So Your Startup Received the Nightmare GDPR Letter
jacquesmattheij.com
jacquesmattheij.com
And now, they still have their name and email in one entry in our system, but it's the record that we deleted the first entry at their request. Thanks for wasting half an hour of my day checking our systems, jerk.
Also, you're going to either need to suck up the admin time, script it, or block the EU. Take your pick, there's not much point slinging names around. Chances are it's going to happen again and you may as well be ready.
https://ec.europa.eu/commission/sites/beta-political/files/d...
[1] https://ico.org.uk/media/for-organisations/documents/2014223....
How does that make the letter irrelevant? Responding to the letter rather seems to be the first countermeasure against the authorities' involvement...
No, it's not: it's the government's fault for passing an over-large law.
You're right, it's the EU's.
It's common theme here on HN to think that users are just some kind of resource and the regulations are anti-climactic things that slows down the party.
Seriosly, As a user, I don't want my information to be sold to random people that I have no information about even if the seller is a tiny business because my feelings are not against the business but against the practice. The size of the violator is irrelevant to me.
If not breaching my privacy and my rights makes your business unprofitable, then simply you don't have a business.
Users are people, not just pageviews or hits or goals - despite what your analytcs software says.
I also stopped hosting demos of my side-projects (just for github or cv links), because following this law for this kind of service is just unreasonable. And I do not even have to cause any kind of harm to be fineable in Germany.
One of my demos required multiple roles for the service and hence had authorization and authentication build in. I.e. it was storing email addresses (though I happily handed out prepared near full-admin accounts to everyone interested). It was on a subdomain with robots.txt set to disallow, so very little chance someone would find it by accident. Still making this GDPR compliant without consulting a lawyer was too much effort and risk for me.
I'm not even sure without consulting a lawyer, if a fully static pure html website would be DSGVO (the German GDPR) compliant without adding a privacy policy to it. After all I could still be tracking users by HTTP/TCP/cookies and would have to inform the visitor, if I do or don't.
Who needs to document their processing activities?
There is a limited exemption for small and medium-sized organisations. If you have fewer than 250 employees, you only need to document processing activities that: are not occasional; or could result in a risk to the rights and freedoms of individuals; or involve the processing of special categories of data or criminal conviction and offence data.
GDPR is designed to be easy for small organisations to adhere to. No documentation needed if you have only small, non-sensitive data flows. IANOL, of course.
If, in order to access the demo, you need to give your e-mail address, and you are harvesting e-mail addresses in this way, you need to inform the users you are doing so, and provide a separate unchecked box "Subscribe to the Newsletter". In this way you are honest with the users, with how you are using their data, and you stick to the letter and the spirit of the law.
One of these has systemic effects, the other does not.
(I don't think small businesses should be totally unregulated. But the administrative burden should be considered, to prevent discouraging new entrants and promoting incumbency bias. GDPR does not take this into account.)
1) You claim that GDPR has a big administrative burden to small businesses but that's not the case as long as your business model is not based on invasion of privacy. If it is, well, tough life!
2) It devalues the individual, it's ridiculous. Small restaurants need to follow hygiene standards just as the big chains, despite the fact that your local burger shop won't cause health problems on the same scale of McDonald's. Do you know why? Because individuals matter too. Can't be bothered to clean your kitchen? Don't run a restaurant. Can't be bothered to take care of your visitor's data? Don't run an online business. The society or any individual doesn't owe you a profit or a business.
Have you ever dealt with a regulatory enquiry? Even if you have done nothing wrong, they are harrowing, time-consuming and--occasionally--costly.
> Small restaurants need to follow hygiene standards just as the big chains
Look at the food codes in most large cities. Multi-location chains have stricter standards than single-venue restaurants. This is because (a) multi-location complexity introduces new vectors for harm (and lets it scale faster) and (b) people are willing to accept greater risks from small purveyors.
No they aren't, WTF?
Everyone isn't. But most people accept home-cooked meals without demanding municipal inspection.
Furthermore, the presence of looser food codes--in the U.S. and Europe--for small-batch and single-location vendors, in comparison to chains, supports the hypothesis that many people see the added risk worth taking for more variety.
Something tells me that your reaction is not based on facts but pure ideology, an ideology that assumes that regulations are always bad the businesses will take care of the consumers if left to their own devices.
Pardon me, I did not mean to imply I have dealt with a GDPR enquiry. I was asking if you had dealt with any regulatory enquiry.
> an ideology that assumes that regulations are always bad
Quite the contrary. I like American and European securities regulation. I regularly call my Congresswoman for more privacy protections. (I had some luck getting a law I helped draft through committee in Albany. No further.) I've also consistently been of the position that Facebook should be broken up on antitrust grounds. My opposition to GDPR is purely on the way it is administrated.
There's something I don't get in your argument: How having a business model not based on invasion of privacy is protecting your business from receiving GDPR Subject Access requests requests, the legal fees a small business needed to spend to take care of those, and the handling of those?
