UK to depart from GDPR
lawgazette.co.uk
lawgazette.co.uk
TBH I'm glad companies stay away from my data if they don't know how to get consent, store data securely, or even what those things mean.
Words like “reasonable” and “legitimate” in the law are not something it is safe for a layperson to reason about. They have specific meanings depending on the nuances of case law, judicial understanding of legislative intent, ideological leanings of the judge you happen to draw, etc.
No company is competent at this, some just have enough money at stake and enough to spend on lawyers that they’re willing to risk it.
The law is not like code. Thank god.
And that's if you can get said legal minds to take a firm position in the first place, instead of the more usual five - six figure "maybe"
It's very much more healthy (and lawful) than just mucking on, stuffing data into limitless digital vaults and then not having a clue when all that data gets leaked.
In the good old days, paper records had the good manners to take up physical space. It was clear when you had too many records because it was a serious inconvenience to your business.
Because GDPR allows for liquidating fines, even for Google. I believe it has a cap of 2% annual global turnover, per infraction, or something similar.
Problem is, GDPR is not enforced. I haven't heard of small companies being investigated, let alone having any fines imposed, even when blatantly violating GDPR.
That to me sounds like they're most likely to sell the data, since they don't know how to use it themselves. Better these companies have less data, not more.
As an example, let's say I want to launch a blogging platform. You need some basic tables (data) like User, Posts, Tags, etc. I'd consider this data the business needs for core business. Does there need to be some GDPR compliance thing?
Anecdotally a dumb app I built I was worried about EU visitors and just wanted to block them instead of figure it out (yea yea maybe that's not the right approach but I'm sure the sentiment is common).
Yes. GDPR is about data protection. If you want to do business in its jurisdiction, then you need to know the laws.
In general, GDPR states that you cannot store anything that isn't strictly necessary, unless you outline what you want to collect and what it will be used for in your data policies. You are not allowed to use it for anything else and once its no longer needed for the outlined use, it must be removed. Personally identifiable information has some additional rules (and its important to note that anything could become PII if combined with something else, that would, together, allow for someone to be identified).
My own (EU-based) country's data protection websites states:
1. Everyone has the right to the protection of personal data concerning him or her.
2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned, or some other legitimate basis laid down by law.
3. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
4. Compliance with these rules shall be subject to control by an independent authority.
This means that every individual is entitled to have their personal information protected, used in a fair and legal way, and made available to them when they ask for a copy. If an individual feels that their personal information is wrong, they are entitled to ask for that information to be corrected.
Sounds like you have to learn something before starting a business.
The GDPR applies to all processing of all personal data regardless of whether that's pieces of paper in a filing cabinet or an entirely online social network.
Spirit of the law is great. Implementation and end result is a typical bureaucracy mess, with not much benefit for end user, that functions mostly as a way for government to have a leverage over companies for non-compliance, whenever they want to put pressure on them.
People focus mostly on the cookie popups, but forcing companies to delete data after the user stopped using the service for too long, or even giving a legal stand on users requesting their data to be deleted wouldn’t have happened any other way I think.
In a lot of european countries GDPR came on top of other existing customer protection, but it helped make companies think about compliance as needed for continued business, instead of something akin to properly filing random local paperwork.
Which is why you NEVER comply: you get exemptions.
In the short term it may sound great that a lot of companies are erring on the side of caution and not using the data, when perhaps they could.
But if there's no enforcement this gives a huge competitive advantage to companies who just don't care at all. They might crowd out the former set. If such companies were not erring on the side of caution, and using some data in a natural way like they used to rather than avoiding it like the plague, they may provide competitive pressure against this dishonest set.
It is a lot like paying taxes. If I am an honest small business owner who pays my taxes but my competitors in the field are known for underhanded cash schemes that dodge tax, I'm not going to last long. I need the law to go after them or I'm done unless I start playing the same game. After dabbling in a small business compliance can be a real killer and it's my honest opinion a lot of people just play it dumb except where they know it matters, and hope for the best.
The law itself says that the default option should be to opt-out. Any site that doesn't have precisely equally prominent "agree to all" and "deny all" buttons violate the GDPR.
The problem seems to be in the complete lack of enforcement.
I don't know if that was the case before gdrp but we have to centraly clarify if and when we store user data, what we do with it and we have to show that we can delete user data if requested.
Not sure how far small companies go through this thow.
I know of small companies that before GDPR didn't really consider the implications of private data at all. They'd just let their SQL databases grow forever (mark as delete and have "script to actually delete the data" as a TODO that never happened), had random backups lying around on dev machines.
GDPR forced them to actual define policy, start deleting old data that was no longer relevant, strip private data from developer test sets.
It was a bit more work, and adds a small bit of friction, but these are still important things!
Forcing cooks in restaurants to wash their hands after using the bathroom also adds friction to the process but is similarly important.
That is the theory. The reality is that many small businesses don't even know the GDPR exists. Others are not complying because they think they will get away with it, and they are probably right. The rules are so ambiguous in some important ways that even those who do intend to comply might not actually be compliant and won't find out until a regulator intervenes. And all of that together means that a small business that does try hard and become compliant is at a significant competitive disadvantage.
To be clear, I am a firm believer in strong privacy protections, and my own businesses seek to be in the latter category. But the GDPR is flawed in important ways, and future regulation deviating from it is not necessarily a bad thing. Obviously it depends on whether the deviation is of the selling-out or the fixing-problems variety. Though admittedly, with the current UK government, I fear the former is much more likely.
If a model box only has "I consent" and "Learn more" buttons, then I don't consider clicking on "I consent" to mean freely given GDPR consent. Since it's the only reasonable way of viewing the website, and the GDPR doesn't permit a consent-wall, it's non-consent, and any use of my personal data following that event remains illegal.
