Facebook Use of Sensitive Data for Advertising in Europe [pdf]
arxiv.org
arxiv.org
I have already bookmarked this "nightmare letter" [1], that was posted on HN a few days ago.
[1]: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
Now about the small companies, the ones that can will shut down European operations and continue elsewhere; the ones that can't, in particular European startups and small tech companies, will have to close shop or face severe penalties every year.
In the end, most of the damage will be done to small and medium European tech companies.
Oh, and EU users finally get the privacy they deserve.
By subsidizing them? By exempting them?
Both are terrible ideas.
All this could backfire, but it's better than nothing, at least.
That doesn't solve any issues. The cost isn't knowing how to be compliant, but all the operations required for compliance. Even if they have a business model that is 100% compliant, they still have to account for the large costs of reporting and certifying the compliance.
For example, replying to all those letters that OP mentioned.
Guess you didn't read my first comment, did you? Facebook and Google will be fine, as they are big enough to automate this. Smaller companies, especially local ones, won't.
I don't see the immovable object here.
Of course we do. GCHQ will defend us if someone want to violate our privacy. ;)
Because then they only have to follow UKs laws (once this happens, of course)
We have a product that deal with quite a lot of personal information (top quintile).
Sure, it’s a headache right now but certainly not insurmountable. The law itself is easy to read, sensible and not needlessly long. You definitely don’t need a lawyer to understand it.
Also, I know that a younger/smaller company with a more modern tech-stack will have a munch easier time implementing data minimization, profile erasure tools and proper encryption/security. For many large companies data is spread out over so many products and systems that just mapping it all up is a painful task.
Also, as a consumer I think 95% of the law makes a lot of sense! Citizens deserve it!
Managing the data is easy, managing the compliance and reporting will be the hard and costly part.
Also, 99% of the law already exists in the Netherlands. I did my first request last week actually, after I discovered a company did WiFi tracking on me. I got a reply today, very professionally and complete (and fast, I should add: they had 4 weeks). I was impressed and it gave me a lot more confidence in the company. And it didn't look like it cost them a lot of time, either.
Its reminiscent of the willful ignorance displayed by the Cuyahoga County Recorders Office, in Ohio. The office responded to FOIA requests by demanding $2 per photocopy, even though the documents were already stored on CDs. They hoped they could simply make freedom of information too expensive. Their legal argument was that the files could be semantically thought of as photocopies of the documents.
Here's a verbatim reenactment of a deposition in the case where a county employee puts on a charade of not knowing that a photocopier is.
What GDPR does is that it makes starting your own business less attractive, and funnels people back into the traditional work environment. And by doing that they also reduce the amount of potential customers for smaller startups aiming at small business and these people.
It's much more of a pain for companies that already have a tried and true stack but didn't use the two full years of warning to replace the parts of the backend that isn't compliant. No rest for the wicked.
And if you have a business running, bad news, costs will increase significantly.
The "this will help <evilcorp>" line of arguing seems to be an attempt to play on the hatred privacy advocates have for Surveillance Valley at the moment, and trick them into arguing against their own best interests.
As a user I do feel some privacy regulation is a good thing. There are certainly good things about GDPR (e.g. a lot of third party ad tracking deserves to die). However, I am far from convinced that the GDPR is the saviour some people think it is.
I might be missing something, but won't they actually have to get your consent again, on everything, but this time in details and with option for you to refuse without service degradation?
> (2) kill third party retargeting companies
Good riddance. That would be the second most annoying ad technique today, after ads interrupting your video streaming.
That's my understanding of the point anyway.
You know that you can keep the data that is requiered to do business.
You can also do this to any company about your own information since many years. In school the teachers often did it as homework for the pupils to select some private company and write to them asking for all information they have. This has been tuned down because of the load it put on private companies now though.
Feels good that we have most stuff down already so not much changes.