In your food example it'd be more like as if a law required you to have an employee meeting with a health inspector daily. And that employee must not be a cook/staff. This seems easier for a big chain to comply than a small business.
Here, to monitor all their email, each social media pages, etc and spend time figuring out if each tweet/post is a subject access request is going to be much easier to scale for a big company compared to a small business.
Also one thing a bit off topic that's not clear to me is if suddenly a business needs to start handling and archiving sensitive information because of GDPR letters (for each request, there must be a proof of identity such as ID, passport scan, etc). You now risk having potentially non compliant businesses handle those. That seems like exposing yourself more to identity theft for each GDPR request you make.
(See "how do we recognize a request" in https://ico.org.uk/for-organisations/guide-to-the-general-da... )
Damn it, the law shouldn't apply all the way down to individuals, over trifling matters and quantities!
If you're harmed by a privacy leak, do you care whether that was perpetrated by a site that has 50 users, or 500,000?
Oh, it was a small mom and pop site that passed on your personal info, so that made it okay; sorry! Next time, only deal with a big time operator.
But we have two sets of building code rules because the regulatory burden is very different. The cost of complying with lots of regulation are fixed, and don't necessarily scale linearly with the size of the company. So to prevent these laws from wiping out small businesses they usually phase on these rules with increasing size.
You can respect everyone's rights and privacy and still be noncompliant, because most of the work of complying with the GDPR for most businesses is in the documentation, customer misinformation, and legal CYA work.
Keeping user information just became so normal in the past few years. it is not just about ads but also security.
You have all your information all over internet. Websites without minimum security requirements store everything just because it is cheap to do it and they just believe they should store it even they don't need it because maybe they need it in the future.
Hackers can do way more than you can imagine with your data if they want.
Storing user data should be expensive. Companies should only store it, if they accept and understand the responsibility and they must feel accountable for it.
We have had our legal team review it to perform a cost/benefit analysis on whether we should comply with GDPR or block the EU region for the time being.
At the end, while we all agreed that the idea behind this law is reasonable, it would benefit us to ignore the EU region. (We reviewed our database to ensure we don't have any EU users currently on the system before doing this)
That being said, we branched out and started to slowly implement some GDPR requirements that can benefit our existing users privacy and we will certainly remove the EU blockage when the scope of this law becomes more apparent to our legal team.
I strongly believe software is due for some serious regulation, just like all other branches of engineering, we need to take responsibility for the systems we create and I feel like this is a sign that our industry is maturing from it's infancy stage.
Kudos to EU for making an attempt to keep Europeans safe.
The even more ridiculous thing in my opinion is that these mom and pop sites are not already GDPR compliant. What could they possibly be doing that makes not abusing a handful of user's privacy an insurmountable issue?
You are writing as though not abusing people's privacy is all that is necessary to comply with GDPR. This is incorrect. GDPR has specific requirements for any company handling certain types of data, and extra requirements if it's handling this data "at scale" (though it doesn't actually define what this means). Any data revealing any of the following is considered protected by GDPR:
> racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
So, basically any user uploaded images or text can be argued to fall under this category since users might reveal their political, religious, or philosophical beliefs in this text. How about something as innocuous as a heart rate monitor? Well, apparently people have correlated 15-30 minute spikes in heart rates in the evenings to figure out people's sex lives so that's restricted by GDPR.
I could go on. The point is, it's not enough to just not abuse your user's data and cross your fingers to be GDPR compliant.
> basically any user uploaded images or text can be argued to fall under this category
If you run a public forum and people choose to reveal things about themselves in posts, that obviously cannot be what GDPR is about.
Even if it is, it doesn't concern any mom and pop site that isn't running a forum.
Yes it is what GDPR is about, the fact that people voluntarily share this information on a public forum doesn't nullify GDPR. Otherwise, Facebook wouldn't be under so much heat. Much of the data they collect comes from posts, comments, etc. all happening on a public forum.
> Even if it is, it doesn't concern any mom and pop site that isn't running a forum.
Say your mom & pop site has a comment section, where users can talk about blog posts they liked or disliked. Now all of a sudden you have to dedicate resources towards GDPR support.
Not like hacker news where you don't even need an email address to sign up, creating a throwaway account if you want to post something private takes one minute. Good luck with that on Facebook.
There is no way to police this stuff short of a total clamp-down on free expression.
The site operators must suspect every account is fake, and whatever that account says about itself is actually about someone else.
Since the protected information is extends to areas like political or philosophical beliefs and whatnot, nobody can discuss politics or philosophy.
The GDPR has explicit provisions for how covered information that is explicitly made public by its subject is treated (for instance, separate consent is not needed for processing such information); outside of those explicit rules for particular effects, though, such information is treated exactly like other personal information of the same subject matter under the GDPR.
Nothing. Doesn't mean they have nothing better to do than respond to letters and regulatory enquiries. (To be clear, I'm not disparaging regulators asking questions. I'm simply observing that such questioning-and-answering has a cost. That cost is reasonable for a large company. It may not balance favorably for something smaller.)
