the dim and dimmer mercury containing CFLs, and the ludicrously expensive and somewhat unreliable early LEDs, if they like.
"From the description Streetlend didn’t violate the GDPR in concept though. Addresses are public record, available in public databases, and there is nothing stopping you from doing lending eBay. All it needed to do was clear it’s records every 6 months and let people delete their accounts."
> But the comment you commented on said:
"The problem is what happens if a legal firm or an agency targets you. Even if you adhered to the spirit of the law, they can dig up evidence that you didn't obey the letter of the law (since GDPR is quite loose and ambiguous)."
The issue seems to be that the resources required to resolve a delta - from Streetlend's pov - are perceived as excessive. Too much risk; not enough reward.
Look at what happened with Thiel and Gawker. Right or wrong is irrelevant if the opposition has deeper pockets and can bleed you to death (in legal fees).
> Startups will find a way to make money that isn’t selling your data.
Perhaps, that could be true. But plenty will not want to be caught in the crossfire in the meantime. And that too is a biz decision.
Just like all regulation its very doable but its way more cost effective for the big players.
I am not asking anybody to take my word for it, just saying how my ethics and tech education tell me I should be doing things.
I don't currently run a business online, but if I were, honestly I'd be more worried about the usual headaches like accepting payments legally, dealing with spam/fraud/abuse, finding product/market fit, etc. GDPR would be somewhere around 500th on my list of "start-up things that give me crippling anxiety."
So from getting sued 28 times with 28 different laws you have reduced your risk to being sued with just 1. Now, in order to have an online business in the EU you just need to comply with 1 data protection law instead of with 28. How is this bad?
What I suspect is that many people were just not aware of the 28 previous data protection laws that they needed to comply with, at all, and are now realizing that these laws exist.
GDPR simply made me aware that I am not willing to go the extra mile for hobby projects so I shut them down and never sold any info to anyone, nor have I served ads/trackers.
Many commenters of my sub-thread here are making me look like a histeric and that's seriously annoying. It's all about deciding if a cost is worth it and I figured in my case it wasn't. Why make it more complex than that?
There is nothing in the GDPR that allows for a person or lawyer to sue a company for GDPR non-compliance. All they can do is complain to the regulatory authority in their EU country, which has the sole power to issue fines. And if you're not taking care of my data, then I have no problem at all with you being fined.
I stated exactly what I had in mind, the rest is your projection and fantasy.
You say there is nothing in the GDPR that allows a person / lawyer to sue a company. I have no reason to doubt that. Okay. But laws aren't that clear and cut; there are overriding laws, parent laws, derivative laws... the spaghetti black hole is huge and everybody who isn't a hardcore specialist lawyer can't possibly hope to be 100% informed and protected.
That was my original point and still is. How did you transition to the hint that I am (1) farming personal info, (2) not taking care of it, and (3) I deserve a fine.. guess that's one of the Universe's mysteries.
Society doesn't owe entrepreneurs a business model, but it does owe people a dignified life and some control over information that can be used to harm them.
I fully agree and that's why yesterday I deleted 7 hobby projects -- all their databases and hosted apps, cancelled VPS subscriptions and never made any backups.
Never put ads, never put trackers, never sold anything to anyone. Hell, I just checked their VPS dashboard once a month, that was all.
Since I don't want to deal with the legal baggage I am doing my part in NOT contributing to the rampaging privacy abuses and simply destroyed anything goodwill that I created in the past that might have collected any shred of personal data.
Thus I am perfectly okay with my personal project being a collateral damage of the GDPR. I believe in the GDPR and want to see responsible private data usage.
Sorry, but society doesn't work like that. You are always responsible for your actions no matter if you earn a profit or not. And not bothering to read up is also not an excuse.
Companies take risks. This is just another one, that has to be managed like all other.
(1) I have a few hobby and free projects hosted on the net where people sign up and might fill up full names. Never made a penny out of them, never had any trackers or ads -- just a bunch of acquaintances used them, and maybe 50-100 strangers.
(2) I don't want to deal with the GDPR.
(3) I delete the entire database without backing it up.
(4) I delete my hosted app and don't renew my VPS subscription.
Zero damage done now and in the past because I never sold any data to anyone.
What part of that gives you the hint I am irresponsible? Society might "not work like that" as you say and since I don't want to deal with extra legal baggage, I am simply doing my best not to contribute to the abusing privacy problem. I delete any and all traces of personal data my hobby apps gathered.
Really, what's so unclear or tempting in my original comment that makes you people attack me?
Fact is, at we have a giant tragedy of the commons due to loose and fast play with peoples personal data. This is similar to what happens in third world countries where people play fast with working safety or environmental laws..
My point was, any data you collect has a risk of doing harm and we have historically grabbed everything in sight, just in case - as if there was no potential downsides to it.
What happens when somebodys sideproject (which hasn't been updated for 18 months due to lack of interest) gets hacked and a gay persons sexual preference and home address is leaked and that person is killed by haters? (extreme example I know)
I have no problem with you doing the above 4 steps, but I do think that we, programmers, have a collective responsibility to safeguard people against non-obvious (to the layman) dangers, the same way as any other industry.
And the tone in this thread is hysterical from the "ooh the GDPR is devil incanated" group.
Fact is that the "new" regulation aligns with what most europeans would have belived had been the law all along (and actually was, just mostly non-enforced).
I also acknowledge that the US have vastly different ethical standards and that everyone is free to be exploited as much as they want..
Click-through EULAs are also not binding in Europe for example, I am interested to see what happens when a DPA takes an american company to court due to having given themselves unlimited consent on page 2712 in their EULA.
If those companies withdraw from Europe, I welcome the collateral damages of some innocent but lazy projects..
Do you really think that a thought about what data you really need (and why), the need to actively safeguard the data (especially the sensitive) and a need to formalize those thoughts on paper is a unbearable burden?
All the american scare-mongering about the fines are people that don't understand European law practice.
And the whole affair of Facebook moving non-EU people away from the Irish juristiction to have them not under the GDPR shows, that it will probably work as intended. (Some people call it Lex Facebook already)
You did misunderstand me. I take partial responsibility but really, give us the programmers at large a bit credit. A good amount of us have a lot of culture in other areas and aren't that immature. (Sadly however, a lot are so I can understand your negative assumption.)
> Fact is, at we have a giant tragedy of the commons due to loose and fast play with peoples personal data. This is similar to what happens in third world countries where people play fast with working safety or environmental laws..
100% agreed with this and your next several paragraphs. I never thought that was okay. Never. But I had a rather cynical view on it: no laws about it? Sure, let's abuse as much as we can! That's how corporations are and that's how they will always be -- it takes a certain mindset to grow into a corporation and I am afraid that being rather scummy is practically a job description for the people who make the corporations come into being, and grow. I also always thought that when the inevitable regulation comes, that's NOT gonna change like anything.
Imagine if FB made you click "I Accept" on a dialog box that deliberately obscures the fact that they want to gather and use your data. What can you do? Report them? By the time a judge calls to them, they might have a switch to make the popup look 100% legit but who cares -- by that time FB or any other corp. might have the "informed constent" of millions of people, again.
It's a huge game of cat and mouse and IMO the regulation we see now is just the first step. I anticipate tens of other steps so things aren't gonna get better anytime soon.
So there you have it. An opinion from an Eastern European dev. ;)
> And the tone in this thread is hysterical from the "ooh the GDPR is devil incanated" group.
IMO only if you feel you are on a mission to calm down histerics. Our perceptions are warped by our preconceptions, we all know it. Example: in my eyes yes, there are alarmists, but much more people who are outraged by the inevitable fact that all of us have to become a little bit of lawyers in order to not get chased by the EU (and not only in terms of the GDPR, of course; there are many other venues through which we can be attacked). I understand the idea of GDPR and I support it fully but that doesn't stop me from disliking legalese.
I don't want to ever abuse people's privacy but I also like to remain a programmer, not become a half-hawyer. Okay? That was my message all along.
> I also acknowledge that the US have vastly different ethical standards and that everyone is free to be exploited as much as they want..
As an European, yes, that has been my observation for a LONG time. USA tech sector has a huge ethics problem and the VC-enabled tech bro culture in SV is only making things worse with time. Somebody should definitely do something because the world is taking notice. VCs operate on reputation as well and sooner or later more and more of them are gonna start refusing to fund startups.
> Do you really think that a thought about what data you really need (and why), the need to actively safeguard the data (especially the sensitive) and a need to formalize those thoughts on paper is a unbearable burden?
OF COURSE NOT. But again, that's my point. It's an expense you absolutely have to spend when you make profit. But I didn't; like the OP, I had hobby websites. It's a simple cost calculation. I don't want to become GDPR expert for things that don't make me money. Thus I shut down my personal projects. If and when I become a guy running a service for profit, I will go the extra mile and shoulder the burden of protecting personally identifiable information.
> All the american scare-mongering about the fines are people that don't understand European law practice.
Not sure it's only that. You can call me a scaremonger in this instance as well. It's just that I am no expert lawyer -- and for me this fact leads to the conclusion that I can be brought down if an expert lawyer wants to get their hands dirty with me. Nothing more, nothing less. Our so-called "justice system" favors the side with the better-paid / more-experienced lawyer and that's pretty much historically proven, especially in Eastern Europe. Maybe it's less visible in most of EU and USA but from what I've read through the years it seems to happen quite a bit there as well.
Maybe the people disagreeing with me believe in the system much more than I do. Perhaps my cynicism is seen as non-constructive. But it's well-founded in the reality I live in.
I just want to add, there is a huge difference between working as a programmer for somebody else and for yourself.
In the latter situation, you have implicitly agreed to shoulder all risks and burdens..
In the former you are a salaried professional, and somebody else has the potato.
The point to protect users, not to prosecute companies for operating. However, GDPR would be enforced if you just ignored it.
It really isnt such a big deal.
And in that case the regulator would write you a letter asking you to fix it. At that point you have the choice to fix it, or to write back and explain why you can't fix it now. Or you can ignore the regulator, which may lead to a small fine.
There's no need to shut the thing down just in case someone sues you when that hasn't happened yet.
On the other hand, there's a good reason to shutter your site because you don't have time to make it respectful of people's privacy. By all means, shut down your site because the GDPR makes you realise that! But that's not what OP is saying.
The problem is also not botching the encryption process -- and relying blindly on some "ready-made frameworks" is a sure-fire way to do that.
I shut down my hobby projects because I didn't want to rework them. Deleted everything, never sold info to anyone, never served ads and had exactly zero external JS snippets on them.
If I am to open a business, I'll however work a lot to be GDPR-compliant. I believe it was about damn time for something like that to emerge.
GDPR is highly vague omnipresent regulation with huge strict fines. It's like infamous cookie law times a million.
They could make it into a good law, my opinion on what should have been done:
Keep good parts, such as:
- Appoint official 'security' representative who're responsible for breach disclosures, promoting security practices etc, that person can be personally held responsible for shifty company behavior (though nothing draconian) like non-disclosing a breach, so they would be motivated to be on user side in the company.
- Let users ability to download their own data
- Let users clear way to tell company that they want to stop using their account (and related data gathering)
- Mandate more open disclosure of what is done with data gathered from users
And also:
- Mandate easier ways to review EULA and changes to EULA (like each change should be available separately, describe what changed and why)
- Create system of centralized disclosure of security vulnerabilities by third parties, with record showing request and response publicly after some time. Maybe also create some system of grants for third party penetration testing for larger players in the internet.
- Split available data into categories, like 'non-sensitive data', 'sensitive data', 'highly sensitive data'. Medical records, financial records etc is highly sensitive and higher standards are applied. Email and name is non-sensitive data (so you could run a simple forum, or any other simple free service, where you only want email from a user, without being afraid).
- Split companies into tiers, under 50 employees or 100000 users nothing applies; 51-1000 employees higher standard applies; over 1000 - full power applies. This also should be tied with previous point - for example, smallest tier company should still be responsible for some rules if they deal with highly sensitive data, and if it's largest tier company they should be following some rules even if they only deal with non-sensitive data.
- More sensible fines. For example 1% or $100k, whichever is smaller for the first time, 2% or $1m second time etc. Designated security officer can also be held responsible in the same manner (like, % of salary and later being forbidden to work as a security officer). It can also be tied to tiers of companies.
- Start applying law gradually, beginning with just applying it only for european countries.
I believe that would keep benefits for users and won't create giant problems for the industry as a whole.
The exception being: there is no minimum for fines. So a small company could be fined absolutely nothing for an infringement if it was representative of the harm caused or they fixed the issue.
Also. Security representatives--actually called data protection officers--are only necessary at large scale or highly sensitive operations.
The law is being applied gradually. It is already in effect and has been for two years. The approaching deadline is when the penalty clauses will come into effect. How it will be applied remains to be seen, but has no bearing on the validity of the legislation itself.
It is pretty clear what streetlend needs to do to be GDPR compliant: if the user data is actually being sent to the third parties (the ad networks) then users need to explicitly be told this. If the data is not being sent to third parties then users already consent to their data being stored by entering the data (the data is necessary for the performance of the service operated).
Next to that: allow users to delete their data when they close their account (this should be as easy as setting cascade on foreign key constraints).
As for the geography: if your interaction with European citizens is incidental and not purposeful, you cannot be charged under the GDPR. It is only if you are actively trying to target your goods or services to the European market that they will enforce against you. This is obviously the case since they will have no power to enforce the law otherwise, but it is also covered by the three paragraphs of Article 3.