It's not a problem with the GDPR; it's a problem with the ICO failing to put a stop to this.
That way I never gave any consent.
Nowadays I have browser plugins that do that for me, but same idea.
In any case I block cookies on all sites except for a few whitelisted ones so big "ha" to them if they think they can cookie me up. "Functional cookies" my ass. The sites work just fine without them.
GDPR regulates, among other things, how information is stored and deleted on servers. I have worked at multiple companies in both Europe and the US who take this very seriously and has definitely altered their practices based on this.
For example, pre-GDPR, we would "mark as deleted" but not delete. Now we delete.
Well that seems untrue, as someone that regularly either outright declines, or goes through and chooses "functional only".
I do occasionally see websites that say "we no longer serve the european market". That's a shame but it's up to them.
GDPR covers way more requirements regarding data management. You need complete control over the lifecycle of sensitive data, exhaustive documentation of data transformations, you have concrete obligations regarding disclosure of incidents, data removal, limitations of for what data is used, user consent management, and the obligation to have people personally liable (which is big, just look at AML regulations to see the effect when not only the fuzzy concept of "the company" is liable).
“Storing data securely” and “getting consent” are both wildly different from full compliance with the onerous requirements of GDPR. You can do both of these things in absolute good faith and still be in violation. Unless you have a team of legal scholars working for you, odds are that you are in violation of at least one provision of this massive, unwieldy legislation - no matter how respective of user privacy you are.
That is why the UK is abandoning it. GDPR, as written, is a business-killing mess.
GDPR has been in place for years, which businesses has it killed?
Do you have an example of a company that you consider was not doing anything wrong in your personal opinion but still got a GDPR fine?
Does anyone else?
American-like but with no negotiating leverage and having burned all the bridges to the other economic unions.
This comment seems to be borne out spite more than any kind of logic.
- The EU exit was, among other things, accused of being a way to relax regulation and legislation to degrade product standards to a US-like level. Chlorinated chicken was a big item on everyone's discussion agenda a while back. This is now evidently happening.
- The government is severely underfunding the NHS, despite paying it lip service. Some accuse the government of doing this as a form of sabotage, so that the service quality degrades and the private sector can swoop in as the saviour. This is controversial because:
a) Brits are very proud of the NHS as a nation (or at least that's the dominant narrative in my news bubble)
b) The privatisation of British rail has been a disaster - ticket prices have skyrocketed, and service quality took a nosedive in some areas.
Train company profits count for about 2% of the total cost of the ticket, and (pre covid) the network carried more than twice as many passengers as it was under BR - nearly 2 billion journeys a year vs a steady 800m in the 70s through 90s. in terms of distance, pax-km
1970 36b 1980 35b 1990 40b 1997 42b (end of BR) 2010 64b 2018 81b
Since 1997 that's a 90% increase.
France has increased 40% since 1997, Germany by 60%.
Fares have increased, but this is a reflection of the cost shifting to the passenger and away from the taxpayer. In 2009/10, franchised train operating companies were paid £275m to run the services (and another £3b was spent on the network those trains run on)
By 2015-2016 that operating subsidy had gone, and instead the TOCs paid £1.2b/year to operate their trains (some areas like Northern and West Midlands were still subsidised, but South West trains and Southern were paying their operating dues and paying for the tracks they run on)
It doesn't make sense to justifiably complain about overcrowdning (high demand) on one hand, but complain about high prices on the other. There is competition to rail if the price was too high -- driving, coaches, flying, not traveling, but the fare is obviously at the right level to result in record levels of travel and relatively low subsidy.
Privatisation has not been perfect, but only someone who does not remember the old days of British Rail in the 1980s and 1990s would consider it a disaster. It's true that fares are high, but service levels and passenger numbers are both far above the British Rail days. (UK rail passenger numbers reached an all time record in 2019)
Prior to Covid, many of the busiest lines were operating near their capacity limits, so setting fares any lower would just cause even more severe crowding. And fares, of course, generate revenue to reinvest into expanding capacity.
In any case, UK rail operators are now de-facto nationalised due to Covid. This has been recognised by the ONS, with rail operator's debts now counted on the government balance sheet.
ONS recognises full nationalisation of the UK railways: https://www.ft.com/content/1baa6b50-47ba-416e-b172-90a77a34c...
There are a couple of other reasons:
The Lansley reforms were about increasing non-NHS provision. They mostly failed because private providers simply can't do the job for the money the NHS gets paid.
Where we see private provision (for example, specialist commissioning in mental health services, or learning disability and autism services) we see terrible standards of care. Winterborne View, Whorlton Hall, St Andrews, are all non-NHS providers. Cygnet Health have had a bunch of inadequate CQC reports.
Indeed, you seem to admit that here, when you state that you got your views of what British people believe from your "news bubble". For example you think everyone else thinks the NHS is awesome, because left-wing journalists told you that's what everyone thinks. One day you'll talk to a Brit outside of that bubble and get a real shock to discover they aren't enamoured with the NHS at all. Remember, nobody has copied the NHS model. Nobody! The rest of the EU looked at it and thought the UK was crazy to do that, they all went with far greater private sector involvement. The NHS is a socialist anachronism and plenty of people would love to move to a more standard social insurance model, but even expressing such an opinion results in nasty, vicious attacks by the left, so people quickly learn to just stay quiet about it.
Quite possibly one day there will be a referendum on this and the same sorts of people whose minds were blown by Brexit will have their minds blown a second time by the degree to which people vote against the NHS.
Likewise for rail. The UK just had a vote on that: Corbyn had very few identifiable policies but re-nationalisation of rail was one of them. Voters rejected that agenda on an a-historic scale. Again, if it ever became a topic of serious political debate like the EU did before the Brexit referendum, you'd be shocked at how little support nationalisation would end up having. Ridership was in decline for decades before privatisation. The moment they were privatised that trend went into reverse and ridership started climbing again, until it reached new records pre-COVID. Ticket prices were rising because the newly privatised railways became so popular (limited supply+growing demand=rising prices).
