Earlier quoted context omitted.
Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.
It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.
GDPR: Don't Panic
431–440 of 833 posts
Re: GDPR: Don't Panic
#432Earlier quoted context omitted.
It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.
Lol, the US has FATCA which makes it very difficult for fin-tech startups to work with americans. I'm an e-resident of Estonia, and almost all financial services state they cannot serve US clients.
Re: GDPR: Don't Panic
#433Earlier quoted context omitted.
i did not mean that the site doesnt work without tracking, but according to the law i should have the option to access the site without being tracked.
No. That is just plainly wrong. GDPR allows for tracking without opt in. It just needs to enable you to opt out of being tracked with for example a link to opt out in the privacy policy page. Something I still plan to make more visible (in the footer or something like that), but is already there [0]. These so called cookie layers are not necessary for tracking. They are not even necessary for first party on site adve…
Second, are you sure about this? My understanding is that if you use third-party tags such as analytics you need to get consent from users and not to use them if they don't consent.
One other thing that is not clear to me is if we need cookie prompts, and how can we implement cookie opt-ins/outs without being able to set cookies.
Re: GDPR: Don't Panic
#434Earlier quoted context omitted.
Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.
As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?
Re: GDPR: Don't Panic
#435Exactly. People try to explain to me how it is impossible to comply and usually it turns out that it would be easy. I think the problem most of time that people misunderstanding the requirements or not reading GDPR (not even TLDR versions).
There is no "TLDR" of the GDPR. It has to all be read, understood and complied with. This is basic legal compliance, and is not at all easy for a small business.
https://ico.org.uk/for-organisations/resources-and-support/d...
It captures the compliance with a checklist which is shorter than the original 88 page law.
Re: GDPR: Don't Panic
#436> The GDPR is going to expose me to fines of up to 20 million Euros for even the slightest transgression
> No, the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers at the various data protection agencies in Europe they will first warn you with a notice that you are not in compliance with the law, give you some period of time to become compliant and will - if you ignore them - fine you. That fine will be proportional to the transgression. You can of course ignore the fine and then ‘all bets are off’ but if you pay the fine and become compliant you can consider the matter closed.
What if you get warned and decide at that point to just shut the site/app/business/project down?
Or is it the case that once you begin operating under the GDPR era, you'll have to handle those "good natured" enforcement warnings, delete data, etc?
I get that I'm probably compliant, and probably wouldn't have any complaints against me. I just don't know if it's worth waiting it out to see if there's an issue, or if now is my only chance to easily not deal with it by just blocking EU users.
Re: GDPR: Don't Panic
#437Earlier quoted context omitted.
Do you have any experience with a Eu country internet regulatory service? I have experience with the CNIL (The french one), and they were helpfull and yes, good-natured. Part of our demand to be able to host data from hospital was drafted with their help, when they had no legal obligation to help us. A friend who work in a legal/tech startup also had good experience with them, and i don't know anybody who ever had a…
You seem to have misunderstood my comment. I was saying that from a legal complience perspective, the notion that the regulatary body is "good-natured" is meaningless. You have to comply with ever letter of the GDPR, you can't just do most of it, or interpret it loosely, and say "oh but they are good-natured people they will understand.". Legal complience doesn't work like that AT ALL!
Re: GDPR: Don't Panic
#438I was hoping for a nice respite to the anti-GDPR stuff we've seen recently, but this is just naked propaganda. In particular, the sentence: "the GDPR has the potential to escalate to those levels but in the spirit of the good natured enforcers ..." The author seems to have the idea that bureaucratic EU systems are inherently "good" and that even if things look bad on paper, it will be fine because they are "good" peo…
Re: GDPR: Don't Panic
#439Earlier quoted context omitted.
Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.
We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…
Re: GDPR: Don't Panic
#440Earlier quoted context omitted.
I really don't know why people think that the authorities will (or even could) automatically punish each minor infraction with 4 % of global revenue or 20 million €. GPDR article 87 specifies in great detail when fines should be imposed and how their value should be calculated, and the Article 29 WP also has a guideline on that: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889 It is therefore simply not p…
Because those people tend to come from a country which doesn't have laws open to interpretation and thus mark people who drunkenly pee on a fence with the same sex offender tag than child molesters. If you're country functions in a way where laws can't be interpreted according to context it's hard to think of a different system.