It's time for us to say farewell
wikispaces.com
wikispaces.com
Having this tool, correctly designed, was too expensive and not worth what people were willing to pay for it. We still had the tool because it was hacked together.
I note that the do not mention GDPR anywhere on the homepage. This reads to me like "our business model is no longer viable" or "income is less than expenditure".
* Over the last twelve months we have been carrying out a complete technical review of the infrastructure and software we use to serve Wikispaces users. As part of the review, it has become apparent that the required investment to bring the infrastructure and code in line with modern standards is very substantial.
If I’m not mistaken, it applies to all persons in the EU (not « living there », or « citizen », literally everyone one currently « in » the EU).
So this is totally possible.
Unless you are Facebook or Google or Amazon or Microsoft (etc), most reasonably responsible companies will already be very close to GDPR compliance. The regulations really are not too onerous.
"Don't be evil" might cover it ...
Websites offer services to all countries by default; all websites are subject to GDPR, regardless of where their owners live, unless they do something like GeoIP restrictions to exclude EU citizens.
We live in such a distributed world that these local constraints are just wishes (and consultancy opportunities).
I am from the EU and love my privacy but I am also realistic.
Color me surprised...
Where on Earth are you getting this number from? It sounds entirely fictional to me.
GDPR compliance for small services is a relatively straightforward process.
From the consultants I have spoken with and looking at the issue for my own company. Depending on what your service does, the process of GDPR compliance can be incredibly complex and involve rewriting a significant percentage of your code. Even then, you may not be in the clear because it is up for unique interpretations in the courts of 28 distinct countries. It is, quite simply, a mess. Maybe it's one that will work out to users' benefit in the end, but that doesn't help the companies trying to serve them that don't have millions of dollars to spend on compliance.
There should be hardly any change needed as long as the service only gathers data that is required for it and users are willingly using the service.
The problem if for companies that do heavy identification of users against their will like in adtech or companies that gather and resell personal information.
You do not need to be a lawyer to understand GDPR, you merely need the ability to read, and have a few hours to devote to research. Implementing a policy that is compatible with GDPR is not hard. It does require some thought and some time and will need some training across your organisation. If you do not have a market in the EU then it need not worry you at all. Funnily enough, if you bin (or neuter) those social icons and a few .js thingies from your website you'll be well on the way. Now think about how you would like to be treated, personally ... yep - you'll be fine. No lawyers needed and certainly not seven figure sums for handwaving. You really can use research and common sense and some time, to do the job in house effectively.
I might politely suggest that it is a pretty good standard to work to anyway: it is designed to protect the privacy of individual people. I consider myself an individual and perhaps you do too.
And yet billions are being spent on exactly that - because it's an incredibly complex law that can indeed be subject to different interpretations in each country. I have been briefed on this point specific by lawyers in the EU for to whom we paid a fortune, only to decide that it was too risky to allow EU traffic.
It's not just a matter of taking away "a few .js thingies" as you put it.
The purpose of GDPR is protect individual's right to privacy - I doubt you can fault that. You and I are both individuals ...
Have you actually sat down with a copy of the GDPR a clear mind, and some really good coffee and bothered to read it? If you are arguing the toss with me based on something that someone else has told you then go away.
GDPR is designed to protect people - you and I if you like. I'm a fan of it.
You should take a look at this well reasoned blog post about why someone stopped selling their products in the EU - https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...
There are just far more issues here than you're acknowledging.
But people are arguing with you because you are all over this thread acting like it is the only business choice. Or that we all need to spend millions to make that choice. In truth, it is a risk management decision, not a legal one, because the legal answers are unknowns. You clearly are drawing this into the quadrant of both high likelihood and high consequences... which is fine, for you. But different organizations may have different answers, putting GDPR compliance into a different risk quadrant, and those are their own decisions to make.
If it costs 7 figures to hire consultants, either your business model was parasitic in the first place or your consultants are attempting to fleece you.
