It’s about ensuring that companies only store and process privacy-sensitive information about people which they are given consent to store and only used for the purposes the consent was given.
There is nothing privacy related wrt the author in a public article published worldwide for everyone to read. Clearly outside the domain of GDPR.
It’s not hard people, just common sense. Just treating user-data with respect. Let’s not fool ourselves into thinking it’s harder than it actually is.
Just like H&S and the Data Protection act are abused today.
Who exits next?
[1] http://www2.sims.berkeley.edu/research/conferences/aps/remov...
There's no scenario where they can respond to the vast scale of GDPR violations that their archive likely represents, when it comes to manually removing content. There are only three possibilities: avoid the EU as much as possible, dump the archives and start over with an entirely different approach, or shut down. Besides that, these laws are going to get a lot more strict and difficult to comply with, not less strict, over time. This is merely the beginning of aggressive regulation of the Internet. Regulation of the Internet will only move one direction from here, in the direction of increasing burden and ever greater regulation. It's hard to imagine Archive.org's archives surviving what's coming.
"GDPR violations". What's that, exactly? As far as I know, you only have to remove personal data upon request, no preemptively. So I don't see how they are "violations".
Will a lot of people make these requests? Possibly, but where's the evidence of that? People have been able to use copyright takedown requests (e.g. under the DMCA) forever, yet the Archive is still around.
[0]https://ico.org.uk/media/for-organisations/documents/1475/de... Pages 4-6
I'm not sure where this idea that nothing could be forced off the web before the GDPR came from.
Comments with usernames. Comments with ip addresses (sometimes old comment systems would allow you to comment without registering but they'd show all or part of your ip address). Comments with personal information in the messages. Comments with email addresses. Blog posts with all sorts of personal details from the author. Personal user account pages, such as the kind you see on sites like Ask.fm or similar, with vast amounts of user information and personal details that can't be deleted. And on it goes. Archive.org is storing all of that and does not allow it to be deleted. Further, it would be nearly impossible to figure out what content is compliant and what is not within the archives. It's a giant GDPR violation system. Their only sane bet is to stay way from the EU jurisdiction wise as much as possible, or shut down.
Read the law before posting wildly misleading comments like this.
If you explicitly make something public, you can’t later come and claim that this information is actually crucial to your privacy. If so, you yourself was the one who violated that privacy, not the company later archiving/caching/processing your public article.
GDPR is all about decency and common sense wrt. user data and privacy.
No need to spread FUD about something that simple. SV proved tech companies can’t be trusted to act ethically, so here comes the regulation. Deal.
The EU cannot enforce its law on entities that are entirely US based. It can only enforce it on non-EU sites if that site has some sort of business that’s within the EU (like offices or employees).
See also changes to "safe harbour".
We are merging with our creations, and will laugh at this "AI" thing when we realize it's us. The WOGPC is really a struggle for self.
When the first purely US based company is successfully fined or shut down by the EU I’ll believe in their ability to enforce GDPR.
Enforcement of national laws is very much a thing across borders, so private businesses outside the EU are right to be apprehensive about what is going to happen as GDPR enforcement ramps up.
[1] https://arstechnica.com/tech-policy/2018/04/france-seizes-fr...
According to [1] the law applies to:
1.) a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or
2.) a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU.
The internet archive doesn't offer goods or services in the EU (if you want to know how that's defined you have to read the actual law I'm afraid) and they're certainly not "monitoring the behaviour of individuals in the EU".
[1]: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
It's the only country in the EU that does not require it's language in translations because even in Ireland nearly no one speaks it.
Why would the owner of the copyright make a complaint to the data protection authorities of the EU who might choose to do nothing when they could directly file a copyright infringement case? I suppose you could add insult to injury, but the data protection agency is likely to rule that the issue is one of copyright infringement.
It's the equivalent of it being technically illegal to take a photo of the Eiffel tower at night, because the light show is a copyrighted artistic display.
free speech is the right to speak about any topic without the gov't attempting to punish or censor you.