Regulation: Whilst the US is not a low regulation zone by international standards, the EU is even worse. I love this headline, UK leaving GDPR. Hell yes. Another brilliant move by the UK post-Brexit, the latest in a string of them. GDPR is a disastrous "law", in quotes because it barely qualifies as a law at all in the traditional sense when you read it. Laws are meant to explicitly state what they disallow but the GDPR is so vaguely worded it could be interpreted to mean almost anything. Just on basic constitutional grounds, junking it is a smart move.
But there are practical benefits too. GDPR imposes staggering costs on businesses to deliver dubious 'benefits' which approximately nobody outside of the reflexive "it's EU so it must be good" bubble actually cares about. There has been no mass migration away from US tech firms at any point, GDPR implementation changed basically nothing about the online experience and the EU's various attempts to legislate tech firms away from domestic markets just made it impossible to create local competitors. Beyond being banned from some local US newspapers and forcing yet more privacy popups everywhere, GDPR has been largely impact-free.
I'm rather sure your Labor party (at least Corbyn) was constantly attacking EU/Brussels and often dutch for neoliberalism.
If your political position is re-nationalisation then it's easier to do it outside the EU unless you think the Conservative party stays in power forever.
Have you ever known any government departments that don’t howl about being underfunded? The NHS is the 4th largest employer in the world, 1.3 million employees to provide healthcare to a nation of 67 million.
The Labour Party is currently claiming that NHS spending will be cut next year... because the emergency funding for the Covid situation won’t be made a permanent part of its budget!!
Brexit mostly was and remains a domestic issue which is why it's such a touchy subject on HN where there is probably a significant number of Britons commenting.
The barbarians are good, loyal and brave. They don't spend their time with cultural frivolities like theater, bathing and running a shop.
Note that it's morning in Europe, and as such there will be lots of British/European people around, for whom Brexit is a bigger deal.
Similar to how broadly views on Trump outside of the US tended to be similar, when people have some distance from a debate they do tend to fall down on one "side".
I presume by "Twitter hot take" you just mean "takes I personally disagree with", right?
#2 The UK has departed from the trading bloc it does 60% of its trade with. It desperately needs new trade deals outside of it. Since America is the biggest economic bloc outside of Europe and because they're big and we are small they have the leverage and that means we start abiding by their rules.
#3 There were plans leaked on how this would be done with the NHS (e.g. deliberately hamstringing the NHS's ability to negotiate drug prices). They kept them secret from the public.
To be frank, your comment seems borne out of a kind of appeal to moderation rather than particular knowledge of UK domestic politics.
The shock of their financial sector leaving.
The shock of getting pitiful trade negotiating.
Being unprepared with anything to offer for negotiating leverage.
The domestic identity further polarizing and inability to form consensus.
You speak in the past tense but this hasn’t actually happened and shows no signs of happening in terms of banks relocating jobs and capital. If anything London is getting stronger.
(I'm aware that all sounds quite America-like already)
The basic premise of the "it's an establishment stitch up" argument is that Britain will be weaker and poorer, but the establishment will end up with a much, much bigger slice of the smaller pie such that they gain overall. It's not clear to me how that's supposed to work though. How is this pie-grab supposed to work as the pie itself shrinks? Some people might manage to pull it off, but the whole establishment class as a group?
Anyway, this whole premise flies in the face of who we know voted overwhelmingly for Brexit - ordinary British voters, many of them up north and from working backgrounds - even as the actual political parties, majority of MPs and most business leaders were arguing against it. The evidence for an establishment stitch up rests on a few very specific data points, like the fact that Jacob Reese Mog and some of Nigel Farage's hedge fund friends have already and will continue to do quite well out of it. They're hardly "The Establishment" as a whole though. They're just some of the people I was talking about trading on volatility, and hardly representative of the financial sector as a whole that is getting screwed over by losing passporting.
The vast majority of the city and other business leaders where asleep at the wheel - what they should have done is had a quiet word with Harry Peirce (MI5) at the club about these dangerous subversives.
This is false, because every time it was presented for a vote Leave won. If the majority were Remain, Brexit would necessarily not have happened.
As for the alleged ordinary voters, what did they want out of it and what are they actually getting out of it?
The Conservatives have a majority and are there any Remainers left in that party - I thought most of them had been purged before the last election?
I'm really not sure about that. I agree that may be the case with some of those ruling individuals. My impression is that Johnson doesn't believe in anything, except his personal interest and profit.
Others in that cabinet, however, really appear to be true believers.
> Others in that cabinet, however, really appear to be true believers.
My impression is that they all have those same beliefs - their personal interest and profit.
A bit like a supercritical fluid, where transition between liquid and gas occurs spontaneously.
Many leading brexit proponents are rich people who made their money from the collapse of the soviet union and have assets largely outside the UK. One conspiracy theory is that they are attempting to crash the UK economy in order to buy the dip, make money from shorts and the sell off of state assets.
Another conspiracy theory is that brexit has an ideological basis in the idea of the soverign individual - related to the idea of the randian hero, the idea is that as states weaken in power, rich people will be able to transcend citizenship and attain some kind of libertarian utopia where they can do what ever they want. One of the leading brexiteers dad wrote a book about it which apparently has some following, but maybe people are just surprised that right wing politicians want a smaller state.
There is also an idea that the UK and its dependencies (e.g. virgin islands) are a tax haven. A lot of brexit money came from US activist billionaires and hedge funds, but a lot of it came from very rich russians who fled tot he UK in the 1990s with huge amounts of money that Russia say was stolen visa corruption and other criminality. The theory is that brexit was a response to EU money laundering and tax evasion rules that would have linked these rich criminals to their money to its sources, leaving them open to russian legal challenge. The theory is that for those people, brexit was a means to escape the net.
