I have a contrarian opinion to much I am reading here. Until a few weeks ago, I hosted my own web site and used blogger to host my blog on a subdomain. With huge reluctance I disabled comments, and then when Google’s patches for GDPR compliance didn’t work for me, I converted my 2000+ blog posts from the last 20 years to Jekyll and now host as part of my web site. While it is nice to have total control, now I need to…
Was your blog personal? Or was it commercial? If it was personal the GDPR doesn't apply.
Shutting Down Forum (GDPR)
511–520 of 534 posts
Re: Shutting Down Forum (GDPR)
#512Earlier quoted context omitted.
I would still be bankrupted by "much less" than $20 million.
Good for you. now understand that fines are proportionate to the offense. Are you engaging in doing very bad thing to personal data on a very large scale and having a business based on this ? no ? then what are you afraid of ? that failing to answert to one guy asking for what data you have on him will cause you to be fined to bankruptcy level ? I pity the fool as said that one guy.
Or how about: I'm sure the advocates for civil asset forfeiture made similar arguments.
If you want to argue that prosecutors on your side of the pond are impervious to corruption, well, consider that you're including Spain, Italy, and Greece in that body politic (at least for now).
Re: Shutting Down Forum (GDPR)
#513Earlier quoted context omitted.
Great example. No, they didn't, though you wouldn't guess that from the news coverage. They filed complaints with four regulators. The details are all here. https://noyb.eu/
Why does your link list maximum fines in millions why other links say billions? "Three complaints worth €3.9 billion were filed in the early hours of Friday morning against Facebook and two subsidiaries, WhatsApp and Instagram via data regulators in Austria, Belgium and Hamburg. Another complaint worth €3.7 billion was filed with French data protection authority France CNIL in the case of Google’s Android operating s…
Re: Shutting Down Forum (GDPR)
#514Re: Shutting Down Forum (GDPR)
#515Earlier quoted context omitted.
We should handle companies that have >1M data records differently from smaller companies. Most countries handle private persons with larger income differently, e.g. they need to pay more income tax. Most countries handle startups differently, e.g. they don't need to pay taxes in the first years. Most countries handle farms differently than other corps, e.g. they give subsidies to them. Most countries handle people wi…
> We should handle companies that have >1M data records differently from smaller companies. What makes you think we don’t already do that? GDPR is about privacy 101; there’s nothing in it that shouldn’t apply to small companies. Do we allow small restaurants to poison their clients because they’re just starting and you-know-it’s-hard-to-build-a-restaurant-so-let’s-wait-a-bit-before-applying-regulation? Of course no.
It looks like our experience on implementing GDPR is different.
Essentially GDPR is like being PCI and SOX compliant from the first day - and looking at what companies go into to not be under PCI compliance, like use Stripe forms, this looks like significant overhead. After implementing GDPR, SOX and PCI in several companies, from an IT perspective they are comparable, with PCI the easiest to implement, especially on the process side, GDPR a little bit more than SOX on the documentation side but no monitoring of code changes and traceability.
Paying 10.000+ EUR for a missing word in your data protection declaration is no problem for a multi billion dollar company, but can and will kill startups.
If your GDPR is not on the same level as a SOX implementation, there will be a rude awakening if you get a review and are fined.
Paying for a data protection officer is hindering small companies and startups.
Updating your deletion infrastructure with every feature you implement is overhead. If you do not automate this and keep it updated and respond to information request by hand, plan for significant manual work.
Having a process documentation of 100+ pages which needs to be updated with everything you do and every new feature that captures or transfers personal data or stores data is a huge overhead for iterating on your product.
Do a risk analysis and data protection sign off for every test feature decreases your speed a lot.
You need to document every process (what data, where stored, when deleted, what cloud/saas/systems involved, who has access, how it is protected, ...) - like sending marketing mails or cold calling or going to a conference collecting business cards or giving stuff away to winners on Facebook - if it touches personal data.
Encryption in the database of personal data and encryption on the storage medium is a lot of operation stuff - this will lead to converging every startup to only use PG instead of being polystorage.
