Live data from Hacker News

What does the GDPR actually mean for startups?

hackernoon.com

41–50 of 56 posts

Re: What does the GDPR actually mean for startups?

#41

Earlier quoted context omitted.

That's a reasonable point, but it's also reasonable to observe that businesses rely on other businesses all the time. As a small business, you usually have little meaningful oversight of the internal processes of outside services you use. You don't get to audit your bank's finances to make sure they're safe to trust with your money. You don't get to review your lawyer's office security arrangements to make sure no-on…

> You don't get to review which products your office cleaning firm uses. Seems a bad analogy, do you make a contract with them but not read it? I mean in the contract you will specify what cleaning products can or should be used(like in some hospitals strong cleaning products must be supplied and you ask for those in the contract if the supplier gives you bad quality ones then sure it is not your fault but it is your…

At least his US customers can now know that their data are could be shared with many third parties that could have weird terms like those third parties could sell it further.

I guess my point is that just knowing of the possibilities isn't particularly helpful on its own. If we're interested in actual privacy and data protection, instead of merely paying lip service to them, what matters is not just what a data subject knows but what control they have and what protections against harm they automatically enjoy. So much of the discussion around the GDPR and privacy policies and this whole subject more generally is only about telling people how they're being exploited instead of just exploiting them quietly without them knowing as happened before. That might be a step in the right direction, but it's far from where I would like the emphasis to be.

Re: What does the GDPR actually mean for startups?

#42

Earlier quoted context omitted.

> You don't get to review which products your office cleaning firm uses. Seems a bad analogy, do you make a contract with them but not read it? I mean in the contract you will specify what cleaning products can or should be used(like in some hospitals strong cleaning products must be supplied and you ask for those in the contract if the supplier gives you bad quality ones then sure it is not your fault but it is your…

Okay, but do you ensure the manufacturer of those cleaning supplies is making them correctly? Do you test the products coming from that facility to ensure they are of sufficent quality before allowing them to be used by your office cleaning firm? And do you vet the ingredients that the manufacturing facility uses to ensure they are pure and safe? Because the commenter above makes a fantastic point that I hadn't thoug…

No, my point was about the OP that said he does not have the time to read the TOS of the third parties he uses.

About the cleaning example if you had a contract that asked for a certain level of quality and they sent you bad product or did a bad job then it is your duty to stop this if you are aware the contract requirements are not respected.

I would also do some tests on the quality of the cleaning products just because people are greedy and they could send me bad products and cost me later.

Re: What does the GDPR actually mean for startups?

#43

Earlier quoted context omitted.

These are your customers. If you don't have the time or resources to talk to your customers, then your business is going to fail anyway. This point isn't about your customers. It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. And if you think this is a hypothetical risk, read the news today about kids linin…

> It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. Except you can't sue anyone under the GDPR. All you can do as a consumer/bitter ex-customer is file a complaint with your country's privacy watchdog. IF there really is a problem, they will just tell you to fix it, that's all. You only need to worry if you…

Unfortunately, the entire point of the "nightmare letter" was that much of what you just wrote isn't actually true. It wasn't about suing anyone. It was about wasting their time and potentially their money identifying which of the numerous points actually required a response (and a few traps among them that most certainly did not) and then gathering lots of obscure information they probably didn't just have as standard in their usual information management systems or published in their privacy policy, and highlighting the fact that the GDPR removed the small but non-zero fee that previous law allowed for exercising these rights that served as a practical barrier to this kind of abuse.

Re: What does the GDPR actually mean for startups?

#44

Earlier quoted context omitted.

Okay, but do you ensure the manufacturer of those cleaning supplies is making them correctly? Do you test the products coming from that facility to ensure they are of sufficent quality before allowing them to be used by your office cleaning firm? And do you vet the ingredients that the manufacturing facility uses to ensure they are pure and safe? Because the commenter above makes a fantastic point that I hadn't thoug…

No, my point was about the OP that said he does not have the time to read the TOS of the third parties he uses. About the cleaning example if you had a contract that asked for a certain level of quality and they sent you bad product or did a bad job then it is your duty to stop this if you are aware the contract requirements are not respected. I would also do some tests on the quality of the cleaning products just be…

But again, this isn't the core aspect of your business. You might do this for the cleaning products, but will you do the same diligence for the lightbulbs you use? The paint on your walls? The apps on the phones of your employees?

