On a side note, should we post a link on HN which most people cannot read without paying?
Google Emerges as Early Winner from Europe’s New Data Privacy Law
31–40 of 94 posts
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#32GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
I think of it like outlawing chemical pollution of rivers. Yes, a Corporation that manages not to dump toxic waste in rivers is going to have a moat against smaller companies that do dump toxic waste in rivers. But I'd rather it be illegal than have companies competing for who can externalize their costs more effectively by passing their problem of waste management to the state / local area.
Nobody disagrees with GDPR's intent. The qualm is with its administrative approach. If someone said "write a bailout for lawyers and lobbyists," it would look like GDPR.
Taking your analogy, a good law would assess a fine for dumping. A bad law would (a) require continuous certification that one is not dumping and (b) allow anyone to prompt an expensive inspection (done via writing letter responses to a regulator, not on-site inspection by an expert) by reporting you to one of twenty-eight national regulators, each of which have jurisdiction over you.
The former imposes a fixed costs, regardless of compliance. That benefits incumbents. The latter promotes venue shopping, a further advantage to size and incumbency.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#33Earlier quoted context omitted.
99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle has to read through. No offense, but this feels like a “99%” and “most” that is something less than rigorous. I don’t think sound arguments for or against GDPR can come from the “Ah Reckon” space. Throwing out made-up numbers that just represent personal…
>No offense, but this feels like a “99%” and “most” that is something less than rigorous. I've read the contracts I have to sign, and generally this throws people off drastically. When I ask, they tell me I'm the first to read them. Things like leases at a place that has been around decades and I'm the first to sit down and read before signing. While it isn't rigorous, from my experience with wet ink legal documents,…
And just as honestly, what are we going to do - say no? Saying no is more and more simply not allowed if you want to use a service. I've had job offers who would rather have me walk than change the terms of employment. There's not a website out there which allows you to use it if you do not consent to their EULA. Hell, I've encountered a EULA when starting my (purchased, not leased) car.
You can't even post on Hacker News without consenting to 39 pages worth of privacy policy and TOS.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#34GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder. If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our pri…
You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and still be in violation of the law and subject to its penalties.
Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with. Your "MVP" has now expanded from "here's a simple idea I cranked out this weekend" to "here's a simple idea and a legal contract and audit trails that prove consent and an obligation to exfil data from my database on demand in perpetuity and data portability endpoints and data exchange contracts with every API provider I use and my database has to be encrypted at rest and highly redundant and I have to set up regular vulnerability scans and if I want to back up my database to a non-EU datacenter I have to obtain consent from all my users first and a bunch of additional requirements that possibly make it illegal to not age out my Apache access logs and why am I doing this at all again?"
GDPR significantly increases the friction for moving new ideas from concept to product, even if there is absolutely zero nefarious happening in the product. If it only made life hard on the people engaged in shady practices, there'd be a lot less concern over it, but that's just not the case. It doesn't just punish the misuse of data, it punishes the lack of proactive compliance to a set of criteria which are frankly beyond many hobbyists.
Some see this as a good thing. But I think that it's also fair to guess that it's going to cause otherwise good and benign ideas, products, and even entire companies to die on the vine as a result.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#35Earlier quoted context omitted.
I don't think "startups" should be able to get away with just doing a "deleted=1" with my personal data, or to not know where my data is ending up, just because they are "startups".
There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#36Earlier quoted context omitted.
I don't think "startups" should be able to get away with just doing a "deleted=1" with my personal data, or to not know where my data is ending up, just because they are "startups".
There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.
Being able to provide a user with the data you have on them, and being able to delete it, should be basic requirements of any software company. And now they are, which is great.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#37While GDPR in itself has accomplished the goal of raising awareness on data security and transparency, probably only temporarily, the mind numbingly idiotic push-button based consent model is an utter failure. 99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle have to read through. It's an extension of th…
Which is why defaulting to 'Accept cookies' is against the principle of the GDPR, other that for cookies vital to the running of the service.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#38Earlier quoted context omitted.
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder. If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our pri…
There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…
I would personally consider “not knowing where users’ data is, or being able to tell them” to be a nefarious act in itself.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#39Earlier quoted context omitted.
I'm not talking about corporations which have the means and the resources to engineer data pipelines that can be scrubbed and lawyers to deal with compliance. I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? I'm working on GDPR right now at my company, and it's not a small effort.
> I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? None. Do not target the EU initially, start in the US market with your MVP. It's by far the most liberal major market to do an MVP in, in all regards. It's the world's largest economy and easily accessible; plus you essentially get Canad…
Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#40Earlier quoted context omitted.
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder. If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our pri…
There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…
For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.