Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

451–460 of 833 posts

Re: GDPR: Don't Panic

#451
post #387

It ain't hysteria if you're in Germany, and a private individual or a nonprofit (e.V.). Due to specialities of German law third parties can serve you legal writs for hundreds or thousands of EURos. Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.

Can you point me to a more detailed source on this issue? I have heard Germans concerned about getting sued by third parties for minor website legalese issues.

I'm not fluent in German so I wasn't able to fully understand the situation.

Re: GDPR: Don't Panic

#452
post #439

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

I find it amazing so many companies are willing to advertise the fact that they will abuse their customers in the way you are doing right now.

Where did I advertise misuse of our customers data? Compliance and privacy are not the same thing, just like compliance and security are not the same thing. We have a great privacy policy and we don’t misuse our customers data in any way.

For us, it didn’t make sense to invest the amount of money we’d have to to establish compliance with the GDPR, or to invest in maintaining that compliance, and the liability that GDPR would introduce for us most certainly didn’t make sense.

Europe is worth almost nothing to us, we don’t market ourselves there because it’s a waste of money. The EU customers we have all sought us out, not the other way around. For us, the cost and liability is simply not worth it. I think you’ll start to see more businesses make this decision, based on facts and numbers. You can’t just cry that they’re all being hysterical or want to abuse they’re customers data and privacy. When you introduce expensive new regulations, that have very strong punitive elements, this is exactly what you’d expect to happen. Small to medium sized businesses will wear the most of the cost (while posing the least of the risk). Luckily for us, EU is worth close to nothing for us.

Re: GDPR: Don't Panic

#453

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

An advocate of rules-based regulation would say this can make regulators unpredictable and capricious. Unfortunately, so might students of history. Ask anyone in the UK who was working in the freelance or contract world when IR35 was introduced. In that case, too, the principle was reasonable enough: there was a loophole in tax law where you could decide you're a contractor instead of an employee and pay less money d…

> It turns out that the vast majority of contractors and freelancers were operating in that fashion legitimately and continue to do so

Which we know is definitely NOT the case for companies storing your data correctly.

Re: GDPR: Don't Panic

#454
post #376

Earlier quoted context omitted.

> In England and Wales, you could be fined £10^99 for having a crumb of cannabis in your pocket. There is nothing - and I do mean nothing - written in the Misuse of Drugs Act Not true. https://www.legislation.gov.uk/ukpga/1971/38/section/25 > The fourth, fifth and sixth columns show respectively the punishments which may be imposed on a person convicted of the offence in the way specified in relation thereto in the t…

You've misread the legislation. The maximum sentences you're referring to are for summary convictions at a magistrates court. Possession of a controlled substance is an each-way offence which can be tried at either a magistrates or crown court. There is a higher maximum sentence if your offence is tried at a crown court, which is listed in schedule 4, namely "5 years or a fine, or both".

But that law has to be read in conjunction with others, which set out when trial is at magistrates or crown court; and what the sentencing guidance is.

The courts must follow the sentencing council guidelines unless it's in the public interest not to do so.

https://www.sentencingcouncil.org.uk/wp-content/uploads/Drug...

The starting point is 100% of weekly income; the range is 75% to 125% of weekly income.

> Band B 100% of relevant weekly income 75–125% of relevant weekly income

Re: GDPR: Don't Panic

#455

Earlier quoted context omitted.

Or, you know, just block European clients from your service if you don't agree to our laws? It's not like if the US laws didn't have any extraterritoriality.

It's not like if the US laws didn't have any extraterritoriality. This is a disingenuous argument. The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website. In fact, no country has ever done this before. GDPR is different, and not in a good way.

> The US has never passed a law that is this easy to violate outside of its own borders, is this ripe for abuse, and carries such enormous penalties and burdens for essentially everyone in the world that wants to operate a website.

The US has clearly passed many laws that meet all those criteria but the last (and with much harsher, often criminal rather than merely financial, penalties), so unless you believe that operating a website is somehow a unique class of activity deserving special protection from extraterritorial application of laws, this is a pointless comparison.

And there's actually a number of US laws affecting website operators that arguably meet all three criteria, as other comments point out.

Re: GDPR: Don't Panic

#456
post #445

Earlier quoted context omitted.

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

Then they can just do that. I'm sure other companies will be happy to scoop up that business.

We’d be quite happy if that happened. Seeing our competitors investing in Europe would simply mean less competition in markets with much greater growth.

Re: GDPR: Don't Panic

#457

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

Wow I wish we had principle-based regulation in the US. It seems like rules are made specifically so that only wealthy, entrenched institutions can follow them without significant burden. When those institutions fail, the fines don't seem relative to profit or size of the company or anything.

Re: GDPR: Don't Panic

#458

Earlier quoted context omitted.

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

> This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. This is a good point, but many people seem to forget that most misdemeanor criminal offenses in the US are punishable by fine and/or up to 30+ days in jail. People do not often get the jail time so most don't even think about it, but it is available as an option to the…

Unfortunately in the US, any conviction leads to essentially a work "blacklist," whereby employers do background checks and deny employment for anything they find within 7 years.

Re: GDPR: Don't Panic

#459
It's like if a new law were introduced requiring a license in order to ride a bike, to make sure people don't hit pedestrians or bike dangerously in the road. The license is free, it just takes a weekend to go take a written test and demonstrate that you can safely ride a bike. Some people who would pass but can't be bothered to give up a weekend would instead choose to just stop biking. It's an unavoidable consequence of introducing a friction where there wasn't one, and there's no way to carefully target or wordsmith the requirement so that this doesn't happen.

I think people miss that there is a very large qualitative difference between "no law" and "law". Even a very carefully targeted law will still have the effect, on the margin, of preventing or stopping compliant activities. But in the case of something like privacy, or control of data about you, maybe that's worth it in order to stop the noncompliant activities.

On a non-hypothetical topic: does anyone have a good resource on the requirements with regard to backups? That's one of the larger technical sticking points for me - do we have to delete from our backups as well on such a request?

Re: GDPR: Don't Panic

#460

Earlier quoted context omitted.

>we can trust EU regulators I want to stress that this is a major point of political polarization in Europe at the moment. Even if this claim is true, it warrants a clear and articulated defense.

Also any Americans reading “we can trust X” will likely get a good laugh out of this. It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government.

> It is irresponsible not to assume that if the law is written a certain way then at some point, the law can (and likely will) be enforced that way when it suits the government.

With the caveat that "the law" in this case isn't just the GDPR, it's the entirety of EU case law. GDPR exists in a particular legal context.

Post reply on HN