It's forced us to think more carefully how we build systems to pick up, retain and scrub data. So all clients (>1,000) and their clients (likely in the millions) have benefited
They absolutely won't have noticed a difference - by design!
Unbeknownst to downstream users, there are now more rigorous systems in place to manage this information and reduce the surface area where it might be captured
Almost all clients took an honest look at data collection and retention policies.
Data was classified and tools built around the GDPR framework to allow customers to be able to fully retrieve, request changes to, or delete their information from servers.
Most clients ended up collecting less data and retaining it for a shorter time.
All in all from my perspective it seems the law did much of what it was designed to do.
Many of these companies didn't have consent to have the data to begin with or at least no way to show that they collected it.
A good example is Wetherspoons Pub chain dropping their email database they used to spam people with. I've noticed I'm not caught in any more breaches according to Troy Hunt whilst before I was getting my email breached once a year by some company. According to Troy Hunt's breach DB, over a dozen companies with my credentials have been breached forcing me to never use those email/password combinations again.
But the real benefit is this:
Some random online store that i bought something from once decided to send me a spam sms around black friday.
One email and 24 hours later, all the data they had about me was deleted.
Of course, this only works if you're in europe buying from an european store so they're subject to fines from some trigger happy privacy authority.
Assholes like Google still do not ask for consent. Guessing someone at the EU is working on gathering a mountain of documentation so they can fine them that famous 4%.
If I take no action, accept the default conditions and don't opt out of anything, then that must be interpreted as me not granting permission to anything - there are a bunch of data use-cases that you're allowed to do without my consent, so you don't need the popups for that, but otherwise no informed explicit affirmative action means no consent.
What I find strange is that google's army of lawyers doesn't seem worried about this.
> One email and 24 hours later, all the data they had about me was deleted.
You make it sound as if this is new, but this was also possible under the DPD from the late 90s. GDPR didn't improve that. (What helped is that GDPR isn't from the late 90s but was introduced in a year where privacy was already a hot topic, so it was picked up by the media and now companies actually know about it so you don't have to point out the law before they understand what you're talking about when you do an access/deletion request. But it technically hasn't changed.)
> this only works if you're in europe buying from an european store
Sort of. While the EU claims it applies to anyone, the Chinese government isn't going to give a rat's ass if you sue and win a court case against a Chinese company. However, if that Chinese company has assets in the EU, they can be seized, not to mention that they can probably be banned from the EU market altogether.
Anyone who wishes to continue selling to Europeans and not have any European assets seized would do well to comply with European law, also if their headquarters / choice of court / assets is/are outside the EU.
GDPR did improve it. Under the implementation by member states of the DPD many required that you can show "duress and/or distress" from continued processing to request erasure. GDPR made it so you don't have to show anything, you can just request it (or, more technically, you can withdraw consent).
And the DPD only said:
> as appropriate the rectification, erasure or blocking of data the processing of which does not comply with the provisions of this Directive, in particular because of the incomplete or inaccurate nature of the data;
Organisations often took a very conservative interpretation of this which wasn't enforced differently by many DPAs in EU states. GDPR Art. 17 is definitely stronger.
Google do ask for consent where required, but consent isn't required. There's various legal bases for the processing of data according to the GDPR (including for the performance of a contract and for legitimate business interests). Google just invested more in lawyers to use the GDPR strategically so they would have to change as little of their processes as possible.
Companies that don't understand the GDPR or privacy spent a fortune on consultants that milked them for money. Such companies seem to think the GDPR is a doomsday weapon and a revolution. It really isn't.
However, in the organisations I have worked with professionally, GDPR is absolutely working - user data collection, storage and security is now a leading conversation - whereas it was a afterthought before, at best. Of course, this isnt generally visible to the end user, and there are undoubtedly still businesses who ignore this - but i guess we wouldnt know unless there is an incident - in which case I would expect the EU to come down HARD.
I think its web-tracking and marketing in particular that still needs fixing.
GDPR has to do that if you provide your phone/mail to some shop or other service they can only use it to contact you with information directly related to their business, like processing your order etc. They can not send you marketing stuff unless you explicitly consented and must remove you from lists if you ask. Even delete your account if you ask (not the data tho).
On data removal: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Personally, I barely receive any out of the blue marketing calls or texts anymore. If someone dubious market’s me via phone or email, I know my rights and I can follow how they acquired my data and who sold them my personal details.
As a software developer/entrepreneur, it made me think more about personal data and has affected my architectural decisions.
That's strange, as anti-spam legislation is completely separate from GDPR and has been in place for much longer. The only connection I see is that data brokers got a harder time selling your data to these third parties that would call or text you, but what those third parties were doing was already illegal and still is for the same reason (so not because of GDPR).
