But reading stuff like this makes me that much more inclined to use that Cloudflare option of IP blocking the whole continent. This feels like a very slippery and dangerous can of worms that’s not worth opening.
But reading stuff like this makes me that much more inclined to use that Cloudflare option of IP blocking the whole continent. This feels like a very slippery and dangerous can of worms that’s not worth opening.
It's bad enough we have to deal with patent trolls. I'm not inclined to add this to my risk profile.
Enforcement is what's going to matter, I'm pretty sure you could dig up other laws that are vague and have high fines, that are just not enforced and thus don't seem as threatening as the widely publicized GDPR.
Of course, I'm not a lawyer, and I may very well be wrong on my assumptions.
On the other hand, patent trolls are not part of the risk profile for our industry in the EU, since software is not patentable there.
But anyway, it makes perfect business sense for a US startup to just block the EU (or at least state somewhere that they are not complying and thus EU users shouldn't sign up) and focus on their home market until they are big enough to comply with the terms (or are willing to take the risk).
Did these precedents take place before or after the DMCA was enacted?
You can't sell guns and drugs online.
If you're taking money, you have to make sure you know your customer (KYC).
I would also like to hear other examples.
It seems like the smart thing for US startups to do right now is ignore EU customers until they’ve validated the business idea enough to justify the engineering and legal expenses of taking this on.
If that worked I'd embrace GDPR. Problem with "any consumer can make a complaint which requires expensive follow-up" regimes is one doesn't have to do anything wrong to incur costs. Someone can mis-interpret something and make a complaint. Now you have to interface with a regulator, which tends to be risky, expensive and time consuming.
I'm not sure what's risky, expensive or time consuming about that.
Data regulator now asks you questions. You must respond. Hopefully they agree with you. But maybe not! Twenty-eight regulators appointed by different political groups are a complex system. You will need to gain expertise on them or hire someone with it.
All I’m saying is that time and money might be better used elsewhere. Particularly by someone just making side projects.
If you're not collecting data, then all of this is irrelevant. You just say "I'm not collecting data". There's no nuance here.
How do you prove you are not collecting data?
If your use default configs of Apache, or Nginx, your access.log is probably infringing GDPR. It’s impossible to prove you’re not collecting this without an extensive audit.
This is your interpretation. Many prominent lawyers disagree.
In any case, convincing a regulator that you are not, in fact, collecting data could be harrowing, distracting and expensive. The risk of incurring those costs probably isn’t a smart one to take for a hacker or very early-stage start-up.
I'd like to point out that it's in the interest of a proeminent lawyer to tell you that their services are needed...
Even if we assume a completely bizarre and pathologically incompetent regulator that somehow ends up zeroing in on some tiny website which exhibits no evidence of violation, the hobbyist might have to... delete their website?
Have you ever responded to a regulatory enquiry?
"replying to their email"
https://jacquesmattheij.com/so-your-start-up-receive-the-nig...
I seems reasonable, but I would argue it's due to the law being new, not to some intrinsic property of it, no?
Don't care about that sphere of activity, never going to do any of theses.
> If you're taking money, you have to make sure you know your customer (KYC).
Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
Data is literally everywhere... that means GDPR apply to almost everything. Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
> Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
So what you're saying is you couldn't care less unless it affects you. Got it.
This is part of my point though. You're a perfect example of what I'm talking about. Who the hell doesn't know about KYC? You just woke up to the world and realized "oh shit, regulations exist! Unacceptable!". Yes, regulations exist, and this is just another one.
> Data is literally everywhere... that means GDPR apply to almost everything.
This isn't about data, it's about PII. And PII isn't everywhere, unless you're collecting it.
> Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
No, that's not why. The reason why is that one has been around for a long time and people got used to it.
It’s different. “Complain and investigate” regulatory regimes are expensive to comply with. That is irrespective of whether one is doing anything wrong.
These regimes aren’t inherently faulty. They’re quite good in the American securities business. But they create a palpable incumbency bias, as well as one towards those who can afford lawyers and make a useful phone call.
Such a regime would have been ideal if constrained to large companies. Rolling it out for everyone means anyone mis-interpreting something could trigger a regulatory investigation. Even if found innocent at the end, that process is harrowing, expensive and distracting.
Every jurisdiction has its costs and benefits. Europe is still a huge market. But if one doesn’t see enough revenues to justify a dedicated compliance person, it’s a market which may now make sense to delay going into.
How about another reason: it simply increases administrative costs. If you have enough users firing these letters off then you could end up spending a significant amount of time simply responding to these letters. Something has to pay for all of that, and it's not like this cost is going to go away at some point, so the entire business model has to be set up in a way where it can just eat this cost.
As far as I'm concerned the process should be like this:
1. EU issues warning and cuts off traffic to the domain after 30 days.
2. Startup fixes GDPR compliance.
3. EU unblocks startup.
Only after the company breaks GDPR after getting unblocked should they be hit with this massive fine. For those of us that don't give a shit about Europe it's so frustrating having to worry about how we have to comply.