Free speech isn't the right to speak at any (private) forum, nor is it about having the right to be heard.
Yes, if a private forum chooses to not let you speak, you can't force them to accept you. But if they DO choose to let you speak, then you do have that right.
Also, this IS about the government attempting to censor people.
It is the Internet Archives freaking website, that they own!
There is plenty of nuance to copyright, such as public forums, public domain, fair use, etc. You have those defenses available to you. However, a person can bring a civil action against you anytime you make a copy of their protected work. The case may or may not be meritorious but already defending against a lawsuit is a penalty. Archival facilities are already exposed to this risk and they actively lobby for protecting their activities as fair use to varying degrees of success.
A person cannot bring civil action against you under the GDPR. They may make a complaint to the data protection authorities who may bring action against you if your use of the data is unlawful. Therefore, there is no way to force a person to have to even face a trial under GDPR. If your use of the data is unlawful, you certainly have no license, so you are not protected less under the GDPR than under copyright law. If your copy counts as fair use, then it will count as being lawful under Article 6.1 (e) and no action can occur under the GDPR.
They already take down pages on request and retro-actively apply robots.txt rules so that solves "right to be forgotten" or other circumstances where PII is present and shouldn't be.
They have sufficiently defensible reason to keep and present the archived information otherwise.
Their key problem will remain copyright and publishing rights arguments not matters of personal data, at least not more so than currently.
(caveat: while I have an understanding of the regulation due to it very much having an effect on our clients and to a lesser extent on us directly, I am not a lawyer by any definition so don't take my interpretation as gospel in any way)
The problem is that GDPR is a stupid legislation written by incompetent people that doesn't understand the subject and imposed with no possibility of choice on member states, like all the regulations from the EU (cookie banner law, for example).
And of course GDPR doesn't impact to much the companies that they aim to fight, like Facebook, Google, etc, they have teams of layers payed millions with the sole purpose to find ways to circumvent these regulations, they will just update the terms of services and done, the ones that will be more affected are small companies, startups, personal no project side projects, people that doesn't have money to spend in a layer for a project that doesn't make him any revenue.
I think that in Europe it's not more possible to do anything, if you have a good and innovative idea and you want to realize it, better take a flight to the US...
The cookie law is a problem because lazy web developers did not implement it right, probably you complain about don't spam me law because it adds a bit of extra work for adding the unsubscribe link and implement the requierements.
The laws are done for the good of the society and not for helping a minority to implement some move fast break things, pivot and try again.
If you look into it I think parent is most likely correct with his predictions since they are easily verifiable i.e. big coorps do have massive teams and monetary funds to deal with this legislation, startups and one-man shops do not. This is completely ignoring the deontological question of what should be the case, where I think most would be in agreement.
That applies to literally every piece of legislation. Yet we don't decide that small restaurants should be exempt from food hygiene laws, or that small construction teams should be exempt from health and safety laws.
Being careless with personal data has harmful consequences.
Being careless with food safety has harmful consequences.
This is why these things are related.
That’s not right, is it?
Didn’t that Nixon aide admit the drug war was a ruse?[1]
1. https://www.vice.com/en_au/article/xd7jkn/a-former-nixon-aid...
But I see a lot of anti EU sentiments here on HN, anything EU does is painted as anti american or anti startups when from inside EU we see it as for the people/society
No we don't. Some of us do and some of us do not. You are self-admittedly in the former group, I am not.
Also, just because something cost big companies money on one front does not mean it doesn't increase the monopolistic power of said companies and even increase revenues on another. Let me use your own example as a hypothesis we will be able to observationally falsify or not in the coming years. By eliminating roaming charges many smaller companies in the space will have to compensate for the loss of funds and will therefore either have to reduce their current plans, drop service offerings outside of the current country, or eventually collapse entirely. Regardless of the outcome, the total market competition has decreased and ultimately the mega corporations stand to win through decreased overall competition in the space. Additionally, due to lack of monetary incentives, I would expect the rate of innovation in large-scale roaming technology and infrastructure to decrease compared to countries which do not have such legislation.