Or might have to be expanded on a bit, point is the response cost can be scaled as well.
Just because you absolutely respect the spirit of the law (don't do shitty things with PII) doesn't mean you are GDPR compliant, unfortunately.
I very much agree with GP that small business should have more relaxed obligations, and more proportional fines (the minimum fine exceed the total revenue of non-negligible percent of small business).
And no, there is no minimum fine set by GDPR, only maximum fines. Most companies will just get a warning to sort themselves out, if the past behaviour of the regulatory authorities is anything to go by — their emphasis is on getting compliance, so only egregious failures will attract fines, with others directed to carry out specified improvements to their processes.
Storing their HTTP logs on archived CD-ROMS would be a violation of the GDPR, unless that same mom-and-pop operation offered users a way to request that CDs be replaced with new versions at will.
I don't think that counts as an abuse of privacy, but it is a violation of the GDPR, which makes immutable logs which contain IP addresses illegal.
The GDPR give a number of reasons where the right to be forgotten does not apply, including for archival purposes, or when the controller was not relying on consent for the processing.
Perhaps they're busy running their business and don't have time to comply with baroque EU regulations, regardless of whether they're actually "abusing their user's privacy" or not.
Regulatory costs are a thing. Even if you're not violating the regulation, filing the forms or whatever to assure some bureaucrat that you're not violating it takes time and energy.
There's a reason why the startup scene in Europe is onlly a fraction of what it is in the U.S.
Private life is such an essential part of human nature and our societies, no matter what the "nothing to hide" camp will say. There will be collateral damage and that's unfortunate yet tolerable, given the extensive abuses.
This cuts against centuries of sovereign tradition and precedent. GDPR's constraint to users in Europe is reasonable. (As is refusing to do business in Europe by blocking the continent.)
This Regulation does not apply to the processing of personal data ... by a natural person in the course of a purely personal or household activity
Note that any external service processing the data must still abide by GDPR.
In software, if you want to skirt the law, its easy to do so with small team/companies. Just spin up shell companies under the limit and use that to skirt the law.
It certainly defeats the spirit, but this is capitalism.. No holds barred, and do illegal moves till you get caught.
I never intended to make real money off it except maybe covering server costs if I'm lucky, but the time it would take dealing with requests like this it enough to scare anyone off.
I'm not sure what the problem is.
Your obligation is to keep the data secure, and only keep data that you need. Then you need to respond to requests to (a) tell a person what data you hold on them, (b) tell them what you do with the data, and (c) delete it if asked, unless you have a legitimate reason to keep it.
So if someone has given you data for the purpose of you providing a service then all you need to do is treat that data with care, don't do anything your customer doesn't expect you to do, and be able to provide and/or delete it.
Fair do, someone disagrees and has down-voted me. Please, having read the actual regulations[0] several times, including the recitals[1], I'd be pleased to see what's missing from that outline, so I can improve my understanding.
Over the course of a few years, doing these things might take up as much time as it would to learn a new language. For a side project, I’m not sure that’s a smart trade-off.
How so? Just build yourself a tiny tool that takes an email address or username and sends them their database entries along with the standard explanations about why you need that data.
For my side projects that will be around two hours per project and then 2 minutes for every request.
Or am I missing something?
You're assuming automated responses will satisfy requestors and, for the unsatisfied, be seen favorably by each of the twenty-eight national regulators, today and into perpetuity.
In any case, I got curious about your 2 hours / project + 2 minutes / request metric. One can achieve "basic fluency" in a number of languages within 480 hours [1]. We thus find a trade-off hyperbola [2]. For 1 project, after 14,340 requests you could have learned a new language. For 5: 2,820 per project. For 10: 1,380. At one request per day, that's under 4 years. TL; DR, even with optimistic figures, a significant toll is extracted purely for administration.
[1] https://blog.thelinguist.com/how-long-should-it-take-to-lear...
[2] 2 * Projects + (1 / 30) * Projects * Requests = 480
There is where our expectations diverge. Do you really expect one request per day for a small side-project? Or even for a moderate start-up?
I find that astonishing. I admit I only have a few thousand users, but I've had a total of three requests.
Do you really think this is going to be a constant, relentless attack on your time? Do you really think that users of a service will constantly be sending DSARs?
I run a few closed services as side-projects totalling a few thousand users. I've received exactly three DSARs, and those are from people who wanted to see if I had processes in place. I'm very surprised that people think the administrative load will be significant.
But these are the underlying assumptions that can, and perhaps should, be explored. Broadly speaking, how many users will send in DSARs? One in ten? One in 100? One in 1000?
How long will it take to respond to a request?
Just out of curiosity, how long did it take you to respond to those requests?
>But these are the underlying assumptions that can, and perhaps should, be explored. Broadly speaking, how many users will send in DSARs? One in ten? One in 100? One in 1000?
>How long will it take to respond to a request?
