So it isn't businesses that GDPR hurts (except for those that rely on EU traffic, who will make up for GDPR costs somehow - at your expense), it's actually the EU itself. Consumer choice is a good thing, and this law will dramatically limit it.
So it isn't businesses that GDPR hurts (except for those that rely on EU traffic, who will make up for GDPR costs somehow - at your expense), it's actually the EU itself. Consumer choice is a good thing, and this law will dramatically limit it.
Let's be real here for a second, what's your definition of dramatic? I don't foresee the EU losing access to more than a handful of services, many of which as in the case above provide questionable products.
I'm very much doubting that we'll be talking here in a year and the EU somehow finds itself behind the great-GDPRwall. That's just arbitrary panic.
>Consumer choice is a good thing, and this law will dramatically limit it.
You're neglecting the fact that consumers can make collective choices about the things they do not want to put up with. Abuse of private data is one such domain. There is no iron law of the business world that consumers need to accept every product of any kind on every market. That's up for societies to decide. The law seems to be quite popular from what I can see, so any cost that we European consumers do actually incur, we are apparently happy to endure.
As horror stories come out and geoblocking tools become easy to use, I'd say that over the next few years, the vast majority of non-EU sites will have blocked EU traffic. Nobody wants the liability unless they make a large percentage of their revenue from EU countries. Accepting such traffic means exposing your business to instant financial annihilation at the whim of a foreign government.
Here is a fact. If your business complied with EU data protection laws, GDPR is only an incremental step. And, here is another fact. The EU is nowhere near as litigious as the United States. GDPR may levy some intense fines at repeat offenders, particularly those who haven't been in compliance with any data security/protection law from the last twenty years. But to claim "financial annihilation at the whim of a foreign government"?? That's just poor taste.
Examples: France suing Apple over developer fees. France blocking the sale of DailyMotion to Yahoo. The war against Uber with the simultaneous promotion of BlaBlaCar, the attacks against Apple for taxes on income that wasn’t even earned in France, the collective freak-out over AirBnB while subsidizing Gites de France.
My point is that exposing yourself to the risk of a European money-grab is too high. Besides, who benefits from collected fines? Governments. Those fines don’t get paid to the aggrieved party, they get paid to the government. Governments have an incentive to levy fines on foreign companies, with very little downside — European jobs aren’t at risk.
The attack surface is just too great to be using “hope” as a strategy.
http://www.privacy-regulation.eu/en/article-83-general-condi...
http://www.privacy-regulation.eu/en/article-58-powers-GDPR.h...
Section 58 is about EU powers under the GDPR. Section 83 gets into the spirit and purpose of fines levied.
Being overly punitive would only invite judicial oversight.
Then let's say "financial annihilation at the discretion of a foreign government"? I don't see how you can deny that the GDPR gives them that discretion, unconstrained by statute (though constrained by a judge's fuzzy standards of reasonableness).
You're saying that they will use that discretion reasonably. You're probably right; but why do they need it in the first place? Like, why is 20M EUR the right number here? Why not 10M or 40M?
Or are you sufficiently confident in your regulators' discretion that you don't think the numbers matter? That's great, but it's not the rule of law.
I think two classes of business will block the EU: those with business models fundamentally incompatible with the GDPR (like unroll.me, I suspect), and those with compatible models that consider their EU business too small to justify the risk. I feel no sadness for the former, but the latter seems to me like real damage. It could easily have been avoided with proportionate fines. Why do you think they didn't do that?
However, I still don't agree that foreign governments can operate unconstrained by statute. Again, I'll point you to article 83 of the GDPR. It starts off with some vague statement about how supervising authorities need to make sure that fines are effective, proportionate and dissuasive. That's bullshit, but if you read further, they add quite a bit more substance to the argument.
I've just been linking to article 83, but it's likely worth quoting once in this thread. Part of it reads:
---
When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
(a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
(b) the intentional or negligent character of the infringement;
(c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
(j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
(source - http://www.privacy-regulation.eu/en/article-83-general-condi...)
