ironically, this very blogger made all the same arguments here:
https://jacquesmattheij.com/gdpr-hysteria
his response to his current concern is: "then automate it" as if this is trivial. and "my blog is compliant" as if this means anything for even the most basic business model.
I think the cost of not having this law is much higher.
Also, lots companies had few problems automating the dissemination of users personal information to dozens of interested parties, building completely automated markets for this information with derivatives trading etc, all without users (and regulators) knowing or understanding anything about these practices. It is long overdue to put a stop to the excesses, and as a EU citizen I am extremely happy with GDPR.
There will be new opportunities for startups, hopefully GDPR can help make sure these opportunities are less detrimental to society than before.
There is no way you could know this and every indication to the contrary. Many EU countries are struggling with jobs and claiming to want a tech sector. This just made it much less likely.
> There will be new opportunities for startups,
The barrier to entry was raised. That means that startups which cannot afford proof of compliance will not exist - whether or not they meet your subjective definition of "detrimental to society."
> Why are we down-voting this post?
Responding to that will certainly not lead to new insights or good discussion. I did respond to the other point.
In other words, your assumptions don't factor in the link between the myriad of web services now available, and the freedom people have had to provide services on the web.
The government has a constructive role to play in the market, in provisioning tools and information to empower people to maintain their privacy, which market players are not economically incentivized to provide in sufficient quantities.
That would take the form of public funding for development of anonymity technologies, public directories comparing services and their abidance to voluntary data protection standards, and possibly public service announcements educating people about what data they disclose while browsing non-anonymously, or browsing particular types of websites, and how that data can be shared and used by private data collectors.
What the government should not be doing is imposing Big Brother laws that violate the privacy rights of companies in relation to the data they store, which properly understood, belongs to them, regardless of who that information is pertaining to, and violate private property rights by regimenting how web service companies will operate.
Centrally planning the web economy in the manner of imposing regulations like the GDPR is so ridiculously misguided. It is going to destroy innovation, and particularly, business creation.
I think not: incumbents will have more changes to make than startups, who can think it through and get it right from the start (for everyone, ideally). Also the data-portability rule directly lowers the barrier to entry and creates huge opportunities for competition.
Ad-tech startups who built their tech in the previous years may feel screwed by GDPR, but I won't shed any tears for them. They may carry on in the US, if that makes you happy.
The solution severely confines the space of operation, by straightjacketing web service provisioning to a narrowly defined set of procedures, and thus I think it's unlikely to be less costly than the problem it seeks to solve.
Creativity does not flow from this kind of central planning. I believe the blind spot that GDPR advocates have is that they don't fully grasp the scope of what they don't know and what has not yet been discovered, and thus they don't fully account for the cost of laws that inhibit the innovative processes that lead to discovering new ways of providing goods/services.
The responsible way of addressing privacy concerns, that would have been far less likely to undermine liberty and have other negative unintended consequences, would have been to develop user friendly anonymous browsing technology, like Tor-enabled browsers.
After you reach anonymously a service (e.g. Facebook) and login you won't get any help from Tor or similar technologies. You need a law to tell the other party to not mess with your privacy
The rest is an issue of contract law. No one is forcing you to use Facebook, thus it is not violating your privacy when you choose to give it your data. Perhaps public education, on how the personal data you disclose to web services can be used, and information on anonymous alternatives, would help in this situation.
Whatever the solution, it should not impose arbitrary restrictions on how websites can use the data others disclose to them, or obligate a web provider to respond to letters they receive. These are Big Brother laws that will limit the availability of services by severely constraining the space of operation.
I want to be able to use the web without other people's overbearing laws severely limiting the range of websites and services available.
I'm in this camp, and to respond to your counterargument:
No one is forcing anyone to use anything... except healthcare, health insurance, car insurance, etc. And in many cases, while you may not be forced to use a tool, not using it puts you at an extreme competitive disadvantage. People shouldn't have to choose between being able to compete and valuing their privacy.
I'm fully on board with acknowledging that complying with GDPR has a pretty high cost, but the flipside of that is that if companies had done the right thing to begin with, a) the cost wouldn't be so high, and b) we wouldn't need this law.
Moving targets are no fun at all when running a business.
Answering a request - even one engineered to be annoying - like this should not be a huge burden for any company that is not doing anything shady and that has been preparing for just such an event.
In some cases you can, but most GDPR DSARs are going to be free of charge.