It's common theme here on HN to think that users are just some kind of resource and the regulations are anti-climactic things that slows down the party.
Seriosly, As a user, I don't want my information to be sold to random people that I have no information about even if the seller is a tiny business because my feelings are not against the business but against the practice. The size of the violator is irrelevant to me.
If not breaching my privacy and my rights makes your business unprofitable, then simply you don't have a business.
Users are people, not just pageviews or hits or goals - despite what your analytcs software says.
I also stopped hosting demos of my side-projects (just for github or cv links), because following this law for this kind of service is just unreasonable. And I do not even have to cause any kind of harm to be fineable in Germany.
One of my demos required multiple roles for the service and hence had authorization and authentication build in. I.e. it was storing email addresses (though I happily handed out prepared near full-admin accounts to everyone interested). It was on a subdomain with robots.txt set to disallow, so very little chance someone would find it by accident. Still making this GDPR compliant without consulting a lawyer was too much effort and risk for me.
I'm not even sure without consulting a lawyer, if a fully static pure html website would be DSGVO (the German GDPR) compliant without adding a privacy policy to it. After all I could still be tracking users by HTTP/TCP/cookies and would have to inform the visitor, if I do or don't.
Who needs to document their processing activities?
There is a limited exemption for small and medium-sized organisations. If you have fewer than 250 employees, you only need to document processing activities that: are not occasional; or could result in a risk to the rights and freedoms of individuals; or involve the processing of special categories of data or criminal conviction and offence data.
GDPR is designed to be easy for small organisations to adhere to. No documentation needed if you have only small, non-sensitive data flows. IANOL, of course.
If, in order to access the demo, you need to give your e-mail address, and you are harvesting e-mail addresses in this way, you need to inform the users you are doing so, and provide a separate unchecked box "Subscribe to the Newsletter". In this way you are honest with the users, with how you are using their data, and you stick to the letter and the spirit of the law.
One of these has systemic effects, the other does not.
(I don't think small businesses should be totally unregulated. But the administrative burden should be considered, to prevent discouraging new entrants and promoting incumbency bias. GDPR does not take this into account.)
1) You claim that GDPR has a big administrative burden to small businesses but that's not the case as long as your business model is not based on invasion of privacy. If it is, well, tough life!
2) It devalues the individual, it's ridiculous. Small restaurants need to follow hygiene standards just as the big chains, despite the fact that your local burger shop won't cause health problems on the same scale of McDonald's. Do you know why? Because individuals matter too. Can't be bothered to clean your kitchen? Don't run a restaurant. Can't be bothered to take care of your visitor's data? Don't run an online business. The society or any individual doesn't owe you a profit or a business.
Have you ever dealt with a regulatory enquiry? Even if you have done nothing wrong, they are harrowing, time-consuming and--occasionally--costly.
> Small restaurants need to follow hygiene standards just as the big chains
Look at the food codes in most large cities. Multi-location chains have stricter standards than single-venue restaurants. This is because (a) multi-location complexity introduces new vectors for harm (and lets it scale faster) and (b) people are willing to accept greater risks from small purveyors.
No they aren't, WTF?
Everyone isn't. But most people accept home-cooked meals without demanding municipal inspection.
Furthermore, the presence of looser food codes--in the U.S. and Europe--for small-batch and single-location vendors, in comparison to chains, supports the hypothesis that many people see the added risk worth taking for more variety.
People accept food from people they know socially or from an organisations that they know.
EU won't go after you if you send a link of your non-complient code to your friend as long as your friend doesn't start a legal action against you.
You are freaking out for no good reason.
Same with the web, if you’re coding for your own social circle GDPR is not something you need to comply as long as someone of your social circle is harmed and starts an action against you.
Also, different regulations for different sizes is due to the nature of the business. It’s not that small shops are allowed to be dirtier than the chains.
Bingo. The intent of the law is fine. But the administrative burden for small projects and teams is inappropriate.
In any case, you originally claimed “small restaurants need to follow hygiene standards just as the big chains” [1]. I was showing that is not true. They follow different rules stemming from common principles.
The same goes for the software, if you’re not doing things that Google does then GDPR affects you less than Google.
Seriously, the cost of GDPR compliance is not the same for Google and mom&pop businesses, just like the cost of food safety regulations is not the same for the chains and small restaurants.
You are freaking out for no good reason.
From "generally regarded as clean" friends and relatives.
Something tells me that your reaction is not based on facts but pure ideology, an ideology that assumes that regulations are always bad the businesses will take care of the consumers if left to their own devices.
Pardon me, I did not mean to imply I have dealt with a GDPR enquiry. I was asking if you had dealt with any regulatory enquiry.
