How the GDPR Will Disrupt Google and Facebook
pagefair.com
pagefair.com
It is pretty simple, only 3 levels (strikes for the fellow Americans):
Strike 1 - Stern warning letter
Strike 2 - 2% of your TOTAL GLOBAL REVENUE
Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher)
And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got axed due to a lawsuit of a single student from Vienna against Facebook. So all you need is a single pissed off German customer you ignored when asking for their data report card and you're fucked.
For startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment.
Enjoy :)
I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps.
You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted.
It all boils down to companies simply don't believe the fines will be enforced given just how expensive the fines are.
And since GDPR doesn't go into affect until May 2018, companies are just waiting and seeing what happens.
It's really hard to sell GDPR because it's essentially an insurance policy. Why spend $5m on software and another $5m in services ($10m combined) if your total fine is only $20m. Do you as a company have a 50% chance of getting fined? If not, then roll the dice and not buy a solution.
[1]https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/def...
For a company that has the means to spend $10m on software and services I'd think that 4% of global revenue would be clearly the larger sum.
If you will; it's the difference between the VW approach and those of (as it appears anyhow) all the other carmakers. They're all cheating; most simply were wise enough to avoid doing so explicitly.
Data protection is also harder to enforce than emissions; and just look at how laughably incompetent emissions enforcement is to get an idea of how seriously you're likely to get caught if you happen to collect too much private information.
I expect the same here as in emissions: no real compliance for years (if not decades), and when enforcement comes, it won't be the regulator that actually catches even egregious wrong-doing. I mean; the high-profile players will play lip-service of course, but that's it.
Most of it is done by our internal development team or the core system providers we use. No need for external consultants.
From what I can tell, the whole banking industry is busy implementing this, at least here in Norway.
The fines are real..
What kind of companies do you sell to? Maybe they are actually trying to handle it internally too? What do they say?
It sounds like a goldmine for the EU government. If they install a group of people chasing for noncompliant companies, they will pay for themselves.
No war except economic war. ;)
The European Parliament wanted a higher percentage but that got negotiated down during discussions with the Council of the European Union.
For companies with lower profit margins or companies that are hit by the lower limit of $20M euro, the threat is much greater. Small companies may go immediately bancrupt from a $20M euro fine, while companies with slimmer margins may be taken from black to red results by a 4% fine.
From my pesonal experience, many such companies do not fully grasp to what extent these regulations will affect their business models if actually enforced.
A very real possibility is that Google/Facebook will have these choices:
- Comply with GDPR.
- Shut down business in Europe entirely and eventually be forced to repatriate offshore assets and incur the relevant taxes.
- Continue business in Europe, ignore the GDPR and pay a fine of 4% worldwide revenue.
- Continue business in Europe, ignore the GDPR, don't pay the fine, have all European assets frozen.
That's ignoring the possibility that the EU may be able to reach their US assets as well.
They could shut down all their European operations, but that would cost them a lot more than 4% of revenue.
There's an interesting assumption in there, and I'm not entirely sure it's a correct one. Facebook and its subsidiaries play a large part in many people's everyday lives now, in particular forming the main way a lot of people stay in touch with their friends and family. It is not at all clear to me what would happen if Facebook decided to call the EU's bluff here and literally switched off its service to everyone in the EU for a day or two, replacing it with a single page explaining that until the law was changed they would not be able to provide their service to EU customers.
If that happens, how long do you think it will take a bunch of companies to spin up replacements for Facebook? It's not exactly rocket science to create a social network application; most of the value of Facebook also does not lie in the platforms' code, but in the network effects that it managed to create. Thus, there would be a timeframe in which a huge number of new social networks would try to win over a critical amount of users, with one of them eventually emerging as the dominant one. As soon as that happened, Facebook would have quite a big problem in case they ever wanted to re-enter the European market, as it would suddenly have to compete with a big network with serious network effects keeping their users from re-joining Facebook, even if that was suddenly possible again. They would probably decide to shill out the largest sum of money ever to simply buy up this competitor, because otherwise there would be a certain risk of the new competitor eventually winning the global race for the dominant network (I assume that due to network effects there will always be a clear gravitation towards a single global general-purpose social network, as long as access to this network is not purposely blocked), and no matter how low this risk is, Facebook would most likely try to eliminate it (remember the large sums they paid to buy up possible dangers in the past).
Other commenters already compared the situation with China; I think that is a pretty good comparison, just that the whole development/transition phase would happen much faster, now that it is pretty well known how the final product would have to look like to be accepted by the user.
People stop using it as much.
That seems particularly bad for Facebook, given the network effects it relies on.
I bet customers would rally against the law rather than pay microtransactions.
The advantage of having armies and police forces is that you can lock people up who don't adhere to your rules. Good luck having any employees in Europe if you decide to ignore their regulations!
Ireland and the Netherlands subcompanies are essential part of US Corporate tax evasion. (Double Irish with a Dutch sandwich).
Whenever you sell to an european company, you must be compliant, as otherwise the european company is liable
Ultimately if the fines or compliance costs get too high that's exactly what happens. A company that does no business in the EU is not subject to EU rules. But because it is such a large and wealthy market the threshold is very high. If Kazakstan passed a similar law it'd be a very different story.
The following outages would impact their US customers, who would sue under US jurisdiction.
Art 83 covers the different triggers.
Having said that there are various schools of thought around levels of potential fines, including from different data protection authorities in the EU.
Considering the ICO in the UK is yet to levy a maximum fine despite egregious violations is at least one factor to suggest fines will not increase dramatically.
Also there are not only increased fines to consider but an increased focus on compensation to data subjects in the event of a violation of their rights (together with an evolving case law to support that in the UK at least).
In reality a bunch of small shops are going to go bankrupt because they don't have a "GDPR implementation" position filled and they didn't do some report properly.
Go get the salt.
