If it's too hard for you to copy paste a GDPR compliant privacy policy and monitor a GDPR email address then well, maybe you're in the wrong job.
We have business reasons for collecting user data, and users have no real reason to tell us to delete it at will, other than the fact that it makes them feel "creeped out".
The future is probably going to be super creepy. If you want to participate, get over it.
-Other than the fact that it makes them feel "creeped out".
Pick one.
My mother does not understand where data is kept, what is encryption or anonymisation even if you darw it for her...
and if my father wants tp watch porn he’ll pop his CC where ever just to jerk off...
Obviously it's "safer" to let others make rules and force us inside the fence to keep us sheep away from the dangerous wolves out there. I do understand that perspective to some extent. However I would never trade my freedom for security. The former is not easy to regain.
Your example where you "want to give your data away to a sketchy website" is not in any way representative of reality when a) the website is as ubiquitous as for instance FB, and thus in no way perceived as sketchy, and b) the user makes no conscious decision to consent (let alone "wants it").
> Hoping you've blocked access to the EU so I don't happen across it :)
Being glad that he doesn't have the freedom to use the site, thanks to a government law (whether a side-effect of the law or a direct effect is irrelevant, because the law brought it out just the same).
That is, if you're offering such a service that exploits users for their data, then I would never want to use it, so it might as well be blocked, for all I care.
Maybe even desirable if it was, so you don't come across it by mistake and sign up without doing proper diligence.
Freedom of choice is nice, but there's an argument that putting rat-poison in food products isn't ok, even if you label it on the package.
thinking it’s a good idea to give your personal data to FB is not FBs fault, it’s yours.
So we should stop government from enforcing food safety and accept poisonings as fact of life...
Counterpoint: Cigarette companies poison you, and they found it's an amazing way to gain repeat customers.
like do they MAKE you smoke? cos government MAKES me pay taxes Marlboro does not MAKE me smoke...
* XIX century wants it's snake oil back * Didn't hear about China and melamine milk scandal? * Would you buy food from Amazon if it was co-mingled in current way? * VW emission scandal
It is easy to be freetard when you do not get diarrhea every so often due to food that was "optimized" (like in XIX century ;)
https://en.wikipedia.org/wiki/The_Jungle
Consider how many modern food standards regulations came about, and what abuses they were addressing.
The milk scandal is interesting tho. I don't disagree that there are people/companies out there that are horrible human beings (or run by horrible human beings), but these are exceptions. There is also a market-based recourse for consumers. Lawsuits and liability is a big deterrent for example. It's also illegal to harm someone (as it should be) so jail time for the offenders is quite possible without having enormous and onerous regulations. And haven't you noticed that it's the giant companies that often push regulation? Because it raises barriers to entry for competitors. Big companies have the resources they need. Using the government to hurt your competitors is one of the oldest traditions in countries with governments big enough and powerful enough to do so.
[1] https://www.history.com/news/7-things-you-may-not-know-about...
[2] https://www.libertariannews.org/2012/11/15/meat-packing-lies...
[3] https://www.zeroaggressionproject.org/uncategorized/upton-si...
The government isn't the only source of power and coercion; private companies are too. A lot of these regulations are the one countering the other.
Riiiight. You sound like the perfect person to be handing my personal information and I would trust you to take full care of it.
Not.
EDIT: Not allowed to say what was previously put here.
> Your laws may say differently
Sure, Canadian laws in this area are very scattered and backwards. I wouldn't put that forward as a good thing though, or use it as a pretense to not bother protecting or managing your users PII.
"I shoot this sex tape myself with my camera, climbed my tree on lawn, zoomed with my long focus lens, stored it in my computer. It's my data. If they don't like it, they should have pulled their curtain."
There must be a threshold somewhere. When does it stops being acceptable, and starts being creepy?
Public places are one thing (he entered this building with that woman at this hour). Looking through private property is another.
But if I do not use your service, then I want that you delete all my personal data. Why is that so hard?
There are pieces of information that are particularly problematic for other parties to know. An email address is not one of those things.
I realize that it was a user error, am a bit miffed about it for two minutes, maybe mail them that they should be more careful with mail addresses.
If, OTOH, it's a business misusing my mail address intentionally and for monetary profit, I hope that regulators stomp on them.
I’d take a big issue to an organization storing a social security number or something of that nature, because its leak would represent a significant risk, but email addresses are fairly disposable items that we only voluntarily attach to ourselves to.
EU citizens turned into "pests" two years ago. Much like Y2K was a "pest" years before January 1, 2000. But unlike EU regulations, Y2K was like The Terminator: there was no appeal process, and it absolutely would not stop...ever, until you fix your Y2K bugs.
GDPR OTOH, eh, maybe there's some way to wiggle out of it? And two years later, when Compliance Day comes, here we are.
Are they really pests for demanding privacy? In today's environment?
"I want to use your free service without participating in your monetization model. K thanks" -- EU citizens
My take is that consumers need to be aware of what 'free' really means for each service that advertises it. What are the real implications - not just something hidden in doublespeak in a ToS or privacy policy.
Everything spelled out in the GDPR is a great thing for users and should have been there from the very beginning - being able to erase all their data, see all their data, export their data, and get notified when data is accessed.