That's a LOT to ask.

I shut down a side project that stored some cookies on the browser for some small settings, and allowed users to upload images of stuff they made in the browser to imgur if they wanted. After looking at the GDPR, I decided to shut it off. I don't have the time or ability to properly vet all of the possible places a users information could end up (user's information in this case is possibly an IP address which the hosting provider might have, but i don't know or have a way of knowing, and the image that they created in the browser which can optionally go to imgur), and the project made me a total of $11 of profit, and from a lawyer I talked to at my main employer, just blocking EU users isn't enough.

Re: What does the GDPR actually mean for startups?

#45

Earlier quoted context omitted.

> It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. Except you can't sue anyone under the GDPR. All you can do as a consumer/bitter ex-customer is file a complaint with your country's privacy watchdog. IF there really is a problem, they will just tell you to fix it, that's all. You only need to worry if you…

Unfortunately, the entire point of the "nightmare letter" was that much of what you just wrote isn't actually true. It wasn't about suing anyone. It was about wasting their time and potentially their money identifying which of the numerous points actually required a response (and a few traps among them that most certainly did not) and then gathering lots of obscure information they probably didn't just have as standa…

> It was about wasting their time and potentially their money identifying which of the numerous points actually required a response

I've seen the letter and it's all questions you should be able to easily answer anyway. If this letter would be a nightmare scenario for you you'd better get your shit in order, regardless of the GDPR.

Re: What does the GDPR actually mean for startups?

#46

Earlier quoted context omitted.

These are your customers. If you don't have the time or resources to talk to your customers, then your business is going to fail anyway. This point isn't about your customers. It's about the bitter ex-customer who decides to take revenge through legal means by exploiting the rights they have under the GDPR to waste your time and money. And if you think this is a hypothetical risk, read the news today about kids linin…

Anyone in retail deals with nightmare customers who use social media to cause them untold pain and misery, and wastes huge amounts of time. It's no different, except that in the GDPR case you can automate the response, and there's an actual regulator at the other end who can decide that the complaint was frivolous. Dealing with customers is always nightmarish waste of time. But necessary. I haven't heard about the ex…

Anyone in retail deals with nightmare customers who use social media to cause them untold pain and misery, and wastes huge amounts of time.

Of course. But they don't do it with the active blessing and support of the legal system.

Again, if you don't understand how your customer's data is being used by a third party, then perhaps you shouldn't use that third party.

Unfortunately, that's easier to say than to respect in practice.

For example, I run a business that allows customers to pay by credit card. There are many parties involved in a single card payment. Obviously at some point along the way there are various checks done to try to reduce instances of fraud. Those almost certainly include automatic decision-making processes that affect my customers.

And yet I don't even know -- and in fact can't know; I asked -- who is making those decisions that might prevent my customer from buying something from me today, nor what basis is used. There is no meaningful right of appeal if my customer or I don't like the decision. In fact, my business can have the money clawed back months after a payment went through apparently successfully and even be fined if one of those payment services up the chain that I still can't identify doesn't like anything for any reason, with no useful explanation given and again no meaningful right of appeal.

This whole arrangement is so totally against the spirit of contracts, money, privacy and data protection rules, and basic common sense that it defies belief. And yet it is absolutely routine: your only alternative as a merchant is not to accept card payments, and your only alternative as a customer is not to have a payment card at all.

Re: What does the GDPR actually mean for startups?

#47

Earlier quoted context omitted.

Unfortunately, the entire point of the "nightmare letter" was that much of what you just wrote isn't actually true. It wasn't about suing anyone. It was about wasting their time and potentially their money identifying which of the numerous points actually required a response (and a few traps among them that most certainly did not) and then gathering lots of obscure information they probably didn't just have as standa…

> It was about wasting their time and potentially their money identifying which of the numerous points actually required a response I've seen the letter and it's all questions you should be able to easily answer anyway. If this letter would be a nightmare scenario for you you'd better get your shit in order, regardless of the GDPR.

