Unroll.me to close to EU users saying it can’t comply with GDPR
techcrunch.com
techcrunch.com
Do they do anything that a quick grep for "Unsubscribe" can't? I guess the digests are somewhat niche
> [...] is to stop serving users in Europe ahead of a new data protection enforcement regime incoming under GDPR, which applies from May 25.
The EU is pretty complicated. Oh and by the way, the UK will 99.99999% maintain GDPR related statutes on the books, post Brexit. Either that or we are madder than I thought.
Hasn't received royal assent yet?
So no, the GDPR is not in force yet.
> This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
"This Regulation" referring to the General Data Protection Regulation. The date on the journal is 4 May 2016, so GDPR entered into force on 20 May 2016.
Article 99
Entry into force and application
1. This Regulation shall enter into force on the twentieth day following that
of its publication in the Official Journal of the European Union.
2. It shall apply from 25 May 2018.
This Regulation shall be binding in its entirety and directly
applicable in all Member States.
Done at Brussels, 27 April 2016.
I guess you're arguing about a fine point and being downvoted for pedantry, then?https://theintercept.com/2017/04/24/stop-using-unroll-me-rig...
Enhanced data protections are a good reason to (by default) be a European.
Which is to reveal the point of the VPN idea. Instead of having to do a lot of extra research on all companies you deal with to know who can comply with the style of rules that GDPR requires, being VPN'd might force them to reveal themselves to you.
At least, that is my guess on what each of those posts was getting at.
How could a company use it for anything else?
The form on the ICO's website is still exactly as absurd today as it was 6 years ago.
For example, if an EU resident browsing Facebook enjoys a higher level of privacy, it’s not hard to see the value.
It does seem a bit odd that EU legislation is being seen as a talisman of protection by some North Americans to protect themselves from their own Silicon Valley multi billionaire disruptives.
Perhaps charitably minded EU citizens could donate a VPN connection to needy US citizens? We could cover the whole lot (1:1) and still have capacity for a few million more.
LOL, l8ers 8)
It’s a relief in the madness that we consider normal.
I want a chrome plugin that GDPRs the shit out of websites and enforces maximum privacy on any website I visit.
This is an unrealistic expectation. You signed a legal contract when you signed up for an account stating that you're a-okay with them using your data.
The last time I logged in, I found that the following have uploaded information about me to Facebook’s ad targeter:
* my car’s manufacturer
* charities I donated to
* political campaigns (red and blue)
* some of my banks
* random pop music groups I have never heard of (thanks, spotify(?))
* my preferred pizza delivery company
and at least three dozen others.
As far as I can tell, this behavior will soon be illegal in Europe.
Under the GDPR, a business needs my explicit consent to share my data with third parties. They can't bury it in the T&Cs or refuse to do business with me if I decline to tick the "do what you want with my data" box.
That consent is granular and revocable. I can ask any business to delete every piece of information they hold about me, a broad category of data or a specific piece of information. Unless they're obliged by some other legislation to keep that data, then they're obliged to delete it.
The GDPR isn't about protecting individuals from their own stupid choices, it's about protecting them from predatory business practices. We've become resigned to the fact that many businesses operate like a surveillance state, but that doesn't make it right or proper. We shouldn't have to live like the Amish just to keep control of our personal information.
a.) Voluntarily giving information in exchange for a discount (Rewards cards, sales, kickbacks, etc.)
b.) Voluntarily using a service that is known to collect data about you (Facebook, LinkedIn, Twitter, your ISPs DNS, etc.)
c.) Voluntarily sending some kind of descriptor that says "track me with this number" (advertising)
I'm not disputing that there is some data collected about people that they never consented to, but the bulk of the problem is data that is taken voluntarily because people are apathetic.
<Random app> requires access to Contacts ... Meh <press OK> ...
Now your entire phone/email book is out there. Your Mum and Dad's phone number is in the hands of several shysters along with all the other stuff you store in your Contacts. I wonder how many bank PINs encoded as part of fake phone numbers are out there along with other extra data? Its no accident that most Contact lists actively encourage gathering more data eg birthdays and much, much more.
That's just your bloody phone book. >30 years ago I had a little black address book stuffed with lots of people's address and phone numbers (and a lot of happy memories). OK it also had my bank PIN but that was carefully disguised in a way more complicated to reconstruct than needed to memorise the actual digits. You would need to put me in dire danger to obtain that data - I still have the little book and Google does not (fuck 'em). Nowadays you only have to claim that your mapping app can't work without it.
So you are as safe as the most apathetic or technically ignorant of your acquaintances, and FB's shadow profile grows again.
Using EU-lockout as a red flag for the GDPR non-compliant. So if they try to use something and get a "nope, not for EU" their thought would be "must have overlooked how that offer is scam-y, better not use"
and
Getting extra rights from the GDPR compliant.
And then all your digital transactions become fair game for the NSA, so there's that.
If your not allowed to spy domestically, just permit foriegn agencies that are your lap dogs to do it for you, and assist them in doing so!
"UnrollMe does not adequately disclose its true business model to users. Instead, UnrollMe disguises itself as an email-management service to mislead users to sign up for the service so that it (and Slice) can access their data."
Original thread: https://twitter.com/elahd/status/575692415132135425
>"We may share personal information we collect with our parent company, other affiliated companies, and trusted business partners. We also will share personal information with service providers that perform services on our behalf. Our non-affiliated business partners and service providers are not authorized by us to use or disclose the information except as necessary to perform services on our behalf or comply with legal requirements".
If that's going to be the sort of business that the GDPR makes unprofitable and unworkable then I'm very proud to be a European citizen.
>When you sign up for Unroll.Me, Unroll.Me uses your data to provide you email management services, and for other purposes described in Unroll.Me’s Privacy Policy and Terms of Service. Unroll.Me is a part of Slice Technologies, whose market research organization Slice Intelligence provides the world’s leading brands, retailers, and marketers e-commerce insights to help them better understand market and consumer trends. In accordance with Unroll.Me’s Privacy Policy and Terms of Service, Unroll.Me shares information from your commercial and transactional emails with Slice. Slice’s technology automatically extracts purchase information from these emails and uses that information to build anonymized market research products for its clients. Slice’s market research products do not include your personal information.