In my opinion, the role these factors played is probably overstated - brexit was primarily a backlash against globalisation and change, and a protest against the UK status quo by parts of the population that didn't believe they benefited enough from it, much like the election of Trump in the US.
If anything I think it is rather unfair to hear people from other EU countries treating this process as something along the lines of 'suits them' and 'they've made their bed'. When in reality a large chunk of them have pretty much not agreed to any of this but are still set to suffer the consequences.
One wonders if remain had one if the leave campaign would have accepted "The vote was clear, put up with it and shut up".
I completely understand why EU governments would be absolutely fed up with the UK government though.
Sadly my generation (40 and younger) are going to have to live the consequences of something we didn't vote for (49 and younger voted remain getting more strongly remain as you go younger) - it's absolutely frustrating.
"In a 52-48 referendum this would be unfinished business by a long way. If the Remain campaign win two-thirds to one-third that ends it."
https://www.bbc.co.uk/news/uk-politics-eu-referendum-3630668...
(I say this with tongue firmly in cheek, but I do think there is some truth to the idea that people broadly get more conservative as they get older)
Yeah, but unfortunately only 64% of the under 35 year olds bothered to turn up, while in the older age groups the turnout was much higher (80% for 35-64, 89% for over 65). That was probably a result of many (including the polls) thinking that the "Leave" side didn't have a chance of winning, same as many US Democrat supporters (also supported by the polls) didn't think Trump could win. The US voters got to correct their mistake four years later, no such luck for the UK voters unfortunately...
The EU isn't perfect, but you'll struggle to argue that it hasn't expanded peace, prosperity and human rights across the continent. This is motherhood-and-apple-pie stuff.
Arguments in favour of Brexit thus tend to boil down to immigration and 'sovereignty'.
There's a consensus amongst economists that immigration makes us financially better off. That makes it hard not to ascribe a strong desire to cut immigration to a powerful desire for ethnic homogeneity and/or a powerful dislike of foreigners. Those things are very close to racism.
Meanwhile, the 'sovereignty' Brexit delivers is almost wholly illusory. In practice, we'll get to choose which of the big players to take the rules from. That's going to be either the US (which hardly anybody actually wants — most Brits value our health service, non-toxic food and drinking water, holiday pay, and so on — and also isn't very helpful, because the US is far away) or the EU (whose decisions we used to play an outsized role in, but no longer have any influence over).
It would be hilarious — if it weren't tragic and a little terrifying — that the ones in charge of 'taking back control' are also the ones stifling parliament, suppressing voting, and attacking academics, judges and the rule of law. As far as I can see, the only ones taking back control are the rulers, and the only ones they're taking back control from are the other citizens of the UK.
Your own example is a single datapoint and according to the vote statistics you are a de facto minority in your age cohort.[0]
[0] https://www.politico.eu/article/graphics-how-the-uk-voted-eu...
What were your reasons behind your decision? What economic class are your parents in?
From my perspective, it's more like "it was inevitable". The people pushing for Brexit would never give up. So the choice was either leave now, or keep talking for the following years/decades/centuries about how the evil EU oppresses the UK, and how everything in UK would be perfect if only...
In some way, it reminds me of dissolution of Czechoslovakia. I was not happy about that either, but realistically, the choice was either do it now, or keep forever listening to voices on both sides about how all problems are caused by the other half and everything would be perfect (though probably disastrous for the other half) if only...
Once you have a major fraction of your population -- and it doesn't make a difference whether it's 48% or 52% -- believing they are being oppressed, it becomes unfalsifiable. Every time something bad happens, you have an explanation ready, and it doesn't matter whether it makes sense or not, believing that it is all someone else's fault is always popular.
If the lesson from Czechoslovakia applies here, at the end none of the prophecies of heaven or hell came true, both sides continue living their boring lives. The only change is that now when something bad happens, this one excuse is no longer available.
So, my guess is that after Brexit, the life in EU will more or less remain the same, and the life in UK will more or less remain the same, with the exception that "everything would be perfect if only EU stopped interfering with our perfect country" will disappear from political speech.
That doesn't seem to be disappearing. My guess is we will be hearing a lot more about the EU for the foreseeable future.
Yes, but a far larger chunk has. Every country gets the leaders it deserves and the UK is no exception.
All things considered it was relatively close so not exactly a far larger chunk.
I don't have any spite towards the British people but I do hope that the EU will act in EU interest which means facilitating the return of financial services that shifted towards London since they joined and not letting the UK and whatever the borderdeal ends up as serve as a loop to ignore single market regulations.
Giggle count: zero.
The US for all the lack of controls that citizens have over business at the very least has a very federalised (in the Euro sense of the term), distribution of power, whereas Britain is pretty much governed from London.
I find that many of the quintessential problems of the U.S.A. were inherited from the British Empire and seem pervasive throughout the Anglo-Saxon world. England too has a district based system, leading to close to a two-party state, and a common law legal system where the judge and juror are often more powerful than the letter of the law.
If anything, the U.S.A. remedied some of the unusual quirks of common law legal systems. — I was recently acquainted with knowledge that in both the U.K. and Australia, a criminal defence attorney would, when his client confess to the crime to him, almost certainly recommend that he be released, and that latter seek new counsel, and that the new counsel be kept in the dark, as apparently the system is designed such that a criminal defence attorney is completely handicapped in defending his client, know he of the latter's guilt. — this is less so the case in the U.S.A., which is rather unique for jury trials, and in most civil law jurisdictions there is no reason not to confess to one's attorney.
The only thing the EU referendum conclusively demonstrated was how easily manipulated people are by the media they consume.
