Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

481–490 of 833 posts

Re: GDPR: Don't Panic

#481
Constantly trying to whitewash over the fact that GPDR is a huge pain in the ass and will involve a lot of work for a lot of companies is what I don't understand, but Mr. Mattheij has been doing it for months, so that's evidently very important to him for some reason.

It's chewed up a few weeks of active development time putting in features for purging and exporting anything that looks like it might be personal information, plus a considerable magnitude more hemming and hawing and trying to figure out if, how and to what extent the regulations apply to us, and how the customers that we sell our products interpret the regulations and what features they require for their interpretation of compliance. It's a big headache, especially where we are also dealing in industries that have conflicting data retention requirements.

If we didn't have EU-based customers with sufficient sales to justify the effort, there are a thousand and one other things that we could have better spent that time and energy on.

Re: GDPR: Don't Panic

#482
post #439

Earlier quoted context omitted.

I find it amazing so many companies are willing to advertise the fact that they will abuse their customers in the way you are doing right now.

Where did I advertise misuse of our customers data? Compliance and privacy are not the same thing, just like compliance and security are not the same thing. We have a great privacy policy and we don’t misuse our customers data in any way. For us, it didn’t make sense to invest the amount of money we’d have to to establish compliance with the GDPR, or to invest in maintaining that compliance, and the liability that GD…

You are advertising that your handling of personal data is so haphazard that GDPR compliance would be expensive. You are admitting that you aren't good enough for the EU, and therefore that you aren't very good in general at whatever you do.

I expect that, at least in some obviously global markets like most e-commerce, GDPR compliance (as opposed to throwing the towel like you) will be treated like a certification of being a relatively non-evil and non-amateur business, with a significant impact outside the EU.

Re: GDPR: Don't Panic

#483

Earlier quoted context omitted.

> This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. This is a good point, but many people seem to forget that most misdemeanor criminal offenses in the US are punishable by fine and/or up to 30+ days in jail. People do not often get the jail time so most don't even think about it, but it is available as an option to the…

Unfortunately in the US, any conviction leads to essentially a work "blacklist," whereby employers do background checks and deny employment for anything they find within 7 years.

Not for non-violent misdemeanors. Unless you're a flagrant offender you will normally be slapped don the wrist and given a stern lecture in the form of a class. Source: was in a fraternity in the US where literally nothing bad happened to anyone I knew with a misdemeanor outside of a fine and class

Re: GDPR: Don't Panic

#484
post #439

Earlier quoted context omitted.

I find it amazing so many companies are willing to advertise the fact that they will abuse their customers in the way you are doing right now.

Where did I advertise misuse of our customers data? Compliance and privacy are not the same thing, just like compliance and security are not the same thing. We have a great privacy policy and we don’t misuse our customers data in any way. For us, it didn’t make sense to invest the amount of money we’d have to to establish compliance with the GDPR, or to invest in maintaining that compliance, and the liability that GD…

What amount of money would you have to invest and for what? Data retention?

Re: GDPR: Don't Panic

#485
post #412

Earlier quoted context omitted.

> It takes time, and real money to be compliant, and getting slow on this quite plausibly can make one a repeat offender. When I read things like this I realize how many companies are not treating user data as they should. Protecting user data should already be built into the company software and process. Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.

Yes. We've had PECR for years. If companies are surprised by GDPR they're probably already violating PECR. But, dispite this widespread non-compliance and fierce fines available to the regulators the sky hasn't fallen. Why do people think GDPR is sudden;y going to make things so much worse?

The OP reacts to news of businesses stopping serving EU, and those businesses are from outside of the Union. So PECR is not so relevant.

>dispite this widespread non-compliance and fierce fines available to the regulators the sky hasn't fallen

Don't you really see how absolutely wrong is this? When law is composed in a way which makes it in practice only selectively applicable, it leads to erosion of justice, and invites for corruption.

Re: GDPR: Don't Panic

#486

Earlier quoted context omitted.

The only thing which would make that outrageous would be an element of force (which would make it not consent anyway, but I digress). Instead, you're giving an example that explicitly allows for a denial. That's exactly as it always should have been, so I really don't understand what the point is that you're trying to make here.

The point is simply that the school is now at risk of huge fines, so in turn it puts pressure on parents to sign as strong as possible waivers. Not many people here seem to understand it but that is what is happening. The force is of purely psychological nature, of course: "surely, you don't want to cause problems to your school?"

What richmarr said. If a contract is in place, then the terms of contract would take precedence over GDPR as "legitimate interest". In other words, zero change before or after GDPR. If the school is trying to get free modelling out of the kids with tick boxes, they risk the consequences, GDPR or otherwise.

Re: GDPR: Don't Panic

#487

Earlier quoted context omitted.

We’ve got a great privacy policy, and don’t abuse our customers data in any way. However compliance would be very expensive for us, largely due to some of our early architecture decisions. The liability is also insane, and we don’t want anything to do with it. When we looked at how little our EU customers were worth to us, it was a very easy decision to simply abandon them.

so you say. if you don’t have strong processes to make sure that is true, it isn’t true. gdpr is mostly about ensuring you have such processes. if you can’t do things such as tell the user what data you have, and delete it, you do not have a great policy. methinks you need some advice from better counsel. i bet that you are closer to compliant than you think.

Do you actually think the only way to respect users privacy is to comply with GDPR? That is an absurd and narrow minded opinion. Do you also actually believe that the entire regulation is reflected in your two line comment?

Listen, you’ve said higher up the thread that you are plan to spread FUD about all companies that don’t comply with GDPR as a marketing strategy for your own product. I don’t see how anybody here could possibly take you seriously. GDPR is going to have a lot of unintended consequences, and people aren’t going to be happy with all of them. One of them is that small to medium sized companies will reconsidering doing business in the EU, another is that the scope of the legislation is especially anti-competitive for small EU based businesses. There’s been a lot of FUD going around HN recently that the only reasons a company would plan to pull out of the EU are hysteria and malevolence. That’s not true, and for many companies this is just a simple business decision.

Re: GDPR: Don't Panic

#488

It's like if a new law were introduced requiring a license in order to ride a bike, to make sure people don't hit pedestrians or bike dangerously in the road. The license is free, it just takes a weekend to go take a written test and demonstrate that you can safely ride a bike. Some people who would pass but can't be bothered to give up a weekend would instead choose to just stop biking. It's an unavoidable consequen…

That‘s all true, but quite boring, isn‘t it?

Because the reverse also hold: if we remove the need for driver‘s licenses for cars, more people will be able to drive.

The fallacy is IMO that many people always consider the status quo ante as the perfect balance. Because we have gotten used to driver‘s licenses.

So the argument that new regulation stifles some non-harmful behaviour is a truism, but doesn‘t really contribute anything, unless it comes with numbers.

Re: GDPR: Don't Panic

#489

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.

Compliance and cost of doing so does not equate to privacy. Remember when all of the auto manufacturers in Europe "complied" with new regulation by spending a fortune on testing?

Re: GDPR: Don't Panic

#490

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

>we can trust EU regulators I want to stress that this is a major point of political polarization in Europe at the moment. Even if this claim is true, it warrants a clear and articulated defense.

Agreed, for some reason people tend to forget that Austria, Italy, and the UK among others have explicitly said the opposite of this
Post reply on HN