345 karma · joined October 30, 2017
1) Before email I had more letters and phone calls
2) If you disrupt your flow to answer emails and that is not mandated by your manager, that is your fault.
3) If you disrupt your flow to answer emails because your manager insists, then that is your managers fault.
I personally don't even notice emails arrive while I am in the zone. I answer them in batches once free.
When I do a new OS install I will try pipenv again...but it dind't work well for me the first time due to conflicting with something I had installed outside of a virtualenv!
Except with GDPR all you could do is report them to the member states governing body. So no trolling.
> Very Specific and not open to interpenetration
Except this makes them inflexible and leads to them having to be constantly redrafted. So no use to the world of the HN.
> Have options for "settlement" as this rewards the guilty, and harms the innocent
GDPR is between you and the regulator, they already do this work and the whole aim of the process is to stop you doing bad things. A fine is a late step in the process for organisations who wont listen.
> Have more public resources for people with limited resources. Law firms and Large corporations use Legal Expenses has a weapon in Civil Courts over smaller companies due to the high costs and generally no public resources for Civil access
Is off topic when it comes to GDPR, see my previous answers
> All Civil Cases must have to show Actual Damages not Theoretical Damages
Again off topic with GDPR, but in the UK that is how damages works already, isn't it?
In the UK the ICO is the governing body, and they say I don't need one. From their guidance linked below
>The GDPR introduces a duty for you to appoint a data protection officer (DPO) if you are a public authority, or if you carry out certain types of processing activities.
I am neither a public authority or carry out those certain types of activity.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
But not all of them have a good reason to log it. /dev/null
> It's not even remotely okay to use random people's blog posts as a compliance strategy.
Then use the simple, human friendly guide from the body who will be enforcing it in the UK. I did. I thought it was simple.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
The big number max fines in GDPR are there to deal with companies like Google and Facebook who can write of $5m as a rounding error.
People who have been fined at all under the existing DPA, being enforced by the very same people as GDPR, have been negligent, repeat offenders. I don't believe anyone has ever received the maximum fine in the existing regulations. That just isn't how UK law works
And the differences in the legal systems specifically. I think this is why a lot of HN commentators are finding the GDPR vague. In the US rule based regulations are the norm. For better or worse this tends to allow those with clever lawyers to search for loopholes. UK law is much more principle-based, which means trying to abuse the exact wording is not going to save you from a fine, and equally a technical-breach of wording is not going to get you prosecuted. It's not just the civil servants that we trust with this, it is the judges too.
I can tell you as someone who is working in an old school retailer/wholesaler we are not, and neither is anyone we are talking to through various trade bodies, employing lawyers to do GDPR.
"Peter Lecount, an assistant engineer of the London Birmingham railway, produced a number of - possibly hyperbolic - comparisons in an effort to demonstrate that the London and Birmingham Railway was "the greatest public work ever executed either in ancient or modern times".[4] In particular, he suggested that the effort to build the Great Pyramid of Giza amounted to the lifting of 15,733,000,000 cubic feet of stone by 1 foot (say, 450,000,000 m3 by 0.3 m).
The railway, excluding a long string of tasks – drainage, ballasting, and so on – involved the lifting of 25,000,000,000 cubic feet (say, 700,000,000 m3) of material reduced to the weight of stone used in the pyramid. The pyramid involved, he says, the effort of 300,000 men (according to Diodorus Siculus) or 100,000 (according to Herodotus) for twenty years. The railway involved 20,000 men for five years. In passing, he also noted that the cost of the railway in penny pieces, was enough to more than form a belt of pennies around the equator; and the amount of material moved would be enough to build a wall 1 foot (305 mm) high by one foot wide, more than three times around the equator."
https://en.wikipedia.org/wiki/London_and_Birmingham_Railway#...
TlDr;
Modern construction techniques do not require lifting heavy blocks of stone, so no-one makes a machine to do it.
If you have a reason for keeping them think about who needs to see them again and on what timescale. As other poster mentioned legal reasons override GDPR.
How big are your logs? Do you really need them?
Which they explicitly choose to do
> some use their real names as their username
Which is not required to use the site
> the site asks for email addresses
But you don't have to give one. If you do give one it is only used for password resets. Write that in your privacy policy and keep the email safe.
> Any website could claim they need IP addresses for analyzing malicious use
Yes they can, and the law allows it. Don't sell them to data aggregators and put it in your privacy policy why you are keeping it. If you don't want to then send the logs to /dev/null
> or the EU will decide
The courts will decide.
> The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
What do you want from the EU? A law that references the internet protocol explicitly, and every possible use of it? What happens when the protocol changes, or someone invents a new protocol, or a new way of exploiting it? Pass another law that says the same thing? Laws in the EU are generally principle based for exactly this reason, they age much better.
> Here's what will really happen to HN - nothing
Because they are doing nothing wrong!
I get my water from a private company. Should they be forced to supply me with clean drinking water, counter to it's financial interests? Presumably it would be cheaper to just pump it out of the river into our homes?
And that is the problem, Google has risen to utility level dominance, and utility level importance. Millions of peoples jobs rely on search and search results, time for regulation.
1) Act in good faith. DPA fines seem to have been to people who had a blatant disregard for data protection and their customers, not those who tried hard but committed some technical breach.
2) Whenever new rules come out there is a long period of interpretation. Unless you are in a very high risk category I wouldn't 'throw the baby out with the bath-water' in the interim.
3) Documentation wins court cases.
4) Personally I was already trying not to have my data stolen, so I am not overly concerned by GDPR. I am updating some policies, employee handbooks and terms. I will watch how other companies deal with it before I act too rashly.
1) It was not their main role
2) It was a token gesture, someone to address post too!
Every consulting firm I know is trying to sell GDPR services atm...
2) Prioritization
3) If non-urgent then take the time to make good decisions
4) Discussion in person is best, phone is second best, email is worst
5) Don't underestimate the work other people do, or their attitude to it