Live data from Hacker News

How GDPR Will Change The Way You Develop

smashingmagazine.com

241–250 of 710 posts

Re: How GDPR Will Change The Way You Develop

#241
post #178
post #157

Earlier quoted context omitted.

If your company is not targeting the EU as a market you are out of scope of GDPR. If you explicitly accept Sterling/Euros, provide localisations for EU countries, talk explicitly about your EU shipping options etc. then you would probably be seen as accommodating the EU market and might find yourself in scope.

Consider the case of an EU citizen traveling in the US transaction in USD. This person is covered. Even if they are in the US.

Wrong. You don't get to make up new laws for the country you are visiting.

Re: How GDPR Will Change The Way You Develop

#242
post #105

Earlier quoted context omitted.

> Then that part is worthless GDPR requires that the use cases be itemized, and the user can opt out of each one individually. So if the user opts out of receiving a mailing but not the store locator, you have to manage how much data you collect about that person. I agree that for the most part this will just be another click-through like the cookie law was, but companies will be required to accommodate those minorit…

Up to 4% or €20 million, whichever is greater .

Let me get it straight: if your global revenue is €10 million, you won't pay 4%(€400k) penalty, you'll pay €20 million, because it's greater of the two? It seems like this will be especially harmful to small companies.

Re: How GDPR Will Change The Way You Develop

#243

Earlier quoted context omitted.

The collective economic effect of that will be massive. Please do. And realize that you are ceding the single largest market to your competition.

> single largest market The EU really isn't a single large market though for most practical purposes. For the purposes of complying with regulations and accepting payment it is, but for every other practical consideration that matters to a company doing business there, it's a few dozen separate markets.

and they're still in the eurozone, so banning eurozone users is still removing yourself from the largest economic bloc in the world

Re: How GDPR Will Change The Way You Develop

#244

Does anyone know of US companies implementing GDPR compliance?

Absolutely! Anybody who does business in Europe or even has users in Europe is subject to this law. The amount of effort being put into GDPR compliance within my organization is just staggering. It really makes me think about these kind of laws from a new perspective, because they cost businesses so much to implement. (I'm not saying whether GDPR is right or wrong! Just that it's expensive.)

> Anybody who does business in Europe or even has users in Europe is subject to this law.

Anybody? Sure technically in the same way that going 58 in a 55mph zone is speeding and could get you a ticket. So the question remains assessing the probability of enforcement of a hypothetically a small US based organization who has European customers. As I read the replies on this page it seems to be a mix of people who have a great deal of theory and not a large amount of practical experience assessing the probability of something actually happening given breaking a European law.

Re: How GDPR Will Change The Way You Develop

#245
post #134

Suppose you were a small startup based in America, accepting online payments from users/advertisers using American platforms or financial institutions. Suppose you make no effort to comply with GPDR - what realistic consequences can you face? I suspect that this is the kind of thing which larger/established companies would worry about. If you're a seed/series-A startup, it seems like you have far more important thing…

What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users. If you feel that your users rights are of no concern to you then you are of course entirely able to ignore this law and to pretend it does not exist because in practice there will most likely not be any consequences whatsoever. You do not have a place of business in the EU, you do not transact…

> What you do or do not do should not be grounded in the consequences that you will face but in what's the best for your users.

I agree with the above. I disagree however that "what's best for your users" is universally a superset of GDPR regulations.

My personal view is that if your company/service becomes so powerful that people can't escape from its influence, the above regulations are a necessary evil in order to counter your outsized influence.

For a tiny startup on the other hand, you have so little influence on the world that if a consumer doesn't like the way you operate, they can just choose not to interact with you. Such startups can best serve both themselves and society at large, by focusing on building valuable features/services.

Reasonable people can disagree about the specifics of a law. As a EU citizen, I can understand your wishes for everyone to comply with EU regulations. It helps to put yourself in others' shoes, and ask yourself how much time/energy you, as a startup founder, would be willing to put into regulatory compliance with Canadian/Russian/Indian laws.

Re: How GDPR Will Change The Way You Develop

#246

Earlier quoted context omitted.

For the same reason that downloading a song is different than stealing with a CD. Digital stuff is innately different. You aren't doing business unless you're accepting payments/selling/shipping things to people in the EU. And as with any law, if you're sufficiently small fry the EU isn't going to care about you until you actually screw up. Don't accept euros as currency. Don't offer to ship to EU nations. Done. If y…

> Don't accept euros as currency. I see multiple comments mentioning this. Do American banks restrict which currencies your credit card can be charged in? As far as I've been able to tell, my bank lets me pay in any currency I'd like, and they will convert the amount to SEK before charging my account.

Don't offer shipping options to the EU.

If dealing with digital products, allow people to purchase without creating an account, or require them to select a country as part of account creation (and prevent those selecting the EU, or don't make it an option). If the bank processes the payment, but you've collected no information, you can't run afoul of the law (since you have no information).

Re: How GDPR Will Change The Way You Develop

#247

Earlier quoted context omitted.

You think I am reaching, but the GDPR does act this way. Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop. They put your name and delivery address in their computer in an MS Access database that makes stickers, emails the delivery guy's gmail account and a person delivers a pizza to you. They have no idea your an EU citizen and they just put enough information…

> Lets say your visiting the USA as an EU citizen and you get a pizza delivery from a local small pizza shop If that pizza store has no relation to the EU then there is no legal ground by which the GDPR could become relevant. There is no treaty which would establish some sory of leverage here. //EDIT: which btw is unlike FATCA for which there actually are bilateral agreements.

You don't need a treaty to enforce the law, you just need a pizza shop owner who likes to vacation in europe sometimes. You carry out the default judgement if they ever arrive in the EU. The GDPR explicitly has a very global scope because it is targeting companies in and out of the EU.

I wouldn't really have much of a problem with the GDPR if it had some small business and non-eu business exceptions. It doesn't and regulators saying 'trust us we wont prosecute the easy to prosecute!' makes most businesses uneasy.

Re: How GDPR Will Change The Way You Develop

#248
post #222

Does this make Apache access logs illegal? 1) There isn't any way to "opt-in" to them 2) You would need to have a tool to remove every entry for an IP address when requested?

It looks like the answer is yes:

https://www.ctrl.blog/entry/gdpr-web-server-logs

Re: How GDPR Will Change The Way You Develop

#249

Earlier quoted context omitted.

It says a lot about the cost of privacy, period. The cost would be staggering whether they're modifying existing things, or creating new things, just in terms of ensuring "Yes, we're doing this correctly".

I just find it hard to believe that the law is a significant cost to companies already doing the right thing. Sure, there is a non zero cost to ensuring your existing practices are lawful, which everyone must pay. But companies already in compliance shouldnt have to modify or create anything. The companies that have to spend significant coin are the ones who are not already complying.

Part of the cost is -documenting- what you're doing. Ensuring the right stakeholders are involved and signed off on it. Etc. When there's a regulation to do it, suddenly you have to involve legal, and the business stakeholders want to better understand it, whereas before it may have just been the developers.

Re: How GDPR Will Change The Way You Develop

#250

Earlier quoted context omitted.

> single largest market The EU really isn't a single large market though for most practical purposes. For the purposes of complying with regulations and accepting payment it is, but for every other practical consideration that matters to a company doing business there, it's a few dozen separate markets.

and they're still in the eurozone, so banning eurozone users is still removing yourself from the largest economic bloc in the world

Are you arguing with my point or just trying to be contradictory? I never said blocking the EU was a good solution, but calling it a single market makes it sound more enticing than it is.
Post reply on HN