just blocking them doesn't seem like that bad of an idea, especially with the fines involved.
I think the things that bother me is:
1) A College student working on a side project with no revenue are treated the same as some massive multi-national.
2) It's a foreign requirement that feels like a violation of sovereignty. Most business/startup owners complain about there being too much domestic regulations, now we have to worry about things outside of our own countries -- that also can come into conflict with our domestic tax authorities on things like data retention. An international agreement would be entirely different.
3) The GDPR requires clear and concise language, but have done nothing of the sort when writing the regulations. For most websites outside of the EU, could they not have produced a concise 1-2 page infographic produced by the regulators themselves?
And why not? The result/harm is the same.
It doesn't matter a bit whether a company's web site is handing its visitors' data over to Facebook or a "private site" does.
The side project or the private site always have the option of not participating in the adtech frenzy.
But of course they want to participate (free money!), even if they find out much later that almost no money is coming their way.
These rules don't stop anything about ads, they just make them less targeted. Not a big deal, but it will increase the costs of serving users and thus decrease the total amount of commercial projects started.
Less targeted ads are exactly what we need. That's what the regulation aims for!
Your argument is like claiming that unfortunately, due to car dafety regulations, we cannot enjoy as many fatal accidents as we once did.
And to make my point of view clear: not all businesses deserve to exist. We as society decide which business models and behaviours are okay. "Decrease the total amount of commercial businesses started" cannot ever be a persuasive argument.
Nobody reasonable is arguing that it's a bad idea to let customers control their data. The actual issue is that the rules are vague and thus create a lot of confusion and waste that affects all companies, while not providing any real protection against the massive conglomerates that abuse data in the first place.
The #1 complaint about advertising is that in 2018, it has evolved into a shadowy, insecure brokerage of surveillance data that it obtains using all kinds of under-handed tactics. If the GDPR curbs this in the slightest, it will be a net positive for people of Europe.
They are playing games, and don't respect the requirements that the GDPR puts on "consent": focussed, freely given (non-punitive), fully informed.
Or maybe it's because the rules are confusing and messy and you have a different interpretation?
This a fallacy, not an argument. [1]
> Or maybe it's because the rules are confusing and messy and you have a different interpretation?
Please point out which rules are confusing and/or messy. Virtualy every single blog post about GDPR points out how it’s well written compared to other juridictions on the same subject. The language is clear and the website provides a Q/A section as well as concrete example for every point.
> Please point out which rules are confusing and/or messy.
The comment thread you just replied to -- the one where you seem to saying that random HN commenter is more accurate than Facebook's entire legal team on regulation that is supposed to be unequivocal -- is a start.
No, it does not.
Maybe your playacting is simply because you‘re „Currently working on Instinctive, a B2B marketing technology company.“?
You do not know my history, and sadly you didn't even bother to do some basic research or you would recognize that I'm one of the few in our industry that has called for regulation and data protections for years. [1] Instinctive has been on the forefront of this as well with our most recent push for net neutrality. [2]
And surprisingly you seem to miss that B2B marketing is rather unaffected by GDPR since everything we do has always been contextually targeted, consent-based, and 1st-party relationships anyway. If you want to have a discussion, base it on the ideas and not the person.
1. https://twitter.com/search?f=tweets&q=manigandham%20regulati...
2. https://www.newamerica.org/oti/press-releases/companies-urge...
--
As for Facebook breaking laws, I find that incredibly hard to believe given their resources, recent legal , 1st-party data and consumer connections in their walled garden, and the fact that consent is already given by billions of users who just want to use FB products and don't care about the rest. They have nothing to gain from skirting regulations that only serve to strength their relationship.
I have nothing against targeted ads. I am against targeting ads and collecting/distributing my data without my explicit consent. E.g. mobile companies selling my real time location because there's some obscure sentence in their 90 page terms of service.
I wish regulation like GDPR would also be implemented in US, but really unlikely.
I mostly like GDPR. Ability to opt-in and being of charge of your data, i.e. removing it from a service if you want to, and the right to export and move it to another service are great and long due.
What I don't like is that it's a principle based regulation and thus it can be applied arbitrarily and selectively.
The side effects would include:
1) Reduced number of services available to EU customers.
2) EU users will be trained to click "Agree" without reading, because web sites would ask them for permission very frequently, and users do not have time to read web site policies anyway.
That’s not a bad thing. If services that don’t want to protect their users’ privacy can’t operate, that’s a good thing.
> 2) EU users will be trained to click "Agree" without reading, because web sites would ask them for permission very frequently, and users do not have time to read web site policies anyway.
How does this have anything to do with GDPR?
Some value it until they hit XXXXXXXXX amount of extra cost. Some only value it until they hit XXXX amount of extra cost.
Most probably only value it as much as they're forced to.
From what I've read, opt-in is only supposed to be used when there's an actual voluntary choice, and "allow us to share your data with 3rd party trackers or we block you" doesn't count as a real choice.
It should be treated in the same way as opting into marketing emails. Totally optional. Not opting in shouldn't totally break a site.
Why not?
The greater the power imbalance, the less free the choice. Social networks are a great example of this. You can choose not to use a particular one, but what's the alternative if everyone is already on that platform? You can go without, but what if it's LinkedIn, and there can be a real impact on your career?
But you do have a choice. Don't use the site if you don't consent to its rules. Pretty straightforward choice.
It is, if you don't think the rest of what I wrote is worth any consideration.
Nobody is suggesting companies provide free services. We're saying that personal data is more than commodity, and we should be looking to more ethical business models. And we won't be sad to lose companies that can't adapt.
edit: And I don't think my point was silly, but I'm also not really libertarian. So I don't think it's acceptable for companies to abuse their dominant position to make things worse for society at large.
because everyone knows that it is better to not make no money at all, than just a slightly less than normal because your ads are not targeted.
> 2) EU users will be trained to click "Agree" without reading, because web sites would ask them for permission very frequently, and users do not have time to read web site policies anyway.
Sure, and it is their absolute right to do so, but other people finally have some control over their data, I especially like the fact that finally user can also remove/change the data about them.
Which is exactly what GDPR is designed to stop. You're welcome - the rest of the world.
is it though? According to https://en.wikipedia.org/wiki/Ease_of_doing_business_index#R...
USA is 3 positions behind Denmark which is in EU, and just one ahead of UK.
Sure, if you cater to users in your own country. If you cater (read: deal with data) to users from the EU, you should follow local consumer protection laws.
EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local companies were forced to respect privacy. Respecting privacy is just not very competitive/profitable at the moment.
Your viewpoint pushed to the extreme (sorry if you don't recognize your original view): China selling counterfeit goods or unsafe toys to the US, and feeling like any push-back is messing with their sovereignty of lax copyright -, trademark -, and health laws.
The old web was mostly static websites. We spoke of visitors. The new web is app-ified/interactive, walled off to logged-in agreement-abiding geolocated users, and even a single logged-out "visit" broadcasts this to 100s of trackers who will remember your every move online.
> The internet doesn't know political boundaries
Tell that to this US law the whole world has to comply with to called DMCA.
I assure you I have been against the DMCA since before it passed, though I don't think it's quite the same nor do two wrongs make a right.
I would suggest that you remove google analytics then. It only causes harm.