I don't know, but I do know that there are plenty of developers out there that would probably have a lot of trouble adequately responding to these kinds of requests. Particularly the people who might have some trouble with English, especially the type of English in these requests. I have no idea how those people are going to handle these situations.
Anyone to whom you are not providing a service should not have any data released to them, so they can get a simple "I'm sorry, you're not a customer, and I hold no data on you." response.
Anyone who is a customer and is sending vexatious requests - I'd refund them if appropriate and terminate their service. Especially for side-projects, you don't need the aggravation.
In my case people were genuinely asking about actual data, and I took the time for the first to respond "by hand" - it took about ten minutes. The second time I documented what had been done the first, and parametrised it. Total time was about 15 minutes.
The third time I ran the script by hand and checked the output. Total time was under three minutes. I'm pretty sure that after another two or three I can just let it run automatically. Time taken for subsequent queries? Probably none.
And I agree that for some people, especially those for whom English is not their first language, would have trouble responding in English. It's not clear that they have to.
But speaking about time taken, I'm now going to bow out. I've made my position and understanding as clear as I can. GDPR is here, and everyone can make their choice about what they do to be seen to comply. I wish you all good luck.
We are talking about side projects. You do that as an hobby. Any minute spend on ANYTHING else than what you like to do is a minute lost for no meaningful reason.
(2) hobbies already cost time, money and effort, this adds a bit more to the time and effort factor, need not cost any money
(3) if you decide you can't operate your hobby and be legal then you always have the option to shut down
or
(4) you can shut off your service for Europe after removing all data on EU citizens that you have collected.
This is no different than any other regulation.
That all seems completely reasonable to me. It's certainly reasonable that a new start-up or side-project should use these considerations as part of their design, and I should think that an existing start-up or side-project that does not comply should look hard at why not.
If you think these demands are unreasonable, I'd genuinely be interested in knowing which, and why.
It's unreasonable, because it imposes an administrative cost on anyone that tries to do things on the side regardless whether they have good data handling practices or whether they have any intention of abusing the data. I would bet money on the fact, that JUST the fact that they must respond to a letter is enough to make some people go do something else. And who knows, maybe the side project could've been the next google.
For customers, how many requests would you expect? One in 100? One in 1000? If I store the data securely, and I only use it for the purpose it was intended, I can automate a response that (a) Sends them a copy of their data, (b) points them at the privacy policy saying I don't do anything unexpected with their data, and (c) offer a link to delete their data.
Once set up, these should not place a significant burden on the provider of a service.
I suspect we are arguing about how much work will be required. I'm saying that once set up, the administrative overhead is negligible, you are saying it isn't. Certainly the services I run have seen no increase in administrative load, I'd be interested to know who has seen a significant increase (once already set up) and why.
I frankyl don't understand why web site owners are entitled to a wild west, now-law zone?
That's a very dangerous sentiment to have. Identity theft is a very real thing. You can do pretty horrible things impersonating other people, things that will lead to people ending up in jail, things that can ruin whole families and drive people into poverty, desperation, and suicide.
It opens people up to blackmail, manipulation and a whole list of other, rather nasty, tactics.
On the extreme end, there's also the fact that not everybody lives in a "free country". In many places saying the wrong things, even online, can have very final consequences. In such cases, you not taking proper care of your user's data, sharing or leaking it all over the place, can result in people vanishing in some torture dungeon never to be seen again.
Adding legal costs like this de-incentivizes website owners which is now causing websites to shutdown EU access which I don't like.
I don't get why the EU thinks there are entitled to get content from the web while not abiding by the business model for targeted advertising companies.
Deleting it if asked might be neither cheap nor possible, depending. What if he has an audit log in his system recording that foo@bar.example attempted registered, baz@quux.example wrote a record &c.? If the audit log is a secure audit log, it's not possible to mutate a record after it's written — but that's exactly what the GDPR requires!
So now he has to either allow his audit logs to be mutable (and thus no longer secure), or he has to e.g. use an opaque identifier for his users, which means he needs another database, his audit-log–viewing system has to perform joins between the logs & that database (which means that it will no longer be straightforward to view with tail(1) & friends), that join has to handle deleted users in some useful way, &c. &c. &c.
That's thought he has to spend on something he didn't have to previously. There's obviously no problem with that in the case of something that's essential (and several provisions of the GDPR are essential). The problem is when the GDPR is mandating something inessential, or — in the case of its mandate that users be permitted to rewrite history — outright wrong. He's being forced by the law to implement a misfeature.
It's somewhat similar to a law mandating key escrow: it imposes engineering cost to achieve a wrong end.
My reading, and the advice I've seen in multiple locations, is that in the case of immutable audit logs (and backups, for example), being immutable logs (or backups) would count as a legitimate reason to retain the information. It would be required to store the logs and backups securely, but that should be done anyway.
The requirement would then be to delete what's possible (which is what the GDPR says) and then not process whatever remains. In other words, it's mandating what is already good practice.
Can you not just have a checkbox that says "I agree not to use this service from within the EU." or something like that? Like, I don't even track IP addresses for my dumb side projects. I wouldn't know where to start with this.
