Earlier quoted context omitted.
GDPR is extremely uncivilized. Forgetting the absurd fines and burdens it places on companies for a moment, consider the extraterritorial reach that EU is claiming for itself. The EU has declared itself Grand Emperor of the Internet. Wars have been fought over less.
https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd . ? The guy committed an "US crime" in Russia, where what he did was not illegal. He arrived on US soil, where he committed no crime. He was still arrested and charged.
GDPR: Don't Panic
421–430 of 833 posts
Re: GDPR: Don't Panic
#422There's certainly no need to panic. The article doesn't address that apart from mindless hysteria there are some very real issues with GDPR. It doesn't have to of course because as the title suggests it's more about dispelling panic than about giving concrete advice. However, many real-life problems seemingly haven't even been considered by legislative bodies. In GDPR support forums questions like these have been rou…
Run your small company website without gathering personal data? No-one can sue you now, that couldn't before. I'm baffled that so many people believe this. I could complain about you to my country's regulation body. Then they could decide to audit you, and for a first offense issue a warning. If you need the address data for marketing only, and you didn't get an explicit (opt-in) yes to receive marketing, then sorry.…
> Storing an IP for a limited time for security reasons is fine. Have rules in place for how this data is used and when it is deleted. Don't keep it longer than nessescary.
How long is necessary? What does limited mean? Does a regulator now get to determine what sort of algorithms I can use to protect my assets? Advanced persistent threats (https://en.m.wikipedia.org/wiki/Advanced_persistent_threat) can exist over a very extended--and arbitrary time period! I'm in the security software industry, and we and our customers need to detect and react to these threats. That requires data which you simply cannot obtain an opt-in for. Sure, you put that in a posted privacy policy, but if you can only keep the data for 30 days, this means actual evidence of a crime might need to be thrown out.
Re: GDPR: Don't Panic
#423Earlier quoted context omitted.
In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act that requires any warnings of any kind, or places any limits on fines. The maximum sentence for possession of a Class B controlled substance is five years imprisonment and an unlimited fine. Period. A fine larger than the number of atoms in the un…
> In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act Not true. https://www.legislation.gov.uk/ukpga/1971/38/section/25 > The fourth, fifth and sixth columns show respectively the punishments which may be imposed on a person convicted of the offence in the way specified in relation thereto in the t…
Re: GDPR: Don't Panic
#424Earlier quoted context omitted.
https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd . ? The guy committed an "US crime" in Russia, where what he did was not illegal. He arrived on US soil, where he committed no crime. He was still arrested and charged.
That’s one guy in one case (that was eventually dismissed). There are probably a few handfuls of other examples you can post here. It doesn't hold a candle to the millions of people and businesses liable under the GDPR who face a nasty framework of foreign laws with no limits on fines other than $10/20 million.
Re: GDPR: Don't Panic
#425Earlier quoted context omitted.
Maximum possible fine for repeated worst possible violation after ignoring previous attempts at regulation and not making changes after previous smaller fines. It's not a minimum.
It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…
Re: GDPR: Don't Panic
#426Earlier quoted context omitted.
Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.
As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?
Re: GDPR: Don't Panic
#427This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…
Welcome to our world :)
Re: GDPR: Don't Panic
#428Earlier quoted context omitted.
>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.
Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.
We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have.
We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about 10 times less than the US market in our industry, so having them chasing peanuts in Europe (and investing in compliance with European - absolutely not international - regulations) would be a truely fantastic outcome for us.
Re: GDPR: Don't Panic
#429How does this affect people who aren't based in Europe?
I think many (most?) companies will implement these privacy policies across all of their users as it can be hard to determine whether a user is in the EU or not... so indirectly, this law might mean that everybody will finally have strong privacy guarantees (at least when it comes to companies of a meaningful size).
In terms of percentages, exceptionally few businesses outside of the EU will implement GDPR. The rest of the world will overwhelmingly entirely ignore it.
There are 20 million businesses in the US. 500,000 new businesses are created each year. 0.1% or less will comply with GDPR. Why? Because very few US businesses ever do business with the EU.
A small clothing retail shop from Texas or Florida or Michigan is not going to concern itself with complying with GDPR just because they took three orders from the EU. They're going to ignore GDPR and continue doing business as they always have. And the EU is going to find it entirely impossible to enforce compliance for those types of small instances due to the scale & tracking required to do so. If by chance they develop a larger EU business, then they'll comply.
Further, how do you force compliance on a US clothing shop from Florida, that sells 27 items per year into the EU, and violates GDPR (while having zero presence in the EU)? They can't, unless the EU develops a Chinese firewall.
The extremely majority of small businesses in India and China also do not do business with the EU. They will not be worried about GDPR. That's true about nearly all the rest of the businesses around the globe.
Re: GDPR: Don't Panic
#430Does anybody know if it's required to remove CDN links (such for Google fonts, cdnjs, etc.) and host all assets locally instead unless consent is given? Assets from CDNs are required for a site to function; what's not required is to send `Referer:` so maybe it's sufficient to set a referrer-policy.
Google fonts is just one of the many font libraries. For example, most web font licenses at myfonts.com don't permit webmasters to self host them. Bypassing the HTTP referer download protection, downloading them and then self hosting the font files could lead to significant legal problems.