Can a cheater now ask to be forgotten and therefore the ban must be removed?
Google Emerges as Early Winner from Europe’s New Data Privacy Law
61–70 of 94 posts
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#62Earlier quoted context omitted.
> I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? None. Do not target the EU initially, start in the US market with your MVP. It's by far the most liberal major market to do an MVP in, in all regards. It's the world's largest economy and easily accessible; plus you essentially get Canad…
That'd be fine if the GDPR were constrained to business done inside the EU, but it purports to exercise authority over any entity which asks for any information from any EU citizen, inside or outside of its borders. Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".
It also doesn't matter what China purports I should do with their citizen data, or South Africa, or Australia, or Brazil: their wishes don't overrule the supremacy of US law inside the US. If China wants me to delete everything on my service about Tiananmen Square, or an anti-China activist, guess what, that's not going to happen for the exact same reason. I'm also not subject to the UK government's enforced media blackout on the Tommy Robinson arrest: they too can piss off.
If a EU citizen signs up with my US based service, their data will be governed by US law.
It is that simple. It will remain that simple. The US isn't going to cede its sovereignty to the EU: it's drastically more powerful than the EU in every regard. There is no scenario where the US lays back and allows the EU to legislate how the domestic US economy operates in such large ways.
The only likely outcome is that the US comes up with its own new privacy rules in the next few years, which will be different - more lenient - than GDPR. If you want to operate in the two markets, you'll have to comply with each approach accordingly.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#63Earlier quoted context omitted.
I don't think "startups" should be able to get away with just doing a "deleted=1" with my personal data, or to not know where my data is ending up, just because they are "startups".
There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#64The perverse effect of these consent buttons is that people who configured their browsers to flush all cookies and session data on closing the session get harassed much more as websites do not remember their choice, even if they are the ones actually least likely to be tracked (save for browser fingerprinting).
It's complete irony. I am seriously clicking through these ginormous modals like there is no tomorrow when i have to do research on many websites.
"Free surfing" or should we say old school internet surfing has become a chore now because of these idiotic modals.
I am sure people will flee to walled gardens pretty quickly if they have to constantly make extra clicks to access stuff.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#65Earlier quoted context omitted.
The sum total requirement for reporting taxes on a hobby project in the US is filling out a single 1099-MISC at the end of the year, during a process that you'll already be doing anyway. It's not an onerous burden which introduces significant friction to the process of bringing a new idea to fruition. I'm not saying "hobbyists shouldn't have to comply with the law", I'm saying "the law is disproportionately punitive…
If, and only if, you don't know what you're doing with your data. Most cases can be covered with a bit of forethought and some documentation. "Hey, I need to be able to query and delete data" is not a huge cognitive overhead when creating a MVP.
You have to be able to demonstrate audit trails of consent, including what the user consented to and when. You have to be able to demonstrate audit trails proving deletion requests. You have to have audit trails of who has ever accessed this data. You have to have a means to exclude pieces of your dataset from aggregate statistics on demand. Also, your audit trails can't contain PII because then your audit trails are in violation of the deletion requests, so you have to have mechanisms of proving that you processed deletion requests without actually identifying the data processed. You're also now obligated to respond to data inquiries in perpetuity, even to people for whom you have no data. Article 32 appears to impose a requirement for encryption at rest, high availability, disaster recovery, and regular penetration testing - all good things, to be sure, but completely impractical for the small hobbyist. Your "querying and deleting" is, by the letter of the law, now required to be a full-blown production-ready architecture with a business's worth of documentation.
And all because you wanted an email address to keep your login form from getting spammed?
I realize that in practicality, this is unlikely to ever be leveraged in any significant scope against most hobbyists, but the law is merciless and it is foolish to assume that you won't be caught in its crosshairs just because you weren't its intended target.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#66Earlier quoted context omitted.
There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.
There isn't, especially for small companies. Also, it starts with recognizing that it's not their data, it's user's data.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#67GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
> yet another moat for established companies What if GDPR is what pushes distributed computing into the mainstream? If GDPR makes it even harder for small fry to compete with the giants, then the small fry should change the rules. Zero centralized servers, zero PII, no EULAs, no legaleze, only open-source P2P. Megacorps can be GDPR-compliant with buildings full of lawyers, and the rest will be GDPR-irrelevant with no…
how that should work exactly? I mean, even if platform is P2P, you still have user id, you still have user interests, et cetera.
The only thing changed bc of P2P is that it gets much more complicated, or even impossible, to delete your account/data.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#68Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#69Earlier quoted context omitted.
There's a large distance between not knowing where your data ends up/using it badly and being actually GDPR-compliant, which in many businesses requires a massive administrative burden.
If it requires a massive administrative burden, that company has collected or is in the business of collecting a lot of personal data. In which case, it's good that there's a burden, since they are holding a lot of sensitive data and should be held accountable for what they do with it, and how they allow it to be used.
2. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way.
3. One can use all that personal data well and not violate the rights of data subjects without being remotely GDPR-compliant.
4. Most of the administrative burden does little to nothing for how well data subjects' data is used.
Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law
#70Earlier quoted context omitted.
That'd be fine if the GDPR were constrained to business done inside the EU, but it purports to exercise authority over any entity which asks for any information from any EU citizen, inside or outside of its borders. Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".
It doesn't matter what the EU purports, that's nothing more than a comical fantasy on their part. I live in the US, my business operates in the US, I operate by US law. It also doesn't matter what China purports I should do with their citizen data, or South Africa, or Australia, or Brazil: their wishes don't overrule the supremacy of US law inside the US. If China wants me to delete everything on my service about Tia…