Implementing access controls to your office (if you use Excel with personal data) as if you were a data center is a lot of overhead - no more starting at home or in the garage. Probably best to go to WeWork who have proper office access control, if you have the money.
Investing into training days, planning and updating training material and managing training and with your staff is a lot of overhead for startups. Together with staying up to date with court decisions on GDPR will cost startups 1 FTE (see above). From now on instead of hiring that second developer I'd consult startups to hire a security officer first.
Having a data processing contract for every prototype feature you test is a lot of overhead to being agile and lean.
Marketing signing up with a credit card to try out some automation in a startup - these days are gone.
I'd say it is significantly more difficult to follow the lean startup methodology than before.
From working in some large companies and some startups, implenting GDRP, SOX and PCI, GDPR will help large companies who already have a large legal team, large compliance teams and who are SOX compliant against disruptive startups. Google and Facebook are the main beneficiaries from the GDPR.
Re: Shutting Down Forum (GDPR)
#516Earlier quoted context omitted.
The GDPR exists because everyone has been a dick because they know they can get away with it. By default the mentality is take take take. Now the business models built on that are being trashed. If someone keeps burgling your house they need to go to prison. Simple as. Time is up for this way of thinking. It is not difficult to be compliant. Most people don’t bother because they are drama queens or hiding what their…
GDPR exists as a proxy censorship tool to close sites using fines without looking like a socialist censor. GDPR is written so that every site can be found non complaint.
Re: Shutting Down Forum (GDPR)
#517Earlier quoted context omitted.
If you aren't in the Union, it applies to you if either [1]: (a) you are processing data of data subjects who are in the union related to the offering of goods or services to such data subjects, or (b) you are processing data of data subjects who are in the union related to monitoring of their behavior as far as their behavior takes place within the Union. If you can avoid both of these, then I believe you can pretty…
geoip based blocking is wrong. An American customer can be travelling in Europe and be blocked while any EU citizen can use a proxy or VPN to workaround your geoip block. If you can live with infuriating a small portion of your customers while have a protection that can be circumvented in a matter of seconds then geoip block is what you want, otherwise ...
Re: Shutting Down Forum (GDPR)
#518Earlier quoted context omitted.
The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website". Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.
Can’t square this comment with the long front page discussion just a couple days ago about whether ref’ing a Google font could violate GDPR. Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.
This is a very good point, and to be fair you're absolutely right. The definition of user-tracking extends far beyond Google analytics, and if you're not fully informed about what 3rd-party services you're using on your own website, and the ramifications of those, this could present problems.
When I said "they can simply not do so", that assumes they are aware of what tracking they're doing, which may not be the case. If you're using some WordPress.com blog theme with CDN calls built in, you might have no idea. There may even be an argument for this falling to WordPress.com (in this example) as the provider of the themes.
Realistically, I don't predict CDN calls to turn out to be in violation of GDPR in practice, even though there's a very reasonable argument for them being that in theory.
I kind of half-hope they are though, as a user. I've never been a fan of their use, and use the uBlock and Decentraleyes add-ons personally to avoid them. I wouldn't be devastated if we returned to a norm of locally linked resources (especially with HTTP2 adoption), though that's probably just wishful thinking.
Re: Shutting Down Forum (GDPR)
#519Re: Shutting Down Forum (GDPR)
#520Earlier quoted context omitted.
I have seen many people complain about how it is unfair that small companies also have to do due diligence with people's data, not just he big ones. It seems really mind-boggling to me. Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception? Should only large restaurants be forbidden from serving rotten food? Should small car makers have exceptions…
Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception? Funny you should say that because I'm an environmental studies major and we do, in essence, let small shops do exactly that. Most toxic chemicals are disposed of in residential and commercial trash because they are being disposed of in small quantities. You basically do have to exceed a certain…
GDPR was never about normal people, it was about companies. Trying to reframe it like it's about people is disingenuous. It is supposed to protect people, yes, but from people like you company owners and executives and others who think "screw everything, I'm looking at my bottom line".
You ignored the example with food, so I'm sure you already know this.