It'd be nice if this was unified but it ain't because:
1. Tech companies lobby like hell at a national level
2. The national government is sort of broken right now
so that's how the cookie crumbles. The fact that a number of companies have skirted local regulations and abused data usage so much is why this is happening, so don't blame the victims of this activity that want sane privacy laws - blame the bad actors that have forced this issue to need to be dealt with.
There's a special hell that exists where one state mandates records must be held for at least seven years and another mandates deletion at five. When the two states border one another and you may not have home addresses, how do you determine how to comply for a given user?
You're absolutely right, in every way, that tech companies have brought this regulatory backlash on themselves. Yet, it might still be worth considering the potential costs.
1798.145. (a) The obligations imposed on businesses by this title shall not restrict a business’s ability to: (1) Comply with federal, state, or local laws.
Now I wonder what sort of dance would occur if, in your example, both states' laws had such a clause.
If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.
Does this outcome make sense to you?
(Disclaimer, I have worked in adtech a little bit, but I have worked a lot more with A/B testing.)
It's not so straight forward as you make it seem.
PII that you don't need can become like radioactive waste. If it gets subpoenaed, and it comes out that you retained and produced it, your reputation may be hosed. But if there's nothing to produce, no problem.
That's actually not quite correct. If you're required by law to retain that PII, you'll be hosed if you can't produce it. But then, maybe you should be doing business in a different jurisdiction.
I'm thinking of Private Internet Access. To my knowledge, logs have been subpoenaed in two US criminal cases. And they just said that they didn't retain logs. But then, VPN services aren't required to retain logs in the US.
That's pretty ambiguous. For example, I'm pretty sure everything Google does that can be considered against privacy can and is tied to the service they provide as features. The fact they keep a history of everywhere you went to can be used by users to recall the locations they've been too. That Google keeps one's contacts can be used in case you lose your phone and get a new one. That Google uploads your voice to their servers is to improve their speech recognition. All privacy violations can be made "essential" by tying it to a feature.
Edit: And they can always offer more. With clear explanation of what information they'll need to retain. And users can either accept, or decline.
They also remember your searches to provide personalized results, and many people do like that.
> Anything else is clearly extraneous.
Isn't the point of a business to provide the best product or service they can (for the price they ask)? What's the point of a business that does the bare minimum? How are they supposed to compete?
In any case, the point is that it's not as clear cut to know what violates privacy and what doesn't. To tie it back to your original comment:
> The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.
They aren't necessarily going to be the same. What is to respect all users' data? There's no concrete consensus on what violating privacy consists of. Is saving searches for personalized results consistent across personal devices violating privacy? Some will say yes, others will say no.
Also, if you err on the side of caution and avoid providing features, you're going to lose edge. It seems to me that it's very important to a business's survival to know where the borderline is.
That's why I would agree with rdlecler1 that
> a small startup needs to ensure they comply with hundreds of regulatory jurisdictions
if they want to have a chance for survival and peace of mind that they aren't even technically guilty of anything in any one jurisdiction even if in their own eyes they did everything to respect their users' data.
The internet probably wouldn't have gotten as big if it weren't for the fact that it's largely lawless. If every geographical region makes their own regulations, only big world corporations will be able to comply.
It's not for the operator of a website to decide what is an invasion of _my_ privacy. It's for the consumer to decide. And that's precisely why we can't rely on website administrators, or the "recipients" of data to determine whether something is private.
I'm one of those website administrators who wholeheartedly welcomes something like GDPR here, even though it would make my job harder. But hey, that's fine. Putting privacy back in the hands of consumers is the right thing to do.
It sure does to me. So much so that if it happened to me, I'd be sure to never buy from that site again.
I was on a web site with several items in the shopping cart. I went to the bathroom on my way into another room of the house to get my phone to make a payment on my credit card so I could make the purchase. When I got to my phone I already had one of those abandoned cart remarketing e-mails from the company.
I went back to my computer and closed the browser tab. No sale, creeps.
Bummer dude. As an engineer type, I say, bring it on. Hard for me to have much sympathy ZuckerBrin can't afford another island or whatever because they made unethical decisions in the past. And if companies blow up because of it: good, that's the idea. There needs to be consequences.
Boohoo and cry me a river. Good riddance. Other companies who take care of customer data from the start will take over.
> It's government dictating the technical architecture.
No, the government doesn’t dictate technical architecture. The government dictates: be careful with personal data.
Our idea is that complying w/ data security & privacy laws should be a devops shift + costs to keep up w/ them shouldn't stop us, as developers, from keeping us just as productive in our application development lifecycle.
We're still trying to figure out the right pricing structure for smaller companies, so if you have any insight there, I'm very interested to hear it.
Yep. And there's nothing wrong with that.
That they may suffer a large expense to correct years of misbehavior doesn't make me sympathetic to them.
This harkens back to the GDPR hysteria. And that was a storm in a teacup: most companies that took compliance seriously were able to get to a good place with a medium amount of engineering work, and didn't suffer financially overmuch. A few companies did go out of business or suffer significantly--and most of those were sketchy, data-abusive entities. In other words, it worked.
Anyway, the only companies that will end up being able to collect data at all are there very biggest ones. Everyone else will have to just fly under the radar or use some kind of SAAS solution to comply with the patchwork of regulation. Not sure that’s really the desired outcome
Do they really believe that, though? I always thought they were just thinking it was just legal cover to allow them to do whatever they want with the data. Respect doesn't enter into it.
