> But, it turns out, most of these emails are pointless. "In the UK it has been the law since 2003 that you can only send a marketing email to an individual recipient when they have consented to receive it or you have an existing customer relationship with them and have offered them the opportunity to opt out," explains Jon Baines, data protection advisor at law firm Mishcon de Reya.
> So why are they sending these emails? It's largely around the fear of GDPR. The regulation says companies can be fined up to €20 million or four per cent of their annual global turnover. Many companies are keen to get their systems in order. Although in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines.
TL;DR: It's basically CYA and checking things that they weren't doing before now that they should have been doing
Actually, I am happy they are sending these. I hope it is really working and they will delete my data as there was not one I approved again.
Job recruiter sites were asking me if I allow sending more emails and as it is practically impossible to unsubscribe from them I will be glad if GDPR makes them stop.
It doesn't seem to be working that way. I only receive informational emails that do not require any action and will not result in deletion of any data.
Have a look through my promtions inbox in gmail and fine everyone of them.
What we need is a tickbox that says do you want all your spam senders fined.
I do wonder if in fact Google is involved in a fair few of them.
Those dumb emails I am getting are not a problem, for me at least. Infact it’s a good opportunity to remove myself from some communications which are no longer relevant.
The biggest problem was the previous directive, which meant all EU websites display an intrusive message about cookies which needs a click to dismiss. That is the most dumb thing I encounter. And continue to encounter on a daily basis.
I find it annoying that every single one of those messages say something to the effect of "We use cookies to improve your user experience", when 99.9% of the time, the only reason you need third-party cookies is user tracking.
Maybe that law should've included a clause about how you shouldn't lie about why you're using third-party cookies?
Both can be true. Why track users? So you can see common paths they take, common stumbling blocks, if feature A is better than feature B, etc, etc. Also ad tracking (supposedly) helps deliver more personalized ads that are actually relevant to the user.
So they argue that tracking does improve user experience. You may disagree with their reasoning but that doesn't make them liars.
> Maybe that law should've included a clause about how you shouldn't lie about why you're using third-party cookies?
In theory the GDPR/EU Data Protection law covers that. If people consent to one thing, then they haven't consented to to the other thing. So you can't lie to get their personal data.
The GDPR is certainly to blame for all of those dumb emails you're getting.
"in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines"
Unless the information commissioner is immortal and is appointed for life there are no guarantees that this will always be the case. Companies read the law and see that they can be fined up to €20 million or 4% of their annual revenue (whichever is greater) and act accordingly. The GDPR is especially pernicious as its scope reaches beyond the boundaries of the European Union. If you're an American company and a single European citizen uses your services you are bound by the GDPR's regulations.
Some people claim that the court system in the EU is more judicious than the United States. For those people I want to ask "Why should I trust the opinion of the people who are going to sue me if I am found to be noncompliant". If you think the people covering their butts are being irrational, read the law again.
It's not that the law wants to apply to you but it doesn't have weight because they can't enforce anything against you, as is often heard on HN. It's that the law doesn't want to apply to you.
The criterium for whether a non-EU company needs to comply to GDPR is: does the company intent to seriously service EU citizen? This is determined based on multiple factors, such as the website's language (do they have e.g. German translations?), providing pricing in euros, testimonials from EU customers, or having a contract with a parcel company with the specific intention of delivering to EU customers. The mere fact that the website can be used by an EU citizen is not enough to have it fall under the GDPR.
> The criterium for whether a non-EU company needs to comply to GDPR is: does the company intent to seriously service EU citizen? This is determined based on multiple factors, such as the website's language (do they have e.g. German translations?), providing pricing in euros, testimonials from EU customers, or having a contract with a parcel company with the specific intention of delivering to EU customers. The mere fact that the website can be used by an EU citizen is not enough to have it fall under the GDPR.
Hey, thanks a lot for this. It seems these days the noise is larger than the signal. Hard to find anyone putting careful thought into this. Thank you.
That is not under dispute. Of course you should be careful with legal advice that isn't tailored for your specific situation. My comment does not contradict that notion. The content of the book also does not contradict that notion. The book explains the general situation and gives generic advice. But even generic advice is useful to a degree. It does not replace seeking specific advice from a lawyer, but it does complement it. Specific and generic advice are not mutually exclusive.
There is nothing you have said that a business who can potentially be fined to death, rely upon.
The fact that every response to the criticism of GDPR being too ambiguous, is ambiguous, only proves critics right. EU lawmakers picked worst combination: huge fine + huge ambiguity. This all could have been done with more certainity. So sad.
Ambiguity is the way to deal with a changing landscape and changing technologies.