If a site has no US presence and blocks all users in the US, what negative repercussion can violating the DMCA incur? Maybe their domain can be siezed, but that can be avoided by not having a domain hosted in the US. The US could block all traffic to the site, but that should be moot if the site has no US users.
It's been this way for nearly 20 years.
I'm still failing to see how the original claim, that everyone has to abide by the DMCA, is true. This seems like claiming that everyone has to abide by Thailand's Lese Majeste laws (laws criminalizing insults to the monarchy). Yes people may face repercussion if they have an economic or physical presence in the country. But if they don't, then theres nothing Thailand can do to enforce this law .*
* not without cooperation with other countries at least. Some nearby countries are known to enforce Thailand's Lese Majeste laws abroad and extradite people. But in most countries, this isn't the case.
Again, if a country doesn't want to abide by the DMCA then they don't have to. Extradition treaties and the Pirate Bay do not disprove this claim.
But extraordinary retention is just the fancy word for CIA abduction. So no treaties are in place here.
As a small blog, no ISP is going to give you the time of day, so it's not PII because you have no avenue for converting it to a person. If you transmit that data (say to google analytics) it might /become/ PII because google (or any other person you transmit it to) may combine it with other data they have access to, to turn it into PII.
The reasons large organizations are fretting about IP addresses are thus:
a) They have IP/timestamp records going back years, maybe decades
b) They may have ISPs willing to talk to them about who had the IP address at a specific time
c) They can't confidently allow that data to pass to partners in case their partners have access to ISP records
d) That data is a ticking timebomb, because even if they don't have an agreement with an ISP now, if an ISP offers that service for free to all takers in the future, their trove of IP/timestamp pairs could suddenly become PII overnight through no action from them
So yeah, for businesses operating at a certain scale, IP/timestamp combos are now a toxic asset. That doesn't mean your log files for your blog are suddenly a GDPR violation, unless you share them with people or have an inside track with a local ISP.
You can read more here: https://www.whitecase.com/publications/alert/court-confirms-...
It doesn't have to.
If I have a brick and mortar business in the US and some one from the EU decides to do business, do I have to follow EU consumer protection laws? Unless I have an physical presence in the EU why should I have to follow their regulations?
Further, why cannot the EU just allow its citizens just do business with other extra-national companies if they choose to? Meaning, if an EU citizen chooses to do business with a non-GDPR compliant website, why does the EU care?
>EU laws have always been more strict than US privacy laws: This caused unfair competition, where US companies were free to export their privacy-damaging business model overseas, while local companies were forced to respect privacy. Respecting privacy is just not very competitive/profitable at the moment.
So what? If the EU wants to stifle competition, why should the US care. They are only hurting themselves.
You don't.
If they're not In The Union, and you're not In The Union, then you're not required to comply with the GDPR.
> Further, why cannot the EU just allow its citizens just do business with other extra-national companies if they choose to? Meaning, if an EU citizen chooses to do business with a non-GDPR compliant website, why does the EU care?
It's impossible to give consent for something if you don't fully understand the ramifications of what you're consenting to[1].
[1]: https://www.nytimes.com/2018/03/17/us/politics/cambridge-ana...
It must feel horrible, now that the US is on the receiving end of this for a change... ;)
Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR.
If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information into that.
The treatment of privacy is one of issues where it's pretty much impossible for individual protect from, GDPR tilts the scale in favor of individuals.
For normal operation system logging is pretty much a requirement for essential operation. That includes most properties of a connection like IP, UA, date, time, URI etc.
Do you disagree with this TLDR of the regulation?
https://www.smartsurvey.co.uk/articles/gdpr-compliant-with-d...
Without a bunch of work that hasn't been done I seriously doubt that they can give Right to Access, Right to be Forgotten, Data Portability, Privacy of Design and it does clearly state it is Personal Data.
It's called software cause it can be changed easily.
I can easily see small websites just ignoring GDPR and hoping they fly under the radar. Or, using something like this Cloudflare configuration to block all EU users until they reach a size where achieving GDPR compliance is feasible and worth the effort.
No, because that website doesn’t collect personal information.
> and build a system to get user consent, etc.
You need user consent to send emails or do something with their personal information (i.e. nothing since you don’t hold that information).
Yes it does. It a least records an email address and password to create profiles. And any features like tagging memes, marking memes as favorites, etc. could be argued to constitue personal data.
> You need user consent to send emails or do something with their personal information (i.e. nothing since you don’t hold that information).
Again, I specified a meme generator site that has at least some user specific personalization.
DPO is only needed in specific cases. Dank meme sites don't fit in any of: a) public authority b) monitoring subjects on large scale c) dealing with criminal conviction data.
> build a system to get user consent
It's called a checkbox. They likely use one to agree to TOS anyway. If you don't have that one, DMCA and COPA is what you should be worried about before GDPR. (If you're based on the US anyway)
However, nowhere does it actually specify what sort of scale constitutes "large". I don't see any user count threshholds or anything like that.
Also, it's possible that someone's list of authored memes is personal data. If somebody creates a lot of political memes then this could easily be covered by article 9, since political affiliation is explicitly covered there.
Additionally just saying "have a checkbox" isn't going to cut it. GDPR forbids blanket opt in or opt out schemes. You would have to build a system to track what the user has consented to and refactor all features to abide by each user's consent configuration.
I'm not saying every these tasks are hugely onerous - just that I can see the use case for blocking EU traffic to avoid having to abide by their regulations.
Themselves
> build a system to purge user data
SELECT * from users, memes, usermemes where userid = #####
You sign up for a website and upload and share a bunch of memes.... honestly... the shit isn't really your data anymore. It is the publics. You shared it and yanking it back is kind of a dick move.
It really isn't as "simple" as a DELETE statement that some people argue it is.
As for personal info, most meme websites don't require any accounts to create them, because it only makes the site less usable, but if the site do have accounts, you do have right to see/update your account, you have right to delete your account and be sure that if your account is deleted the data is actually gone.
Very generous assumption on your part. Article 9 specifically says that anything revealing personal info like ethnicity, political affiliation, etc. is covered by GDPR. If I look at a Adam's list of authored memes and there's a bunch of pro-Democrat memes and I look at Bob's and it's all pro-Republican memes, then it's very easy to see a court ruling that a memes reveal political affiliation.
This is my plan. What are they going to do, extradite me over claims that my access logs includes IP addresses? Claim that I do business in the EU when I don't take payments, every side project I've made is in English, and I've never set foot there?
If not, then worrying about GDPR which is mostly not enforceable in the US sounds disingenuous.
I'm guessing they also ignore those laws, because of posts like this one. If you're running a business complying with regulations, you likely already know how to block a country. I mean, you keep track of the current embargoes and block relevant countries, right?
How about you look at what bs comes out of the US gov't? That is the worst foreign requirement and violation of sovereignty so far, and it keeps on giving.
2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency worldwide, and argues in length for years whether wiretapping its citizens is OK, because everybody agrees wiretapping others is perfectly fine. USA forces poor half of the world to follow ridiculous copyright law, including software patents and art becoming public domain after a century or more. There's no good will earned there, so don't expect a free pass cause of your feelings. Want to serve customers from other countries - have to obey the law there.
3. they probably could. Still - I'm sure there will be "GDPR as a service" soon. Maybe some libraries, frameworks and standards how to handle personal data will finally be created? This should have been done decades ago.