What do people mean when they say this?
The referendum wasn't a statistical exercise that sampled a subset, so the idea of "error" seems really oddly applied here.
What we need is respect for democracy.
The trouble with the DPA was fines capped out at £500k and international enforcement was limited so large international companies like Google and Facebook could treat the law as an optional slap on the wrist while smaller international businesses effectively flew under the radar, the GDPR largely rectified both of these issues while modernising the laws in response to issues that generally didn't exist prior to the mid 2000s.
UK market is large enough to stand on it's own and EU has been grossly incompetent in public for a while now. There's going to be downsides for sure but becoming "America like" is not going to be one of them.
It makes sense for smaller countries like mine (Croatia) because of free travel, easier access to a larger market, lower cost of doing business, and truly being too small to negotiate good terms on a global scale. It probably makes a lot less sense for UK which can negotiate it's own terms with other global powers that fit them much better.
I have no doubt there will be many negatives to Brexit, but as demonstrated by COVID situation there's a huge opportunity for UK - for example I suspect they can secure better trade deals with the US without having to worry about the protectionist interests pushed by other EU members.
The European Union has categorically failed, and if it survives this, it will need huge amounts of change.
Seems like not being part of a larger "union" has allowed them to start vaccinating at 3 times the pace of its European neighbours. Historically, power removed further from the people does not benefit the people. There are very few "economies of scale" in politics. As the system grows larger, accountability becomes more difficult and decision making is harder and harder.
Nice example is Iceland. after the 2008 crash. https://www.bloomberg.com/news/features/2016-03-31/welcome-t...
GDPR has given a 50M EUR handslap to Google and similar to some other large companies[1] while seriously hurting smaller companies with existing custom web applications for whom they may not even have someone on staff to modify those to be GDPR-compliant.
Small businesses like others must determine what PII is, how to anonymize it, and how to remove it when users request their PII to be removed. PII could be in their server logs or other locations that are inaccessible to most employees of the business. Backups might be excluded from PII scrubbing, but so much is unclear.
Let’s also talk about what it doesn’t protect. PCI, not GDPR, attempts to provide protection for cardholder data. GDPR doesn’t protect against PII that was previously shared. Nor does it protect from data being stolen, unless the user had their data removed prior.
[1]- https://dataprivacymanager.net/5-biggest-gdpr-fines-so-far-2...
Companies of all sizes can have a lot of PII and code that’s not GDPR compliant, and it’s non-trivial to fix that. When asked by a user to remove PII, the removal is sometimes incomplete at these companies. Even the process of incompletely the removing PII wastes time; the users requesting PII removal often didn’t even do business with the company, in my experience.
Companies of all sizes but often small companies hire out development of web apps that keep PII and may not have someone permanently on staff to maintain it to make the changes needed to allow users to remove their PII.
I’d go so far as to say that I’d intentionally not work with users if I knew they would be painful to work with, leaving me with nothing but a legal requirement to wipe their asses because they used my old site. I hope that EU didn’t intentionally do this to hurt small businesses and foster new startups within the EU to brunt the cost of this stupid, stupid law.
I’m a privacy advocate.
If the government passed a law requiring all housing to be be built to code to survive a magnitude 9 earthquake in a region where there are no earthquakes, and every house needs to be retrofitted, would you say the burden is low? After all, if you start from scratch without a house there is no requirement to do anything! And building a new house is much easier, after all!
Hoping we see the light, and the blight that is the cookie law goes the way of the dodos.
If your teeth turn out blighted all blue/purple, you generally don't blame the tablets. ;-)
It’s really just theatre and on balance it makes the internet a crummier experience.
Hacker News has reached new lows :(
It's like newspaper headlines that say X, but (have to) nuance it in the article itself. Except that Twitter doesn't support articles, so it's only headlines.
The euro is truly an unremarkable currency and I'm not sure that the EU would be much worse without it. It's equally likely that the EU would have done much better without the euro. I can't blame the UK for avoiding the euro.
Of course it's very fashionable on the internet to shit on brexit. "haha brits be dumb cus independent" - I can only imagine what sort of insecurity you're dealing with about your own country that you have to resort to this.
We'll see if this is still the economic "gold standard" to compare countries when China overturns the US in GDP.
Just ignore every other benefit of the EU to make your case.
I’m sure they’ll feel much better when there’s yet another set of rules and laws they’ll have to follow. Oof.
This is a deeply depressing take if the conclusion is to scrap GDPR. Is this true for 'data' in the general sense, or actually only true in the murky cases where there's an opportunity to use and abuse our personal data.
In my book, that implies that GDPR is working exactly as we hoped it would.
>The UK has the freedom to strike its own partnerships, he said, and he would announce priority countries for data adequacy agreements shortly
will be an announcement that the US has adequate data protection.
Overall I think GDPR is a very positive thing, but from the government's perspective if they could keep the adequacy agreement in place with the EU while still relaxing some of the current GDPR legislation then that would be a big win for them, especially from a political point of view as it would be some much-needed validation of their brexit strategy: "Look! We have all the benefit of being in the EU [via the adequacy decision] but we get to make our own rules! Go us." I could imagine them doing something along the lines of greatly reducing the maximum fine, for example. Big fines are typically not being issued, so they likely wouldn't see it as a big loss.
No-no of course we don't want to sell your data for profit, that would be ridiculous. Clearly it is just our corporate sponsors who will be doing it for us!
The nation (any country) needs to have human goals - not economical goals for their own sake - but a better life for us, for us all.
Like Brexit, the people benefiting most from it are already well settled, they're working on their short- to mid-term plan to earn a lot of money before retiring to their private island or estate or whatever. They live outside of the negative consequences of their decisions.
Meanwhile, the rest of the population will have to suffer through the consequences for the foreseeable.