> One requires transparency in gathering and using data in order to allow EU citizens to exercise their rights to personal data. Therefore, the General Data Protection Regulation sets forth a variety of information obligations.
American citizens don't may or may not have rights under GDPR, or may have rights only where the processing is done within European borders, but European citizens have rights under GDPR regardless of where they are.
If its client side encrypted its not Personaly identifiable information.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Is a good starting point. Yes, you can refuse a request if it does not qualify but in this case there is more than enough meat to take it serious.
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
But reading stuff like this makes me that much more inclined to use that Cloudflare option of IP blocking the whole continent. This feels like a very slippery and dangerous can of worms that’s not worth opening.
It's bad enough we have to deal with patent trolls. I'm not inclined to add this to my risk profile.
Enforcement is what's going to matter, I'm pretty sure you could dig up other laws that are vague and have high fines, that are just not enforced and thus don't seem as threatening as the widely publicized GDPR.
Of course, I'm not a lawyer, and I may very well be wrong on my assumptions.
On the other hand, patent trolls are not part of the risk profile for our industry in the EU, since software is not patentable there.
But anyway, it makes perfect business sense for a US startup to just block the EU (or at least state somewhere that they are not complying and thus EU users shouldn't sign up) and focus on their home market until they are big enough to comply with the terms (or are willing to take the risk).
Did these precedents take place before or after the DMCA was enacted?
You can't sell guns and drugs online.
If you're taking money, you have to make sure you know your customer (KYC).
I would also like to hear other examples.
It seems like the smart thing for US startups to do right now is ignore EU customers until they’ve validated the business idea enough to justify the engineering and legal expenses of taking this on.
If that worked I'd embrace GDPR. Problem with "any consumer can make a complaint which requires expensive follow-up" regimes is one doesn't have to do anything wrong to incur costs. Someone can mis-interpret something and make a complaint. Now you have to interface with a regulator, which tends to be risky, expensive and time consuming.
I seems reasonable, but I would argue it's due to the law being new, not to some intrinsic property of it, no?
Don't care about that sphere of activity, never going to do any of theses.
> If you're taking money, you have to make sure you know your customer (KYC).
Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
Data is literally everywhere... that means GDPR apply to almost everything. Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
> Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
So what you're saying is you couldn't care less unless it affects you. Got it.
This is part of my point though. You're a perfect example of what I'm talking about. Who the hell doesn't know about KYC? You just woke up to the world and realized "oh shit, regulations exist! Unacceptable!". Yes, regulations exist, and this is just another one.
> Data is literally everywhere... that means GDPR apply to almost everything.
This isn't about data, it's about PII. And PII isn't everywhere, unless you're collecting it.
> Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
No, that's not why. The reason why is that one has been around for a long time and people got used to it.
It’s different. “Complain and investigate” regulatory regimes are expensive to comply with. That is irrespective of whether one is doing anything wrong.
These regimes aren’t inherently faulty. They’re quite good in the American securities business. But they create a palpable incumbency bias, as well as one towards those who can afford lawyers and make a useful phone call.
Such a regime would have been ideal if constrained to large companies. Rolling it out for everyone means anyone mis-interpreting something could trigger a regulatory investigation. Even if found innocent at the end, that process is harrowing, expensive and distracting.
Every jurisdiction has its costs and benefits. Europe is still a huge market. But if one doesn’t see enough revenues to justify a dedicated compliance person, it’s a market which may now make sense to delay going into.
How about another reason: it simply increases administrative costs. If you have enough users firing these letters off then you could end up spending a significant amount of time simply responding to these letters. Something has to pay for all of that, and it's not like this cost is going to go away at some point, so the entire business model has to be set up in a way where it can just eat this cost.
As far as I'm concerned the process should be like this:
1. EU issues warning and cuts off traffic to the domain after 30 days.
2. Startup fixes GDPR compliance.
3. EU unblocks startup.
Only after the company breaks GDPR after getting unblocked should they be hit with this massive fine. For those of us that don't give a shit about Europe it's so frustrating having to worry about how we have to comply.
And before someone says something about "it's only for companies targeting the EU" that isn't as clear as people make it out to be. An errant ad, or a single conference talk, or even engagement on social media can be construed into requiring GDPR compliance.
But of course the reason the EU didn't want to block corporations flouting the GDPR technically is because they saw the arms race happening in China and decided that they didn't want a second firewall. So instead they went the lazy route and they pushed the whole mess on small startups that aren't the problem in the first place. Large corporations are the problem. The fundamental design of the internet and web is the problem.
I don‘t believe that you truly believe that, after it has been refuted a dozen times in every single GDPR discussion.
There is no lower floor. There is not even an obligation to hand out fines.
But that is irrelevant in this thread.
There is no lower floor. That was a lie!
The authorities can easily fine someone a thousand Euros or a million Euros.
