If your business relies on re-selling user data or aggressively targeting ads through data mining, coming into compliance will be painful and expensive; it might completely break your business model. If your business just sells a useful service at a reasonable price while respecting user privacy, you've got very little to worry about.
I get the advantage of being more prepared to apply GDPR but that lasts 1-2 months max. The fact that people keep using facebook mindlessly in and out of EU over the last year makes one wonder: Does it really matter to users?
The advantage is in having a sustainable business model that isn't based on exploiting user data.
With GDPR-compliant privacy controls in place, it'll be a lot harder to target advertising or profit from user data by selling it to third parties. Companies that provide a "free" service based on these revenue streams will face a long battle of regulatory enforcement and dwindling ARPU. They might have no choice but to completely pivot their business model. If you just provide a service in exchange for money and take reasonable steps to protect your users' privacy, it's business as usual.
This applies doubly to startups. If a service like Snapchat or Instagram were to launch next week, potential investors will be asking a lot of questions about how their revenue model will hold up against GDPR. The old approach of "grab a ton of users, harvest a ton of data and figure out how to monetise it later" doesn't really stack up when your ability to financially exploit personal information is severely curtailed. If you decide to fence off EU users and exploit everyone else's data, you're playing a risky game - the regulators will not react sympathetically if it turns out your geofencing technology is imperfect and you've been illegally harvesting EU user data.
facebook can do that too (it's just less profitable), so there isnt really an advantage here.
What about games/apps people would never pay for but they would be ok with getting targeted ads within? Is the EU ok with losing these services because they would not be profitable businesses if their only option were to ask users to pay?
Evidently, yes. If your business can't survive without infringing on the rights of users, then the EU doesn't want your business.
At that point, the discussion would be all about all the "jobs we would destroy" and "businesses opportunities we would shut down!", and heavy lobbying would make sure it gets nowhere.
The information you provide to people must be concise, transparent, intelligible, easily accessible, and it must use clear and plain language.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
They recently came out with a new screen asking users to consent to a bunch of things, so they weren't compliant until then, and I wouldn't bet they are now.
Liability means that mistakes are (hopefully) punished more proportionally to their effects, which allows one to scale measures as the business grows. Meanwhile, the transparency means that any potential issues are easier to spot, making it possible for suits to be brought. Note that transparency towards users has been shown to be rather ineffective, similar to how no-one reads the eula.
- The UK ICO's Guide to the GDPR is a good step. Kudos to those who got the budget passed to do that. https://ico.org.uk/for-organisations/guide-to-the-general-da...
- Produce clear example cases before things are litigated. That way, you don't run into the problem of "Well, nobody really knows how things are going to shake out and people are trying to stay in the middle of the pack in terms of compliance" (Which is what I heard from an entrepreneur at a panel at Slaughter & May)
- Hire someone to write The Manga Guide to GDPR Compliance, in the style of https://nostarch.com/mg_databases.htm Or in the style of http://lawcomic.net/guide/?p=1585.
- Post video courses with the same sort of content.
Part of the problem here is that law firms have a strong incentive to publish SEO-optimised content which proclaims that compliance is difficult and confusing and that you should hire an expert law firm.
No it doesn't. Everything was working completely fine before.
This is a bit awkward for me since I don't use Facebook.
If people actually start writing software from ground up where it's easy to handle GDPR requirements, such as user deletion, giving users access to their data, etc., then it shouldn't be hard to start compliant and stay compliant.
ALTER TABLE users ADD COLUMN consents jsonb;
Easy enough.One evil is better than two.