I think it is safe to say that 99% of the users using unroll.me have no idea how much data they are handing over.
If your business model is incompatible with GDPR then your business model in not compatible with how we want (our data) to be treated.
Companies complaining about GDPR goes into the same category as companies complaining about minimum wage for me.
I ended up using it to clean up my mom's email inbox because she was subscribed to nearly a thousand marketing emails and it was the only service I found that could actually fix that without at least a day's worth of manual effort.
It's more like complaining about any other compliance cost. Consultancies are making probably billions of dollars off of the General Electrics of the world preparing them for gdpr compliance. Then you've got the legal fees. And in the end it feels like you have just burned all that money, because in most cases, regulation doesn't actually accomplish anything. But hopefully it is all worth it for the cases where it actually improves people's lives.
This is the sort of business that GDPR makes unprofitable and unworkable - but unfortunately it's not the only sort. Normal, everyday services - sites that you might use and enjoy - will also have to close to EU traffic simply to avoid the liability.
At my company, we do nothing nefarious with user data. We have a combined total of a few million visitors per month across a handful of sites. After consultation with experts, we had to make the decision to either spend high six/low seven figures to hopefully comply and buy special liability insurance that would help pay any fines (this law is subject to unique interpretations in 28 distinct countries, so nobody can actually know what "full" compliance is), or simply block EU traffic. We chose the latter, and many thousands of other sites that have no intention of doing anything nefarious with your data will as well.
The laws need to be broad enough to apply to everyone and have the intended effect, which means that especially in the early stages with a lack of clarity and guidelines it's goig to be a little messy.
But I look at it like I'd look at a 20th century environmental regulation. Yes, it might impact genuinely good businesses, but at some point you have to do it if you want to advance user interests. I don't really see a better point than now.
So it isn't businesses that GDPR hurts (except for those that rely on EU traffic, who will make up for GDPR costs somehow - at your expense), it's actually the EU itself. Consumer choice is a good thing, and this law will dramatically limit it.
Liability for what? You're not going to get sued. At worst you're going to get fined for negligence, probably after after repeated warnings. I don't think you can find insurance against willful repeated misconduct.
It's only if your service can't possibly comply without losing your bottom line that you have to worry, in which case the GDPR is working as intended.
Find a better business model for EU costumers, or cease your presence there. It's a win-win for EU consumers either way.
Yes, this is the most confusing thing - a lot of posters talk about "being sued because of GDPR" but that's not how it works. And it's always people with the same arguments - small companies, getting sued, crazy money for lawyers, etc.
If I was paranoid, I would think this is some kind of organized campaign to spread FUD and have as many people be against GDPR as possible, perhaps as a way to make sure something similar won't happen in the US.
It's probably just misinformed people.
Probably. There seems to be a real disconnect between US and EU perception of legal and business landscapes here, with the US worrying about the EU legislation more than those based in the EU, who would be far more affected by it (after all, they can't "shut out" Europe).
One of those things is not like the others.
I have no idea where the meme about exploitative lawyers looking for minor non-compliance came from, because the primary means of enforcement under the GDPR is regulatory action. The whole strategy of threatening legal action to prompt a profitable out of court settlement is much less viable under typical EU legal systems than in the US anyway.
However, GDPR definitely can cause significant compliance overheads for small organisations, including those who have done nothing wrong. The official guidance is still terrible, and just the uncertainty around several key points is a problem for reasons we've previously discussed at length on HN.
Trusting in regulators to do the right thing is also a risky strategy. I write this as someone whose business really did receive a crippling demand for monies never owed direct from an EU government tax office after the VAT changes, with very scary accompanying threats and impossibly short timescales to respond, and there were many thousands of other small businesses similarly attacked just in the incidents I'm personally aware of.
From a pragmatic point of view, the regulator in my country is well known to be under-funded and under-staffed, but even that doesn't necessarily help because as with other issues within their remit, it makes smaller organisations easier targets than those with big legal departments to fight back.
$20 million in fines that - despite the protestations of everyone that has ever commented in these threads - can be imposed for a first, single violation, without any warnings. If they meant for there to be any safeguards for companies, that language would have been built into the GDPR. But it wasn't. There are no limits, other than $10/$20 million.
When it comes to getting the max fine at first strike. The GDPR is not the first law in the EU with teeth. There are strict laws about corruption, pollution and antitrust here as well. Do companies get dinged with max penalty from the start violating these laws, not that I've seen. Why should enforcement of the GDPR be different from the current laws?
http://blogs.discovermagazine.com/notrocketscience/2011/04/1...
GDPR has strong language around the purpose of fines and the kinds of considerations that should be made before imposing them. Being overly punitive, especially if a company shows good faith effort to comply, would only welcome judicial oversight. What would the EU gain in such a scenario? And what could the EU lose in such a scenario?
It gains the millions of dollars from the fines, in addition to aiding local EU competitors by bankrupting or hobbling their international foes. It loses nothing.
You can’t see why that’s an incentive and indeed an invitation to abuse GDPR?
First, I have significant trouble believing that the entire European Union would collude to attack international companies in favour of local companies. For a perfect example of this, do some research into the International Procurement Instrument. The IPI is an example of when the EU as a whole has bent over backwards to make sure that non-EU companies have fair access to EU public contracts, even if the playing fields are not level and EU companies don't have equivalent access to the non-EU markets. I assume that you're North American (I am too), so reading about the IPI will seem like comedy hour at Bizarro world, particularly when you see how difficult protectionism is in the EU.
Second, it's worth noting that your scenario as described gets uncomfortably close to a definition of passive corruption. Again, I have significant trouble believing that you could get so many people to agree to do something so potentially explosive.
And third, the EU currently has a very strong tool in its arsenal to enhance data security. The GDPR is very strong because it's ambiguous and people like you are scared of it. The moment that GDPR starts to face legal challenges, that ambiguity will get chipped away.