The law is designed to cover pessimistic case. You can get sick because of food poisoning, you can be robbed because your identity was stolen.
I don't think my comparison was dishonest.
Nobody’s saying both are treated equally under the GDPR. The law stays the same, the way it’s enforced is adapted to the case, like any juridiction. Whatever the situation, you always get a warning before being fined.
When corporations like Equifax or Cambridge Analytica have engaged in identity theft to the tune of basically half the continent of North America, you want to repeal one of the few laws fighting against it with an argument about kids in dorm rooms? It's basically the tech equivalent of "won't somebody think of the children?"
Oops, seems you’ve forgotten about the “right to be forgotten”, and several other requirements. Better prepare yourself for those >$20 million fines — how dare you negligently handle personal data, college software engineering student!
I’m all for strengthening privacy protections and punishing bad actors in this domain, but designing strong regulations that don’t have seriously bad unintended consequences, is a really really difficult task. I’m not necessarily saying it shouldn’t be done; just that I don’t envy the jobs of those trying their best to do good for the world via regulations without accidentally destroying some really good things.
It may turn out that GDPR has few unintended negative consequences, or it may turn out the harmful side effects are far more severe than anyone predicted. Only time will tell, I suppose.
Personally, I wish there were a technical solution to privacy concerns — something akin to DRM, but applied to each individual’s personal data to prevent it from being used in unauthorized ways. That’s about the only kind of DRM I think I could really get excited about :)
Those kind of fines are simply not compatible with low quality advise like “Just add an opt-in checkbox, and you’re good to go for GDPR! What’s the big deal?”.
Overall, I like GDPR a lot (though as a disclaimer, I should say I haven’t read all ~80 pages yet).
Still, I am not as confident as many here that GDPR will have no serious unintended side effects.
Imagine for example if Google, Microsoft, Facebook, etc. all get hit with huge fines despite genuine best attempts by them to be compliant, after which they decide to cut their losses and exit the EU market entirely. Stock markets could crash globally, a new recession would occur, etc.
I very much doubt anything like that would happen, of course. But until things settle post-GDPR, I don’t think anyone can say for certain how this will economically affect the EU, and the world.
If the side project uses personal user data, then there is no reason to treat them differently.
EDIT: Example: https://ec.europa.eu/justice/smedataprotect/index_en.htm
I hear you, but the argument is that the data doesn't care who caused the leak. A college side project leaking an SSN does the same amount of damage as a multinational leaking an SSN, so the law is going to want them to treat them equally seriously.
This is by the way the same problem with the various restaurant analogies. It makes some sense for the health department to inspect large restaurants. It would make no sense for them to subject neighborhood cookouts to the same degree of scrutiny.
GDPR seems to be based not on actual harm that could occur based on invasive, sketchy or otherwise bad data storage practices; instead, it seems based on a subjective idea that people have "fundamental rights" to various forms of state-mediated protection in relation to technology. Rights are unequivocal and almost entirely uncompromising.
>
> 1) A College student working on a side project with no revenue are treated the same as some massive multi-national.
That's false. The GDPR repeatedly refers to evaluating the risk with regards to various decisions. The ICO even has separate guidance for small businesses and big businesses.
> 2) It's a foreign requirement that feels like a violation of sovereignty. Most business/startup owners complain about there being too much domestic regulations, now we have to worry about things outside of our own countries -- that also can come into conflict with our domestic tax authorities on things like data retention. An international agreement would be entirely different.
This one I can appreciate, but perhaps look at it from our point of view:
You're violating our laws that protect our citizens.
Why would we possibly have any sympathy for that?
> 3) The GDPR requires clear and concise language, but have done nothing of the sort when writing the regulations. For most websites outside of the EU, could they not have produced a concise 1-2 page infographic produced by the regulators themselves?
The GDPR is easier to read than many US laws, and you don't have to read it anyway. The ICO has written extremely high-quality guidance for most businesses which will suffice. It should take no more than a few hours to determine how your business would be affected.
No one forced your citizens to come to my website.
But when you want to trade with Europe, you have to abide by our standards for human rights.
I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication.
I've been talking to a very well known giant corporation (also based in US, but has many global offices) for months. The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. They are putting some draconian clauses, (various ISO certifications and such) in the contract that I, as a small company, cannot comply. That's their interpretation of GDPR. It doesn't matter whether it's right or wrong.
The VP and Director are really nice people and I've developed very good rapport with them. But I'm afraid their patience will run out soon and they'll go back to using spreadsheets. A lose-lose situation.
This is the side-effect of GDPR.
I'm all up for GDPR. I have uBlock, have blackholed all Facebook domains, etc. But don't assume that GDPR doesn't affect normal business transactions. Of course, blocking European users doesn't do anything for me since I want to do everything I can to protect user privacy.
But anyone who says, "Oh, how hard could it be?" has no idea what they are talking about.
And this law’s effects are all about the unintended consequences. Anyone thinking government regulators are reasonable and benevolent has never dealt with said regulators beyond any trivial level. To make it more fun each member country handles enforcement, so now you have a risk of 28 different interpretations of the law. It’s madness. Even if you do everything right there is still a compliance risk. It’s like HIPAA in the US — HIPAA is pretty “easy” to comply with, but the consequences are so severe that it necessarily drives up operational costs significantly. Unless Europe is a significant part of your revenue, better to block Europe and decrease your risk to near zero rather than have a potential risk of catastrophic, company-ending fines. Because the fine isn’t against profit, it’s against total, worldwide revenue. So unless your European profit exceeds 5% of your worldwide revenue, no sane person would take that risk. Even without the enforcement risk, you still have to deal with potentially hundreds or thousands of information requests — even if you are doing everything by the book.
This is possibly the strangest comment I've seen about this whole ordeal.
I understand it's frustrating on your side, because you have no control over the response of your customers. But understanding what GDPR is (and not falling for FUD) is why the VPs and Directors get paid the big bucks and get the fancy titles. If they can't or won't work with legal to become compliant, they should resign and let someone else do the job properly.
I'm not saying, "oh it's easy" -- it's not easy. But that doesn't make the law wrong either. And it's not OK to blame GDPR as being "bad", when those rules are mostly just putting some real enforcement around stuff all moral and ethical organizations should have already been doing anyway.
Your points don't "make the law right". In whose view? Right or wrong for whom? In his example he listed all the ways he is handling user data in a respectful way. And yet, he is still harmed by this law.
That the VP and President may be doing their jobs wrong (in your view) is no recourse for OP, he is harmed all the same.
And ... are they doing their jobs wrong? At the end of the day, they are limiting their risk. What threshold of risk of harm to their business and livelihoods would you feel is an acceptable tradeoff to comply?
There are many real world effects of GDPR and we are just starting to see the pros/cons of it.
Please tell me I've read something wrong. Otherwise, this is just panic induced stupidity. I expect they will grow out of it (though maybe not before you go bankrupt, which obviously sucks big time).
The GDPR regulates both Data Controllers, and Data Processors
Suppose I'm excited to hear about Hats.example, a site that sells hats. I visit, but they don't have any hats for my ostrich. Damn. But, they do have a box where I can leave my email address "to be contacted about future products". Great, maybe they'll introduce Ostrich hats. I fill out the box.
Hats.example uses famous email deliverability company WeSpamPeople.example to ensure their marketing emails have "industry best in class reach". I soon get an email every week featuring different styles of hat, but they're all for people, disappointing.