The same law that fined me $1,800 because a posted notice fell off my door in a blizzard? The same law that allowed the judge to uphold the fine by saying "I don't believe you". Bureaucracy sucks, and the second it gets its tentacles on you, no amount of cheek clenching is gonna delay the inevitable.
People play games with language and try to pretend that just because judges have discretion that this isn't somehow ridiculous.
It is not mandatory that the EU issue a warning. What the EU should have done if they didn't want small startup owners to freak out is they should have made the process clearer and if the $20m level is only aimed at massive corporations then why make it $20m at all? Why not just make it 10% of revenue? I'm not from the EU, I have no idea how the EU court system works. They did not make this easy for small startups.
Excellent. Then maybe some competitors will arise with products that are built with privacy in mind from the ground up.
Nope. Surely you can think of a technical solution to this problem.
established companies have no issues with fees, or legal requests.
gdpr is to protect the established companies from competition.
it is basically a reverse china ban. because china-style banning of competition is still considered bad in the eu.
"GDPR, the European Union’s new privacy law, is drawing advertising money toward Google’s online-ad services and away from competitors that are straining to show they’re complying with the sweeping regulation."
1. Adding a dialog as the first step in an onboarding funnel that's already difficult to get users through
2. Handling non-consent. WTF! So if the user doesn't give consent to something that 99% of the population doesn't understand, I'm not allowed to prevent them from using the app. And so my engineering team needs to waste critical hours figuring out things like how to deal with crashes, or maybe how in the fuck we're supposed to fallback to not using services that we're built on (e.g. Firebase)!
3. Dealing with the fallout of #1 in the form of bad reviews that are the kiss of death to startups
This is like a living, breathing example of why GDPR had to be written the way it was, so that arrogant techbros couldn’t rationalize their way around to screwing everyone over for a quick dollar. It’s also a perfect example of why you get zero sympathy. “But maaaa, it’s hurting my funnel!” Good.
this is likely a big and unnecessary burden to most startups.
i believe in less regulation in general so my opinion could be biased.
While bigger businesses, with very established monetization models that don't comply with GDPR, are now in a pretty unfavorable place and have to scramble looking for alternative monetization models, forcing much bigger changes.
I would suggest not getting too hung up on this, it is showing you the worst outcome and assuming you have made a good effort to be compliant I should think things would be fine even then. No doubt you have Ts and Cs, that document is full of clauses put in place because of things like this, and any of them could probably result in a worse letter from a customer wanting to sue you over something. But I image also that hasn't happened to you yet either?
What you think does not align with my understanding of the GDPR, what makes you say this?
No, location is what matters. Of course one could argue if IP is a reliable indicator of location, given VPNs, potentially faulty GeoIP databases, ...
We'll see what the regulators think.
[0] From Recital 23: "[When deciding whether processing is in scope under Article 3(2)], it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union."
If you want I can research the matter in more detail, someone else came up with federated sites like Mastodon nodes and that's another pretty gray area.
> I am little Joe running internet forum about space battles with maybe 5 active users right now and no more than 100 active members historically.
Ok.
> Should I sign data processing agreement with Google because I am using Gmail to send E-mails?
No. You could try to stretch the law to include that particular example but from my reading of it this is perfectly acceptable.
> Should I hire DPO?
No, but you are the de-facto DPO, so if you receive a DSAR then you probably should answer it, though with your user counts I think the chances of that are very small.
> Am I risking my house being taken from me to cover multimilion fine because user posted their photo or e-mail 5 years ago and I’ve missed it because I don’t delete user-posted content together with their account?
No.
But if a regulator should tell you that you should remove a users data (because you refused to for some reason or other) you probably should. The EU does not 'fine first and ask questions later', they will investigate first, warn and then when ignored they will fine. And for a small entity like yours which is more of a hobby than anything else I highly doubt regulators would even bother but you can't rule it out completely. Better increase you comet insurance as well if that's your main worry :)
> You could try to stretch the law to include that particular example but from my reading of it this is perfectly acceptable.
But I should still note about the fact in my privacy policy, shouldn't I?
Couple other things I've noted when working on GDPR compliance for my forum:
- It may be good idea to write in your forum rules that you don't allow users to embed their data outside of forum profile. - Forums accumulate tons of lurker accounts (users that register account but don't post or browse anything) that could be automatically deleted - Forums like to log IP's used by users when they, say, post messages. Those could be overwritten to 0.0.0.0 for items older than X days.
I've also been working on privacy policy template for people in my position that I have on GitHub and would love to have any feedback:
https://github.com/rafalp/misago-privacy-policy-examples/blo...
I think that we might have this view about it right now, but I could easily see a scenario, where somebody targets you for "harassment" through something like this. Maybe you say something somebody else doesn't like on Twitter and they do that to you.
The GDPR requires that the DPO must be independent from the organisation, so you can't be 'your own DPO'.
On the other hand the DPO is only required when sensitive or large quantities of data are concerned.
Thankfully the responses I've had thus far have been equally amicable.
- do you believe generally, even for an “upstanding” company you’ve done business with for a while, that commercial entities can be trusted with your data?