The GDPR replaces the Data Protection Directive, which left the levels of penalty to the discretion of individual member states. In the UK, the maximum fine for a breach of the Data Protection Act (the British implementation of the DPD) is £500,000. You can see a full list of enforcement action taken by the Information Commissioner's Office at the link below. I defy you to find a single example of a monetary penalty that was disproportionate.
I don't think that's necessarily true. If a company does not provide the service in the EU but there is demand for it, someone else will fill the spot.
Laws are not mailing lists.
No, and for a good reason. Just like if you could opt out of employee protection laws, the "opt out" would soon become mandatory to get a job.
> You can choose to work more than 48 hours a week on average if you’re over 18. This is called ‘opting out’.
> Your employer can ask you to opt out, but you can’t be sacked or treated unfairly for refusing to do so.
https://www.gov.uk/maximum-weekly-working-hours/weekly-maxim...
IMO, the best solution is per-row encryption with the keys stored in a second database. This second database can still be backed up, with backups that have a maximum lifespan, eg: 30 days. When a user deletes their account, their decryption key is deleted, and is unrecoverable after the backup max life.
How long do you keep your backups? If you just store them for, say, 30 days, that's fine. The EU regulators aren't going to come after you for a 30-day lag for all traces of data to be deleted, as long as that process is documented.
There's still one annoyance left: you do need to keep track of accounts/users who have deleted data, so if you have to restore from a backup, you can't restore any data belonging to users who have deleted their data within that window.
Otherwise, this is frankly not such a big deal. If you're storing backups for longer than 30 days, why? Where I work, if we had to restore from a 30-day-old backup, it'd be catastrophic for the business given how much data would be lost.
That seems like a big annoyance. The only way around it is a 2nd database that removes certain data in case a backup is ever restored. Ironically, keeping data on the data you need to delete.
Let's be real here for a second, what's your definition of dramatic? I don't foresee the EU losing access to more than a handful of services, many of which as in the case above provide questionable products.
I'm very much doubting that we'll be talking here in a year and the EU somehow finds itself behind the great-GDPRwall. That's just arbitrary panic.
>Consumer choice is a good thing, and this law will dramatically limit it.
You're neglecting the fact that consumers can make collective choices about the things they do not want to put up with. Abuse of private data is one such domain. There is no iron law of the business world that consumers need to accept every product of any kind on every market. That's up for societies to decide. The law seems to be quite popular from what I can see, so any cost that we European consumers do actually incur, we are apparently happy to endure.
As horror stories come out and geoblocking tools become easy to use, I'd say that over the next few years, the vast majority of non-EU sites will have blocked EU traffic. Nobody wants the liability unless they make a large percentage of their revenue from EU countries. Accepting such traffic means exposing your business to instant financial annihilation at the whim of a foreign government.
Here is a fact. If your business complied with EU data protection laws, GDPR is only an incremental step. And, here is another fact. The EU is nowhere near as litigious as the United States. GDPR may levy some intense fines at repeat offenders, particularly those who haven't been in compliance with any data security/protection law from the last twenty years. But to claim "financial annihilation at the whim of a foreign government"?? That's just poor taste.
Examples: France suing Apple over developer fees. France blocking the sale of DailyMotion to Yahoo. The war against Uber with the simultaneous promotion of BlaBlaCar, the attacks against Apple for taxes on income that wasn’t even earned in France, the collective freak-out over AirBnB while subsidizing Gites de France.
My point is that exposing yourself to the risk of a European money-grab is too high. Besides, who benefits from collected fines? Governments. Those fines don’t get paid to the aggrieved party, they get paid to the government. Governments have an incentive to levy fines on foreign companies, with very little downside — European jobs aren’t at risk.
The attack surface is just too great to be using “hope” as a strategy.
http://www.privacy-regulation.eu/en/article-83-general-condi...
http://www.privacy-regulation.eu/en/article-58-powers-GDPR.h...
Section 58 is about EU powers under the GDPR. Section 83 gets into the spirit and purpose of fines levied.
Being overly punitive would only invite judicial oversight.
Then let's say "financial annihilation at the discretion of a foreign government"? I don't see how you can deny that the GDPR gives them that discretion, unconstrained by statute (though constrained by a judge's fuzzy standards of reasonableness).
You're saying that they will use that discretion reasonably. You're probably right; but why do they need it in the first place? Like, why is 20M EUR the right number here? Why not 10M or 40M?
Or are you sufficiently confident in your regulators' discretion that you don't think the numbers matter? That's great, but it's not the rule of law.
I think two classes of business will block the EU: those with business models fundamentally incompatible with the GDPR (like unroll.me, I suspect), and those with compatible models that consider their EU business too small to justify the risk. I feel no sadness for the former, but the latter seems to me like real damage. It could easily have been avoided with proportionate fines. Why do you think they didn't do that?
However, I still don't agree that foreign governments can operate unconstrained by statute. Again, I'll point you to article 83 of the GDPR. It starts off with some vague statement about how supervising authorities need to make sure that fines are effective, proportionate and dissuasive. That's bullshit, but if you read further, they add quite a bit more substance to the argument.
I've just been linking to article 83, but it's likely worth quoting once in this thread. Part of it reads:
---
When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
(a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
(b) the intentional or negligent character of the infringement;
(c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
(j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
(source - http://www.privacy-regulation.eu/en/article-83-general-condi...)
---
Also, consider that GDPR isn't a huge change over existing EU privacy legislation. The scariest change in GDPR is that it gives the European Union tools to force non-European companies to comply. While that is scary, if a non-European company has been showing a good faith effort to comply with existing EU privacy protections, they shouldn't have much to fear unless something fucked up happens.
To summarize my position, if a company is already complying with EU privacy law, they don't have much to fear. If a company is not complying with EU privacy law, they have a problem, but seeing as how the first draft of GDPR came out almost six years ago I don't feel particularly bad for them. And finally, if a company was found not to be in compliance, it would be hard to justify the maximum fines if they were showing a good faith effort to become compliant.
The wildcard here would be what would happen if a popular company suffered a massive data breach. Consider for example, the time that LinkedIn accidentally lost a whole bunch of unhashed passwords. On one hand, that's a massive breach, LinkedIn did a very poor job as data stewards and it's a perfect opportunity for a maximum fine. On the other hand, what would be the political ramifications? And where would liability flow?