Socio-economical systems are complex and nonlinear in nature, unfortunately, we i.e. humans have not evolved to think well about nonlinearities neither have we built ourselves sufficient tooling to augment our prediction capabilities for such systems. IMHO, this is the well-spring for the difference between intentions and outcomes in regulatory policy.
Your point is that we should not have made the security belt mandatory in cars because there could be a side effect somewhere like a person won't be able to evacuate in time, the idea is to calculate the benefits and the drawbacks and if benefits are much larger then we make the law and update it later.
I am sorry if a small telecom company can't adapt and compete without the roaming charges but we should not pay billions to the big companies so this small company also survives, we can make laws to help small companies like preventing abuses from big companies
If it's the same as the cookie law or spam rules, they'll come in and say "we've had a complaint, you're doing this wrong, fix it". Then if you don't fix it, they'll fine you.
Not only that, but many of the regulatory enforcers responsible for this in the EU are not particularly well funded and why would they spend the limited resources they have investigating one man bands?
In the USA it caused massive increase in organized crime and corruption - the effects of which are still with the US today
I know that laws get abused but do you see the OP asking to remove laws that are in his favor like copyright law or patents law?
No, because the legislators fundamentally misunderstood cookies. Almost any website needs to have some basic tracking of users for fraud detection, bot detection, and yes, basic analytics.
Instead of writing out a thoughtful approach, we get a mandatory nag screen right up there with "This product is known to cause cancer in the state of California" on anything sold ever. Users ignore them because the information isn't useful - infinite noise, no signal.
This is the opposite of the CAN SPAM law which did have thoughtful requirements - allowing exceptions for account related emails, requiring one-click unsubscribe but also giving systems a period to obey that to handle mail already in transit.
GDPR has so far been grossly in the cookie nag screen category, except instead of a tiny bar on visiting a page I get a multi-select based dialog of doom. The answer most companies are going to take is simply not market services to folks in the EU, and those that do will implement annoying nag screens.
More rules blindly applied rarely solves problems.
The only way to completely avoid the GDPR is to not hold personal data of EU citizens or EU residents.
(This is for foreign businesses. EU businesses have to apply it to everyone, regardless of their location or citizenship.)
https://www.linkedin.com/pulse/gdpr-does-apply-eu-citizens-g...
But really, it's plain from the text.
Funny, because the GDPR explicitely says this is not the case.
Art2. Paragraph 2
This Regulation does not apply to the processing of personal data:
c) by a natural person in the course of a purely personal or household activity;1. Nobody in Europe will be blocking anything.
2. The Wayback machine will continue to operate.
3. GDPR is generally pretty well-written legislation, based on extensive experience by privacy regulators across Europe.
There are some questions about exactly how the rules will evolve in practice. The thing to bear in mind is that privacy regulators are interested in compliance, not in punishment.
Edit: I of course know that Russia is not in the EU, lol. Parent said "Europe" and I added Telegram as a fun remark after two serious examples (and there are more). Calm down with the downvotes.
The porn block in the UK (or opt-in block, more like) is a voluntary measure taken by ISP.
Not allowing information about people to be kept ad-infinitum (and sold ad-infinitum)?
Allow data breaches caused by sheer incompetence to go unchecked?
As much as I worry about its consequences, companies saw it coming.
Like the cookie nag, users are going to blindly click through until the confusing nag screen goes away and then be upset that it wasted their time.
The 'cookie law' is actually subtle genius.
If your site only uses cookies for operational reasons, such as enabling login or maintaining a basket, you don't need to inform the user.
So anytime you see a cookie-banner that indicates that the site is doing something additional with cookies. Like tracking for ad-networks. It's a yellow-flag.
Though now that I think of it, perhaps blocking [the archive.org crawler] could then become mandatory for GDPR compliance ...