GDPR fines were meant to rock the data privacy world
wired.co.uk
wired.co.uk
It's just that the current privacy abuses of software companies are so complex and egregious that it takes a long time to sort things out.
Essentially every US company was doing things wrong for example. Just the other day I was reading LinkedIn's cookie notice which can be paraphrased as "accept our tracking commoner". And this is a bug company owned by MS, the new heroes of open source (and spyware).
It's the wild wild west out there.
Austrian Post sold voter preference data without having the right processes in place and was fined 10% of last years profits.
Noyb.eu is also an interesting organization to watch. They are a non profit taking lawsuits against large incumbents with egregious privacy practices with the backing of the GDPR. They triggered the 50 million € Google fine.
A lot of businesses (big and small) were getting too cozy with collected data. With little regard to what was being collected and how long it was stored for. GDPR forced businesses to take a hard look at their data and ask some difficult questions, and I genuinely believe it has changed the way people look at data.
Personally, I was professionally shocked to find how some businesses dealt with data - If anything, GDPR forced common sense down some technologically inept management teams.
At this point, I might see one or two lines of text for a news article on initial load between their gommy sticky header, a couple of ads, and their "We're using cookies here, if you don't like it, go screw" popup. Of course that's assuming it's not paywalled.
The net effect of the GDPR, from my perspective as a user, has been to make the internet even shittier to use. There's also the developer side that I have to deal with, but to be honest, after an initial flurry a year or so ago, nobody even asks about whether the software we provide is GDPR compliant anymore.
The privacy options we suddenly ot from large companies from companies such as facebook were unheard of before GDPR.
It have already drastically changed how the world handles data, but it is a slow process. It will take decades and more work.
Massive success all in all, thanks to GDPR there is now hope for the future.
https://www.cookielaw.org/blog/2014/2/5/spanish-cookie-law-f...
Sending tracking information to third parties required a notice of some kind, no matter if it was in the form of cookies or some other mechanism.
So, no there was never a EU cookie law, it was just a major FUD operation and a lot of people put up completely unneccessary cookie consent popups without understanding why.
Older systems which depend on having PII and even financial information as cleartext in the database are the problem - and its essentially technical debt with far-reaching consequences, so no-one will fix a system that uses tenants’ customers’ SSNs as a primary-key (yup).
I have tried to explain so many times that this system needs to be replaced urgently not for security reasons but because no one actually knows how to use rails 1 anymore.
If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then they'll likely be outcompeted.
But that's exactly what we do. The health inspector doesn't come to your home to verify that you wash your cutting board, even on the day you have a dinner party to entertain business clients. Depending on local law you may or may not be expected to follow the same rules as McDonalds (getting a food service license etc.) when you hold a high school bake sale, but people commonly don't actually do it and governments commonly don't actually enforce it in those circumstances.
Because it's more important, and justifies a higher compliance burden, to ensure that the company serving billions of hamburgers isn't giving people food poisoning than the individual serving four.
Then what does it actually do?
Not all of them. Especially not "I'm pinning a note with the phone numbers of the parents of my daughters friends to the fridge".
As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes.
And then the phone number is not shared with the public, but stored at a secure location (fridge) having organizational (family rules) and technical (locked doors, windows) policies in place to secure the information.
Given the required security level for a __single__ phone number I would say this would be a reasonable level of caution.
So what happens if you got the phone number from your friend's sister? Or off of caller ID?
> As it's really hard to use a phone number for anything else than phoning someone, we can also reasonably say that the data is only used under the originally stated purposes.
There are lots of things you can do with a phone number other than phoning someone. There are services that effectively use phone numbers as usernames, you could give it to them to see if your friend is on that service. When your new girlfriend asks who this number on the caller ID is you can tell them who it is (disclosing it to them). You could store it on your computer which gets backed up to some random cloud service in the US. That's all common human behavior.
> And then the phone number is not shared with the public, but stored at a secure location (fridge) having organizational (family rules) and technical (locked doors, windows) policies in place to secure the information.
The scenario is that it's also being posted to a public blog.
> Given the required security level for a __single__ phone number I would say this would be a reasonable level of caution.
Is it more common for a person to know a __single__ phone number, or have an address book full of them?
You're looking for the case where by coincidence it happens to not be a violation. Even if you find it, that doesn't help anything if accidental violations remain widespread.
I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email addresses or first names then that should be far less strict than if a company handles medical information, home addresses or credit card information.