If yes, you’ll see the template as overbearing and needlessly aggressive outside the context of some specific incident when a company proved to be untrustworthy. Especially if you operate a side project or business of your own, and believe you personally would not abuse consumer data collection, you’ll see it as rude in the best case, trollish resource wasting in the worst case.
If you’re a consumer with a general mistrust of all commercial entities, even “upstanding” ones, when it comes to data practices, or if you just happen to believe that the potential risks for data abuse or harm are too high to be offset by anyone’s good intentions or past good behavior, then you’ll see this as a reasonable template, perhaps needing a few modifications for differing contexts, and that jumping straight away to legalese boilerplate just has to be assumed necessary when dealing with self-interested commercial entities.
I’m hopeful some big corps will be heavily fined to set precedent and to ease concerns that GDPR is a mild form of regulatory capture intended to be misused (regardless of its wording) to asymmetrically inhibit new entrants and small firms.
At the monent the law is unenforceable
GDPR is super expensive to remain compliant, simply because of the broadness of the terms used, leading to undefined scope of liability.
The cheapest way to stay compliant with GDPR is to completely block access to EU customers. In fact, this is what I did with my business. I redirect to a generic text file (not even a HTML that could trigger a GDPR clause by itself) explaining my stance.
The rest of the companies threatening to block the EU are seriously overestimating their importance.
Sadly, I think this is the lowest cost approach to dealing with the law, and removes the ability of an insane customer from causing us millions in liability.
Quoting the Information Commisioner's Office:
Q: We have received a request but need to amend the data before sending out the
response. Should we send out the “old” version?
A: It is our view that a subject access request relates to the data held at the
time the request was received. However, in many cases, routine use of the
data may result in it being amended or even deleted while you are dealing with
the request. So it would be reasonable for you to supply information you hold
when you send out a response, even if this is different to that held when you
received the request.
However, it is not acceptable to amend or delete the data if you would not
otherwise have done so. Under the DP Bill, it is an offence to make any
amendment with the intention of preventing its disclosure.I would very much consider this to be non-compliant, as this is a form of transparency evasion. If it isn't directly addressed, it might be covered by whether the data handed out should be the data available at the time of the request, in which case it would be prior to you having a chance to delete it.
and closes with "actually, those are are all valid and reasonable questions that you should have answers to if you were not breaking the law in the last five years. Answering them automatically should be easy
If you, no matter what company size, are not dependent on illegally and immorally profiting from personal data, then GDPR may even be good for you."
hehehehehehehe
Even so, in isolation and moderation the questions make good sense and answering them properly using an automated system and an updated privacy policy should not be a huge burden.
Look, we all know that you think the GDPR is a great idea, but a law which can't be used to its full extent is IMHO not a great law. I agree with the goals of the GDPR: they're laudable. But its details & its implementation are, quite simply, wrong.
You don't install a self-destruct mechanism which can be triggered by just pushing a single un-guarded button. Likewise, you don't pass a law which can inflict grave economic harm just by sending a letter.
It's not about wether the information is useful or not, it's about seeing what a company has.
If I get some unsolicited comms from a company then I'm going to want to get information about all the data they hold on me, preferably including where they got it from and where they sent it to.
I imagine the client will then send you another letter, to which you reply that you've already sent the information. And so on.
In the end, the client may sue you. But in that situation, you make the effort of deleting the information you said you didn't have, and you win the case.
Had the company had the information at a time in the past doesn't mean they would do now.
How should we provide the data to individuals?
If an individual makes a request electronically, you should provide the information in a commonly used electronic format, unless the individual requests otherwise.
The GDPR includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information (Recital 63). This will not be appropriate for all organisations, but there are some sectors where this may work well.
However, providing remote access should not adversely affect the rights and freedoms of others – including trade secrets or intellectual property.
Ref: https://ico.org.uk/for-organisations/guide-to-the-general-da...
Going out of your way to make the response useless is probably not a good idea.
This makes me wonder: what if you encrypt using a proprietary tool, and sell a decryption tool through another company? You could actually make money from GDPR requests.
> 2. ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
https://gdpr-info.eu/art-4-gdpr/
- BUT -
Article 2(1) limits the whole GDPR to personal data "processed" in the context of a filing system, whether electronic or physical.
In other words (in my non-lawyer reading): If I have your business card in my pocket, or I leave it on the table, or throw it away, I'm not "processing" your data in a covered way—even though I have it. If I put it in my stack of business cards or add you to my CRM, I am.
These three words can mean everything and nothing. It will take years to see how each of the EU's twenty-eight members' regulators take to interpreting them.
So having a database index would almost certainly be covered.
https://webcache.googleusercontent.com/search?q=cache:QSStS_...
1. Running a tech company
2. Funnels, conversions, and retentions
3. Writing software
Either that or they just want to watch the world burn.
The best way to deal with that is to answer the request in detail (which makes it very unlikely that a regulator would follow up if there was a complaint) and to refer to public resources such as your privacy policy because that's something that indicates that the claimant didn't do their homework, which is something a regulator will use to weigh whether or not to follow up on the complaint.
