No, you don't
> This is one of the potential factors why the EU loses out to other markets in startup-friendliness.
No, it doesn't.
What it "loses out on" is on price dumping through unlimited investor money and wholesale private data collection
I used to be think GDPR was a good thrust for user privacy but years later what I see is an adorned web already suffering under the weight of its own crap super-adorned with these cookie banners that impact my actual, day to day life of the net.
That's not a failure of the companies doing the tracking, that's a failure of regulation. The EU could have legally enforced the existing Do Not Track flag but instead we get a worse web that has literally shaved off hours (days?) of my life clicking through cookie forms. And no number of uBlock scripts that promise to erase them from the web has been enough to stop them.
So, report these privacy invading companies to your local data protection body, you say! Sir, madam or epithet of your choice, have you tried reporting a breach to the Danish Data Protection Agency? They will do everything in their power to invalidate your claim. That was the last straw for me. Our protectors are indolent or powerless and here we proclaim victory!
All I've seen from these rulings is spinning wheels, wasted labor, money set fire and pain.
Our German clients have screamed and hollered (thanks, Schrems II!) to bifurcate our clouds so that one side is AWS and the other is a German cloud that moves with the glacial pace of the 90s and with that decade's service portfolio. Don't even get me started on the service level difference:
AWS: how can we literally give you everything you need to build your successful business? How about these free recruits who just graduated out of our program that specifically re-trains people from disadvantaged backgrounds to be cloud all-stars? How about regular consulting sessions with our teams to identify how you can save money with us?
German cloud: let's make setting up a managed DB the most horrifically onerous process possible that's unreliable and flaky with your data and then charge you thousands of euros for support fees fixing the things that were our fault to begin with.
I did. And I do.
> Because I do and the amount of money we need to throw at compliance, both in direct costs and dev hours, is immense.
It's not immense, with emphasis. It's just the cost of doing business.
If you run into having to do compliance or certification, it means that you're doing something that requires you to be, you know, compliant.
For example, financial institutions have to be compliant. And we, as society, really-really want them to be compliant and responsible for what they are doing. Not like Equifax in the US.
> And we're not doing ads, user targeting, or any other such "nasty" industry practices.
It doesn't matter, if you do it or not. The "immense" cost of compliance is just your business deciding to cut corners and then realising that no, you shouldn't cut corners, and then scrambling to fix that when you were most likely caught red-handed.
I worked at a company which was a bit lax with its practices, and then had a run-in with an unexpected audit. Omg, you wouldn't believe, but the cost of compliance with laws was immense as we rushed to meet al requirements before the deadline imposed on us. Had we not been lax, this wouldn't even be a problem.
> I used to be think GDPR was a good thrust for user privacy but years later what I see is an adorned web already suffering under the weight of its own crap super-adorned with these cookie banners that impact my actual, day to day life of the net.
Ah yes. Another person who complains about compliance, and then immediately pretends that the state of the web is the result of a law.
No, the web is the way it is now precisely because these companies flaunt and break the law. All those cookie banner with dark patterns? They are illegal. The only real downside of GDPR is that it's not enforced as rigidly as required, and nowhere on the required scale.
As for compliance with GPDR, it's essentially zero added cost for small companies with greenfield projects. For small-to-medium companies the cost of GDPR compliance is the function of data practices. If it's "immense" for you, this only means that you were already siphoning user data you didn't need and did nothing to protect it. I can't feel sorry for you.
> Our German clients have screamed and hollered (thanks, Schrems II!) to bifurcate our clouds so that one side is AWS and the other is a German cloud that moves with the glacial pace
Once again, you blame your own technical decisions on the law. Of course German customers would want their data in Europe. Why wouldn't they? Data on American servers is basically forfeit, and can be examined, analysed, and seized by the US at any moment. Wow, I can only imagine why German customers would not want that. Whatever might be the case, hm?
> German cloud: let's make setting up
Once again: it was your decision. AWS (and GCP, and Azure) literally provides a service to European customers where they keep data in Europe only, and that is more than enough for most any compliance (I know banks in Europe who use AWS and/or GCP). [1]
So, your poor technical decisions have lead you to suffer increased costs, and you blame that on laws. Keep it up, it's a good way to stay in business.
[1] AWS: https://aws.amazon.com/compliance/eu-data-protection/, Azure: https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boun..., GCP https://support.google.com/cloud/answer/6329727?hl=en
We're working, willingly and early, with an independent auditor we hired.
As for the German cloud, no AWS Outpost or anything else we (and AWS' legal team) pitched was enough.
> The only real downside of GDPR is that it's not enforced as rigidly as required, and nowhere on the required scale.
Whose actual fault is this? The EU pushed through a ruling without teeth. It's a lose-lose for everyone from business all the way down to the person assaulted by these cookie notices.
> So, your poor technical decisions have lead you to suffer increased costs, and you blame that on laws. Keep it up, it's a good way to stay in business.
This is just rude, please don't.
> If it's "immense" for you, this only means that you were already siphoning user data you didn't need and did nothing to protect it.
Why are you continuing to state things as fact you don't have a clue of? This is completely false.
You've asked if I worked at small-to-medium company in the EU. I told you I did. My experiences are significantly different from yours. This only tells me that there's definitely something wrong you're doing, and blaming it on the law. Since you're not giving any details, it's pure speculation at this point.
> Whose actual fault is this?
I think no one could even predict the scale of the issue. No one could imagine that:
- even well-to-do commercial companies would include literally hundreds of trackers on their web pages
- almost literally everyone would decide to break the law instead of, you know, stopping wholesale data consumption
The ad industry played a nice trick: now everyone believes the EU with its GDPR is the bad guy, and not the motherf@ers who siphon your data to 500 advertisers on every page.
As for the teeth, GDPR can fine you for a significant chunk of your global turnover. So yes, it has teeth.
> Why are you continuing to state things as fact you don't have a clue of?
Are you the only one allowed to state things?
Additionally, let's break out out of the HN bubble and assume the role of somebody who is not a tech aficionado. E.g. the C-level exec of small and medium sized producing company in Germany (e.g. automotive). Now they not only face the burden of having to modernize their often dated tech system but also get the handicap of having a whole new sea of GDPR complexity before them which, if something goes wrong, can be business ending. I've seen this being a preoccupying topic for meetings for years for companies which really should not have to care (producers of automobile parts). It's a significant part of the IT budget going down the drain which could've been spend improving existing processes.
Let's start with this question: how are they running their business?
> also get the handicap of having a whole new sea of GDPR complexity before them which, if something goes wrong, can be business ending.
1. There's nothing complex about GDPR
2. GDPR is not business ending, as data controllers are expected to help and guid the companies who are found to be in breach of GDPR
> I've seen this being a preoccupying topic for meetings for years for companies which really should not have to care
It means they don't care in the least. GDPR is an amalgamation of the various data protection laws that existed before GDPR. So, these "poor companies who are in meetings for years" didn't care about data protection then.
Then companies were given two years of transition to get in shape and get their act together. Omg, these "poor non-technical companies" are still "in talks for years".
GDPR has been in force since May 25 2008.
So. At least a decade of data protection laws (and German laws have always been quite strict) + 2 years of transition period + 3.5 years of the law being in effect. And it's still " preoccupying topic for meetings for years"?
> It's a significant part of the IT budget going down the drain which could've been spend improving existing processes.
Yes, indeed. If 15 years later they still can't figure out why they shouldn't keep personal data around, they definitely need to improve their processes. And IT has nothing to do with it.
For example, a government which ensures that you don't go to jail for some bs reason is a government which I would be more trustful of as an enterpreneur.