Earlier quoted context omitted.
You only have had to gone through the implementation challenges personally to know that it’s hard and the costs (to do it by the letter) are high. In fact to do it by the letter you’re going to have to hire a law firm to ensure you’re compliant and they’re going to err on the side of caution and take you down a rabbit hole of implementation changes.
Can you give me a concrete example where the GDPR forces you to do a lot of relatively costly stuff that are not worth doing otherwise?
GDPR: US news sites unavailable to EU users over data protection rules
641–650 of 680 posts
Re: GDPR: US news sites unavailable to EU users over data protection rules
#642Earlier quoted context omitted.
That would be the self same reason the net is starting to attract regulation. Some of that significant disruption basically involves extending a middle finger to the laws and regulations of the country they want to do business in. I might call it taking the piss. Taking the piss with laws and employment rights such as Deliveroo etc, or taking the piss with user data and personal privacy. We'll be left with some of th…
Conversely, people have also seen how some laws - like those protecting taxi drivers in this example - did nothing to help consumers. Not all regulations are being missed.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#643Earlier quoted context omitted.
My comparison is simply to show the standard laissez faire talking point of "oh, regulation exists just to protect incumbent market players" as bullshit: regulations exist to protect consumers from negligence and misbehaviour on the part of the companies. The fact you think GDPR only applies to websites rather than the huge clusterfuck of personal data loss means you haven't understood the reason behind GDPR. Equifax…
In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked, and the primary bottleneck to making software more secure is crap tools, crap platforms, poor training and inability to hire people who deeply understand security. Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".
- Unpatched, publicly documented vulnerabilities.
- Unauthenticated S3 buckets.
- Unencrypted laptops.
- Default passwords.
This isn't subtle crypto weaknesses or attack vectors missed in the security assessment of protocol designs. It's carelessness. It's stuff that any high school kid who's good with computers will tell you about, let alone any IT professional or software engineer.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#644Earlier quoted context omitted.
The activity they restrict isn't showing targeted ads; it's collecting the data necessary to show targeted ads. That is to say, you're not allowed to collect data that would show that the user is e.g. a 33-year-old African-American male living in Fremont, CA and with an interest in certain sports, which is necessary to show targeted ads. If you could show such ads without collecting that information, I'm sure GDPR dr…
Okay, I think I finally understand your argument. You’re saying that Recital 43’s citation of “performance of a contract” refers to merely the performance of the provider — the good or service handed off by the provider to the customer. (It’s the sandwich in our example from earlier.) It does NOT also include whatever good the user provides to the service provider as their side of the contract. So if a service provid…
The core of the regulation is Article 6(1), which is basically a big old "or" statement; you have to fulfill one of the conditions listed in order to lawfully process data. [1]
a) is consent, as explained in Recital 43 and clarified in other places. The sandwich vendor clearly doesn't have that, since they've conditioned the service on the delivery of data.
b) is "necessary for the performance of a contract". This is the option on which your free-lunch-giver is leaning. "Necessary" is not well-defined in the EU-wide regulation, but judging by the UK example I linked (the ICO), implementing Member State agencies are going to take a narrow view of "necessary" - as in where it's impossible for the controller to perform the contract without processing the data. By contrast, Recital 43 uses "dependent" to refer to the service provider establishing conditions. This also fits well with the usage of the word in the other tines of the Article 6(1) fork. (c: "necessary for the compliance with a legal obligation", d: "necessary to protect the vital interests of [actual people]", e: "necessary for the performance of a task carried out in the public interest or in in the exercise of official authority" [2]). This interpretation is also, in practical terms, the only one that makes sense, as otherwise the consent option (a) would be redundant.
[1] The most friendly version of the English-language full text I can find is here: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...)
[2] This interesting clause stemming from an even more interesting feature of GDPR: it applies to government agencies. Meaning the regulation needs specific language to specify that yes, the Ministry of Transportation in your country is allowed to use your vehicle registration information as part of its road planning process.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#645Earlier quoted context omitted.
Isn't Moviepass hæmmoraging $20 million a day while its share price tanks? No, if you knew how Europeans think, you'd realise that this is really just about securing privacy. Most of the regulators are really focussed on ensuring compliance, not levying fines.