> Next to that: allow users to delete their data when they close their account (this should be as easy as setting cascade on foreign key constraints).
That is definitely not easy and doesn't work like that. That's why it's common practice in any serious system to have 'deleted' flag instead of actual deleting.
> It is only if you are actively trying to target your goods or services to the European market that they will enforce against you.
Yes, and if you target whole world like most sites in the internet do, you're targeting Europe?
Nothing. GDPR enforcement is carried out by each country's regulatory authority; they're the only ones who can sue, target or take action against you for non-conformity.
As I understand it, you will be able to appeal or somehow else address the European Data Protection Board, that will be tasked with ensuring the consistent application of the regulation:
Coordination and Consistency
Under the Directive, there has been a certain level of coordination in interpretation and enforcement. Apart from informal contacts among authorities, there has been a succession of non-binding opinions issued by the “Article 29 Data Protection Working Party,” an advisory committee comprised of representatives of the national supervisory authorities (commonly termed “data protection authorities” or DPAs), along with the European Data Protection Supervisor appointed by the European Commission. Under the Regulation, that group will become a more independent and powerful regulatory body called the European Data Protection Board, tasked with ensuring “the consistent application” of the GDPR. An entire chapter of the Regulation (Articles 55-63) is devoted to cooperation and consistency, with procedures for multiple DPAs to coordinate investigations and promulgate consistent decisions and policies reviewed by the Board and reported to the European Commission.
One feature of coordination that should be helpful for multinationals is a provision for companies to work with a “lead supervisory authority” in the country where the company has its “central administration.” That authority will then coordinate with the authorities in other countries where the company operates, attempting to achieve consensus on issues that affect all of them.
https://www.infolawgroup.com/2016/05/articles/gdpr/gdpr-gett...
Further, in my opinion the GDPR is wholesome. You ought to implement it even if it didn't exist. If your business relies on playing fast and lose with user data then IMO it's not an honest business ...
Further still, the worse punishment is 4%/20M; it's not the default intervention or anywhere near the only way that the GDPR will be enforced.
>Small tech owners can't fight such litigations. I am kind of baffled how this point evades so many people in this thread.
Isn't this the same with the other laws, like copyright,trademark, patents, software licenses? I could say the same about one of this other laws, like you may have a video of you doing something cool and a bit of copyrighted music could be heard in background then you coulg get sued by a big bad law firm, the difference is that in this case the regular citizens are protected and not the budget of big music publishers.
They don't even need to dig up any possible violations - just the legal process alone is enough to kill any side project.
Or, "You can beat the rap, but you can't beat the ride." For a small company or individual, even winning a GDPR case will be a Pyrrhic victory.
Guess they believe in the system more than I do. My country -- and the EU -- has been known to have cases where a big player makes a grizzly example out of a small player, in basically every business area.
Then maybe those people shouldn't be opening side businesses? Running a business implies having to deal with business matters which include legal.
For example in Switzerland if I want to open a small cafe in the corner selling home made cheesecake, I'll have to first figure out what the exact regulations in my state are, obtain a permit for opening one, create a "Hazard Analysis and Critical Control Points" concept and send it to the authorities, make somewhat sure I get accounting right, maybe getting a permit for infrastructure changes, etc.
I'm not talking about GDPR especially because I don't know enough about it yet. And in general I am sceptical of laws and regulations that don't seem absolutely necessary.
What I don't get is why anyone should care that some tech people running a business don't want do deal with legal like everyone else? What makes us so special?
I had 7 hobby projects that very few people used. After I read on the GDPR yesterday, I simply deleted all their databases and apps (without backing anything up) and didn't look back.
I believe in the GDPR and I don't want to become a part of the problem. The lowest friction solution was to just delete stuff I don't deem at all important.
If I am to open a business, I'll cross 100 rivers to be GDPR compliant. And you are correct -- us the techies aren't special, of course.
I only asserted that for hobby projects or projects that are not turning a profit the extra effort is simply not worth it. Nothing more.
This is still debatable, because what if in near future your encryption turns out to be weak and all the personal data become readable again? Things like this... This law was really not thought through.
Eventually some good souls gathered the fine money and bailed the poor man. And then the suers got pissed and tried to raise the fine, eventually had to pay for... I don't know the legalese for that, but basically they took it too far and the judge called them out on it and forced them to cover ALL legal expenses.
My point however is that for ordinary people even the nerves and time lost in a lawsuit are too big a price to pay. We aren't machines, these things get to us.
Considering one can be sued for just about anything, or accused of patent infringement for just about anything in tech, the fear of litigation isn't a compelling argument.
This article sounds a lot like sour grapes and shows no real attempt to actually figure out what compliance would look like.
Which is what the site in question did...
A lot of people here: please CHILL. You make me look like a histeric. Not what I had in mind.
- I don't want to become a semi-lawyer or hire a lawyer until absolutely necessary.
- I had 7 hobby projects where people could fill out full names if they wanted to.
- I deleted all of them -- apps and database -- without backing them up. Never served ads or trackers, never had a 3rd party JS on any of them. Unless somebody had unfettered access to the VPS-es without me knowing it, I never leaked personal info.
It's a very simple cost calculation: I don't even want to invest 2 hours in reading the GDPR in details nor do I want to rework the hobby projects to encrypt the personal data in the DBs, hence I refuse to be a part of the abusing privacy problem and delete anything that might have gathered any personal data. I believe in the GDPR and this was my way to at least not contribute to the problem.
Seriously, what's so unclear? You can repeat to me that "knowing laws and protecting from bogus lawsuits is a fact of life" but it doesn't have to be before I have a business -- which I don't. So I still respectfully disagree that I have to learn legalese today.
So seriously, don't get so worked up over a comment that expresses a sentiment that I want to become more law-aware only when absolutely necessary and not a minute before that.
Geez.
You don't want to hire a lawyer until absolutely necessary, but you're willing to delete everything way before absolutely necessary?
My hobby projects were inconsequential. Nobody cares about them much, including myself. I prefer tinkering, not becoming better versed in legalese.
It's rather fascinating to me how I keep being misunderstood. I guess I am not stating things as clearly as I imagine.
I run a small business and I like this. Just about anybody can read it and understand what rights and requirements are being set out in it.
The GDPR specifically refers to the concept of "micro, small and medium-sized enterprises" [GDPR 40p1 and 42p1 use this text; they direct member states about the spirit of the law, referring that the needs of such businesses need to be taken into account].
GDPR 58p2 sets out that regulatory bodies in a member state have the power to issue warnings. As in, if you mess up, unless the mess-up is malicious or excessively negligent, you get a written warning and reasonable time to fix the problem. My government (The Netherlands) has taken the effort, as have a significant number of third parties, of creating a legal document of 3 to 10 pages covering some details, and they generally set out more explicitly that you grant yourself a week or so to fix problems without penalty. Whilst the GDPR is intentionally ambiguous in order to try to be somewhat futureproof and remain short enough to read back to back in an afternoon, it's fairly clear this is perfectly fine.
The most strenuous sections of the GDPR involve requests from those whose data you store. If they ask you to supply what data you have of them, and whom you've shared it with, you have to comply. Within reasonable timeframes, and you cannot lie about it. If they ask that you delete this data, you must be capable of doing so, and you must do so within a reasonable timeframe. However, the GDPR is nice enough to grant you exceptions for reasonable measures which nevertheless make it hard to comply. Things like a backup tape are specifically called out. It's okay if data that's been requested to be removed, stays on those. You would have to show that this data is pseudonimized (GDPR-ese for encrypted, pretty much).
Any service which has a hard time supporting requests to explain what data you store and where you've stored it, or which cannot delete it from the main service on demand... should indeed just call it a day and shut down. I don't think a service like streetlend would have a hard time supporting such requests, however.
I don't run a small business, I make small things on the internet, this is not why I got into tech, I don't want to read 68 pages of yuk. If I made a small site that saves some user data i'd just pull it down too, I don't want the burden of worrying about being sued for some small thing I created, you just wont have it anymore.
FB fucked it up for everyone, ultimately people gota learn that when you give data to someone you implicitly entrust them with it. FB had to go and be evil and now the EU is overreaching demanding everyone spend their time bubble wrapping everything... everyone backing them up are the village people taking to the streets with torches and burning shopkeepers after the king was found doing witchcraft. Go burn the king.
If you're making something that stores personally identifiable information outside of what you need, and don't care enough to secure it or offer ways for a user to manage that data then yes, take it down. Good riddance.
Or, just don't store that data in the first place. If you're storing usernames, passwords and the like then you have nothing to worry about.
Absolutely false. Anything pertaining to a person in any way is personal data. All default web server installations are GDPR violations, unless nginx grew an "edit the access.log entries pertaining to you" endpoint recently. (Although you can maybe argue "legitimate interest" for web access logging if you invest the time, and implement the right to erasure).
Something as simple as running Google Analytics without a processing agreement in place is a liability.
1. User profiles can't be sent to GA. For example, hacker news has /user?id=JohnDoe for profiles, and that contains a username, which is personal data that should not be shared with GA. Ok, so I could rewrite my profile URLs before sending them to GA without the usernames.
2. I haven't heard a single source mention referrals. If I'm on a user profile on my site and click a link, that's going to send /user?id=JohnDoe to GA as the referral. I would need to overwrite the referrals before sending them to GA as well.
3. What about 404 pages that I make up? What if I visit https://www.example.com/JohnDoe? That's sending my personal name to GA again. Hmm, ok, the site could exclude GA from 404 pages.
4. What about search boxes? What if I use the search field on a blog? https://www.example.com/posts?search=JohnDoe. Hmm, that's my personal data being sent again. Ok, we need to make sure any data from search boxes is now stripped and not sent to GA.
5. What if I manually add a query parameter or modify one? A homepage might have https://www.example.com/?page=2, but what if I change it to https://www.example.com/?page=JohnDoe. Hmm, yes, that's personal data being sent again. I guess I need to validate the page parameter to ensure it's an integer before sending the URL to GA. What if I then type in a personal phone number as the page number?
There’s no damage that GDPR protects you from, and it doesn’t add any liability for stolen, hacked, or misused data.
Facebook can do the same shit they were doing under GDPR!
> (83) In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.
also:
> Section 2, art. 32, Security of processing:
> Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: [..]
Actually I think that's a good thing then.
One of the goals of this law and similar efforts is to make it clear that you need to consider the social, ethical, and legal ramifications of the things you crate. You are not creating neutral things in a vacuum; there is no neutral ground in a burning world[1]. That "small thing on the internet" might be reuniting families that were separated by work or politics, or it might be undermining the support structures of an entire industry or community. Maybe you are creating a social space*, which includes a duty to manage that space to keep so it doesn't become a tool of abuse[2]. Maybe your small site stays small. Obviously you cannot be expected to foresee every potential consequence of your creation, but you at least need to make the effort and catch the low-hanging fruit (e.g. the basic privacy features enforced by the GDPR).
[1] http://opentranscripts.org/transcript/no-neutral-ground-burn...
[2] http://www.gdcvault.com/play/1024060/Still-Logged-In-What-AR
One often wonders whether lawmakers heed their own advice here with what they create.
Well, not really: That's the constitutional court's job.
I personally find regulation like this abhorrent and against my morals. Sadly I don’t have the money to fight the EU so my creations will be blocked to its citizens going forward.
The end result of this is that EU citizens will be the ones that suffer from lack of access to technology and the smart ones will end up VPNing into non-EU networks to stay on the cutting edge.
This is a relatively simple regulation that basically required anybody processing user data to do so responsibly. How does one have an ethical objection to that?
Alternatively, hire a lawyer, like you would for any other regulatory requirement.
Far better details? It gives vague info on what might be considered personal data... I would not call it very detailed. In most cases just says personally identifiable information.
Right, because everyone who lives in Europe is too incapable of coming up with technology and businesses themselves (that have the added benefit of being GDPR compliant) and without access to American firms they will surely fall into a technological dark dark age.
Instead of viewing GDPR as some nightmarish spectre coming to ruin everything, why not think of it as a potential opportunity? You're familiar with making money in a borderline no-holds-barred approach, now try and come up with some innovative business ideas that _don't_ rely on scraping and selling as much data as mechanically possible to prop up a business. This is a great for the disruption hackernews loves so much.
Cite one EU startup that you’ll miss if the issue was reversed.
That's the best way to think about it. When the EU started imposing VAT taxes on non-EU companies on internet sales to EU customers, a bunch of businesses sprouted to handle all of that accounting for you. (So instead of me selling my software online directly, technically all of my EU customers now buy from a US company called FastSpring instead. Fastspring remits VAT on EU sales for me so I don't have to deal with EU tax law, just my own Australian tax law.)
There's probably similar opportunity for a GDPR service that stores customer data via API service, that shields small / micro businesses from all the GDPR compliance. (Eg all your personal Wordpress blog comments are actually stored, hosted and served by a service that handles GDPR modal-consent forms and deletion requests on your behalf.)
>... now try and come up with some innovative business ideas that _don't_ rely on scraping and selling as much data as mechanically possible...
The problem is a lot of us who would never scrape or sell data and have no interest in exploiting our customers, are still worried about not being GDPR compliant, and the EU choosing to pursue us an example for something that none of our customers actually care about.
Why would you be worried about being pursued as an example? Is there any data that supports this as a reasonable fear? Isn't this exactly the "GDPR is a nightmarish spectre that can destroy anyone at any time" mentality?
Your points are well argued - especially regarding the ethical and social implications of what we create, and I agree with them, however we have differing definitions of "small" in this context.