Unless you're a start-up that handles personal data, in which case it's another bureaucratic overhead that also carries a risk of draconian penalties if you make a mistake, even if you have perfectly sensible reasons for working with that data and you're not doing anything at all surprising or dubious with it.
Of course, the EU has form for this, given its similar approach to both consumer protection and VAT rules in recent years. It does seem to have an unhelpful habit of imposing regulations at big business scale to deal with big business scale problems, but not considering that both of these may be wildly disproportionate for smaller businesses.
GDPR explicitly mentions that "warnings" and "periodic data audits" should be considered measures to take before the fine is applied.
It also says[0] that when deciding on the fine, due regard shall be given to nature, gravity, and duration of the infringement; degree of cooperation, intention or negligence, actions previously taken by the authorities, previous infringements, nature of data etc.
It seems unlikely that anyone in good faith would get screwed by this.
[0] http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
Most small businesses don't have a lot of outside investment, if any. If you're running a bootstrapped business funded with your own savings, the last thing you need is to have to spend significant time and money figuring out where you stand on GDPR compliance and what you have to do with regards to any other organisations that your business in turn depends on. The theoretical fines aren't the most immediate problem for small businesses; the overheads are.
Almost every US supreme court decision come from a single guy challenging something. Are you suggesting that under a certain size, one shouldn't be allowed to sue in court?
It takes a single person whom was wronged. That's it.
I predict, lawyers are going to make a lot of money on this.
For startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment.
I'll start by saying that I have found myself leaning in favor of this law -- I've made a much longer comment about it and won't rehash it, but I wanted to make sure my statements that followed weren't taken as a blanket anti-GDPR but rather a devil's advocate response.I take issue with the quoted statement because it ignores the downside for startups[0]. Companies like Google, Facebook et. al., have the money and time to hire teams of lawyers to find a way to work around these regulations in a manner that maximises their ability to continue tracking while minimising their risk in getting smacked by the hand of the law. Getting hauled off to court won't bankrupt them and they have the legal teams to probably win regularly enough. Even barring that, they have the finances to adjust their business to be fully compliant (in whatever degree business adjustments require) without going bankrupt.
Joe's Advertising Supported Free Service does not. Joe's not going to start his own ad network and start mining personal data for it -- it's way too expensive to try to compete with Google/Facebook (and it was already way too expensive to do it, before). If he does, he's the one who's going to get hit with the second and third strike; probably from that "single pissed off German customer".
Investing in firms that touch this space will be met with far more skepticism. I wouldn't be surprised if any company that simply asks for a user ID and password won't face a little scrutiny from investors, at least until the regulatory atmosphere is understood (I doubt it'll be that extreme for terribly long, but one bad court ruling/fine laid out where it wasn't expected could change that). The cost of establishing many, many kinds of companies will now increase because the risks are high enough that going to market without having your legal bases covered on this one. That money has now been shifted to a business who -- potentially -- is selling snake-oil (and startups are going to be more likely to do business with that snake-oil salesman since they'll probably also be the least expensive).
Then there's the "unintended consequences". Here's a crazy hypothetical, but a lesser variation of it is plausible if this were a US law: Some individual exercises his free-speech rights and chucks something up on the Internet that has a bunch of horrible things on it, say, like 'a guide on how to slaughter and prepare kittens for healthy and inexpensive dinners'. Some kid reads it and kills/eats his neighbor's cat. The guy didn't do anything illegal, really, but his web host knocks him off the web and people are calling for blood. He happens to use an ad-network, but doesn't, himself, collect personal information. However, this ad-network does, and at one point was nailed under this law. He uses the ad-network, so some overzealous prosecutor figures out a way to bring it in front of a judge that he's responsible for what this third-party did and should also be prosecuted. At the height of outrage, a jury isn't hard to find to connect the dots[1].
[0] And hey, that's fine, you're an internet commenting individual just like me -- we don't have to present both sides of the story -- that's the replier's job.
[1] Yeah, I took that a little far, but I think back to when "The Columbine Massacre" happened and everyone believed it was FPS video games that warped those evil children's "precious little minds". It took all of two seconds to call for banning violent video games (constitution be dammed), many idiotic and ultimately overturned laws were passed, and if there was some way to haul the developers who wrote the game off to jail (I think they were blaming DOOM at the time), it would have been possible within those first few weeks.
Since it was already too expensive to roll his own, Joe's site will simply include content from whatever ad network he chooses. All he has to do is make sure that the network is GDPR compliant. If he didn't think to do that, the first warning should give him the necessary time to find a different ad network or to specially handle EU-based customers.
Your "kitten meal" example also wouldn't work, since the first violation doesn't carry a fine, and if the website has been taken down, there is no possibility of a second violation.
So I think the changes won't affect ad-supported businesses themselves all that much, they will simply lead to a restructuring of the supporting infrastructure to become compliant. In the worst case, every website will have a huge "opt in to tracking" modal you have to click, like the cookie policy.
It also gives a REALLY good pathway for any big company to take down a smaller company that is competing on data.
20mil EUR even for zero revenue?!
That's not a startup, that's a hobby.
So there is no setting up an offshored tiny company to wear the liability - your parent company is on the hook, wherever that money may reside.
Why would they impose a 20M limit and not stick to 4% revenue irregardless of it...
edit: I'm not sure that the down voting is about.. it's still a limit, a limit that means a company turning over 0-500M will pay up to a 20M fine.. not so bad the closer you get to 500M but not so great if you're a small company, especially so as the regulation is so open to the "law of unintended consequences" right now and only larger companies will have the funds / man power to navigate it.
I've just started a business myself, and this regulation affects my company too. It makes development costlier; it'll take from the precious little time we have to spend on compliance paperwork rather than work on our core business. In the short run, it does hurt our chances of success.
Yet, none of the trouble is even comparable to what's to be gained here. And it bothers me (though doesn't surprise me) that some people don't see that.
