As an analogy, if I recall correctly banks have very stringent laws to follow regarding data export and money export to other countries. The solution they choose is to have a bank per country, not a global bank.
This is exactly what is being done by the large corporations that can afford to do it. European datacenters staffed by Europeans. Americans are not allowed to view any PII for any European (at least with the company I work at).
Russia requires the same thing, although they just want the servers in their country so they can put a SORM-3 alongside it and intercept whatever data they want.
For example, what happens if US courts demand data you have stored on Irish servers,[1] but an EU citizen asks that you destroy this data?
Do you destroy the data and risk being charged with destruction of evidence in the US? Or do you keep it and risk being non-compliant with the GDPR?
[1] https://www.theguardian.com/technology/2014/apr/29/us-court-...
There is nothing stopping you from shooting yourself in the foot either. (Or stabbing I guess in case you don't have access to firearms)
Of course there is. You comply with both laws or suffer the consequences. If you can't comply with both, you choose the cheaper law to break. If that's too expensive, your business sucks.
GDPR is EU wide regulation that trumps national privacy laws. It doesn't even need to be approved by individual members, so when it goes into effect on 25 May 2018, it will be working EU-wide on the same day. Furthermore, it affects companies all over the world that serves EU citizens. There's much skepticism on how EU will enforce this law worldwide, but for now it was quite successful dealing with big companies, remember: Microsoft vs EU (paid €561 million fine), multiple cases of Google vs EU (right to be forgotten, Ireland tax rulling, ongoing case vs Android), Facebook/WhatsApp vs EU (€110 million fine) etc. To answer your question: no, there will be no conflicting laws - if you serve EU citizens, you must follow GDPR. From my personal perspective, GDPR is one of those not-so-often moments that I'm proud of EU.
No gdpr applies if companies target EU citizens [1][2]. My personal opinion of the law is that its as useless as cookie law but way more costly and unpredictable.
[1] (122), Pg 22, https://docs.google.com/viewer?url=http%3A%2F%2Fec.europa.eu...
[2] Pg 13, https://docs.google.com/viewer?url=http%3A%2F%2Fwww.linklate...
The mere accessibility of your website by individuals in the Union or use of the languages of one of the Member States in the Union (if the same as the language of your home state) should not by itself make you subject to the Regulation. However, the following factors are a strong indication that you are offering goods or services to individuals in the Union and so are subject to the Regulation:
> Language - You are using the language of a Member State and that language is not relevant to customers in your home state (e.g. the use of Hungarian by a US website).
> Currency - You are using the currency of a Member State, and that currency is not generally used in your home state (e.g. showing prices in Euros).
> Domain name - Your website has a top level domain name of a Member State (e.g. use of the .de top level domain).
> Delivery to the Union - You will deliver your physical goods to a Member State (e.g. sending products to a postal address in Spain).
> Reference to citizens - You use references to individuals in a Member State to promote your goods and services (e.g. if your website talks about Swedish customers who use your products).
> Customer base - You have a large proportion of customers based in the Union.
> Targeted advertising - You are targeting advertising at individuals in a Member State (e.g. paying for adverts in a newspaper).
How is this useless for end-users? It forces companies to encrypt this data at rest, and allow users to delete it when they want.
EU law does not subsume US law.
Companies did this before the internet and even with internet they did it for China regulations.
I mean, even translation to different languages is basically "special implementation" for different countries...
This is an example of why some local services are winning out against global competitors. Respect for and knowledge of their specific niche.
It seems all good for this specific policy because most of us agree with it globally. But data protectionism and/or extreme regional deviations/regulations in law will reduce the globalism everyone shares. Other options (such as educating the populace or encouraging competition) can be more effective than restrictions.
This is something to think about as the EU grows smaller, not larger. Even today, small companies with fewer EU users may stop and think about providing access at the cost of, e.g., building a portal for them to manage cookie settings.
I guess we'll see what happens with Brexit, but I would argue that the EU is growing in global importance and leadership. With the USA's recent NSA scandals, isolationist rhetoric, and backing out of international environmental agreements, I think we're going to see the EU increasingly set the tone for international trade.
I'm sure there will be plenty of tech firms that choose to serve only US customers (in the same way that there are Chinese-only and Russian-only companies today), but competing "globally" will mean following the EU's lead.
That's a different type of restriction than respecting user privacy because you can't apply the same approach everywhere. A company could easily extend the same rights to all their users. If your offering needs to violate user privacy to exist, maybe it shouldn't.
>Other options (such as educating the populace or encouraging competition) can be more effective than restrictions.
This appears disingenuous.
1. Competition: In your example above respecting user rights nets <0 ROI. There can be no competition here that respects user rights, so how would this help the situation? Conversely, restrictions will encourage competition by protecting less profitable and wealthy ventures from predatory global competition solely focused on maximizing profit.
2. Educating: You're seeking to shift responsibility from experts to laypeople, then blame the laypeople for their lack of education. It's like suggesting we should eliminate building codes then educate people on proper construction. Basically you are advocating for schools and high-rises that collapse.
What the EU is trying to do is make it so countries outside the EU only have to think of the EU as a single country. This is why theres a single market and single currency.
I think this is a good set of data protections and hope there are ways to make compliance incredibly low friction.
So yea, a 20M EUR fine could destroy a startup.
In other words, it's not a replacement: it is an additional set of rules to keep (although most of it would be a superset of various national laws).
I quote from the title of 2017/0003/COD COM (2017) 10:
Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT
AND OF THE COUNCIL concerning the respect for private
life and the protection of personal data in electronic
communications and repealing Directive 2002/58/EC
(Regulation on Privacy and Electronic Communications)
Note the word "repealing".My point still stands - you still need to conform to both GDPR and the state-specific legislation.
But assuming that I am right, then a replacement directive would simply cause the states to update their laws and nothing would really change in terms of complexity compared to the situation before.
If our company had to delete all customer data for a particular customer, then I would need to:
restore 6 months of database backups individually, remove the data, then run then take and store each backup again.
have 3 years worth of tape backups shipped back to us from our data protection company. Restore the databases off of them, delete the data, store them back on tape, and have them shipped back to the long term storage facility.
(To be pedantic, we build technology to serve business goals, which are fulfilled within the larger context of serving human goals. Laws like these are to prevent shortcuts that would serve business goals while at the same time be detrimental to human goals.)