Also: Doesn't the extraterritoriality bother you? There are roughly 200 countries in the world. Do you really want to argue that each of them can impose a burden on a website operated outside its borders, just because its people might happen to visit it? That seems like an incredibly dangerous precedent to me. Can the UK enforce a super-injunction against all websites available to its nationals? What's the difference between the GDPR and that super-injunction? It can't just be that "one is good and the other bad"--what law determines that?
As I understand it the penalty is assessed and levied by the regulator. Just like DPA penalties where the number of people receiving any fine at all has been minuscule. The proportionality of instances where fines have been given seems good. I think most EU citizens would feel too few, and too low fines have been the norm.
> That level of unpredictability doesn't seem like law to me
That is how most UK and EU law has worked for, well, forever. Most offences have a maximum penalty yet it is the US that regularly makes headlines for extreme penalties or length of incarceration.
Plenty of people get small fines in the hundreds, or just a caution, or their business gets a letter for offences that have fines running far into the thousands.
Talking of extraterritoriality, doesn't that also apply, along with the burden to 200 nations you criticise, to the US DMCA for sites with user content?
My question isn't whether the fines are frequent or high enough. It's whether they're predictable enough--whether the law is described in enough detail that two people interpreting it independently would reach something close to the same number given the same facts. I don't think it is. (Do you?) The usual answer is "but don't worry, the people interpreting it make good decisions". I think that's probably true; but when the maximum penalty is indeed financial annihilation, that doesn't seem too comforting.
The USA has indeed pushed the extraterritorial limits. I think that's bad, and I don't see how it makes the EU's reach any better. And to emphasize, my concern isn't the burden to ~200 nations--it's the burden from ~200 nations. Should the UK be able to enforce that super-injunction? If not, why not? Iran, a prohibition on the Satanic Diaries?
I'm used to the law going easy for a first offence, or an accidental breach. Occasionally we have separated offences (murder and manslaughter for example), but most of the time there's just a maximum that is reserved for the most wilful, or repeat or extreme cases. No one has ever been bankrupted by our unlimited fine for cannabis possession (most get a caution or trivial fine).
Apart from anything else means are assessed before any fine is levied. If you're on minimum wage a £100 fine is going to hurt rather more than to a millionaire. So means are assessed first to try and remain proportionate.
So how is it done in the US? I only have what I've gleaned from the media. Does the judge or regulator enforcing really have no discretion of penalty or always seek the maximum? I find it very difficult to believe that the entire range of penalties and when they apply are spelt out in every law and judges or regulators have no discretion or common sense. Movie "experience" seems to indicate a lot more horse trading goes on.
Do our legal systems diverge so much that US citizens completely distrust theirs to do anything but bankrupt them for minutiae whilst we remain certain they can and will be proportionate?
> ...extraterritorial limits. I think that's bad, and I don't see how it makes the EU's reach any better
I'm somewhat uncomfortable with some of the global precedents myself. On the other hand I'm not sure how it is avoided in a world that is so globalised and so many internet services have essentially ignored EU privacy and data protection. So what's the alternative?
We're not enthusiastic to adopt the US model of privacy and many internet services aren't even paying lip service to our (too) limited protections. How else to fix it? EU wide Facebook blocks seem like a fine way to start a trade war!
I think...maybe? It's a continuum, and a legal system with zero judicial discretion would either require impossibly detailed law or yield obviously unjust results. I don't think the model in the USA is strictly adversarial--like, it's not entirely that the regulators are supposed to punish you to the maximum extent of the law as written, and if that's unjust then blame the legislators. It's closer, though. This has advantages (less opportunity for selective enforcement) and disadvantages (increased complexity of law, greater opportunity for loopholes).
> I'm somewhat uncomfortable with some of the global precedents myself. On the other hand I'm not sure how it is avoided in a world that is so globalised and so many internet services have essentially ignored EU privacy and data protection. So what's the alternative?
Any large player has operations within the EU, making the extraterritorial reach unnecessary. For smaller players, I see lots of unexplored opportunity to regulate indirectly through ad networks, payment processors, etc.
The precise mechanism isn't defined in the GDPR, but I suspect it'll operate similar to judicial review - a court can determine that a reasonable decision was made by the authority, and thus allow the fine as is, or they can determine the authority acted unreasonably or did not take into account the proper factors, and thus quash the decision and order it to be remade. I'd be somewhat surprised if the courts were directly setting fines.
Aside: What's with all the downvotes? Your comment seems fine to me, as do many others in this thread. It seems like any discussion of the mechanics of enforcement gets a nasty response here, as if the only people who should care about that are criminals. The GDPR might be the perfect legislation with which to erode civil liberties, since the people who would normally jump on such arguments will be on your side... Or is there another reason?
> I think most Americans (including me) would still put Article 83 in the "fuzzy standards of reasonableness" category
Is it valid to say that you're not wrong, but I disagree? :)
I agree that article 83 will be hard to interpret if people act in bad faith. But, it provides a good framework for how to act in good faith.
I would argue that if you genuinely care about your users and their data, you'll likely be okay unless something fucked up happens. And when something fucked up happens, as long as you're transparent, respectful and helpful, you'll still likely be okay unless something really fucked up happens. And then, you'll have bigger things to worry about anyways, so fuck the GDPR. :)
> I agree that it probably works in practice, but I wouldn't see it as much of a constraint. Like, how closely would you expect the rulings of two independent judges each assessing a fine according to these guidelines to match?
I completely agree with you. Unfortunately, vast parts of the American/Canadian justice systems would also fail this test.
> Also: Doesn't the extraterritoriality bother you?
It sure does. The extraterritoriality is first class bullshit. But, if current European data protection laws are any guide, it will mostly be used as a tool to gently encourage compliance and actual punishments will be very rare.
1. We complain about those too.
2. The dangers of extraterritoriality and vagueness seem synergistic. A major check on regulators' discretion is political will, and screwing foreigners tends to be a lot more popular than screwing your own citizens. The ideal tax is one on foreigners living abroad...