It also bothers me that such vocal opposition barely comes up when the discussion is just about bigger companies such as Google and Facebook. How can we expect "un-evilness" from bigger companies when we're barely willing to do anything in that regard ourselves?
The spirit of the law is nonsensical. It makes all commercial activity illegal, to the extent that all businesses keep records of their sales, inventory, etc. which reflect the activities of their customers, employees, and suppliers.
Google's current ecosystem of data-sharing means that Assistant can make educated context guesses on what I mean when I talk to it based on my browser history and map navigation history. If the new privacy constraints damage that passive interconnection, that's not a net good for me.
I agree, but that's a different topic, really. The comments here aren't about the (un)/importance of privacy. The main debate seems to be either about the technicality of the law and its possible unintended consequences, which are legitimate concerns, or they're about how "this is gonna make my job much harder," which is not really a legitimate concern in this context, and those comments were the ones I was talking about.
> Google's current ecosystem of data-sharing means that Assistant can make educated context guesses on what I mean when I talk to it based on my browser history and map navigation history. If the new privacy constraints damage that passive interconnection, that's not a net good for me.
I think we're overestimating a technical difficulty here, and downplaying a moral principle.
Providing a personalised service without storing large amounts of personal information in a central location is not impossible. It's just technically harder to do.
And even if it was impossible, then still, we need to sort out the moral consequences first. Not by banning technological progress of course, but perhaps by bringing more oversight to corporations. Or by making sure that people of lower socioeconomic background aren't hit harder than the wealthy.
Take the right to be forgotten. First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't like the content, but that is what the EU has ruled should happen.
I get the desire to have a company forget about you, and remove all the personal information they have. It makes sense from a personal standpoint. But how do you do it technically?
If you follow GDPR strictly you would need to be able to purge the data from your backups. Now most backups are considered immutable, so you aren't going to do that, meaning you need a way to ensure that "forgotten" users never get restored.
But how do you even delete the live data? Does the tech company you work for have the ability to delete all traces of a user from their system, cleaning severing all relationships with other objects in your system? Do you have the ability to retrieve everything you know about a specific user, and provide it to them? You will need to write the code to do this.
There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.
Do you sell a SaaS service to businesses, and those businesses send you their customer's data? Then you are the processor and they are the controller. Cool, less for you to do, sort of. Except that controller must agree to every sub-processor you use. Want to switch from AWS to GCP? You can only do it if all your customers agree. Want to use try out a new metrics or logging service? If it will have any PII you can't do it without customer (controller) permission.
You will basically need to hire full-time compliance officers to deal with this. The big tech companies already have compliance officers, but GDPR is so massively invasive to businesses that even small companies now need compliance officers.
No, it is about deleting personal data attached to your user account, not "news articles". This thing intends to make the "delete my account" button to actually, you know, "delete my account", instead of fake-deleting it by setting a "deleted" flag and telling me that everything is gone now while still keeping gigabytes of data associated with me in your database.
> [...] meaning you need a way to ensure that "forgotten" users never get restored.
If this is considered to be a hard problem, then I assume storing some list of deleted users in a separate place and immediately purge those users from the backup after restore must be some kind of rocket science.
> There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.
I wouldn't call it "to become GDPR compliant", I would call it "to build a sound database structure". Because if you are unable to purge all data associated to one of your users' accounts from your system without destroying the integrity of the rest of your data, then you obviously have a half-baked system at your hands that lacks a core feature - to actually delete accounts. And you surely should spend some of your money to refactor this crap into a long-term viable solution while you are still small and agile enough to do that. Because it's only going to be way more expensive later on...
You've gone from: backup.bak to backup-encrypted.bak and backup-keys.bak
This does make your backups slightly less reliable, because it's one more thing that touches them, but if you do a sane implementation and exhaustively test it, the risk is manageable.
I'm also not sure you really need to keep that many backups of this file. Replicate it and make sure you can roll back when your replication is borked, but if you really need to restore your database from months ago, using a newer list of encryption keys shouldn't be a problem.
Does your data not have a lifetime anyways? Do you really need to store everything forever? If you have system that just tracks changes and one that occasionally records full state, after you delete someone from prod you could simply overwrite old full-state backups with your new, post-deletion backup and update your change-only backups to replace data about that user with `deleted`.
In your backup, encrypt each user's data using a per-user key (AES or something). The keys will be tiny, so you can store the keys in a hot database. When a user deletes their account, simply purge the user's key.
Tada - like magic all of that user's data on your tape backups has turned into unreadable noise.
No it is exactly that! The test case was from a man specifically Mario Costeja González wishing for his past financial embarrassments to be erased.
https://en.wikipedia.org/wiki/Google_Spain_v_AEPD_and_Mario_...
Doesn't it just affect companies which rely heavily on lack of privacy for monetisation? I think that's sort of the point - that your business should not rely on tracking individuals and selling that information without their consent to gov/private bodies. It's obviously a huge change, since so many big tech players rely on this to make profits. But the internet will be a much nicer place for everyone else if right to privacy is protected.
This seems incredibly broad from the article and would touch nearly every startup. Maybe there are limits on the businesses affected? Otherwise I'm not sure how one could formally define "rely heavily on lack of privacy for monetisation."
https://unroll.me/ is a good example. They provide a free service to users but make money by leveraging their total access to your inbox to sell ad analyics and competitive intelligence.
It might hurt the bad players but it really depends on how readable the text will be to the average user. If it's going to be a checkbox it will likely not do much.
No, unfortunately not.
HN itself is illegal under EU regulations because you can't delete old comments, and we know that the admins know how many RPS they are getting but I haven't specifically opted in to using records of my HTTP requests for traffic monitoring.
And as far as this stuff being difficult to do, sure, but isn't it worth doing? Why shouldn't a customer have a say which cloud provider hosts their data? Why shouldn't we be able to make sure no data is kept about us after we stop using a service? Like with anything novel in software it only seems hard to do because we haven't done it, but in a ground up design it's not that hard to add gdpr compliance, and a few years down the line this stuff will be business as usual.