Your arguments apply to things that are maturing and are reasonably big already, but big things have small beginnings... and the internet/web is a fantastic place for nurturing those very very small ideas for basically free, this law appears to threaten those small ideas.
What you call overeaching other's call protecting the interests of consumers.
Nah, just for companies that trade personal information as if it was cattle feed. As an individual, I have no problem with the GDPR.
If you won't handle my personal information with proper care, you should shutdown or get sued out of existence.
Cheers.
Do you find yourself accidentally including data sales SDK's? Do you finish your website or app and realise you've accidentally set it up to fingerprint the user, scrape everything you can from them and sell it?
If your business is just a tool supported by wanton data scraping are you actually doing anything innovative and worthwhile or are you just making an MVP to pack full of advertising and jump on that bandwagon?
If you aren't doing that, then it's just a matter of checking what data you are harvesting and thinking about why you have it and if you really need it. Because if it's actually critical to the running of your business then GDPR does allow you to keep it. If it's not, why waste space, effort and now risk in bothering to harvest and keep it in the first place.
For example, an online shop might collect customer addresses, even if the sale is purely digital. If the shop ever decides to expand to physical goods, those addresses will be very useful to find an optimal location.
However, GDPR prevent the shop from collecting (or more accurately, raises the cost of doing so), since the use, and value of, said data only becomes apparent in the future. So the shop makes the best choice now to remove the collection, and then suffer the future disadvantage.
Maybe show a notice just below the address input fields that "we remember your address for a while, this is why" and link to the relevant section in the privacy policy.
Then you already had a ton of legal obligations, you were just not aware of them, since only now everyone is talking about the GDPR.
"FB fucked it up for everyone"
A lot of the things people are complaining about right now were already illegal, before the GDPR. People were just not caring about it.
Questions without answers in the GDPR:
* how to carry out a legitimate interest balancing test
* who is your lead regulator (do you have a lead regulator?)
* When do you need a DPO (large scale is left undefined, as is systematic)
* How reasonable will any particular regulator be towards inadvertent violations
* what precisely counts as the required technical and organizational measures in art24
* how do you define what is one purpose and what is two purposes?
Painful when needing to implement? Absolutely (not my favourite either, I want definite answers). The way it is? Yes.
Not all laws, nor all legal systems, are equally vague. It would be really helpful if the regulations had been accompanied with a large set of 'example applications' demonstrating how EU members should be expected (or required) to implement the law in specific scenarios.
Uncertainty is a real cost too.
1 page or 1,000 pages, most people are not in a position to accurately interpret it and understand what does or does not comply.
1. Get consent when someone creates an account, saying what you do with the data including how you make automatic decision (e.g. which amazon pages you recommend).
2. Allow people to unconsent/delete accounts
3. Have a page that allows a user to download their data.
4. Have a way for them to fix mistakes in that information
That doesn't seem that burdensome. In fact some flavor of that is pretty much what you get with standard a standard create account/view account/change account/delete account workflow.
Now they do.
He wants to leave the game? Feel free! He wants people to be completely powerless? Well.. the kitchen has a door. Feel free to open and leave if it gets too hot.
What you say it's an unintended side effect, I think is very much intended. That's why the GDPR (if it doesn't fail for other reasons) is a very welcome regulation.
Once upon a time Facebook was the fresh new competition. Once upon a time Google took pains to maintain their "Don't be evil" motto. Everyone starts out starry-eyed, keen to destroy the oppressive incumbent. Very few stay that way.
Show us some proof the GDPR is harder for small and new businesses to comply.
McDonald's has it easier to comply with food safety regulations than the cozy mom and pop cafe down the street. Would you be willing to shit your guts out because the ambiance is better there?
People cooking for themselves at home aren't required to comply with (the same) food safety regulations. Obviously, you never eat at home or at the home of a friend or relative either, right?
People collecting phone numbers in their personal phonebooks aren't required to comply with data security and privacy regulations.
What does it change? Not much just by knowing, but it can allow for change, including exercising a right to delete that data under GDPR. That is a positive change in my opinion.
You understand, you just disagree and you seem intent on moving the goalposts as needed to make your “GDPR = bad” point.
Regulation allowing me to delete that is good.
It's pure FUD.
But since we're throwing out wild speculations it's more than possible this guy was doing something really shady. (He admits to affiliate links which are perfectly fine under GDPR). There would definitely be a market for user data even about who's borrowing what, where. Certainly the vast majority of these "the GDPR killed our free business" are precisely these shady businesses who knew they were dead anyways if they had to actually ask their users for consent in plain language.
Number 2 could be an "email me if you want your account removed". This will trigger like two emails a year, and you just run a DELETE FROM command. If it becomes more, you make a page.
For numbers 3 and 4, see number 2. I expect that this won't be much either.
The page doesn't mention a single thing that would be a good reason to quit over GDPR. I think the author was looking for a reasonable-sounding exit, especially since he was operating at a loss (and apparently cared about it, since he was cooperating with Amazon to begin with).
What were the previous data protection laws in the UK anyway? In the Netherlands, none of the 4 points above are new. Our data protection law from 2001 also required all of this.
So the owner might be making an excuse, yes, but I don't blame them as it seems like a legit way out if they wanted to close up.
If you administer a free service that takes an hour a month to keep running, and suddenly you're faced with an immediate upfront time cost plus the likelihood of spending many more hours every few months responding to user requests, shutting your service down might be a rational decision when you would otherwise have kept it running.
However, I felt the need to comment on the assumption that an application that is only 5 years old would imply that it uses a tech stack that no one would care about.
How is it that after a quarter of a century of web development, that the state of the software used is so bad that people still assume that something that is a few years old is assumed to be useless?
Five years ago I was messing around with Fortran 2008. Having done so, it's not as interesting anymore. That's not a function of Fortran, which was created when my grandparents were 20-somethings, but of the time spent with it.
Which, you know, the guy directly cites as the reason he's shutting down if you actually read the site.
There's plenty of ambiguity in the GDPR, especially around logging, backups, and third parties (e.g. login through Facebook/Twitter/Google, you know, that thing that five years ago everyone was trying to sell at the way to do user authentication). This guy just decided it's not worth the potential of being sued while we wait for the dust to settle on how those ambiguities shake out (because, honestly, the only way we're going to get those cleared up is if someone is sued and they're made clear by case law).
My concern has been the account deletion provision. Does the GDPR expect us to be able to go back and modify past backups? Years-old tape archives?
I would guess there is no requirement data is wiped. Your file system doesn't wipe data, it just marks it as deleted. At some point it's a technicality, the important part is that you stop using the data.
I suspect intent matters more than technicality.
When you collect data, you have to tell your users at collection what your retention policy is (this is part of Right to Transparency). So, right there, you should probably have a retention policy, and "forever, always" isn't really a well-thought-out policy.
The Right to Erasure is not as far-reaching as some people seem to think it is. If the Legal Basis of the data collection is Consent, then that consent is revocable and processing (including storage) pretty much has to end as soon as consent is revoked. But if the Legal Basis of collecting the data is something else, and I really feel like 90% of the time in practice it's going to be Legitimate Interest, then the Data Controller gets to balance their own needs against the rights of the Data Subject when handling a Right to Erasure or Right to Object request. And you can probably make a good argument that you don't need to modify back-ups. Your argument is stronger if a) your restore-from-back-up procedure can ignore or delete the user's data during/after restore b) your data retention policy eventually deletes the back-up.
Also, that data is still associated with the user. Is it to the letter of the law to keep it, even if it's unreadable?
Also, how does this mesh with pci retention rules. (Yes, they are not law, but it's still an awkward place to be.)
You couldn't possibly anonymize the data and then do the analytics, unheard of.
It's not that the analysis can't be done anonymously, but to do so requires foreknowledge of everything you would like to analyze.
Second, I think you're missing the context here. If I need to encryption each log entry that pertains to a user, even if it doesn't contain pii, then adhoc analysis is nearly impossible to do.
If the WORM store rotates out old data (webserver logs, tape backups with retention and rotation, etc.) then you simply inform the user of that and that's it.
Can you point me to where that's allowed? What if retention is reasonably long (a year)? or not (10 years)?
> s it truly a WORM store that cannot delete any data ever never? If so, you'll need to encrypt the data in a way that allows you to make records inaccessible.
So now I can't perform impromptu analysis of my own data in any computationally easy way? Security analysis? Analyzing shipping information to optimize in the future?
[0]: https://www.acronis.com/en-us/blog/posts/backups-and-gdpr-ri...
[A0]: http://www.gdprarticles.com/gdpr-articles/data-subject-right...
[A1]: GDPR Art. 5 §1 a, b, c and f, §2
[A2]: GDPR Art. 17 §1 b and c, §3 b and e
>So now I can't perform impromptu analysis of my own data in any computationally easy way? Security analysis? Analyzing shipping information to optimize in the future?
Any analysis will have to be done in a way to make sure you're not exceeding the bounds of network security or you're outside legitimate interest.
Analyzing shipping information is the same, as long as you do everything to make sure the data is pseudonimized or not otherwise in risk of leaking personal data, it's fine or alternatively you ask customers about it.
>What if retention is reasonably long (a year)? or not (10 years)?
Use your own judgement of what is reasonable, worst case you get a letter from the EU asking you to reduce the retention timeframe as long as you made an actual effort to implement the regulation.
Why do you think that's a given? It seems like an implementation detail with a couple of easy solutions such as caching or batching, and it should encourage better system design in many cases where the analysis doesn't require PII and thus it's better from a security perspective not to have access to it there to begin with.
There have been a ton of breaches over the years where reporting or test systems had data which they didn't even need but which had been loaded anyway since it was less work than subsetting the data.
Unless I'm pulling from a raw dump of shipping I've bought, which would contain the address so that it can be cross-checked if there is an issue and I didn't know ahead of time that I wanted to perform this analysis.
If you want shipping analytics you'll have to decide that ahead of time. That way you reduce the risk for your customer in case you don't want to do this and if you do want it you still make an effort to reduce the data necessary.
You should keep in mind that the basic premise of the GDPR is that the shipping address isn't yours to begin with. It's personal data of your customer and ultimately belongs to them.
If they don't allow you to use it for analytics, tough luck.
Yes, I should be omniscient. Thanks for clearing that up.
> Any kind of profiling or monitoring goes through several layers to ensure the minimum amount of data necessary is collected.
Yes, because they need to collect it. It's not about looking at what they have.
> If you want shipping analytics you'll have to decide that ahead of time.
Again, I'm not omniscient. I can't figure out what my company will be doing in a year, and waiting another year to collect the data I already have could see me hemorrhaging money.
> You should keep in mind that the basic premise of the GDPR is that the shipping address isn't yours to begin with. It's personal data of your customer and ultimately belongs to them.
Which is an absolutely silly notion. It is the company's data, not the users.
> If they don't allow you to use it for analytics, tough luck.
Which is silly. It's the company's data; they should be able to use it to improve their business.
Not omniscient but being able to plan ahead does help a lot, yes.
> It's not about looking at what they have.
Yes, because they only collect what's necessary and if they don't have that they ask if it's necessary and collect it.
>I can't figure out what my company will be doing in a year, and waiting another year to collect the data I already have could see me hemorrhaging money.
Then simply ask your customers to hand over data with consent to use it for analytics, problem solved, no?
>Which is an absolutely silly notion. It is the company's data, not the users.
No. Under GDPR this is no longer the case. The data belongs to the user now because corporations have shown time and time again that owning the user data is too much responsibility for them.
You do not own the customer data anymore, the customers own it. And they can decide what you're allowed to do with it.
End of story.
Which is entirely silly and basically contrary to everything else, e.g. data retention regulations that assume the company owns the data.
Even that data isn't owned by you. You are merely responsible for keeping it safe while you have to store it. Ultimately it's the customers data. End of story.
If you’re trying to do analytics, you don’t need PII - anonymized locations, sizes, bucketed prices, etc. will cover that and usually makes the process faster, too.
Look at it from a different perspective: does ignorance of food handling procedures or electrical wiring codes remove your obligation to follow safety regulations? This is the same thing for data: yes, it requires you to act as if you care about users’ privacy but that’s another way of saying that you’re no longer being subsidized by being allowed to fob the cost of negligence onto the users rather than being responsible. Everything which people have been talking about in this thread is already covered by accepted security best practices.
The company will have to decide for themselves, primarly, if some interest is legitimate.
This means you weigh the data you collect by the single user against the continued function of the company, the great good and all other users. The company should then be able to demonstrate this process to the regulatory body.
There is no nailed process but keeping logs for a short amount of time to ensure network security and keeping some logs longer for legal compliance will most certainly pass as legitimate interest.
Network security benefits the user themself, the company and all other users by ensuring their data is secured against breaches. It goes beyond simple self-interest of the company and protects the users too.
Similarly having an email address to contact a user can be legitimate interest. If you only send them informative mail, ie "Someone changed your password" and "We had a databreach" or even "Someone tried to login from Uganda using your password, check if that's alright please" it serves primarly to protect you, the customer and the relationship you build up.
IMO that means it's legitimate.
On the other hand, of course an adcorp could claim their personal tracking data is legitimate. The data collected does not benefit the user other than showing them ads and selling it to others. Of the three groups, only one benefits.
Or keeping a webserver log for 20 years including usernames and emails.
IMO that would mean it's not legitimate.
If you are wrong in what you think is legitimate, you get a sternly worded letter from your favorite regulatory body asking you to fix it.
If you think they are wrong about that, the best option is to write them back and explain why you think it's legitimate. You can work out a solution with them that satisfies both sides.
