It ain't hysteria if you're in Germany, and a private individual or a nonprofit (e.V.). Due to specialities of German law third parties can serve you legal writs for hundreds or thousands of EURos. Which is why I'm shutting down these 20 domains running HTTP/SMTP services I'm hosting in less than a week, and wait until the smoke clears.
GDPR doesn't apply to personal projects unless those are commercial projects.
GDPR: Don't Panic
641–650 of 833 posts
Re: GDPR: Don't Panic
#642Earlier quoted context omitted.
Right now we are going through a federal audit. We sell only to US orgs, but also have a social media platform. Because our social media platform is open to all, we are addressing adhering to the GDPR. In spirit, we already do, but they want what amounts to 5 documents how we use metrics and user data. (Edit: we use metrics only in a '20 new people signed up'. We treat all data as federal confidential data. We also a…
So because you don’t have many in-scope systems, you believe that the cost of compliance is going to be the same for every company in the world? And what did I say that gave the impression that I don’t respect my users or their data? Our application is a financial one, so I’d say it’s reasonable to assume that it ends up with a lot more in-scope PII than yours does. In spirit, we also comply with almost all of the GD…
I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph.
Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation.
Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat excessive) risk-aversion reactions.
I've come to suspect that the HN readership has a high risk-affinity, not just because of the startup leanings, but also even because of the preponderance of programmers working in internet/web tech, possibly never even being exposed to an environment that's life-critical or money-critical (is there a word for that? fiduciary?). Given that, I also suspect there's also broad, possibly even unconscious assumption that risks like you're describing are no big deal, 80% compliance is more than enough, (always) ask for forgiveness instead of permission, and that sort of thing.
Personally, I don't think there's anything wrong with either risk-affinity or risk-aversion, as long as one is aware of it and it's not an unconscious bias.
Re: GDPR: Don't Panic
#643Earlier quoted context omitted.
I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…
>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.
Then they'll try to come back... after their EU user-base was kicked out and forced to find alternatives.
Re: GDPR: Don't Panic
#644Earlier quoted context omitted.
That's a myth, and the article you posted is an op-ed piece with no substance to back up the claim it makes.
The source is the book of that name, written by an US lawyer. There's some discussion and better sources on Google.
It has no statistics behind it, just made-up stories.
Re: GDPR: Don't Panic
#645Earlier quoted context omitted.
Oh man, the rest of us are so sorry that you are now required to responsibly handle personal information. To quote the author: > Then automate it. If you could automate the collection of the data in the first place then you definitely can automate the rest of the life cycle. There is no technical hurdle companies won’t jump through if it gets them juicy bits of data but as soon as the data needs to be removed we’re s…
I am happy the author is fighting the power. However since most of us live in society we generally would prefer less chaos. The difference between investment to collect data and investment to protect dat is there is no ROI for compliance (in any compliance domain) so the capital is not easily available. Instead of punishing companies for existing in the universe and subject to the laws of thermodynamics, the most eff…
And now GDPR can bundle both together, so that the ROI for collecting data pays for the cost of handling it reasonably, because otherwise you can't collect it.
It levels the playing field and fixes the broken incentive structure around data collection.
Re: GDPR: Don't Panic
#646Earlier quoted context omitted.
>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.
It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.
Re: GDPR: Don't Panic
#647Earlier quoted context omitted.
I'm starting to wonder if there's an active disinformation campaign about this somewhere. Are people getting their fears from Facebook again? Edit: If there is such a thing I bet it's Cambridge Analytica/"SCL group" involved, since they made their money from large scale nonconsensual abuse of political personal data, and have an arm dedicated to swinging elections with misleading Facebook adverts.
I mean part of the issue is that I literally cannot answer the question "are we GDPR compliant?". The amount of time we've spent figuring out whether we need to sanitize apache logs has been ridiculous. If you search for GDPR IP address you'll get 100 different opinions on what you need to do. That in my opinion is what makes this law ridiculous. How can companies be expected to comply with something this unclear? I'…
Re: GDPR: Don't Panic
#648Earlier quoted context omitted.