But then, WeSpamPeople's VC runs thin, and they cut a deal with OutrightFraudAndScams.example, which tricks people into making dubious "investments" and wants a lot of "leads". Now as well as the hats newsletters I asked for but don't really care about, I'm getting stuff inviting me to invest in Venezuelan Bitcoin mining and a project to make "Green cyber-organic goats for the blockchain". Ouch.
Hats.example are a Data Controller. The GDPR says they are responsible for looking after the data that I gave to them, even if "technically" that form I filled out is a Javascript frame injected by WeSpamPeople.example, it's part of the Hats.example business, so it's their responsibility to ensure my email is not abused by a processor like WeSpamPeople.example, for example through contractual terms requiring WeSpamPeople.example to delete my email, never to send it elsewhere, etcetera.
WeSpamPeople.example are a Data Processor because they were given my email address and other details to send me "marketing" information. They have a duty under the GDPR to get reasonable assurance that this was OK with me, for example maybe Hats.example did some paperwork that promised they're legitimate and they got sign-off for these email addresses. Regardless of whether they were given terms requiring them to do so by the Data Controller, the GDPR says they have to take care not to abuse the data, for example they can't sell it to anybody, since they obviously don't have permission to do that.
OutrightFraudAndScams.example are also a Data Processor, and maybe also a Data Controller they know they didn't have permission to touch this data, but presumably they also routinely violate all sorts of other anti-fraud or anti-scam laws. Maybe the GDPR will help add to the fines and charges and put them out of business.
[Edited: minor typos / fixes]
Just so it's clear, you're positing that when WeSpamPeople breaks every existing contract they have, that those on the other side of said contracts are now liable?
Of course it could happen, but I don't see the EU fining those on the other side of the contract as long as they moved to another DP and alerted their users when the breach of contract was discovered. Both actions should happen regardless of GDPR.
TBH, email is a bad example anyway because good providers are already pretty quick to boot bad actors so they don’t end up on blacklists.
Yes.
It's not unreasonable, because GDPR has components that require vendor assurance (more or less). So the megacorp with a point-of-presence in the EU has to be cautious about what strictly-US SaaS services it uses if there's any potential for data crossing into the SaaS.
This is almost certainly exactly what GDPR is intended to do. It aims, in part, to make sure companies can't shirk their responsibilities by handing everything over to vendors who will ignore GDPR.
An actual compliance audit from an accredited auditor, paid for by the SaaS offering of course, is not going to be cheap or easy.
And the GDPR is the side-effect of people running hog-wild with PII etc. I feel for you but I see your situation as collateral damage of the privacy crisis.
As a dev though, I also understand the frustration. Creating startups is already time-intensive and stressful. A lot of us are on shoestring budgets. Most startups will fail. To a solo developer in the US, the idea of spending time understanding and complying with GDPR is daunting, it's more than just a hindrance to many. Still, I don't want to break European law, so maybe it's easier to block EU users at first and change policies later if profitable.
I think blocking is at least showing you respect the law, compared to just doing nothing and being non compliant.
"Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.
I think assuming the EU won't care about tiny startups is irrelevant - I want to follow the letter of the law, it's why I'd opt to block EU users instead of just ignoring the existence of the law.
Hence, the blocking of the EU - its better to block at the beginning and then expand to the EU once we have revenue to support someone handling this as an employee.
You know this is not what would happen, right, that you'd be given advice and the opportunity to towards an amicable resolution?
I know nothing about European legal systems though
And as a member of a EU country that for the last year has been constantly bending (when not breaking) the rules to repress and attack legitimate political reivindications, the relativism in the application of GDPR is something that I find very worrying.
Uber versus Night School is an example of this. Uber: Ignore taxi regulations, get tons of VC, get rich while being awful people. Night School: try to work with government and play by the rules, fail, get used as a cautionary tale.
Source: https://psmag.com/economics/night-school-failed-because-it-f...
I think something akin to GDPR is necessary and good, but GDPR as written probably isn't it. I look forward to seeing how it works out in practice, and how it develops/is replaced, and in the meantime feel bad for the developers and customers that suffer through the unintended consequences and misfeatures of it.
After the law gets clarified some, I think you're right that it won't be bad for small players. But I wouldn't want to be one of the test cases.
Calling the data protection agencies "government" may be correct in some very legalistic sense, but is utterly wrong under any colloquial meaning of the word.
You don't know this.
How many $300kEUR fines (the maximum in Germany until yesterday) served by a German DPA (we have 17: one federal, one per state) have you heard about in the last 5 years?
From April 2015 to March 2017 there were 124 proceedings, with 47 leading to fines.
The aggregate sum of all those 47 fines was... 174.226 Euros.
[1] http://www.dw.com/en/germany-fines-man-208000-for-stealing-c... [2] https://www.thelocal.de/20170405/germany-to-fine-social-medi...
The second one is a law very much like GDPR (notice the little words "up to"?). Not a single fine has been given based on that, not even a small one.
GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, including for malicious reasons like taking out a competitor, and political reasons like a eurocrat taking a disliking to a particular company.
Most large banks and insurance companies are listed.
We had two major expenses: liability insurance for meetings and SOX insurance for the officers. Everything else was in the noise.
I've been involved in GDPR efforts at work and all the policies seem fairly straight forward to me. If you're not doing shady shit and you're upfront with your users what you are collecting the data for, how long you keep it and what access policies you have set up.
Not a problem if you ask me.
Enforcement guidelines are ill-defined, and the definition relies on vague terms. For example, is retaining an IP critical to running your business? What if you're getting DDos'd? Now it is up to someone else to make that distinction, and you're dependent on them "being reasonable."
You can even self-report if you're not sure you handled the privacy well, and they will point you the stuff you have to work on (and give you month to do that).
I Understand Americans are afraid of fine and lawsuits, but please don't be afraid. Read GDPR statement from regulatory instances, they are here to help business too.
I think GDPR is short-sighted from a game theory perspective and will short-change European citizens.
When I sold software online, Europe was < 5% of my sales. Why take on business-ending liability risk for that amount of sales? Sure, maybe I'd do these things anyway, but once you open that pandora's box, you're relying on favorable interpretation and the goodwill of regulators.
Having seen what happened in the US with civil asset forfeiture, well-meaning laws can have their purpose bent, and goodwill can be perverted. Why take on that exposure?
Why would you hand of the data of your customers to someone that won't/can't prove to you that they will be in compliance with the current legal requirements?
Honestly that is the entire point of the GDPR, don't misuse customer data and don't hand it over to 3rd. parties unless the customer allows you to.
Good. Outsourcing violations, ethical or legal, shouldn't get you off the hook for them.
Besides which, what are you doing handing off stuff that's important to your business without knowing what's being done with it? Not a recipe for success. And if it's not important, then...
Are you just making this stuff up, or has this actually happened?
You didn't (as hundreds of others), so now the EU forces you to. So now you have an opportunity to become a better company: https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...
You're working in the real world, with real consequences if you end up exposing people's personal data. The party is ending. Either deal with it, or find something else to do.
They are dealing with it... by limiting their liability.
As far as I can tell, the "user" doesn't have a whole lot of choice there and Facebook isn't the only company doing that kind of aggregated data collection.
I see them as a very poor example of good things coming out of Silicon Valley...