You don't need a compliance officer, but you do need a security officer, and their job now also involves data lineage, not just data security. You already should have that person if you're building a SaaS solution.
I was referring to Google vs. Costeja, which I realize isn't GDPR, but an EU court did rule that way.
> You don't need a compliance officer, but you do need a security officer
I strongly believe that compliance and security are two very different things, that are only slightly related. They come at it from a very different perspectives. A security engineer should be doing threat modeling and protecting against threat vectors. A compliance officer may consult a security engineer, but ultimately their job is to check boxes to make sure regulations are followed. I think compliance staff are more appropriately part of a legal team than an engineering team.
That isn't to say compliance officers aren't useful. Having a strong compliance voice can be great. I've seen companies without a compliance officer reduce security because an auditor told them regulations required something. A good compliance officer would have been able to push back against the auditors, pointing out what regulations actually require, and working with the security engineers to come up with a solution that meets regulations and actually improves security.
That is not correct. The right to privacy is not an absolute right. It has to be balanced against other rights, such as the right to free press. In a normal news article case, free press would prevail.
> There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.
I advise a lot of small customers to implement manual procedures to retrieve or delete data in case a request for it might be done. And to set up a basic privacy and security policy which they should have had already. This doesn't cost much.
> Except that controller must agree to every sub-processor you use.
This can be a generic agreement where the processor notifies the processor.
> Want to switch from AWS to GCP? You can only do it if all your customers agree.
Not true, you do however need to be able to tell customers what companies receive their data. Which can be quite a challenge with sub-sub-subcontractors.
Want to use try out a new metrics or logging service? If it will have any PII you can't do it without customer (controller) permission.
Not true if the processing agreement contains a clause that instructs processor to perform metrics or logging. Customer consent is often not needed unless it has big impact on their privacy. Consent is only one of the legal grounds.
> You will basically need to hire full-time compliance officers to deal with this. The big tech companies already have compliance officers, but GDPR is so massively invasive to businesses that even small companies now need compliance officers.
If this were true I'd be a lot busier. It would be wise if companies assign the responsibility for privacy and security, but it doesn't always need to be a full time job with a level background.
Or they could, I don't know, just not collect that data in the first place.
The company I work for has no ads. It does no analytics on personal info. It does nothing you would care about. What it is is a SasS product for businesses. We aren't the controller, so we don't need permission from end users, our customers need to get permission from their customers. But end users can ask our customer (the controller) to delete data, and our customer can ask us (the processor) to delete it.
Fine, we now have an engineer building GDPR features instead of features that benefit our customers. Oh well. But it isn't as clear a win for end users as people make it out to be when they only come at it from an anti-Google and anti-Facebook perspective.
It sounds good in theory, but things like Article 28 certainly make it harder to move quickly.
> The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
I am not finding any shred of sympathy for your story. To me this sounds approximately as evil as saying you are a pipeline company having to comply with all of those pesky environmental and occupational regulations by spending money on worthless safety features for people working and living on or around the pipe, and that none of this benefits your customers: the oil companies.
Yes: you built a bunch of software around a specific set of assumptions about what you were allowed to do, and in the process you took advantage of cost savings by ignoring externalities such as information privacy, and now that this law exists you will be negatively affected. However, the point of this law is to say what you were doing was NOT OK and that future companies should not do this and existing ones had better figure out a way to stop doing this.
In a perfect world, everyone would have built these featurs in to their systems without this law, but they didn't, so now you all are going to get punished. If your business is still possible (and I have no particularly care if it isn't) and any of your competitors had spent the in your mind wasted effort making sure this was possible in the past, then I am not just OK with but extremely delighted that they will now have a competitive advantage over you as you scramble to retool.
You are essentially asking for sympathy here without first taking a step back and showing that any of what you were doing was not just expedient for you, and not just beneficial to you, but that it was also simultaneously what people other than you deserved: the presumption here is that you are the villain, and it is really hard to ask for sympathy from that position, and I can tell you all you are doing from my reading is digging yourself a deeper pit.
It's easy to post bold privacy advocacy from the cheap seats, but I suspect you wouldn't like a world where these new rules really were enforced to the letter. Many of the organisations whose products and services make your life better in some way would most likely cease to exist, and the economy on which your personal quality of life depends would surely take a huge hit.
GP's company isn't doing the tracking and analytics, but it is pulling data from companies that do. Therefore, regulations that affect GP's customers affect GP. This is right and proper, and I don't see what the problem is.
I think most people are okay with that since this at best will be a temporary inconvenience.
How about data breach? Can they also guarantee that the data is stored safely?
GDPR benefits customers. What you say is similar to justifying not to provide good security with the reason to benefit customers or justifying not to provide safety features in cars. After all, it happens not that often.
So you do no analytics on personal info, but if someone wants their personal info deleted, you have to delete some of your data.
How does that make any sense? Doesn't that imply that you are, in fact, using their personal info? Or do you subscribe to a moral theory where e.g. browser history is not "personal info" and this is a gripe about how regulators disagree?
(I don't think it absolves them of any responsibility to implement privacy measures, but it does at least make sense.)
That companies haven't even thought of being able to delete user data makes the law even more important. It should be common business practice to delete data if a user asks, not something technically impossible.
Do you think it's reasonable to have to get individual user approval to move their data from one database vendor to another?
Then you should already be treating your data in this way. If you're not, then I'm glad you're being forced to now.
As for your other point, sure. Customers should absolutely have a say in what happens to their data.
I think a lot of EU people (I'm not one) would disagree with you here. The notions of privacy and of the goals of the criminal-justice system in several parts of Europe are radically different from the notions your "common sense" position is based on, which means that what seems "common sense" to them seems ludicrous to you, and vice-versa.
Overall, this will be yet another additional challenge for EU-based startups in comparison with their US peers and keep armies of lawyers busy.