And I agree it sucks, but it sucks less than the alternative (which is to be rigid and say something that becomes meaningless one year after the law is published)
It's not as easy as that. As I stated, the criterium for GDPR compliance for non-EU businesses is "does said business intent to seriously do business with EU citizen?". Pricing in EUR is merely one of the multiple possible factors that a judge would use to determine whether this is the case.
I'm not a lawyer so I'm not in a good position to evaluate Github. But I do know that Github has an office in Amsterdam, The Netherlands, so there is at least the possibility that they have to be GDPR compliant.
But let's say you're buying from a random small business web shop in the US, and everything about that web shop clearly screams that their main business intention is work with US customers, it's just that their delivery service happens to ship world wide even though they clearly don't care about non-US customers. Then yes in theory they can "what they like with my data". In practice they probably have to define what "what they like" means in a contract, like a privacy policy, so it's not as if you can't know about what they will do. You are still able to make an informed decision of whether you want to do business with them.
Can you provide a reference in the text of GDPR itself or an official government source such as the UK ICO that supports that criterion for determining if a company needs to comply with GDPR?
Your description does not match with what I have seen about GDPR applying to European data subjects which is the language the regulation uses.
I am not a lawyer myself, it is not very useful to ask me to reference a text in the GDPR. It is far more useful to consult a lawyer. The information I posted is from a lawyer's book, translated almost literally from Dutch to English.
The GDPR is perfectly straightforward to interpret and apply. It's remarkably similar to the existing Data Protection Directive. If you are using data in a specific, explicit and legitimate way, you have nothing to fear from the GDPR. It only seems radical because tech companies have operated with relative impunity in the past, hoovering up data en masse with no regard to the privacy or security of their users.
Article 83 clearly states that penalties must be proportionate to the scale of the breach, the impact on users, the intentional or negligent character of the breach and the degree of co-operation with the supervisory authority. A supervisory authority can't just bankrupt your company out of spite.
Your bio says that you're a founder of a company that processes healthcare data. The maximum civil penalty for HIPAA violation is a fine of $50,000 per violation and there have been several multimillion dollar penalties. The maximum criminal penalty is 10 years imprisonment. If you're worried about GDPR, you should be absolutely terrified of HIPAA.
Why, I used to be a HIPPA architect and basically the government (and even more this one) ignored all evidence of HIPPA violations. Our compliance was a complete joke, covered by some fancy "audit" which failed to ask a single question. Laws don't matter unless they enforced.
> Your bio says that you're a founder of a company that processes healthcare data. The maximum civil penalty for HIPAA violation is a fine of $50,000 per violation and there have been several multimillion dollar penalties. The maximum criminal penalty is 10 years imprisonment. If you're worried about GDPR, you should be absolutely terrified of HIPAA.
Yes, I also find this hilarious, people love to spread FUD about the GDPR, but HIPPA is more serious (though limited in scope).
I think the scope differences between HIPPA and GDPR, as well as the specificity of some of the language used, are key factors in why someone might disagree with GDPR, but not HIPPA.
Those chapters and sections are logical and clearly written. It's very easy to figure out which provisions apply to your business and what action you need to take. The ICO have provided extensive guidance and a toolkit for assessing your GDPR compliance.
If you're making a hardware product for the US market, you need to comply with FCC Title 47 Part 15. If you've never been involved in this process, I'd encourage you to read it. The rules governing a bluetooth speaker are at least as complex as the rules governing Facebook and Google's hoard of personal information.
> Unless the information commissioner is immortal and is appointed for life there are no guarantees that this will always be the case.
Not wishing ill on that particular person, but I actually hope they'll change their mind or get replaced by someone who is heavy-handed with fines.
Because that's the whole point. The reason so many people (myself included) are so impatiently waiting for May 25th is because GDPR has teeth, and can actually do some serious damage to companies continuing to abuse people's data. So if companies are now sending those e-mails because they're afraid, I am happy, because it's evidence that GDPR works.
As it happens I just received an email from Kickstarter informing me about their policy changes due to GDPR, the mail does not contain an not opt-out or unsubscribe link !
That is required by GDPR, or at lease good practice right ?
Those emails are awesome and any company sending looks better in my book.
That said I never accept their plead, I absolutely never ever sign up to any kinds of email marketing so the ONLY reason they even attempt this is because they were doing shady business earlier.
I bet that we will see lots of complaints where companies cry of losing their audience. Well first off it was an illegal channel anyway and second noone read your mail anyway.
GDPR is one of few things that honestly gives me hope for the future of internet. It has the potential to embed a consciousness of how data is managed, both in companies and users.
The point is that those emails are clear signs that companies are ignoring existing laws. It's already illegal, under PECR, to send marketing email to people without their permission.