And before someone says something about "it's only for companies targeting the EU" that isn't as clear as people make it out to be. An errant ad, or a single conference talk, or even engagement on social media can be construed into requiring GDPR compliance.
But of course the reason the EU didn't want to block corporations flouting the GDPR technically is because they saw the arms race happening in China and decided that they didn't want a second firewall. So instead they went the lazy route and they pushed the whole mess on small startups that aren't the problem in the first place. Large corporations are the problem. The fundamental design of the internet and web is the problem.
I don‘t believe that you truly believe that, after it has been refuted a dozen times in every single GDPR discussion.
There is no lower floor. There is not even an obligation to hand out fines.
But that is irrelevant in this thread.
There is no lower floor. That was a lie!
The authorities can easily fine someone a thousand Euros or a million Euros.
The same law that fined me $1,800 because a posted notice fell off my door in a blizzard? The same law that allowed the judge to uphold the fine by saying "I don't believe you". Bureaucracy sucks, and the second it gets its tentacles on you, no amount of cheek clenching is gonna delay the inevitable.
Again, you're derailing. I was replying to the claim that no fine lower than 20 million Euros could possibly be imposed.
People play games with language and try to pretend that just because judges have discretion that this isn't somehow ridiculous.
It is not mandatory that the EU issue a warning. What the EU should have done if they didn't want small startup owners to freak out is they should have made the process clearer and if the $20m level is only aimed at massive corporations then why make it $20m at all? Why not just make it 10% of revenue? I'm not from the EU, I have no idea how the EU court system works. They did not make this easy for small startups.
Excellent. Then maybe some competitors will arise with products that are built with privacy in mind from the ground up.
Nope. Surely you can think of a technical solution to this problem.
established companies have no issues with fees, or legal requests.
gdpr is to protect the established companies from competition.
it is basically a reverse china ban. because china-style banning of competition is still considered bad in the eu.
"GDPR, the European Union’s new privacy law, is drawing advertising money toward Google’s online-ad services and away from competitors that are straining to show they’re complying with the sweeping regulation."
1. Adding a dialog as the first step in an onboarding funnel that's already difficult to get users through
2. Handling non-consent. WTF! So if the user doesn't give consent to something that 99% of the population doesn't understand, I'm not allowed to prevent them from using the app. And so my engineering team needs to waste critical hours figuring out things like how to deal with crashes, or maybe how in the fuck we're supposed to fallback to not using services that we're built on (e.g. Firebase)!
3. Dealing with the fallout of #1 in the form of bad reviews that are the kiss of death to startups
This is like a living, breathing example of why GDPR had to be written the way it was, so that arrogant techbros couldn’t rationalize their way around to screwing everyone over for a quick dollar. It’s also a perfect example of why you get zero sympathy. “But maaaa, it’s hurting my funnel!” Good.
If you would have built your whole app on "free" services for which your users pay with their personal information, that would be problematic under GDPR. And rightfully so.
What if I decide that crash reporting is an essential service (it is), and the EU's lawyers decide that it's not? Who is going to pay my legal fees, and potential fine? I should be on the hook because some schmuck uses a service that I provide for free (which essentially means I'm paying for it with my time), and is upset that I may not be handling his data in the way that the EU says I should be? The sane solution would be to allow me to tell this individual that he cannot use the app if he doesn't consent. But here comes the EU telling me that I must allow him to use the app.
No, the EU only stipulates that you are not allowed to sell, leak or otherwise slander personal data from EU residents without their freely given consent, and makes you liable for that.
IANAL, but I think there is no reason to fear too much, though I would stay on the safe side regarding interpretation. And remember that anybody can report you for anything to the authorities, or sue you already; if you are prosecuted you'll have to pay your legal fees and fines whether it's about GDPR or not.
this is likely a big and unnecessary burden to most startups.
i believe in less regulation in general so my opinion could be biased.
While bigger businesses, with very established monetization models that don't comply with GDPR, are now in a pretty unfavorable place and have to scramble looking for alternative monetization models, forcing much bigger changes.
I would suggest not getting too hung up on this, it is showing you the worst outcome and assuming you have made a good effort to be compliant I should think things would be fine even then. No doubt you have Ts and Cs, that document is full of clauses put in place because of things like this, and any of them could probably result in a worse letter from a customer wanting to sue you over something. But I image also that hasn't happened to you yet either?
What you think does not align with my understanding of the GDPR, what makes you say this?
No, location is what matters. Of course one could argue if IP is a reliable indicator of location, given VPNs, potentially faulty GeoIP databases, ...
We'll see what the regulators think.
[0] From Recital 23: "[When deciding whether processing is in scope under Article 3(2)], it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union."