That was a response to the comment about the default installs in most distros, not the ability of centralized services to rotate logs. It was pedantic and I regret derailing the discussion with it.
> The company will have to decide for themselves, primarly, if some interest is legitimate.
Until a regulator comes and makes a separate decision, and you have to plead with them that you're not wrong even when they think you are.
> If you are wrong in what you think is legitimate, you get a sternly worded letter from your favorite regulatory body asking you to fix it.
From a regulatory body that has no real authority over me, except it might?
I think my biggest issue is that I don't deem data a company has on me _my_ data or that they have to explain everything they do with _their_ data about me. I was never under the impression that it was my data, and in fact, I assume anything I put on a computer I don't control or have a paid, contractual agreement around is public. I fundamentally don't agree with or understand the premise that the situation is otherwise.
(The biggest exception being that I do expect companies to honor their contractual obligations under their credit card processing agreements, but that's not really about _me_ or data about me.)
If you want a shortcut, you can try the EnterpriseReady site which has a great overview specific to SaaS companies: https://www.enterpriseready.io/gdpr/
As always though, your best resource is to talk to a lawyer. Do not trust any internet comments about legal decisions for your business.
One easy way to do this is with an expiration policy on s3 objects. You need to have an independent backup of those deletion requests though.
If you have a years-old tape archive you probably have a massive legal team who is much better equipped to answer this question.
You decide on a timeframe for deletion of backups (ie. X days). You keep a record of deletion requests you receive for X days. If you need to restore to a backup, you delete data again for the users that requested it.
Then you delete the backups and records of deletion (or the tables in it that contain personally-identified information) after X days.
All of which requires a good deal of development work.
[1]: https://www.citizensadvice.org.uk/consumer/get-more-help/how...
If you care about consumer's rights over companies's profits that is.
I am an architect for a company that does ABM, B2B ads, so I am well versed in the subject. We had to move all of our PI data in the raw form to a different AWS account, and only certain individuals with "legal" clearance can access it. This forced us to re-architect almost our entire stack, and rethink our main API.
The whole thing was a massive endeavor that took a whole engineering team two quarters. If this was three years ago, when we were less than a dozen engineers, we would have most likely thrown the towel and forego cookies and business in the EU altogether.
This has always been true, nothing has changed
The expected value of the case to the lawyers is the probability of winning, multiplied by the minimum of the expected award and the resources the defendant has available to pay, multiplied by the fee percentage that the lawyers are charging, minus the costs involved in litigating the case.
In the cases we're considering here, the probability of winning is low, the expected award is low, and the resources available to the defendant are low. They're simply not going to take them on.
She alleged I colluded with and stole manuscripts from her publisher (I published my content before she did). I knew I was in the right, and had proof to back it up. Then I found out it would cost tens of thousands to take the case to court and then if I won, I could claim the lawsuit was frivolous and sue for legal fees.
People can use the legal system to rope you into an expensive game that you don’t want to play. Even if you win, that victory might come at a huge cost financially and emotionally. Irrational and vindictive people can hire lawyers too.
Even in the case where fees are awarded, there is absolutely zero upside in being sued. The best possible outcome is to tie up tens of thousands of your own money in legal fees, and invest huge amounts of time and energy in a court battle. And of course there is always a risk you could lose the case.
For a passion project that is a big investment. I cut my losses, and I’m glad I did.
She tried the same stunt on someone else who went to a reporter, and tried to case the in the court of public opinion. She was resoundingly defeated.
All you have to do to be Gdpr compliant is delete user data when asked. There is no "trap card" provision.
I just do not get what there is to complain about here - the GDPR is a good thing for consumers, and as a business owner than gives a damn about privacy, it is not onerous to comply with.
For having an unfair competitive advantage over competitors who properly follow the law. This is a well-known tactic to get rid of competitors or just companies you don’t like.
Want to host the data on aws? You need a documented data processor agreement with them. Same thing with cloudflare and any other service you might want to use.
Want to use google analytics or some other javascript? Those cookies aren't required so you need a way to let users opt-in to using those cookies. And opt-out and delete any third party cookies. I'm still not clear on how the regulations expect you to delete third party cookies.
Amazon affiliate links also aren't necessary to use the service, and that sets cookies. Have to get consent before users can click on those links.
Don't forget that ip addresses are considered personal data.
And all of this might have to be written down and documented per Article 30 as well. The organization is smaller than 250 people, so that might be an out, but people are using the site daily so one could argue the processing is not occasional.
So that maybe someday we'll have a web without tracking again.
Assuming that these cookies are only set after clicking the link, and that there is no personal information in the links, then what is the problem? In any case, Amazon setting cookies is not your problem, it is Amazon's.
And that's just the engineering work. The website owner cannot know whether or not the engineering work and website meets the requirements of GDPR by himself. He does not have the ability to interpret the GDPR policies. The website owner would need to consult with a compliance lawyer or expert to assess the website for compliance. I would guess it would take a lawyer 10 hours at minimum (assuming the lawyer is a GDPR expert and already knows GDPR in and out) to assess a website for GDPR compliance, billed at a low $250/hr is $2500.
https://www.ctrl.blog/entry/gdpr-web-server-logs
"All of these logs contains personal information by default under the new regulation. IP addresses are specifically defined as personal data per Article 4, Point 1; and Recital 49. The logs can also contain usernames if your web service use them as part of their URL structure, and even the referral information that is logged by default can contain personal information (e.g. unintended collection of sensitive data; like being referred from a sensitive-subject website).
If you don’t have a legitimate need to store these logs you should disable logging in your web server. You’re not even allowed to store this type of information without having obtained direct consent for the purposes you intend to store the information"
Are you going to either 1) completely disable logging on your webserver or 2) ask for consent just to use a default Apache/Nginx logging configuration? The law makes no technical sense.
3) Change your webserver not to store IPs or to delete them relatively quickly?
The default Apache/Nginx configurations aren't suitable for production in many other ways but most distributions ship them with log rotation enabled which would prevent this from being a problem in the default install.
You don't.
Civil engineer failing to comply with regulations ending up in jail vs. software engineer well, doing nothing if his software does something wrong.
So welcome to the future where software engineers will be held responsible for what they create. I think it's right direction. And don't start with 'hackers playing for fun with side projects will no longer be able to do this'. It's same for engineer building a shed in his backyard. No one will have problems if he has not done load calculations and is using that shed by him self. Only difference is that if you put it on the internet it's like building that shed in a public park. And then you have problems if you don't think what you are doing.
There's a reason companies which are 100% software can be valued in the billions of dollars. Their software has huge, very real consequences.
Companies are valued at billions not because of life and death risks but usually because it enables other companies to make money. On the other hand, basically everything done in civil engineering could be seen as having real danger implications. Bridges and tunnels of course, but even roads which can wash out and cause harm.
Online services have “real consequences.” But not of the type as goods in the physical world. PCI and HIPAA have tried to mitigate against some of the most egregious crossovers of failed software. GDPR scares me. Not in the “I don’t like the consequences” but in the “I don’t know what this does and how screwed I might be.” I’m very happy to be on the other side of the pond where I can safely observe the fallout. Feels like buying a first generation Apple device: I’ll wait a few years and let the early adopters go through the pain for me...
If software didn't have strong real-world implications the entire software market would have been just a subset of the gaming market.
I'm not a regulations fan but for me, it feels simply like something obvious materializing.
Food safety, for instance, can affect everyone because bacteria can be anywhere and a lapse in safety practices has a high chance of public sickness.
I do think some software should be regulated more than it is. Is GDPR the answer? I don't feel so.
Make a calculator App and GDPR doesn't care. Make a calculator App that collects financial info and personal info and sends that info somewhere, then GDPR cares.
The difference here is that code published online has no assurances of being correct or adequate to the task.
Someone building a shed in a public park is, as far as I'm aware, generally not a regular occurrence and certainly you'd agree that a building on public property could be reasonably assumed to have been built to some sort of safety standards by a public body. There's a tacit agreement that, if I enter such a structure, I can reasonably assume it won't collapse on me due to poor design.
Code, on the other hand, is published online by hundreds of thousands of developers everyday. No reasonable individual can expect that any selection of that code is likely to contain anything that can be considered production-grade. Why are we taking the liability from the irresponsible corporation whose service gets pwned because they didn't review my shitty experimental crypto before using it?
Even popular and well used libraries and software shouldn't be held to this standard. You're expecting people who are building something in their free time to bear legal responsibility for the mistakes of an organization who is paying nothing to use their software. That's beyond not fair -- that would absolutely kill open source software and completely ruin the current ecosystem where a single developer and huge enterprises are on a similar level from an access-to-technology standpoint.
This bit is true. If the startup I work for had not turned profitable in the years leading up to GDPR, we would not be able to compete in this space anymore.
If your business is on such shaky ground that straightforward changes required by GPDR are going to cause your business to collapse then you have bigger problems. Because one employee suing you or your rent increasing will also cause you to collapse.
Yes, these are well-known causes of company collapse, so well-known that we have entire industries mitigating the risk (multi-year leases at fixed rate, shell corporations renting (see: wework), and temporary contractor/agency staffing). We don't have that for GDPR yet.
Firstly, there's nothing this site does that is so unusual. If the user gives explicit and informed consent for their data to be used in this way, then you are likely to be covered.
Secondly, it's looking unlikely that the rules will be enforced that strictly in the near term, especially against a small, hobby website. IANAL but you likely have a couple of years until you have any chance of being on the ICO's radar (ICO is the UK's enforcer). And even then, you can reasonably expect the find to be << €4M.
Thirdly, if you run this site from a limited company (about £100/year to maintain), then the very worst case would be that you are investigated under the GDPR in the future, and you can fold the site then at which point your liability ends. No need to do it now, in fear of something that may never happen.
I hope it's not too late to change your mind about shutting down!
So far I haven't found ANY person who has read the full 80 pages. Everyone is asking eveyrone else, they download whatever presentations they find on the internet, but NOT ONE have bothered reading the damn thing.
It will be a massacre for many companies, only because very few do their homework.
On the other hand I bet you have a better life with your belief until - if ever- you learn the difference the hard way.
Take the simple question: can you look at personal data on your monitor? What about Van Eck phreaking? Basically you are broadcasting the data. Do you need to protect against that?
Tell me what GDPR says about that.
It's like worrying that someone will be struck by lightning because they're located on your property near an antenna you set up, and you'll be charged with murder because of that. Yes, it's possible, and about equally as likely.
[1] https://en.m.wikipedia.org/wiki/Van_Eck_phreaking#LCDs
I would estimate the frequency of the attack similar to Lightnings killing people. I’m quite sure it happens but only in very small scale because you have to get so close to the victim.
If you choose to display customer data on your screen while raising funds for launching a new cryptocurrency in the Sultanate of Kinakuta from sketchy Chinese generals, it's on you.
But if you read the law, claim to understand it and don't implement it properly, you are screwed. It's just another case where savy managers are avoiding personal risk at the expense of corporate risk.
You're onto something, though: in a corporate environment, the word "compliance" is a magic spell that disables all critical thinking skills within earshot.
Is that a bad thing? The vast majority of regulations exist because someone's "critical thinking" went too far in the name of profit.
Your mistake is assuming that the idea being sold internally under the heading "compliance" is required by, or even tangentially related to, an actual regulation.
> Steve Wood, ICO Deputy Commissioner: Will there be a grace period? No. You will not hear talk of grace periods from people at the ICO. That's not part of our regulatory strategy.
All those concerns about the GDPR are, as far as I can tell, younger than a year, most of them even younger than a few months.
You had two years grace period.
If 6 years wasn't a long enough period for companies to prepare I submit that no amount of time would ever be.
I can understand why a small project that isn't immediately profitable can take a look at the uncertainty and say, "no thanks."
Within society "in general" there are usually other forms for quantifying, and spreading, the cost of uncertainty among larger groups. We usually call those markets "insurance." Car insurance, life insurance, health insurance, disability insurance, homeowners insurance, landlord insurance... all of it exists to "cope" with uncertainty.
If you're running a small operation that's hovering at or below breakeven, it's reasonable to look at the existing uncertainty surrounding GDPR and find that the only winning move is to not play.
I'm not a FUD guy; I'm a numbers guy. Uncertainty is real and entire markets exist to deal with them. Where there are _not_ markets that allow you to quantify uncertainty, it is reasonable to look at the potential downside and say, "that's not worth the risk."
I'd be very hard pressed to run a business that catered to the EU at this point until the first N lawsuits happen. There's a reason why in the US people prefer to incorporate in Delaware: it's not because it's the most business friendly state, it's because there is so little uncertainty in case law.
I am making no claims as to whether GDPR is a good thing or a bad thing. Simply that it's an unknown thing. And unless you have the pockets to play in unchartered legal territory, it is perfectly reasonable to shake one's head and walk away.
Super Monday Night Combat wich was developed in the US by Uber Entertainment [1]
Ragnarok Online terminates the access from Europe. They are in Korea. [2]
1 https://steamcommunity.com/games/104700/announcements/detail...
For example, IP address is PII and if you derive city, region or country from that it becomes personal data. Now if you are a small project or startup there is high chance that you are using some of the external analytics tools like GA or mixpanel(as building a good analytics tool is an effort on its own). Now you have to take care of data like country there as well and be very careful that you delete data like this as well.
I don't think city itself is a personal data. You could use user's IP address to get the city and then discard it and this way you know user's city but don't have to keep their IP address.
