Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

271–280 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#271
While I see some of the concerns about the _technicality_ of the law as completely legitimate, it still bothers me that so many people reject the whole spirit of this law, and cannot put the negative of "tax on startups" against the much greater good of personal privacy.

I've just started a business myself, and this regulation affects my company too. It makes development costlier; it'll take from the precious little time we have to spend on compliance paperwork rather than work on our core business. In the short run, it does hurt our chances of success.

Yet, none of the trouble is even comparable to what's to be gained here. And it bothers me (though doesn't surprise me) that some people don't see that.

It also bothers me that such vocal opposition barely comes up when the discussion is just about bigger companies such as Google and Facebook. How can we expect "un-evilness" from bigger companies when we're barely willing to do anything in that regard ourselves?

Re: How the GDPR Will Disrupt Google and Facebook

#272

Earlier quoted context omitted.

Yes, the EU regularly kicks the asses of companies to help consumers in Europe. I'm sure we won't get the same protection on pesticides, pharmaceuticals/medicine, GM, white goods, monopolistic practices like this, roaming charges, etc. etc. once the UK leaves the EU.

How come the EU doesn't care about "pesticides, pharmaceuticals/medicine, GM" ?

I think the original comment needs to be interpreted as 'EU does care, UK post-EU less likely to'

Re: How the GDPR Will Disrupt Google and Facebook

#273
post #209

Earlier quoted context omitted.

Which would harm them... how?

They will probably lose a billion customers?

THAT is the harm. That's my point. You can't sue someone for something that abstractly maybe implies something else. You sue for damages and have to show damages.

Re: How the GDPR Will Disrupt Google and Facebook

#274
post #132

Earlier quoted context omitted.

> as those players can easily shell out another $10M here and there to be compliant with this regulatory monster. Sounds like you missed the part where the fines are based on a percentage of your global revenue.

Parent comment is talking about the cost of compliance, not fines for non-compliance.

True, whoops.

Re: How the GDPR Will Disrupt Google and Facebook

#275

> The critical question for both businesses is whether users will click “yes”, when asked to consent. Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's…

Clicking yes might not even be necessary: I recently went to a laywer-oriented event (IANAL) that discussed the GDPR and it had a cheerful talk about "Alternatives to Consent"

The talk listed all the possible ways the law allows you to store/manipulate user data without requiring explicit consent... There are a shocking number and iirc they apply basically whenever you have a direct consumer relationship with some company.

Re: How the GDPR Will Disrupt Google and Facebook

#276
post #109

Earlier quoted context omitted.

You need to research the right to be forgotten as it applies to news articles, it doesn't work in the way you describe. And as far as this stuff being difficult to do, sure, but isn't it worth doing? Why shouldn't a customer have a say which cloud provider hosts their data? Why shouldn't we be able to make sure no data is kept about us after we stop using a service? Like with anything novel in software it only seems…

> You need to research the right to be forgotten as it applies to news articles, it doesn't work in the way you describe. I was referring to Google vs. Costeja, which I realize isn't GDPR, but an EU court did rule that way. > You don't need a compliance officer, but you do need a security officer I strongly believe that compliance and security are two very different things, that are only slightly related. They come a…

[deleted]

Re: How the GDPR Will Disrupt Google and Facebook

#277

And if you think GDPR is a toothless joke, let's take a look at the defined fine stucture. It is pretty simple, only 3 levels (strikes for the fellow Americans): Strike 1 - Stern warning letter Strike 2 - 2% of your TOTAL GLOBAL REVENUE Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got…

Throwaway account. I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps. You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted. It all boils down to companies simply don't believe the fine…

The fine doesn't absolve you of responsibility for complying. If you're fined you have to pay up AND you have to comply. Otherwise they'll just fine you again, as they did to Google.

Re: How the GDPR Will Disrupt Google and Facebook

#278
post #217

Earlier quoted context omitted.

This makes me very nervous about data loss. If I accidentally wipe the hot database then I've effectively deleted all my backups. It also makes corporate ramsomware attacks much easier.

So keep a backup of your hot database in S3 or something, and make a workflow by which you can periodically update it. Or make a write-only backup of your encryption keys every day and only keep the backups for a week (or a month, or whatever the legal requirement is). Complying with this requirement will require us as an industry to make some changes to how we store user data. But the amount of work each company nee…

There's been a wave of targeted ransomware attacks recently that spend time surveilling and infiltrating their targets before holding their data for ransom. If companies take your proposed approach, some of them will find their backups have been compromised and be forced to pay up by ransomware attackers. It's simply inevitable.

Re: How the GDPR Will Disrupt Google and Facebook

#279
post #159

I encourage a little more thought before cheering this on as a win. While GDPR isn't as ridiculous as the Cookie Law, it still shows that the EU/EC don't understand the technology they are trying to regulate, and it comes at a huge cost to tech companies. Take the right to be forgotten . First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't…

If you follow GDPR strictly you would need to be able to purge the data from your backups. Now most backups are considered immutable, so you aren't going to do that Encrypt with a user-specific key, and destroy that key to drop all backups concerning that user.

If the key required to decrypt your backups isn't backed up, you don't have backups. If it is, you're back to the original problem.

Re: How the GDPR Will Disrupt Google and Facebook

#280
post #189

And if you think GDPR is a toothless joke, let's take a look at the defined fine stucture. It is pretty simple, only 3 levels (strikes for the fellow Americans): Strike 1 - Stern warning letter Strike 2 - 2% of your TOTAL GLOBAL REVENUE Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got…

For startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment. I'll start by saying that I have found myself leaning in favor of this law -- I've made a much longer comment about it and won't rehash it, but I wanted to make sure my statements that followed weren't taken as a b…

> Joe's Advertising Supported Free Service does not. Joe's not going to start his own ad network and start mining personal data for it -- it's way too expensive to try to compete with Google/Facebook (and it was already way too expensive to do it, before).

Since it was already too expensive to roll his own, Joe's site will simply include content from whatever ad network he chooses. All he has to do is make sure that the network is GDPR compliant. If he didn't think to do that, the first warning should give him the necessary time to find a different ad network or to specially handle EU-based customers.

Your "kitten meal" example also wouldn't work, since the first violation doesn't carry a fine, and if the website has been taken down, there is no possibility of a second violation.

So I think the changes won't affect ad-supported businesses themselves all that much, they will simply lead to a restructuring of the supporting infrastructure to become compliant. In the worst case, every website will have a huge "opt in to tracking" modal you have to click, like the cookie policy.

Post reply on HN