It's bad enough we have to deal with patent trolls. I'm not inclined to add this to my risk profile.
You can't sell guns and drugs online.
If you're taking money, you have to make sure you know your customer (KYC).
I would also like to hear other examples.
It seems like the smart thing for US startups to do right now is ignore EU customers until they’ve validated the business idea enough to justify the engineering and legal expenses of taking this on.
I seems reasonable, but I would argue it's due to the law being new, not to some intrinsic property of it, no?
If that worked I'd embrace GDPR. Problem with "any consumer can make a complaint which requires expensive follow-up" regimes is one doesn't have to do anything wrong to incur costs. Someone can mis-interpret something and make a complaint. Now you have to interface with a regulator, which tends to be risky, expensive and time consuming.
I'm not sure what's risky, expensive or time consuming about that.
Data regulator now asks you questions. You must respond. Hopefully they agree with you. But maybe not! Twenty-eight regulators appointed by different political groups are a complex system. You will need to gain expertise on them or hire someone with it.
All I’m saying is that time and money might be better used elsewhere. Particularly by someone just making side projects.
If you're not collecting data, then all of this is irrelevant. You just say "I'm not collecting data". There's no nuance here.
This is your interpretation. Many prominent lawyers disagree.
In any case, convincing a regulator that you are not, in fact, collecting data could be harrowing, distracting and expensive. The risk of incurring those costs probably isn’t a smart one to take for a hacker or very early-stage start-up.
Even if we assume a completely bizarre and pathologically incompetent regulator that somehow ends up zeroing in on some tiny website which exhibits no evidence of violation, the hobbyist might have to... delete their website?
Have you ever responded to a regulatory enquiry?
I'd like to point out that it's in the interest of a proeminent lawyer to tell you that their services are needed...
How do you prove you are not collecting data?
If your use default configs of Apache, or Nginx, your access.log is probably infringing GDPR. It’s impossible to prove you’re not collecting this without an extensive audit.
"replying to their email"
https://jacquesmattheij.com/so-your-start-up-receive-the-nig...
Don't care about that sphere of activity, never going to do any of theses.
> If you're taking money, you have to make sure you know your customer (KYC).
Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
Data is literally everywhere... that means GDPR apply to almost everything. Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
> Can you be more precise? What are the laws about that and should'nt it be Paypal job to support that? Never wanted to compete with Paypal either..
So what you're saying is you couldn't care less unless it affects you. Got it.
This is part of my point though. You're a perfect example of what I'm talking about. Who the hell doesn't know about KYC? You just woke up to the world and realized "oh shit, regulations exist! Unacceptable!". Yes, regulations exist, and this is just another one.
> Data is literally everywhere... that means GDPR apply to almost everything.
This isn't about data, it's about PII. And PII isn't everywhere, unless you're collecting it.
> Which is why you may see some people complains about being able to sell guns online but you will see much more people complains about GDPR.
No, that's not why. The reason why is that one has been around for a long time and people got used to it.
Enforcement is what's going to matter, I'm pretty sure you could dig up other laws that are vague and have high fines, that are just not enforced and thus don't seem as threatening as the widely publicized GDPR.
Of course, I'm not a lawyer, and I may very well be wrong on my assumptions.
On the other hand, patent trolls are not part of the risk profile for our industry in the EU, since software is not patentable there.
But anyway, it makes perfect business sense for a US startup to just block the EU (or at least state somewhere that they are not complying and thus EU users shouldn't sign up) and focus on their home market until they are big enough to comply with the terms (or are willing to take the risk).
Did these precedents take place before or after the DMCA was enacted?
It’s different. “Complain and investigate” regulatory regimes are expensive to comply with. That is irrespective of whether one is doing anything wrong.
These regimes aren’t inherently faulty. They’re quite good in the American securities business. But they create a palpable incumbency bias, as well as one towards those who can afford lawyers and make a useful phone call.
Such a regime would have been ideal if constrained to large companies. Rolling it out for everyone means anyone mis-interpreting something could trigger a regulatory investigation. Even if found innocent at the end, that process is harrowing, expensive and distracting.
Every jurisdiction has its costs and benefits. Europe is still a huge market. But if one doesn’t see enough revenues to justify a dedicated compliance person, it’s a market which may now make sense to delay going into.
How about another reason: it simply increases administrative costs. If you have enough users firing these letters off then you could end up spending a significant amount of time simply responding to these letters. Something has to pay for all of that, and it's not like this cost is going to go away at some point, so the entire business model has to be set up in a way where it can just eat this cost.
As far as I'm concerned the process should be like this:
1. EU issues warning and cuts off traffic to the domain after 30 days.
2. Startup fixes GDPR compliance.
3. EU unblocks startup.
Only after the company breaks GDPR after getting unblocked should they be hit with this massive fine. For those of us that don't give a shit about Europe it's so frustrating having to worry about how we have to comply.
And before someone says something about "it's only for companies targeting the EU" that isn't as clear as people make it out to be. An errant ad, or a single conference talk, or even engagement on social media can be construed into requiring GDPR compliance.
But of course the reason the EU didn't want to block corporations flouting the GDPR technically is because they saw the arms race happening in China and decided that they didn't want a second firewall. So instead they went the lazy route and they pushed the whole mess on small startups that aren't the problem in the first place. Large corporations are the problem. The fundamental design of the internet and web is the problem.
I don‘t believe that you truly believe that, after it has been refuted a dozen times in every single GDPR discussion.
There is no lower floor. There is not even an obligation to hand out fines.
But that is irrelevant in this thread.
There is no lower floor. That was a lie!
The authorities can easily fine someone a thousand Euros or a million Euros.
Again, you're derailing. I was replying to the claim that no fine lower than 20 million Euros could possibly be imposed.
The same law that fined me $1,800 because a posted notice fell off my door in a blizzard? The same law that allowed the judge to uphold the fine by saying "I don't believe you". Bureaucracy sucks, and the second it gets its tentacles on you, no amount of cheek clenching is gonna delay the inevitable.
People play games with language and try to pretend that just because judges have discretion that this isn't somehow ridiculous.
It is not mandatory that the EU issue a warning. What the EU should have done if they didn't want small startup owners to freak out is they should have made the process clearer and if the $20m level is only aimed at massive corporations then why make it $20m at all? Why not just make it 10% of revenue? I'm not from the EU, I have no idea how the EU court system works. They did not make this easy for small startups.