8 ms·
> Facebook will do just fine, they had years to prepare and an army of lawyers. They won't do fine. Don't want to go into details but their actual products/req
by waytogo 9y ago
> Facebook will do just fine, they had years to prepare and an army of lawyers.
They won't do fine. Don't want to go into details but their actual products/required architectures for their products just can't be GDPR compliant. And they didn't prepare anything. You confuse them with Google--they prepared GDPR but FB?
Btw, one of GDPR's key motivation was to take FB down.
- ionforce 9y ago> one of GDPR's key motivation was to take FB down. Do you have a citation for this claim?
- stochastic_monk 9y agoWithout a citation, I doubt this claim and wonder if you have any personal investment in or relation to Facebook or a similar company whose profit is generated by selling or buying personal data.
- x0x0 9y agoNo, but I have to comply with the GDPR. The first thing to understand about the GDPR is much of it is quite vague, and is essentially a framework for rule making for 30+ privacy regulators. See eg legitimate interests where you are supposed to conduct a balancing test between competing interests with very limited guidance on what a reasonable balancing test is. Second, these lazy morons haven't issued final guidance approximately three months out from the deadline. Now, there is some guidance, but there's no hard cap on the distance between working and final guidance. How they expect companies to comply with that is obvious: they don't, and will use the opportunity to fine them. The ICO has been quite explicit about this; I don't have quotes on this laptop but one of their senior staff basically said that grace periods are not part of their regulatory strategy. Grace periods are apparently only for the regulators. And that's the ICO, one of the more reasonable regulators! The french regulators, who aren't particularly reasonable, are no doubt anticipating the influx of cash. So if you're a company that is relying on some mix of legitimate interests and consent to service your customers, market, and perform outbound, it's very difficult to understand what the rules are. And this is worse if you are an American company and therefore probably don't have a lead regulator and will have to attempt to comply with the (almost certainly) conflicting rules as decided upon by every privacy regulator instead of just one. Much of the GDPR is quite reasonable (besides the DPOs, ie employment program for EU lawyers) -- privacy dashboards, the ability to delete data, SARs, etc. But it's wildly unreasonable to not have final regulations in place.
- stochastic_monk 9y agoI agree that it should be better executed, but I’m glad efforts for consumer protection are being made at all. Thank you for your thorough explanation.
- blibble 9y ago> Btw, one of GDPR's key motivation was to take FB down. this all seems very similar to the new VAT scheme, in that it was designed to target a foreign giant (Amazon), which was barely affected as a result, and instead ended up hurting the competitiveness of the EU's own small businesses the EU Commission's response to small business concerns about that new VAT scheme? "we'll allocate some time to talk about that in 5 years" fantastic
- jimnotgym 9y agoCan you elaborate on which scheme you mean please?
- blibble 9y agohttps://www.theguardian.com/small-business-network/2014/nov/25/new-eu-vat-regulations-threaten-micro-businesses https://www.theguardian.com/small-business-network/2014/nov/... and https://www.theguardian.com/small-business-network/2015/sep/14/eu-propose-vat-exemption-small-businesses-protests https://www.theguardian.com/small-business-network/2015/sep/... my solution was to stop selling into the EU, though amusingly once the UK leaves the EU I'll be able to start again (by just ignoring the EU's VAT rules)
- jimnotgym 9y agoI knew about that but I was thrown by this > new VAT scheme whereas this is from 2015. I was confused by language where you described it as a law to target Amazon. Now I see that was just an opinion. > my solution was to stop selling into the EU Interesting business decision. Was the cost of compliance that high, or was your revenue that trivial? > though amusingly once the UK leaves the EU I'll be able to start again (by just ignoring the EU's VAT rules) Well I was having a conversation with one of the UK's foremost VAT specialists on Friday, from one of the UK big 4 accountancy firms. He was very clear that the general opinion is that the UK will align with the EU for VAT. This was a response to my question about the catastrophic cashflow impact that losing the VAT rules on imports would have to UK businesses. He told me not to worry, as VAT alignment was simply a necessity.
- dang 9y agoA grandiose claim offering nothing better than "don't want to go into details" counts as unsubstantive and flamebait, two qualities that are deprecated here. In the future, could you please either make a comment like this substantive, or just not post? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- waytogo 9y agoDang, no need to get aggressive. I was on mobile and had not the time explain why all products around Facebook—which need to collect user's behavioural data to target ads etc.—can't ever get compliant with the strict GDPR. I guess you are not informed about GDPR. If you were my prior message with a "don't want to go into details" would be have been super clear. So, this is a misunderstanding and again your aggressive tone is for somebody who is representing YC just sad. Besides, thanks that you gave my profile more gravity when posting comments. Now my comments drop so quickly (first seconds after posting) and people with 0 karma move above me. Great way to deal with different opinions, Dang.