Google Analytics can be a problem; Google or someone else should make the analytics that doesn't store IP addresses.
And I think ISPs should randomly rotate IP addresses of their customers so they cannot be used for identification.
Quote [1]:
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’);
I think that soon there will be extensions for popular servers that implement something like this. I wish it were the default configuration.
Also I think if IPSs rotated IP addresses among their customers daily it would not be a problem at all.
The actual law is here and it applies when you offer services or goods to people in the EU or if you monitor their behavior in the EU.
The recitals are a pretty good commentary to clear up the law, the same recitals will be used by regulatory bodies and judges later on, as a guideline.
But they are not law. The law says anyone "in the Union".
Afaict from summaries on court cases in germany, "offering goods or services" definitely means you have to have more than accidental contact with EU customers. Monitoring is hopefully obvious.
The law says anyone in the EU (or is it EEA?) that you're interacting with.
Article 3:
> 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(This also seems to mean a forum with no monetary value at all, but that's another issue.)
The thing is, if you want to do business in the EU, you better know the legal system there. The US forces people in the EU to adhere to their legal system all the time.
Why? That's such a silly thing to assume. It's possible I've targeted no one by location or nationality.
> The thing is, if you want to do business in the EU, you better know the legal system there.
How is a silly forum a business?
It's not about targeting but about offering services to people in the EU. A silly forum that has a few EU users is beyond incidental/accidental contact and will have to adhere to the EU laws.
A silly forum may not be a business but atleast under german law it can be classified as business-like or otherwise commercial even if you don't make any money on it.
Atleast under german law, you are business-like if you offer a website beyond personal interest (ie, a webpage about you, your family or your hobby). A forum is certainly business-like.
The same forum can still be non-commercial, you don't have to make any money to fall under business-like.
In total, a non-commercial entity, which is business-like, and has more than incidental EU users will fall under GDPR.
>They've made a law that applies extraterritorially which requires knowledge of European cultural context to interpret correctly!
I'm sorry, the US made extraterritorial laws that require US cultural context to interpret correctly. You don't get any special treatment here.
If you save data beyond what is strictly necessary to conduct business, like doing analytics, then you will need to ask your EU users if they are OK with that. If you don't want to do that you can simply exclude EU users from any analytics.
Or exclude them from google analytics. Wouldn't be a giant effect.
There are plenty of devs out there who were running things probably at a loss, but for the sake of their community and users. Sure a few bug fixes here and there was a pain, but it was so small that it was worth it to make a couple people happy. Now they have one big reason to not keep it up.
Our dependency on services that will go away is a problem, but I'd prefer we'd search for different ways to preserve software once unmaintained. Government requires authors to send a few copies of books&newspapers to libraries... maybe something like that with source code?
If the user then decides NOT to share their location or want their data deleted entirely, then the as long as the site stops sharing their location or removes their data completely (within 30 days), then they are still GDPR compliant, AFAIK.
EDIT: Sounds to me like a side project started getting a little unwieldy or had too much technical debt for the developer to manage, and he decided to shut it down using GDPR as a vague justification?
> GDPR threatens website owners with fines of 4% of turnover or €20 million (whichever is higher) if they do not jump through a number of ambiguously-defined hoops. The law, combined with parasitic no-win-no-fee legal firms, puts website owners at risk of vindictive reporting. Young websites and non-profits cannot afford legal teams. Therefore the risk posed by GDPR is unacceptably high.
> Perversely, this new EU law hurts small and ethical startups, but helps reinforce the dominance of Facebook, Google and Twitter, who are able to prepare and defend themselves using established legal teams and cash reserves, and who now face less competition from startups. The EU Cookie Law, EU VAT regulation and now the EU GDPR are all examples of poorly-implemented laws that add complexity and unintended side-effects for businesses within the EU.
I will be first to admit that GDPR is full of holes and ambiguities and has never been tested in a court of law yet, but rather than (as the two quotes you pulled from his site) assume that GDPR has been set up to give the 'big boys' free reign and punish small operators, I'd like to think that GDPR actually puts a LOT more accountability on the larger players and actually will put smaller players on a semi-equal footing.
I really don't think that the EU will be spending the money and time (and open themselves to the PR disaster) of suing websites that might make $1000/mo for the full EUR20Million, do you?
I expect some early chilling cases that will scare the shit out of small operators. That's almost guaranteed to happen. I don't expect the EU to need to be aggressive in pursuing small operators (spending lots of money & time on it), a few demonstrative examples will do the job. They'll need to do that to make sure they're all in line. It's too great of a task to force compliance on millions of small businesses otherwise, they will have to make an example of some small businesses. If they don't, compliance by those millions of small businesses will erode over time.
And it's not as if you'll get fined €20 million if one email ended up in a spam box and you didn't remove someone's account in time... it's really blowing things out of proportion to mention that without further qualification. The big money is to threaten companies like Microsoft, not small businesses that don't even make a profit.
Your premise doesn't make sense. You're arguing against someone's subjective regard for risk. That's like telling someone that their love of skydiving is stupid because it's too risky. If the operator has a very low tolerance for risk - assume it's extraordinarily low for these illustrative purposes, as we're discussing a principle that applies regardless of scale - then that's down to their preferences. It does no good to argue against subjective preferences.
That's my theory as well.
It's just too bad that he drags GDPR through the mud with this as well, since there are indeed a bunch of people (just like anyone can, apparently be against net neutrality) who would prefer things to remain lawless. They'll point to this article as justification, after which the other party will have to go and read it thoroughly and attack its points, and win that sub-argument, before they're even back to square one with the original discussion.
Truth is, for most tech people, law is a huge extra expense -- of time, money and tons of risk.
GDPR threatens website owners with fines of 4% of turnover or €20 million (whichever is higher) if they do not jump through a number of ambiguously-defined hoops. The law, combined with parasitic no-win-no-fee legal firms, puts website owners at risk of vindictive reporting. Young websites and non-profits cannot afford legal teams. Therefore the risk posed by GDPR is unacceptably high.
Perversely, this new EU law hurts small and ethical startups, but helps reinforce the dominance of Facebook, Google and Twitter, who are able to prepare and defend themselves using established legal teams and cash reserves, and who now face less competition from startups. The EU Cookie Law, EU VAT regulation and now the EU GDPR are all examples of poorly-implemented laws that add complexity and unintended side-effects for businesses within the EU.
Can anyone in the EU actually comment on the content here? This seems completely out of proportion with everything I have heard about the GDPR.
Given the authors stance on data privacy and accessibility, I am somewhat glad that he is shutting the site down.
The figures cited above are correct, but the consensus from people I've spoken to is that the maximum fines would only be for the most serious breach. It's hard to imagine a small non-profit being fined €20 million. That said, people are taking it seriously.
I can't help wondering if the owner of Streetlend has just decided it's not worth maintaining at a loss anymore and decided to take a swipe at GDPR. I can't know that of course. However what seems fairly inevitable is that technical, commercial and legal changes will come along now and then and it takes real work to adapt. I don't know of any company/organisation that is motivated to keep running but didn't try to comply with GDPR.
https://www.borroclub.co.uk is managing (so far) to compile to GDPR.
GDPR compliance is catching up with your project's "ethical debt" in much the same way as a project sometimes has to deal with a "technical debt". If it's unimportant, it's of no concern. If you kept up with good practice, it's of no concern. It's only if it's important and you let the debt accumulate that it could potentially be a problem.
This is needlessly polarizing. I don't have any ethical issues with a service not letting me delete my account or download all my data. Sure, it's nice, but it's not an ethical issue if they don't. I also don't have issues with services processing and analyzing _their_ data (it's not my or our data) any way they choose without notifying me.
Tech has already and will continue to interact with laws/lawyers. At some point open source libraries will appear to streamline compliance. For now it sucks but ya gotta muddle through or call it a day.
GDPR requires restructuring of applications to keep data on a temporary basis with the consent of the users, to remove data after the fact, to selectively restore, and to allow users access to their own data. These are proactive steps required, and while applications written in the next six months will be built with those requirements in mind, it's still a fairly large burden for business-as-usual applications.
I don't want to trivialize compliance. Even ostensibly simple requirements are never quite that, and every second spent on them is time not spent on your product.
The GDPR requires mostly that you document what data is stored and how, and that you have a legitimate reason for doing it this way. Consent is not necessarily required.
> to selectively restore, and to allow users access to their own data.
So, you get a takedown/access notice, and then you take down/show that data. Compliance solved.
Or it could be the people running 100-user-or-less sites are trying to see if they can just leave their sites up, ignore the "oh yeah, well your web server has IP addresses in your LOGS doesn't it!? Well guess what, OUR logs show an EU IP address, so you know what the letter of the law let's us do? €20 million fine, you data slurping fiend!!" frivolous lawsuits in hopes of keeping their little side project which while (maybe) technically noncompliant, aren't actually using the data for those nefarious purposes, only DDoS and spam mitigations.
> the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union;
I mean this should really be:
> the offering of goods or services to such data subjects in the Union, irrespective of whether a payment of the data subject is required;
I mean why put that sub-clause in the middle of the sentence to which it relates? Seems bizarre to me.
I get the point about legal trolls,but how are the hoops ambigously defined?
- don't store data you don't need for your business' stated purpose
- get active consent before you do so
- be ready to delete data on command
- store the data with best principles (i.e., instead of having ID and other stuff connected, centralize identifiying information and protect,use pseudonyms otherwise)
IANAL, but this seems pretty sensible?
That said, I think the fear of no win, no fee legal firms is a little overblown. You can't get blood out of a turnip and if he's not making money there's no reason any law firm would be interested in suing him.
I'm honestly wondering what the law previously said regarding data protection. The Dutch WBP from 2001 already covers everything that he would have to do under GDPR given this website, so unless the UK has some very weird laws (or unless we're weird), nothing would change. Perhaps an extra tickbox on signing up that says "yeah yeah I'm really very aware that my data is shared with third parties".
Most likely, this is a good excuse to go "I refuse to read the long legalese [even if it's 95% the same as before] and I'm just going to quit this loss-turning website without the community turning sour on me because I have a good excuse".
Generally speaking, I think most sites will require some additional development work to update their UI and to store the data. If you have been compliant with the previous laws then it should be no problem. One wrinkle is that in the previous laws there was no way for your customer to find out if you were following the law or not (without suing you). With GDPR they have a right to both be notified what you plan to do and the right to request evidence that you are following that plan. There will be many companies that will have to alter their processes significantly to account for this.
In the businesses I'm working with, I'm finding the biggest problems with GDPR aren't with GDPR - they're because the business wasn't compliant with the UK's Data Protection Act (1998). So the pain is the scramble to catch up.
I think you could ask that question about all the other formalities you have to engage in as well if you run a business? Managing his taxes probably takes more time than making that kind of business GDPR compliant
>- get active consent before you do so
These are mutually exclusive. The GDPR specifically warns against soliciting consent for collection and processing activities that are actually needed, as consent is not considered meaningful when the alternative is to avoid doing business. Consent is only valid if you can "degrade gracefully" in its absence. (I'm not a lawyer).
Well, just in this thread, two people providing 4-point lists of _simple_ things that can be done to abide by the GDPR provide two different lists that they themselves are ambiguously defined.
So, perhaps it's not as _simple_ as you make it out to be.
Deletion of data from all external services that you use and internal services. If you have some processed data from internal data pipelines you will have to clear that as well. What about error reporting services? Internal logs? I think for data backups you can have it encrypted and that works as a good alternative but if you have to delete data from there it is not at all feasible.
- store the data with best principles (i.e., instead of having ID and other stuff connected, centralize identifiying information and protect,use pseudonyms otherwise)
Even if in the main data stores you store them in a well normalized way. It becomes a pain to do the same thing to do the same in data pipelines, sinks etc. If you are having a reporting DB it would make sense to denormalize data there.
As a Brit, he would most likely already have to comply with most of the stuff already. And he should know that most government bodies use dialogue instead of fines initially..
Disregarding the "hoops" -- shouldn't this 4% go entirely to the affected users? I thought this was meant to protect the users. Seems like a cash-grab by the government. Can someone make a good argument as to why the fines should be paid to a third party (the state) when this issue is between the service provider and the customers?
The only thing I can think of is that the state is the only entity which can enforce the new rights, meaning they get paid for violations of the rights. Still, if someone threatens the integrity and privacy of your data, shouldn't the damages be paid to you?
Much like class action lawsuits, the end user doesn't make much. The lawyers or the state, which go to great expense may recover their expenses, or they may not. The largepunitive fine is to prevent the suits from ever happening in the first place.
> [...]Can someone make a good argument as to
> why the fines should be paid to a third
> party (the state) when this issue is between
> the service provider and the customers?[...]
The same reason you pay speeding tickets to the
state instead of personally to each person living
on the street you sped on, or who could otherwise
have been directly affected by that specific
occurrence of speeding. Or the same reason health
inspection fines for restaurants in the US are
paid to the city or state, not everyone who's ever
visited the restaurant.There's no concept in the GDPR that the violation only exists between the site and the users whose privacy it violated, where are you getting that idea from?
Roads are usually state-owned property, whereas your personal information is your property, right? If Alice mishandles Bob's property, why is Charlie getting paid for it?
> There's no concept in the GDPR that the violation only exists between the site and the users whose privacy it violated
Why not? The site-customer relationship is the only relevant one here. What prevents a profitable, large-scale data mining company from simply accepting the Max(4%,$20m) = 4% tax for mishandling data?
