One of the sites on this list is the Aiken Standard. We're talking a local newspaper serving Aiken, SC - a city of less than 30,000 people. Even if an EU citizen (or someone traveling in the EU) cared about their local news, it's simply not worth it - that's not their audience.
> At the very least there are additional record keeping steps, policies and procedures to draft, the appointment of a DPO that responds to requests for access or erasure, and the development of the features to fulfill both of those requests.
* "Record keeping steps" are not needed if you don't keep records (which is what you should do);
* "Policies and procedures" are what you should already have, of course, and GDPR didn't change that in any way;
* A DPO must be appointed only if processing the personal data of your customers is your core activity;
* Developing features to fulfill requests for access or erasure isn't necessary if you don't keep records.
The Aiken Standard doesn't have to worry about GDPR just like a small town newspaper in Spain doesn't need to worry about complying with every privacy law that every US state decides to implement in the coming years (following in California's footsteps).
There is a vast misunderstanding of how jurisdiction works and how it's going to play out in the near future. The vast majority of the world will disregard GDPR and comply with their own local laws instead. Small and mid size sites from any given country are not going to attempt to comply with 407 different privacy laws from every country/city/state/region/zone/province/whatever around the world.
There is no alternative to this future. The sole, sane approach is to disregard Internet privacy laws if they do not apply to you in terms of jurisdiction. You will not be able to comply with the zillions of Internet-focused laws that are going to get created across the globe in the coming decade. GDPR should act as the training wheels for people building online sites/services/businesses to understand jurisdiction.
Even if you are independent and there's nothing the EU can realistically do to you, it's just one more thing you have to deal with. Figuring out WTF is going on, getting a lawyer to verify that there's nothing they can do to you, etc. etc. There are still some hard costs associated and it's going to distract you from what your company actually does for a while.
At the very least you still need a policy to give people telling them what data you keep and who you share it with. Even if that is nothing and no one, you need to be able to tell them that and you need someone who is responsible for handling those requests when they come in.
"Just don't keep anything" is not a sufficient answer.
No it's not. Stop spreading FUD.
If so, every part of every Internet-connected system on earth would be required to be completely redesigned to be GDPR-compliant. Demanding anything like that is not only unreasonable, it's 100% unrealistic.
The GDPR is perfectly reasonable legislation and has legroom for obvious operational requirements, like access logs.
(If you however mine the access log to derive or track users, that is another matter completely.)
So under GDPR you're not allowed to process data you've already got? I wouldn't call this reasonable legislation.
Furthermore, although IANAL, I suspect that certain classes of processing fall under different rules, therefore the processing could potentially be in violation even if the collection wasn't.
"I was just dumping data in logs, I don't have to care about privacy concerns. Oh, and now I have all this data on my server, since it's already here I surely deserve to process it without caring about privacy concerns!"
Might want to talk to a data protection officer before you go around swinging terms like FUD.
https://www.itgovernance.co.uk/data-protection-officer-dpo-u...
There is no exemption for small and medium-sized enterprises (SMEs), which has been reaffirmed by the Information Commissioner’s Office (ICO): "I've heard plenty of people talking about there being a DPO exemption for SMEs - this is absolutely not the case." Peter Brown, Senior Technology Officer, Information Commissioner's Office (ICO)
You need a DPO if:
* you are a public authority or body (except for courts acting in their judicial capacity)
* your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking)
* your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.
Imo, those are all pretty reasonable cases where you should have somebody responsible managing your data privacy. DPOs are for people managing very private data, or profiling people at very large scales. For most businesses, DPOs aren't relevant.
Even if you can avoid both of those you still need a point person who answers GDPR-related requests. Whether you end up calling that person the DPO (with the legal responsibilities and consequences that comes with) or just the "GDPR Guy" (also known as Ted from Accounting...) it's still something new you have to deal with, train for, etc.
That only applies if you illegally track users.
You know what a simple solution to that is? Yup: Don't illegally track users. Pure magic, I know!
It's simple arithmetic to decide it's cheaper to block all EU visitors.
They don't. They need to designate someone as the DPO, it doesn't have to be full time.
The DPO is a major imposition and simply being required to comply with the DPO parts alone is sufficient to make the EU not worthwhile for many businesses.
1. Whilst a DPO can theoretically be part time, a DPO is not allowed to have other roles in the firm that could create a "conflict of interest". This is so vague that in a company that works with data, almost any other role could be argued to create such a conflict of interest.
2. The DPO position has a list of mandatory responsibilities and even qualifications that will be accepted. For example the EU has advised DPOs need "expertise in EU data protection law". Where will foreign websites find such a person?
