Customers immediately complained.
For business reasons, we undid all of our changes.
Go figure...
The question is rather how many companies that pre-GDPR stored my data in ways I (as a technical person) would consider unsafe, or used it in ways I would consider "bad", that have changed their ways.
My local bowling alley still stores my password in plaintext and use an outdated Wordpress-plugin for bookings, and Google stills knows as much about my behaviour online and IRL.
It probably doesn't, as fewer websites will be so blasé about pumping every piece of metadata they can think of into Adwords and Analytics APIs these days.
So even if some sites are pulling out their GA, some won't and that's good enough for Google
My local bank has, post-GDPR, started adding Google Analytics to their logged in client section. I've complained to them ("but we use anonymizeIp()") and to the data protection officials here in Germany ("how did you even see that? Can you explain again what is the issue?" and then they dropped silent).
Nobody cares. Really.
Like everywhere else.
And this will never change.
The only thing the GPDR allows for is for governments to bury and destroy companies they don't like, which at this point is mostly the big internet companies, but that won't last.
I am quite used to hearing this from people who oppose GDPR, however I am yet to hear at least a single strong point made about what they would do instead.
Apathy due to not being able to do best is incredibly self-defeating. In my own personal take on this I think this is exactly what Google et al want you to do: being afraid to do anything because you haven’t yet found a way to perfectly resolve the situation.
It’s a policy issue, and thus if you knew how to resolve it in an ideal way there would be nothing to resolve in the first place. We’re not dealing with number theory where some brilliant mind can suddenly imagine a mental framework that will resolve our all sufferings.
If Amazon violates my privacy I basically get better suggestions for a birthday present for my daughter a week before her birthday.
What I fear is the government passing my medical file to health care, police and insurerance companies. What I fear is an incompetently recorded and therefore wrong home moving record getting passed to the IRS and that resulting in an investigation, blocking my accounts. What I hate is a wrong camera match to my face resulting in the police wrongfully arresting or convicting me. What I fear is the police agggressively investigating me because they have some random tiny bit of “evidence” such as my cell phone being close to a crime, or because I dialed a wrong number that was involved in a drug case.
I therefore want the ability to permanently edit and erase my own medical record, as well as any other government record on me, from school data to ex spouses when a divorce is final. The ex spouse is allowed to have proof. City hall is not. I want the government itself to be liable for passing any info even to the police. I want contact tracing to be impossible even if it makes police 5% cheaper at the cost of allowing for great abuses. I do not want laws that cannot be enforced against government departments, I want it to be erased.
Compared to those threats, I don’t really care about private companies knowing I watched porn yesterday evening. Without effective protection for the Crown Jewels of my privacy I don’t care about tiny details.
> a present for my daughter’s birthday a week before
Can anyone on NH suggest whether this ever happened to them? This never happened to me practically so I think this is quite far away from reality.
https://www.washingtonpost.com/national/health-science/peopl...
"What’s more harmful to patients being treated for drug or alcohol abuse: Risking their health by keeping other medical providers in the dark about their substance abuse treatment? Or risking their jobs, homes and child-custody arrangements by allowing potentially damaging treatment details to be electronically shared with an array of medical providers?"
(Never mind that if this goes for drug/alcohol abuse, the same goes for single mother families: do you let your kids broken arm get treated and risk youth services taking away the child, or do you let it go untreated, risking ... ? And of course there's the never ending list of government departments demanding access to this data, from the IRS to some department registering pets.
(I even object to DOCTOR's use of medical records. I was diagnosed with kidney stones. Now I can tell you, that HURTS. ESPECIALLY if for 2 weeks doctors refuse to test, instead giving some pain medication and sending me home asap. Why? You feel the pain in your abdomen, and I look like I'm maybe 25 years old. I eventually found out that these doctors refused to check for problems ... because pain in the abdomen is most often caused by heroine addiction causing constipation. If my medical record had even a little support for that conclusion, I could have died, slowly, in incredible pain. So no, I don't even want doctors to have access to my medical records AND I DON'T WANT THEM TO KNOW THEY DON'T HAVE ACCESS. Why? Because I don't want to die. No other reason)
2) The EU legal framework is even less effective than laws. GPDR enforcement on your behalf is impossible unless ... you convince a government employee to start the case on their behalf. These employees, of course, have since turned out to barely know what cookies are and have not really started cases, not even against companies. I can request for someone to sue their own employer on my behalf. This is a blatant conflict of interest, working against me and every individual or family.
Against government departments, of course, enforcement is nonexistent entirely.
So for me, as a PERSON, there is NO legal protection in the EU framework. None whatsoever.
So the only acceptable solution is to not let the government record or keep this information in the first place.
It's a mess, and it works like an hallucinated moat. If you obey the law, you have a strong disadvantage. If you don't obey the law, you have a strong advantage, and nothing will happen to you. Non-enforcement trains people to not honor the law, because they can't compete if they do.
But also partly deletion and opt-out also of course, and that probably works well, for those who use it. But with the huge implementation cost (cited by PwC as upwards of 150 billion USD in the U.S alone [0]), I wonder what the price per delete request or opt-out is.
[0]: https://truthonthemarket.com/2019/05/24/gdpr-after-one-year-...