(if you don't believe me, email mdk@shadowcat.co.uk and ask - I run the tech team, I'm not nearly as much of an expert on the rules as he is - and if you're emailing him to ask with no intention to pay us anything, that's fine, just make sure to blame me)
there are essentially no situations in which GDPR compliance should be particularly onerous. The principles are pretty simple, and while it will take some time until there is clarity on edge cases, most actions required should be straigtforward.
I’d be fascinated to know what product you build that is so inextricably tied to user data that it will cost “millions” to comply.
Then you obviously haven’t read the whole thing or had to comply with it.
It it possible that you’ve been fleeced by your consultants? You’ve notably avoided talking what you’re doing that would require onerous compliance, details of which would go at least part way towards substantiating our rather unbelievable ideas about the cost of compliance.
The people I’ve met who aren’t fall into three categories:
1. People who don’t know much about the rules and have concocted a distorted version of them
2. People who are running a business that relies on misuse of personal data and who will be directly affected
3. People who have some ideological or politicical viewpoint which generally opposes regulation.
I have encountered no situation where someone has been able to demonstrate to me a convincing case where GDPR compliance is onerous, or indeed more work than any best practices they should have already been following.
> The timing is likely not a coincidence.
Online services shutdown all the time. I appreciate it's human nature to find patterns but this doesn't strike me as one of those occasions it's warranted.
That's possible, however it could also be that they've cleared any money that they could be fined for out of the LLC and are just hoping that rudimentary measures will be enough to get them by without much hassle from EU regulators even if they aren't in full compliance, while giving enough warning to users to be courteous.
More likely is they just have years of tech debt and their operating profit isn't high enough to warrant the reinvestment into the platform. Particularly if their paying membership has been in decline (or even just stagnating). They're in a crowded space and sometimes it's better to bail out while you're still in the black rather than throwing money at a problem that simply is never going to see high returns anyway.
Also for what it's worth the EU isn't some evil organisation that will go after every single business until everyone is bankrupt. There seems to be a fair amount of hysteria in your post about just how negatively GDPR will affect the average online business. So long as you handle your data properly and don't work in the ad / social media industry or other sectors where your business is selling user data, you don't have much to worry about. Frankly I welcome the GDPR.
You must not have much experience with government-types. Laws are always used to the furthest extent that they can be. In this case, the EU has declared itself an Internet dictator, with the authority to reach into the pockets of foreign companies that have no presence in the EU. This will be a boon to government coffers, at least for a few years, and then most foreign sites will close their doors to EU traffic as horror stories flourish. Only a handful of giants that can afford to comply will still allow this traffic, and they will be able to obtain user permission to do anything they want, because of the lack of competitors still serving the EU market (rendering informed consent and all disclosures effectively worthless).
However the EU has also frequently put processes in place to protect businesses - particularly the little ones - from unfair bullying (eg FRAND patents).
Let's be honest, the web / online industry isn't new anymore. They've had a chance to self regulate and instead all they've done is finely honed how to capitalise on their customers data. Even services you pay for are now in the business of tracking their users and selling that data. So someone had to step in and regulate the industry. And if GDPR really affects your forums that significantly (I'd wager not because forums are a dying breed and you're hardly sounds at the forefront of forum tech, from little you have disclosed) then I'd suggest you're likely doing something shady with your user data as well in which case I welcome the EU protecting me against your unethical business model as well. But more likely is the argument that your site isn't that big of a risk and you're just being irrational / listening to so bad advice. Maybe the consultants you've bought in are trying to justify their own jobs by feeding you FUD about GDPR? Either way I'd recommend you switch kool aid brands.
That's just bullshit. GDPR compliance isn't a thing you can get accredited for in the first place and besides that any company that (1) respects their users and their data and (2) has proper security in place is most likely going to already be mostly compliant before they even start.