A $20m dollar fine would surely deter smaller actors, but the 4% fine doesn't seem like a deterrent for large-scale data-mining operations, which can be incredibly lucrative. For example, if Facebook had the choice between not using the data and making $60b per year, versus using the data and making $90b - .04 x $30b, wouldn't they accept the tax and continue using the data? If this is the case, I don't see GDPR making a big difference if the highest-market-share companies can "get away" with paying the fee.
This would increase the gap of viable profit models between smaller and larger companies, at the sole benefit of the state, with little, if any, benefit for the victims (the users). Of course, I am assuming that there is no criminal penalty for noncompliance. The government might think: why impose a criminal penalty if the state can simply tax large corporations for the mountains of profit they are making off of insights from personal data?
> If Alice mishandles Bob's property,
> why is Charlie getting paid for it?
If Alice and Bob both join Fight Club and have a consensual fight and
one of them dies, even in the US the survivor will be charged by the state for
that.The reason is that certain violations aren't simply seen as person-to-person violations, but disturbances of the general order that have ripple effects on the rest of society.
European countries in general are more prone to seeing something like the violation of business law as being a crime against the state, not just a violation of the specific people who were victims in that specific instance.
It has upsides and downsides, but I think in general it's better than the US system. American companies tend to have to worry about compliance with regulators and the possibility of huge payouts from court cases filed by individuals. If you have a small company and screw something up (but not much more than other companies in general) you can go bankrupt mainly due to bad luck.
In Europe companies tend to mostly have to worry about just the regulators and the state, except in cases of gross negligence, which makes it easier to predict when you need to be compliant etc.
There's also the practical matter that the state has a lot more leverage against the likes of Facebook and can exercise collective bargaining. You can see how well this "your personal information is your property" idea is going in the US with the likes of Equifax, Facebook etc. In practice the little guy just has to eat the TOS of these services and doesn't have anything like a property right over his information.
As to your question of whether some companies will simply eat the 4% fine. We'll see, but that's a topic unrelated to who the fine is being paid to.
If some company like Facebook were to publicly flaunt the GDPR you can bet they'll find something else to charge them with. The GDPR isn't the only privacy regulation in effect, there's also various national regulations that could be brought to bear. The threat of the 4% fine is mainly intended as a big stick to bring companies into compliance.
I consider myself lucky that I'm in a state that doesn't make me collect tax in states I don't have nexus.
Europeans are required to use something like chargebee to deal with VAT in different countries. I don't mean to be rude, but if a service like chargebee didn't exist, you Europeans would be fucked.
I'm sure VAT is just the visible part of the iceberg. It's an awful situation for entrepreneurs.
Bare in mind that you probably use some sort of service to handle every time of payment, even if it’s a local sale (e.g. Stripe, VISA Pay/V PAY etc.). Additionally, selling goods in the US is just as complicated for an external business as it is into the EU - state, county and city sales taxes, as well as exemptions from US taxes laid out in international treaties have to be accounted for. The general advise if you want to sell internationally is ‘get an accountant’, because it’s actually quite a complicated subject (unsurprisingly).
The compliance tax burden for American companies varies by state. I'm lucky to live in one that isn't onerous.
Luck is a factor when starting a business, but regulatory capture is a bad kind of luck.
Sounds like a business opportunity right there.
And all in all, it really looks like a way to get out without having to admit some other failure.
The biggest change going to GDPR is clearer definitions of what a data controller is and data processors and new restrictions on "automated decision making".
The ability to view, delete and demand data be accurate has long been a requirement of meeting UK data protection laws and I'm sure many other countries too.
It seems that businesses just ignored the law until it came with fines worth worrying about. A bit like the VATMOSS changes where US businesses were worrying they would have to start dealing with EU VAT even though that was the case previously.
There is no incentive for lawyers to troll around trying to sue for breach of GDPR, because there's no money to be made by them.
Time will tell best, I guess.
Article 82, "Right to compensation and liability," begins with the text "Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered." https://gdpr-info.eu/art-82-gdpr/
Also, requiring the government to not just frame laws but provide this kind of information. The ico website[1] seems to be doing it for this particular law.
This might be less useful in boundary cases, where firms with legal resources play at the edge, but it can at least serve as a safe upper bound for a lot of regular activity. Lot of this information already exists in books, legal reviews, but this is important enough to be made conveniently available on an public website.
[1] https://ico.org.uk/for-organisations/guide-to-the-general-da...
I won't hold my breath that this will ever happen. For that reason (and many others) I expect that GDPR enforcement will be capricious and biased and used as a weapon against unpopular groups.
It's counter productive in that disabling or regularly clearing cookies to improve privacy can result in annoying popup messages every. single. time. a website is visited.
I am truly grateful to the developer or the firefox addon 'I don't care about cookies'...
That describes most of it
Should they just pretend they don't exist? The Europeans haven't interpreted this law or provided a clear history of enforcement either. That's the point of these discussions – they're uncertain about the consequences of the law!
But the interpretation should be seen in light of enforcement of current data protection regulations (as per ICO in the UK, and corresponding BDSGs in Germany, for example).
GDPR is not "starting from zero" but it's based on current legislation.
See for example: https://globalcompliancenews.com/data-privacy/data-protectio...
My fear is that patent-lawyer-style firms will start aggressively blackmailing companies for "settlements" or they will begin tons of GDPR-based violations aimed at your business.
It seems the root of the issue would be financing the changes.
In a way, looking further into the regulations to clear how to deal with ambiguous parts or even straight hire a lawyer to look at the details would be a simple move if the expense could be justified.
Could it be summed up as “unexpected but mandatory changes kill unprofitable business” ?
Which is kind of what GDPR wants to do for personal data: if you want to collect it from me, there are a minimum set of standards that you need to adhere to because it’s my data.
In particular if you already went though PCI DSS, it’s only a few additional things here and there.
The pci DSS has nothing in it like the gdpr; I'm not even sure why you would compare them.and it makes me think you know nothing about either.
While doing these changes, there will usualy be a rethinking of how user data is handled at its core. For instance I worked in the past on dissociating user account with it’s profile and private info, so we could get rid of personal info and only keep behaviors.
With GDPR you get similar leeway for keeping most of your data as long as you get rid of identifying info in a reasonable manner. If I’m not mistaken backups are also safe up to a point, but I don’t have the details at hand.
My main point was that if someone had the occasion to think thoroughly about user data policy and cleaning unwanted traces at leadt once in the past, GDPR was a lot easier than one might think at first.
Also, I think the reason why this site cannot cope with GDPR run deeper than being willing to add a 'delete account' and 'download my data' functionality to a loss making site.
On the screenshots, it shows a prominent section on the home page: “StreetLend with Facebook friends (and their friends, and people they endorse)”
This suggests they are using the Facebook login to harvest from the Facebook social graph.
Head down that particular road and you are in a privacy shit show - and after Cambridge Analytica and GDPR my guess is that Facebook is cutting of this supply of data - or setting hurdles that streetlend cannot hit.
A few people were sued by the ICO for non compliance with the DPA - but it didn't open the floodgates of civil litigation. To my mind (and I am in the processes of updating two small businesses to be compliant) it just sets good ethical standards and Google / FB etc are missing a trick in not just declaring this is the standard they will follow worldwide.
This explanation might aid those who're confused about why a community strengthening, environmentally positive, socially worthwhile website like Streetlend would shut down in response to this huge collection of laws that was sold to us as actually helping us.
If Streetlend were even remotely as you described, they would have easily made enough money to defend itself against the government - all in glorious free market fashion. All hail supply side Jesus! Oh wait, it's tiny operation making a pittance in revenue. Whoopsie!
Thankfully, this is the 21st century and Western society has long ago decided that it'd rather have "the government" destroy individuals with a system of courts to appeal to rather than let anyone do whatever they wanted. Thanks Obama.
The ability to run a failing business is also valuable in and of itself. Look at the businesses run by the McDonalds brothers before they opened McDonald's restaurant for example, which helped them gain the experience necessary to eventually create a successful business.
>>Thankfully, this is the 21st century and Western society has long ago decided that it'd rather have "the government" destroy individuals with a system of courts to appeal to rather than let anyone do whatever they wanted.
Ah yes the 21st century, where a growing proportion of young adults live at home, have given up on starting a family, and have a shrinking pool of industries in which they can afford to start a business or career, as a result of an increasing number of well-intentioned regulations.
Regulations like GDPR are hopelessly misguided attempts to centrally plan greed and abuse out of society. The complex bureaucratic rules attempt to anticipate every permutation of commercial interaction, and predetermine the correct parameters of action for each permutation.
It's absurdly reductionist and unworkable, and only results in more rent-seeking and less efficiency.
"Please note that we have no obligation to delete any of stories, favorites or comments listed in your profile or otherwise remove their association with your profile or username."
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
"The General Data Protection Regulation (GDPR) gives individuals the right to ask for their data to be deleted and organisations do have an obligation to do so..."
So no, it's not compliant.
Comments could be considered that…
It'd be nice if it was obvious tho whether they were or were not.
Something about legitimate interest: https://youtu.be/-stjktAu-7k?t=4563
Let me just point to one sentence: "Processing conducted due to "faulty" balance test (your interest vs. person fundamental human rights) may expose the controller (you) to highest level of fines". I wouldn't gamble here and go for local analytics (again piwik is simple to install and use) or require consent from the user.
ePrivacy is not here yet, GDPR is and I doubt the analytics will be excluded as it is tracking in its purest form and you can set up your own software, no need for 3rd party processor here. It would literally destroy the GDPR principles which I doubt ICOs will allow.
For my (user) perspective: I don't have problems giving consent to particular site if they don't give the data to any 3d party processor, from google, fb, amazon to various ad networks. Bottom line, the problem is not for various sites to have my PII, but I have huge problem with agregating those data by single entity and I will never give consent for that (read as: google analytics).
1. Y Combinator only funds US companies
2. American TLD with no EU country TLDs
3. English only
People's reaction to their data being scooped up by Cambridge Analytica just because a facebook friend did a survey proves the need. What CA did was probably legal, but in most people's minds should not have been legal.
Is there? What if people just accepted responsibility for carelessly handing out information to third parties? Certainly there is much more individuals can do to protect themselves before the government steps in and slaughters small business like the EU did.
> but in most people's minds should not have been legal
Do people think a company selling user data to another company should be illegal? Or are most people more concerned with the relation said company has with Russia, and their potential involvement in influencing the US election? I think it's the latter. And certainly there should be laws about data transactions involving the state's democratic security.
> What if people just accepted responsibility for carelessly handing out information to third parties?
Without being legally compelled to, few companies have been forthcoming about providing users with information about what they are disclosing and when. Consent is being given, but not informed consent.
It's not _their_ data. This is the part that drives me nuts. When you give something to facebook, it's no longer yours and you loose control of it. It's like this for _everything_. That nude you send your SO? It's out of your control. That nude your SO took of you? It's even less in your control.
If you don't have a service agreement with someone, it's not your data. It will never be your data. Stop pretending.
It's dangerous to let people think they control data they hand to other people. They don't. They never will. Why perpetuate the illusion?
If I put my money in the bank, that does not actually make it the bank’s money. They have the right to do things with it - invest it, loan it, but there is an agreement that it has not been perminantly given. That agreement is backed by consumer protection, insurance, etc. and the bank, no matter how much they would like to, can’t make me sign a EULA that makes my deposits theirs.
Which are mainly extensions of harassment law (again, not something you control, but a penalty after action).
> If I put my money in the bank, that does not actually make it the bank’s money.
You also have an agreement with the bank as such. If I just gave it to some guy on the corner (or PayPal) then, you know, whatever is just as possible.
I’m fine with punishing companies after they violate data protection/privacy laws.
> You also have an agreement with the bank as such
I’ve not read many bank agreements but I don’t believe they say anything like “the bank can’t take my money to the casino and put it all on black”. Yet if they do that they’ve broken the law.
1. Try
2. Do it
3. Keep Doing it> "but We Tried and then We Kept Trying"
Will literally get you 100% of the way there if done in good faith. Crypto-shred anything you acquire from an end user and you are good. Collect the bare minimum to offer the service you claim to be offering, and you are good. Alert the customer on how their data will be stored, used and fused and you are good.
Of all people, programmers should stop whining about how hard and oppressed their lives are. The EU is telling you to stop being a clueless *sshole. If you even attempt to stop being one, you are fine.
Disclaimer: we are a vendor that makes a SaaS offering for GDPR
Option 1: close it down through fear of something happening.
Option 2: close it down if the worst thing actually happens.
Either way if the small company is operating at a loss/ v small profit, it’s not going to harm you personally?
You get reported to an authority that will handle the process. The Americans think you can just sue people all the time. It not what it is like in Europe. The point of this legislation is to help users, not to penalise businesses.
I mean how many companies were prosecuted for the cookie law?
And then the authority will prosecute and fine you. You're screwed either way.
It is really not such a big deal.
If your breaches are deliberate and flagrant you may end up with a fine. But regulation in Europe really is light touch.
I think you can delete from BigQuery now, but even just a year ago you couldn't.
Don't know how to do RMA though, maybe for each purchase my site and the buyer both should have a receipt that just records the transaction but nothing else private, still not sure how to implement that though.
It's so unhelpful for small business owners.
You can market without having per-user data. People did it for millennia.
This is only for the worst, flagrant willing and knowing breaches. Small websites who made an effort to comply wouldn't ever get hit with this kind of fine.
On the practical front,how would a product like google docs that offers collaborative editing deal with "forget me"? If I edited someone else's document, would Google (or whoever) be obliged to contact the co-authors to request that edits be removed? ... or should they do that automatically? What's expected to happen to the version history of these documents?
