Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

1–10 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#3
> The GDPR is seen as one of Europe's most complex pieces of legislation by the technology sector

Really? Now I'm no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document (https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...) is only 88 pages long, this cannot realistically be "one of Europe's most complex pieces of legislation". A lot of privacy-conscious SME basically had to do nothing to be compliant, telling me it seems to hit the mark of being not too complicated.

Most of the cases I've heard people complaining about GDPR being "complicated" or "impossible to implement correctly" have been from people/organizations who are breaking GDPR, and have no way of reaching compliance without removing things they ultimately earn money from, which in my mind is the exact purpose of GDPR. Most orgs don't seem to be introspective enough to understand why they are having such a hard time with GDPR though.

I hope that their proposed "simplification package" doesn't actually remove what makes GDPR useful and good, but since they seem to be making a bunch of bad-faith arguments for this simplification, I'm not super optimistic.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#5
The politicians cite competitiveness as the motivator for relaxing the GDPR. The real reason for the EU lagging behind the US in "big tech" is of course the lack of venture capital and the red tape in registering corporations.

The GDPR does not prevent US big tech from operating in the EU.

As it stands, this is just another attack on EU citizens' rights. It is also the least of the EU's current problems. De-industrialization due to high energy prices is, but of course von der Leyen will not mention that.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#7

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> do away with the worthless cookie banners requirement

Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly.

> cut some generous but reasonable slack to small organizations

Some more slack you mean, since they already have a lot of slack compared to larger organizations?

What exactly is so cumbersome for a small business to comply with? They're generally "common sense" requirements, and most organizations who already take care of their data basically had to do nothing to be compliant. What are you doing that is so complicated or essential that it's hard to comply, as a SME?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#8
I think simplifying the law for companies smaller than the 500 person cutt-off makes sense. The Brussels effect is strong. I was just in a company of approximately ~150 people in America and a significant portion of our time went to GDPR/California law takedown requests. User data was everywhere, it was a nightmare. No one thinks of this stuff when everyone is still in sink or swim mode. We got it done though.

Maybe it's an argument for the other side though as well. The architecture of the system was designed to track people as much as possible so we could do A/B, app design, and marketing more effectively. It felt like it was the company's life blood.

I would say the law should at least make people get their architecture right when small so that when they're big it's not impossible to comply later.

One last thought: our company was small in head count but is getting much bigger right now in revenue. I've heard of small head count, billion dollar companies. What of them?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#9
post #3

> The GDPR is seen as one of Europe's most complex pieces of legislation by the technology sector Really? Now I'm no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document ( https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... ) is only 88 pages long, this cannot realistically be "one of Europe's most complex pieces of legislation". A lot of privacy-conscio…

On the spot

> Most of the cases I've heard people complaining about GDPR being "complicated" or "impossible to implement correctly" have been from people/organizations who are breaking GDPR

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#10

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

Cookie banners are not a requirement in the first place. They are a convention set by giant risk-averse consequence-free tech companies, and followed by everyone else.
Post reply on HN