4 ms·
Any insight from HN insiders on how seriously companies big and small are taking this? In my experience, the buzz around this is much more serious compared to
by napoleoncomplex 9y ago
Any insight from HN insiders on how seriously companies big and small are taking this?
In my experience, the buzz around this is much more serious compared to previous efforts, "the cookie law" for example, though I have no idea on the actual impact.
In our company, we've decided to implement the necessary changes, because a lot of them just make sense (be clear with the user on tracking, don't store personal data you don't need...). It could turn out to be a competitive advantage, but only if the rules really are enforced.
Otherwise it will be the same as the cookie law, the companies following it had a shittier user experience, and the ones that didn't were never penalized (the cookie law was absurdly bad legislation in my opinion to be clear).
So any insight from the HN crowd would be much appreciated!
- cotillion 9y agoGDPR is something completely different. The cookie law was an email from compliance with something like. 'Oh, and by the way we need a cookie warning. Please fix it.' GDPR begun with mandatory briefings for all employees (not just IT) a year ago and the projects spawned have been going full steam since then.
- ust 9y agoHi, I'm involved with GDPR for my work, although in academic context, i.e. the primary motive in processing of personal data is in security, provisioning services, accounting purposes, etc. Also, I'm not a lawyer, and this is just my personal opinion. So, while I do work in academic environment, I do have contact with people from industry, and they are taking this seriously. (Of topic, this actually created a new business opportunity, for compliance with the GDPR). However, GDPR is not that different from the Directive, if you were compliant with the Directive, chances are, you're probably (mostly) compliant with the GDPR. Yes, the conditions for consent are strengthened, and since now we have a Regulation, it is valid in all countries. There are other differences, and it is more stringent now, but it is not drastically different from the Directive. BTW, this link[1] have a nice overview (I'm completely unaffiliated with that firm, I just like how they structured it...): [1] https://www.whitecase.com/publications/article/gdpr-handbook-unlocking-eu-general-data-protection-regulation https://www.whitecase.com/publications/article/gdpr-handbook... One thing that people lost sight of, at least in my opinion, that GDPR is not just about punishment, or stopping the processing of personal data, it is also about transparency. People should not be coy/evasive/unclear about what kind of data one is collecting and for which purpose. This is one of the most important things (again, in my opinion). Processing of personal data has a valid and important purpose, and the GDPR is not there to stop it. And for the question will the GDPR be enforced, I think it will. For the moment, though, all data protection authorities (DPAs) are a bit overloaded, and I suspect that will be the case in the near future. But obviously, EU and EC are taking GDPR quite seriously. Hope this answers your question. (Edited for grammar...)
- cJ0th 9y ago> One thing that people lost sight of, at least in my opinion, that GDPR is not just about punishment, or stopping the processing of personal data, it is also about transparency. People should not be coy/evasive/unclear about what kind of data one is collecting and for which purpose. This is one of the most important things (again, in my opinion). Processing of personal data has a valid and important purpose, and the GDPR is not there to stop it. But doesn't that make the GDPR just another "Cookie Law" (albeit with more effort to implement it)? The average person will not reflect on the permissions they give I am afraid. They'll mechanically accept them like they do with EULAs. I don't think that the GDPR is bad it's just that before launching it they should have made sure that people (especially kids in school) really understand what kind of madness they're currently engaging in.
- stingraycharles 9y ago> Any insight from HN insiders on how seriously companies big and small are taking this? CTO of a video service platform that caters to webshops here. We take it very seriously; we had discussions with our lawyers about this about 1.5 years ago, and have been preparing our data warehouse in the meantime to be able to fall under the "analytics exempt". On a weekly basis, there is at least one customer whose legal team is asking for some documentation / proof on how we handle this. We have had a compliance audit, which effectively tested whether - we were not doing third-party tracking, but only first-party - all our customers' data is segregated / separated from each other (which effectively means a different database per customer), so that data cannot be combined Perhaps this is a bit different in the ecommerce space than industry-wide, so YMMV.
