Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

511–520 of 833 posts

Re: GDPR: Don't Panic

#511
post #476

Earlier quoted context omitted.

It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…

Did you actually look into the GDPR before jumping to these conclusions about the effects on your business? For example, if you have a legitimate need for user data (e.g. "I need to collect it and store it to comply with other laws") then the GDPR does not apply. This is very plainly laid out for those that care to actually inform themselves.

> Did you actually look into the GDPR before jumping to these conclusions about the effects on your business?

The fact that I have to look into the GDPR already proves my conclusion to be true. I fully expect there to be few if any issues, but I still need to verify against the regulation, which is thousands of lines of text.

I can't just refer to "salvar on hackernews" saying it's "legitimate" if it's for legal compliance.

Re: GDPR: Don't Panic

#512
I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I also agree that the authorities aren't going to be handing out 7 figure fines like candy, both because it's not their historical approach and because they don't have the resources to fight too many of those battles. I want to say I read that the Irish authority's annual budget is around $9M. Theirs is higher than most and Ireland is where most of the US tech giants are established due to tax laws. That said, I think to say that GDPR compliance is simple because it's text is fairly readable or that EU data protection law is simply a matter of transparently respecting people's personal data and not being a bad actor as to privacy is an overstatement. For example, the ePrivacy Directive, most known for prompting all those cookie consent banners, can be incredibly complex to comply with. Each member state has implemented that Directive in different ways. Look at this example https://ico.org.uk/media/action-weve-taken/mpns/2013732/mpn-... where Honda sent out emails to its 350k database simply trying to confirm continued interest in being on their list and got a 13k euro fine for their troubles. I don't know all the facts, but from the document, it doesn't appear that Honda got the fine because they were recalcitrant or being terrible actors. And if the fine is proportionate to the offense (not to the size of the violator), then 13k euro might be levied against a small company for whom it is a significant penalty (not to mention costs, legal fees, etc. in dealing with it).

Re: GDPR: Don't Panic

#513

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

Yes and there's nothing saying I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US. There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income. Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you…

> I won't be arrested and thrown into a cell for the rest of my life if I say something incorrect by mistake when entering the US

For the rest of your life? Source please?

You can be put temporarily into a cell for plenty of stuff but that's temporary. A fine is pretty permanent and when it can be millions, well that's probably the end of your business too.

> There's nothing that says IRS won't prosecute you if someone buys you a soda and you don't declare it as income.

Isn't it simply paying back what you should have + interest? (with some threshold)

Paying taxes is already part of the cost of running a business too (and that's a pretty low cost for a startup, versus having an actual trained DPO).

> Or that you won't be prosecuted by someone in the US if your blog has a copyrighted image and you don't receive a DMCA request that was sent to you.

Which is exactly why you try not to put copyrighted image over your website. Most of the times PII isn't something you can just avoid for a business.

> All fines can be administratively and judicially appealed.

Any appeal represents a cost. A cost that you can't always support until the end.

At the end, it's all about the cost of the risk... that's it. GDPR seems a pretty high cost.

Re: GDPR: Don't Panic

#514
> So if that’s your business model then good riddance to you and your company.

That’s the best way to ensure EU will never have a decent startup scene.

Re: GDPR: Don't Panic

#515

Earlier quoted context omitted.

There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…

I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…

[deleted]

Re: GDPR: Don't Panic

#516

I think much of this probably comes down to cultural and ideological differences between the US and the EU. It certainly seems that almost all of the rabidly pro-GDPR crowd is from the EU. Interesting: I have a number of anti-GDPR comments here and on last night’s GDPR thread that got upvotes last night US-time, heavily downvoted throughout the night, and are now going back up :)

America innovates, the EU regulates. It's been the story for decades now and there will always be a naturaul tension between innovators and regulators

Re: GDPR: Don't Panic

#517
post #404

Earlier quoted context omitted.

It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…

> I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. Have you seen this? It seems to say that GDPR allows you to do what you're doing. https://gdpr-info.eu/art-6-gdpr/ > processing is necessary for compliance with a legal obligation to which the controller is subject;

I fully it expect it to allow it, but you can't just pick one line out of the whole text and be done. For instance, what's the definition of processing? How does it cross-reference with the whole body of other EU regulations? Etc.

Re: GDPR: Don't Panic

#518

I personally am not hysterical about any of this, I just am concerned for the citizens of the EU while living under this law. My main issue with the GDPR is that articles and supporters are constantly thinking in terms of "business" and not in terms of other services, and also not thinking in terms of long term impact. For instance, I run a small community website (~30 people). I receive no income, and I know everyon…

Another thing I fear for the EU is that they will begin to lag behind. If technology forums/other interest group sites are being blocked, how will they stay current?

Re: GDPR: Don't Panic

#519
I'm a citizen of the United States, which is a sovereign nation.

I will never pay the EU "internet transgression fees", no matter how well intentioned they are. Full Stop.

Re: GDPR: Don't Panic

#520

Earlier quoted context omitted.

Not for non-violent misdemeanors. Unless you're a flagrant offender you will normally be slapped don the wrist and given a stern lecture in the form of a class. Source: was in a fraternity in the US where literally nothing bad happened to anyone I knew with a misdemeanor outside of a fine and class

A lot of companies won't hire you if you have a criminal record of any kind. Some won't even hire you if you have any record of arrest, regardless of conviction. Which fraternity?

If the court seals the record its nearly impossible for anyone but government agencies to discover
Post reply on HN