In the Netherlands it hasn't been legal to cold call someone that opted out of cold calls (using a national register of phone numbers that don't want to be called) since 2009. Any marketing call you do receive has to offer enrolling you on this list to prevent future calls.
For email, again speaking of Dutch laws, companies are not allowed to send you unsolicited, promotional messages. Not sure as of which year this is, but it has been the case for as long as I remember.
I assume most EU countries have similar constructions (I'm not sure if our laws are based on a EU directive).
> And when it matters, it's just being ignored.
Where is that? Though you're welcome to point those out to your country regulator.
> Most (medium-sized) companies haven't even realized there is a new law.
Actually they have, I was surprised at getting emails from medium sized, non-online business about it
Blanket forced consent in terms "we need to track you because we have a business need, take that or leave", despite being explicitly prohibited in all GDPR-related guidelines is still something you get away with.
Also one word: Facebook.
But I use ad blocking/cookie blocking so I guess it works the way I want regardless of what they think
There should be a standard implementation of these popups so that I don't have to do it for each new website on each new browser again and again.
Also, as I mentioned in another comment just now (https://news.ycombinator.com/item?id=21857843), the banner means they want to do something that you probably don't want, because that's why they have to ask consent. The banner is not needed for things like visitor counting, browsing products in a webshop, or other expected operations that involve personal data. It's only necessary when they do something that requires consent (see the link for an example).
I still hope we'll be able at some point to come up with a more refined protocol than http (or better sandboxing of the browser/device), where you could selectively reject loading JS resources and where resources would need to explicitly say what they were gathering, where pixel tracking would need to be announced (and only after your consent would those resources run/load). Totally ok with the site not loading either if you didn't gave the permissions. Probably never going to happen, but that would be a true handshake, "I want to check this out", RE: "Sure, we want your location, track your navigation across the website and we'll sell this as part of a dataset, including your IP, so that someone else then can buy several different datasets and create a proper picture of your activity", "Sorry, thanks, not interested". (and yes, it would need to be written in a way that's understandable, not 5 pages of crap). The same applied to mobile phones/computers/apps.
Or better yet, a browser/device API, where you (the developer) would need to declare all resources you wanted to access (DEVICE_IP_ADDRESS, DEVICE_LOCATION, MOUSE_POSITION etc) this would compile all of them into legible manifest that you could read before it being un-sandboxed and allowed to run. Any attempt to read such information from the browser/device where one of those permissions weren't granted would return null (might be the best argument for the existence of null).
A lot of sites throw up a modal that just disappears when you say no. And I've verified that in most instances this completely kills all telemetry.
I was involved working at a SaaS that provided first party personalisation at the time GDPR was introduced and heard a lot of stories about clients just dropping pointless and long term data.
I have family in the school system that called panicking that this was a disaster... then a few months later admitted it meant that they actual handle their data well and no longer accidently leak personal info (financial, medical, behaviour, attainment) to other families, kids, teachers, or third party companies. Oh, and their emergency fire list is now kept up to date.
I've used the powers of the GDPR to eliminate some low level harrassment of my grandfather.
Google, Facebook, and the Yahoo auth group are still diddling with data they shouldn't, but on the whole it is a much much better world.
It's kind of the opposite: if they need to ask for your consent, that means they're doing something that is not part of the standard exceptions.
For example, if they only use your data to do what you asked them to do, they don't need consent. If I ask Contoso to ship me a horse, they don't need my consent to process my address.
Every time you see a cookie banner, the message is: we want to invade your privacy.
If you want to find those that don't have their data protection in order, look for sites without privacy policy, or policies that were updated prior to ~2016 (that's when the GDPR text was finalized, i.e. the earliest time they could have updated it to be compliant with new requirements). A cookie wall is a signal that it's bad, not that it's good.
You also know you can get all the information a company has on you, and get them to delete it if you need to. I haven't made use of it yet, but I've read of people who have.
From inside the business side, I see most companies thinking about GDPR compliance when developing new products and features. What was never the case before and you notice now is they try to minimize PII collected to avoid headaches, and they are very careful about how data is shared with 3rd parties, asking for consent before doing it, etc.
GDPR says nothing about marketing emails. I can only speak for the Netherlands, but our laws about unsolicited commercial communication is what applies there.
What GDPR has to do with it is that they need your contact details to send you anything, so they process personal data. The predecessor to GDPR (called DPD, from the late 90s) also required companies to ask consent if there was no need to process your data for things like fulfilling a contract (same as with GDPR: they only need consent if it's not for a certain set of exceptions).
> You also know you can get all the information a company has on you
This was also the case under the previous law.
From the perspective of selling a B2B SaaS service, GDPR has been incredibly successful at making Security & Compliance an important discussion that is had during the sales process. Most leads will have security/compliance as an agenda item during sales calls, while before GDPR this was much less common.
