Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

461–470 of 833 posts

Re: GDPR: Don't Panic

#461
post #427

This article actually points out my philosophical problem with GDPR. In one point he says you have to be compliant if you want to do business in the EU. In another he observed that it is difficult (maybe impossible) to block EU folks from coming to a web presence. It’s the expansive reach that bugs me. I’ll note that for real businesses this is just a thought excercise, but it’s one I keep coming back to. What if som…

Are you American, by any chance? The whole internet dances to the US tune, legally. Welcome to our world :)

For 20+ years the US - as the dominate controlling agent regarding the Internet - ensured the modern (post early 1990s) Internet remained extremely non-regulated and non-interfered with by ~195 nations (when it came to the global Internet system). It worked globally out of the gate and required no special adherence to US laws. The Chinese did not have to adopt US freedom of speech approaches to use the Internet. The Iranians or Saudis did not have to adopt US freedom of religion approaches to use the Internet. The EU did not have to adopt US legal approaches or laws to use the Internet. Any other scenario than the one the US pursued would have resulted in a fractured, mostly useless global Internet. The US was about as good of a shepherd as any nation could have ever been: thus we got several billion users onto the Internet from wildly diverse background jurisdictions. The way the US built the Internet made it possible for the EU to say: hey, we're going to do GDPR, because that works for us (and yet the Internet still works); and for other jurisdictions to say: hey, we're going to do this that or something else because that works for us.

> The whole internet dances to the US tune, legally.

You've got that almost exactly backwards. The US approach has required almost no dancing at all to the US tune. That's precisely why ~4 billion people can use the Internet from 195 nations, all with dramatically varying laws. They're not adopting US law to use the Internet. That's why the Chinese have been able to implement their unique approach and still use the Internet (restricted to fit their tolerances at a government level).

You very specifically do not have to dance to US legal tunes to use the Internet. Even when it comes to IP laws, you do not have to dance to the US tune (Europe has varied widely from the US on such, eg as it relates to piracy, and yet the Internet keeps on regardless).

Re: GDPR: Don't Panic

#462
post #414
post #364

Earlier quoted context omitted.

If you are fined 10k-100k you have the typical problem of whether it is worth fighting.. But you are supporting the argument that you could be illegally (according to article 83) fined 4 million euros as a first offence because a regulator wants to be disproportionate and set an example with your small company and then have costs of 10-100k to throw out an obvious case, but it wouldn't be worth it?

It's worth it but it bankrupts you. No customers, no investors, and all your cash gone before your appeal is heard. Block all EU traffic. Just cut the transatlantic cables.

I don't think there's a need to cut the transatlantic cables, but if a company doesn't want to take proper care of user data then it's perfectly reasonable that they stay away from that market and let other companies have that business.

Re: GDPR: Don't Panic

#463

Earlier quoted context omitted.

I am concerned that the effect of this legislation on the private individual is the opposite of the stated intention. People are being forced to sign agreements which jeopardise the natural rights to their data which they would otherwise have. One example: a friend who has a very pretty daughter was asked by her school to give them the right to film her and to use any and all such recordings as they see fit for 50 ye…

The only thing which would make that outrageous would be an element of force (which would make it not consent anyway, but I digress). Instead, you're giving an example that explicitly allows for a denial. That's exactly as it always should have been, so I really don't understand what the point is that you're trying to make here.

The point is simply that the school is now at risk of huge fines, so in turn it puts pressure on parents to sign as strong as possible waivers. Not many people here seem to understand it but that is what is happening.

The force is of purely psychological nature, of course: "surely, you don't want to cause problems to your school?"

Re: GDPR: Don't Panic

#464

Earlier quoted context omitted.

Good lord, it's like you didn't read the article. Or, you're fine with a competitor who isn't afraid of entirely reasonable international laws coming in and eating your lunch.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about.

my company OTOH is choosing to apply gdpr principles globally.

Re: GDPR: Don't Panic

#465
post #80

Earlier quoted context omitted.

The regulators have been running for two decades, and this is EXACTLY how they operate. Scepticism in this case is unreasonable, given the massive evidence base.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

>if in 10 years a new Commission arrives and changes their mind they can retroactively decide that things previously allowed were actually illegal.

If 1) A new European Commission arrives and proposes a change in the law that is retroactive; AND 2) The European Parliament agrees with the change; AND 3) The Council of the European Union (ministers from every EU member state); AND 4) the Court of Justice of the European Union doesn't strike the legislation down

THEN you can worry.