And if you're complying because you want users in the EU, then you might as well design your system to comply for everybody. And that's a Good Thing as more privacy is better.
This is just another opportunity for easy money if you're in the states and enjoy/don't mind compliance work.
Perhaps, but it's a design problem that approximately 100% of otherwise reasonable backup systems will have, and working around it comprehensively will be extraordinarily expensive.
Do we really want to impose rules that incentivize businesses storing personal data on behalf of their customers not to back that data up properly, in order to avoid any potential liability under the GDPR? Because that's exactly what this law does, as it stands.
Yeah, if you want the data, you need to be able to handle the data in a compliant way. The other solution is to not collect the data. Keep in mind that this is targeted at user tracking. Don't expect me to be sympathetic to the troubles of backing up all of that tracking data.
But since that data will include things like routine server logs, back-ups of customer records necessary for statutory financial record-keeping purposes, and so on, it's never that easy. With such a broadly written law, you could spend a small fortune on legal advice just to find out what your real, practical obligations are to make a good faith attempt to comply.
Keep in mind that this is targeted at user tracking.
The intent might have been to go after user tracking, but unfortunately, that's not what the law they made actually says.
If you follow GDPR strictly you would need to be
able to purge the data from your backups.
Now most backups are considered immutable, so
you aren't going to do that
Encrypt with a user-specific key, and destroy that key to drop all backups concerning that user."Then don't do that"
Sure, but now you actually have an imposition because the ability to do this kind of thing can't be done on any commercially available backup system.
"purge the data from your backups" Again you should already be doing this if you do business with the EU or you are breaking the law.
"Do you have the ability to retrieve everything you know about a specific user" Again this is already in the EU data protection law you should already be able to do this or you have been breaking the law.
Im not a lawyer so take this all with a pinch of salt this is just stuff I need to know as an EU developer. Sure it might be slightly more work for US tech companies but I can't be arsed is not a valid reason to break the law. If you think it will cost to much then don't do it, there are plenty of EU companies that do.
This isn't actually that complicated if their software is designed from scratch with GDPR in mind. Current approach is collect all the data you can with the intention of selling this to data brokers. GDPRs discourages this. It shouldn't be that complicated and that expensive if you store the minimum amount of information you can to cut costs.
> The big tech companies already have compliance officers, but GDPR is so massively invasive to businesses that even small companies now need compliance officers.
This can be done away in a way small business hire contractor lawyers and accountants with an hourly rate. If you are small, you shouldn't do anything which might involve high fees from them.
So here is how to avoid the GDPR penalties.
1. Get compliant - it is pretty much ISO27001 and it will cost you money 2. Don't collect excessive PII data and if you do, store it securely - after all it is a very basic ask 3. Avoid collecting PII data at all cost - think of it as another form of PCI
Frankly, there is no need to panic.
Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's traffic after the first week?
The actual original cookie law, that was decided on EU level, requires users actually to be able to opt out.
But it was a directive, and so countries could interpret it for local implementations.
The GDPR is a regulation, which means its text is directly law, and it also means it can be a lot stricter.
And the law required prior informed consent to cookies with opt-out not generally being considered to be valid consent.
No, they won't. When the EU imposed new consumer protection rules not so long ago, it resulted in having to put some scary-looking legalese directly on your sales funnel pages if you were supplying digital content, even if said legalese was of no practical value to anyone including your customer. That alone was enough to hurt conversions, even if you didn't require something like a token checkbox to be ticked before continuing. The GDPR compliance requirements are potentially on an entirely different scale.
The talk listed all the possible ways the law allows you to store/manipulate user data without requiring explicit consent... There are a shocking number and iirc they apply basically whenever you have a direct consumer relationship with some company.
As I see it the most relevant processing conditions for companies offering a service and storing / processing data without gaining explicit consent are likely to be 6(1)(b) - Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract 6(1)(c) - Processing is necessary for compliance with a legal obligation
My understanding is that these are far from a blank cheque to store / manipulate arbitrary personal information. Specifically, the storage and use of data in question must be provably fundamental to either provision of the relevant service in (b), or meeting legal obligations in (c).
So yes, a company providing you a service will gain the right to store certain customer details demonstrably necessary to provide that service - say hosting your email. It won't however allow arbitrary use of such data to e.g. provide targeted advertising, since such use is not fundamentally required for performance of the service. This would require a specific opt-in (and from what I recall, a failure to opt-in cannot interfere with the provision of said service - not so clear on this however).
In other words I know that clicking on a Facebook dialog box saying "you agree to give us 50% of your income" is meaningless and so I will click on it and use the website.
GDPR prevents the companies from discontinuing service for users whom wish not to be tracked.
This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation.
I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society. This includes allowing businesses to use all the data they can get their hands on. People can produce infinitely more data than any google can realistically process.
I cannot understand why people who are otherwise for transparency and against prohibition are celebrating this as a big win against FB/AMZ/GOOG, as those players can easily shell out another $10M here and there to be compliant with this regulatory monster.
There are all kinds of 'innovations' that don't involve collecting data about me, and the companies creating these kinds of products don't have to care one lick about the GDPR.
Transparency is when powerful entities (companies, governmental bodies, elected officials…) disclose stuff about themselves. Allowing a business as big as Google or Facebook to use all their user's data as they see fit is not transparency, it's mass surveillance.
Leaked info to governments, especially in places in the world where it can mean imprisonment or death is a real issue.
Processing of PII may gave people the willies, but being annoyed by targeted ads seems like #firstworldproblems compared to people who've experienced real attacks via PII leaks.
It also creates opportunity costs for improving human society. How many human diseases could be cured if "processed" PII health data, anonymized statistics or case studies, were used by researchers freely? How much additional burden does it incur if each time this data is transferred to a sub-processor everyone must re-opt-in again?
Would a world of perfect privacy be a utopia, or a nightmare?
