Show HN: Ship Your Enemies GDPR
shipyourenemiesgdpr.com
shipyourenemiesgdpr.com
The arguments brought forwards against GDPR tell you probably more about the author than the regulation if Jerre's only concern is with the potential costs for businesses. That may be news to some, but the maximization of company's profits is not a value in itself or should be the goal of our societies. Otherwise, we wouldn't have safety/labor/product standards regulations, such as OSHA. Instead, ensuring human rights, such as privacy and data rights, (and a high quality of life) should be our concern - and that can cost companies - slavery would've been a lot cheaper too.
It speaks to a certain discourse prevalent in Silicon Valley and among business owners. The main source has been pretty well counter-argued in the original thread [1] but the author rather parrots that misleading information.
We need a median amount fined to non-complying organizations vs. median amount spent complying by complying organizations.
That's how regulations protect public interest.
Honestly, it's crazy—HN is the only place I see this kind of anti-GDPR stuff. Everyone I have talked to about it sees it as a huge positive. I include myself in that by the way—being able to get (and delete) my data from providers reliably is a huge positive, and it has clearly improved the way my data gets handled a lot of the time. The cost is relatively small.
1) People who think any sort of government regulation is pure evil
2) People who read the opinions of the first group and assume that because it was said on HN it's correct
3) Adtech startup devs
4) People who really hate not being able to hoard personal data for no reason
5) People who think money is significantly more important than privacy
It's not... You cannot enforce GDPR on any person / company who doesn't have a presence in the EU.
That annoys me, because _although I'm willing and do comply_ many people reach out to me regarding their personal data with a lot of arrogance. However, my company isn't based on the EU and I don't have to comply (which I cleared with a lawyer already). Their method of their approach makes me not want to comply.
Not true, I am not required to not offer to EU citizens. They simply can choose to visit my U.S. servers and use U.S. dollars.
Laws aren't global. Laws are based on jurisdiction. EU doesn't have said jurisdiction, unless I am hosting services or have a presence in the EU. Customers from the EU effectively travel to the U.S. (via the internet) to get to said service. The U.S. could force us to follow EU laws, then sure. However, that's not the case today.
You can think of it as: if I call a vendor in China to purchase some widgets. The vendor in China is not required to validate you're following the laws of your land - that's your job. The Chinese vendor just needs to make sure they are following China's laws.
Read this article for more details http://www.mjilonline.org/fines-under-eu-gdpr-in-non-eu-juri...
There is a difference between a 5 person biz like bear notes who would be totally cool in deleting your login info on request / sending whatever small amount of data they have on you, and what they actually have to do be properly compliant with GDPR. They are probably not and they, like many small EU software business, are a liability waiting to happen.
Also this kind of legal DOS is almost definitely against the spirit of the law and I’d be surprised to see any real company use significant resources to respond.
Small businesses are still, for example, subject to abusive SARs of the kind used for illustration here. They're still required to write documentation like privacy policies according to the new standards. And unlike large organisations, where there is the 4% cap on fines, a small organisation faces an existential threat if regulators decide to impose heavy fines, which they have considerable powers to do.
Defining a surveillance capitalist company without BS is difficult although, so in the end, I would probably just wholesale exempt private small businesses that are not subsidiaries of larger ones. The small businesses would need to be arms length from larger ones too.
A lot of the danger of surveillance capitalism come from concentrated power, and many small businesses are by definition the opposite of that.
The data is the same, regardless of who collects it. Leaking it is equally dangerous.
You know what makes it really easy to comply with the GDPR?
Stop spying on your users.
Just stop.
It infuriates people precisely because it threatens the ad surveillance economy this whole website and most of its users have come to rely on. Consistently, the sites I've gone to with the most intrusive and aggressive complaints and reactions to GDPR ... are also the sites that are riddled with spyware and tracking.
It is very much a case of "methinks thou dost protest too much."
If you are dissatisfied with a government agency, it seems counterproductive to deliberately make them operate less efficiently. This attitude seems like it would just reinforce an endless cycle of inefficiency and dissatisfaction
On the other hand you are right in that it helps do other stuff that does benefit me, I just don't notice the benefits as much as the harm because the harm is direct and the benefits are societal.
I suppose you could make it a bit worse by asking to see the information collected - then simple copy-paste will be insufficient, they will have to run a script as well.
Please post the name and address of your data protection officer.
> To show that GDPR is fucking stupid. Really, have a look at these crazy stats after 1 yr of GDPR:
~$60m in fines
compliance costs for US firms estimated at $150b (2500x fine amount!)
small co's hurt more than large. GOOG actually benefits!
VC $ invested in EU startups drops significantly
Is it redundant to say that this characterisation seriously misses the point of the legislation, and that this is a lot of trouble to go to just make a childish nuisance?For example, draconian drug laws have great intent but horrible externalities - so much so, that even though I'm vehemently opposed to recreational drug use, I'm now sympathetic to treating it as an illness and not as a crime.
I'm a critic of the GDPR, yet I'm also a big advocate of stronger privacy protections. I see no conflict here, because my criticism isn't about what the GDPR is trying to do, it's about what it actually does.
I'm glad to see surveillance companies suffer.
That's rather the point of the thing.
That does not make the right to such requests stupid, and it's annoying that there are people that abuse it and risk getting it watered down, thereby removing all positive effects. (Such as the effects those fines and compliance costs have on civil liberties.)
This assumes they can even do so; if there are national regulators who hold the same opinions that some HN posters do about Google and Facebook, there may be no definition of "undue burden" they are willing to accept.
> Do you have a list of said sites?
You are the one who claimed that all sites required to implement GDPR are privacy abusers. Do you have a list? In my country we adhere to the concept of "innocent until proven guilty" and we don't keep lists of innocent websites.
How do you automatically comply with a free-form letter sent via e-mail or, even worse, snail mail? You need one or more humans in the loop to identify these requests, even if it is just to send a canned response back.
You can have thousands of people send GDPR requests. Each person will take at least half an hour to print, compose, wrap and send letter. And someone at the company will take under a minute to reply to each one, because all they'd need to do is a quick scan of the letter, then send a pre-printed response.
Not all websites are ran by huge companies. Actually, most are not.
The point of this site is that there is no composition. Just print, address, and send if you want to snail mail. If that takes you half an hour, I don't know what to tell you.
> And someone at the company will take under a minute to reply to each one, because all they'd need to do is a quick scan of the letter, then send a pre-printed response.
Under a minute to 1) identify the letter and the sender; 2) pull the correct pre-printed response; 3) address and send the response? How does your hypothetical employee do this so much faster than your hypothetical private citizen?
The real ones to be worried about are the usual 'do no evil' suspects. They already have all the data.
Small companies dealing with their first request likely have (at best) a manual process that will take many hours of someone's time to process.