I hate this "empowering users" philosophy of the EU. It's reminiscent of "right to be forgotten" type regulation where EU believes users should be in control of "their" data, when it reality it isn't "theirs" to begin with. Once data is "public" you can't ever "erase" it because it's not "yours". I'm sorry, if you shoplift in my store (online or no), I'm keeping track of you no matter how much you demand that I erase "your" information.
"I want to use your free service and to participate in your monetization model only after you explicitly tell me how you are going to do with my data. If you can't tell me this, and get me to accept the trade off, why should I trust you?" -- EU citizens"
So it's more like "if you can't do this according to the whims of my government regulators, I'll still be using your service, AND prepare for a large fine."
No one is asking.
Rather, the right question is whether the entity demanding (the EU government) has the right to do so on the basis that their jurisdiction extends to anywhere that a citizen of theirs can reach via the Internet. I argue no.
You probably disagree, which is fine, but this ultimately comes down to enforcement. And for now at least, I win on that front.
I think we’re perfectly fine with telling you we use your data for ML training, internal analytics or showing you relevant ads. That is standard stuff you consent to in a TOS.
If you can't easily delete or export my data, it means that you don't have a coherent, legible record of exactly how my data is being processed. You can't be sure if my data has been leaked or stolen. You can't guarantee that you'll be able to notify me in the event of a breach. You can't prove that my data was lawfully collected. I can't check the data you hold on me to ensure that it is accurate.
The GDPR is easy to comply with if your data protection policies and processes were decent to begin with. If you have read the text of the GDPR and can't see how you could bring your business into compliance, then you are almost certainly doing something seriously negligent or seriously shady.
What we can do, is set a little deleted flag on your profile to treat you as "deleted".
> ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
So not a database query itself, but the thing that drives the database query. It also extends to things like logs - aka don't keep a log full of SQL queries that are full of peoples personal information. Don't ship that log off to some third party, or make it available to random people.
For web apps it's mostly the storage and retrieval aspects that are important. Don't store too much PII. Don't allow anybody to access it at the DB level. Implement appropriate access restrictions at the web-app level.
It is perhaps a bit too abstract, but that's because it's covering a highly complex topic, but I don't think it's too vague on this: If it contains PII, protect it. Which, of course, you should be doing already.
For the longest time companies have been able to market something as 'free' when they have been the ones who have been trying to hide the fact that users' data was being sold, etc. So I would argue that if someone is 'stealing', it is actually the companies themselves.
The "stealing" is because they are trying to get companies to give their content out for free without paying the cost which requires targeted advertising (and no, generic ads pay shit which is why tons of companies are blocking all the EU because they now aren't worth the server costs).
You don't need to create a specific feature for European users if you don't want to, just as European users don't need to do business with you if you don't value their privacy. Economic exchanges are voluntary. If you think ignoring European customers is something that pays off for you, go for it.
If we would not care about privacy to a greater degree than other regions we would presumably not pass legislation that protects private information and cuts into ad-revenues.
After all, if someone exhibits a certain attitude towards their users' data that is a good indicator that there is more that isn't done properly.
It's funny that you think that it's totally ok to do this.
What's really being affected on the backend side of things is bulk data collection and storage and sharing with 3rd parties without consent.
If you're sick of people using your product and not giving anything in return, Charge. A. Fee.
The GDPR specifically forbids giving users the option of paying with data. (In that you can't deny access if the user doesn't agree to the data usage).
Charge. A. Fee.
It turns out that a whole lot of users don't want microtransactions for everything they do online, and would rather allow providers to monetize their data in exchange for access. You not liking those agreements is not a reasonable justification for forcibly banning them.
More than USA citizens with dubious DMCA takedown requests?
Both seem wrong, can we agree on that? DMCA is a disgusting weapon, as is a lot that the US has done. Does that make weapons created by Europe ok?
That's an excellent attitude to take towards your users.
Valuable, dear, beloved users for which the business has boundless sympathy, empathy, and compassion are now awkwardly the source of compliance concerns for which the costs outstrip the reasonably expected revenues enabled by compliance. While compassion is unlimited, it is possible the budgets and time may not be.
Better?
The GDPR is not about revenue but about privacy. It's not meant to be cost neutral. Bank robbers could also quote you to complain about the burden of anti-robbery laws.
However, is it possible that in a context where companies are weighing the cost of GDPR compliance against the benefits of GDPR compliance (i.e., keeping their EU business) some might come down on the side of jettisoning the EU business? They might even opt to do it by using a tool, like Cloudflare Workers, that they can convince to block everyone in the EU.
You would be absolutely, completely, 100% right to consider this fully in line with the intentions of GDPR. Protect privacy or GTFO, right?
With that said, it's possible that a fragmented market with fewer legal business models may not be as conducive an environment to all possible businesses. It's even possible that as a result, not all gaps will get filled.
Different legal models also provide grounds for experimentation. Who knows what works better in the long run? Wild West or regulation like GDPR? We don't know.
Which is to say that you could be right! Absolutely and completely! Or you could be really wrong. Time will tell. The economic history of protectionism could be read by some to provide some clues, though.