HNHacker News
TopNewBestAskShowJobs

cccbbbaaa

257 karma · joined March 3, 2023

GDPR expert by hn standards.
submissionscomments
cccbbbaaa··on GDPR: Is It Worth It?
It already was equivalent under ePrivacy.
cccbbbaaa··on Translation of Rust's core and alloc crates to Coq for formal verification
I'm not sure which first step you are talking about. Typically, one would write the program directly in Coq and use the extracted code as-is.
cccbbbaaa··on Translation of Rust's core and alloc crates to Coq for formal verification
You can write programs in Coq and extract them in OCaml with the `Extraction' command: https://coq.inria.fr/doc/v8.19/refman/addendum/extraction.ht...

This is used by compcert: https://compcert.org/

cccbbbaaa··on Translation of Rust's core and alloc crates to Coq for formal verification
This is what happens in french classrooms when you talk about bits :-)
cccbbbaaa··on Biden signs TikTok bill into law, starting clock for ByteDance to divest
This decision is based on Schrems II, which does not really apply anymore since the DPF. Though the latter is already being challenged.
cccbbbaaa··on Serious security breach hits EU police agency
Thank you for the clarification.
cccbbbaaa··on Germany drafts law that will make E2EE mandatory for messengers and cloud
The important points here are “Taking into account the state of the art” and “appropriate technical and organisational measures to ensure a level of security appropriate to the risk”. For example, this case is cited in the page linked above:

https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_DI-2021-43...

> Sending an e-mail containing sensitive data with enforced TLS-encryption instead of end-to-end encryption was deemed insufficient secured under Article 32(1) GDPR.

cccbbbaaa··on Serious security breach hits EU police agency
> Unfortunately, national security services are not subject to GDPR or LED at all

They are AFAIK, but can be exempt of articles 12 to 22 under national law. What did I miss?

cccbbbaaa··on Serious security breach hits EU police agency
It's a myth that gets repeated here. In reality, it's more subtle. Laws can be the legal basis for some processing, if it is deemed proportional; and in some countries (eg. France), government agencies cannot be fined.

GDPR doesn't apply to EU activities related to foreign policy or law enforcement, but EUCFR articles 7 and 8 still apply, as does regulation 2018/1725 for the former, and directive 2016/680 for the latter–so in theory, some activities are indeed exempted from GDPR, in practice, they're still subject to data protection laws that require essentially the same measures as GDPR.

Source: GDPR article 2 and 6. On a more personal note, I've already requested my data under GDPR, cited WP29/EDPB guidelines, and filed complaints against various govt agencies.

cccbbbaaa··on GDPR Enforcement Tracker – list of GDPR fines
The violation happened in 2021. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs...

I'm actually surprised the ICO can fine the UK government. This can't happen in France, for instance.

cccbbbaaa··on Dear Paul Graham, there is no cookie banner law
You can find a lot of guidelines around GDPR or ePrivacy made by the EDPB or a DPA. For instance:

https://ec.europa.eu/justice/article-29/documentation/opinio...

This says that cookies for a shopping cart or user preferences are exempted from consent. The ICO and the CNIL say the same, as expected.

cccbbbaaa··on Dear Paul Graham, there is no cookie banner law
Cookies banner are a response to the ePrivacy directive from 2002.
cccbbbaaa··on European crash tester says carmakers must bring back physical controls
I had the same on a 2003 Twingo. Very handy, except for that time when I horned at a poor jogger on the side of the road instead of activating the turn signal :(
cccbbbaaa··on EU right to repair: Sellers liable for 1 year after products are fixed
No, ePrivacy article 5(3) always had an exception for strictly necessary purposes, with clear guidance of what it means from DPAs and WP29 (now EDPB). I agree with the rest of your message though.
cccbbbaaa··on Amazon Fined $35M in France over 'Overly Intrusive' Surveillance
It's a GDPR fine above 20M€, so it's already based on their income.
cccbbbaaa··on Airbus Shatters Record for Jet Orders as Demand Soars
Asseline can claim what he wants, but, unfortunately for him, the FDR and reconstitutions (performed in a simulator and in a real plane) do not back him up. And the only “proof” of FDR tampering comes from someone who did not understand what he was looking at.

Now, I don't want to be too harsh on him. AF set him up to fail (acknowledged by the BEA report), then threw him under the bus. I can understand why he chose the support of the SNPL, even if it meant going at war against the plane.

cccbbbaaa··on Airbus Shatters Record for Jet Orders as Demand Soars
AF296 crashed because the pilot selected TOGA too late for the engines to spool up in time, and was completely unprepared. There was no issue with the FCS, nor the autopilot which was disengaged.