The only thing I can do as a customer is be mildly amused at the fact that you're complaining it's inconvenient for you to respect my privacy now that a law is coming into effect forcing you to do so. From the other end of the spectrum, I know you're wildly exaggerating the difficulty of compliance.
It's not inconvenient, it's costing me money . I don't want your data, I need to collect it and store it to comply with other laws, now I need to verify that the particular way I collect and store that data isn't violating some other new law. You are not my customer , but even if you were, keep in mind that for every piece of regulation (and there's tons of it!) I need to fulfill, I have to pay, which means you need…
I recently learned about the AU warranty rules, which are very consumer-friendly — and which a commenter pointed out might be the reason that Apple and others charge significantly more when selling products in AU.
Note: I'm not saying anyone should raise prices as a result of GDPR, just wondering if anyone has done so.
Re: GDPR: Don't Panic
#649Earlier quoted context omitted.
There is nothing - and I do mean nothing - written into the GDPR that requires any warnings of any kind, or places any limits on fines, except for $10/$20 million or 4% of revenue, whichever is greater. Period. A multimillion-dollar fine without warning for a first, minor violation is perfectly lawful under GDPR. The idea that "yes it says that but we can trust EU regulators to not assess large fines against foreign…
I think you and everyone making similar points in this thread are getting tripped up by the difference between rules-based regulation and principles-based regulation. This is unsurprising, given that the US is so heavily rules-based, but the EU (certainly the UK) has a long history of principles-based regulation. In rules-based regulation, all the rules are spelled out in advance, and the regulator is basically an au…
The problem with this approach is if you run a large or small company or are a sole proprietorship or simply have a hobby site, you can't write off legitimate fears of heavy handed enforcement. No one wants to be the example.
In the former cases, if your company is how people are feeding and clothing their children, do you want to be the person who says "Oh well we tanked the company this year because weren't worried. Someone on the internet told us they'd be gentle! How could we have known they'd be serious about levying the maximum penalty!?"
If this law is "no big deal" or "so easy to implement" or any other version of the arguments proposed this week, it would not be causing so much concern. It's neither an unreasonable ask or a trivial one. People are being impacted in large ways.
I'm on my company's GDPA compliance team and it is serious business. Our European footprint is small but not insignificant. If we were an unreasonable bunch, we'd just shut the whole thing down and move on. The very expensive very well versed German legal counsel we're paying to help us do this right completely disagrees with what many are saying here. We have no reason to not believe them as they have a lot of experience with the German laws the GDPR is based on. We're paying them far more than the fines we'd see because we believe in doing the right thing. Ergo, we must take the "hard" regulator view rather than your "kid glove" view. Our lawyer's underlying point in every discussion is that this is really really serious business and that they're not fooling around. Adding to that is a GDPR like law is likely to be implemented in Canada and other jurisdictions in the future. We must be ready for that as well.
I think GDPR is great for consumers. I think we'd actually be in a better/easier place if it were a requirement in the US since everyone would have to follow the same rules. The problem is that implementing it takes time and effort to do well at scale. To not loose your competitive edge against other large competitors that do not serve the EU and can operate under only US law. These are real concerns that have nothing to do with the regulators and whatever their whims are.
So even if you're right, these are the real costs. You're going to be held accountable to the people you let down if you put your company in peril. You're going to be held accountable if you loose marketshare because you got this wrong and an unencumbered competitor outmaneuvers you. And most of all, you simply cannot assume the best case, kid glove, approach is what is going to happen. THIS is what people are frustrated with.
I do hope that the EU is fair and equitable (which is my belief) but it would be irresponsible for me to act as if that is the only possibility.
Re: GDPR: Don't Panic
#650Earlier quoted context omitted.
The ROI for compliance is you get to do business with EU citizens and businesses. What EU security directive are you thinking of, regarding IP addresses?
Go look up what CPMs are for the EU. Having your website in the EU will simply not mske you much money, why even bother?