I think the GDPR will probably be fine, and have net positive effects even as it pushes small, essentially-compliant but risk-averse operators out of the EU. I find its legal basis troubling.
One time, I was afraid of some anti-corruption laws because it seemed like basic parts of doing business here would result in severe penalties there. My roommate at the time thought I was being certifiably insane, because the EU just doesn't work like that. He couldn't imagine what transgression I could possibly commit to warrant more than a strongly worded letter (on better stationery than I'd get from the Canadian government).
From there, I started learning more about how open the EU is.
I mentioned this in another comment, but I'll also encourage you to read about the International Procurement Instrument. The EU (like many other economic bodies) has trouble with non-EU companies bidding on EU public contracts and winning because the playing fields just aren't level. I don't want to give too much of the story away, but as you read about the IPI meandering its way through European politics, you can see an EU bending over backwards to make sure that foreign companies have open access to EU markets.
If you read about the IPI with North American eyes, it seems absolutely bizarre. But it's a good primer to the EU's difficulty with protectionism. I'm from western Canada and seriouslu, if the Canadian government felt this way about protectionism, I could get a western independent movement off the ground in a matter of months...not that I would or would even want to, but it would be so egregiously opposite how we do things that radicalism would ensue.
Sorry for droning on and on, but I don't think I can really debate you. I agree with you and everything you're saying is logical. My only response is that Europe is so incredibly different and that response is honestly starting to wear thin.
Besides, I'm being a shitty entrepreneur. The more people are afraid of GDPR, the more opportunity I'll get!! :)
(I've enjoyed this talk with you. Thanks for engaging with me!)
My understanding is that "consumer choice" is a code for radical deregulation of the markets until all the "choices" that the consumer is left with are each as bad as the other. "Sure, you can go to our competitor, but they hoover up your data just like we do".
Bollocks.
I run a small (IT) business in the UK. I will have just as much internet as you post 25 May. The difference may be that my company and others in the EU might automatically be perceived as more trustworthy than those that do not comply with GDPR and hence we may benefit.
GDPR is not a money making exercise.
My company has a wiki page called "Risks and Opportunities". GDPR is definitively under Opp. these days - for us and our customers. I also quite like it as a person - a private individual.
The most interesting thing to me about this whole ordeal is which companies only comply in Europe, where they're legally required, and those who have gone ahead and made sure they are compliant globally: It defines the difference between people ensuring your privacy rights because they have to, where they have to, and those ensuring your privacy rights globally because it's the right thing to do.
Google's AMP project just introduced a whole set of new features not just to mark whether or not an EU user has consented to tracking, but also a new feature to geolocate users, specifically for the purpose of determining if they're legally required to get that consent. Which is sad to me; they should be getting user consent everywhere.
Let's first be totally clear: GAFA isn't suspending their EU operations, nor is any other company that 1) has already an established EU base and 2) can afford the cost of compliance. What I think will happen is that new players will stay out of the EU, because of the perceived risk (accurate or not) and the cost of compliance. So I do agree with the parent that the GDPR will eventually lead to a slow pauperization of the internet in the EU, the only difference with China being that it is self-inflicted rather than self-imposed.
Note that there are very few regulations out there (EU or US) that have actually helped the internet. Most of the regulation that was drafted in good faith turned out to bring more harm than good to the internet, the recent FOSTA bill being a prime example. At this time, I have no indication to believe that the GDPR will succeed where most other bills have failed. But if it turns out otherwise, I'll be the first to admit that I was wrong.
This is a gross exaggeration. I agree that truly small companies may have issues, but companies way smaller than FB and Google can and are spending the time to comply.
You don't know that. Show me where, written in the GDPR, it says that warnings must be issued or that there are any circumstances under which the maximum fine must not be imposed.
I'll save you some time. It's not there.
> When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to [...] the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement.
Look, their goal here is compliance. They don't want to fine a company into oblivion, because that just encourages companies to be fearful and do what you're doing: cut ties with the EU entirely. And that's not a win for them either.
I get that it's hard to trust governments, but remember that they're still made up of people. If you deal with the regulators in a straightforward way, and cooperate to the best of your ability, they're not going to stick it to you. No, I don't know that for every single instance. But I also don't know a lot of other things that can add risk to a business, but that doesn't stop me from doing business in general.
But sure, if you've done the math, and the cost of compliance isn't worth the EU revenue you'd otherwise get to keep, that's your call. I'm just getting a little tired of all the FUD getting spread around GDPR.
Sure there is. Their government will be the direct beneficiary of the money. Why would they care if they bankrupt a foreign company? In fact, they may use it for this explicit purpose. They win by collecting the money, and they win by decimating foreign competitors of local businesses.
When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
the intentional or negligent character of the infringement;
any action taken by the controller or processor to mitigate the damage suffered by data subjects;
the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
any relevant previous infringements by the controller or processor;
the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
the categories of personal data affected by the infringement;
the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement; where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
You should DEFINITELY look for a better lawyer. Pro tip: one not looking to sell mitigation services.
Well that caveat was not actually written in the law, and enforcement changed later. Now you can be pulled over and fined for nothing other than not wearing a seat belt.
So whatever "they say" about enforcement is meaningless. You can only consider what is actually written in the law.
Thank god for that.
Change your experts. If you really aren't doing anything nefarious with the data as you say, the adjustments are relatively easy to understand, and very often also to implement. In fact, many subregulations of the GDPR were already implemented in many companies in Europe, so what's happening it's shocking much more to American companies, not so much the European ones.
You will not be fined 20 million for that. This argument is beyond absurd.
I don't know what is more absurd: people repeating this on HN or those who actually started to believe this FUD.
It's not FUD when that's what the law says in black and white.
Edit: typo (proportional->proportionate)
By whose definition? Germany might disagree with you.
You could totally eliminate the risk of meteorite impact on your business by relocating down a mineshaft...
I like the GDPR. It's a lot easier than ISO9001/27001 and actually nearly falls out if you have those.
How many times have we whined and opined about a lack of responsibility displayed towards our personal data? Now a major bloc in the world is trying to get to grips with that issue with some pretty decent legislation (IMNSHO.) Do you have any idea how difficult it is to get something like this ratified by the EU? Do you have any idea how diverse the EU actually is? Getting this thing out is a massive feat.
