Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

131–140 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#131
post #123

I encourage a little more thought before cheering this on as a win. While GDPR isn't as ridiculous as the Cookie Law, it still shows that the EU/EC don't understand the technology they are trying to regulate, and it comes at a huge cost to tech companies. Take the right to be forgotten . First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't…

I believe that in many countries there has been laws for a while mandating the deletion of personal data after a certain number of years (for instance I believe this is the case in banking). This is not new and if your backup system does not comply with regulations, it's probably more of a design problem.

This is not new and if your backup system does not comply with regulations, it's probably more of a design problem.

Perhaps, but it's a design problem that approximately 100% of otherwise reasonable backup systems will have, and working around it comprehensively will be extraordinarily expensive.

Do we really want to impose rules that incentivize businesses storing personal data on behalf of their customers not to back that data up properly, in order to avoid any potential liability under the GDPR? Because that's exactly what this law does, as it stands.

Re: How the GDPR Will Disrupt Google and Facebook

#132
post #41

I see this as yet another tax on (European) startups who have to invest even more resources into regulatory compliance. This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation. I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society.…

> as those players can easily shell out another $10M here and there to be compliant with this regulatory monster. Sounds like you missed the part where the fines are based on a percentage of your global revenue.

Parent comment is talking about the cost of compliance, not fines for non-compliance.

Re: How the GDPR Will Disrupt Google and Facebook

#133
post #41

I see this as yet another tax on (European) startups who have to invest even more resources into regulatory compliance. This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation. I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society.…

To be honest, the Facebook, Amazon, Apple, Microsoft and Google of this world aren't the one that have been leaking the most personal data. It's the smaller companies and startups that have been leaking personal data at an alarming rate. What we are beginning to see now is the regulatory backlash. Regulations are inconvenient, expensive, create barriers to entry (ask bankers!). But the current pace of gathering then leaking of personal information is just unacceptable and unsustainable. Between the two evils, I am not sure I prefer the current statu quo.

Re: How the GDPR Will Disrupt Google and Facebook

#134

Are all companies beholden to this or those with legal entities in Europe. For instance, can a Chinese company with ZERO legal presence in the EU completely ignore these requirements? The internet has no real borders, after-all.

Yes.

If you process the personal data people in the EU then you have to comply:

Article 3

Territorial scope

1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

Re: How the GDPR Will Disrupt Google and Facebook

#136

I encourage a little more thought before cheering this on as a win. While GDPR isn't as ridiculous as the Cookie Law, it still shows that the EU/EC don't understand the technology they are trying to regulate, and it comes at a huge cost to tech companies. Take the right to be forgotten . First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't…

> First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't like the content, but that is what the EU has ruled should happen.

No, it is about deleting personal data attached to your user account, not "news articles". This thing intends to make the "delete my account" button to actually, you know, "delete my account", instead of fake-deleting it by setting a "deleted" flag and telling me that everything is gone now while still keeping gigabytes of data associated with me in your database.

> [...] meaning you need a way to ensure that "forgotten" users never get restored.

If this is considered to be a hard problem, then I assume storing some list of deleted users in a separate place and immediately purge those users from the backup after restore must be some kind of rocket science.

> There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.

I wouldn't call it "to become GDPR compliant", I would call it "to build a sound database structure". Because if you are unable to purge all data associated to one of your users' accounts from your system without destroying the integrity of the rest of your data, then you obviously have a half-baked system at your hands that lacks a core feature - to actually delete accounts. And you surely should spend some of your money to refactor this crap into a long-term viable solution while you are still small and agile enough to do that. Because it's only going to be way more expensive later on...

Re: How the GDPR Will Disrupt Google and Facebook

#137
post #133
post #41

I see this as yet another tax on (European) startups who have to invest even more resources into regulatory compliance. This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation. I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society.…

To be honest, the Facebook, Amazon, Apple, Microsoft and Google of this world aren't the one that have been leaking the most personal data. It's the smaller companies and startups that have been leaking personal data at an alarming rate. What we are beginning to see now is the regulatory backlash. Regulations are inconvenient, expensive, create barriers to entry (ask bankers!). But the current pace of gathering then…

Leaking PII isn't the main issue. Processing of PII is. And Facebook et. al. do a lot of that.

Re: How the GDPR Will Disrupt Google and Facebook

#138
post #123

Earlier quoted context omitted.

I believe that in many countries there has been laws for a while mandating the deletion of personal data after a certain number of years (for instance I believe this is the case in banking). This is not new and if your backup system does not comply with regulations, it's probably more of a design problem.

This is not new and if your backup system does not comply with regulations, it's probably more of a design problem. Perhaps, but it's a design problem that approximately 100% of otherwise reasonable backup systems will have, and working around it comprehensively will be extraordinarily expensive. Do we really want to impose rules that incentivize businesses storing personal data on behalf of their customers not to ba…

It feels like the reaction of a VW engineer complaining that CO2 emissions regulations are making his job complicated.

Yeah, if you want the data, you need to be able to handle the data in a compliant way. The other solution is to not collect the data. Keep in mind that this is targeted at user tracking. Don't expect me to be sympathetic to the troubles of backing up all of that tracking data.

Re: How the GDPR Will Disrupt Google and Facebook

#139
Might be easier for small niche companies with no offices in the EU but willing EU customers to ask for payment via a cryptocurrency.

It just seems to me in the long run, more and more laws like this will pop up, and using cryptocurrencies will get easier/ more familiar.

Re: How the GDPR Will Disrupt Google and Facebook

#140
post #137
post #133

Earlier quoted context omitted.

To be honest, the Facebook, Amazon, Apple, Microsoft and Google of this world aren't the one that have been leaking the most personal data. It's the smaller companies and startups that have been leaking personal data at an alarming rate. What we are beginning to see now is the regulatory backlash. Regulations are inconvenient, expensive, create barriers to entry (ask bankers!). But the current pace of gathering then…

Leaking PII isn't the main issue. Processing of PII is. And Facebook et. al. do a lot of that.

Yeah but they have the resources to deal with these regulations. The parent comment complains about smaller companies having to deal with these regulations.
Post reply on HN