HN user

Fraaaank

99 karma
Posts2
Comments41
View on HN

From a compliance POV it's not enough. For example: "<NAME PERSON ONE> is president of the United States" is still identifiable even though the name has been redacted.

Since you can't be 100% certain that a filter redacts all personal data, you'd have to make sure that you have measures in place which allow OpenAI to legally process personal data on your behalf. Otherwise you'd technically have a data breach (from a GDPR pov).

And if OpenAI can legally process personal data on your behalf, why bother filtering if processing with filtering is also compliant?

Consent-O-Matic 6 months ago

According to the EU law if you don’t click accept it’s equivalent to denying.

The result is the same. Technically there's no such thing as denying, only providing (explicit) consent. If consent is required and no consent is provided, then there is no ground for processing.

Electronic invoicing makes the live of the receiver easier. The sender has to adapt the standard.

Besides, many standards have been created over the past 20 years, yet most invoices are still only sent as PDF.

Not entirely true. If I'm incorporated in country A and want to offer a service in country B, I'll have to comply with the local regulations. Furthermore, most VPNs have local presence in the EU as well. NordVPN is incorporated in Panama, but also has an entity in The Netherlands.

I should've been more specific. The study you link states that 'To prevent vitamin D deficiency, one should spend 15 to 20 minutes daily in the sunshine with 40% of the skin surface exposed.'. The screenshot on lume health shows a goal of 120 minutes.

Moreover, sun exposure is not by definition 'healthy'. Spending two hours in the sun at noon in the middle of summer does more harm than good.

Original Text: "Bruh, that party was straight outta Ohio, no cap. Skibidi vibes only. Tyler’s drip was bussin’, and Jessica was ghostin’ everyone like she hit airplane mode IRL."

Finally, words I can understand

You can also anonymize data and that is no longer considered personal data under GDPR so it is possible to hash an IP address and that be acceptable.

That's not completely true. Recital 26 of GDPR stipulates that

“information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.”

Hashing does not meet this threshold. If the same IP address is hashed using the same method, the result will always be the same, meaning it can be matched. Hashing is therefore considered pseudonimization and under GDPR, pseudonymized data is still considered personal data.

Moreover, the act of anonymization itself is a form of processing and therefore falls under the scope of GDPR. So even attempting to anonymize personal data doesn't remove GDPR obligations for the anonimyzation itself.

There isn't any rule that requires websites to use a cookie banner. Your required to obtain explicit consent before reading/setting any cookies that aren't strictly necessary. The web came up with the cookie banner.

Google could've implemented a consent API in Chrome, but they didn't. Guess why.

Very original, I like it! Do you also have the option to schedule a call when either person is not available? Or should you offer your customers to either call you via OnAir, or schedule via (e.g.) Calendly?