Live data from Hacker News

GDPR fines were meant to rock the data privacy world

wired.co.uk

1–10 of 99 posts

Re: GDPR fines were meant to rock the data privacy world

#3
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records on an un-restricted FTP server...

Re: GDPR fines were meant to rock the data privacy world

#4
No. They weren't GDPR was meant to get conpanies to take the user security and data ownership seriously and change their ways. Unless you are being egregious, you will get a warning and guidance and hit with fines if you continue being stupid. As is sensible.

Re: GDPR fines were meant to rock the data privacy world

#7
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Just because they're small and weak doesn't mean bad data policies can't cause harm. If you have 100 customers you're the little guy, but if your 100 customers are political activists in authoritarian states, it's kind of a big deal if you leave a .csv file containing their personal info on your http server, isn't it?

In the end whether a penalty is just depends on the significance of the offense and whether the bad actor has reformed. The GDPR does give regulators discretion over whether to issue fines or take legal action, they don't immediately wreck people.

People need to remember that while laws are very rigid in drafting, they typically grant a lot of flexibility to the humans that enforce them... and humans often just opt to ignore them. So you can't just look at the law in terms of what it appears to read as, you have to also look at how it's applied in the real world. That can of course mean that a law like the GDPR has unintended negative impact, but it also means that sometimes the impact is not the negative you'd assume from reading it.

Re: GDPR fines were meant to rock the data privacy world

#8
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

Being honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records o…

I work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.

Re: GDPR fines were meant to rock the data privacy world

#10
post #2

GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action

At the time, everybody who pointed out that this was exactly what was going to happen got flamed hard. I hate that cynicism usually proves the correct stance.
Post reply on HN