Some of the worst private offenders in europe are actually public services like tax authorities who dug up tons of stolen data from banks, financial services, or who use google maps and facebook to find out who is flaunting their wealth. While not NSA-level, police authorities are catching up. Registries of all kinds with very private info have very lax access rules in EU countries outside the rich north.
Sure, some techies may feed their entitlement by going after some glaring cases of violations for a few months, but the case remains that, if privacy is a big issue, people are going to have to pay for it (i.e. they have pay a premium). Cryptography/decentralization remains another option.
Could we have some examples of the ambiguity and poor implementation?
Personally, I think there will be a number of court cases post-GDPR to clarify what precisely is "legitimate interest" and what is a breach of the regulations.
I really don't see how this is the case. A small website will be going after product market fit, then they can scale and do compliance. Not adhering to GDPR means your websites can always become compliant later.
To put it another way, Facebook and Google started in the US. Any founder in the EU might consider moving to the US first, getting product market fit before worrying about GDPR compliance, then get compliance once you know your product is good and you aren't just throwing that work away.
The only way to avoid the GDPR is to not hold personal identifying information on any EU citizens or EU residents.
No, you do not have to comply if you're outside of the EU's jurisdiction. They can only hit you if you've got business in the EU that they can directly touch. Facebook, Google, etc. are aggressively complying because they want to continue making money in the EU.
They'll have to overrule eg US or Chinese jurisdiction to force outside companies to comply with GDPR.
How exactly do they intend to force compliance upon the two global superpowers with $34 trillion in economic output? It's laughable. US Federal courts will bury any attempts by the EU to legislate US laws/regulations on these matters.
If I'm a US service/site, I do no business in the EU, and I store information from EU residents on my servers in the US, the EU can't force me to comply with GDPR. They have no means to force that compliance, and to overrule or dictate US domestic laws. The EU doesn't govern the world's laws, if they didn't already realize that they're about to discover it.
As a counter example. A US-based service I'm building now, will have zero business dealings with the EU, although it may store EU resident data (people that sign up that are from the EU). I have no concern about complying any time soon. I may choose to never comply, as I doubt I'll be drawing revenue from the EU. It's about the last thing on my list of things to worry about (GDPR, not user privacy in general).
[1]: https://ec.europa.eu/info/law/law-topic/data-protection/data...
> The European Commission has so far recognised Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, Uruguay and the US (limited to the Privacy Shield framework) as providing adequate protection.
[2]: https://ec.europa.eu/info/law/law-topic/data-protection/data...
I agree unless you have business in EU it's not really worth worrying about it... And even with business in EU, depending on how much of a hassle it would be to overhaul everything, an underconsidered option in all the panicked headless running about is just to have code branches that don't collect any data if the context is EU. Overhaul only what's needed for business, but no need to run around fixing all the other data vacuuming / data laziness going on just yet.
(It's possible decent companies will not limit GDPR provisions though.)
2. The GDPR is already law, it just had a 2 year delay before it fully came in to force
I have semi anonymized data that I can now either make fully anonymous or link it directly to a user.
Worst of all is however that the complexity of my app doubles easily when I Actually follow all the rules.
GDPR hasn't effect https://www.borroclub.co.uk/ So seems like it is possible to have a sharing website and not violate GDPR
Judging by their post and the comments here, this is more of a problem with the US/UK legal system not with the EU regulation.
Ah, that's exactly it. Decades worth of software irrevocably centred around tracking and analytics.
It would be glorious to see it all thrown in the fire. We can write software and protocols that don't spy on people. Let's get back to that.
I firmly believe that companies need to protect their data better as the consequences of loss aren't shouldered by them, which the gdpr says nothing about.
I also firmly believe that it's their data. When I send data to another machine, I was never under the impression that said information was mine. I was never under the impression that anything I have on Facebook was ever or will ever be private. I consider order information vital information _of the company_. When I choose to load thea Google analytics tracker, I have no notion that I own that tracking information.
Splitting basic infrastructure like backups and logs by customer or introducing a whole system of flimsy cryptography to support that is no where near reasonable and well beyond common decency.
Explaining all uses of data and why decisions are made isn't common decency. Again, I sent you my data, it is now the server's/company's. I expect them to do what they will with it.
The gdpr is well intentioned, but ultimately nothing more than toxic smoke and carnavel mirrors. It is an underspecified mess and burden creating the notion that you can renege on data you send someone else.
So long as they clearly allow opt in to what data is being processed, and why, and a way to delete it, you are mostly ok.
As the site might need to deal with issues of fraud, you are allowed a little more leeway in storing personal data.
Yeah man, that's why we have the safest cars and airplanes in history, because of the free market, not because of regulations. I'm sure that United Airlines, who literally dragged a passenger from their airplane, would have invested a ton in passenger safety if not forced by regulators.
Sarcasm aside, laws do work. There's a reason the most developed countries in the world have a very strong legal system. You give up a bit of freedom (which is a bit of an obsession for Americans) in exchange for a lot of protection from various nasty things people do to each other. As a result you sleep better and you get the side benefit of a special brand of freedom: freedom from fear from your fellow human beings, from their arbitrary whims (to a reasonable degree). Unregulated societies look like Somalia. Trust me, you wouldn't like that brand of freedom ;)
He's running an unprofitable business (by his own admission), and likely is running it as some sort of sole proprietorship and doesn't want to take the risk on himself.
The solution is to create a company so that the company can shoulder most of the risk so the company goes bankrupt in the event he finds himself unwilling to comply with regulatory requests.
I'm guessing he just doesn't want to dump any more money into a failing project, which is his decision to make.
Is this a failure of the GDPR though, or a success?
Personally I think fly-by-night websites should be the last people responsible for handling personal data. If they're unwilling to attempt to comply with regulations, then perhaps the internet is a better place without these sites.
Let's look at an alternate universe for a moment, where online shopping developed with very barebones regulations, PCI-DSS isn't a thing and fraud is far more rampant. Now the EU introduces new regulations much like PCI-DSS with heavy fines attached to it.
Suddenly you would have every small business coming out of the woodwork, claiming PCI compliance is a huge hassle, the fines are unreasonable, etc. Yeah, PCI compliance is a hassle (which is why we have companies such as Stripe taking care of it for you). But to protect and empower the users, it's needed. This isn't about your business, it's about your users and how they can, today thanks to PCI-DSS, generally trust that their credit card is safe to enter online (which is a net good for any industry that needs online payments).
But that universe is crazy because, who wouldn't treat credit card numbers as extremely sensitive data? Well, many companies who today aren't actually PCI-DSS compliant. Sometimes devs just don't know why, when or even how to encrypt the data and nobody audits that until there's a breach.
So my opinion is this is a success of GDPR. Clearly nobody in this comment section thinks the person in question would really have had a hard time complying with it, and probably wanted to shut down anyway. Either its users are better off because the service is a data vampire that doesn't care about compliance, or it's a no-op because it would have shut down either way. Make room for competition that does care, I'm all for that.
That would be amazing! Then we'd actually have to adopt a push-based or one-time-use transaction model, rather than living under the fantasy (disproven on a daily basis) that merchants should be in the business of keeping secrets, or are even capable of it. It's hard for me to take anything someone says seriously after they express admiration for the credit card number security model.
Payment card data is secret information, that's a given of the industry. If you disagree with that, I welcome you to share your credit cards in a reply here. Is it a design flaw? Yeah, you could say that; there's much better models and PSD2 will fix many things (not all) at the core of your complaints.
In the mean time, having to treat credit card numbers as highly sensitive is a fact of life, and when you're trying to protect users, you have to be pragmatic, you can't live in an ideal world with theoretical technology; you have to regulate what's there.
The GDPR's definition of PII is broad and contains many things which aren't secrets. I can tell you my full name, it's easy to figure it out from my profile, that's not a secret but it's still PII and GDPR asks that you treat it as such. Same for usernames, which are most often publicly visible on websites.
GDPR, more than dictating what you should encrypt, gives the users a set of rights over a class of data they share with companies in order to give (european) users more trust and comfort when choosing whether to share data with those companies. Things like "I should be able to know what a company has on me, and I should be able to download it and delete it".
I can't tell you the number of websites I've seen that don't let you delete accounts properly. That don't let you edit your real name (even if you get married or you legally change it!). That don't allow you any insight into where your email address ends up after you sign up with it. This is the problem that GDPR is trying to solve.
It's a fact of life because the payment card industry found a legal way to externalize the risk of its idiotic architecture onto others. The networks are as motivated as can be to continue having transactions to intermediate, and had the technology for what I describe 20+ years ago. Smart cards are a 1990s technology. (Magstripes are a 1960s technology). They continue to drag their feet on the migration because we've made it cheaper to implement "security" through the legal system. Fraud losses are low enough for the industry to prefer the status quo, but high enough that credit card fraud is still a fact of life, because we have allowed it to create liability around data security.
So? Why should you be able to delete an account?
> That don't let you edit your real name (even if you get married or you legally change it!).
This seems like an issue for the company and one they should fix for their own good, not yours.
> That don't allow you any insight into where your email address ends up after you sign up with it.
I also don't have control over who my friends give my email or phone number out to, or if they sign up for facebook and facebook slurps that data (even if facebook becomes 100% truly gdpr compliant which I doubt they will even if they claim it). Why should I be able to control what other people do with something I gave them? If they breach my trust, maybe I should look elsewhere.
This is an obtuse, bordering on malicious misreading of the post. They're not unwilling to implement the necessary features. They're unwilling to shoulder the risk.
> Personally I think fly-by-night websites should be the last people responsible for handling personal data. If they're unwilling to attempt to comply with regulations, then perhaps the internet is a better place without these sites.
This isn't a data broker, a credit reporting agency, someone with a giant sensor fleet, etc. It's extremely straightforward to not share data with a "fly-by-night" website like this.
Yeah, it's extremely easy to not share your data with them.. if you know they don't care about protecting it.. But what about all of the other people on the internet that don't know this guy doesn't care about your privacy?
Convincing businesses to take your personal data seriously is the whole point, and you shouldn't get a free pass just because you only handle people's personal data in your spare time.
Because people voluntarily provide it to them.
> But what about all of the other people on the internet that don't know this guy doesn't care about your privacy?
Governments confront problems with this general shape all the time... the result is usually labeling requirements. Sure, this guy should not be allowed to claim he has a crack team of elite cybersecurity engineers when he doesn't. Regardless, no one is asking him keep secrets for them. It's a niche Craigslist.
>Because it's a small operation?
You're actively campaigning to degrade privacy (and also user freedom, competition, and choice) to a much greater degree by displacing these activities onto large, centralized platforms. Especially those which are monetizing your data to a high enough degree that it's worthwhile to staff a compliance team for the privilege of continuing to do so.
Voluntary or not, there are some rights that you cannot give up to someone else. In Europe, one of those rights is control over your own personal information.
There's also the issue of information symmetry. Just because I voluntarily bought your product doesn't mean that you should be 100% free from any liability that it may cause.
If that were true, you would not be able to post this comment (the most highly sensitive category of personal data, political views) in a public forum.
But if it's all the same, would you mind sharing your credit card numbers, SSN, and date of birth? I won't leak it, pinky swear.
The GDPR concerns all information related to people. It doesn't treat PII (i.e. identifiers) separately.
Which is a dangerous illusion. You don't control anything you hand over to someone else.
You do have control, actually. You and the bank have an agreement as such.
This is also where GDPR is at. Without it, in theory, you have a shrinkwrap tl;dr agreeement with the service, but in practice, they can do whatever they want with your data, with no repercussions.
See: Facebook and CA. Facebook misused my data (Because my friends opted in to sharing it), CA misused my data (Because they weren't even supposed to be given access to it), and the outcome? Nothing of consequence.
GDPR does three things:
1. It makes those repercussions have teeth.
2. It makes sure that you give informed consent to use of your data. (Unsurprisingly, similar laws exist for banks!)
3. It clarifies what has to happen when you stop being a user of a service. (Prior to it, de-facto, your data would be opted into whatever changes of the data usage policy the service made - regardless of whether or not you still had an active account, whether you agreed with the ToS, etc. If you deleted your Facebook account, you had zero leverage of how your data would be used.)
Even at a bank, if you open a joint account (enable sharing) and the other person absconds with the contents, you’re out of luck.
I think your reading of the comment you're replying to is itself obtuse, bordering on malicious. They clearly understood that the core issue with GDPR for the OP is risk, and suggested a reasonable solution to address it:
> The solution is to create a company so that the company can shoulder most of the risk
Further:
> It's extremely straightforward to not share data with a "fly-by-night" website like this.
Not if you're using the site. The €20 million fine OP is worried about is only triggered in case of an actual leak of personal data. If you're seriously worried that you might end up leaking personal data, maybe you shouldn't be storing it to start with?
The author is clear that they are concerned with having to defend themselves in court.
The fine is the bait that draws the true threat.
The fines are imposed by the government; in the UK that means the ICO. They cannot be levied as the result of a lawsuit brought by private parties. The ICO also has discretion when levying fines, and they've stressed repeatedly they will not be reaching for maximum penalties.
GDPR offers the prospect of big fines if you screw up badly enough. It also is likely to lead to a lot of lawsuits. But there are totally separate issues, and cannot be conflated as you are doing.
OP might get sued. And he might get fined for €20 million (although realistically...no, of course not). But he won't get sued for €20 million.
> The fine is the bait that draws the true threat.
