GDPR isn't to blame for all the permission emails you're getting
wired.co.uk
wired.co.uk
The biggest problem was the previous directive, which meant all EU websites display an intrusive message about cookies which needs a click to dismiss. That is the most dumb thing I encounter. And continue to encounter on a daily basis.
Maybe that law should've included a clause about how you shouldn't lie about why you're using third-party cookies?
So they argue that tracking does improve user experience. You may disagree with their reasoning but that doesn't make them liars.
In theory the GDPR/EU Data Protection law covers that. If people consent to one thing, then they haven't consented to to the other thing. So you can't lie to get their personal data.
Block them with your chosen ad blocker.
That said I never accept their plead, I absolutely never ever sign up to any kinds of email marketing so the ONLY reason they even attempt this is because they were doing shady business earlier.
I bet that we will see lots of complaints where companies cry of losing their audience. Well first off it was an illegal channel anyway and second noone read your mail anyway.
GDPR is one of few things that honestly gives me hope for the future of internet. It has the potential to embed a consciousness of how data is managed, both in companies and users.
The point is that those emails are clear signs that companies are ignoring existing laws. It's already illegal, under PECR, to send marketing email to people without their permission.
This should be somewhat reassuring to all the GDPR alarmists: we have very many companies ignoring the law at the moment, but not being fined.
That is awesome.
I see two kinds of emails. One is along the lines that "FYI: we updated our policies regarding X", those are perfectly fine.
Then we have "please click here to allow us to send you more emails", which is more or less admitting "hey, we abused the system and spammed you before, please let us continue to do so".
And I actually get a smile on my face when I receiver either of them. Yes, the second one should be really bad but I already knew that. The signal I get from the second email is "hey, we're not particularly happy about the situation but we will at least obey the new law". And that makes me happy for many reasons.
Job recruiter sites were asking me if I allow sending more emails and as it is practically impossible to unsubscribe from them I will be glad if GDPR makes them stop.
So lots of firms, including some I've worked with, have huge mailing lists with addresses from multiple sources and are _pretty sure_ they got consent in all of those cases, but have no way of showing that if asked.
Personally I would prefer more neutral language. Something like "As a consequence of GDPR, companies have started changing their behavior from X to Y." If you want to give the readers context you could optionally add "Y is already law in the UK, but UK prosecutors have for the most part chosen not to enforce it."
"in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines"
Unless the information commissioner is immortal and is appointed for life there are no guarantees that this will always be the case. Companies read the law and see that they can be fined up to €20 million or 4% of their annual revenue (whichever is greater) and act accordingly. The GDPR is especially pernicious as its scope reaches beyond the boundaries of the European Union. If you're an American company and a single European citizen uses your services you are bound by the GDPR's regulations.
Some people claim that the court system in the EU is more judicious than the United States. For those people I want to ask "Why should I trust the opinion of the people who are going to sue me if I am found to be noncompliant". If you think the people covering their butts are being irrational, read the law again.
And also an indication that GPDR might be working.
That isn’t really true. If you have no legal presence, no employees, no offices, etc in Europe, enforcement actions cannot be taken against you.
The law may say you’re in scope, but that’s only relevant within areas where EU laws have any weight.
https://news.ycombinator.com/item?id=17058645
It's not that the law wants to apply to you but it doesn't have weight because they can't enforce anything against you, as is often heard on HN. It's that the law doesn't want to apply to you.
This is false. I blogged about this topic a while ago: https://www.joyfulbikeshedding.com/blog/2018-04-17-should-no...
The criterium for whether a non-EU company needs to comply to GDPR is: does the company intent to seriously service EU citizen? This is determined based on multiple factors, such as the website's language (do they have e.g. German translations?), providing pricing in euros, testimonials from EU customers, or having a contract with a parcel company with the specific intention of delivering to EU customers. The mere fact that the website can be used by an EU citizen is not enough to have it fall under the GDPR.
Source: the book "Handbook GDPR, Compliance in practice" (page 11) by Arnoud Engelfriet & co, a Dutch IT lawyer. https://ictrecht.nl/boeken/handboek-avg-compliance-in-de-pra...
Hey, thanks a lot for this. It seems these days the noise is larger than the signal. Hard to find anyone putting careful thought into this. Thank you.
The fact that every response to the criticism of GDPR being too ambiguous, is ambiguous, only proves critics right. EU lawmakers picked worst combination: huge fine + huge ambiguity. This all could have been done with more certainity. So sad.
And I agree it sucks, but it sucks less than the alternative (which is to be rigid and say something that becomes meaningless one year after the law is published)
I'm not a lawyer so I'm not in a good position to evaluate Github. But I do know that Github has an office in Amsterdam, The Netherlands, so there is at least the possibility that they have to be GDPR compliant.
But let's say you're buying from a random small business web shop in the US, and everything about that web shop clearly screams that their main business intention is work with US customers, it's just that their delivery service happens to ship world wide even though they clearly don't care about non-US customers. Then yes in theory they can "what they like with my data". In practice they probably have to define what "what they like" means in a contract, like a privacy policy, so it's not as if you can't know about what they will do. You are still able to make an informed decision of whether you want to do business with them.
Your description does not match with what I have seen about GDPR applying to European data subjects which is the language the regulation uses.
Article 83 clearly states that penalties must be proportionate to the scale of the breach, the impact on users, the intentional or negligent character of the breach and the degree of co-operation with the supervisory authority. A supervisory authority can't just bankrupt your company out of spite.
https://gdpr-info.eu/art-83-gdpr/
Your bio says that you're a founder of a company that processes healthcare data. The maximum civil penalty for HIPAA violation is a fine of $50,000 per violation and there have been several multimillion dollar penalties. The maximum criminal penalty is 10 years imprisonment. If you're worried about GDPR, you should be absolutely terrified of HIPAA.
Yes, I also find this hilarious, people love to spread FUD about the GDPR, but HIPPA is more serious (though limited in scope).
How can anything with 11 chapters and 99 sections be "straightforward to interpret and apply"?
https://ico.org.uk/for-organisations/guide-to-the-general-da...
If you're making a hardware product for the US market, you need to comply with FCC Title 47 Part 15. If you've never been involved in this process, I'd encourage you to read it. The rules governing a bluetooth speaker are at least as complex as the rules governing Facebook and Google's hoard of personal information.
https://www.ecfr.gov/cgi-bin/text-idx?SID=91a501119ab6978f87...
Not wishing ill on that particular person, but I actually hope they'll change their mind or get replaced by someone who is heavy-handed with fines.
Because that's the whole point. The reason so many people (myself included) are so impatiently waiting for May 25th is because GDPR has teeth, and can actually do some serious damage to companies continuing to abuse people's data. So if companies are now sending those e-mails because they're afraid, I am happy, because it's evidence that GDPR works.
Yeah, no. You're wrong.
Thanks for the link, if you had actually read it, it would have listed all the criteria for applying penalties.
https://gdpr-info.eu/art-83-gdpr/
> "Why should I trust the opinion of the people who are going to sue me if I am found to be noncompliant"
Because that's what people (and lawyers) do in every case concerning regulatory bodies
> So why are they sending these emails? It's largely around the fear of GDPR. The regulation says companies can be fined up to €20 million or four per cent of their annual global turnover. Many companies are keen to get their systems in order. Although in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines.
TL;DR: It's basically CYA and checking things that they weren't doing before now that they should have been doing