This should be somewhat reassuring to all the GDPR alarmists: we have very many companies ignoring the law at the moment, but not being fined.
Rereading GP I might have misinterpreted a bit (the above still stands though).
I see two kinds of emails. One is along the lines that "FYI: we updated our policies regarding X", those are perfectly fine.
Then we have "please click here to allow us to send you more emails", which is more or less admitting "hey, we abused the system and spammed you before, please let us continue to do so".
And I actually get a smile on my face when I receiver either of them. Yes, the second one should be really bad but I already knew that. The signal I get from the second email is "hey, we're not particularly happy about the situation but we will at least obey the new law". And that makes me happy for many reasons.
I don't understand this article. It's entire argument is there was already a law in the UK preventing unsolicited emails, but nobody was following it. Now that the GDPR has huge fines, there is a lot more liability. Seems its exactly the GDPR to blame...
It's also that they had insufficient recording of how consent was given (which GDPR was stricter on).
So lots of firms, including some I've worked with, have huge mailing lists with addresses from multiple sources and are _pretty sure_ they got consent in all of those cases, but have no way of showing that if asked.
They are _pretty sure_ they got consent, i.e. they know they didn't, and half of those lists are probably from shady sources. GDPR without requirements for audit trail would be useless.
I think it's the wording. You say "Seems it's exactly the GDPR to blame", but you could've said "the GDPR is to credit" and it would be equally true. The thing is that those two have different conotations. The first suggests that GDPR is bad (for motivating companies to follow UK law, which is bad), the second suggests that GDPR is good (for motivating companies to follow UK law, which is good).
Personally I would prefer more neutral language. Something like "As a consequence of GDPR, companies have started changing their behavior from X to Y." If you want to give the readers context you could optionally add "Y is already law in the UK, but UK prosecutors have for the most part chosen not to enforce it."
The title is saying "companies think they need to do a bunch of stuff because GDPR, but really they already needed to be doing that stuff under existing law".
57 comments
[ 3.0 ms ] story [ 115 ms ] thread> So why are they sending these emails? It's largely around the fear of GDPR. The regulation says companies can be fined up to €20 million or four per cent of their annual global turnover. Many companies are keen to get their systems in order. Although in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines.
TL;DR: It's basically CYA and checking things that they weren't doing before now that they should have been doing
Job recruiter sites were asking me if I allow sending more emails and as it is practically impossible to unsubscribe from them I will be glad if GDPR makes them stop.
The biggest problem was the previous directive, which meant all EU websites display an intrusive message about cookies which needs a click to dismiss. That is the most dumb thing I encounter. And continue to encounter on a daily basis.
Maybe that law should've included a clause about how you shouldn't lie about why you're using third-party cookies?
So they argue that tracking does improve user experience. You may disagree with their reasoning but that doesn't make them liars.
In theory the GDPR/EU Data Protection law covers that. If people consent to one thing, then they haven't consented to to the other thing. So you can't lie to get their personal data.
Block them with your chosen ad blocker.
"in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines"
Unless the information commissioner is immortal and is appointed for life there are no guarantees that this will always be the case. Companies read the law and see that they can be fined up to €20 million or 4% of their annual revenue (whichever is greater) and act accordingly. The GDPR is especially pernicious as its scope reaches beyond the boundaries of the European Union. If you're an American company and a single European citizen uses your services you are bound by the GDPR's regulations.
Some people claim that the court system in the EU is more judicious than the United States. For those people I want to ask "Why should I trust the opinion of the people who are going to sue me if I am found to be noncompliant". If you think the people covering their butts are being irrational, read the law again.
https://gdpr-info.eu/
And also an indication that GPDR might be working.
That isn’t really true. If you have no legal presence, no employees, no offices, etc in Europe, enforcement actions cannot be taken against you.
The law may say you’re in scope, but that’s only relevant within areas where EU laws have any weight.
https://news.ycombinator.com/item?id=17058645
It's not that the law wants to apply to you but it doesn't have weight because they can't enforce anything against you, as is often heard on HN. It's that the law doesn't want to apply to you.
This is false. I blogged about this topic a while ago: https://www.joyfulbikeshedding.com/blog/2018-04-17-should-no...
The criterium for whether a non-EU company needs to comply to GDPR is: does the company intent to seriously service EU citizen? This is determined based on multiple factors, such as the website's language (do they have e.g. German translations?), providing pricing in euros, testimonials from EU customers, or having a contract with a parcel company with the specific intention of delivering to EU customers. The mere fact that the website can be used by an EU citizen is not enough to have it fall under the GDPR.
Source: the book "Handbook GDPR, Compliance in practice" (page 11) by Arnoud Engelfriet & co, a Dutch IT lawyer. https://ictrecht.nl/boeken/handboek-avg-compliance-in-de-pra...