If you're into adtech and your hobby is to try to find exactly what is and isn't legal then yes, it will cost you but for a normal business that acts in good faith you are looking at much more modest figures than the one you quote.
If the law said this, and only this, that would be fine. But that's not what it says. It's a very complex law subject to unique interpretations in the courts of 28 unique countries.
GDPR compliance isn't a thing you can get accredited for in the first place
Did I say you could get accredited for it? I didn't, but nevertheless, you have to comply with the law (or block EU traffic, if you don't rely on it), and doing so can be very expensive.
Sure you can make it as complex as you want. But the practical upshot is this: as long as you are going around using FUD rather than fact to pretend that the GDPR is unworkable you're setting yourself up for a nasty surprise. Instead go and make a 'best effort' and spend a few productive weeks on getting rid of the most obvious differences between where you are today and where the law says you should be and you will be doing better than most and will be able to sleep just fine because just like with running away from hungry lions you only have to run faster than the competition.
And as long as you're not in fintech, social media, advertising, medtech, insurance or doing something really shady you most likely will be fine anyway because those segments are where the majority of the people that I talk to about this subject expect the first action.
The courts of '28 unique countries' are not each and every one of them going to give a unique interpretation of this law. What you can expect is that starting 2019 or so a couple of serious offenders will be first warned and then fined to show the rest of the world they're not dicking around this time so make-believe arguments won't cut it.
I'm pretty happy that the GDPR exists, the business world had a bowshot in the form of the cookie law, that got ignored or arm-chair legalesed into an ineffective operation when everybody had the option to actually comply with the spirit of the law as well as the letter (the spirit: stop tricking users everywhere: the letter: put up a cookie wall and continue tracking like before once the user inevitably clicks 'ok').
When industries fail to self-regulate sooner or later regulators step in. In this case it is later but as laws come the GDPR is surprisingly clear and accessible.
In our case, the best decision was to block EU traffic and ban EU users from the forums we operate. GDPR compliance for forums specifically is essentially impossible, because almost all forums allow users to embed external images. The owners of the servers on which those images reside could start deploying tracking cookies that the forum doesn't know about at any moment, and therefore there will likely be exactly 0 GDPR compliant forums, except perhaps text-only forums. That issue alone was enough to get us to block EU users, but that doesn't begin to address any of the other fine points of the law.
You also seem to be uner the impression that the law will not be abused by revenue hungry governments to reach into the pockets of foreign corporations. Call me cynical, but if that doesn't happen, it would be the first time in history. The spirit of GDPR is great. The implementation is the exact opposite of great.
So... proxy the images and strip the cookies?
You are not going to get fined by the EU for that happening. The sites issuing the tracking cookies are the ones in breach, not you.
> You also seem to be [under] the impression that the law will not be abused by revenue hungry governments to reach into the pockets of foreign corporations. Call me cynical, but if that doesn't happen, it would be the first time in history. The spirit of GDPR is great. The implementation is the exact opposite of great.
I honestly cannot see that happening in this instance. Most governments bend over backwards to appease big businesses and often at the expense of consumers. What you're suggesting would be a complete U-turn on Western politics.
That's a misinterpretation of the law. We can indeed be held responsible for that - it's no different than putting a pixel on ourselves. The burden is on us to know what we are including on pages under GDPR.
Most of the people in favor of this law, who claim it's not a big deal unless you have bad intentions, haven't neither read it nor spoken to legal experts about it, and are not in charge of having to comply with it themselves. If they were, most would be singing a different tune. I am not arguing that there wasn't a need for some reasonable limits on tracking. But GDPR is an atrocious law designed to allow the governments of EU countries to reach into the pockets of companies in other parts of the world (especially the US). This serves a dual purpose: to make it easier for EU Internet companies to flourish by sucking down the capital of their foreign competitors, and filling government coffers with money they aren't entitled to. That is how this law will be used, regardless of the well-intentioned hopes of those that support it.