In the EU, we all have to comply with GDPR by default - all of us from cobblers to rocket scientists. I'm sure you'll manage.
We (UKoGBnNI) are still in the EU for now - next year we sort of leave (ish!!)
I've always whinged about those self serving bureaucrats in Bruxelles. Some of them are our own home brewed UKIP lot. It says a lot about democracy that UKIP or the SDP (int al) can even exist.
We'll see what happens to the little old UK post Brexit - it will be written up as both a triumph and a disaster and yet I suspect life will tick on, much as before.
GDPR on the other hand: that is important and worth paying attention to.
Bear in mind the UK use Sterling and the RoI use Euros. A NI person could work in RoI and be paid in EUR but pay rent etc in GBP. Obviously the reverse is true a RoI citizen might work in NI and be paid in GBP but needs EUR to live on. All a bit of a pain and of course the bank's exchange rate doesn't help.
It is easy to poke fun at those at the edges but I think on balance a bit of sensitivity might be warranted here. Little Britain might think that they (we) have some problems to deal with wrt Brexit.
I would suggest that we might look at NI and RoI and at least try to understand that the really important issues are right there - those issues and our responses to them are the ones that really define what sort of people we are now and will be in the future.
The rest is accounting.
I have, and it's things you should have been doing anyway. I'm curious what your business is that complying is too onerous.
There are some parts that are inexact, like how must a company protect data and exactly what data is considered PII. Thing is, if you treat any data that could identify a person as PII and
a) Protect it as such
b) Keep a living document on your site listing the data you capture and why
c) Get and store consent
d) Allow a user to 'be forgotten' and/or export their data
e) If you change the data you capture or what you do with it, you must get consent again
If you follow those steps you have complied with the spirit of the law [1]. Too many companies today capture more data than they need to provide the service the user signed up for, and then sell that data later when the service can't support itself.
The high end of the fines are high, but that is the only way to get companies like FB and Google to fully comply. Hopefully spammers who I never gave consent to email me will also get put out of business, but they are like cockroaches and impossible to kill.
[1] There are other points like you can't force consent, i.e. download this white paper only after you consent to accept marketing emails.
The spirit of the law is not the letter of the law. And as we all know, a single violation of the letter of the law can result in fines of up to $20 million.
While doing business in Europe I sometimes got some things wrong, for example with taxes. I wasn't really punished even once - I just had to pay what was missing and correct the documents, even if the maximum punishment for what I did (or failed to do) was some years in jail.
The only new thing seems to be higher fines and aligning laws in all EU countries, rather than having different implementations of roughly the same thing. But if you don't comply with GDPR, odds are that you should never have been able to do business with a lot of European countries. To the best of my knowledge, you should have geoblocked the Netherlands long ago (the only country I know the laws well enough of, to say that there is truly only a small difference between the 2002 WBP and the new GDPR) if you have to close to the EU for GDPR.
So we have a foreign government (to us) that has asserted authority to reach beyond its borders and into our pockets with an absurdly complex regulation, where a single violation would financially destroy the company. Since I don't have $20 million to give to them, and the families of my employees depend on their income for things like food and housing, I have to either carry expensive liability insurance to protect against that, or block EU traffic. For us, and I suspect most other sites on the planet, that's an easy decision to make. I'll take a 5%-10% hit in revenue from the loss of EU traffic and be able to sleep at night knowing that someone in a country I've never been to isn't out there filing documents that have the ability to destroy my and my employees' livelihoods.
I won't go into the minutiae of why it's so easy to violate and why most of the experts we have spoken to agree that being compliant is an uncertain endeavor at best, even if you want to comply, because that would be a very long winded comment. But if you do a Google search, you'll see the gist of the problems.
Can you please quote the "concrete points" made in the parent post?
> the extraterritorial reach, and the absurd maximum fines that can indeed be assessed for a first, single violation
As I said in my comment, I don't think those are big issues if you comply with the law (and 99% of the law is common sense or was already in place in most countries), but they are points that a lawyer might indeed have brought up.
Might be a good opportunity to make some contacts in the Trump administration too, who will be interested in asserting US sovereignty.
That's a big risk, given the size of Europe and the fact that it the US is your current target demographic, it's not a far stretch to think Europe might be, too.
Blocking the EU effectively means the same thing, though, because it's announcing to everybody that you're ignoring that market and leaving the door open for companies who can copy your business model but are willing to respect user's privacy. Not to mention the reputation damage from snubbing their privacy laws. The door's still technically open, but it's going to be much more difficult.
I also wonder if this kind of announcement will backfire a bit for these companies. When I see a "We're dropping the EU over GDPR," article, I don't think about how bad the GDPR must be, but instead I wonder what shady activities these companies are doing that makes them unable to comply, and that makes me avoid them.
The general public are pretty clueless on these things (look at the surprise around Facebook lately), but I do feel it'll cost them some users.
If you refer to the flowchart on how enforcement is to be handled (notably including referring to "proportionate"), the FAQs on regulator sites, and even the track record of penalties under DPA you'll find this is not the case.
Why there are some who keep wanting to catastrophise this is beyond me.
The section you are referring to that uses the word “proportionate” gives a brief list of suggestions of the kinds of things that regulators should consider when issuing fines. But it no way limits their legal ability to issue maximum or multimillion dollar fines for minor violations, and doesn’t even define “proportionate”. A hardline country like Germany may easily decide that because they so value their privacy, “proportionate” is a maximum fine for a single violation.
Anyway, "proportionate" isn't as ill-defined as you claim. It's a term of art used in many laws and we (and the courts) know pretty well what the legislator meant with it. Heck, they even list some criteria. If those aren't fulfilled a maximum fine isn't possible. Also, "proportionate" implies that a more severe violation must have a higher fine meaning the maximum can hardly ever be reached.
A law isn't code and shouldn't be read as such.
Yes, they could, as is clearly stated within the text of the GDPR. Regardless, most websites outside the EU aren't going to want to put up with the headache, and will block EU traffic. Who wants the risk?
