Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

31–40 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#31
post #8

Earlier quoted context omitted.

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

Its funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"

> Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"

But that's exactly what we do. The health inspector doesn't come to your home to verify that you wash your cutting board, even on the day you have a dinner party to entertain business clients. Depending on local law you may or may not be expected to follow the same rules as McDonalds (getting a food service license etc.) when you hold a high school bake sale, but people commonly don't actually do it and governments commonly don't actually enforce it in those circumstances.

Because it's more important, and justifies a higher compliance burden, to ensure that the company serving billions of hamburgers isn't giving people food poisoning than the individual serving four.

Re: GDPR fines were meant to rock the data privacy world

#32

Earlier quoted context omitted.

The GPDR is a large compliance burden. The bigger your company is the less this hurts you because it’s very approximately a fixed cost. So the GPDR kneecaps small companies while being a painful but bearable expense for large ones. On net it helps the internet giants by reducing competition.

This is no different than anything else. All sorts of unethical and exploitative arrangements are helpful for small firms’ bottom line, but easier to handle properly with larger scale. Dumping toxic byproducts in the river. Forcing employees to work unpaid overtime. Keeping fraudulent books and evading taxes. Selling illegally dangerous products. Not following local building codes. Facilitating third-party fraud or m…

You're assuming that treating data carefully and complying with the law are the same thing. You can easily do the former and not the latter. More to the point, you can easily have already been treating data carefully and still have the compliance burden of paying lawyers to verify that fact put you out of business.

So what you're really saying is, if a company cannot afford to stay in business while navigating a legal framework designed for companies the size of Google, then perhaps they should not be in business. The result of which would be to have only companies the size of Google.

Re: GDPR fines were meant to rock the data privacy world

#33

Earlier quoted context omitted.

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…

You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email…

> they probably can't afford to do it right

Two things occur to me here.

1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit.

2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ (first search hit).

> here should be some exceptions to it for small companies

This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.

Re: GDPR fines were meant to rock the data privacy world

#34

Earlier quoted context omitted.

This is no different than anything else. All sorts of unethical and exploitative arrangements are helpful for small firms’ bottom line, but easier to handle properly with larger scale. Dumping toxic byproducts in the river. Forcing employees to work unpaid overtime. Keeping fraudulent books and evading taxes. Selling illegally dangerous products. Not following local building codes. Facilitating third-party fraud or m…

You're assuming that treating data carefully and complying with the law are the same thing. You can easily do the former and not the latter. More to the point, you can easily have already been treating data carefully and still have the compliance burden of paying lawyers to verify that fact put you out of business. So what you're really saying is, if a company cannot afford to stay in business while navigating a lega…

The same goes for any other kind of regulatory compliance.

No small company has to pay lawyers to validate that they are complying with GDPR. It’s just that if it turns out they weren’t, the fines for violations can be quite steep, so a risk-averse company is going to be proactive about it.

There are many types of regulations which are much stricter with more up-front costs than GDPR, which companies of every size manage to cope with (or sometimes don’t, and go out of business). The technology industry has just gotten used to not being held accountable when it harms people, so now that some sensible consumer protection regulation comes down (some) people are freaking out.

Re: GDPR fines were meant to rock the data privacy world

#35
post #33

Earlier quoted context omitted.

You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email…

> they probably can't afford to do it right Two things occur to me here. 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. 2) Sounds…

>1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit.

Except that foreign companies won't have this same limitation. The end result is that all of your online services will be provided by foreign companies, which ironically is already the case in the EU.

A foreign company that's beyond the jurisdiction of the EU can abuse GDPR as much as they want. If they get caught then they'll just lose their business. The EU can't actually fine them, but that same company likely outcompeted EU companies for years.

>This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.

They can do the same thing with foreign companies though. If you can set up a system where you would use your small companies to escape regulation, then the same can be done with companies run by foreigners.

>2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ (first search hit).

And said business opportunity is additional inefficiency on businesses in the EU that their global competitors don't have to follow.

Re: GDPR fines were meant to rock the data privacy world

#37
post #33

Earlier quoted context omitted.

> they probably can't afford to do it right Two things occur to me here. 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. 2) Sounds…

> 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. Except that foreign companies won't have this same limitation. The end result is…

I recently did a stint as a contractor at one of Australia's "big 4" banks. I can assure you that they are so active in the privacy space, and foresee more and more GDPR-like regulations, that they've created their own privacy framework based on GDPR plus likely similar frameworks to come in other jurisdictions. It is one of the biggest funded projects in that bank (it helps that Australia recently had a negative spotlight on the banks' behaviour. Thanks Royal Commission!).

The point I'm trying to make is that if you have European customers, then the GDPR applies. Therefore, "foreign companies" competing for EU customers, definitely do have this limitation. Fines have been issued for companies that don't comply, and the sizes vary immensely (e.g. over 200 million euro for British Airways down to 118 euros (not millions, 118) for the Data Protection Authority of Saarland).

http://enforcementtracker.com/

Re: GDPR fines were meant to rock the data privacy world

#38
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Much like a bulk of eu regulation, made by people who have no clue how the real world works. No longer wondering why the uk wants to leave, and why those who stay have to kept in by fear.

Re: GDPR fines were meant to rock the data privacy world

#40

Earlier quoted context omitted.

Its funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"

But that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then the…

But I don’t think McDev above was talking about a software startup in the poorest part of the world. I have implemented GDPR in a small non profit open source SaaS business. A funded startup should have no issue doing the same.
Post reply on HN