Hacker News new | ask | show | jobs
by ericb 2972 days ago
I think there might be some pretty draconian side effects to properly implementing GDPR, but I'd like to hear from someone who knows to what extent these things might be true:

* The legal tracked information includes IP addresses, which means all logs must be able to selectively expunge IP address info.

* You can no longer have soft-deletes as a safety mechanism to maintain referential integrity if your data is (as is common) related to a user/account as you are responsible for being able to expunge that data.

* There are no exemptions for first time visitors, which means you can't just put up a no-EU unwelcome mat and serve up any third party tracking.

* The penalties are pretty draconian for a small business.

* It looks like retargeting businesses might be in trouble? Maybe?

1 comments

The penalties given are a max figure. A small business isn't going to be fined 20 million euros for slipping up. In fact, in the UK the ICO have stated that their preference is to avoid having to impose penalties as much as possible.