I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
Yes, a Corporation that manages not to dump toxic waste in rivers is going to have a moat against smaller companies that do dump toxic waste in rivers.
But I'd rather it be illegal than have companies competing for who can externalize their costs more effectively by passing their problem of waste management to the state / local area.
I'm working on GDPR right now at my company, and it's not a small effort.
None. Do not target the EU initially, start in the US market with your MVP. It's by far the most liberal major market to do an MVP in, in all regards. It's the world's largest economy and easily accessible; plus you essentially get Canada as a bonus: a combined $21.5 trillion in economy. Entirely disregard GDPR until you've scaled the business enough to afford whatever you've calculated GDPR compliance will cost you in terms of effort / resources, then push into the EU when it's convenient.
Enforcement and jurisdiction have yet to be tested yet, of course, but it isn't as simple as "don't set up shop in the EU".
It also doesn't matter what China purports I should do with their citizen data, or South Africa, or Australia, or Brazil: their wishes don't overrule the supremacy of US law inside the US. If China wants me to delete everything on my service about Tiananmen Square, or an anti-China activist, guess what, that's not going to happen for the exact same reason. I'm also not subject to the UK government's enforced media blackout on the Tommy Robinson arrest: they too can piss off.
If a EU citizen signs up with my US based service, their data will be governed by US law.
It is that simple. It will remain that simple. The US isn't going to cede its sovereignty to the EU: it's drastically more powerful than the EU in every regard. There is no scenario where the US lays back and allows the EU to legislate how the domestic US economy operates in such large ways.
The only likely outcome is that the US comes up with its own new privacy rules in the next few years, which will be different - more lenient - than GDPR. If you want to operate in the two markets, you'll have to comply with each approach accordingly.
It's not a thesis, it's proven, court established rule of law with more than a century of built-up precedence establishing how things actually work when it comes to US sovereignty. This is all quite laughable.
It's identical to saying: well, the US is just going to enforce its freedom of speech approach on Germany or the UK (where offending people is increasingly illegal). So all people and businesses in those nations should disregard their own laws and comply with US laws, you don't want to test the thesis about just how far US jurisdiction extends, better to comply with US freedom of speech laws instead.
Imagine me traveling to Britain and telling them that since I'm an American, their speech laws don't apply to me. I'm governed by US speech laws, regardless of where I'm at. That'd be good for a jolly laugh: look at this delusional, entitled American that thinks they control the planet. Or try telling the Chinese the same thing on their territory.
There are millions of small businesses in the US, very few of them will ever comply with GDPR - even if they have occasional stray EU customers - precisely because the EU has no jurisdiction and those businesses don't operate by EU law.
Account for deletion when designing the product. When considered from the beginning, the cost is typically negligible. It's only when shoehorned on the end that it gets expensive.
But... companies have had two years of notice about this. Any projects that have been running for fewer than two years have had plenty of notice. And it's not only the government who requires data deletion - it's your data sources (like Twitter) and your big customers who write it into their contracts.
Just plan for being able to delete data. You are gonna need it.
Yeah sure, all that privacy, who needs it anyway?
/s
Who would have thought that legislators had something to gain from a proposal they push?
Without targeted advertising there is much less financial incentive to collect data so the surveillance state won't get help from corporations.
The worst I've heard of was the abuse of millions of people's data by Cambridge Analytics to mess with an election, but maybe that's just a little icky too?
Nobody disagrees with GDPR's intent. The qualm is with its administrative approach. If someone said "write a bailout for lawyers and lobbyists," it would look like GDPR.
Taking your analogy, a good law would assess a fine for dumping. A bad law would (a) require continuous certification that one is not dumping and (b) allow anyone to prompt an expensive inspection (done via writing letter responses to a regulator, not on-site inspection by an expert) by reporting you to one of twenty-eight national regulators, each of which have jurisdiction over you.
The former imposes a fixed costs, regardless of compliance. That benefits incumbents. The latter promotes venue shopping, a further advantage to size and incumbency.
Note that the European consumer protection laws already allow consumers to sue in their own country. So if you do business in all EU country, you can be sued in lots of places.
Maybe if you are continuously worried about regulators, then it is better to not start a business. In the real world, regulators are busy enough. Regulators are not going to bother random companies in other countries just for the fun of it.
In my opinion the GDPR should have tiered regulations based on global revenue. It's pretty hard to profit off of data and not have some sort of cash flow
What if GDPR is what pushes distributed computing into the mainstream?
If GDPR makes it even harder for small fry to compete with the giants, then the small fry should change the rules.
Zero centralized servers, zero PII, no EULAs, no legaleze, only open-source P2P.
Megacorps can be GDPR-compliant with buildings full of lawyers, and the rest will be GDPR-irrelevant with no lawyers at all.
how that should work exactly? I mean, even if platform is P2P, you still have user id, you still have user interests, et cetera.
The only thing changed bc of P2P is that it gets much more complicated, or even impossible, to delete your account/data.
No _you_ don't.
Peers on the network may have this but there's no entity subject to GDPR.
So if GDPR tilts the playing field in favor of the megacorps, perhaps it also encourages anonymity and distributed networks.
If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our privacy as enforced by regulation or law.
And also including doing creepy things with our private data that stay just on the right side of the law.
You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and still be in violation of the law and subject to its penalties.
Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with. Your "MVP" has now expanded from "here's a simple idea I cranked out this weekend" to "here's a simple idea and a legal contract and audit trails that prove consent and an obligation to exfil data from my database on demand in perpetuity and data portability endpoints and data exchange contracts with every API provider I use and my database has to be encrypted at rest and highly redundant and I have to set up regular vulnerability scans and if I want to back up my database to a non-EU datacenter I have to obtain consent from all my users first and a bunch of additional requirements that possibly make it illegal to not age out my Apache access logs and why am I doing this at all again?"
GDPR significantly increases the friction for moving new ideas from concept to product, even if there is absolutely zero nefarious happening in the product. If it only made life hard on the people engaged in shady practices, there'd be a lot less concern over it, but that's just not the case. It doesn't just punish the misuse of data, it punishes the lack of proactive compliance to a set of criteria which are frankly beyond many hobbyists.
Some see this as a good thing. But I think that it's also fair to guess that it's going to cause otherwise good and benign ideas, products, and even entire companies to die on the vine as a result.
I would personally consider “not knowing where users’ data is, or being able to tell them” to be a nefarious act in itself.
For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.
In a jurisdiction. GDPR means a dollar can buy more MVPs outside Europe than inside. Keep in mind that this has no bearing on the privacy stance of the ultimate product. Just the fixed cost of iteration.
I hope it does. Europe, however, has a unique penchant for unnecessary bureaucracy. Nobody is complaining about GDPR’s requirements. It’s the ancillary administration which is destructive.
Companies have had years in which they were receiving warnings and recommendations for best practices - they ignored them. This is the piper coming with the bill.
I'm not saying "hobbyists shouldn't have to comply with the law", I'm saying "the law is disproportionately punitive to hobbyists in terms of burden imposed".
"Hey, I need to be able to query and delete data" is not a huge cognitive overhead when creating a MVP.
You have to be able to demonstrate audit trails of consent, including what the user consented to and when. You have to be able to demonstrate audit trails proving deletion requests. You have to have audit trails of who has ever accessed this data. You have to have a means to exclude pieces of your dataset from aggregate statistics on demand. Also, your audit trails can't contain PII because then your audit trails are in violation of the deletion requests, so you have to have mechanisms of proving that you processed deletion requests without actually identifying the data processed. You're also now obligated to respond to data inquiries in perpetuity, even to people for whom you have no data. Article 32 appears to impose a requirement for encryption at rest, high availability, disaster recovery, and regular penetration testing - all good things, to be sure, but completely impractical for the small hobbyist. Your "querying and deleting" is, by the letter of the law, now required to be a full-blown production-ready architecture with a business's worth of documentation.
And all because you wanted an email address to keep your login form from getting spammed?
I realize that in practicality, this is unlikely to ever be leveraged in any significant scope against most hobbyists, but the law is merciless and it is foolish to assume that you won't be caught in its crosshairs just because you weren't its intended target.
No, all this because companies were selling your email address to spammers.
Also, your reading of the law seems at odds with most other readings I've seen. I'm sure it will come down to a lawyer - but I'm also sure that hobby programmer who take reasonable steps won't ever be in the crosshairs of the EU.
You have to tell the user why you are collecting it, what it will be used for and for how long you will retain it.
If you are just using as a login and to confirm the e-mail is valid, there's not much else you have to do.
Oh - you want to use that e-mail for lots of other things, some of which aren't central to the running of the service the user's signing up for? Then yes, you have to document and enumerate those reasons and ask the user if they are OK with that.
Just saying "I'm using your email for signups" doesn't make you compliant. If it did then I doubt anyone would have a problem with it.
Other than to try and make the regulations seem more baroque than they are.
2. The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way.
3. One can use all that personal data well and not violate the rights of data subjects without being remotely GDPR-compliant.
4. Most of the administrative burden does little to nothing for how well data subjects' data is used.
I don't think this is the case at all. Essentially all personal data is sensitive.
The amount of personal data and the administrative burden are sometimes correlated, but often aren't. Collecting name and email from a few people in eighteen different ways creates a much, much larger administrative load than collecting name, email, and ten other items of information in a single way.
That's true, but also seems entirely reasonable. If you are collecting data in eighteen different ways, that means there are eighteen times as many ways you can fail to adequately audit or secure it.
One can use all that personal data well and not violate the rights of data subjects without being remotely GDPR-compliant.
Probably technically true, but in practice? Regulators are more concerned about compliance than anything else. Are there likely scenarios in which data is collected and processed in a responsible manner, but technical GDPR compliance is a huge burden?
Most of the administrative burden does little to nothing for how well data subjects' data is used.
Why would this be the case? Most of the administrative requirements appear to be entirely justified methods to ensure that you have understood and evaluated the methods of compliance.
Noooooo, not according to this or any other privacy law. Under the GDPR, it's "data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation."
> Are there likely scenarios in which data is collected and processed in a responsible manner, but technical GDPR compliance is a huge burden?
Yes. My company, and most companies of other privacy professionals I've talked to.
> Why would this be the case? Most of the administrative requirements appear to be entirely justified methods to ensure that you have understood and evaluated the methods of compliance.
If you think that any cost is justified to ensure that something that ought to be done is actually being done, sure. By any analysis of costs and benefits, I think you might come to a different conclusion, but that would require some kind of real analysis of costs and benefits. I haven't seen that from anyone who is both (a) a supporter of the law and (b) has actually spent time implementing it in a real, involved business that deals with personal data (and I mean actually implementing it, and not the absurdly simple version many HN commenters seem to be doing that doesn't include massive amounts of documentation).
Being able to provide a user with the data you have on them, and being able to delete it, should be basic requirements of any software company. And now they are, which is great.
I highly doubt that Google is pleased with the current situation as the article implies.