4 ms·
For purposes of this discussion I would say the EU is one entity. If all citizens of the EU are sharing the same rights and those rights are defined in a single
by forgotAgain 11y ago
For purposes of this discussion I would say the EU is one entity. If all citizens of the EU are sharing the same rights and those rights are defined in a single legal framework then I would say (for data privacy anyway) the EU is a single entity without borders.
As far as the difference between need and sense I think what you're talking about is actually cost. If citizens want data privacy there will be a cost. If they think the cost is too high then they will decide that it doesn't make sense. They should have the opportunity to decide.
- richmarr 11y ago> They should have the opportunity to decide. "Opportunity to decide" implies that end users are prepared and waiting to make that decision, which I'd suggest is broadly untrue. When you say "have the opportunity to decide"... I hear "be forced to learn about then make a decision on a complicated thing in the middle of a buying decision". EU companies already have to inform users if personal data leaves the EU. Nobody reads it. People don't read T&Cs. You could force companies to summarise their privacy/data policies during the buying decision, but you'd have to compress so much you'd mislead as much as inform. Besides, I think if people cared enough about this stuff then P3P would still be a thing. The ones that DO care enough can read the privacy policy that already explains it.
- forgotAgain 11y agoAs I said before: There is a check box next to the purchase button. The check box says that to complete the transaction you agree that information will be transferred to the destination country. Not all that hard or complicated.
- richmarr 11y ago> Not all that hard or complicated. A checkbox isn't complicated in itself, but there are a few things about it that are complicated. (1) All the thinking the customer needs to do once they see the checkbox in order to understand exactly what information is shared with which legal entities in which territories. A checkbox that says "personal data shared with companies in the US" that might mean recording your email address with a centralised logging system in a comparatively secure datacentre... or it might mean sharing your photo, location data & bank balance with a mob front. If you don't include that detail you're not giving the customer a basis to make a sound decision... but if you do communicate it you're dumping a ton of cognitive load onto them while they're trying to transact, and hence shitting on your own conversion rate. (2) All the thinking in the creation & maintenance of that checkbox... involving web ops, legal, product management, most likely marketing & biz dev too as they're also likely candidates for using personal data in SaaS tools. Then add in work done by regulators & auditors to verify that the checkbox is actually represented truthfully... because I don't see how a sane P/L owner would agree to reduce their conversion rate voluntarily with no promise of a boost to LTV or CAC (3) Change management, when you have a database full of people who've consented to their data being stored in Ireland and your marketing team is screaming to use some shit-hot new CRM from Israel or wherever and you need to get in touch with every single one before being able to use it. In reality you'd just have to be allowed to just make 'reasonable effort' to contact them, which in reality would just be an email or a letter notifying them of intent... but still, rather than just being allowed to run your IT you now have to inform your customers how you're running your IT and expect them all to understand, risking misunderstandings and reduced LTV. Don't misunderstand, I like privacy, I'm a fan of Snowden, I want customers to own their own data. I just don't buy this checkbox idea.