> an ideology that assumes that regulations are always bad
Quite the contrary. I like American and European securities regulation. I regularly call my Congresswoman for more privacy protections. (I had some luck getting a law I helped draft through committee in Albany. No further.) I've also consistently been of the position that Facebook should be broken up on antitrust grounds. My opposition to GDPR is purely on the way it is administrated.
It's really not that big of a deal.
I would have trouble only if I was doing illegal business, make people work in an unsafe and dirty environment, didn't provide the sanitary needs and paid them less than the national minimum wage.
Even worse in Germany, we have something called "Abmahnung" (https://de.wikipedia.org/wiki/Abmahnung). Every lawyer can send you a letter telling you to follow the law and request payment from you for the "service" of telling you that. This can be several hundred euros and you can then decide to go to court (and lose if they were right) or pay them. German law firms can pick up non-GDPR compliant websites using crawlers (e.g. just identifying pages without privacy policies accessible, is a simple one) and fine exactly the persons that are not targeted by the GDPR. It's absurd and it has nothing to do with these people doing any kind of damage.
It would be similar if you had to to put your workspace policy and data proving your fulfillment of workspace regulations up in the internet, so any single lawyer can check them and send you a bill, if they find something wrong. This can't be the right way to go for private websites, small non-profits and even small businesses. It's just insane.
Edit in response to the comment below as I can't reply for whatever reason: Multiple legal help pages about the German law say that you can get an "Abmahnung" even without proving that there is a client that is a competitor. E.g. here https://www.datenschutz.org/datenschutzerklaerung-website/#d... "Seit Anfang 2016 können nicht nur Mitwerber, sondern auch Verbraucherschutzverbände Abmahnungen wegen fehlender Datenschutzerklärungen versenden. Das bedeutet, dass diese Option nicht allein gewerbliche Websites treffen kann." It's limited to Verbraucherschutzverbände (probably translatable as customer protection agencies), so the risk for a private page is close to zero based on this, but I'm not a lawyer, I don't know what exactly changed here through GDPR/DSGVO and you still basically have to consult a lawyer to be on the safe side.
The lawyer would need to show that there is (a) a client and that this client is (b) a competitor of the target.
For your personal page that‘s next to impossible.
There's something I don't get in your argument: How having a business model not based on invasion of privacy is protecting your business from receiving GDPR Subject Access requests requests, the legal fees a small business needed to spend to take care of those, and the handling of those?
In your food example it'd be more like as if a law required you to have an employee meeting with a health inspector daily. And that employee must not be a cook/staff. This seems easier for a big chain to comply than a small business.
Here, to monitor all their email, each social media pages, etc and spend time figuring out if each tweet/post is a subject access request is going to be much easier to scale for a big company compared to a small business.
Also one thing a bit off topic that's not clear to me is if suddenly a business needs to start handling and archiving sensitive information because of GDPR letters (for each request, there must be a proof of identity such as ID, passport scan, etc). You now risk having potentially non compliant businesses handle those. That seems like exposing yourself more to identity theft for each GDPR request you make.
(See "how do we recognize a request" in https://ico.org.uk/for-organisations/guide-to-the-general-da... )
Damn it, the law shouldn't apply all the way down to individuals, over trifling matters and quantities!
If you're harmed by a privacy leak, do you care whether that was perpetrated by a site that has 50 users, or 500,000?
Oh, it was a small mom and pop site that passed on your personal info, so that made it okay; sorry! Next time, only deal with a big time operator.
But we have two sets of building code rules because the regulatory burden is very different. The cost of complying with lots of regulation are fixed, and don't necessarily scale linearly with the size of the company. So to prevent these laws from wiping out small businesses they usually phase on these rules with increasing size.
You can respect everyone's rights and privacy and still be noncompliant, because most of the work of complying with the GDPR for most businesses is in the documentation, customer misinformation, and legal CYA work.
Keeping user information just became so normal in the past few years. it is not just about ads but also security.
You have all your information all over internet. Websites without minimum security requirements store everything just because it is cheap to do it and they just believe they should store it even they don't need it because maybe they need it in the future.
Hackers can do way more than you can imagine with your data if they want.
Storing user data should be expensive. Companies should only store it, if they accept and understand the responsibility and they must feel accountable for it.
We have had our legal team review it to perform a cost/benefit analysis on whether we should comply with GDPR or block the EU region for the time being.
At the end, while we all agreed that the idea behind this law is reasonable, it would benefit us to ignore the EU region. (We reviewed our database to ensure we don't have any EU users currently on the system before doing this)
That being said, we branched out and started to slowly implement some GDPR requirements that can benefit our existing users privacy and we will certainly remove the EU blockage when the scope of this law becomes more apparent to our legal team.
I strongly believe software is due for some serious regulation, just like all other branches of engineering, we need to take responsibility for the systems we create and I feel like this is a sign that our industry is maturing from it's infancy stage.