Tl;dr, policy optimizing for short term individual gain instead of long term sustainable gain. And the long term gain would be so much more better as well.
All of the countries currently under a short term gain capitalist regime could be so much better for their inhabitants. Wealth, socialist policies, comfort, safety, stability, etc is all in reach. But instead the people at the top - who already live a very comfortable and privileged life so they don't see and never will see the problem - choose short term personal gain for them and their 1% friends.
Oh, nonsense. People disagree with you politically. That doesn't make it 'unveiled corruption'. What a lazy way to think.
But there is a systemic and widely recognised issue in the UK with the government flagrantly handing out public money without due diligence or fair recourse.
Selling citizens data for profit is just another data point.
https://medium.com/shit-britain/the-bumper-uk-conservative-g...
https://thejist.co.uk/politics/a-list-of-alleged-conservativ...
https://www.thelondoneconomic.com/politics/how-the-tories-no...
What a lazy way to think
"Fortunately, Switzerland, along with 12 other non-EEA countries, has received an "adequacy decision" from the European Commission. An adequacy decision is a recognition of the strength of Switzerland's data protection law."
The problem is that the ICO is absolutely incompetent at enforcing it (I found it very funny that the article claims businesses are afraid to use data while in reality not only do they appear to use it just fine and even a bit too much for my liking, but our regulator has only ever handed out 4 fines, all for data breaches and not other abusive usage of data).
They ought to be annoying. so sites that do not track you for advertising can just add your cookie when you actively sign in, without the annoying popup on first visit, and receive more traffic because they are less-annoying.
Most of the modals are full of dark patterns that basically force you to accept the cookies etc. unless you go through multiple different screens and checkboxes.
GDPR has nothing to say on state snooping and if you think Germany or plenty other members aren’t.... I’ve got some bad news for you
Maybe if they harmonize along CCPA or something it would be of value.
I am surprised that nobody is realizing that what's bad for startups and SMBs is also ultimately bad for the users, just on a longer timescale (with an equally long reversal period).
I remember the US Congress grilling Zuckerberg back in 2018, and him responding that he's certainly willing to make amendments, but if you tie his hands too much, someone from China will swoop in and bypass all regulations. Everyone scoffed at that, and less than 3 years later, TikTok is unstoppable despite Facebook's best efforts. While users' privacy has benefited from Facebook's downfall, their privacy has never been at more risk with the rise of TikTok (I do realize that TikTok's servers are in the US and Singapore, but let's not fool ourselves - the ByteDance leadership would be quickly replaced if they refused a data request from their government). I would consider this a net negative for the users, and particularly for the US as a country.
Just another example proving that the paradox of tolerance [0] is a real thing. If you get too tolerant too quickly, you end up with a less tolerant outcome.
On the second-order basis, there is an interesting comparison between how well Facebook hindered Snapchat's growth with their rollout of Stories, vs how well it hindered Tiktok's growth with their rollout of Reels (not very). There are obviously a million factors to consider, but I would argue that us taking Facebook through the dirt 1) weakened its hold over its users and 2) triggered a talent exodus, both of which contributed to Facebook's Reels not being as impactful as Stories (viewed strictly through the lens of defending against the new competitor).
Edit: removed needlessly aggressive "That is a lie" opening gambit.
I think you need to back that up with credible numbers.
GDPR was and has been a massive kick in the backside for companies large and small in the UK. I certainly know from talking to my past client base and current network, which is from a fairly broad spectrum of organisations, they treated GDPR compliance pretty seriously. Hell even my local village pub made sure they were in compliance, despite just having a manual paper based guest register.
Imagine the desire for wealth and power at the expense of others being defined as a mental illness that needed treating instead of giving these cunts more power.
Congratulations Britons, your data's back on sale.
edit: wow that's a lot of downvotes in a short space of time. Maybe I should back my point up with some evidence to prove I'm not talking out of my arse (though it was widely reported at the time so I'm surprised anyone would disagree with me): https://www.bbc.co.uk/news/uk-politics-44966969
The thing is, even though the GB decides to ditch GDPR, they're still bound by it if they want to do business with the rest of Europe, just like the US is bound by it.
I know that some purchases of cloud services are halted for now to be sure about this. Data movement is going to be increasingly an important matter. It should have been from the begining but here we are.
https://incountry.com/blog/data-residency-laws-by-country-ov...
Organisations which receive and hold any of regulated data types to follow the GDPR requirements. According to GDPR, companies have to keep the data secure inside the EU and if the data is to be transferred outside of the UE, then it can only be transferred to countries or organisations that have signed up to equivalent privacy protection."
So the EU has all the power here to say that the UK doesn't meet their standards and require businesses to transfer their data.
However, I would guess that most international organisations would have already moved their EU customer data out of the UK.
There were years of uncertainty with the Brexit negotiations, keeping data in the UK would have too much risk.
Plus many other countries have data residency laws, so it's not like a foreign concept to international businesses.
Instead of frontloading compliance for any new venture, they can build for the UK first then work on compliance if and when they go for EU business.
we'll wait for the actual documents, but in the meantime:
1. does this mean no more cookie stuff, and no more "click here to accept" modals? if yes, then it's a huge win. years of useless clicking, and countless Mwh will be saved in the long run.
2. will this mean no more protections whatsoever? this is not so great imo, and sincerely impossible in today's world of Big Tech legislation (especially in the highly litigious Europe).
3. what about the right to forget? will they touch that part as well?
I am not sure this will have a significant impact, as UK will have to comply with GDPR if they want to to reach European customers.
[1] https://www.activemind.legal/gb/guides/eprivacy-regulation/
On the one hand, I think GDPR is a great step towards stopping companies hoarding your data and holding you hostage to it. On the other, main GDPR change is those awful 'hand over data / pretend you're not' dialogue boxes. When I'm feeling strong, I look for the 'reject / object / blah' box, but often I don't find it in me to resist anymore.