For Airbus Industrie 129, it seems that the FCS was not the root cause of the issue, but I don't know a lot about this flight.

cccbbbaaa··on Meta unlawfully ignores the users' right to easily withdraw consent: complaint
https://noyb.eu/en/pay-or-okay-beginning-end

https://noyb.eu/en/pay-or-okay-tech-news-site-heisede-illega...

cccbbbaaa··on Alaska 737 cockpit voice recorder data erasure renews safety debate
No need to be confrontational, I'm not opposed to FDR/CVR streaming. I just dislike solutions to problems that have already been solved, and we were just pointing out that starlink does not bring anything to the table vs. ADS-B, radars, and inmarsat.
cccbbbaaa··on Alaska 737 cockpit voice recorder data erasure renews safety debate
We know where MH370 disappeared thanks to ADS-B, and after it was disconnected, it was still seen by primary radars.
cccbbbaaa··on EU lawmakers scolded for concealing identities of content-scanning experts
Le Pen has toned down her anti-EU stance a lot since Phillipot left the RN. Leaving was no longer part of her program for 2022, for instance.
cccbbbaaa··on EBCDIC Is Incompatible with GDPR
To be exact, companies with fewer than 250 employees are exempt of some obligations in article 30.
cccbbbaaa··on EU Chat Control Bill Postponed
The right to be removed from search results is not systematic, there is a balance to attain between privacy and public interest. Corruption charges from politicians will be hard to scrub, for instance. See:

GDPR, article 17(3)a: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

> 3. [Right to erasure] shall not apply to the extent that processing is necessary:

> (a) for exercising the right of freedom of expression and information;

More precise information from WP29. See the criteria list, beginning in page 13: https://ec.europa.eu/justice/article-29/documentation/opinio... This was from the DPD era, but still applies to GDPR.

How Google handles removal requests: https://support.google.com/legal/answer/10769224?hl=en&sjid=...

cccbbbaaa··on Irish privacy group files complaint against YouTube adblock detection system
Yeah, this specifically:

>The deployment of that js file itself requires consent

is an “interesting” interpretation of ePrivacy.

This:

>the running of the javascript within the browser to ascertain how the browser is behaving also requires consent

is true in some cases, eg. browser fingerprinting for tracking purposes.

cccbbbaaa··on Google has sent internet into 'spiral of decline', claims DeepMind co-founder
Consent was already required to be freely given under the DPD. Agree on the two other points, it seems that GDPR clarified this–I thought it was already covered by the DPD.
cccbbbaaa··on Google has sent internet into 'spiral of decline', claims DeepMind co-founder
No. Please read the ePrivacy directive (the so-called “cookie law”), especially article 5(3):

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

>3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

The directive:

(1) does not target cookies, but methods to store information, or gain access to information stored;

(2) allows strictly necessary purposes without consent or popups;

(3) requires consent for other purposes.

The directive talks about cookies in recital 25, but only as an example.

The GDPR replaces the Data Protection Directive (Directive 95/46/EC), and along that, references made to it in ePrivacy. But it does not bring anything new about cookies.

Though, I agree with you: the GDPR is well made–apart from the litigation part, but that's going to change with the GDPR Procedural Regulation. ePrivacy is good too, but 5(3) aged poorly, unfortunately.

cccbbbaaa··on Stop EU Chat Control
Stop with the FUD. GDPR is not enforceable if you respect 1-3. https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_161/2...
cccbbbaaa··on Stop EU Chat Control
You are wrong, cf. GDPR article 3. The Belgian DPA even ruled that GDPR is unenforceable if the controller is not located in EEA, does not serve anyone in EEA, and does not monitor EU individuals. https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_161/2...
cccbbbaaa··on Stop EU Chat Control
It was enforceable before too, thanks to the Data Protection Directive from 1995. GDPR is an harmonization of the various national transcriptions of the DPD, plus higher fines, a better cooperation mechanism, and data portability (which is a bit useless but it's nice to have). Cookie banners also predate GDPR (it was the ePrivacy directive).
cccbbbaaa··on Streaming service DAZN took almost five years to answer a simple access request
GDPR article 2(2)c. It will not apply to the receiver of the email, but maybe to the provider. Perhaps it depends on the kind of relationship between the two parties. Mailing lists will be covered.

Side note: I know someone who requested their data to their DPA, and part of the response contained emails mentioning them and their complaints in the _content_ of the message (they were not in the From:, To:, Cc:, or Cci: fields). All names and emails address were censored, though, in accordance with 15(4).

← PreviousPage 3 of 6Next →