But Silicon Valley isn't a monolith where everybody is on the same page about everything, I have no doubt there's plenty of people in SC who consider FB a success-model to be followed into a shining future.
If “fighting over coconuts” is not on their list of things they wish to do, it’s not a completely absurd choice.
These are things I can put off until later, I don't need them to validate my startup concept. If the startup is successful, it might make sense to expand the market.
Plus, blatently ignoring regulation is cheaper in the short term, and if you successfully leverage that advantage into revenue than you can start throwing money at the problem once the regulators finally do get around to prosecuting you.
Worked for Uber.
I do agree with your overall point though.
The thing about GDPR that I disagree with is how it aims to have global jurisdiction. If it was a US law (as a US-based developer), perhaps I'd protest it, but I'd still follow it if I wanted to work in software.
So if you "sell" to EU residents, follow EU's rules.
Surely this will just result in the development of the reseller model?
As long as the reseller doesn't collect data, they're protected and as long as the US company doesn't maintain a presence or ideally market to the EU, they're untouchable due to the lack of any EU-US enforcement agreement for the GDPR.
The Poland proposal [1] to limit GDPR compliance to only large businesses was trying to address that. But it's flawed, because a small company (Cambridge Analytics) could still make a lot of damage to users' privacy... but the intent of Poland was good.
I feel there should be an opt-out based on the numbers of users and the age of the company/service: If you can easily prove that you're not handling more than X users and your company is less than 2 years old, then GDPR does not apply yet, as long as you warn clearly on your website that you're not-yet-falling-under-GDPR. If you're still in the GDPR-waiver zone but believe to be GDPR compliant, then you can remove the warning and are subject to GDPR like every other company.
That way entrepreneurs won't be scared to try some MVP here and there. I'm especially thinking of those trying to start a startup in countries that are part of the E.U.. The rest of the world entrepreneurs can just focus on their local userbase.
[1] https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
"We are a startup on a shoestring budget, we can't put safety belts in our cars!!!"
The cost of being in the car business is to build safe cars. The cost of being in the webservice business is to protect userdata.
If you can't, you are not good enough to be allowed on the market.
If you disagree, should the US also stop prosecuting VW for the diesel cheating?
Great point about VW btw, I forgot about that !
The safest car is one that can't drive, and the most privacy-friendly software will fail to compile. You should be able to build a functional car before you need to worry about making it as safe as possible, and similarly you should be able to build a functional MVP of your software before you need to worry about compliance with a huge international policy.
Before you are permitted to use your DIY car you need to comply with safety regulations to avoid harming others. You can keep your unsafe car off the street in your garage, though. Same for software that is not compliant; you just don't get to call it a "product" and let it loose on the public.
you can drive your unsafe car on the track, and your negligent mvp on your customers own hardware as in-house software.
A one person entrepreneur might not consider him/herself to be "being in the webservice business". Instead he/she would consider being in the business of [whatever problem the MVP is trying to solve]. It just hapens that in the 21st century, most of innovation happens online.
Back to your car analogy, it seems that people on one side argue that all companies "being in the webservice business" are 'car makers'. some people on the other side of the argument might say it's not.
Also, ultimately, it's possible that after spending a lot of time and hours examining the legal requirements of GDPR, a startup realizes it's not technically hard to comply, but the issue here isn't implementing the requirements, it's more about getting all the legal analysis, certification, handling customers requests, etc.
> If you disagree, should the US also stop prosecuting VW for the diesel cheating?
In that case, VW has clearly been in the car business for much more than 2 years, and in my example "X users", a good value for X would be something order of magnitudes less than the number of VW customers around the globe. So no, the US would continue prosecuting VW.
It's that the equivalent of starting a new car company and arguing that you shouldn't be required to follow the same safety standard as Volkswagen Group, because you're still a small company?
At it's core the GDPR is simply stating that you're accountable for the data you collect and that you're only allowed to use the data for the purpose is originally collect. Building privacy into your product is much easier for someone designing something from scratch, compared to retrofitting it into the business plans of Facebook and Google.
I get the feeling that most of the people arguing against the GDPR are people who are focused solely in collecting user data as a core business. The people I know who are building actual product, where people pay for a service, are doing fine. Even though that they have to build products in a manner I suggested five years ago, where user data is either not collected or delete when processing is completed.
If your business is based around exploiting user data however it might be a lot harder, but then that's the point of GDPR, to prevent people exploiting user data.
GDPR exists because it turns out we can't trust companies to handle personal data with the care it deserves, and I don't see why any company should be excused that proper care.
It will also do just about nothing in regards to the major companies that everyone had such a big privacy issue with in the first place, so not only is the regulation vague but it's also ultimately very ineffective.
They tried hard rules, rather than principles with the cookie laws and the companies around the world turned a good idea into a shit-show of popups while continuing to behave like nothing happened.
Honestly the more I read and the more I see how different business react I start to view the GDPR as EU finally showing that will not accept businesses viewing it as a second rate legislator.
The GDPR and reactions to Trumps policies an EU that is finally starting to behave like it's representing the best interest of 500 million people.
I mean, if companies cared about privacy in the first place, there probably wouldn't be the need for such a regulation. At the very least, GDPR will get the general population be conscious about what the hell is going on under most websites.
We've also lost customers (including a contract that would have been our second-biggest) because our competitor is either lying or doesn't know anything about the GDPR, and has convinced customers they're compliant. Their story sounds easier than ours; "We're in the EU, so we're compliant" as opposed to "Hey, you need to sign this DPA with us to be compliant."
And no, many companies already did care about privacy. Companies are not faceless villains -- they're made up of people like you, assuming you have a job, and even aside from not wanting the bad publicity of breach or misuse most people want to use data correctly.
I think a lot of that is down to decisions taken by US-based management that is simply clueless about how law works outside the US. And probably also only got their information from US-based lawyers that were either as clueless as themselves, or had incentives to make everything look very complicated.
On the other hand, most of the companies around me that have no links with the US were not particularily worried, and either consider that they are already compliant, conducted minimal work to be acting in good faith, or at worst are waiting for the regulatory body (CNIL here) to tell them what they are doing wrong, if that is the case.
However, I don't know any company that does shady things with their users' data, and things might be very different for those.
Right now there are billions of people around the world clicking "yes" on all the privacy and consent popups while grumbling about the annoying notices and just wanting to get back to what they were doing. Meanwhile there are also plenty of people creating havoc by filing lawsuits against every company they can, adding up to billions demanded on just the first day.
No, the EU is not the US, no lawsuits have been filed. Some individuals have reported some companies to their local data protection agencies, just like the GDPR says you should. No money has been "added up to billions", because the DPAs don't sue for damages, the levy fines to ensure compliance.
Huge difference. If you're going to critique the GDPR, please understand how the legal and regulatory systems of Europe work first.
This law has been in application since 1978 [1]. And in 2018, we have adtech companies like Criteo. [2] I have one of my best friend who started his adtech startup in France. Everything is good.
There's is a lot of implicit contracts (you filled up our sign up form? Well, then you chose to give us your data. ...) The only things you have to do: know which data you collect and give the ability to people to update/delete their data. That's all.
I don't understand the fear. I don't understand what is "vague" about it. It's so simple and low barrier that Microsoft decided to make it the rule for all of their users. But thanks to the hysteria, they made a PR stunt out of it.
