GDPR Resource Library
carpedatumlaw.com
carpedatumlaw.com
Definitely watch the videos. I can tell you having done GDPR legal risk assessments for the past few years that if you're only thinking about this now, you're probably too late. The good news is the regulators are 1) going after low hanging fruit first (Facebook, Google, Apple, etc); 2) many of them are in disagreement about enforcement and priorities; 3) much of this is really about pseudo-taxation (hence the 4% of global gross revenue scare tactic); 4) some regulators are going to fight about who "gets to" go after certain companies; 5) if you're a tiny solo shop that does messaging apps, the likelihood of you even being noticed is so slim that closing up shop is really extreme; 6) compliance is probably easier than you think if you are that small.
GDPR is anti-tech and anti-small business.
Have we seen any enforcement at all yet?
Because the little guy won't put up much resistance?
I think GDPR is a good thing BTW.
It literally says this.
"4% of annual global turnover or €20 Million (whichever is greater)"
"...subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher."
It also says "...the fines imposed shall be effective, proportionate and dissuasive."
https://gdpr-info.eu/art-83-gdpr/
"Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:"
Proportionate how? That's obviously up to them to decide and they probably mean that large companies like Google will be subject to the 4% instead of 20 million euro. Are you going to bet your life savings that they will fine you 4k euro instead of 1 million euro?
Why would they bother to add the phrase with "whichever is higher" if they were even going to consider a fine lower than 20 million euro? Think about it. They don't care about the fine being proportionate to the downside, they are just worried about it not being strict enough to companies like Facebook and Google.
Yes, the maxima are high, but it's crazy to believe the DPAs will be able (both legally and politically) to hand fines even close to that out left and right, even if you assumed they over night suddenly turn into organizations hell-bent to do maximum damage.
It's weird how people see that maximum amount and somehow believe those will be the norm, throwing all experience with both the DPAs and other regulations out of the window. How many undeserving businesses have been fined to death in other areas (financial regulation, environmental protection, ...) and why should this suddenly start with privacy law? No government has an interest in its enforcement arm ruining business, of course they care about downsides. Regulation and its enforcement doesn't exist in a vacuum, as much as the revenge-boner some "privacy advocates" (ideally selling some GDPR advice on the side...) get right now wishes it were otherwise.
(On the other hand, these numbers seem to be the only thing motivating some business owners to care, so even if they're never used they've served a purpose. Really, the amount of conversations you see that go "And they are complaining that suddenly doing X is so much work", "Didn't they have to do X under previous law as well?" "..." is mind-boggling)
There's absolutely NO detail on how exactly the fines will scale DOWN other than to say that the fine could be as low as 10 million euro to 2% of global turnover. And it is filled with vague, totally up to the imagination terms like "nature, gravity and duration".
Do you really want to leave this up to the imagination of poor EU countries like Croatia or Romania and think they are going to care about making some random people bankrupt so they can cash in millions?
If the law does not prevent it, you can bet it will be abused.
How many business have been fined to death in other areas? I don't know but I am sure you won't hear about them. No one wants to be the guinea pig.
This law probably has the widest and easily enforceable scope out of any others in the past. That's what makes it different from before.
1. http://www.seyfarth.com/dir_docs/publications/GDPR_Webinar_2...
I wonder what you would consider long.
It's not 88 full 'pages' of text, and what few legal terms they use are either A) defined in other parts of the document or B) easily googable.
If you print it you can see 88 pages.
2. Enforcement will likely follow the current path of most national regulators, which is about compliance more than punishment
3. Why do you think it applies to only tech companies?
4. Small companies will find compliance much easier.
Again though, the concerns are real, and I wish I had a better answer other than "don't worry, it's highly unlikely anything bad will happen."
“2) many of [the regulators] are in disagreement about enforcement and priorities; 3) much of this is really about pseudo-taxation.... 4) some regulators are going to fight about who "gets to" go after certain companies;”
So it says a) the rules are extremely unclear, even to regulators (which means that each of the 28 countries WILL have different interpretations of GDPR), b) that it WILL be abused to “tax” international companies; and c) each of the countries are so eager to abuse their newly granted “pseudo-taxation” collection powers that they will literally be waiting in line to do so.
None of that gives me any comfort.
Stop repeating this BS. Unless you're facebook (and even then) you're not going to get fined $20 million
Facebook will face much larger fines. The maximum fine is 4% of revenue, or $20 million, whichever is greater. Have you not read the GDPR?
Before you say “yeah but they won’t hand out big fines,” please show me where in the GDPR it says that they legally can’t. Because according to GP, GDPR will be used as a form of “pseudo-taxation”. That means abuse, and going after anyone and everyone for as much as they can.
Quite amazingly 4% of FB's revenue for 2017 is 1.6 Billion Dollars. Intel's anti-competition fine was bigger than that.
What a bargain. And here I was, ridiculously thinking that the fines were high! For a small business like mine, I only have to pay up to 20 million EUR to foreign governments in countries I have never been to and do not operate in.
Never mind that it would take me a lifetime or two to come up with that.
(b) It's possible to simultaneously believe that the GDPR is basically lawless (i.e., that regulatory discretion determines who pays what more than the text of the law does), and basically fine. That's how most of the countries in the world work--China has no law explaining who they'll kill for their organs, but I still know they won't kill me for mine. I happen to like the rule of law, and I'm sad to see Europe degrade that, with its citizens cheering the way; but most humans in history have lived without it.
You’re correct. Which is actually more than $20M.
China has no law explaining who they'll kill for their organs, but I still know they won't kill me for mine
I don’t live in China, and the odds that they will come to the US and kill me for my organs are quite small. However, the odds that the EU may be able to use existing, well-established international treaties regarding the enforcement of EU judgments to impose their new “pseudo-tax” on me in the US are considerably higher.
You don't have to purge your system of all PII upon request. An IP address is only considered PII if it can be used with other data to identify a person. If you delete the user's account, you can keep your server logs with IP addresses as long as you have a compelling business reason.
That reason is "security and monitoring".
Really most of the GDPR is just best practices codified. You are only really in trouble if you are using customer data for purposes that you A) haven't received their consent for and B) aren't what the customer would expect given what they are using your service for.
If you are able to map the IP to a user then it becomes personally identifiable but the IP itself is not.
"a. the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;"
Because the data is still necessary, you don't have to delete it.
That's what the full-time solicitor at my company said. It will be like PPI, only worse.
The big punitive fines people are talking about are the ones available to the regulators via a separate mechanism. As far as I can see, they do potentially apply to technical breaches as well, but that's quite a different context legally speaking.
I say as a strategy they don't go after those but the middle tier who is less able to put up a fight legally. Perhaps you remember how long it took the Justice Department to fight Microsoft in the 90's. These large corporations have a great deal of brains and legal muscle. It's hard to believe that they will be the initial targets (although anything is possible). The 2nd tier is more likely the ones that will have issues (if any). Most companies aren't even close to this they are probably 7 or 10th tier targets. Some (small company with nominal user base) aren't even going to get noticed. That's the reality. Powerful law firms. Connected people. Even access to powerful US politicians. What's the chance? (Look at what is happening with ZTE now in China). To big to fail. This is not Monsanto dumping chemicals or asbestos type harm anyway.
It's like spam (but not because major companies are not abusing that typically). You can do what you want as long as you are not operating an industrial strength spam machine. The emails that you send to your customers for whatever reason w/o even explicit approval will not get you into hot water (sure anything is possible but highly unlikely).
Especially because a bunch of the regulators aren't ready yet.
I get paid for strategy and get paid highly providing that type of advice to companies including one that was mentioned in this thread.