So maybe it's not awful they're reshaping GDPR.
I remember it used to be a thing in the netscape navigator days until everyone got sick of it.
All you need to do is not say yes. The easiest way to do this is filter cookiebars/walls/whatever in as many places as you can. Without an answer, the answer is no.
No active (this does NOT include "by using this site you accept...") approval = no permission to collect data and give it to third parties.
That's the law. But we'll still need some hard work and hefty fines to make everyone obey it.
The UK has an equivalence agreement with the EU, which unlike a trade agreement can be rescinded quickly (something like 4 weeks). This means that we have to have equivalent provisions to continue to handle data about EU citizens.
so the UK might be "departing" from GDPR in name, it won't be in substance just by this act.
This of course assumes the the UK is acting rationally.
Those who ultimately respect user privacy and want to do the right thing are often paralysed by process and making sure that they absolutely can't be sued, rather than being able to show respect for data and best practices but still getting things done.
Those who ultimately don't respect user privacy use it as an excuse. They plaster their services with GDPR notices, and then ignore the spirit of the law and sweep up all the data they want, regardless of whether they need it or should have it, but of course this is invisible to users so nothing happens about it.
I wonder if this disconnect comes from the enforcement? I'd like to see a few high-profile cases that set out some precedents for what is and what isn't a breach of GDPR.
Things it didn't fix: Data leaks.
If I was a betting man, I wouldn't bet on this being a significant change, given the world is moving more towards privacy (yes, including US).
https://edri.org/our-work/uk-japan-trade-agreement-violates-...
As Boris Johnson said, "The UK won't immediately send children up the chimneys or fill beaches across the country with raw sewage". Emphasis on "immediately".
...Dowden said that under the regime ‘too many businesses and organisations are reluctant to use data – either because they don’t understand the rules or are afraid of inadvertently breaking them’."
However this would only be in relation to UK data. If they want to do business with EU citizens, then businesses have to comply with GDPR.
Seems pretty myopic.
I'm sure this is a minority opinion on HN but I'm glad to see some countries pulling back, especially in light of recent calls to expand GDPR even further (!).
It seems this can only lead to
1) Rolling back to pre GDPR, where user data is largely a free for all 2) The UK having it's own 'unique' rules
Neither which seems very good for users and/or businesses.
Perhaps the point here is to make some kind dubious 'look what we can do because of brexit' argument. When the reality is that 'freedom' has a reality which is more negative than any positives it might have.
What does that have to do with personal data? Sounds like keyword stuffing
Quotes from Alex Voss in today’s Financial Times [1]
> The government has sent a first signal of its intention for UK data protection laws to part company with the EU’s General Data Protection Regulation. In a Financial Times article last week, culture secretary Oliver Dowden said he would use the appointment of a new information commissioner to focus not just on privacy but on the use of data for ‘economic and social goals’.
So we don't know the UK is going to depart from the GDPR, but despite that, this website is reporting that it will.
>The UK has the freedom to strike its own partnerships, he said, and he would announce priority countries for data adequacy agreements shortly
Either he recant that comment or announce a country (the US I bet) that doesn't have an adequacy agreement with the EU. You can't have it both ways. If he does announce a list that isn't the same as the EU's they'll have scrapped GDPR.
And big companies seem to completely ignore it anyway. Take twitter - all they have is a banner along the bottom that says:
"By using Twitter’s services you agree to our Cookies Use. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads."
and a close button. How is that consent?
Also, your Twitter quote shows another issue: conflating GDPR with the Cookie directive. They are two very different laws. GDPR is concerned with personally identifiable data and data protection, the cookie laws are concerned with tracking users online. GDPR applies to all data (not just websites), the cookie laws deal with what websites can do. They are not at all the same thing. The popups you see tend to be for the cookie law, because GDPR doesn't require anything like that. Both do require consent (opt-in) though, but both also have exemptions for data and cookies required to provide the service.
Twitter are specifically saying that they’re going to use cookies for a bunch of things there that are not necessary - like ads. So how is that allowed?
If you're an online business established outside of the EU with no presence in the EU then as long as you abide by the data protection laws of your own country I don't see how an EU country's data protection authority could do anything to you.
This is a general issue online where sites and potentially services can be reached and used globally whilst each country basically cannot do anything outside of its own borders.
The part of the GDPR that says that the regs apply worldwide as long as the individual is in the EU is not really realistic in many actual situations.
In some cases bad actors exploited GDPR for fraudulent purposes - eg. requesting a full account deletion in the event of a ban. They can then recreate the same account with the same data.
Just because the effects are not obvious to a layman, doesnt they aren't there
Right to restriction of processing is not right to restriction of storage. Trying to re-register with your banned e-mail address is consent to processing and subsequent refusal to serve the person.
Good for them.
Looks like in the UK there will be a lot less time wasting clicking on useless "Accept all cookies or else" disclaimers pop-ups.
``` window.getPersonalDataPreferences() ```
It should only prompt the user to submit their preferences if no preferences were detected, or a specific permission is required to allow certain features.
People may argue that everyone will just turn everything off everywhere and forget about it, and I would argue "so what?".
The burden of GDPR has been dumped on the wrong people and has become so tedious to administer it's basically useless and a massive waste of time and energy.
The GDPR applies when any processing of any data is done regardless of context.
Have you even read it? The GDPR is a quite straightforward piece of legislation.
A pdf copy of it runs to 156 pages. Not particularly straightforward.
Can you sum what the legislation does up in a couple of paragraphs?
Does this mean no more of those stupid little popups every time I see a site? HOORAY.
Does it mean less absurd bureaucracy and non-jobs? GREAT.
As for data privacy... does anyone seriously think that Facebook was stopped from collecting data due to GDPR?