--
[1] https://en.wikipedia.org/w/index.php?title=Data_ownership&ol...
The difference is that France is insignificant in the adtech market. The real money is in the US and spread out across Europe, with Asia soon to overtake. The existing rules you point to weren't affecting global operations where Criteo and others made their money.
It's strange that you think the business models are going to fly in Asia. China and many Asian countries are laying out privacy regimes that are even more strict than the GDPR. Take a look at China [1] or Thailand [2]. Pretty soon it will be the case only in America that adtech companies can collect and sell endless personal information without consequence.
[2] https://www.bangkokpost.com/business/news/1455534/new-data-l...
Ok, spend all your time going after the ad company and ignore the government which is 1000x worse and will control your life or toss you in a cell. Good luck with that.
The laws are not stricter (they arent even laws yet), and they are meaningless in those areas because the government itself already defies them.
That doesn't make laws meaningless.
But China grants legal exemptions without especially good or consistent oversight over those countries. The net result is an awful lot of folks who get a legal exemption for a specific aspect of their business and then tend to run roughshod in other less scrutinized areas.
How is this different from any other western government?
Now if you're taking about security contractors, that's different and the same the whole world over I guess.
Second... I don't see how valuation matters. Did they loose money? Went out of business? No. VW lost valuation during the whole diesel gate scandal. Did that make VW a less relevant? No.
And the last thing that I wanted to mention: I said "this is just an implementation of an old French law into the European Level". And I was mentioning the French law itself, not the European Law.
The cookie issue that you're mentioning is related to the ePrivacy directive, which is solely European Law, that was passed one or two years before the whole lost of valuation. My point was just that the GDPR doesn't affect anybody.
Do you know that they are a publicly traded company? Losing money is exactly what happens when the stock price falls. When you lose more than half of your value, going out of business is a serious risk.
It only affects the ability to make more money by issuing new shares.
But the "bank account" of the company doesn't get divided by two. Customers don't start paying only half the price for their service.
Given the EU assertion of global jurisdiction, the GDPR seems like a bit of a trade war and it's surprising more commentators aren't treating it as such.
The US should be inspired by this and give online retailers the opportunity to collect and remit sales taxes.
Sincerely hoping that this marks the end of the data gold rush
I'm sorry the analogy is totally flawed. On one hand you have something consumable: food, on the other side that can be made eternal: data.
When making an application that collect data, you just have to make a form/button to give the ability to update/delete data. It's no more different that when you make an adult website, you have to make a page "Are you above 18?"
Sometimes, it sounds to me that people on HN don't have a problem with the law X or Y. They rather have a problem with the concept of regulation in general. (See the comments on all the posts about Germany requiring Uber drivers to have a car insurance with a higher liability.)
But if you want to give an analogy to normal business, a more suitable one would be: "Giving people the option to delete their data is a bit like allowing customers to get their money back on their gift card they purchased 2 years ago"
How is that unfair?
You're not understanding the analogy. What does a user get out of using Google's services? They get access to a suite of products (search, email, cloud storage, online productivity apps, videos, and so on) that are maintained by a rather expensive group of employees and run on a rather expensive collection of hardware. When you use those services you pay for them by letting Google collect information about your use of those services. The value you get from those services is often intangible (you watched a cat video or looked through a photo gallery of your sister's new kid), though sometimes monetary (you don't have to pay an ISP for an email address if you use gmail.) When you choose to no longer use the services and demand that Google delete all the data they have gathered are you going to return that intangible value and pay them for the money you saved by using their systems? How would you do return the experience of watching a stupid cat video? It's exactly like eating a meal but insisting the restaurant give up the value, i.e. the money, that they got from you.
But still, the analogy is flawed then. If I give the restaurant money, the way the use they money afterwards doesn't affect me. They cannot take more money from my bank account or from my pocket. The only thing they can do is invest it and make more money, but it does not affect me.
When I give my data, the way they use my data – after I've "eaten there" – can affect my life. They can send me spam, they can put me into database of "people with suspicious behavior", ...
The law is more about giving a second chance: I could have given information in the past, and you could have sent me commercial emails in the past. But now I've realized I've made a mistake and I don't want you do that anymore.
If you want an analogy to real life: it's more about giving 5 years of jail to a burglar. They committed a mistake, so they have to pay for it, but they should have the right to get out after having paid, and live a normal honest life.
How is that unfair?
Google generates money not by collecting data but by showing targeted ads (they need personal information to do good job at targeting).
They actually do provide option to opt out, remove information about you but they make a quite a hassle to opt out and block features that could otherwise work, to encourage you to opt back in. For example you don't agree for Google to your location history? Fine, you don't have location history in Google Maps even for places you searched 5 seconds ago.
Anyway, to turn things around, yes they provide you services for free, and you're paying for using them by have targeted ads, if you decide to not use those services anymore you can't get an offline version of their tools that doesn't phone home, so why should they be allowed to keep your data in perpetuity?
The fair result of a person choosing to stop using a company's service is that they get to stop paying for that service, i.e. Google doesn't get to collect data about your current and future activities.
People truly underestimate how much information about them is actually worth.
There are also extra procedures you have to follow that could be really complicated depending on the business. This is even worse for small businesses. I can definitely understand those people who want to just wash their hands of it, especially if they don't get much business from Europe.
As I said other comments, I'm not sure if people on HN have a problem with the GDPR, or just with the concept of regulation itself.
Also, when I read about "complicated rules for small businesses". It reminds me about American republican politicians explaining how taxes on the rich will affect the average joe's taxes.
The reality is that many rules only apply to big businesses. And small businesses are exempt of many rules. My favorite one is the "Data Protection Officer", everybody on the internet™ says that you need one. The reality? Most small business won't. The article 37 explains that the Data Protection Officer is when a business is "collecting data on a large scale" [1] Second of all, people interpret that as "Hiring somebody", you don't. It's just a role, take your CEO, and now he's your "Data Protection Officer", ...
--
Perhaps in early stage of a startup a founder will take the title to save cost, but he/she will want to lose that responsibility as soon as possible.
Congratulations, you're uncompliant. Thanks for playing "GDPR is easy".
> (5) The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
Expert knowledge just mean that he/she read the entire directive. The same way that most employer in europe have read their country's labor law.
The reason why they say that is because the "Data Protection Officer" is the person liable for GPDR violation. The same way the CEO is liable for many wrong doing a company could do. They require no certification, no degree for a person to be a "Data Protection Officer."
Just having read the GDPR doesn't count for "expert knowledge", it's just knowledge. "Expert" is something more. How much more? Funny you should ask, welcome to GDPR limbo.
Also, it doesn't say expert knowledge merely of GDPR, it says expert knowledge of "data protection law", vague and unbounded, certainly not limited to the GDPR. GDPR is probably the most restrictive you have to comply with, but the text literally requires you to have to have expert knowledge of the others, too. Finally, there's the little "and practices". It's not enough to read it, you have to be an expert in how data protection law is used in practice.
Before you have processed even a single byte of data, you're literally uncompliant simply by being blasé about how you name your DPO. It seems unlikely that anyone will get busted simply for this, but low likelihood of enforcement is not the same as compliance, and why would they include this paragraph if they didn't feel it was important? People who actually care about being compliant need to think about this.