GDPR has effectively turned Security & Compliance into a selling point and a point of competitor differentiation (it was this way in the past too, but much more so after GDPR). I think in the long run, this has/will result in companies having a heightened awareness of security/privacy and budgeting more time and money on security, simply because GDPR has connected it more directly to the business's bottom line.
I think it's good in the long run. In practice, the result is probably a decrease in risk of data breaches (less companies have your data, and the ones that do are more aware of their responsibility to treat it properly).
It's important to note that this benefits everyone (not just people of the EU). Very few companies will go through the trouble of treating EU data differently than non-EU data. Everyone is benefitting.
Our software does contain customer information, but isn't the focus. As somebody actually designed it properly, compliance wasn't particularly arduous. Huge sections simply didn't apply, and where it did we could just link each requirements to the relevant details, API, logs etc.
As you mention, I think the main benefit is just formalizing something that should already have been designed.
Another benefit is that it's driven 'bottom up' - Customer doesn't have to pay every vendor to provide them a new feature for say "scrubbing a customer". All their providers supply "here's how you scrub in my product" and customer just needs to stitch these mechanisms together to give their customers the ability to be scrubbed.
I have also used it to stop unwanted postal ads from local companies. I get to find out how they obtained my info, and also stop some junk mail.
For the sibling comments mentioning the GDPR popups / cookie notices, why not add a blocklist for these to your adblocker? At this point adblockers should be considered basic security software, like a firewall or antivirus. These lists exist are are pretty comprehensive.
As an American living in Europe I think it's a great law and I wish there was something comparable to protect my friends and family stateside. And as someone who administers a fair amount of business and client data, I do not find the law inconvenient to comply with. I am very pro-privacy and protective of user data, and I didn't have to make any major adjustments.
This hasn't changed. Every EU country implemented the Data Protection Directive and you could just have sent a letter since the late 90s (the exact date depending on your country).
For many of us software people, it isn't that revolutionary. These are things we should've been doing for a long time, and many of us have been doing.
But many companies are massive and bureaucratic. Everything from random giant companies to schools, hospitals, etc. These people don't really care about 'privacy', and many abused the hell out of people's privacy, many unintentionally (just careless). And since they make up big processors of data it was necessary to have them improve their practices. Now they actually think about how data is being processed rather than just chucking it around.
The GDPR's biggest impact or purpose isn't to reduce online tracking. It's to secure data rights for citizens in general. And the biggest abuses of that didn't happen due to advertising or tracking.
Personally, I feel the conversation on data in many organizations has helped me feel more secure in my privacy considerations. Although it may not be because of the GDPR, I feel I can make facebook/google/<data_aggregator> accountable about my personal information, if I really wanted to. Although I have not done it yet.
So there's been a big change on how my data is being handled in the real world - any effect on random websites online are just a nice-to-have bonus, it's sort of moving in the right direction but it's obviously not a priority in enforement and a better treatment for that can be tweaked in a next version of GDPR, the important thing was to tackle all the big relationships (and privacy abuse potential) people have with e.g. their cell phone provider, supermarket chains, lenders, etc, which are now mostly 'clean' and the major online players such as Facebook, Google, etc which will probably require years in courts.
So I sent them a GDPR request, and they told me exactly what data they had and which data they didn't have (confirming that it was next to nothing, and thus that I didn't have to worry about the breach too much). They also confirmed which wallets are in the account (allowing me to confirm that they were empty, as expected, thus giving me no reason to fill ou the KYC).
Without GDPR, I'd be faced between the choice of giving them more data, or not being able to confirm that the wallet is empty (thus potentially losing out on cryptocurrency that I had forgotten about). In the end, I'd have probably provided the information, potentially exposing it when they will inevitably have the next breach.
Before that, Germany already had GDPR-style laws. I get very little spam, because people don't sell my address. I think there was one case where my address was passed along - I demanded to be told who passed it along, deleted, and the deletion request be passed on too, and the spam stopped. Doesn't work for completely fly-by-night companies and proper spammers, but does work for the ones who try to stay on the shady-but-not-illegal side (losing one address doesn't matter to them, and is certainly not worth the trouble of not complying with the deletion request).
I'm literally not using a spam filter.
After I contacted the chain about it, within a few days my information had been erased and they said the clerk did not act appropriately and they'd also contact the shop in question to make sure this is not repeated.
It's a long story, but when purchasing, the payment terminal asks "Member?". If you answer in the affirmative, apparently somehow one becomes a member. In this case, the clerk reached out from behind the counter and pressed the button on my behalf while I was busy putting my card away. The receipt had the text "member" with a membership number and so on.
In retrospect I suspected that the clerk's KPI contains the number of new members. Most people probably won't care enough to raise noise about it.