On the other side, we should have audits in companies to see how the personal data is handled. Particularly in ones that deal with sensitive information.
Two things occur to me here.
1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit.
2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ (first search hit).
> here should be some exceptions to it for small companies
This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.
Except that foreign companies won't have this same limitation. The end result is that all of your online services will be provided by foreign companies, which ironically is already the case in the EU.
A foreign company that's beyond the jurisdiction of the EU can abuse GDPR as much as they want. If they get caught then they'll just lose their business. The EU can't actually fine them, but that same company likely outcompeted EU companies for years.
>This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.
They can do the same thing with foreign companies though. If you can set up a system where you would use your small companies to escape regulation, then the same can be done with companies run by foreigners.
>2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ (first search hit).
And said business opportunity is additional inefficiency on businesses in the EU that their global competitors don't have to follow.
The point I'm trying to make is that if you have European customers, then the GDPR applies. Therefore, "foreign companies" competing for EU customers, definitely do have this limitation. Fines have been issued for companies that don't comply, and the sizes vary immensely (e.g. over 200 million euro for British Airways down to 118 euros (not millions, 118) for the Data Protection Authority of Saarland).
Or do I have it wrong and that there is an enforcement mechanism that can make a Chinese company do things the EU says?
The EU can't force a foreign company to pay, just like China can't force an American company to pay. Or am I mistaken and there's some international agreement that allows the EU to force them to pay up?
The simplest way to comply is to not obtain and store personally identifiable information at all. Luckily this is also the cheapest. So I don't really buy that you "cant afford to do it right".
If you want to obtain and store personally identifiable information, then you have to mange it properly, just like selling food, medicine, financial services etc. need to follow certain regulation.
Note that all the competitors in the space will have to follow the same regulation, so it is not like it put you at a disadvantage.
I'm not sure if we have passed the line of too many regulations, but I know it's out there.
In the end whether a penalty is just depends on the significance of the offense and whether the bad actor has reformed. The GDPR does give regulators discretion over whether to issue fines or take legal action, they don't immediately wreck people.
People need to remember that while laws are very rigid in drafting, they typically grant a lot of flexibility to the humans that enforce them... and humans often just opt to ignore them. So you can't just look at the law in terms of what it appears to read as, you have to also look at how it's applied in the real world. That can of course mean that a law like the GDPR has unintended negative impact, but it also means that sometimes the impact is not the negative you'd assume from reading it.
Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. This can be seen by the constant consent popups on every website. Users click yes on the major sites, then deny the rest.
I feel the opposite may be true. When the law came to pass, I took some time to review my privacy options on Google and Facebook, since they are a big impact for me.
On the other hand, when I click on a link on HN to some random news paper, and get presented with a five-step process to start to see my options, I don't usually bother and dismiss it as soon as I can, probably with some 'opt-in' consent. Since I'm not planning on viewing the site again, I consider it a minor annoyance.
Dumping toxic byproducts in the river. Forcing employees to work unpaid overtime. Keeping fraudulent books and evading taxes. Selling illegally dangerous products. Not following local building codes. Facilitating third-party fraud or money laundering...
Being a small business should not be license to do whatever you want, irrespective of the harm to customers, business partners, or others in the society.
In the case of data protection specifically, companies (perhaps especially small companies) are very cavalier with all sorts of data including personally identifiable information, financial information, communications, ...., and this causes serious harms when that data is misused directly or stolen by/leaked to/sold to someone who misuses it.
If a company cannot afford to stay in business while treating data carefully, then perhaps they should not be in business.
So what you're really saying is, if a company cannot afford to stay in business while navigating a legal framework designed for companies the size of Google, then perhaps they should not be in business. The result of which would be to have only companies the size of Google.
No small company has to pay lawyers to validate that they are complying with GDPR. It’s just that if it turns out they weren’t, the fines for violations can be quite steep, so a risk-averse company is going to be proactive about it.
There are many types of regulations which are much stricter with more up-front costs than GDPR, which companies of every size manage to cope with (or sometimes don’t, and go out of business). The technology industry has just gotten used to not being held accountable when it harms people, so now that some sensible consumer protection regulation comes down (some) people are freaking out.
I don't think anybody disagrees with that. All regulatory burdens harm small businesses -- which is why they should all be minimized to the greatest extent possible.
> No small company has to pay lawyers to validate that they are complying with GDPR. It’s just that if it turns out they weren’t, the fines for violations can be quite steep, so a risk-averse company is going to be proactive about it.