That said, almost all EULAs and privacy statements I've ever read have not been forthcoming about the use of data. They usually state, in broad terms, that they'll share unspecified user data with mysterious "partners" for nonspecific reasons.
But being privacy respecting and properly complying with GDPR with audit log systems, etc are 2 different things that require hiring 1 or 2 extra engineers or causing them to pause the companies roadmap as 1 or more people implement government bureaucracy infrastructure for half a year.
If they say it's easy and cheap, then they haven't actually tried to do it properly and are exposing themselves to multi-million dollar penalties.
[0] https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...
Take the data deletion requirement. I know of many instances where users have permanently lost absolutely critical data because of that provision (already found in other privacy laws). When a user (accidentally) indicates they want you to delete their content, the provider has to permanently delete it within a reasonable timeframe, including purge from all backups.
Most users don't give a flying f'ck about all this privacy BS, but they care very much about what happened to their Master's thesis. They want a company who will be able to rescue them from their own mistakes. They want dependability. But they get "privacy" instead, and their accidentally wishes that you purge all their stuff gets obeyed.
Maybe you call that progress. But it really sucks when you purchase vague hypothetical benefit at the cost of real-world misery.
I admit it was vague phrasing. All I mean by respect peoples' data is to recognize that people should own their own data. You should get explicit permission before collecting it, using it, selling it, etc. At any time it should be just as easy to remove the data as it was for you to collect it.
As for any data deletion, I think it makes sense to have a strong warning any time a company has files that the user themselves have uploaded. Perhaps even listing filenames and folders to remind users what's there.
As for every country making their own laws - well, yeah? That's what sovereignty is all about?
This case follows the same pattern: whatever meager privacy protections in place at the Federal level will continue to apply, but California law will take precedence in the case where it's stronger.
There are certainly exceptions, like how currently Trump and the EPA are attempting to disallow CA's higher vehicle emissions standards, but, again: exceptions. (In this case, the relevant law has specific language that makes the EPA the final authority on this sort of thing, and requires states to get waivers for going their own way. That's not a general, common thing, though.) And I expect that bit to be tied up in court for a while.
https://www.law.cornell.edu/uscode/text/29/218
That's an exception that's written into the law, while federal preemption is the usual rule.
In this case I don’t think there is a national privacy law that preempts CA, but companies are lobbying now for one to be created. I think it would be a good idea, a national sales tax and a national privacy law are a natural fit for the Internet age - needing to know different laws and regulations for 50 states is only going to hurt small businesses and startups.
FTA:
> Since the law passed, tech giants have pulled out their last card: pushing for an overarching federal bill.
> In doing so, the companies would be able to control their messaging through their extensive lobbying efforts, allowing them to push for a weaker statute that would nullify some of the provisions in California’s new privacy law
Funny enough, the emails sent by these companies are not GDPR compliant and they’ve given me no indication as to how they gathered my info, nor do they give me an opt out.
Maybe helpful - http://euro.ecom.cmu.edu/program/law/08-732/Jurisdiction/Lon...
If your business operates well above board and is not doing anything close to what might be the danger zone, then you should have nothing to worry about.
It's always the folks walking right next to the cliff complaining about how complicated their path needs to be.
The startups end up either (1) ignoring the laws or (2) giving up.
Good job EU, if making the FAANGs the only companies with the clout to hold customer data or break into new markets was your primary goal.
We've already seen non-adtech companies simply shut down EU access if they don't have enough revenue. That's probably not a good thing.
I support the GDPR, but complying with it is far from simple and the jurisprudence is not yet clear.
That's debatable. I imagine that many EU residents who are tired of having their data collected and sold by US companies consider this to be a very good thing.
It also means that an EU-based company can come a long and fill the void left by the former incumbent that doesn't want to play ball, which is likely good for the EU's economy.
Maybe it's not good for the US company, or for the US economy, but the EU (in theory) exists to further the interests of EU citizens.
As a California resident, if the same happens with the CCPA, I will not shed a single tear.
Until that game you like simply shuts down in the EU. Or until that website you visit simply blocks all EU access.
Just because someone can't prove they comply with the GDPR doesn't automatically mean they aren't in compliance.
You've added a bunch of friction to the little guys in order to punish Google, who won't really notice. Maybe you agree with that, maybe you don't. But you have already made that trade whether you like it or not.
Why not? Serious question.
Soooo I kinda suspect you're talking with absolutely no first-hand experience.
Additionally:
- before GDPR most EU countries already had similar laws (e.g. data protection laws in Sweden). Sometimes for decades
- GDPR gave two years to become compliant
All in all everyone had two to twenty years to become compliant. Those who didn’t? I personally wouldn’t give two shits about them.
Your expense management software? Well, you company chose it. It looks like your company are responsible for making sure that the software you use is GDPR compliant. Someone at your company and at FROSCH screwed up and now you blame GDPR for the screw-up.
Also: is this your line of reasoning? It’s really weak. To take it to extremes: “we’re still using asbestos and lead pipes because the legislation was nonexistent when we started using them”.
Collect no information. Share no information. You are good - everywhere. And that really ought to be the default behaviour..