Earlier quoted context omitted.
The amount of discretion and lack of clarity in the penalties is part of the problem. It opens you up to risk based on the whims of politics and the regulators and increases uncertainty. Laws should be clear, limited, and understandable - this is not.
I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…
GDPR: Don't Panic
381–390 of 833 posts
Re: GDPR: Don't Panic
#382Earlier quoted context omitted.
In principle I might agree with you, however the EU has a long history of striking a fair balance between consumer rights and commercial interests. There is no point, in history, of the EU doing anything remotely like you've described. Which actually gives me more faith in the GDPR than legislation in a corrupt ecosystem as corrupt individuals will find a way to warp legislation in their favor anyway. So yes, I do tr…
Related to this, there is a difference in culture that may had add to the fear for people running SMEs outside of Europe. I am talking about a difference in the culture of fines, at least at the local level of government based on my personal experience. When I lived in Canada (and the US briefly) it was common for me to get fined for various trivial offences. I used to joke I should have a fine budget, or at least fi…
Re: GDPR: Don't Panic
#383Re: GDPR: Don't Panic
#384Earlier quoted context omitted.
But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…
"his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future." EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and…
As you mention that "they are wrong" in reference to saying that the regulators aren't to be trusted, could you explain how the Dutch regulator behaved badly?
I'm Dutch and have followed what they've been doing over at least 10+ years. I don't think I'm wrong in my assertion, but feel free to point out the details. Also, I'd like to know how often you've followed what the Dutch regulator has been doing. I get the feeling you're not aware of their name.
Re: GDPR: Don't Panic
#385The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.
I think it gets "hate" from people who don't have much data but they still have to implement all the requirements, which go beyond than their own data storage. Ad-supported websites are probably the most common case here, even if the sites don't store any data themselves.
Internet advertising is a viper pit of privacy invasion. They didn't get their house in order, and let it turn into the horrible mess it is today, so they shouldn't be surprised that the regulators stepped in.
Re: GDPR: Don't Panic
#386The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.
I don't think that's fair. I rather think it gets a lot of hate because it leaves a lot to the discretion of the regulators. Overall, the SMEs I talk to don't have a problem with regulating data (most think it will pop the gangrenous ad-tech bubble). It's the lack of predictability that bothers them.
"You're making efforts to comply with the regulations, but could you have a look at how you're storing this and that?"
vs
"You're not compliant with the regulation so we have to impose a fine"
Are you really saying you'd prefer the second?
Re: GDPR: Don't Panic
#387Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.
Re: GDPR: Don't Panic
#388Earlier quoted context omitted.
GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.
Many countries believe their law applies extraterritorially. The US Foreign Corrupt Practices Act applies to any company that does any business in the US. A German director of a Canadian company that pays a bribe to an Ethiopian government official can be prosecuted under the FCPA if they set foot in the US. Sweden will prosecute citizens, and I presume residents, who purchase the services of a sex worker abroad. I d…
Re: GDPR: Don't Panic
#389This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…
> and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc. If your company can not show the candidates why they were not hired, you are doing a very bad job. Are you discriminating against protected classes? Are you rude or offensive in your comments? Then, stop doing it. That will be a very good side-effect of this situation.…
Re: GDPR: Don't Panic
#390Earlier quoted context omitted.
>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.
That's what we've chosen to do. The reality is that most businesses outside the EU will wind up blocking EU traffic, simply because they don't want the liability.
If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.