The irony here is that American users are so used to being endlessly surveiled without consequence that they are genuinely shocked that the rest of the world refuses to put up with this bullshit. This is completely normal to them.
The GDPR is just another step in a global fight by people all over the world to regain their data sovereignty and protect themselves from endless surveillance. The momentum at the international level is very clearly for data sovereignty. Russia and many Asian countries are following closely behind. And while everybody was freaking out about the GDPR nobody seemed to notice that China passed even stricter online privacy laws [1] earlier this month. Singapore [3] and Malaysia [4] are up to speed and even Thailand [2] will likely soon require minimum standards. (Edited to add more links.)
The end result is like so many other things: American companies will end up blocking everybody but American users who they know they can exploit without consequence. American users will celebrate their exploitation as freedom from Big Government. Everybody else will move on and just shake their heads.
[1] https://www.csis.org/analysis/new-china-data-privacy-standar...
[2] https://www.bangkokpost.com/business/news/1455534/new-data-l...
[3] https://www.pdpc.gov.sg/Legislation-and-Guidelines/Personal-...
Also it's hilarious to claim China has better privacy when that government tracks everyone using facial regulation with real-time threat scoring and national social rankings called a "citizen score". A late payment on a single bill gets your face and contact info on a giant billboard so go ahead and try complaining about your data over there and see how far that goes.
Get this: not everybody is consumed by paranoid fantasies concerning their government. And while your shallow understanding of China based off a few western-oriented articles here and there may validate your own biases do understand they have no real relation to reality. In reality, there are no extraordinary consequences for missing a single bill. On the other hand if you're sued in court over a debt the judge -- not unlike American judges (!) -- can use public humiliation to try to modify your behavior.
And sure, China has nothing to worry about other than this: https://en.wikipedia.org/wiki/Social_Credit_System
>>> People have already faced various punishments for violating social protocols. The system has been used to already block nine million people with "low scores" from purchasing domestic flights. While still in the preliminary stages the system has been used to ban people and their children from certain schools, prevent low scorers from renting hotels, using credit cards, and black list individuals from being able to procure employment. The system has also been used to rate individuals for their internet habits (too much online gaming reduces ones score for example), personal shopping habits, and a variety of other personal and wholly innocuous acts that have no impact on the wider community.
Also tell these people it was just a big joke: http://www.scmp.com/news/china/society/article/2144690/chine...
>>> Authorities vowed to collect the personal information of debtors and publish it in public places such as newspapers, train stations and other high-visibility platforms. The Supreme People’s Court reported in January that by the end of 2017 it had publicly listed the names of nearly 10 million people. They had been blacklisted from various activities, with 9.36 million of them prohibited from buying plane tickets and 3.67 million from buying high-speed rail tickets.
I see this "not clear" repeated here. Can you cite a section that you find not clear, so we understand what you mean?
So n = 8000 makes a sand pile.
If folks find ambiguity in the GDPR, do NOT get into American Fintech. Here's a great question: what are the technical requirements mandated by the US government to become a bank?
It is a blocker that slows down your efforts to work on the next feature. It is not hacker friendly. It is a huge pain in the ass.
Edit: btw, I don’t really blame the EU. Google and Facebook got us into this mess.
AIUI that's one of the main changes, that explicit consent is now needed to retain data and specific details of how it will be secured, who it might be passed to, must be given. Also that if the service being offered doesn't need the data, that the company offering the service can't insist on having it.
It is a big thing for micro-businesses and SMEs in the UK - despite having data protection laws already - it does change the complexion of how one handles PII and the embedded assumptions. We're talking about businesses many of whom have paper bookings diaries - the diary apparently needs to now be secured, whilst it's always sat on the counter before; that's a costly structural/workflow change (unlock the diary for every phone call!).
What is poorly written about it?
> there must be clear paths to implementation and verification.
There are.
>Perhaps that should've been fixed instead of wondering why so many companies don't really want to deal with it.
There's nothing to fix, and I'm going to assume you can't even name 3 things since your post is just an extremely vague talking point.
There are examples of regulation that does work, but GDPR is not really in that category.
I haven't seen many grey areas or difficult corner cases in the discussions here, so far.
Only people claiming that everything is unclear, because they don't want to accept the truth: that they clearly fall under the GDPR.
...Ok, because you say so? Are you a lawyer? Do you realize that this whole discussion exists precisely because it's unclear?
There are already billions in lawsuits against facebook, google and others so companies are rightfully being careful. And even if you fall under GDPR, there is plenty of vagueness about the data and processes itself. This is not as simple as you make it out to be.
I realize that this statement is untrue.
Some people are dredging up all kinds of "but what if" and "I really, truly don't understand how my collecting data could be considered GDPR-triggering".
I find that dishonest. Protest as much as you want.
Oh, and surprisingly, just by some bizarre happenstance, you are "Currently working on Instinctive, a B2B marketing technology company."
I can tell you immediately that whatever you're doing falls under the GDPR.
Cool, except we weren't confused about that. Figuring out what data exactly and when, along with the proper processes, documentation, and interaction with all of our clients took lots of lawyer time though.
> I would be very wary of a company who claims this legislation is onerous. It is potentially life threatening to companies who do very shady things without your consent. That much is true. That is the entire point.
I somewhat suspect those companies hiding behind the 'oh lets just block Europe' excuse just don't want to admit the extent of what they are doing with the data.
US citizens should take note of this, because it's their data too.
[1] https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...
EU citizens should not be pissed off that second-order effects exist in the world. If they are, they need to take ECN 101/102 again and pay closer attention.
If the cops showed up at your door asking to search your home, business, and Internet accounts without a warrant, would you let them? Why not? What are you hiding?
Thing is? We changed almost nothing about the way we processed data. Data subjects are no better off because we've spent tens of thousands of dollars complying. Whether people comply or not, the fact of the matter is that this regulation is onerous. It's onerous even if you love the intent of it, and it's onerous even if you think it's worth it.
Blocking Europeans sounds a lot more reasonable than having to hire a lawyer and spend double the time and effort just to be compliant while writing a new JavaScript MVC Todo List app.
The people (by and large government is run by the people, for the people, at least in some countries) have had enough. I've had enough, and this is us telling companies they've had their chance and not made the grade so we're dictating now. As a person, and father (who has to worry for the rest of my live about my offspring's health and happiness, and linked to that, privacy) I'm very happy with this law. I support it, as seemingly a lot of people do. That's not authoritarian, it's the will of the people.
And no, I'm not some sort of communist beard stroker, I'm pretty central in my political beliefs and I also don't appreciate governments sticking their noses in where it's not welcome, but this, this is welcome.
I have a site that I did this with. I also wish the US would pass a law like this. And I beg to differ. No, I don't believe this is self-contradictory.
The issue is risk. I'm a one-man band - the site in question does make money most of the time, but not much, and it has always been much more of a hobby/labor of love than a business[1]. And when any legal change means I might end up with legal grief or potentially not be visit European relatives again, even if I generally approve of the change, I'm going to knife it because there is no planet on which the site means more to me than the risk.
My plan right now is to let the big boys who can afford it take the initial lawsuits and let them shake out what the vagaries mean, then come back in a year or so and see what my exposure would be if I let ya'll back in.