> Isn't Moviepass hæmmoraging $20 million a day while its share price tanks? Correct me if I am wrong. But that just proves my point rather than yours, correct? They are losing so much from ppl using not because ppl are quitting it due to privacy concerns.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#646Earlier quoted context omitted.
In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked, and the primary bottleneck to making software more secure is crap tools, crap platforms, poor training and inability to hire people who deeply understand security. Hacking is not a problem you can solve by passing a regulation that says "don't get hacked".
> In practice fining companies for getting hacked just boils down to a tax, as no company wants to be hacked No, it boils down to an incentive . No company wants to get hacked, but a lot those same companies aren't willing to invest in security measures and training that could mitigate the risk. > Hacking is not a problem you can solve by passing a regulation that says "don't get hacked". I don't think anyone's propo…
It was the financial industry and government that were responsible for implementing an identity scheme with a less insane architecture than handing the same secret material to every relying party. I disagree that we can or should force everyone to tie themselves in knots supporting it.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#647Earlier quoted context omitted.
By hosting non-tracking ads. Like they used to be before Google started this whole profiling menace.
I keep seeing this argument. But the reason I don't see this happening is the giant amount of fraud out there. Sure ad fraud is an arms race, but if you can't do js fingerprinting, cookies, etc it would be impossible to verify ad impressions are real humans, not bots. And actual clicks from real humans would be impossible to differentiate - not coming from the same bot clicking over and over again (can't store ip, co…
To show ads you don't have to report about all of your site visits to Facebook and Google.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#648Earlier quoted context omitted.
Everything's fine if they add generic, non-targeted ads that are completely under control of the news publisher, hosted on their servers, don't track users, don't use cookies. Just like print media and TV does since forever.
The problem is that those ads could not be pay-per-click because you need cookies, javascripts and other tricks to combat clickfraud and impression spam. If that USA Today site sticks around and adds advertising, it will presumably be low quality inventory like the internet used to be flooded with - casinos, punch the monkey etc.
I don't want data about me to be someone's asset. I want an Internet shop to delete data about me as soon as possible after I made a purchase. That's why I want GDPR in my coutry too.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#649Earlier quoted context omitted.
And how can be a business sustainable in this way? By not building their entire business around ads and tracking.
People have tried lots of other stuff in the last 10-15 years, it was not sustainable (micro-transactions never took off, subscription-based newspapers are the exception rather than the norm etc). I'm personally fine with newspapers like the LA Times collecting and selling my personal data as long as I can read articles for "free" on their website, I think it's a pretty fair deal.
Re: GDPR: US news sites unavailable to EU users over data protection rules
#650Earlier quoted context omitted.
If the 1-3 person startup's application is geared around personal information and it needs a complex privacy policy to describe what it does with data, then yes, it will have to work very hard to comply with GDPR, but that will also result in meaningful improvements in privacy and data control for its customers. Do you have examples of startups where data is not a core business concern, who still find it very onerous…
Here's an example: I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication. I've been talking to a very well known…
Their policy office is probably still busy waiting for Y2K.
It sucks, but HIPPA was exactly the same, and I heard exactly the same complaint from tiny companies back then too.
You can get ISO27001 for as little as $5k. My advice is that if you can afford it, suck it up, if you can't, offer ISO27001 on-prem installation for an extra $10k. If they walk. They walk. You can probably get them later (see below).
But see, it's important to understand that you're wrong: This isn't a side-effect of the GDPR.
This is a side-effect of capitalism: With no laws requiring that they keep personal data safe, it is to their benefit to keep the data in as insecure a form as possible.
Look at Equifax[1], who have lost control of perhaps every single american's name, DOB, SSN, and address.
Data Protection laws are designed to protect people. Eventually, people will get used to them; the dust will settle. You'll have an opportunity to explain the actual risk/reward clearly to your potential customer's CIO office because the savings/efficiency you're promising will make it worthwhile.
But right now? Too much fucking hyperbole about the GDPR for anyone to be thinking clearly.
[1]: https://www.sec.gov/Archives/edgar/data/33185/00011931251815...