IMO, forums that are large enough to be potential GDPR enforcement targets -- which is a vanishingly-small percentage of them -- should be doing their own image rehosting anyway.
Image hotlinking has always been a very perilous thing to allow, from both legal and technical standpoints.
GDPR does not discriminate based on the size of the site. My 7 year old niece could start a site, throw Google Analytics code on there, and be fined millions of dollars for not disclosing it if an EU visitor happens to come by. That is the world we now live in.
This hysteria of yours is nonsensical.
You're pulling out the scariest parts of the GDPR and assuming everyone is going to get bettered with it regardless of:
* whether they've already been warned or not
* their site's size or income
* business size or income
* nor even the severity of the transgression
Thankfully our universe and reality doesn't operate in your worst case fear-mongering. And as I've already stated, you can look back at the history of EU legislation to see evidence to that effect. Posting absurd and unfounded arguments like your previous example really doesn't help the situation one bit.
By the way, there are zero provisions in the law that require warnings before an action is taken to issue fines. You can keep saying that they’ll issue warnings, that doesn’t make it true.
Or to phrase it in our own words: You can keep saying that they'll fine your niece millions for a hobby project but that doesn't make it true.
GDPR is internally consistent and designed from the ground up to protect individuals like you and I from the sort of companies that I at least do run and I have no idea what you do.
There is no extraterritorial reach at all. If you want to deal with Europeans then you should respect their laws. In the same way I would not dream of abusing your rights, according to those laws that your legislature have granted you (within reason).
In a way you might describe GDPR as a form of politeness and I'm sure we are all in favour of that. (No lawyers needed)
You clearly have no idea what you're talking about here.
In the UK, GDPR will replace the current legislation (Data protection Act 1998) https://www.itgovernance.co.uk/data-protection
The same will happen across the entire EU.
It's not a very complex law subject (whatever that is) You do need to do some research and spend some time in consideration but it is not beyond the wit of man.
You have been told this by the 27 remaining governments? Great news! /s
Do I really have to spell it out?
TES are a long standing UK company so Wikispaces will have already been subject to the Data Protection Act if there is any possible GDPR angle. DPA wasn't so different, GDPR just adds, modernises and adjusts.
Since they didn't cite that as a reason, I am going to conclude none. Even if they did cite it, I would still be inclined to assume it was being offered as a palatable pretext for a simpler baser bottom-line-driven business decision.
A little Googling shows that TES Global acquired Wikispaces in 2014:
https://www.businesswire.com/news/home/20140304006078/en/Wik...
TES appears to fancy itself a social network. Wikis are a slightly different animal. And now that TES has Wikispaces users in pocket, I imagine they could care less about maintaining a wiki platform.
And yet they spent money to buy it just a few short years ago. Seems odd doesn't it? I have been on the Wikispaces site within the last year, and there were no obvious attempts to get me to sign up for any other site, so this was not a grab at users. Now they're closing less than a month before GDPR takes effect (after 13 years of operation), citing the high cost of keeping up with modern standards. While they didn't specifically mention GDPR, I'd say the likelihood that it had no impact is roughly 0.
They wouldn't be the first company to pull out of EU over GDPR, nor would they be the last. Here's one example: https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli... . According to that blog post, even Microsoft shutdown a specific service due to GDPR compliance issues.
For a company like Google or Facebook, which collects a broad variety of PII from users all over the Internet and shares extracts of that data with advertisers, compliance is a big deal.
For a company like Wikispaces, which is unlikely to collect much (if any) PII, compliance is relatively straightforward.
Some things possibly adding step changes to the costs can be regulatory (GDPR) and patching (outdated dependencies having no obvious upgrade paths). The latter is a killer, especially if it's a platform going away, eg some LTS OS.
These are real problems that can kill a company. The only resolution is to rewrite or reverse engineer everything, not an option for old software with little revenues.
If they had just said "the business is no longer profitable" I wouldn't have a complaint.