11 ms·
And if you think GDPR is a toothless joke, let's take a look at the defined fine stucture. It is pretty simple, only 3 levels (strikes for the fellow Americans
by shadowtree 9y ago
And if you think GDPR is a toothless joke, let's take a look at the defined fine stucture.
It is pretty simple, only 3 levels (strikes for the fellow Americans):
Strike 1 - Stern warning letter
Strike 2 - 2% of your TOTAL GLOBAL REVENUE
Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher)
And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got axed due to a lawsuit of a single student from Vienna against Facebook. So all you need is a single pissed off German customer you ignored when asking for their data report card and you're fucked.
For startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment.
Enjoy :)
- xd 9y agoStrike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) Why would they impose a 20M limit and not stick to 4% revenue irregardless of it... edit: I'm not sure that the down voting is about.. it's still a limit, a limit that means a company turning over 0-500M will pay up to a 20M fine.. not so bad the closer you get to 500M but not so great if you're a small company, especially so as the regulation is so open to the "law of unintended consequences" right now and only larger companies will have the funds / man power to navigate it.
- deleted 9y ago[deleted]
- ATsch 9y agoYou seem to misunderstand, 20M is not a limit, but a minimum
- downrightmike 9y agoA lower limit, a minimum. If 4% is 20.1M+ they'll pay that.
- jpk 9y agoI understand your point, but I still think it's wrong. The minimum on the third strike is so a little-to-no revenue startup or shell company or something doesn't willingly abuse data because the fine will be 4% of nothing.
- spyspy 9y agoBig consulting firms have been milking this thing for a long time already.
- mnm1 9y agoI wish more penalties were like this. This sounds great. Now these companies will finally have real incentive to comply. Hell, the percentages should be higher. That's the only way to enforce regulations. Otherwise, they'll just pay a puny fine, American style, and not do shit.
- usaphp 9y agoIt's a percent from revenue not from profit. So 5% from google revenue is a lot
- mnm1 9y agoThat's even better. The more the better.
- deleted 9y ago[deleted]
- trashtester 9y agoIt is. On the other hand, companies like Google/Facebook/MS/Apple have such huge profit margins that a conviction will be but a speed bump, and given that their business model is based on the data regulated by GDPR to such a great extent, one may expect them to challenge the new regulations as much as they can. They also (probably) have the most competent legal divisions, which will help them exploit any gray areas. For companies with lower profit margins or companies that are hit by the lower limit of $20M euro, the threat is much greater. Small companies may go immediately bancrupt from a $20M euro fine, while companies with slimmer margins may be taken from black to red results by a 4% fine. From my pesonal experience, many such companies do not fully grasp to what extent these regulations will affect their business models if actually enforced.
- jpetso 9y agoYeah, but 4%/20m is only the third strike. If as a small company you're unwilling or unable to fix those issues in a reasonable time frame after the first two strikes, you might not deserve to survive as a business in the first place.
- grabeh 9y agoThe reality is that the 2% or 4% figure depends on which part of the GDPR you have breached and isn't a tiered approach. Breaches of core requirements (for example valid processing grounds) will attract a 4% fine straightaway technically speaking. Art 83 covers the different triggers. Having said that there are various schools of thought around levels of potential fines, including from different data protection authorities in the EU. Considering the ICO in the UK is yet to levy a maximum fine despite egregious violations is at least one factor to suggest fines will not increase dramatically. Also there are not only increased fines to consider but an increased focus on compensation to data subjects in the event of a violation of their rights (together with an evolving case law to support that in the UK at least).
- pascalxus 9y agoIn addition to the solutions you mentioned, This might create more jobs at facebook and google as compliance will take a huge amount of effort. I predict, lawyers are going to make a lot of money on this.
- taysic 9y agoIt may be doable for big companies but does this mean startups will be more likely to delay entry to the EU market?
- throwaway_9123 9y agoThrowaway account. I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps. You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted. It all boils down to companies simply don't believe the fines will be enforced given just how expensive the fines are. And since GDPR doesn't go into affect until May 2018, companies are just waiting and seeing what happens. It's really hard to sell GDPR because it's essentially an insurance policy. Why spend $5m on software and another $5m in services ($10m combined) if your total fine is only $20m. Do you as a company have a 50% chance of getting fined? If not, then roll the dice and not buy a solution.