I keep hearing this but I think in reality the volume of troll requests will dictate whether that is practical or not for any given company. Small startups might have problems if that volume is not proportionately small.
You probably should not be making such blanket statements. Keep in mind that the companies that receive such requests may have substantial assets in the EU (or may even be based entirely in the EU).
This is akin to telling people to break copyright law because the courts are too busy to go after everybody and it could take years before it is your turn.
Disclaimer: We are a GDPR model company in Ireland. This means that we are implementing the mechanisms that the country is going to take as default for every other company. We had EU folks over here for months.
Please take a look at the full enforcement process:
https://ec.europa.eu/commission/sites/beta-political/files/d...
You don't have to take my word for it, this is not legal counsel, it is just reading the law before jumping to extreme conclusions.
Years of regulatory investigation sounds expensive. Furthermore, willfully ignoring regulators is a good way to piss them off. The only winning strategies here are (a) lawyer and lobbyist up and (b) block users in countries where you don't have (a).
https://ec.europa.eu/commission/sites/beta-political/files/d...
First you should receive an enquiry about yor DPA asking for the information they need and your processes, if they deem it necessary they will do an in-depth investigation. After that, they can reach a conclusion. Then if you are still not GDPR complaint, you will be fined.
Big online marketing companies are looking at a variety of technologies to turn their user's into buying customers of their advertising customers both online and in-store.
Look at Facebook as an example with their dreadful user interface attempt to trick EU customers into opting-in to facial recognition technology.
https://venturebeat.com/2018/04/18/facebook-engages-in-priva...
But there's a good reason for this. The ability for stores to know who their customer is, what they buy and re-market to them is powerful, and incredibly creepy.
https://www.pymnts.com/facebook/2017/facebook-patent-facial-...
http://www.thedrum.com/news/2017/12/01/facebook-reportedly-d...
I now turn my phone into flight mode before I enter a high street store.
https://www.kaspersky.com/blog/offline-tracking-ads/16510/
GDPR is a good reminder to all companies that the individual user owns their data, not the company. I personally like this shift, which will over time make companies think about the business models they implement, encouraging us to have customers rather than users.
The author of this piece just twisted the meaning of the letter completely.
The blog post is a response to this Ask HN:
This is allowed under the law! If you don’t like it, change the law!
The reason people have been complaining about GDPR this whole time is exactly this. Things take on a whole new meaning when complied with at scale when all you need to send is an email. This seems worse than FOIA (the US Freedom of Information Act) and Europe placed it on their entire private sector.
EDIT: clarity.
Step 2: Ignore letters about GDPR.
Alternatively, set up a form response to autosend whenever you get an email with some of those keywords.
There's an ethical and moral aspect here you're ignoring.
What about the pharma companies in India that copy American drugs (to the great benefit of humans worldwide)? US law does not rule in other sovereign nations.
Am I missing something? Is it just me? "Is It Up"[0] says it's up ...
Maybe I'll try via a different IP address.
Edit: The number of upvotes (twelve and counting) shows it's not just me. I've now changed my IP address and it loaded almost instantly.
Jacques - FWIW the IP address that's not working is 92.18.56.74 - it's been failing to load your site for at least the past hour, I have no data from before that.
https://webcache.googleusercontent.com/search?q=cache:QSStS_...
https://us.hideproxy.me/go.php?u=xRv6FweyJ5wXueEdkahRiAzzGVM...
I like to provide value to people who write articles worth reading. Jacques is definitely one of them.
I've mirrored it here in case it may help: http://blogs.intellique.com/so-your-start-up-receive-the-nig...
On what basis do you make that assumption?
It is still the internet, routing issues can and do occur. There is absolutely nothing in the configuration of my server(s) that would block anybody from any nation.
I'll alert my hosting provider to make sure they know about it just in case it's a novel thing and their monitoring didn't pick it up yet but it could easily be further upstream.
Or couldn't. I changed IP address and can now.
Many/most people have dynamic IP addresses, and I wonder if Jacques' provider has aggressively blocked addresses that have been abused in the recent past.
Anyway, the server is definitely 'open to all takers', nothing there that could cause this. Also, last Saturday ABN-AMRO (one of the bigger Dutch commercial banks) went offline for many hours due to a huge DDOS, this may be related but I never thought my lonely blog would be in the line of fire.
Receive => Received
Edit: apparently not blocked, but still can't connect apart from via VPN.
The idea that information about someone belongs to that person, no matter where it is stored, is a philosophically flawed perspective that if fully implemented, would lead to total global tyranny, by obligating people to do the work of disclosure and information deletion on demand, and ironically, by eradicating all privacy in relation to information people have about other people.
You have no moral right to dictate what I remember about you, to compel me to disclose what I know about you, to compel me to disclose what steps I took to disremember you, or to restrict who I may relay the information I remember about you to. The GDPR empowers you to do all of these to me in the context of a web service.