9 ms·
God damn it EU, all these regulations make it impossible for small companies, indie developers to cope with all the bureaucracy. The VAT for digital products,
by boggio 9y ago
God damn it EU, all these regulations make it impossible for small companies, indie developers to cope with all the bureaucracy.
The VAT for digital products, now the GDPR.
10 more years of regulation and you will spend 90% of the time working on implementing legal requirements and 10% on the actual product.
- lucideer 9y agoGDPR—while vastly different to what has become the defacto standard practice in most companies—is largely simple, basic, common decency and common sense. My very tiny startup won't have any problems complying because we've actually given a smidgen of consideration to our users' privacy up until now. In fact, I foresee it being a much greater tax on large corporations: the work in GDPR is not compliance—that's relatively easy once you have procedures in place—the real work is converting existing non-compliant systems to bring them into compliance. This is going to be much easier for those maintaining relatively small, simpler systems, and easiest of all for brand new startups.
- davnicwil 9y agoFrom what I have seen and understood about the regulations and the spirit of them this is basically right. If your system was intentionally designed with both privacy and the ability for users to own their data (i.e. edit & hard delete whatever, whenever for any reason) in mind, then GDPR should be essentially complied with already 'out of the box'. If this was not the case, either for cynical reasons, simple disregard for the importance of these things, or a decision to not prioritise these things in favour of shipping more features faster, and you just essentially slapped a checkbox with some legal copy over your signup process and thought you were done with all that pesky user data privacy stuff, well, you're in for a pretty bad time now. Maybe my reading of it the regulations is naive and it won't be so easy in the first case and will be easy to subvert anyway in the second case. But if not, to be perfectly honest it seems just like what good regulation should do - incentivise good behaviour - allowing businesses that behave well by nature to thrive without too much extra hassle introduced, and suppress both the bad behaviour itself and the general productivity of the business behind it where that's not the case.
- crazygringo 9y agoI'd hardly say that. "Forget me" can take a lot of design work (can introduce a ton of edge cases). "Export data" requires building an entire information processing pipeline. Larger corporations have the resources to dedicate to this. But for a small startup deciding between spending 4 dev-months on "forget me" and "export data" versus on enabling the top 3 new primary use cases users are asking for, I understand how this could feel really difficult. I really wonder if it wouldn't be better to make some of the requirements only for companies above a certain revenue threshold or the types of data collected. (E.g. export data is critical for health or finance-related sites, probably less so for a meme generator startup.)
- geocar 9y agoI would. I'm doing some GDPR consulting at the moment and most of my conversations are "I don't think it's as complicated as you do". Americans tend to read law very pathologically unless they are familiar with how European legislation works, and every programmer out there thinks they are an armchair lawyer since there are "obvious" skillset similarities between decoding software and decoding law. "Forget me" is very simple: If someone calls you up and asks you to stop using their data, you stop using it and remember that they've done this. You do not have to: - Destroy invoices - Delete web logs - Delete the record of them asking you to stop using their data - Reprocess all of your backups - Recall any reports you might have sent out Or anything else that is silly. But your salespeople aren't allowed to see that person's details in your CRM anymore. "Export data" is also very simple for most companies. If you have a CRM containing information about a person, then that person can ask for that information. > probably less so for a meme generator startup What possible "personal information" do you think a meme generator startup actually has to collect on individuals that aren't their customers? They should have a CRM containing companies who are purchasing advertising space on their meme generator startup, and perhaps leads that they have obtained through various incremental marketing sources. They probably do not have any personal information on their users, or if they do, their business will not be impacted by simply not collecting that personal information. But maybe I don't understand what a "meme generator startup" would do because I'm not in their target market.
- 9y ago
- deleted 9y ago[deleted]
- dagmx 9y agoI'm not sure I've read anything in there that is hard to implement, other than retroactively. I'm sure as time passes there will be frameworks and best practices developed for conforming to these regulations, but I honestly don't see anything egregious or complex to develop in there.
- mycall 9y agoSo what's the alternative? Completely lose all of your privacy? It is only developers who can fix this massive PPI leaking.
- nawitus 9y agoThere's plenty of alternatives. The main problem with GDPR is not the goal of advocating privacy but the details. I would have done it like this: a) bring out regulation gradually instead of in a single big change like GDPR to have companies time to comply b) don't write vague laws c) give specific examples of what GDPR means in practice d) be more lenient on smaller companies
- bozho 9y agoa) companies had 2 years go comply. Furthermore, the guidlines of the European Commission are clear that the process should be gradual - inspect, write recommendations, small fines, bigger fines. Nothing like "20 million in June" b) the law had to cover a lot of usecases and in order to do that concisely, it may sound vague in places. I also don't like (developers never like uncertainty), but there's established practice already in regulators and courts about what is considered "adequate", "appropriate", etc. I agree it could've been better though. c) that is happening already, e.g. ICO (the UK regulator) has a pretty good set of guidelines and examples. There's also the process of "prior consultation" where if you are not sure about something, you go ask your regulator for a decision d) this is exactly what the "proportionate", "adequate", etc. are in for. If you are a small company with 2000 data records, you are not posing a high risk for the rights and freedoms of data subjects and so most of the things are not a strict requirement
- nawitus 9y agoa) The problem with this is that this practical guide was released in November 29, 2017. And this is unofficial. EU should have released a practical guide two years ago in my opinion. If the process is gradual the law should reflect that. c) Good to hear :). Apparently it's this: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/ https://ico.org.uk/for-organisations/guide-to-the-general-da... - I hope it's not written from the perspective of the UK legislation. d) The law should clearly define what is required for smaller companies and what is not. There's some disagreement if this is the case in GDPR articles too.
- rectang 9y agoIt wasn't the company's data to begin with. Modern businesses have caused harm to countless individuals by treating data cavalierly. The GDPR puts things right. It brings the externality into the market, and now the market can correct. Businesses that rely upon slinging private information around irresponsibly need to adapt. If they can't, their failure in the marketplace is just.