- rsp1984 9y agoI understand it that $20m is just the minimum on strike three, not the upper bound (there is none I understand). For a company that has the means to spend $10m on software and services I'd think that 4% of global revenue would be clearly the larger sum.
- the_mitsuhiko 9y agoThe talk on GDPR has definitely only really taken off very recently. While a year ago it was a few people that brought it up, the reality of the situation is now slowly kicking in as European customers are asking for this.
- tyfon 9y agoI work in a (small) bank, but we are already quite far in implementing GDPR. Most of it is done by our internal development team or the core system providers we use. No need for external consultants. From what I can tell, the whole banking industry is busy implementing this, at least here in Norway. The fines are real..
- existencebox 9y agoSpeaking as an eng for MSFT, across multiple orgs, GDPR is certainly taken very seriously here.(Probably safe for me to say given [1]) I would expect the big players will all follow through as a CYA because they'd be the first to be made an example of. I think a sister post's comment on lack of sales was probably accurate, since my above reasoning likely doesn't apply to "most small companies" and the effort to comply properly is certainly not negligible, even if you've already assessed the changes that need to be made (frankly that seems like it might be the easy part if you can leverage someone with background on the nitty gritty of the legislation). It will be "interesting" to see how this pans out. [1]https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/default.aspx https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/def...
- 77pt77 9y ago> Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) 20mil EUR even for zero revenue?!
- Espressosaurus 9y agoTurns out it's a bad idea to ignore regulators enforcing the law.
- M2Ys4U 9y agoYes, but who exactly is processing personal data with zero revenue?
- cm2187 9y ago> Keep in mind that the EU/US Safe Harbor agreement got axed due to a lawsuit of a single student from Vienna against Facebook. Almost every US supreme court decision come from a single guy challenging something. Are you suggesting that under a certain size, one shouldn't be allowed to sue in court?
- occultist_throw 9y agoI believe they were trying to make a point that it doesn't take a whole government, or a class of people to be wronged to change things in court. It takes a single person whom was wronged. That's it.
- Silhouette 9y agoFor startups - GDPR is like Y2K at the time, a GOLDMINE. Unless you're a start-up that handles personal data, in which case it's another bureaucratic overhead that also carries a risk of draconian penalties if you make a mistake, even if you have perfectly sensible reasons for working with that data and you're not doing anything at all surprising or dubious with it. Of course, the EU has form for this, given its similar approach to both consumer protection and VAT rules in recent years. It does seem to have an unhelpful habit of imposing regulations at big business scale to deal with big business scale problems, but not considering that both of these may be wildly disproportionate for smaller businesses.
- riffraff 9y ago> a risk of draconian penalties if you make a mistake, even if you have perfectly sensible reasons for working with that data and you're not doing anything at all surprising or dubious with it. GDPR explicitly mentions that "warnings" and "periodic data audits" should be considered measures to take before the fine is applied. It also says[0] that when deciding on the fine, due regard shall be given to nature, gravity, and duration of the infringement; degree of cooperation, intention or negligence, actions previously taken by the authorities, previous infringements, nature of data etc. It seems unlikely that anyone in good faith would get screwed by this. [0] http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#d1e6226-1-1 http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
- Silhouette 9y agoIt seems unlikely that anyone in good faith would get screwed by this. Most small businesses don't have a lot of outside investment, if any. If you're running a bootstrapped business funded with your own savings, the last thing you need is to have to spend significant time and money figuring out where you stand on GDPR compliance and what you have to do with regards to any other organisations that your business in turn depends on. The theoretical fines aren't the most immediate problem for small businesses; the overheads are.
- taysic 9y agoWhy is it Global revenue? It seems presumptive for the EU to want a share of their global revenue rather than EU revenue
- StavrosK 9y agoI assume it's because it's less easy to game, rather than say "oops we made all our money in Switzerland that year".
- johnvonneumann 9y agoBig companies make a habit of pushing their tax liabilities to the most favourable jurisdiction. As the other comment said, they would take the piss.
- marsRoverDev 9y agoAlso, it is worded to say that it's 4% of global revenue for your parent company. So there is no setting up an offshored tiny company to wear the liability - your parent company is on the hook, wherever that money may reside.
- RivieraKid 9y agoJust create two tiny companies, one being the parent of the other.