Take a look at this link, for example: https://iconewsblog.org.uk/2017/08/25/gdpr-is-an-evolution-i...
If you don't care about ethics then expect an unethical economy.
I think this is the wrong approach, EU should try to make it easier for European businesses to compete with US-based ones.
But in the end we have another layer of bureaucracy on top of all the things a US startup has to worry about, and those mostly non-technical/non-innovative people want to be a part of the picture.
Tracking people around the internet. To follow them everywhere they go and save their personal information, their political ideology, etc. It is not innovation, that's just stepping over personal rights.
> I don't think it is about ethics, it is about control.
Yes. About giving back control of citizen privacy to the citizens themselves. It is not the government that decides who can own your data or when to delete it. It is European citizens that decide individually who should have their data and whom can not.
> EU should try to make it easier for European businesses to compete with US-based ones.
If you give away freedom for economic gain, you don't deserve either one.
What gives you the right to deny others the right to trade their personal information as they see fit?
What gives you the right to force me to trade in my personal information?
What gives you the right to decide that corporations are free to use my personal information for whatever they please?
Well the EU seem to think that not all of this innovation is good innovation and the law specifically targets this.
I don't want US innovation. Thanks for the offer.
No. Can't. I can't do my job without Google and my social life wouldn't survive without Facebook (messenger, groups, events). Using these services is not voluntary at this point.
Like the fucking plague. You should too.
Plenty of us do.
This also affects American companies and the degree it affects you primarily depends on how much of your business model was depending on you doing nefarious things with customer data.
Yeah, yeah, "giving up lots of customers," but if you're a small startup it might be attractive to target a smaller problem space to start with. Also, everyone does this already with, "I am older than 13" boxes since it's broadly illegal to collect childrens' data; you probably wouldn't even have to do any verification as long as you don't wilfully stick your fingers in your ears.
That works for B2C situations but it won't work if you have European companies as customers.
What's the EU going to do? They have no jurisdiction over me.
The big problem for the EU is that consumers actually choose the best product in a free market (the internet of free services), and they overwhelmingly decided to use the US-based options.
All the framing as "nefarious" is propaganda, consumers choose freely the option they value the most. If someone else comes along providing more value than google or facebook everyone would switch in an instant.
> All the framing as "nefarious" is propaganda, consumers choose freely the option they value the most.
Customers cannot choose freely. I'm a customer and I cannot chose certain products because they do not exist. Companies I never engage with are tracking my activities through tracking pixels and other things and because I never establish a business relationship with them, I cannot avoid that. This bill now forces a company I might do business with not do business with companies that do not permit me to get rid of my data.
I think this a good development because it finally makes certain backroom deals visible.
You can easily avoid being tracked by using an adblocker. Other websites only track you because they are business partners of the tracking companies, which provide a lot of value in terms of analytics for the business - free of charge.
> I think this a good development because it finally makes certain backroom deals visible.
As a German, I'd like to have more transparency into the backroom deals that are done in Berlin and Brussels.
But this won't happen unfortunately, and they'll try to regulate IT to death to the benefit of local corporations who failed again and again providing the consumer with as valuable producs as their US counterparts.
Except not really. Plenty if tracking happens regardless based on fingerprinting. And even ignoring ads there are plenty of free services that after a while turn iut to be so shoddy that they lose the data i left on their services and provide no way for me to demand deletion.
I get a mail every other month that my email address and password where found in a data leak.
This regulation is a good first step of forcing companies to think about the consequences of having data.
> As a German, I'd like to have more transparency into the backroom deals that are done in Berlin and Brussels
Same. I want a lot of transparency including from my own government. I'm however going to accept any positive development and won't demand them to be in a certain order :P
There are a lot of people who are trying to shape the EU into a better institution. It's not perfect but it's a pretty good start.
It really isn't.
The EU are global leaders in data protection, and it comes from a belief that the right to a private life is a fundamental human right.
From what's written in the article it seems it impacts anyone who is doing anything with data, which is basically every startup.
Don't collect data you don't need. Don't collect data you don't have explicit consent (or a legitimate need) for. Don't use data collected for one purpose for another purpose.
That'll get you almost all of the way to complying.
If they are the middle man with no dependence on private information, then yes it will cost them to be compliant but it won't break their business model.
Sounds like you missed the part where the fines are based on a percentage of your global revenue.
Taken literally this means it's illegal to provide a service in exchange for tracking. Can someone elaborate on whether this is true and what else it applies to or what else other business models are made outright illegal?
The "forced consent" so many apps and services use is scummy at best and I have no qualms about this tactic being denied at regulatory level.
Inb4 someone comes back with an argument about advertising/tracking being the "only" way some things can survive, then I won't miss them, and if they want options then they should allow for a reasonably priced usage fee, so that we can escape this "ads/tracking or nothing" business model.
See http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...
> In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.
(My italics.) The second sentence seems clear: "consent is presumed not to be freely given" if the service could be provided without the consent. Which means consent cannot be traded in exchange for an unrelated service, like e.g. webmail.
I'm not sure what the relation between the two sentences is. Does the second one ("consent is presumed...") apply only to the cases addressed by the first, i.e. "where there is a clear imbalance"? Or are they independent?
https://www.privacy-regulation.eu/en/7.htm
In answer to your question the two items are independent. The first item gets at the idea that it's not possible to provide consent where the you really have no choice but to consent (i.e due to imbalance of power). One area of particular interest is in the field of employer-employee relations. Bundling up consent with a job offers means it's very difficult for the employer to refuse.
The other item gets at general service provision. You shouldn't make consent a condition of providing a service where that consent isn't necessary to provide the service.
So really the feeling at least consent-wise is that Google cannot attach consent to gather info for advertising with a service provision like search.
However they may instead seek to rely on a separate processing ground under art 6. The main one would be legitimate interests. There is some debate over the applicability if that ground is acceptable though.