---
Also, consider that GDPR isn't a huge change over existing EU privacy legislation. The scariest change in GDPR is that it gives the European Union tools to force non-European companies to comply. While that is scary, if a non-European company has been showing a good faith effort to comply with existing EU privacy protections, they shouldn't have much to fear unless something fucked up happens.
To summarize my position, if a company is already complying with EU privacy law, they don't have much to fear. If a company is not complying with EU privacy law, they have a problem, but seeing as how the first draft of GDPR came out almost six years ago I don't feel particularly bad for them. And finally, if a company was found not to be in compliance, it would be hard to justify the maximum fines if they were showing a good faith effort to become compliant.
The wildcard here would be what would happen if a popular company suffered a massive data breach. Consider for example, the time that LinkedIn accidentally lost a whole bunch of unhashed passwords. On one hand, that's a massive breach, LinkedIn did a very poor job as data stewards and it's a perfect opportunity for a maximum fine. On the other hand, what would be the political ramifications? And where would liability flow?
Also: Doesn't the extraterritoriality bother you? There are roughly 200 countries in the world. Do you really want to argue that each of them can impose a burden on a website operated outside its borders, just because its people might happen to visit it? That seems like an incredibly dangerous precedent to me. Can the UK enforce a super-injunction against all websites available to its nationals? What's the difference between the GDPR and that super-injunction? It can't just be that "one is good and the other bad"--what law determines that?
As I understand it the penalty is assessed and levied by the regulator. Just like DPA penalties where the number of people receiving any fine at all has been minuscule. The proportionality of instances where fines have been given seems good. I think most EU citizens would feel too few, and too low fines have been the norm.
> That level of unpredictability doesn't seem like law to me
That is how most UK and EU law has worked for, well, forever. Most offences have a maximum penalty yet it is the US that regularly makes headlines for extreme penalties or length of incarceration.
Plenty of people get small fines in the hundreds, or just a caution, or their business gets a letter for offences that have fines running far into the thousands.
Talking of extraterritoriality, doesn't that also apply, along with the burden to 200 nations you criticise, to the US DMCA for sites with user content?
My question isn't whether the fines are frequent or high enough. It's whether they're predictable enough--whether the law is described in enough detail that two people interpreting it independently would reach something close to the same number given the same facts. I don't think it is. (Do you?) The usual answer is "but don't worry, the people interpreting it make good decisions". I think that's probably true; but when the maximum penalty is indeed financial annihilation, that doesn't seem too comforting.
The USA has indeed pushed the extraterritorial limits. I think that's bad, and I don't see how it makes the EU's reach any better. And to emphasize, my concern isn't the burden to ~200 nations--it's the burden from ~200 nations. Should the UK be able to enforce that super-injunction? If not, why not? Iran, a prohibition on the Satanic Diaries?
I'm used to the law going easy for a first offence, or an accidental breach. Occasionally we have separated offences (murder and manslaughter for example), but most of the time there's just a maximum that is reserved for the most wilful, or repeat or extreme cases. No one has ever been bankrupted by our unlimited fine for cannabis possession (most get a caution or trivial fine).
Apart from anything else means are assessed before any fine is levied. If you're on minimum wage a £100 fine is going to hurt rather more than to a millionaire. So means are assessed first to try and remain proportionate.
So how is it done in the US? I only have what I've gleaned from the media. Does the judge or regulator enforcing really have no discretion of penalty or always seek the maximum? I find it very difficult to believe that the entire range of penalties and when they apply are spelt out in every law and judges or regulators have no discretion or common sense. Movie "experience" seems to indicate a lot more horse trading goes on.
Do our legal systems diverge so much that US citizens completely distrust theirs to do anything but bankrupt them for minutiae whilst we remain certain they can and will be proportionate?
> ...extraterritorial limits. I think that's bad, and I don't see how it makes the EU's reach any better
I'm somewhat uncomfortable with some of the global precedents myself. On the other hand I'm not sure how it is avoided in a world that is so globalised and so many internet services have essentially ignored EU privacy and data protection. So what's the alternative?
We're not enthusiastic to adopt the US model of privacy and many internet services aren't even paying lip service to our (too) limited protections. How else to fix it? EU wide Facebook blocks seem like a fine way to start a trade war!