That's simply incorrect. You're looking at a normal civil case, with normal damages.
The risk remains.
We started out talking about the risk of an opportunistic civil suit filed by a law firm working on a contingency basis seeking a €2m payout; now that we've established that isn't possible, we're talking about the risk of an actual fine for breaking an actual law levied by an actual regulator (who is on record as saying that large fines would be a weapon of last resort in the most extreme cases).
So other than the risk being much lower, the likely penalties much lower, the chance of an unfair outcome being much lower, and the incentives and mechanisms being completely different...
...sure, the risk remains.
The question is more on the side of, is the cost worth it? A good and much longer-running example of this is in the medical industry. There are massive regulations around development of new drugs and treatments. Massive regulations around experimentation on humans. This stifles innovation and prevents potentially life-changing drugs from making it to the market faster, or sometimes ever. It also prevents a lot of other things, such as crackpots from entering the mass market and selling poison as an anti-aging drug.
Is it worth it? There's still debate about this today, especially when promising cancer treatments are taking years/decades to reach the market (=> how many lives are lost during that time? What's the tradeoff for someone who is terminally ill anyway? etc). I'm not nearly informed enough to pick a side in that debate, but it goes to show it's not necessarily a bad thing for "fly by night websites" to be heavily impacted by regulations like these.
Part of my concern is that in order for those regulation-solving businesses to have a working business model, they can't just support every stack under the Sun. Instead, you'll get something like GDPR for Azure™ — which means that it'll be that much more expensive for a startup using an outside-the-box stack to get started.
That's the point of a lot of regulation, really: to insulate firms which already exist from disruption.
The question, then, is whether a small "business" that's closer to a charity or a resume padder needs to be regulated in the same way as Facebook when it doesn't collect data on the same scale. I don't think this applies to medical startups, where human lives are at the same risk regardless of how many customers are using the tech.
The online ad-tech industry is pretty fragmented [1] and widespread data-sharing would certainly be a problem even without the larger companies. It's not like Google or Facebook invented it; this goes back to nearly the beginning of the web. And the offline component goes back even further.
[1] http://static.adweek.com/adweek.com-prod/wp-content/uploads/...
Related to GDPR i can definitely see a similar situation developing where large entrenched player leverage it to gain an unfair competitive advantage against startups who could threaten then in their market, using the same FUD tactics. This is a silent killer which will wipe out grass roots innovation in Europe.
I also think it’s going to be pretty harmful to startups, and that we’ll see more businesses just trying to avoid Europe at all costs. Regulation like this can either be easy to comply with, or they can be effective, you can’t really have both at the same time. Even then it just boils down to the old tension between security and compliance. I work with a lot of PCI orgs, all of them have AoCs, very few of them are actually what I would view as compliant. They all managed to satisfy the box checkers, but the DSS doesn’t do much to protect the consumers in most situations. The reality is that the DSS is just a mechanism of shifting accountability around, which is what I see the GDPR as. A bunch of politicians using poorly written regulations to shift accountability on to the market.
God forbid we try and apply some of those ethics to IT. (Europe is big on privacy, again a somewhat hard-learned lesson.)
To compare PII to medicine is trying to invoke an emotional reaction, not a reasoned one. I don’t think this regulation is well designed at all, I don’t even think it’s going to achieve half of what it’s trying to do. But it will achieve increases compliance costs to pretty much every company, costs that will put startups at a serious disadvantage to established companies. Europe thinks they’ll have some protection by claiming every company in the world must comply, but only time will tell how that will work out for them.
Second, Europeans take privacy serious, and it's a right for us, similar to free speech in America. Also, while not as bad as some medical risks, identity theft is not fun. But, yeah, the risks are different, and the GDPR is pretty mild compared to medical laws, no? I mean in Europe, you can't advertise prescription drugs.
Third, Europe is not claiming every company in the world must comply.
But if you're mad at governments overreaching, maybe you could sort out the requirements FATCA/US tax law puts on foreign banks, or the US attempting to extradite "cyber criminals" before you get to the GDPR?
In any case, none of that responds to any of the points I made. The EU does think this regulation applies to every company in the world (unless you can somehow prove you don’t handle any EU data subjects data - which almost no company could do). One of the reasons being that they don’t want to only hamstring European company’s with it, as that would be a very poor strategic move for their markets. How enforceable this ends up being is entirely unknown at this point, and you can bet there’ll be a lot of legal challenges ahead regarding this.
I would imagine it's incredibly easy for many US companies, like e.g. a restaurant or a tire-repair shop to prove they don't explicitly go after EU subjects.
Since I was elaborating on how the EU and EU nationals feel like the GDPR is appropriate in addressing the risk of privacy violations - which part of that did you feel like didn't address your comment of "Except that approach ignores the nature of risk"?
This does completely ignore the nature of risk, because it does not consider impact at all, which traditionally accounts for 50% of total magnitude. A SaaS company with 50 customers has to comply with exactly the same set of regulations as Google does, and faces €20,000,000 fines, regardless of the fact that the small company poses a quantifiably smaller risk to PII. There’s also an argument to be made that the small company is less likely to become the target of a sophisticated attack, as an adversary is much less likely to invest huge amounts of effort into breaching a small set of PII.
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.
So it's simply not true that "you are in scope for it, regardless of whether you intentionally solicit EU customers or not." I could continue, but I suggest you actually read it if you're going to argue about it.
So spare me with all this "risk" bollocks. You're just another person willfully misunderstanding our laws, and spreading FUD to try and impose your culture and your rules on our society.
[0] http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...
The GDPR just made that gift more expensive. If he's not doing anything deliberately shady, then the probability that he'll get fined is small; but a small probability times 20M EUR is still a big number.
Maybe I don't understand the GDPR well enough, but the statutory fines seem insane to me. Why do you think 20M EUR is the right number here? Or am I missing details of the law (the law, not how you expect it will be enforced) that mean his actual maximum liability is smaller? Do you just have extraordinary confidence in the regulators to "do the right thing", and thus no qualms about giving them the legal authority to ruin his life?
Perhaps it was unintended to increase the potential burden of monetary cost to running services that were created and provided as hobbies or otherwise as a goodwill gesture to others. Or maybe the regulators didn't care to consider the impact on such services. Or maybe ...
Regardless, thanks to regulators and data/service silos the web we once new or dreamed of is fading from reality. With just the silos to contend with such services could hitherto continue to exist with little concern for the actions of the behemoths; but now such an existence is threatened by regulatory concerns which blanket all regardless of their role and activity.
Perhaps the correct action is to blackhole .EU?
A defensive piece you've made completely misunderstands how a business works in terms of the decisions made regarding risk, especially to an individual who lacks bandwidth/resources.
According to your post, you only expect well endowed individuals/large businesses to be compliant, which is precisely the problem.
I fully support protection against physical locations and personal information (name, address, etc), but to include email and IP address seems a little excessive.
It's not a perfect solution, but I'm not sure there is one.
Single member LLCs allow piercing of corporate veil pretty easily.
If a site makes it very clear EU citizens are not welcome on the service and will be banned on site, can they really be held liable for any EU citizens who get in anyway through proxies?
Our company has stated it has no plans to comply with GDPR and if faced with litigation it will simply be ignored unless the United States government gets involved. Complying is simply something we can’t afford to do right now, especially for a market that makes us a lot less revenue.
GDPR is a great example of the kinds of disasters that happen when nations try to force the entire planet to follow their unilateral actions.
If a tribunal gets asked to delete the personal data of the accused, they will keep the data.
There is a principle of public interest and public obligations to keep data.
What part do you think that is a disaster?
uh... this post is about a guy losing his business because of the GDPR. What part of that isn't a disaster?
>If you are a bank and a client asks you to delete their data. The bank will still keep it for the tax agencies.
> If a tribunal gets asked to delete the personal data of the accused, they will keep the data.
> There is a principle of public interest and public obligations to keep data.
In other words, GDPR has no teeth outside of Europe.
In other words, GDPR has no teeth outside of Europe.
Your example "my employer will have to delete records of firing me!" is exactly how the GDPR works.
There are exceptions -e .g. if the firing is now leading to a court case, but they are less than you think.
In an ironic twist, after deleting the data subject's personal information, you must be left with nothing that identifies them, so you don't even know that they have requested this in the past - only that someone exercised their right to erasure (not who).
The right to erasure does not apply if processing is necessary for one of the following reasons:
to exercise the right of freedom of expression and information;
to comply with a legal obligation;
for the performance of a task carried out in the public interest or in the exercise of official authority;
for archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing;
or for the establishment, exercise or defence of legal claims.
Article 17.1 The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; https://gdpr-info.eu/art-17-gdpr/
If you read further down the page, you come to the section you are quoting, 17.3, which says that the above right from 17.1 does not apply even if one of the conditions in 17.1 is met. However the scenario we are talking about is one where none of those conditions were met in the first place, so we never had to look at 17.3.
You can argue that 17.1.b/c would require an employer to remove any demographic/political data it had stored on you, but absolutely not that it requires the employer to remove the record of your existence at the company.
17.1.b appears to be the trump card held by the data subject. They can withdraw consent at any time and request erasure.
Once they do, the data controller can then use any of the exceptions in 17.3 to deny them. However none of these is "because I want to keep records of all firings".
My further understanding is that you certainly could keep a record that someone was fired, just not a record that included any personal information that could identify who that was.
i.e. pseudonymization..
(edit - and I think you could keep the information about their race/etc if it was properly pseudonymized, but I haven't tried working that out so I'm not sure).
The GDPR applies to trying to do business in europe. Seems simple enough.
meaning you can be doing business with EU residents as a US only company.
I'm not quite sure how they intend to enforce the GDPR on foriegn companies, but they are making that claim.
This doesn't sound crazy to me.
If I'm in europe and I sell to an american, I have to adhere to certain US laws just the same. I have to fill in a W8-BEN form or whatnot.
I can elect not to, but next time I'm in the US, things might get awkward at customs. Also, my customers might be fined or more or less 'ordered' not to do business with me. That's within the US's right.
That's just how it works. Everywhere. For all countries.
GDPR (EU Law) requires companies to delete private data upon request.
SOX (US Law) requires companies do not delete private data, in case the government wants to investigate those companies later on.
SOX has existed since 2002. Did the EU lawmakers even consider this when crafting GDPR? I'm betting not, considering the damage they've done to the WHOIS system as well.
This kind of fallout is the result of poor planning and pushing incomplete legislation for political purposes and I think all of us realize that, so let's not pretend otherwise.
That is literally a disaster. I wonder if this kind of thing is why the EU is crumbling.
(Shrug) It's a public response to abuses by private actors. It's a great example of the kinds of disasters that happen when the user is the product and not the customer.
I disagree, I think it's a political move and won't have the kind of positive impact that we want it to.
GDPR, as it is written, should put Facebook and Google out of business. Invading people's privacy is a huge part of their revenue stream. I'm all in favor of protecting privacy of individuals but I'm cynical that we'll see any real progress as a result of this and the negative consequences are real, and possibly more significant than any positive effects. Time will tell.
- "[GDPR] creates uncertainty and risk" -- which?
- "fines of 4% of turnover or €20 million (whichever is higher)" -- as if a small infraction is going to get the maximum punishment. He can't be serious here.
- "ambiguously-defined hoops" -- which requirements are ambiguous?
- "parasitic no-win-no-fee legal firms, puts website owners at risk of vindictive reporting" -- if you ever needed one of those companies (I did unfortunately), you'd know that someone always ends up paying the lawyers. Either the sued company or the client. It's definitely not risk-free for the client.
- "this new EU law hurts small and ethical startups" -- what clause of GDPR would ethical startups run afoul of anyway? It's aimed at unethical ones. And as for "small", then you can't get a big fine anyway right? At least, unless you intentionally cause big damages, I don't see how a small firm like this could unintentionally cause such big damages that large fines are in order.
So it's not answered. And I am still wondering what part of GDPR he doesn't already comply with in the website's current form, as the Dutch "WBP" from 2001 required 95% the same things. I assume the UK generally has somewhat similar laws.
Another potential violation would be asking a users age(like asking their birthday), but not needing their age for the operation of the service.
It is currently unclear how rigorously GDPR will be enforced. In the extreme case of rigorous enforcement nearly all current server/frameworks would cause violations by default and would need to be overhauled.
There are a bunch of other examples in the comments that are likely violations for the site as well. It is unclear how many of these apply since it is unclear how the GDPR will be enforced.
In theory, in the US this could be driven by COPPA, but I havn't seen a birthday asked for that reason in a long time. It also wouldn't be a reason to store it, only to ask and process ephemerally. I believe it's also common in the US for alcohol-related websites to ask age, although that could be misguided, it is common. Again, not a reason to store, but to ask.
Storing the value, rather than ephemerally processing it, is a matter of convenience so you do not have to ask your authenticated user to re-input their age/birthday/<are you an adult> all of the time.
That said it seems unlikely that a regulator would come down hard on a data processor that stored a date vs storing a boolean value.
Basically, in good faith, everyone is happy: website owners take measures to protect their users' data, and ask for consent. But 1 unsatisfied user, or heck a slimy competitor, can bring you down (I assume €20 million fine is business-killing for most startups).
The key is "targeted". If you're targeted, since it's ambiguous, your chance of losing is higher.
On the brighter side: Some people make extra income! /snark
Who will likely do nothing based off a single report.
You can't have it both ways. Either you want to have EU residents as customers, or you don't want to deal with EU laws.
But damn if they don't destroy a few small businesses to show that the government is on the case.