3 ms·
Throwaway account. I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps. You'd be surp
by throwaway_9123 9y ago
Throwaway account.
I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps.
You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted.
It all boils down to companies simply don't believe the fines will be enforced given just how expensive the fines are.
And since GDPR doesn't go into affect until May 2018, companies are just waiting and seeing what happens.
It's really hard to sell GDPR because it's essentially an insurance policy. Why spend $5m on software and another $5m in services ($10m combined) if your total fine is only $20m. Do you as a company have a 50% chance of getting fined? If not, then roll the dice and not buy a solution.
- rsp1984 9y agoI understand it that $20m is just the minimum on strike three, not the upper bound (there is none I understand). For a company that has the means to spend $10m on software and services I'd think that 4% of global revenue would be clearly the larger sum.
- the_mitsuhiko 9y agoThe talk on GDPR has definitely only really taken off very recently. While a year ago it was a few people that brought it up, the reality of the situation is now slowly kicking in as European customers are asking for this.
- tyfon 9y agoI work in a (small) bank, but we are already quite far in implementing GDPR. Most of it is done by our internal development team or the core system providers we use. No need for external consultants. From what I can tell, the whole banking industry is busy implementing this, at least here in Norway. The fines are real..
- existencebox 9y agoSpeaking as an eng for MSFT, across multiple orgs, GDPR is certainly taken very seriously here.(Probably safe for me to say given [1]) I would expect the big players will all follow through as a CYA because they'd be the first to be made an example of. I think a sister post's comment on lack of sales was probably accurate, since my above reasoning likely doesn't apply to "most small companies" and the effort to comply properly is certainly not negligible, even if you've already assessed the changes that need to be made (frankly that seems like it might be the easy part if you can leverage someone with background on the nitty gritty of the legislation). It will be "interesting" to see how this pans out. [1]https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/default.aspx https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/def...
- davedx 9y agoYeah, both my work and my wife's companies are taking it very seriously. The point is at the moment, we all think we can handle it internally: legal is very busy doing prep work that will result in requirements across the business, some of which will result in development work (I'm in the IT department). My wife is busy documenting and preparing requirements too. What kind of companies do you sell to? Maybe they are actually trying to handle it internally too? What do they say?
- simonh 9y agoThe fine doesn't absolve you of responsibility for complying. If you're fined you have to pay up AND you have to comply. Otherwise they'll just fine you again, as they did to Google.
- emn13 9y agoNevertheless, a 4% fine is very low, given the low frequency of fining. Tech firm margins are much larger than this; so while it's clearly unethical to do so, it may be more profitable to simply accept the fines as a kind of tax for as long as possible, and to continue to profit from all that data until things get really dire. In actuality; a firm wouldn't need to choose quite so starkly to flaunt the law; simply failing to invest and dragging your feet looking for impossible have-it-all solutions might well be enough to get away with a few fines until you really try to get your act together. If you will; it's the difference between the VW approach and those of (as it appears anyhow) all the other carmakers. They're all cheating; most simply were wise enough to avoid doing so explicitly. Data protection is also harder to enforce than emissions; and just look at how laughably incompetent emissions enforcement is to get an idea of how seriously you're likely to get caught if you happen to collect too much private information. I expect the same here as in emissions: no real compliance for years (if not decades), and when enforcement comes, it won't be the regulator that actually catches even egregious wrong-doing. I mean; the high-profile players will play lip-service of course, but that's it.
- RivieraKid 9y agoI really doubt that these companies would lose more than 4% revenue by complying. Worse ad-targeting in the EU is not worth that much.
- emn13 9y agoI'm not so sure. And it's not just ad-targetting - all kinds of personalized stuff and simply general purpose data mining suffer too. And don't forget that they wouldn't get the full 4% immediately; and would likely be fined much less than once per year based on current trends anyhow. So that 4% is going to be further diluted.
- amelius 9y ago> It all boils down to companies simply don't believe the fines will be enforced given just how expensive the fines are. It sounds like a goldmine for the EU government. If they install a group of people chasing for noncompliant companies, they will pay for themselves.
- fixermark 9y agoAnd with most of the major tech players being American companies, well... No war except economic war. ;)