Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

21–30 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#21
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

That’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/

Google has so far only received a 50M euro fine from France, and a tiny one from one of the other countries. Depending who you ask, there are different stories for why Google hasn't suffered larger fines. One story is that the law is toothless and we need something stronger. Another story is that enforcement in complex situations takes time, and we'll see bigger Google fines down the line. And then the final story is that Google is actually complying with the law.

Re: GDPR fines were meant to rock the data privacy world

#22

Earlier quoted context omitted.

That’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/

They paid the fines, but and what changed? Are users any better off now because those companies got fined? Did those companies stop collecting user data? Has online privacy improved because of those fines? Nope!

I think there's an argument to be made that GDPR had some effects. For example, you can now enable or disable ads personalization on Google at https://adssettings.google.com. I don't think that was there before GDPR. Google also presumably did explicit opt-in for EU users, since otherwise they'd have already faced some pretty massive fines.

It may be that most users consented, but I think the take away from that should be that most users do not consider ads personalization a significant violation of their privacy.

Re: GDPR fines were meant to rock the data privacy world

#23
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Dude if you are intelligent enough to run a successful small business, then you are adaptable enough to learn the PII storage requirements of GDPR.

Re: GDPR fines were meant to rock the data privacy world

#24
post #8

Earlier quoted context omitted.

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

My experience with startups lately is if it’s a greenfield project that started within the past 3 years then they’ll do everything by the book: sometimes even down to storing email addresses as hashes in the database, requiring a user to login first for the software system - and the company - to know their email address).

Older systems which depend on having PII and even financial information as cleartext in the database are the problem - and its essentially technical debt with far-reaching consequences, so no-one will fix a system that uses tenants’ customers’ SSNs as a primary-key (yup).

Re: GDPR fines were meant to rock the data privacy world

#25
post #8

Earlier quoted context omitted.

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

Its funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"

Re: GDPR fines were meant to rock the data privacy world

#26
post #8

Earlier quoted context omitted.

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

My experience with startups lately is if it’s a greenfield project that started within the past 3 years then they’ll do everything by the book: sometimes even down to storing email addresses as hashes in the database, requiring a user to login first for the software system - and the company - to know their email address). Older systems which depend on having PII and even financial information as cleartext in the data…

I am aware of a legacy system powering a local business which runs on Rails 1 on a version of debian from 2012 and stores users passwords in plaintext, downcased.

I have tried to explain so many times that this system needs to be replaced urgently not for security reasons but because no one actually knows how to use rails 1 anymore.

Re: GDPR fines were meant to rock the data privacy world

#27

Earlier quoted context omitted.

That’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/

Google has so far only received a 50M euro fine from France, and a tiny one from one of the other countries. Depending who you ask, there are different stories for why Google hasn't suffered larger fines. One story is that the law is toothless and we need something stronger. Another story is that enforcement in complex situations takes time, and we'll see bigger Google fines down the line. And then the final story is…

AFAIK Google has gone to great pains to attempt to comply, at least within the advertising and analytics space. I've seen significant product updates in Google Ad Manager, Google Analytics, AMP, BigQuery, etc to allow for consent, right of removal, designating a DPO and more.

Re: GDPR fines were meant to rock the data privacy world

#28
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…

You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all.

I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email addresses or first names then that should be far less strict than if a company handles medical information, home addresses or credit card information.

On the other side, we should have audits in companies to see how the personal data is handled. Particularly in ones that deal with sensitive information.

Re: GDPR fines were meant to rock the data privacy world

#29
post #8

Earlier quoted context omitted.

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

Its funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"

But that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food.

If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then they'll likely be outcompeted.

Re: GDPR fines were meant to rock the data privacy world

#30
https://www.reuters.com/article/us-austrian-post-fine/data-p...

Austrian Post sold voter preference data without having the right processes in place and was fined 10% of last years profits.

Noyb.eu is also an interesting organization to watch. They are a non profit taking lawsuits against large incumbents with egregious privacy practices with the backing of the GDPR. They triggered the 50 million € Google fine.

Post reply on HN