I think...maybe? It's a continuum, and a legal system with zero judicial discretion would either require impossibly detailed law or yield obviously unjust results. I don't think the model in the USA is strictly adversarial--like, it's not entirely that the regulators are supposed to punish you to the maximum extent of the law as written, and if that's unjust then blame the legislators. It's closer, though. This has advantages (less opportunity for selective enforcement) and disadvantages (increased complexity of law, greater opportunity for loopholes).
> I'm somewhat uncomfortable with some of the global precedents myself. On the other hand I'm not sure how it is avoided in a world that is so globalised and so many internet services have essentially ignored EU privacy and data protection. So what's the alternative?
Any large player has operations within the EU, making the extraterritorial reach unnecessary. For smaller players, I see lots of unexplored opportunity to regulate indirectly through ad networks, payment processors, etc.
The precise mechanism isn't defined in the GDPR, but I suspect it'll operate similar to judicial review - a court can determine that a reasonable decision was made by the authority, and thus allow the fine as is, or they can determine the authority acted unreasonably or did not take into account the proper factors, and thus quash the decision and order it to be remade. I'd be somewhat surprised if the courts were directly setting fines.
Aside: What's with all the downvotes? Your comment seems fine to me, as do many others in this thread. It seems like any discussion of the mechanics of enforcement gets a nasty response here, as if the only people who should care about that are criminals. The GDPR might be the perfect legislation with which to erode civil liberties, since the people who would normally jump on such arguments will be on your side... Or is there another reason?
> I think most Americans (including me) would still put Article 83 in the "fuzzy standards of reasonableness" category
Is it valid to say that you're not wrong, but I disagree? :)
I agree that article 83 will be hard to interpret if people act in bad faith. But, it provides a good framework for how to act in good faith.
I would argue that if you genuinely care about your users and their data, you'll likely be okay unless something fucked up happens. And when something fucked up happens, as long as you're transparent, respectful and helpful, you'll still likely be okay unless something really fucked up happens. And then, you'll have bigger things to worry about anyways, so fuck the GDPR. :)
> I agree that it probably works in practice, but I wouldn't see it as much of a constraint. Like, how closely would you expect the rulings of two independent judges each assessing a fine according to these guidelines to match?
I completely agree with you. Unfortunately, vast parts of the American/Canadian justice systems would also fail this test.
> Also: Doesn't the extraterritoriality bother you?
It sure does. The extraterritoriality is first class bullshit. But, if current European data protection laws are any guide, it will mostly be used as a tool to gently encourage compliance and actual punishments will be very rare.
1. We complain about those too.
2. The dangers of extraterritoriality and vagueness seem synergistic. A major check on regulators' discretion is political will, and screwing foreigners tends to be a lot more popular than screwing your own citizens. The ideal tax is one on foreigners living abroad...
I think the GDPR will probably be fine, and have net positive effects even as it pushes small, essentially-compliant but risk-averse operators out of the EU. I find its legal basis troubling.
One time, I was afraid of some anti-corruption laws because it seemed like basic parts of doing business here would result in severe penalties there. My roommate at the time thought I was being certifiably insane, because the EU just doesn't work like that. He couldn't imagine what transgression I could possibly commit to warrant more than a strongly worded letter (on better stationery than I'd get from the Canadian government).
From there, I started learning more about how open the EU is.
I mentioned this in another comment, but I'll also encourage you to read about the International Procurement Instrument. The EU (like many other economic bodies) has trouble with non-EU companies bidding on EU public contracts and winning because the playing fields just aren't level. I don't want to give too much of the story away, but as you read about the IPI meandering its way through European politics, you can see an EU bending over backwards to make sure that foreign companies have open access to EU markets.
If you read about the IPI with North American eyes, it seems absolutely bizarre. But it's a good primer to the EU's difficulty with protectionism. I'm from western Canada and seriouslu, if the Canadian government felt this way about protectionism, I could get a western independent movement off the ground in a matter of months...not that I would or would even want to, but it would be so egregiously opposite how we do things that radicalism would ensue.
