You’re also claiming people are rightfully concerned. Where is that right coming from? From past experience? Or is they just baseless concerns?
No, that's not my argument at-all. That's just your personal interpretation of my words.
> "You’re also claiming people are rightfully concerned."
I'm not "also claiming". That was the sole claim from the very start.
> "Where is that right coming from? From past experience? Or is they just baseless concerns?"
It's literally in the comment:
(1) Some elements of the GDPR are up for interpretation.
(2) There's currently no case law surrounding GDPR.
If you take both of these facts into account - it is perfectly plausible for people to be concerned, as there's no telling how things will play out in a court of law.
all those claims about warning shots and leniency and goodwill of the regulator are completely unfounded. the linked article makes the claim, the linked article should substantiate the claims, and we maintain a healthy right to remain skeptical of those claims until some meat is added to them.
I'm not going to link cases, because they're in Danish. They are available from their webpage, and the most resent ones are linked on the frontpage. The last few cases large companies was not in compliance and the didn't get a fine, but they are expected to address the issues, and if they don't then they will get a fine.
We have plenty of cases serving as prior judgements, and if a DPA suddenly act with a disproportional reaction, there is multiple levels of courts that can and will reverse the decision - nationally and EU level as well.
In one a company was handling sensitive personal data (medical data). They're required to register with the ICO. They did not do so. The sceptics would claim they got huge fines. They didn't. THey got a letter asking them to register, with no further action taken. ICO released a statement.
Last para here: https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...
In another the Crown Prosecution Service lost data in the same way they had previously lost data: they sent unencrypted DVDs through the mail and those DVDs got lost. The DVDs contained victim interviews from children who had been sexually abused. It's hard to think of worse: very sensitive data, transmitted in a stupid easily fixed manner, and a repeat offence. Even this didn't attract the biggest fine. They got a £350,000 fine.
https://ico.org.uk/action-weve-taken/enforcement/crown-prose...
We have over 20 years experience of regulation. We're not making this up.