Hey, thanks a lot for this. It seems these days the noise is larger than the signal. Hard to find anyone putting careful thought into this. Thank you.
The fact that every response to the criticism of GDPR being too ambiguous, is ambiguous, only proves critics right. EU lawmakers picked worst combination: huge fine + huge ambiguity. This all could have been done with more certainity. So sad.
And I agree it sucks, but it sucks less than the alternative (which is to be rigid and say something that becomes meaningless one year after the law is published)
I'm not a lawyer so I'm not in a good position to evaluate Github. But I do know that Github has an office in Amsterdam, The Netherlands, so there is at least the possibility that they have to be GDPR compliant.
But let's say you're buying from a random small business web shop in the US, and everything about that web shop clearly screams that their main business intention is work with US customers, it's just that their delivery service happens to ship world wide even though they clearly don't care about non-US customers. Then yes in theory they can "what they like with my data". In practice they probably have to define what "what they like" means in a contract, like a privacy policy, so it's not as if you can't know about what they will do. You are still able to make an informed decision of whether you want to do business with them.
Your description does not match with what I have seen about GDPR applying to European data subjects which is the language the regulation uses.
Article 83 clearly states that penalties must be proportionate to the scale of the breach, the impact on users, the intentional or negligent character of the breach and the degree of co-operation with the supervisory authority. A supervisory authority can't just bankrupt your company out of spite.
https://gdpr-info.eu/art-83-gdpr/
Your bio says that you're a founder of a company that processes healthcare data. The maximum civil penalty for HIPAA violation is a fine of $50,000 per violation and there have been several multimillion dollar penalties. The maximum criminal penalty is 10 years imprisonment. If you're worried about GDPR, you should be absolutely terrified of HIPAA.
Yes, I also find this hilarious, people love to spread FUD about the GDPR, but HIPPA is more serious (though limited in scope).
How can anything with 11 chapters and 99 sections be "straightforward to interpret and apply"?
https://gdpr-info.eu/
https://ico.org.uk/for-organisations/guide-to-the-general-da...
If you're making a hardware product for the US market, you need to comply with FCC Title 47 Part 15. If you've never been involved in this process, I'd encourage you to read it. The rules governing a bluetooth speaker are at least as complex as the rules governing Facebook and Google's hoard of personal information.
https://www.ecfr.gov/cgi-bin/text-idx?SID=91a501119ab6978f87...
Not wishing ill on that particular person, but I actually hope they'll change their mind or get replaced by someone who is heavy-handed with fines.
Because that's the whole point. The reason so many people (myself included) are so impatiently waiting for May 25th is because GDPR has teeth, and can actually do some serious damage to companies continuing to abuse people's data. So if companies are now sending those e-mails because they're afraid, I am happy, because it's evidence that GDPR works.
Yeah, no. You're wrong.
Thanks for the link, if you had actually read it, it would have listed all the criteria for applying penalties.
https://gdpr-info.eu/art-83-gdpr/
> "Why should I trust the opinion of the people who are going to sue me if I am found to be noncompliant"
Because that's what people (and lawyers) do in every case concerning regulatory bodies
That said I never accept their plead, I absolutely never ever sign up to any kinds of email marketing so the ONLY reason they even attempt this is because they were doing shady business earlier.
I bet that we will see lots of complaints where companies cry of losing their audience. Well first off it was an illegal channel anyway and second noone read your mail anyway.
GDPR is one of few things that honestly gives me hope for the future of internet. It has the potential to embed a consciousness of how data is managed, both in companies and users.
The point is that those emails are clear signs that companies are ignoring existing laws. It's already illegal, under PECR, to send marketing email to people without their permission.
This should be somewhat reassuring to all the GDPR alarmists: we have very many companies ignoring the law at the moment, but not being fined.
That is awesome.
I see two kinds of emails. One is along the lines that "FYI: we updated our policies regarding X", those are perfectly fine.
Then we have "please click here to allow us to send you more emails", which is more or less admitting "hey, we abused the system and spammed you before, please let us continue to do so".
And I actually get a smile on my face when I receiver either of them. Yes, the second one should be really bad but I already knew that. The signal I get from the second email is "hey, we're not particularly happy about the situation but we will at least obey the new law". And that makes me happy for many reasons.
So lots of firms, including some I've worked with, have huge mailing lists with addresses from multiple sources and are _pretty sure_ they got consent in all of those cases, but have no way of showing that if asked.
Personally I would prefer more neutral language. Something like "As a consequence of GDPR, companies have started changing their behavior from X to Y." If you want to give the readers context you could optionally add "Y is already law in the UK, but UK prosecutors have for the most part chosen not to enforce it."