[1] Oh, and it should already be complaint, at least as I understand 'compliant'; I added notices and rejiggered a few things for selective denial and whatnot. I never have and never will sell/rent/share user data, don't integrate with any surveillance/ad networks, etc. But I have no confidence that someone won't see me as a likely target to use to make some point, and hiring a legal consultant for something this size would take it from slightly profitable to a future break-even measured in many years.
Much like China, which has managed to develop a huge internet industry because it doesn't have to compete with the American competitors, the EU's huge market will provide a lot of space for EU startups if the American competitors refuse to do business in Europe. But unlike China, the GDPR will make those European companies more competitive on the world scene rather than less.
If the choice was between 2 services, one of which complied with GDPR and one which didn't, and explicitly excluded GDPR protected users, I'd assume the vast majority of regular consumers, but definitely businesses, would pick the GDPR compliant one.
In my limited view, this is pretty much the case. When I was telling our management team about the GDPR and how it relates to our new European-focused project, the first thing the CEO said was "how do we get around this?"
Management decided we're not gonna comply with the GDPR and just hope nobody notices.
Which in the longer term turned out to be right. I'd love to see Winterkorn behind bars for that one.
Although they don't say it that way, that seems to be what most GDPR advocates are implicitly advising. They keep saying not to panic and shut down your web site or block europeans because and the EU is not going to sue you as a first step, etc etc.
What used to be a full opt-in to the content and business model of a site, the EU wants to only get the content and choose whether or not they want to support a sites business model. You cannot have your cake and eat it too. If you want the sites content, then you should also agree to their business model to actually support it.
Unsurprisingly, now that you cannot tie a sites value with their business model, many companies are choosing to leave the EU as they assume most people don't want to pay for the content they consume (in addition to other things).
I don't know about you, but I have learned a great deal!
I've mostly learned that Eurocrats can't actually write useful regulation. Blah blah blah human rights blah blah reasonable measures. Next chapter. Blah blah envisage blah blah reasonable measures. Blah blah blah inter-government communications protocols blah blah codes of conduct.
What's a reasonable measure? How do I know if I'm compliant? How do I know if a vendor is compliant?
GDPR is a wonderful, incredible, essential document for laying out human rights for the digital world. It's also terrible and incomprehensible regulation.
I mostly agree that the lack of concrete measures makes it horrible from a compliance view, but I'm not sure you can have both things, especially in a relatively immature area of law.
I would have been happier if they'd done something around setting up an administrative body that authors and updated regs.
Did they ask for explicit permission to use your data? Do they provide the service if you only provide the data they actually need, rather than asking for a swathe of PII so they can sell it on? Do they provide info on how your data is stored, and who has access to it? Do they provide a way for you to view and/or delete all the PII they have on you?
Do they take reasonable measures to detect and inform me of a breach? Do they take reasonable measures to ensure it's me requesting data being deleted? Can they provide the same data about all Data Processors they make use of?
It's possible that the answers to this might not be easily and readily answered in every single potential case one might encounter when dealing with specialist vendors.
You're completely right to spell out those questions. It's just possible that there may be more to GDPR compliance - and certainty - than that in some cases.
When you're in "move fast and break things" mode, getting stuff working for SOME users is better than having a complete solution for all users that come much later. It's not even just about ignoring Europeans. A lot of these products and software solutions start "only available in California", or hell, only in SF. That's even true for some stuff from big companies like Amazon.
Then as you grow, you can start tackling more barriers and regulations from other countries. I mean, there's plenty of companies that won't ship to my address because they don't do business with the US. Or when I lived in Quebec, I could not participate to a lot of contests because it wasn't worth it for these entities to deal with Quebec's gambling laws. That's ok.
Even if you agree with the general idea of GDPR, even if you want to implement the tightest privacy rules you can't in your software, there's more to it than that. I've watched lawyers duke it out over some of the details. My employer takes GDPR very seriously and we've done everything in our power to comply, not just with the letter, but also with the spirit of the law. But we're big, we have money, and we're actively trying to grow internationally. 10+ years ago when the company was barely afloat? I'm not sure they would have been able to deal with the fine prints even if they wanted to.
There's more to GDPR than sending a silly email and adding a "Delete all the things!" button.
As for SV seeing GDPR as more of a hindrance: SV was build on the freemium model of gathering as much data as possible. Companies were funded under the assumption that their user growth would lead to valuable data stores.
GDPR and an increased privacy aware public are existential threats to these companies, as there is little chance to pivot to a non-data-use company. You have to start over.
I hope we will look back at these companies as ugly centralizing dinosaurs, as little by little, the consumers realize the power they gained back (or always had) over their usage and data, does not justify these business models to exist.
(Also, GDPR, even when seen as an opportunity, _is_ a hindrance to implement. Regulation in response to market evils is known to be heavy-handed and clumsy).
It doesn't matter it's ineffective. The block means they're complying with GDPR's requirement that they not target Europeans.
the only way for all businesses around the world to avoid abuse and subjugation to eu regulators, who they cannot influence, is to not exist at all?
This means that you should be criminally prosecuted by the US. The government sees this the same as hacking.
XD XD XD
Why would you think that SV would be interested in offering anything for its own sake? The vast majority of the model is to create new rent-seeking profit opportunities for investors, with internet users as a mere means to that end.
The GDPR is even an issue for people running simple blogs and forums. Many public software for these don't even have the features for GDPR compliance.
That’s the startup I’m presently working on. We’ll expand beyond the US borders (and implement GDPR) when we advance to a larger revenue stream. But right now, GDPR compliance is a distraction that interferes with gaining enough traction to help us afford the engineering and legal resources to ensure such compliance.
NOTE: we delete all client data when they cancel already. And we don’t do any creepy marketing.
Meanwhile they'll be using VPNs to access your site anyway :)
This does sound like you'll have an easy time complying with GDPR! :)
So what's there to worry about? Sounds like you're well on your way to being compliant
If anything, this allows you to be transparent with your users too.
Do you inform your users what data you're collecting, why you're collecting it, and get their consent? Are you taking proper precautions with the expanded PII data (encrypting at rest for example)? You've basically covered the requirements.
> Yet needs to be sure they don’t end up giving the company to the EU because someone over there signs up on a marketing list.
What kind of FUD are people reading...if someone voluntarily gives you their email to sign up for a list that's fine. You just need to keep that they consented to receive what they agreed to. What you can't do is use that email for crap they didn't sign up to receive. Obviously normal unbsub rules apply, which in this case says forget that someone ever signed up.
This makes it difficult, if not impossible, to find links to living individuals. A ton of people have done a ton of work to build a shared public tree, and some 50-100 years of it are getting chopped off the bottom.
Don't take it seriously.
I would say this is also applicable in reference to the unintended consequences of regulations
It's a bit like a good forest fire. Out of the monocultural ash sprout (life sustaining) varieties.
To a lot of US-ians the GDPR is just some EU bureaucrat stopping them from making more $. Nothing matters apart from being able to do whatever you want and make $.
It’s just a different mindset.
The example from a previous HN article was the Chicago Tribune blocking EU access.
Are you saying that there's a "huge immediate opportunity" for people in Europe to read local Chicago news?
Not every business is global. In fact, 99%+ aren't.
Yet. Give it some time.
I guess they can afford it.
They will learn. It's a financial certainty.
On a separate note: I feel totally disgusted with the kind of people who are totally uninterested with the the fate of their users. It's not exactly uncommon in Silicon Valley. Fuck these guys.