Sorry for droning on and on, but I don't think I can really debate you. I agree with you and everything you're saying is logical. My only response is that Europe is so incredibly different and that response is honestly starting to wear thin.
Besides, I'm being a shitty entrepreneur. The more people are afraid of GDPR, the more opportunity I'll get!! :)
(I've enjoyed this talk with you. Thanks for engaging with me!)
My understanding is that "consumer choice" is a code for radical deregulation of the markets until all the "choices" that the consumer is left with are each as bad as the other. "Sure, you can go to our competitor, but they hoover up your data just like we do".
Bollocks.
I run a small (IT) business in the UK. I will have just as much internet as you post 25 May. The difference may be that my company and others in the EU might automatically be perceived as more trustworthy than those that do not comply with GDPR and hence we may benefit.
GDPR is not a money making exercise.
My company has a wiki page called "Risks and Opportunities". GDPR is definitively under Opp. these days - for us and our customers. I also quite like it as a person - a private individual.
The most interesting thing to me about this whole ordeal is which companies only comply in Europe, where they're legally required, and those who have gone ahead and made sure they are compliant globally: It defines the difference between people ensuring your privacy rights because they have to, where they have to, and those ensuring your privacy rights globally because it's the right thing to do.
Google's AMP project just introduced a whole set of new features not just to mark whether or not an EU user has consented to tracking, but also a new feature to geolocate users, specifically for the purpose of determining if they're legally required to get that consent. Which is sad to me; they should be getting user consent everywhere.
Let's first be totally clear: GAFA isn't suspending their EU operations, nor is any other company that 1) has already an established EU base and 2) can afford the cost of compliance. What I think will happen is that new players will stay out of the EU, because of the perceived risk (accurate or not) and the cost of compliance. So I do agree with the parent that the GDPR will eventually lead to a slow pauperization of the internet in the EU, the only difference with China being that it is self-inflicted rather than self-imposed.
Note that there are very few regulations out there (EU or US) that have actually helped the internet. Most of the regulation that was drafted in good faith turned out to bring more harm than good to the internet, the recent FOSTA bill being a prime example. At this time, I have no indication to believe that the GDPR will succeed where most other bills have failed. But if it turns out otherwise, I'll be the first to admit that I was wrong.
Liability for what? You're not going to get sued. At worst you're going to get fined for negligence, probably after after repeated warnings. I don't think you can find insurance against willful repeated misconduct.
It's only if your service can't possibly comply without losing your bottom line that you have to worry, in which case the GDPR is working as intended.
Find a better business model for EU costumers, or cease your presence there. It's a win-win for EU consumers either way.
Yes, this is the most confusing thing - a lot of posters talk about "being sued because of GDPR" but that's not how it works. And it's always people with the same arguments - small companies, getting sued, crazy money for lawyers, etc.
If I was paranoid, I would think this is some kind of organized campaign to spread FUD and have as many people be against GDPR as possible, perhaps as a way to make sure something similar won't happen in the US.
It's probably just misinformed people.
Probably. There seems to be a real disconnect between US and EU perception of legal and business landscapes here, with the US worrying about the EU legislation more than those based in the EU, who would be far more affected by it (after all, they can't "shut out" Europe).
One of those things is not like the others.
I have no idea where the meme about exploitative lawyers looking for minor non-compliance came from, because the primary means of enforcement under the GDPR is regulatory action. The whole strategy of threatening legal action to prompt a profitable out of court settlement is much less viable under typical EU legal systems than in the US anyway.
However, GDPR definitely can cause significant compliance overheads for small organisations, including those who have done nothing wrong. The official guidance is still terrible, and just the uncertainty around several key points is a problem for reasons we've previously discussed at length on HN.
Trusting in regulators to do the right thing is also a risky strategy. I write this as someone whose business really did receive a crippling demand for monies never owed direct from an EU government tax office after the VAT changes, with very scary accompanying threats and impossibly short timescales to respond, and there were many thousands of other small businesses similarly attacked just in the incidents I'm personally aware of.
