Live data from Hacker News

GDPR: Don't Panic

jacquesmattheij.com

701–710 of 833 posts

Re: GDPR: Don't Panic

#701
post #643

Earlier quoted context omitted.

>and you'll have to engage with it on those terms Or you can just disengage with Europe all together, which is an obvious choice for many small to medium sized companies, given the risks and costs involved.

A bunch of companies are going to do this and then regret it when they notice that their competitors really didn't have to do much work to become compliant. Then they'll try to come back... after their EU user-base was kicked out and forced to find alternatives.

That’s assuming that a competitor can make it cost effective.

If the original business couldn’t, its unlikely the competitor could.

I know in my business I’m shutting off EU sales.

Re: GDPR: Don't Panic

#702
post #642

Earlier quoted context omitted.

So because you don’t have many in-scope systems, you believe that the cost of compliance is going to be the same for every company in the world? And what did I say that gave the impression that I don’t respect my users or their data? Our application is a financial one, so I’d say it’s reasonable to assume that it ends up with a lot more in-scope PII than yours does. In spirit, we also comply with almost all of the GD…

> However, that’s not how we manage risk. I think that this point can't be over-emphasized, and I wish you had put that sentence in its own paragraph. Risk (management) was also alluded to elsewhere in the comments in the discussion of "rules-based" versus "principles-based" regulation. Perhaps characterizing certain business reactions as "panic" is grossly unfair, when they're merely sensible (or even somewhat exces…

Great points. It’s all about risk and the cost/benefits of complying.

Re: GDPR: Don't Panic

#703

The GDPR gets so much hate because it hits so many businesses where it hurts: data. GDPR "simply" gives you guidelines on how you can handle data from people within the EU. And that that data cannot be handled so liberally as it has been before. Of course that's annoying from a business perspective, but from an individuals privacy perspective, it's fantastic.

It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…

[deleted]

Re: GDPR: Don't Panic

#704

Earlier quoted context omitted.

We ran the numbers on how much it would cost to establish compliance, and with that alone it was barley worth it based on the current EU customer base we have. We also considered all the additional liability we’d be taking on, and with that alone it was barely worth it based on the current EU customer base we have. We’d also be very happy if one of our competitors started investing in the EU market. It’s worth about…

thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.

There is a difference between complying with GPDR and caring about privacy.

I completely and utterly care about privacy, but things like not tracking IP address and allowing people to request removing them are a bridge to far. I can’t comply with that. I treat my customers important PII (names, addresses, etc) very delicately. But the cost of complying GPDR is too must.

Re: GDPR: Don't Panic

#705

Earlier quoted context omitted.

Or just ignore it, take on EU customers anyway, deal with the risk.

An option that I see a lot of companies taking, we considered it, but decided it wasn’t worth it. I personally know of a few companies that have decided to blatantly ignore it until they see how offshore enforcement works out. If it ends up being favourable, it’s a strategy we may adopt.

I was considering that as well, but I think I’ll take a wait and see policy as well.

Re: GDPR: Don't Panic

#706
post #646

Earlier quoted context omitted.

It is not possible, unless you'll check id and residence certificate of all visitors. Blocking EU IP is not sufficient.

I am having a hard time seeing how EU judgements will be enforceable in the US?

I was really wondering that as well. Can we be held accountable?

It would be nice if the GDPR had a piece about “if a company refuses sales, even if they accidentally happen, the company isn’t liable” and/or “blocking EU IPs or redirecting to a no sale page is sufficient to avoid compliance”.

Re: GDPR: Don't Panic

#707
post #556

Earlier quoted context omitted.

Do you actually think the only way to respect users privacy is to comply with GDPR? That is an absurd and narrow minded opinion. Do you also actually believe that the entire regulation is reflected in your two line comment? Listen, you’ve said higher up the thread that you are plan to spread FUD about all companies that don’t comply with GDPR as a marketing strategy for your own product. I don’t see how anybody here…

> That’s not true, and for many companies this is just a simple business decision. But likely based on incorrect advice. You haven't said why you think your company isn't compliant with GDPR, and it's possible your company is compliant with GDPR, or would require only minor tweaks to privacy policies to make it compliant.

Sounds like he analyzed if very closely, so probably not base on incorrect advice.

And I’m guessing he can’t share too much about why since he has said its based on architectural decisions, which might reveal business secrets.

The biggest reason I don’t like complying with GDPR is the IP address situation- I’m going to continue to track them and I’m not going delete them because somebody requested.

Re: GDPR: Don't Panic

#708
post #692

Earlier quoted context omitted.

Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.

One could read this as you're being dodgy with your user data. If you were reasonable with the data in the first place, then compliance costs nothing.

That doesn’t compute.

There is a difference between what GDPR says is okay with user data and what is actually okay with user data.

We may be reasonable with user data, but either disagree with a portion of GDPR (like IP addresses) or do not have the time or money to very we comply.

Re: GDPR: Don't Panic

#709

Earlier quoted context omitted.

Your comment led me to wonder if any businesses are considering raising prices for EU customers as a result of this law. I'm not so much wondering about the "we lost revenue because we can't sell your data anymore", but more along the lines of "complying with the regulatory environment in this region is expensive, and we pass the cost of compliance along to customers in the region". I recently learned about the AU wa…

Yes, it's being considered.

Do you think companies will/should make explicit the cause of higher/differential pricing? On the one hand, it could anger consumers. On the other hand, it would provide transparency so that consumers would understand where the price increase came from.

Re: GDPR: Don't Panic

#710
post #491

Earlier quoted context omitted.

> you are already responsible for adhering to hundreds of other laws in which the fines could reach millions. Source please? > If you are going to crank the anxiety to 10 every time a situation like this occurs, you probably shouldn't be running a business or handling others' data in the first place. I'm not running one right now. It's not the situation that give me anxiety, it's just that it no longer seems interest…

Canadian here. You are making assumption about decisions you don't know about,- like "Do theses companies had too much anxiety for our regulation? None at all, they were some multi billions companies that did this. It was just not worth it." That is a sweeping generalization and if you dilute and guess what the most probable reason for excluding Quebec was,- it's probably for the best. It was a shady contest to begin…

“Not that hard and costly to comply with”

That’s what you think. But its still a risk, because its different. It’s still easier and cheaper short term and long term just to skip the oddballs.

It’s why you see so many online contests in the US that only apply here. Not because they want to avoid it, but because its easier and cheaper not to comply with other laws.

Post reply on HN