For example, "due regard shall be given to" has a very specific meaning with decades of precedent and does not mean whatever pops into a layman's head when reading the text.
How can we be required to delete IP addresses in our logs yet also be required to keep access audit logs for 7 years.
A bullshit law written by people that assume everyone is Facebook and data mining.
I don't know where you got this idea, but I strongly suggest you find someone who has experience with the GDPR and discuss this with them. These two things are not even remotely close to any grey areas that could land someone in hot water.
IANAL but from what I read and heard (indirectly) from lawyers at work this is not a problem. GDPR doesn't apply to data that you are required to keep for other legal reasons.
Then you may well be able to rely on the Legal Obligation basis for processing, namely that “processing is necessary for compliance with a legal obligation to which the controller is subject.”
To be honest, for better or worse I kinda tuned out your indignation at the intricacies of maintaining compliance the moment I saw "HIPPA". HIPAA - the Health Insurance Portability and Accountability Act.
Just how many Europeans would you have with US therapists? Besides, the GDPR specifically mentions data that is already covered under other privacy mandates.
The law has a bunch of unintended consequences that are about to be unleashed. Or maybe, they are consequences that are fully indended: a de facto trade barrier against non-European companies who’s own laws conflict with GDPR.
They are. You just need to tell them what you want to do with their data, and then do what you told them you were going to do. And not something additional ("oh hey look at all these IP addresses stored for security purposes, I bet we could make funny graphs about Bob's sleeping schedule too!") That is apparently too hard for many companies, so now this is codified in law and can actually be enforced.
There are some additional clauses like right to view your data, correct it if incorrect, and remove it if there is no longer a need for it... but that has existed in Dutch law since 2002 and few people ever exercise it. I recently did for the first time when I found out someone was doing WiFi tracking based on MAC addresses (I didn't remember giving consent), and I got an email from them (which looked like it took 15 minutes to look my data up and type it out), so it's not such a big deal.
Hopefully not permanently. Maybe over time the law will be clarified.
I can definitely see EU customers more or less funding GDPR compliance in the long term, though (see EU intervening in roaming charges - https://www.theguardian.com/money/2018/apr/30/three-mobile-r...).
Then why do you need millions of dollars to make it reasonable and transparent?
This is no different to environmental regulation or something like this. Yes, making you stop pour acid into river will make your business more difficult. No, it does not matter.
You say "we don't do bad stuff to environment but complying with 'stop pouring acid into rivers' legislation will cost us spend high six/low seven figures"? That kind of seems like you're not exactly telling us the truth, doesn't it?
Thinking about this, we should probably compile a list of companies that do this, so we can name and shame them.
Reasonable and transparent would be fine. That may be the spirit of GDPR, and I'm sure it's been sold to the EU public like this. But the wording is anything but reasonable. You are talking about things you obviously haven't personally evaluated.
What specifically is not reasonable? GDPR is by european law texts one of the most readable ones.
https://www.exchangewire.com/blog/2016/07/07/an-american-per...
Why not? HN is a pretty fair forum. I'm not familiar with exchangewire and that link is dated July 2016. We've all passed a lot of water since then.
If that was true then you would already be GDPR-compliant, by definition.
And the GP sounds like a large business a small business that maybe has 50 orders a month form EU customers won’t be able to afford a top tier international firm, hire a mandatory local representative and open themselves to this level of liability.
The irony is that the companies that can both comply and abuse the GDPR to their benefit are the ones that regulation such as the GDPR was supposed to protect us from.
As has been discussed before, the GDPR is an EU regulation and as such does not require national governments to pass any enabling legislation and is directly binding and applicable, therefore it is is not subject to "unique interpretation" of any kind. In fact, that was the whole point of making it a regulation, rather than a directive (like the previous Data Protection Directive).
Furthermore, the regulation establishes a European Data Protection Board, tasked with ensuring the consistent application of the GDPR. Articles 55 to 63 of the regulation are devoted to cooperation and consistency, with procedures for multiple Data Protection Authoritiess to coordinate investigations and promote consistent decisions and policies reviewed by the Board and reported to the European Commission.
Now, can we please stop it with the entirely unsubstantiated statements about how everyone will interpret the GDPR as they please?
When has that happened?
You would you be equally proud if we sprayed weed-killer chemicals everywhere to wipe out dangerous plants ("If Water Hemlock is the type of plant that RoundUp kills, then I'm very proud to be a Monsanto stock owner") while killing scores of non-harmful plants? Your scope is narrowly framed and misses the big picture.
Here is an example:
I’m a ukulele maker from Argentina I sell 50 ukulele‘s a month to the EU via my webshop and I use PayPal as my payment processor.
I collect the following information from you that is considered PII under the GDPR.
IP address. Name and Address. Phone number. EMail address.
I don’t need to do anything nefarious with that information to have a huge headache and a potentially huge liability under the GDPR if my data leaks or I don’t comply with a request by a EU customer.
I’m also out of luck if my local legislation contradicts the GDPR since unlike EU member states I don’t have a DPA and my local laws mean squat to the EU.
Complying with a request to be forgotten is surely not too hard and also you still have a right to hold on to probably all Ukelele sales related data for your reasonable accounting purposes. IP address - maybe not unless you use an IPSEC VPN for support 8)
It really is not as bad as you imply. Bear in mind these regs are designed to be complied with by EVERY SINGLE BUSINESS (BIG OR SMALL, TECHNICALLY SOPHISTICATED OR NOT) IN THE ENTIRETY OF THE EU. You are a HN commentator with ~9500 karma - you are probably not stupid and will cope fine.
Its not really a bad idea to take a long look at the data you hold and consider its lifecycle in your org. If it helps, I (UK IT business owner) am not frantically removing IP addresses from logs. I am however enjoying the thought that some bloody stupidly large email accounts will become indefensible, post 25 May. Also the stupid "archives" of old customer docs can damn well get deleted, rather than cluttering up my file servers.
>It really is not as bad as you imply. Bear in mind these regs are designed to be complied with by EVERY SINGLE BUSINESS (BIG OR SMALL, TECHNICALLY SOPHISTICATED OR NOT) IN THE ENTIRETY OF THE EU. You are a HN commentator with ~9500 karma - you are probably not stupid and will cope fine.