- Radim 9y agoThe response is across the board. Some companies (B2B, larger enterprises) take it very seriously: form a compliance team, dedicate a budget for tools/consultants etc. Others have a "fuck it" attitude, self-author a 1-page PDF declaring GDPR compliance and documenting the "process", and wait for how the enforcement will pan out in reality. Most do the absolute bare minimum, hoping to claim "good faith" when (if) shit hits the fan [0]. The funny thing is, the larger enterprises have no idea what data they even have. Or where it is (never mind whether there's PII in it, or if it's compliant, or how to find out). They've acquired smaller companies left and right over the decades, each with their own databases, data shared in the cloud, forgotten backups, archives… A complete mess. The "discovery cost" for doing things by the book there is significant. We built some AI-enabled software to help with GDPR discovery (pii-tools.com), and the responses are varied, across the board. It's really interesting to watch the whole field progress and evolve through the imposed chaos. [0] "Having larger fines is useful but I think fundamentally what I'm saying is it's scaremongering to suggest that we're going to be making early examples of organisations that breach the law or that fining a top whack is going to become the norm. Our office will be more lenient on companies that have shown awareness of the GDPR and tried to implement it, when compared to those that haven't made any effort." - Elizabeth Denham, UK's information commissioner (in charge of data protection enforcement)
- mbrookes 9y agoPII (Personally Identifiable Information and its variants) is predominantly a US term. PII is much narrower in scope than Personal Data, as defined by GDPR. If your tool has broader application than PII, you might want to rethink the name. If it doesn't, you might want to rethink your target market. I agree that the response is varied. Disclosure: My employer sells tools for unstrctured data discovery and classification.
- Radim 9y agoHah, competition? :) Ping me an email, I'm open to a chat how we could help each other… it's a big pie.
- deleted 9y ago[deleted]
- dspillett 9y agoWe sell products/services to regulated sectors (investment arms of banks mainly) for managing compliance, training and competence. That sector for one, both large companies and much smaller ones, are taking the matter very seriously. I know people in the charities sector, and they seem to have taken or are taking pro-active action too - even people close to being "on the ground" have been given introductory training in some instances. Initially at least fear of enforcement will drive purchasing decisions, it already is doing: you won't sell as much of your solution if you can't slap a "GDPR compliant" sticker on it. It will affect existing contracts less but if your clients haven't started asking about it yet they may do in a mad panic over the next few months. How things go from 2019 onwards will depend on how sharp the teeth end up being and how often/effectively they are applied, but the general feeling I get is that this is not going to be a damp squib or quietly fade away after for first big bang.
- youngtaff 9y agoIn our analytics product we've moved ourselves out of the scope of GDPR by no longer capturing personal data e.g. removing last octet of IP addresses, storing location less precisely etc.
- tkoski-hs 9y agoIn our company, even we are "small", we have taken this very seriously (formed a team responsible of this, talked with layers, etc). Personally, for our kind of business (saas for other companies who uses our software with other companies and organizations), I find this a competitive advantage as well. Well done GDPR -> makes buying easier.
- BrentOzar 9y ago> Any insight from HN insiders on how seriously companies big and small are taking this? We stopped selling online training in the EU because of it: https://www.brentozar.com/archive/2017/12/gdpr-stopped-selling-stuff-europe/ https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli... I actually love the idea behind GDPR, but as a small company, the cost of compliance (and heaven forbid, responding to an EU inquiry) is just too high relative to the low amount of revenue we get from EU citizens. I'm looking forward to revisiting that in 2019 as WordPress, WooCommerce, Gravity Forms, etc make it easier to be compliant, but right now there's just no way.
- TeMPOraL 9y agoThat's a very informative post. I missed it at the time it was discussed on HN, so thanks for linking it. As an EU citizen, I can say your decision is totally understandable, and I sincerely hope that after the dust settles, you'll get your chance again to sell to EU customers. You might have more competitors by then, though - I fully expect that as various companies retreat from European markets and/or shut down the "products which were on the backburner anyway", we'll have local companies popping up to fill the void.
- kabes 9y agoI do consulting work for various companies inside the EU and they all seem to take it very serious. The EU has made it clear it's serious about enforcing these laws and the fines can be huge.
- MaxBarraclough 9y agoAh yes, the half-baked cookie law. Misguided, and never enforced anyway. I rather enjoyed http://nocookielaw.com/ http://nocookielaw.com/