From a pragmatic point of view, the regulator in my country is well known to be under-funded and under-staffed, but even that doesn't necessarily help because as with other issues within their remit, it makes smaller organisations easier targets than those with big legal departments to fight back.
$20 million in fines that - despite the protestations of everyone that has ever commented in these threads - can be imposed for a first, single violation, without any warnings. If they meant for there to be any safeguards for companies, that language would have been built into the GDPR. But it wasn't. There are no limits, other than $10/$20 million.
When it comes to getting the max fine at first strike. The GDPR is not the first law in the EU with teeth. There are strict laws about corruption, pollution and antitrust here as well. Do companies get dinged with max penalty from the start violating these laws, not that I've seen. Why should enforcement of the GDPR be different from the current laws?
http://blogs.discovermagazine.com/notrocketscience/2011/04/1...
GDPR has strong language around the purpose of fines and the kinds of considerations that should be made before imposing them. Being overly punitive, especially if a company shows good faith effort to comply, would only welcome judicial oversight. What would the EU gain in such a scenario? And what could the EU lose in such a scenario?
It gains the millions of dollars from the fines, in addition to aiding local EU competitors by bankrupting or hobbling their international foes. It loses nothing.
You can’t see why that’s an incentive and indeed an invitation to abuse GDPR?
First, I have significant trouble believing that the entire European Union would collude to attack international companies in favour of local companies. For a perfect example of this, do some research into the International Procurement Instrument. The IPI is an example of when the EU as a whole has bent over backwards to make sure that non-EU companies have fair access to EU public contracts, even if the playing fields are not level and EU companies don't have equivalent access to the non-EU markets. I assume that you're North American (I am too), so reading about the IPI will seem like comedy hour at Bizarro world, particularly when you see how difficult protectionism is in the EU.
Second, it's worth noting that your scenario as described gets uncomfortably close to a definition of passive corruption. Again, I have significant trouble believing that you could get so many people to agree to do something so potentially explosive.
And third, the EU currently has a very strong tool in its arsenal to enhance data security. The GDPR is very strong because it's ambiguous and people like you are scared of it. The moment that GDPR starts to face legal challenges, that ambiguity will get chipped away.
The GDPR replaces the Data Protection Directive, which left the levels of penalty to the discretion of individual member states. In the UK, the maximum fine for a breach of the Data Protection Act (the British implementation of the DPD) is £500,000. You can see a full list of enforcement action taken by the Information Commissioner's Office at the link below. I defy you to find a single example of a monetary penalty that was disproportionate.
I don't think that's necessarily true. If a company does not provide the service in the EU but there is demand for it, someone else will fill the spot.
Laws are not mailing lists.
No, and for a good reason. Just like if you could opt out of employee protection laws, the "opt out" would soon become mandatory to get a job.
> You can choose to work more than 48 hours a week on average if you’re over 18. This is called ‘opting out’.
> Your employer can ask you to opt out, but you can’t be sacked or treated unfairly for refusing to do so.
https://www.gov.uk/maximum-weekly-working-hours/weekly-maxim...
IMO, the best solution is per-row encryption with the keys stored in a second database. This second database can still be backed up, with backups that have a maximum lifespan, eg: 30 days. When a user deletes their account, their decryption key is deleted, and is unrecoverable after the backup max life.
How long do you keep your backups? If you just store them for, say, 30 days, that's fine. The EU regulators aren't going to come after you for a 30-day lag for all traces of data to be deleted, as long as that process is documented.
There's still one annoyance left: you do need to keep track of accounts/users who have deleted data, so if you have to restore from a backup, you can't restore any data belonging to users who have deleted their data within that window.
Otherwise, this is frankly not such a big deal. If you're storing backups for longer than 30 days, why? Where I work, if we had to restore from a 30-day-old backup, it'd be catastrophic for the business given how much data would be lost.
That seems like a big annoyance. The only way around it is a 2nd database that removes certain data in case a backup is ever restored. Ironically, keeping data on the data you need to delete.
This is a gross exaggeration. I agree that truly small companies may have issues, but companies way smaller than FB and Google can and are spending the time to comply.