Re: GDPR: Don't Panic

#466

Earlier quoted context omitted.

An advocate of rules-based regulation would say this can make regulators unpredictable and capricious. Unfortunately, so might students of history. Ask anyone in the UK who was working in the freelance or contract world when IR35 was introduced. In that case, too, the principle was reasonable enough: there was a loophole in tax law where you could decide you're a contractor instead of an employee and pay less money d…

> It turns out that the vast majority of contractors and freelancers were operating in that fashion legitimately and continue to do so Which we know is definitely NOT the case for companies storing your data correctly.

Are you claiming that most companies are not storing data in compliance with current law today? There's a meme about how all businesses are trying to exploit personal data mercilessly at any cost, yet among the small businesses around here and the people I know who work there, none of us is in that line of work, nor I suspect would any of us want to be.

Re: GDPR: Don't Panic

#467

Earlier quoted context omitted.

Lol, the US has FATCA which makes it very difficult for fin-tech startups to work with americans. I'm an e-resident of Estonia, and almost all financial services state they cannot serve US clients.

Lol, the EU has GDPR which makes it very difficult for any startup to work with anyone because of the danger that someone from the EU might stumble by.

Except that FATCA's sole purpose was to raise money, and the US isn't even compliant itself. FATCA is a whole different ball game to GDPR, and I don't recall the complaints from Americans when EU instituions were forced to implement it. In addition, the costs for implementation of FATCA were huge. Most people are halfway there with GPDR compliance already, unless they're doing something they really shouldn't have been doing.

GDPR is not a money making mechanism but a way of forcing compliance. I think that's the difference that many US people don't seem to understand.

Also I was responding to the comment that the US has never done anything like this, which is completely false, US people tend to forget what it's like for the rest of the world.

Re: GDPR: Don't Panic

#468

Earlier quoted context omitted.

As a formerly European person running internet companies in the USA this baffles me. Why the teeth gnashing over being told not to spy on your users?

We’ve got a great privacy policy, and don’t abuse our customers data in any way. However compliance would be very expensive for us, largely due to some of our early architecture decisions. The liability is also insane, and we don’t want anything to do with it. When we looked at how little our EU customers were worth to us, it was a very easy decision to simply abandon them.

so you say. if you don’t have strong processes to make sure that is true, it isn’t true. gdpr is mostly about ensuring you have such processes. if you can’t do things such as tell the user what data you have, and delete it, you do not have a great policy.

methinks you need some advice from better counsel. i bet that you are closer to compliant than you think.

Re: GDPR: Don't Panic

#469

Earlier quoted context omitted.

It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. You can, of course, say "don't be slow then", however, when for an out-of-EU entity (be it biz, or NGO) simple math doesn't show it is worth the effort, then it makes perfect sense to stop offering services to EU. Which is a side effect of the legislation. OP apparently understands it puts GDPR in a…

> It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. When I read things like this I realize how many companies are not treating user data as they should. Protecting user data should already be built into the company software and process. Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.

As a user I suppose they should do whatever satisfies me, and I'm not always need a bunch of populists from EU parliament, who can't write a clear text, run to save me, making field even more favorable for big corpos at the expense of SMEs, and small non-profits in the course of action.

>Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.

That would be good news for the EU, of course. Even before GDPR, entrepreneurs were routinely advised to incorporate in US instead, and the legislation likely added incentives for that.

Re: GDPR: Don't Panic

#470
post #80

Earlier quoted context omitted.

But that's purely your own opinion. I do have some direct experience of working with EU data protection regulators. My experience has been that they vary wildly in "reasonableness". UK ICO is pretty OK, they want companies to succeed. France's CNIL is a joke. Petty, spiteful and utterly inconsistent. I watched as a company worked closely with them to get their sign-off on a change to their terms of service and privac…

"his belief that everyone working in GDPR enforcement in the EU will not only be totally predictable and reasonable today but also going forward into the indefinite future." EXACTLY! There seems to be an almost cultish devotion to the benevolent institution that it can do no wrong, neither now nor henceforth. I understand WHY people have this belief. The EU is under constant attack at the moment from many sides, and…

This seems like a very dishonest assessment. Are all the people who see this differently from you just brainwashed EU cultist who just feel the need to defend wrong things?
Post reply on HN