Live data from Hacker News

Google Emerges as Early Winner from Europe’s New Data Privacy Law

wsj.com

51–60 of 94 posts

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#51
post #9

Do you know that saying: "Don't ask me how I made my first million?" Many of the wealthy people became rich at first through business practices that either were in a grey area from the beginning, outright illegal, or they were made illegal later on. However, they got to keep their money , either because laws tend not to be retroactive, or because nobody caught them, etc. I agree there is an element true in "regulatio…

There are 11 million millionaires in the US. You've got it exactly backwards: few of them did something illegal to earn that first million. There are not many grey areas in US law as it pertains to business, there are very few. Most millionaires derive their wealth from ordinary small businesses.

The US isn't the wild west of Capitalism. It's a very regulated economic system. It has been that way for a very long time now. At least 10m of those 11 million millionaires generated the bulk of their wealth in the last 30-40 years, a time in which the US economy was largely as regulated as it is today. They didn't get that wealth by not having to deal with regulations or laws that were imposed later - the US has more than doubled its millionaire count just since 1996.

I grew up in a very poor area of the US. I knew at least two dozen self-made millionaires. Every one of them did it via rather boring small businesses: insurance agencies, convenience stores, shops, franchises, publishing, real estate, car dealerships, etc. Not one of them operated in a legal grey area. There was no magic to it either, it was grinding year after year for multiple decades.

I've also spent my entire adult life researching business, business formation, finance, economics, and reading every book I can get my hands on for those areas. I've read dozens of books on the history of business in the US over the last 25 years. I spend hours per day reading every consequential financial figure and article that gets published about the US and global economies. The notion that a meaningful share of rich people get started via doing something illegal, is nothing more than propaganda, and entirely unsupported propaganda at that. You will never see such claims supported with evidence.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#52

Earlier quoted context omitted.

And if your MVP makes money, you're on the hook for a lot of taxes and income reporting. It's part of the cost of doing business. For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.

> It's part of the cost of doing business. In a jurisdiction. GDPR means a dollar can buy more MVPs outside Europe than inside. Keep in mind that this has no bearing on the privacy stance of the ultimate product. Just the fixed cost of iteration.

I hate to break it to you, but the idea behind the GDPR is gaining traction outside the Europe. Fighting this trend is only going to hurt more in the long run.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#53
post #34

Earlier quoted context omitted.

I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder. If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our pri…

There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…

> Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with.

You have to tell the user why you are collecting it, what it will be used for and for how long you will retain it.

If you are just using as a login and to confirm the e-mail is valid, there's not much else you have to do.

Oh - you want to use that e-mail for lots of other things, some of which aren't central to the running of the service the user's signing up for? Then yes, you have to document and enumerate those reasons and ask the user if they are OK with that.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#54

Earlier quoted context omitted.

There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.

Please give us more details of what you think the administrative burden is, because I think you have overestimated it. Being able to provide a user with the data you have on them, and being able to delete it, should be basic requirements of any software company. And now they are, which is great.

I'm an attorney leading (from a legal standpoint) a SaaS provider's GDPR compliance effort. There most definitely is an administrative burden (setting aside whether you think that burden is merited). The SaaS provider is acting as a processor for its business customers (so fewer obligations than if it were controller) and there are many admin requirements. The GDPR is an accountability framework and one must be prepared to demonstrate not just compliance but often how one got to the compliance decisions they landed on. One must maintain processing records, implement DPA's and a variety of other things. The GDPR is not a privacy law, it's a data protection and personal rights law, which is much broader.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#55
post #39

Earlier quoted context omitted.

> I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? None. Do not target the EU initially, start in the US market with your MVP. It's by far the most liberal major market to do an MVP in, in all regards. It's the world's largest economy and easily accessible; plus you essentially get Canad…

That'd be fine if the GDPR were constrained to business done inside the EU, but it purports to exercise authority over any entity which asks for any information from any EU citizen, inside or outside of its borders. Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".

Yeah, there is going to be a wealth of problems in this regard.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#56
post #7

While GDPR in itself has accomplished the goal of raising awareness on data security and transparency, probably only temporarily, the mind numbingly idiotic push-button based consent model is an utter failure. 99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle have to read through. It's an extension of th…

> 99% of people don't read anything before they push yes

Unfortunately the option of reading something isn't always reasonable. Check out Ultimate Guitar [0]. Clicking "Manage my choices" gives a list of just shy of 250 vendors, and no explanation as to what or where they're sharing with those vendors. Other websites have longer lists, and have an opt-out per vendor!! These websites are deliberately making it as difficult as possible to reasonable manage your data.

[0] https://www.ultimate-guitar.com/

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#57
post #49

Earlier quoted context omitted.

And if your MVP makes money, you're on the hook for a lot of taxes and income reporting. It's part of the cost of doing business. For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.

The sum total requirement for reporting taxes on a hobby project in the US is filling out a single 1099-MISC at the end of the year, during a process that you'll already be doing anyway. It's not an onerous burden which introduces significant friction to the process of bringing a new idea to fruition. I'm not saying "hobbyists shouldn't have to comply with the law", I'm saying "the law is disproportionately punitive…

If, and only if, you don't know what you're doing with your data. Most cases can be covered with a bit of forethought and some documentation.

"Hey, I need to be able to query and delete data" is not a huge cognitive overhead when creating a MVP.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#58

Earlier quoted context omitted.

99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle has to read through. No offense, but this feels like a “99%” and “most” that is something less than rigorous. I don’t think sound arguments for or against GDPR can come from the “Ah Reckon” space. Throwing out made-up numbers that just represent personal…

No offense, but this feels like ivory tower obtuseness, I mean, they made a law, so of course it will get implemented EXACTLY as it was designed and nobody will abuse it ever and it will never become a monster. Laws always work and they always do what we intended them to do. We made murder illegal and now nobody gets murdered. It's just that simple. You read and understand every boilerplate contract of adhesion you'v…

> We made murder illegal and now nobody gets murdered

No, we made murder illegal and now we have a system to deal with murderers when they kill someone.

Out of analogy, we made non-consensual data collection illegal, and now we have a mean to handle the situation when it arises.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#59
post #34

Earlier quoted context omitted.

There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…

> Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with. You have to tell the u…

Yeah, that's article 5. There are 98 additional articles to the law, many of which impose additional administrative and technical requirements on your product.

Just saying "I'm using your email for signups" doesn't make you compliant. If it did then I doubt anyone would have a problem with it.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#60
post #3

GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.

> yet another moat for established companies

What if GDPR is what pushes distributed computing into the mainstream?

If GDPR makes it even harder for small fry to compete with the giants, then the small fry should change the rules.

Zero centralized servers, zero PII, no EULAs, no legaleze, only open-source P2P.

Megacorps can be GDPR-compliant with buildings full of lawyers, and the rest will be GDPR-irrelevant with no lawyers at all.

Post reply on HN