And investors are risk-averse, so investors want to see compliance, so they're forced into the choice between going out of business due to the compliance burden or going out of business as a result of an inability to get investment without showing compliance.
> There are many types of regulations which are much stricter with more up-front costs than GDPR, which companies of every size manage to cope with (or sometimes don’t, and go out of business).
Two wrongs don't make a right. Nor do a hundred.
> The technology industry has just gotten used to not being held accountable when it harms people, so now that some sensible consumer protection regulation comes down (some) people are freaking out.
The technology industry is Intel and Samsung. Chips rather than bits. Plenty of regulation there -- environmental, patents, government contracts, etc.
But now we're talking about regulating information. It's not a particular industry, it's a thing all people do all day long. It's regulating people talking and writing stuff down. The number of people subject to whatever burden you impose is effectively everybody, so the burden inherently has to be small or when you multiply it by everybody everywhere it becomes an absurdity. If it's too complicated then either nobody complies with it and it's useless (and dangerous) or you crash the world by making everybody try to.
Compliance cost at the place I work in the UK was negligible. We have personal data on every customer, had to make some one time code changes, and ongoing costs are essentially zero. Frankly, compliance was trivial and little different to Data Protection - which was also trivial to comply with.
If you're data mining everyone to death and selling it off to multiple unnamed third parties, compliance may well be more challenging. Hardly surprising as that's one of the things it's trying to constrain.
Are users any better off now because those companies got fined? Did those companies stop collecting user data? Has online privacy improved because of those fines? Nope!
It may be that most users consented, but I think the take away from that should be that most users do not consider ads personalization a significant violation of their privacy.
Yes
>Did those companies stop collecting user data?
Maybe not google so much, but other companies certainly stopped or collect a lot less. And it's still early, and there is plenty of low hanging fruit for GDPR enforcement to hit.
>Has online privacy improved because of those fines?
The full effects remain to be seen, but yes, it has improved. Maybe not for you, but for me it certainly has, in particular with German businesses I use.
Aside from regulations, it also fueled and still fuels public discussion, especially in the tech space. Where half a decade back everybody would have ignored e.g. GitLab's email informing users and customers that they are going to roll out third party tracking, but this time around the backslash was so swift and hard GitLab went back to the drawing board (goof for them!).
On top of that, the EU inspired similar laws around the world including most the (somewhat lenient) California Consumer Privacy Act that comes into effect next year.
I might be tempted to agree, but the impact was all too predictable.
In general, complying with regulations often has economies of scale.
No, fuck small companies playing fast and loose with other people's data.
The smallest and weakest is not the small company or website operator, but the individual consumer, aka me and you.
Complaining that your small startup cannot collect and sell data nillywilly is like complaining that you can cannot run a startup from your garage that sells homemade miracle cancer vaccines you have vicariously tested, but only on stray cats in your neighborhood.
On top of that, the actual big fines so far for the most part targeted big and/or well-established and/or serial abusers. The small companies only have been "inconvenienced" in so far that they now have to think about what data to collect, about how to collect it and how to get consent, about whom to share it with and about how to store it reasonably secure. Something they should have done in the first place.
It's not rocket science!
Opt-out is typically covered by a ton of shady UI patterns, so it is hard to do this. Another clear violation of GDPR is punishing those who does not agree for tracking by serving them crippled content or no content at all.
And just to make it clear: I am strongly against extraterritorial laws like GDPR or FATCA. US does not have any rights to enforce their regulations outside US, similarly EU does not have any rights to tell people outside EU how their websites should look like. This is clear abuse of the economic and military power that US/EU have.
GDPR has some good points (like PII data storage rules), however some of its regulations, like the once that force open forums to provide "right to be forgotten" for posts, are pure crap.
The unfortunate vagueness of this regulation does not help either - real live example from Poland: if school teacher takes home pupils copybooks, which are signed with a pupil first and last name, does this mean that GDPR rules apply to the teacher (getting consents, proper handling and storage for copybooks, etc.)? Some lawyers claim they does not, some say they does, some have no idea. As a result in some schools pupils are forbidden to sign anything that enters the school building with a full name... Overreaction? Probably. But you never know when some mean parent would want to use GDPR against the school.
I don't see why your example from Poland is bad. Teachers are now thinking about the privacy of their pupils - this is mandatory in today's world.
I don't see how you could possibly claim that this is a kind of automated processing or a structured filing system.
So it's another example of fear without knowing the basic principles of the GDPR.