/edit Plus the new ePrivacy Regulation brings additional considerations - in particular there's not currently any legitimate interests ground for processing
Consent is presumed not to be freely given IF it does not allow..., OR IF the performance...
Visit turbotax.com to file a tax return, it asks for your bank account before you fill out the tax information. But it's not required, unless you're reporting interest earnings on that account.
On turbotax.com, after you fill out the tax form you have a refund of overpaid taxes. The site asks for your bank account in order to arrange for the refund to be deposited, or instead they can arrange for you to receive a paper check and you don't have to give your bank account.
I don't think any technical-oriented people in this thread would agree that they have "little incentive" to allow Google Search personalization. When I turn off Google Search personalization, I get inferior search results that are less likely to be what I was searching for.
If you don't want your results personalized, there is an option in the search results to turn personalization off.
The problem I have with this law is that Google will need to default to non-personalized results and then prompt users if they want personalization. Google probably doesn't want to increase UI friction, so they will most likely just disable personalization and not prompt to enable. This will result in less-engaged users and inferior search results for the average EU citizen.
I disagree. I turned off Search personalization a long time ago, and haven't looked back.
DDG might sometimes show me some rust proofing results when I'm search for programming related things, but it least it doesn't ignore my refined searches.
> “A purpose that is vague or general, such as for instance ‘Improving users’ experience’, ‘marketing purposes’, or ‘future research’ will – without further detail – usually not meet the criteria of being ‘specific’”
I wonder if there is a browser extension that will auto-opt-out of all 1,000,000 (or whatever) trackers on the internet each time you clear cookies.
I've been using "GDPR hazard" as a useful way to kill bad ideas at work. "Sure you can do that! We just need you to confirm that your business unit accepts responsibility for this user-identifying data and ... oh, we can delete it? I'll do that now then."
We have lots of user-identified data, going back years. I can't see it as a bad thing for us to behave properly with regard to it, and to be required to do so.
What I mean by that is, it's easier to build your db and backups to comply with these laws before you have anything set in stone, than after you have any meaningful amount of personal data. Like, if you organise your backups and db to happily be able to handle removal of requested data before you accrue too much technical debt/inertia then you're going to be ahead of anyone who has to retrofit, which in many ways actually puts you at an advantage.
Also, I for one won't be mourning the loss of the business model that parasitically lives of exploiting user data.
I have worked for 2 big tech companies in Europe. And in both, there is a big effort to make sure that they are compliant with the legislation. I see everyone taking it seriously. Why do you think that it is going to fail?
Even the stupid, really really stupid, cookie warning was implemented everywhere. What does this different? (A part of being actually a good law that protects citizens from indiscriminate tracking).
I take it the actual implementation went a bit more smoothly than the infographic suggests?
That means in order for it to be changed then the European Commission would have to propose a new law, and the European Parliament and Council of the European Union will have to agree to it. The former doesn't really care about whether national governments can get on with their jobs or not.
> "Nor can they deny access to their services to users who refuse to opt-in to tracking.[1]"
> "[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1. See Recital 42’s reference to “without detriment”, Recital 43’s discussion of “freely given” consent, and Article 7(2) prohibition of conditionality. See also the UK Information Commissioner’s Office’s draft guidance on consent, 31 March 2017, p. 21, which clearly prohibits so-called “tracking walls”."
What, in this regulation, prevents the company from denying users (who opt out) access to a service they provide free of charge or a downgraded experience? And how would a court measure the level of service?
However the above analysis really ignores free services where you are essentially paying with your data.
It is an ongoing question as to how to deal with these services in relation to GDPR. To my mind privacy advocates ignore the fact that without giving companies the ability to use data, the services may not be available for free, a potential detriment in itself.
If your service won't work functionally without certain data then consent is not right ground of processing to rely on. There is a specific ground relating to processing necessary to provide a service.
If your service isn't financially viable because you can't use data to obtain revenue to support the underlying service provision then consent may not be a viable ground because of the above reasons.
The debate continues however on how to support free service provision outside of the confines of consent.
Some uses of data might be ancillary to the direct goal of the user but still unexpectedly useful.
Interesting from the article: "purpose that is vague or general, such as for instance ‘Improving users’ experience’, ‘marketing purposes’, or ‘future research’ will – without further detail – usually not meet the criteria of being ‘specific’”.[3]"
I actually work for a platform that is squarely in the GDPR crosshairs (digital marketing). There are a lot of things where our lawyers' perspective is different from what most people say here (I didn't talk directly to lawyers, but I presume product managers did).
- You don't have to comply in 2018, you have to show that you started seriously working on a solution, even if you're not fully prepared. - You don't have to have automated processes for everything (e.g. delete from backups), it's actually perfectly reasonable to say "we'll process your request" and do it manually (ref: startups spending inordinate amounts of effort for GDPR compliance). - Opt-in is not as "game changer" as suggested here, my understanding is that you can do implicit consent (notify the user about what you do, give them a link to take action; crucially, that link might even be the link to your privacy policy which contains the link to the opt-out interface... if I got this right - and I think that I did - this may not amount to much more than a slightly modified "this site uses cookies" thingy). - Delete requests may be handled by "de-identification" (don't delete the data, delete the association with you). - Related to that, while I don't have a definitive answer, I strongly suspect that GDPR only applies to information that can be positively associated with you (e.g. authenticated activity). I'm not obliged to show you anonymous browser activity/information that I've probabilistically associated with you, for the simple reason that I might be wrong and I might disclose sensitive information (think about girlfriend looking up "what does Amazon know about me" and finding up that "she is interested in an engagement ring" because you anonymously browsed from her computer, thus spoiling your surprise even though you were careful to delete your browser history/ browse anonymously. Yes, incognito mode doesn't necessarily help you - we do efforts to identify server-side the incognito sessions and de-link them from the probabilistic marketing profiles, because we don't want to negatively-surprise the customers; but I suspect not all players are that careful).