I've seen the letter and it's all questions you should be able to easily answer anyway.

The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. If you think that is easy, presumably you know how to automate that process, in which case I look forward to seeing the multi-billion-dollar business you have presumably built scanning unstructured data reliably in ways that no-one else has figured out how to do yet.

Re: What does the GDPR actually mean for startups?

#48

Earlier quoted context omitted.

> It was about wasting their time and potentially their money identifying which of the numerous points actually required a response I've seen the letter and it's all questions you should be able to easily answer anyway. If this letter would be a nightmare scenario for you you'd better get your shit in order, regardless of the GDPR.

I've seen the letter and it's all questions you should be able to easily answer anyway. The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. If you think that is easy, presumably you know how to automate that process, in which case I look forward to seeing the multi-billion…

> The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions.

The magic words here are "still stored", PII is a liability so you never want to store it longer than absolutely necessary. Why are you hoarding this data when you can't even retrieve it easily, what is the point ?

Re: What does the GDPR actually mean for startups?

#49

Earlier quoted context omitted.

No, my point was about the OP that said he does not have the time to read the TOS of the third parties he uses. About the cleaning example if you had a contract that asked for a certain level of quality and they sent you bad product or did a bad job then it is your duty to stop this if you are aware the contract requirements are not respected. I would also do some tests on the quality of the cleaning products just be…

But again, this isn't the core aspect of your business. You might do this for the cleaning products, but will you do the same diligence for the lightbulbs you use? The paint on your walls? The apps on the phones of your employees? That's a LOT to ask. I shut down a side project that stored some cookies on the browser for some small settings, and allowed users to upload images of stuff they made in the browser to imgu…

I agree that is a lot of extra work if you want to delegate part of your work to a third party, but in present you don't send credit cards info, secret api keys to any third party, so it is fair to try protect the other kind of data(not only credit card or medical data)

What I hope is that this third party services will advertise the fact they respect GDPR or put documentation on how to properly use this APIs and respect GDPR.

As a user when I get the GDPR prompt that has only the Accept button I just close that page or if I really want to see the content I use a private window, accept the popup .

If i would build my own product SPA I would avoid the third parties crap, if I can't because I really need the third party I would make sure to read the TOS since at my work I seen how much it sucks getting screwed by a third party.

Re: What does the GDPR actually mean for startups?

#50

Earlier quoted context omitted.

I've seen the letter and it's all questions you should be able to easily answer anyway. The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. If you think that is easy, presumably you know how to automate that process, in which case I look forward to seeing the multi-billion…

> The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. The magic words here are "still stored", PII is a liability so you never want to store it longer than absolutely necessary. Why are you hoarding this data when you can't even retrieve it easily, what is the point ?

Why are you hoarding this data when you can't even retrieve it easily, what is the point ?

Do you have a filing system for every email you ever wrote? Can you identify every backup copy, every forwarded message, every print-out, every excerpt copied and pasted into a Word document? Can you remember or look up every individual ever referenced in those messages?

Now, let's talk about letters. The paper kind. And faxes. Including unsolicited ones that aren't part of any formal process where a customer helpfully included their password so you knew it was from them. And mentioned that it's their mother's birthday, in case you were wondering.

Have you ever written down an address or phone number on a piece of paper because that was what you had to hand when someone read it out to you over the phone? Or opened up a quick text file to keep notes from a meeting?

If you're a director responsible for a company of 2,000 staff, do you think anyone else in your company has ever done any of those things, and would you like to bet your job that no-one ever kept a record other than as part of your comprehensive, perfectly-specified and loophole-free official processes?

If you're a director of a startup with 5 people, do you even have those processes, or is almost everything actually being done with text files and Post-It notes (or Slack channels and Google Docs, or...)?

This is not an easy problem. People have made very, very large amounts of money building businesses trying to solve this problem, and the first people who really nail it are going to make even more. You can't just hand-wave away the possibility of having personal data that is not immaculately organised, rigorously controlled and fully indexed in any organisation of significant size and lifetime. A law that makes such a requirement is like a law that says you can only ship software with no bugs, or a law that says all laws will be unambiguous and enforced with zero tolerance.

Post reply on HN