Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

171–180 of 710 posts

Re: How GDPR Will Change The Way You Develop

#171

Earlier quoted context omitted.

Arrest when you have a layover in the EU for some reason, on purpose or because of an emergency. And a default judgement.

Not a chance. The only country that has a history of such actions is the United States.

So if I ignore a law in Canada or the EU (extradition request, default judgement, etc) as an officer of a corporation, I wouldn't get arrested when I show up on the border? Really?

Re: How GDPR Will Change The Way You Develop

#172
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users.

If you feel that your users rights are of no concern to you then you are of course entirely able to ignore this law and to pretend it does not exist because in practice there will most likely not be any consequences whatsoever. You do not have a place of business in the EU, you do not transact any business there to begin with so you are free to ignore the law. And this is doubly true because you are 'small fry', nobody will notice.

Except for your customers maybe. And then that time that you got hacked and you lost all the data you collected over the years because you forgot to implement life cycle management. And this will then marginally affect the ability of other companies like yours to be able to do business.

And little by little the people that chose to ignore the law will start to become a large enough problem that something will be done about it (I hope). Which might mean harmonizing EU law and US law, or it might mean that you can be fined just as if you were in the EU for those breaches were you are clearly deficient.

In the end I don't think that you will enjoy the results much. But since you are small fry you probably will get away with it. But collectively, you and your buddies will harm American enterprise more than you probably realize.

Re: How GDPR Will Change The Way You Develop

#173
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

It's hard to say at this point, or even after. It's on a nexus of vague things. First "internet laws" have a history of leading to nothing much, like the EU "cookie law" which everyone "complies" with by popping up a nag. Second because online jurisdictions and how these get enforced is ambiguous. Third, because the enforcement path is still pretty unclear. It may be all about a handful of high priority cases, with small sites getting a pass.

Ultimately, there are all sorts of laws all over the world. With an online, potentially global business, you're breaking some of them. Turkey does not really expect some international user generated content site to comply with their political content laws. A bigger site based in Istanbul... You'll get a knock on the door.

About ten years ago, I had a client with an e-commerce site, for workplace safety gear in Australia. They sold to the US, but rarely. During bird flue, they somehow got on the radar of some US advertising standard. There were some politicians actively policing it anyway they could (not courts).

Tldr is that they had their payment gateway and PayPal shut them down immediately (someone got scary phone calls). Even shutting off all US shipping, and adding a big red "No US" sign didn't help. They had to drop the products. So.. jurisdiction is often erratic.

I think the last (possibly most important) point is cultural. If it takes, GDPR may impact consumer expectations and you may need to do it for that reason.

If you want to avoid GDPR, just hold back for 3-6 months until after the date. It'll get clearer as it progresses and if you're as outside the purview as you suggest, you're probably going to be fine ignoring it at the start (or forever).

Re: How GDPR Will Change The Way You Develop

#174

Will the GDPR eventually make bitcoin or other immutable public distributed databases illegal in the EU? Do you have default judgements on thousands john doe node operators around the world? Will EU ISPs be required to censor any kind of blockchain node eventually when someone has a GDPR complaint for that network? Will we arrest teenagers for running ethereum miners on their gaming computers after all of this?

Will any information that enables identification of the individual (or the other ancillary information spelled out in the article and regulations) be in the blockchain? If not, doesn't sound like it.

Here is one way to think of this. Any EU citizen has a "right to be forgotten". If there is nothing in your records to identify that person, the you don't need to provide that ability.

Re: How GDPR Will Change The Way You Develop

#175
post #157
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

So basically this legislation will make it less likely websites will accept European currency and localize to European languages?

Re: How GDPR Will Change The Way You Develop

#176

Earlier quoted context omitted.

Not a chance. The only country that has a history of such actions is the United States.

So if I ignore a law in Canada or the EU (extradition request, default judgement, etc) as an officer of a corporation, I wouldn't get arrested when I show up on the border? Really?

For ignoring the GDPR as a small business owner operating on the internet the chances of individual consequences are nil.

High profile cases would have a much higher risk and companies that went out of their way to advertise the fact that they are going to break the law would run a significant risk.

Show me just one example of a company located outside the EU without a legal presence inside the EU that had an executive detained upon entry for breaking an EU law that does not normally result in criminal prosecution.

Re: How GDPR Will Change The Way You Develop

#177
post #81

Earlier quoted context omitted.

I thought that was needlessly snarky. I'm pretty sure other fields rely on lawyers to know the relevant legal landscape just like we do.

No. Professionals in engineering or the trades have to know the regulations that govern their industry and abide by them. What many SVers call "innovation", other industries would call "reckless". How embarrassing for us! EDIT: In terms of regulation, we're practically chiropractors.

The comparison is disingenuous. The internet makes anything you build automatically global. You're blasting software engineers for not knowing worldwide regulations. How many New York lawyers know the regulations of France? How many local UK construction companies know the building codes of Japan? None.

Knowing all regulations in the world for any given industry would be a full time job. The people you seem to be implying exist do not exist.

Re: How GDPR Will Change The Way You Develop

#178
post #157
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

Consider the case of an EU citizen traveling in the US transaction in USD. This person is covered. Even if they are in the US.

Re: How GDPR Will Change The Way You Develop

#179
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users. If you feel that your users rights are of no concern to you then you are of course entirely able to ignore this law and to pretend it does not exist because in practice there will most likely not be any consequences whatsoever. You do not have a place of business in the EU, you do not transact…

"You do not have a place of business in the EU, you do not transact any business there to begin with so you are free to ignore the law. "

Wrong. If you have a customer from the EU or any component of your infrastructure in the EU, you must comply with GPDR.

Re: How GDPR Will Change The Way You Develop

#180
post #179

Earlier quoted context omitted.

What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users. If you feel that your users rights are of no concern to you then you are of course entirely able to ignore this law and to pretend it does not exist because in practice there will most likely not be any consequences whatsoever. You do not have a place of business in the EU, you do not transact…

"You do not have a place of business in the EU, you do not transact any business there to begin with so you are free to ignore the law. " Wrong. If you have a customer from the EU or any component of your infrastructure in the EU, you must comply with GPDR.

I'm not saying he's not in scope and should not comply I'm saying he can get away with ignoring it in practice, which was what he was asking about.
Post reply on HN