Earlier quoted context omitted.
But merely being a repeat offender isn't enough to trigger the maximum fine. You'd have to be a consistant repeat offender, with no effort made at remediation, with no cooperation with the regulator, and probably handling sensitive or financial data. Here's a list of recent actions taken. I think the current maximum fine is £500,000. Have a look through a few of these hopefully it's somewhat reassuring. https://ico.o…
Note that this is the UK agency, you might see different behaviors if you scanned the Belgian regulators enforcement list.
GDPR: Don't Panic
401–410 of 833 posts
Re: GDPR: Don't Panic
#402Earlier quoted context omitted.
There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…
Isn't there wording that says the punishment is proportional with your transgression?
Re: GDPR: Don't Panic
#403Earlier quoted context omitted.
You're right, laws in Europe are uncivilized, maybe that's why they have the highest rate of incarceration in the world.
GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.
Re: GDPR: Don't Panic
#404Earlier quoted context omitted.
The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.
It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…
Have you seen this? It seems to say that GDPR allows you to do what you're doing.
https://gdpr-info.eu/art-6-gdpr/
> processing is necessary for compliance with a legal obligation to which the controller is subject;
Re: GDPR: Don't Panic
#405This doesn't consider some factors that dictate how strong any company will experience their firehose of GDPR requests to be: - how incentivised people are to make GDPR subject access requests of the company (how angry, confused, hostile curious they are) - how easy it is for them to make requests (entirely manual vs. online service) - wildcard factors (internet flash mobs bent on vengeance against a corporate) There…
> and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc. If your company can not show the candidates why they were not hired, you are doing a very bad job. Are you discriminating against protected classes? Are you rude or offensive in your comments? Then, stop doing it. That will be a very good side-effect of this situation.…
You sound like you've never had to deal with telling a candidate they weren't chosen for a position. There's a reason rejection letters are usually canned responses - it's not that HR teams are unanimously evil people, it's because any bit of information could open up the potential for a law suit, even if in good spirit. Someone gets a rejection letter saying "they aren't a good fit"...oh well it must be because I have different colored skin, right? It's a slippery slope from there.
Re: GDPR: Don't Panic
#406Earlier quoted context omitted.
The substance of this line of criticism is that yes, it's probably going to be fine. But if it's not, they can fine you at 4% of global turnover. They probably won't, but they literally can . "I read on a blog that they'd be nice and send me a warning first" gets you exactly nowhere in court ("very well, but what did your lawyer tell you?"). The article praises the GDPR for having teeth -- being timid can be somethin…
> "I read on a blog that they'd be nice and send me a warning first" That's not what happened. Various people pointed out various cases where it's shown over the course of 20 years what happened. Ample history. > Don't panic, but take the advice of a non-lawyer's blog over your actual lawyer's at your own extreme peril. Are you from the US or EU? Immediately going to a lawyer seems strange and unique to me. Within a…
Yes, and other various other people are pointing out that now there's a new law that changes a lot of things, perhaps what happened in the last 20 years isn't a perfect guide for what's going to happen in the future.
> Immediately going to a lawyer seems strange and unique to me
I'm from the EU, and I go to lawyers for things much smaller than those that can get me fined 4% of turnover. And so should you, if you're serious about managing your risk. If your things are in order, it's not terribly expensive, and you get to lean on your lawyers professional liability insurance if things get weird regardless.
Re: GDPR: Don't Panic
#407Earlier quoted context omitted.
I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…
>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.
Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.
Re: GDPR: Don't Panic
#408Earlier quoted context omitted.
> and also to be curious about why they were not hired. A GDPR button lets them indulge their curiousity and start digging in to interview notes etc. If your company can not show the candidates why they were not hired, you are doing a very bad job. Are you discriminating against protected classes? Are you rude or offensive in your comments? Then, stop doing it. That will be a very good side-effect of this situation.…
> If your company can not show the candidates why they were not hired, you are doing a very bad job. You sound like you've never had to deal with telling a candidate they weren't chosen for a position. There's a reason rejection letters are usually canned responses - it's not that HR teams are unanimously evil people, it's because any bit of information could open up the potential for a law suit, even if in good spir…
...in the US. Probably not anywhere else, unless the hiring company is illegally discriminating.
Re: GDPR: Don't Panic
#409Earlier quoted context omitted.
Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.
It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…
When I read things like this I realize how many companies are not treating user data as they should. Protecting user data should already be built into the company software and process.
Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.
Re: GDPR: Don't Panic
#410I think people should be glad about this in the long run, it shows the law has teeth. Some things are going to shut down as a result of this, that is a normal result of added regulations. If nothing changed it would prove the law didn’t do anything.
There are plenty of food businesses that just never start because of the regulations involved. Our societies have decided that’s okay- but it’s still something we decided, because you can’t have it both ways. People who take one look at it and say “nah, not worth it” are not necessarily overreacting. It’s petty to paint it that way, and certainly unhelpful.