Have you ever tried browsing many US news sites? They block the entire EU from even seeing their content. That's how much they care about their in-GDPR users. The idea that people cater to a global audience by just implementing the EU rules for everyone is patently false. If the UK diverges, it's free revenue to just add it to the whitelist, basically.
Sites where I have granted access keep asking me to re-grant no matter what. Sites where I have denied do the same (although here I would expect it, not that I agree, since I already clicked "no").
And actually it's cool, sometimes you go to some docs and there's 33 "essential" cookies for the well functioning of the website (for a paid product) from which 30 are trackers.
Others, like wetransfer will show them as non-essential when receiving a file, but about the same amount of trackers, and this is ok, it's well defined and they're not trying to trick me into clicking "accept essential cookies" with 30 trackers tackled on them.
Perhaps one day we can start blacklisting those who don't implement a correct consent cookie form from the internet and dns wouldn't resolve for those non-compliant domains.
Sometimes people talk about technological solutions to social problems. I think here the tech solution (like tracker blocking) kind of works, like I can use it on Firefox or Safari and it doesn't waste my time; and the legal solution is a failure.
https://www.decisionmarketing.co.uk/news/facebook-sets-aside...
Right to delete (not just deactivate) your account only exists due to gdpr.
Right to opt out at all only exists because of gdpr, and many companies do actually stick to it.
That many don't follow the spirit of the regulation is not really the fault of the regulation. Thing is its not been tested much in the courts yet, but the cases have really started last year so hopefully more enforcement incoming.
I doubt that since takeout precedes gdpr by several years.
Comments skip straight to how dumb we all are.
:shrug:
Who will create forum for a community if one has to deal with all the bureaucracy, "right to be forgotten", data accuracy checks, data export request, gathering consents, being responsible for bugs in some forum software if there will be data leak and risk huge fines if something is not done correctly.
Another issue is vagueness of the regulation. What exactly is data processing/controlling? If kids leave they clothes in kindergarten or school, can clothes be signed with kid first and last name (so it is easier to find lost items)? Is school a processor or controller of kids' PII in that case? Probably not, but who knows what will happen if someones signed hat will be stolen?
Forums do not necessarily require personal information to exist.
AND EVEN THE RANDOM UUID THAT YOU ASIGN TO USERS ON YOUR FORUM BECAUSE YOU'VE GIVEN UP AND ONLY IDENTIFY USERS BY THAT AND THEIR PASSWORD.
In effect everything where a user has to input something instead of being just a recipient, or where the user is connected to any persistent identifier contains PI according to GDPR.
Say bye bye to most kinds of technical server logs used to debug stuff, to your database, and storing stuff in general.
The only way to be truly GDPR compliant if you followed the law to the letter would be to just provide TV and Teletext service via radio waves.
> Who will create forum for a community if one has to deal with all the bureaucracy, "right to be forgotten"
Most forums are created with softwares handling everything, virtually nobody creates a forum from scratch with his own tech stack.
> If kids leave they clothes in kindergarten or school, can clothes be signed with kid first and last name (so it is easier to find lost items)? Is school a processor or controller of kids' PII in that case?
People asking these kind of questions are either trolling or making their life much harder than necessary.... The text is pretty simple if you read it in good faith and don't act like a 6th grader who doesn't want to do his homework and pretend he doesn't understand the question...
Do you think GDPR is aimed at facebook &co storing millions of users data without the immediate business need nor the consent for it ? or at kindergarten kids who have their name written on their clothes ?
If you don't host the forum yourself you need a data processing agreement with the hoster to be GDPR compliant. If you want to load the user image from Gravatar, you need a DPA with Tumblr. Good luck with that.
Reading contracts and laws in good faith is a pretty bad idea if you don't like being sued and loosing. Always read laws in a way as if someone was going to use it just to ruin your day.
The centralization of the web on very few commercial platform has many reasons, data protection is probably the least important and might even be a counter-force in my experience.
I'm afraid your example is a prime case of that - leaving a hat at school that happens to have your name on it clearly doesn't fall within the remit of data processing under GDPR, it's a strawman (straw boater?) argument
I also don't agree it's a bad thing to make no distinction on size of company, doing so would leave a grey area of when a thing becomes "big enough" to transition from outside to inside scope and therefore gaps in the enforcement.
If you want to build a hobby forum, you're free to do it without requiring my personal data. If you want to collect my data for analysis or marketing then I absolutely want you to abide by the rules and look after it even if you're a lone programmer in his basement.
In the end though, you don't have to go crazy about it, because there is zero chance of enforcement over small pebbles.
Moreover, they don't want to copy any of the successes - e.g. their public housing system or strict "you WILL go to prison if you overcharge" price controls on medical care.
They just want the tax haven, deregulation, an under the thumb easily exploited workforce working themselves half to death and handouts to their friends.
As for exploitation of workers, Singapore has seen massively more wage growth than the UK over the last 50 years, so I don't equate a free labor market with exploitation.
I will add that there are important ways in which the UK is more conducive in the long run to a free market and free society than Singapore, but at least in the short run, Singapore's simulation of a free market economy has been offering more practical liberty and working better at raising living standards.
Ideally, the UK would maintain its pluralistic and democratic core, while adopting Singapore's economic policies.
no matter how much I like this idea, this will never happen in a European country unfortunately. there's just too much baggage of big state and other nonsense.
GDPR does not prevent EU government from handling their citizens personal data for bureaucracy.
However a good example of GDPR applying to the government is the COVID tracking app built by (for?) the French government, which still has to provide ways to opt out from tracking + clean your personal data.
I think that's what the GP was talking about.
Not to say that the necessary technology (big data, ML etc.) is to a great extent driven by commercial applications - and businesses should have economic incentives to develop them further.