GDPR fines were meant to rock the data privacy world
61–70 of 99 posts
Re: GDPR fines were meant to rock the data privacy world
#62Earlier quoted context omitted.
Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…
I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.
Re: GDPR fines were meant to rock the data privacy world
#63Earlier quoted context omitted.
You're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email…
> can't afford to do it right The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right". If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation…
Re: GDPR fines were meant to rock the data privacy world
#64Earlier quoted context omitted.
Its funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"
> Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food" But that's exactly what we do. The health inspector doesn't come to your home to verify that you wash your cutting board, even on the day you have a dinner party to entertain business clients. Depending on…
Re: GDPR fines were meant to rock the data privacy world
#65GDPR as applied is a joke. At one of the places I work they keep talking about "we can't backup this data anymore because it has personal info".
It's not rocket science!
Re: GDPR fines were meant to rock the data privacy world
#66Earlier quoted context omitted.
I have a Rails 1 product making $10K a year but I don’t have even the ability to log into the box anymore so if even the tiniest thing falls over that revenue is permanently gone for me.
I'm curious about the economics of this - is it big enough to not be worth redeveloping when you consider over the income over say, 3-5 years?
Re: GDPR fines were meant to rock the data privacy world
#67GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action
No, fuck small companies playing fast and loose with other people's data.
The smallest and weakest is not the small company or website operator, but the individual consumer, aka me and you.
Complaining that your small startup cannot collect and sell data nillywilly is like complaining that you can cannot run a startup from your garage that sells homemade miracle cancer vaccines you have vicariously tested, but only on stray cats in your neighborhood.
On top of that, the actual big fines so far for the most part targeted big and/or well-established and/or serial abusers. The small companies only have been "inconvenienced" in so far that they now have to think about what data to collect, about how to collect it and how to get consent, about whom to share it with and about how to store it reasonably secure. Something they should have done in the first place.
Re: GDPR fines were meant to rock the data privacy world
#68A lot of businesses (big and small) were getting too cozy with collected data. With little regard to what was being collected and how long it was stored for. GDPR forced businesses to take a hard look at their data and ask some difficult questions, and I genuinely believe it has changed the way people look at data.
Personally, I was professionally shocked to find how some businesses dealt with data - If anything, GDPR forced common sense down some technologically inept management teams.
Re: GDPR fines were meant to rock the data privacy world
#69Earlier quoted context omitted.
Of course not. There is no law requiring cookie notice popups, there never was.
That's not true. It is law in the EU and companies have been fined: https://www.cookielaw.org/blog/2014/2/5/spanish-cookie-law-f...
Re: GDPR fines were meant to rock the data privacy world
#70Earlier quoted context omitted.
That's not enforcement, that's misreading...
Not really - you need a way to scrub user data on demand from backups and they should also have limited duration.