It actually is I think many individuals as well as small and medium organizations don't realize the full extent yet and the nuances of switching from the DPA to the GDPR. I work for a very large global financial exchange and I've seen estimates from multiple sources of it's impact I've also seen the estimates that LSEG did. And oh boy it will have a much more substantial impact than what most people here predict.
In fact will guarantee that if you were to be audited on the 26th of May (well the ICO won't do it on a Sat) by the ICO you would be found in violation of the GDPR in one form or another.
I think the GDPR is overreaching and there should be exemptions for small businesses.
I think the GDPR needs to have provisions for blockchain and current cryptocurrencies.
I think that fact that the EU wants to apply it extrajudicially to non-EU entities and organizations is terrifying and amounts to sheer tyranny since they have no say in how the law is enforced or interpreted nor do they have any representation.
And it's clear that you and me think about this on completely different levels, you were making jokes about wiping IP addresses from your logs about using VPN.
If we go back to my specific example then how much do you think it would cost me to get a lawyer that could advise me on GDPR in say San Juan vs London or Amsterdam? How much would it cost me to have a mandatory local representative in the EU? In the UK if I need help I'll talk to the ICO, I'll talk to my MP, I'll take to my EU MP, who the hell do I talk to about GDPR as a ukulele maker from San Juan.
Do you still not see a problem here?
It's terrifying to me that there is already ongoing strong arming to force certain service providers in payment, ecommerce and hosting industries to ensure that all their non EU customers to comply with the GDPR or to face non-compliance which will force businesses to stop offering services to EU residents and or consolidate the already heavily monopolized industry even further by allowing a few companies to dominate the market by providing "GDPR certified" walled gardens.
I think the GDPR needs to have provisions for blockchain and current cryptocurrencies.
Why?
If anything than because you can actually do that under the GDPR: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."
The problem that this has to be evaluated against "the interests or the fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller."
This is more or less going to be open to the interpretation of the DPA and your local EU memberstate laws, the problem is that non-EU entities don't get a DPA, their legal system isn't part of the decision making and they are now open to 28 different interpretations byu 28 different regulators (DPA in each EUMS) and 28 different legal systems.
EU regulators tend not to apply fines for companies making simple mistakes. They do want the companies to come back into compliance.
It is also a bit of a bugger to prepare for (I own a small UK based IT business) but it is a good thing in my opinion.
There are ~0.5 billion EU citizens and GDP is roughly 22% of the world. So it has some clout. The EU as a whole has decided that people's data is important and have come up with some rules about the same. Bear in mind the EU is a very diverse place and getting 28 states to agree on something is akin to cat herding.
I am still in shock about it. I am also very happy about it but it is only a start. Getting FB and Co into line will take a lot longer as will the world getting a decently diversified and mutually compatible, healthy social presence environment working.
[1] https://en.wikipedia.org/wiki/Censorship_of_GitHub#Russia
So sad to see these businesses go (not)
On the flip side, does anyone know of side projects or community projects that have said "We chatted with a European lawyer, who said we don't have anything to worry about, and we'll keep doing our thing"? I know Debian is having that chat (https://lists.debian.org/debian-devel-announce/2018/04/msg00... - and there are some privacy things I think Debian should change, like not keeping people's support emails from years ago public) but I'm curious about projects that are smaller in scope and are basically not trying to hold personal data at all.
Refusing to protect your users from your own predatory use of their personal data because the ROI isn't there is still shady.
Then there's all the GDPR expert blog posts, blasting the EU for not giving any leeway or transition periods. You were in it!
They may well be shut out of the EU now, which is sad, because I know for a fact there was zero malicious intent.
Why would that be?
I think there's a lot of misunderstanding and/or uncertainty about the scope of the GDPR. The fact itself that you know, for a fact, there is no malicious intent, means that the GPDR will have little to no bearing on you.
If you're having a simple free e-mail raffle of goodies for a list of players that signed up for that, there's nothing that prevents you from doing that. What would change is that if someone asks you what you have on them, you have to mail back "we have your email address in a list of email addresses", and you have to really delete it if they request it.
These are things any decent company would normally comply with regardless. It's only problematic if you would be harvesting data for non-transparent purposes, but that's not something that could reasonable be included with "zero malicious intent".
Why would you think that? Collecting email addresses for an optional contest is a legitimate use case. The company just needs to ensure that these addresses are stored securely and must give users the option to get their data deleted.
As a matter of fact I wonder how a company without physical presence in the EU could ever be fined for any violations. And even if they can be fined on paper, I doubt many non-EU countries will cooperate collecting the fines.
Given the chaos around IPv4 assignments, I doubt that only VPN services are affected.
I hope GDPR defenders will understand that if more and more companies adopt this strategy.
Ehm, no. These laws represent how we want (our data) to be treated. If you're business model can't exist within that legal realm than your business model is one we don't want.
Deleted comment
But doesn't anybody else think this has at least some worrying optics of censorship?
Are we going to end up with another great firewall around Europe? And are you sure that only companies which enjoy a consensus as evil will be clawing the outside?
Won't the internet interpret this as damage and route around it?
No. No more than I think being able to sell fake medicine is a censorship.
In fact, I think I have better instincts about detecting fake medicine than I do about detecting the fake arbiter.
What happened in this case is that the Unroll me pill manufacturer announced that they'd not be selling their pills in the EU anymore due to the GDPR.
So, though your concerns remain valid in the general case, in this particular case there could be no shifty arbiter. Unroll me self-assessed and decided that their own pills are fake.
...but what if you were selling a medicine that you knew worked, that you really believed in, but that you knew was going to be labeled fake by an arbiter in the employ of your competitor (and I think it's not unfair to say that the FDA is, at times, exactly this)?
Might you decide not to spend the money to attempt to achieve compliance?
Don't you think that some well-meaning organizations, knowing that they have powerful, well-connected beasts who wish failure for them, might opt to just stay out of Europe (either initially or always) instead of facing the costs of assuring compliance?
No.