Overall... despite what many people think, I think big players are actually fairly careful/sensitive about your privacy (well, if we exclude Facebook here :D ). It's the startups that would concern me more... they have very little incentive to guard your data well, because there are so many OTHER reasons why they might fail, that "privacy disaster" is very low on their list of concerns.
For instance, can a Chinese company with ZERO legal presence in the EU completely ignore these requirements? The internet has no real borders, after-all.
If you process the personal data people in the EU then you have to comply:
Article 3
Territorial scope
1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
Same with an American company with no legal presence in the EU. However quite a few things require you to establish one. Likewise if you are engaging in B2B activities your European customers will ask you for it.
Here's the problem as I see it: I know all of the things that are collected, how they're collected, what shady practices are used[1] and I'm completely aware that there is no anonymity left on the internet. The old "when the product is free, you're the product" isn't lost on me. In reading this, though, I was still finding myself a little outraged[2]. I look at it this way: if yesterday, we had an web with plain old "dumb advertising" techniques limited in sophistication in the manner of television advertising in the 90s, and today we ended up with this, there would be rioting (in the USA, anyway[3]). This didn't necessarily happen slowly but it happened gradually and quietly. I remember when Facebook announced that it was adding the ability to track you on other sites that you visited while you were logged out -- that was announced and it was met with criticism (briefly, though I quit the platform about a month later in a quiet, personal, revolt).
Here's the thing - if you ask an average non-technical individual if they understand that they're being tracked on the internet, they'll shrug and say "yes". If you dig a little deeper, you'll discover that they haven't the faintest idea how deeply they're being tracked and that they don't even have an analogy in their own lives to equate that tracking to. I couldn't come up with anything to describe the extent of tracking short of extremely lengthy explanations of what's being done and used[4].
And then there's me - I understand I'm being tracked and have basically chosen the head-in-the-sand approach. I use adblock, and a few extensions that supposedly "limit tracking" (doubtful) but I know they're worthless. Here's the thing, though, what choice do we have? And that's where I concluded how I was able to land in favor of some form of regulation on this behavior[5]. It is becoming increasingly impossible to avoid interacting with companies like Google and Facebook[6]. I look at it this way -- a company that becomes a monopoly in such an important industry can exert as much, if not more, control over the citizenry than their own government[7] but without the limitations imposed by democracy.
What should be done? I'm not sure. Self-regulation isn't working. I have zero faith in government crafting any kind of law related to technology that won't be some combination of horribly ineffective, worse than what we have today, utterly breaks something really important, or is used as a means to insert something horrible (watch them try to pop in a line-item around key-escrow). I'm kind of surprised to find myself thinking that approach that looks the best, out of the options, is probably forced-competition through breaking up the companies involved and I hate that idea in principal and in practice -- it's worked just-about as well in the past.
[0] I don't want this to devolve into a flame-war of whether regulating is "good or not", though I fear I may have just stoked that flame, I'm simply providing background for contextual purposes.
[1] I half- admire the creative uses of WebRTC with STUN on what are otherwise regarded as highly reputable major news sites. It's difficult for me to not see that practice as poking a hole in my firewall and I feel no less outrage when I see that happening than I do when a piece of malware does the same thing.
[2] Part of me had forgotten the idea that when GMail was "scanning e-mails for advertising purposes", they were scanning e-mails that were coming inbound from non-GMail users who couldn't have possibly consented to that. I'm sure there's a really good counter argument, but I'd have a hard time not feeling a little violated by that practice if I weren't a GMail user, already.
[3] Probably elsewhere, but my experience is that some European countries' citizens (particularly the UK, where I have the most experience outside of the US) are more tolerant to this sort of thing whereas when I was a child, you'd have seen people gathering in militias the moment the government tried to propose something like Real ID.
[4] I can only speak anecdotally since I had this conversation with family members who are non-technical and after about two hours, had them quite disgusted -- asking how is that legal ... and these are some of the most government-skeptical conservative people you'd ever meet.
[5] And I have zero faith in the US government being able to craft a law that works. Minimally the "they must still offer the service if the user opts out" will be removed, entirely, turning the "agree to be tracked" button into the moral equivalent of the "Cookie Warning" -- something you click because you have to. And philosophically, if we weren't talking about monopolies or near-monopolies here, I'd agree with that approach.
[6] Yes, DuckDuckGo is my default search engine, everywhere. And I've now trained myself to use the shortcut to get to google for the 60-70% of searches that DDG returns unworkable results. I think it's my search patterns, which tend to be very narrow in results, causing Bing/DDG to "broaden" and ignore terms (or when used with parameters, simply yield nothing). My parents (both retired) use DDG and rarely anything else since I switched all of their browsers around (they didn't even realize I had changed it -- they don't think of Google as a company, they think of search as something "the internet just has ..."). They are perfectly happy with it.
[7] Or can work in concert with it. Requirements to hand over Facebook credentials at the border are becoming common. I'm waiting for the day when I say "yeah, I don't use that" and end up back in a little room with an angry looking man asking me a bunch of (the same; slightly rephrased) questions and responding to them with the assumption that I'm lying (personal experience on that one; not fun). I mean, after all, I'm a programmer/live on the internet/et. al., surely I must use Facebook and I'm trying to hide something! /s
I'm not sure if that would apply to a message I sent to you, but it may, and if that's the case, it's "my property", not yours. I'd be interested to know if any case law exists on this. Considering how often the DMCA is abused, I wouldn't be surprised if someone tried a DMCA takedown claiming copyright ownership on an embarrassing e-mail sent to someone and then subsequently posted online.
It just seems to me in the long run, more and more laws like this will pop up, and using cryptocurrencies will get easier/ more familiar.
Luckily, we will always know of everything that was/is legal now will be illegal in the future, and that people/companies throughout history will always submit to the costs of regulatory compliance of all governments in the world, no matter how burdensome they may be in specific instances.