Kudos to EU for making an attempt to keep Europeans safe.
The even more ridiculous thing in my opinion is that these mom and pop sites are not already GDPR compliant. What could they possibly be doing that makes not abusing a handful of user's privacy an insurmountable issue?
You are writing as though not abusing people's privacy is all that is necessary to comply with GDPR. This is incorrect. GDPR has specific requirements for any company handling certain types of data, and extra requirements if it's handling this data "at scale" (though it doesn't actually define what this means). Any data revealing any of the following is considered protected by GDPR:
> racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
So, basically any user uploaded images or text can be argued to fall under this category since users might reveal their political, religious, or philosophical beliefs in this text. How about something as innocuous as a heart rate monitor? Well, apparently people have correlated 15-30 minute spikes in heart rates in the evenings to figure out people's sex lives so that's restricted by GDPR.
I could go on. The point is, it's not enough to just not abuse your user's data and cross your fingers to be GDPR compliant.
> basically any user uploaded images or text can be argued to fall under this category
If you run a public forum and people choose to reveal things about themselves in posts, that obviously cannot be what GDPR is about.
Even if it is, it doesn't concern any mom and pop site that isn't running a forum.
Yes it is what GDPR is about, the fact that people voluntarily share this information on a public forum doesn't nullify GDPR. Otherwise, Facebook wouldn't be under so much heat. Much of the data they collect comes from posts, comments, etc. all happening on a public forum.
> Even if it is, it doesn't concern any mom and pop site that isn't running a forum.
Say your mom & pop site has a comment section, where users can talk about blog posts they liked or disliked. Now all of a sudden you have to dedicate resources towards GDPR support.
Not like hacker news where you don't even need an email address to sign up, creating a throwaway account if you want to post something private takes one minute. Good luck with that on Facebook.
There is no way to police this stuff short of a total clamp-down on free expression.
The site operators must suspect every account is fake, and whatever that account says about itself is actually about someone else.
Since the protected information is extends to areas like political or philosophical beliefs and whatnot, nobody can discuss politics or philosophy.
The GDPR has explicit provisions for how covered information that is explicitly made public by its subject is treated (for instance, separate consent is not needed for processing such information); outside of those explicit rules for particular effects, though, such information is treated exactly like other personal information of the same subject matter under the GDPR.
Nothing. Doesn't mean they have nothing better to do than respond to letters and regulatory enquiries. (To be clear, I'm not disparaging regulators asking questions. I'm simply observing that such questioning-and-answering has a cost. That cost is reasonable for a large company. It may not balance favorably for something smaller.)
Or might have to be expanded on a bit, point is the response cost can be scaled as well.
Just because you absolutely respect the spirit of the law (don't do shitty things with PII) doesn't mean you are GDPR compliant, unfortunately.
I very much agree with GP that small business should have more relaxed obligations, and more proportional fines (the minimum fine exceed the total revenue of non-negligible percent of small business).
And no, there is no minimum fine set by GDPR, only maximum fines. Most companies will just get a warning to sort themselves out, if the past behaviour of the regulatory authorities is anything to go by — their emphasis is on getting compliance, so only egregious failures will attract fines, with others directed to carry out specified improvements to their processes.
Storing their HTTP logs on archived CD-ROMS would be a violation of the GDPR, unless that same mom-and-pop operation offered users a way to request that CDs be replaced with new versions at will.
I don't think that counts as an abuse of privacy, but it is a violation of the GDPR, which makes immutable logs which contain IP addresses illegal.
The GDPR give a number of reasons where the right to be forgotten does not apply, including for archival purposes, or when the controller was not relying on consent for the processing.
Perhaps they're busy running their business and don't have time to comply with baroque EU regulations, regardless of whether they're actually "abusing their user's privacy" or not.
Regulatory costs are a thing. Even if you're not violating the regulation, filing the forms or whatever to assure some bureaucrat that you're not violating it takes time and energy.
There's a reason why the startup scene in Europe is onlly a fraction of what it is in the U.S.
Private life is such an essential part of human nature and our societies, no matter what the "nothing to hide" camp will say. There will be collateral damage and that's unfortunate yet tolerable, given the extensive abuses.
This cuts against centuries of sovereign tradition and precedent. GDPR's constraint to users in Europe is reasonable. (As is refusing to do business in Europe by blocking the continent.)
This Regulation does not apply to the processing of personal data ... by a natural person in the course of a purely personal or household activity
Note that any external service processing the data must still abide by GDPR.
In software, if you want to skirt the law, its easy to do so with small team/companies. Just spin up shell companies under the limit and use that to skirt the law.
It certainly defeats the spirit, but this is capitalism.. No holds barred, and do illegal moves till you get caught.