- AndrewKemendo 9y agoI'll eat my shoe if a regulator ever gets even 2% total global revenue out of any of the top 100 software companies based on this. In reality a bunch of small shops are going to go bankrupt because they don't have a "GDPR implementation" position filled and they didn't do some report properly.
- bad_user 9y agoThe EU just fined Google €2.42 billion in an antitrust settlement for manipulating search results. Go get the salt.
- andy_ppp 9y agoYes, the EU regularly kicks the asses of companies to help consumers in Europe. I'm sure we won't get the same protection on pesticides, pharmaceuticals/medicine, GM, white goods, monopolistic practices like this, roaming charges, etc. etc. once the UK leaves the EU.
- davedx 9y agoIndeed. The conservatives are already drooling over all the consumer/citizen-hostile things they'll be able to do once the UK is out.
- davidatyc 9y agoHow come the EU doesn't care about "pesticides, pharmaceuticals/medicine, GM" ?
- twidger 9y agoI think the original comment needs to be interpreted as 'EU does care, UK post-EU less likely to'
- AndrewKemendo 9y agoCompletely different scenario - But even if it was similar they are fighting it hard [1] so I doubt they will end up paying anything close to that. [1]http://fortune.com/2017/07/10/google-eu-fine-lawyers/ http://fortune.com/2017/07/10/google-eu-fine-lawyers/
- mdip 9y agoFor startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment. I'll start by saying that I have found myself leaning in favor of this law -- I've made a much longer comment about it and won't rehash it, but I wanted to make sure my statements that followed weren't taken as a blanket anti-GDPR but rather a devil's advocate response. I take issue with the quoted statement because it ignores the downside for startups[0]. Companies like Google, Facebook et. al., have the money and time to hire teams of lawyers to find a way to work around these regulations in a manner that maximises their ability to continue tracking while minimising their risk in getting smacked by the hand of the law. Getting hauled off to court won't bankrupt them and they have the legal teams to probably win regularly enough. Even barring that, they have the finances to adjust their business to be fully compliant (in whatever degree business adjustments require) without going bankrupt. Joe's Advertising Supported Free Service does not. Joe's not going to start his own ad network and start mining personal data for it -- it's way too expensive to try to compete with Google/Facebook (and it was already way too expensive to do it, before). If he does, he's the one who's going to get hit with the second and third strike; probably from that "single pissed off German customer". Investing in firms that touch this space will be met with far more skepticism. I wouldn't be surprised if any company that simply asks for a user ID and password won't face a little scrutiny from investors, at least until the regulatory atmosphere is understood (I doubt it'll be that extreme for terribly long, but one bad court ruling/fine laid out where it wasn't expected could change that). The cost of establishing many, many kinds of companies will now increase because the risks are high enough that going to market without having your legal bases covered on this one. That money has now been shifted to a business who -- potentially -- is selling snake-oil (and startups are going to be more likely to do business with that snake-oil salesman since they'll probably also be the least expensive). Then there's the "unintended consequences". Here's a crazy hypothetical, but a lesser variation of it is plausible if this were a US law: Some individual exercises his free-speech rights and chucks something up on the Internet that has a bunch of horrible things on it, say, like 'a guide on how to slaughter and prepare kittens for healthy and inexpensive dinners'. Some kid reads it and kills/eats his neighbor's cat. The guy didn't do anything illegal, really, but his web host knocks him off the web and people are calling for blood. He happens to use an ad-network, but doesn't, himself, collect personal information. However, this ad-network does, and at one point was nailed under this law. He uses the ad-network, so some overzealous prosecutor figures out a way to bring it in front of a judge that he's responsible for what this third-party did and should also be prosecuted. At the height of outrage, a jury isn't hard to find to connect the dots[1]. [0] And hey, that's fine, you're an internet commenting individual just like me -- we don't have to present both sides of the story -- that's the replier's job. [1] Yeah, I took that a little far, but I think back to when "The Columbine Massacre" happened and everyone believed it was FPS video games that warped those evil children's "precious little minds". It took all of two seconds to call for banning violent video games (constitution be dammed), many idiotic and ultimately overturned laws were passed, and if there was some way to haul the developers who wrote the game off to jail (I think they were blaming DOOM at the time), it would have been possible within those first few weeks.