3. The DPO works for the firm but cannot be told how to do their job. They also cannot be fired or penalised for anything related to their job responsibilities.
In practice these rules mean it's very likely everyone will outsource the DPO role to third parties.
I think a large part of the scare that can be observed among American companies is due to legal advisers jumping on the opportunity to make big money by misleading their customers into thinking there are enormous, complicated and unlikely requirements for compliance, and huge risks to making any mistake.
The risk to making mistakes: fines of up to 4% of your turnover, in the worst case. As many companies have margins below this, it means losing all your profit for a year or more.
As for the rest, the vastness and vagueness of the GDPR has been extensively documented elsewhere. Bear in mind the EU Commission itself was immediately found in repeated violation of the GDPR just via their own website once the law activated. Their answer was that they themselves didn't have to comply with it.
* you are a public authority or body (except for courts acting in their judicial capacity)
* your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking)
* your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.
That's from https://ico.org.uk/for-organisations/guide-to-the-general-da..., which is a pretty good summary generally, from the UK Information Commissioner's Office.
If you're running an ad network building profiles of millions of users, then yes, you need a DPO. If you're storing extremely personal medical data, then yes, you need a DPO. If you're running an email newsletter, you 100% do not.
The EU has no jurisdiction over newspapers in South Carolina. It is that simple legally.
If I visit a random popular Chinese site, landing on a Chinese mainland server in the process, the US Government is not going to get to tell that Chinese site how it can legally use my data in their country. Shouting that I'm an American citizen and that they must comply with US privacy laws, will do no good: the US Government has no jurisdiction over the matter. It works exactly the same way for the US-EU-GDPR as it pertains to a newspaper from South Carolina.
You might as well apply the same premise to US vs EU vs Chinese (vs any other country) freedom of speech laws.
It's the exact same jurisdiction premise on how rights are governed, whether we're talking about privacy or otherwise.
Just because I'm an American, that doesn't give me US freedom of speech protections when I step foot into EU countries or Brazil or China or North Korea. I'm bound by the local laws on most things, with few exceptions.
You seem to not understand that one of the core principles of the GDPR is that the EU intend to enforce it in all jurisdictions. Which they can do without an armed invasion using trade treaties, and instruments such as the New York Convention. For any entity anywhere in the world that doesn’t do business in the EU, blocking the entire union is the most risk averse and cost sensitive option.
The risk to local newspapers is low for now, but comes from the possibility of future agreements by the USA to cooperate with the EU on GDPR enforcement (e.g. as part of some trade deal), or their executives going to the EU for a business trip or holiday and coming under jurisdiction that way, or selling or wanting to be sold to a firm with EU presence, etc etc. Lots of ways the EU can end up with leverage over an apparently small and local firm.
Just like the US does not have the ability to dictate to China what privacy laws look like in that country or how US citizen data is managed within that country (eg when I visit a Chinese site).
How could any this possibly be difficult to understand?
If South Dakota comes up with its own crazy privacy laws, that doesn't mean it gets to actually "assert" how EU sites must manage data for people from South Dakota. It doesn't matter how much South Dakota screams about it, that state has no power to dictate anything to the EU. You would only have to particularly worry about it, as an EU site, if you were eg hosting a server in South Dakota, or doing business there.
edit: replying to your comment below, because my replies are throttled
It is in fact how jurisdiction works today and yesterday and always. The exceptions require agreed upon, established laws between the parties that say otherwise, which you just admitted is the case by referencing FATCA as an example.
Look at FATCA. A US law that every financial institution in Europe has to comply with whether they like it or not.
The EU knows it isn't going to invade the USA. Nonetheless, it has explicitly asserted many times that everyone, globally, is expected to comply, regardless of whether they have any EU corporate presence or not. Why do you think they would do that, if they aren't intending to find ways to make it enforceable? And there are certainly many tools available to do that with that aren't military in nature.
Given how US techies here on HN seems to constantly overreact and loudly proclaims how the GDPR means they need to hire 20 new employees and how they all will be suited into bankruptcy anyway...
If they are now stuck in a needlessly rigid legal regime, it's hard NOT to say they brought it on themselves.
So you block access to your goods/services/website to EU IP addresses. Your suppliers and service providers are happy, your legal counsel is happy, and your business is not impacted in any meaningful way at all.
I haven't looked at the sites on the list, which may well contain "shady" websites, but bear in mind that these are the entities who have looked at the GDPR and concluded it was somehow or other better to expressly tell visitors that they do not comply with the GDPR.
A shady business wouldn't even bother putting a notice up on their website!