Before GDPR, and actually before the improved EU privacy laws in general, say, 20 years ago, fixing this would have likely involved navigating some sort of swamp of dark patterns with several phonecalls and tons of queueing, with a long lead time for the removal and so on.
In the run-up to the GDPR we saw an increase in companies that started to take security and privacy a lot more serious than before. Before the GDPR all data was viewed as an asset and more was better.
After the GDPR went live - and especially after the first fines were issued - this has substantially improved, most - but definitely not all - companies that can afford it now have their security at a reasonably high level, they've hired in-house specialists to help analyze the risks of their operation. Typically access to live databases is now far more restricted and so on.
There are some downsides as well, but that was to be expected (such as: the GDPR being used as an excuse to do things via web portals that used to be done via email, of course that same email can be used to reset the password to the portal...). Overall I'd say the improvement is vast.
The law exists but it isn't enforced by the regulator and the way the GDPR law is set up there is no way to bring private prosecutions to enforce fines and get the law applied. So since the regulator isn't doing it the law is effectively useless. Some companies are complying but the bad ones are seeing no consequences and the compliant ones are bound to notice soon that they can safely ignore it completely soon enough. It has no enforcement currently, there is no rush to ensure your company complies.
For example, I now am far more willing to consider signing up for a loyalty card, as long as they don't use my data for profiling purposes. I didn't have many cards before, but the number has grown.
Same thing applies to online shops: I am far more willing to create an account when I see that my rights are being observed, and I can eg delete my data easily.
This, of course, assumes a processor that would rather be compliant with the GDPR in its current form, rather than fight it. Facebook, for example, needs to profile, and is using an IMO ridiculous interpretation of the GDPR to weasel it out of the consent issue. Let's hope the courts do the right thing.
Had I not been protected by GDPR I would have had to submit documents to prove my identity, none of which was even required to operate the account in the first place.
They were harassing me, calling etc, and I wondered how they got my details after so long. Made requests for data they held on me, and complained to CNIL about their practices. They dropped everything and are now being investigated by CNIL on how they handle GDPR.
Without GDPR the majority of those hidden improvements would've been postponed indefinately.
I do regard spammy notifications as regressions though.
The previous law was optional to implement for member states but I lived in a member state (the Netherlands) that did (as "Wet Bescherming Persoonsgegevens") and I think most other states did as well. Any company that wants to do business in the Netherlands had to comply with that law already (just like you can't come here to do business that is illegal for any other reason).
The main features as I see them are that companies have to obtain consent or have a valid reason for processing personal data, and you have a right to view your data. That was the case and is still the case. I've done data access requests prior and post GDPR and the responses are identical.
A number of details changed, but if you complied with the previous law and you're not a personal data broker, then you have to do very little to comply with GDPR. To give an example, consent now has to be "freely" and unambiguously given, whereas before it just had to be unambiguously given, which means that an employer can't ask you for consent due to the power relation and it's popularly interpreted to also mean that you can't bundle it ("consent or don't get the service") because then it's not "freely" given.
OP was asking for EU residents to comment on how it impacted them. This is how it impacted me. If someone else is very happy with GDPR because their country didn't implement the previous law (DPD), they should comment separately.
Edit: actually, all EU member states implemented the DPD: https://en.wikipedia.org/wiki/Data_Protection_Directive#Impl...
So this is actually representative for everyone else.
> Also, the impact of a [breach] is much bigger now
Indeed, as I mentioned, the fines are higher, and that's the only change in that regard.
Note that the requirement to report data breaches to the authorities is not a GDPR thing. The Netherlands introduced a separate law for that prior to GDPR.
And the reason you can be fined for a breach is not because you had a breach. It's not a crime to become the victim of criminal activity, so that's also not new with GDPR. The reason for it resulting in a fine is that it often highlights inadequate security of personal data, which was also illegal under the previous law.
Stage one: these cookie consent popups are empowering. I'm glad the people won.
Stage two: I am getting a bit sick of having to understand custom consent forms on every site.
Stage three: what have we done, cookie consent has made the internet suck even more!
Stage four: I wonder what all this privacy stuff is really about (goes and reads about it).
Stage five: The internet is a strip mall crossed with a red light district run by the mob - we are doomed.
Stage six: This is something the government will be bad at for quite some time, and I actually have the power to take control of my personal privacy and freedom with minimal effort (relative to say overthrowing a tyrannical government).
In each case, A had no legitimate reason to store or process my data. In particular the GDPR forbids them explicitly to exchange C's data with any third party. Doing so could lead to severe penalties.
In all three cases I only had to point out these facts once to stop the whole claim. Very comfortable.
A friend of mine has used the GDPR give-me-my-data / delete-my-data email to expose companies doing shady stuff as they’re afraid of penalties under the law.