I don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR. I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests. They can't fine me, I don't have a physical or business presence in Europe,…
This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…
Statement on 4 Years of GDPR
161–170 of 195 posts
Re: Statement on 4 Years of GDPR
#162Earlier quoted context omitted.
One option would be to collect less data on users, which should make it easier to manage.
Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.
In order to get a fine you have to act evidently in bad faith or to lose your users’ PII or credit card information.
People don’t get fined billions because a legacy system saves an email address in the wrong table.
Re: Statement on 4 Years of GDPR
#163I don't think the law has done much at all. I operate a business that serves as a data broker / processor under GDPR. I have had a total of 66 data requests in 4 years. I handle data requests and follow the laws, but I also understand the EU/UK has zero grounds to enforce anything against my business if I were to flat out reject all requests. They can't fine me, I don't have a physical or business presence in Europe,…
This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…
If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe.
GDPR is framed as a human rights law, and that has long-reaching claws.
It is currently not well-enforced, but there are many examples of clawbacks coming in. For US slavery, those clawbacks are coming 160 years later: buildings, businesses, and schools are being renamed. Statues are being torn down. In some cases, you're starting to see reparations (see Harvard). Milder versions of racism are subject to cancellations; things acceptable in 1980 are having repercussions on people's careers in 2020.
Then you've got issues of when you're persecuted for an unrelated reason, and the government is looking for an excuse or pretext to take you down. A famous mobster was taken down a century ago for tax evasion.
Re: Statement on 4 Years of GDPR
#164There are signs that it's getting better. I started seeing cookie dialogs with a Reject all button. Sometimes it's a big one, sometimes it's almost white on white, but it's there. Anyway the vast majority of those dialogs is still misleading. The usual We care about your privacy, accept all, settings thing.
"Better" would mean not seeing cookie dialogs at all.
There has (perhaps predictably) been significant lobbying against that by entrenched industry players, so we'll see what emerges as a result.
(I have to admit I'm not up-to-date on the latest happenings regarding this regulation)
Re: Statement on 4 Years of GDPR
#165Earlier quoted context omitted.
This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…
Jurisdiction issues are complex. In this case, the jurisdiction is defined by the location of the customer, not the business. If your business ignores EU courts, that might not have an immediate impact, but in the longer-term, you have a liability if you ever do business in Europe, want to be acquired by someone with a business presence in Europe, and potentially in the future, travel to Europe. GDPR is framed as a h…
I want to be clear I think they have a moral and ethical obligation to delete that person's information if so requested. There's just no (legitimate) legal requirement. The huge jurisdictional overreach by GDPR is part of why you're seeing companies just outright ignore parts of it.
Reasonable people can disagree about whether or not GDPR actually covers anything in the spectrum of "human rights" but for the love of god slavery has nothing to do with anything about it.
Re: Statement on 4 Years of GDPR
#166Earlier quoted context omitted.
This is an admirable position, and one of my biggest problems with GDPR. Honestly, my only problem with it. The EU does not have the legal jurisdiction to tell any company based outside of the EU what to do with its data, whether that data is about EU citizens or not. If I ran a SaaS I would probably do the same thing as you (out of respect for my customers) but I certainly wouldn't feel any legal compulsion to do so…
Is that really true? My understanding for example in the USA is that if you violate the laws in another country, you automatically violate the laws in the USA (under the Foreign Corrupt Practices Act - https://www.justice.gov/criminal-fraud/foreign-corrupt-pract... ) - or is that really just limited to bribery? AFAIK some other countries have similar provisions.
What US law requires a US citizen to comply with EU law?
Re: Statement on 4 Years of GDPR
#167Earlier quoted context omitted.
This seems to be a very common misconception, but the cookie consent dialogues are not part of GDPR.
https://gdpr.eu/cookies/ Cookie compliance To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must: Receive users’ consent before you use any cookies except strictly necessary cookies. Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received. Document and store consent received from users. Allow…
Consent is part of the GDPR, but the way I've seen it operate in practice is widely out of compliance. You're supposed to ask for consent in each specific instance of data collection, not present a blanket approval, and default to "no."
Re: Statement on 4 Years of GDPR
#168I completely reject the premise of this, that one is somehow EU citizens are not personally responsible for the information they themselves put online. The most hilarious thing is cookies! For example, cookies exist, and they work a certain way... and despite not liking how they work.. they are here, and not going away, and imposing some kind of contract-law of cookies being accepted or rejected totally ignores that…
The idea of cookies was to establish sessions - something which can be done by other means, so cookies aren't needed. It would be good to have browsers which would clean all cookies every browser restart. Not enough though, some browser sessions can last months, so a better solution is needed.
Re: Statement on 4 Years of GDPR
#169Re: Statement on 4 Years of GDPR
#170Earlier quoted context omitted.
"Better" would mean not seeing cookie dialogs at all.
The EU's ePrivacy Regulation[1] has (or had - it seems to fluctuate) a goal to move cookie consent into the user's browser settings. There has (perhaps predictably) been significant lobbying against that by entrenched industry players, so we'll see what emerges as a result. (I have to admit I'm not up-to-date on the latest happenings regarding this regulation) [1] - https://en.wikipedia.org/wiki/EPrivacy_Regulation