8 ms·
It will cost companies so much money and time to be compliant with GDPR. Maybe even become a neck-breaker for some young startups
by janemanos 9y ago
It will cost companies so much money and time to be compliant with GDPR. Maybe even become a neck-breaker for some young startups
- edent 9y agoGood. Perhaps there will be fewer reckless start-ups who sell on my personal details without permission.
- jl6 9y agoYour insurance will cost more because implementing GDPR is costing insurance companies a lot of money.
- geocar 9y agoI hope so. If they were putting my data at risk because they didn't have enough money, then this was required, right?
- jenscow 9y agoYes, exactly. "Unfortunately we have to increase prices, because we now have be careful with your personal data"
- peteretep 9y agoI am comfortable with this.
- janemanos 9y agoWell, the cost for GDPR won't be that high, if the EU would have thought this through. Talked to a few of the GDPR "Consultants" and as soon as people have some more in-depth questions how A or B can be handled, you just get a surprised look. I'm all for better protecting my information but if you introduce these regulations you, as the regulator, also have to have answers to basic questions.
- jimnotgym 9y ago> Talked to a few of the GDPR "Consultants" and as soon as people have some more in-depth questions how A or B can be handled, you just get a surprised look. I'm all for better protecting my information but if you introduce these regulations you, as the regulator, also have to have answers to basic questions. Talk to better consultants. Consultants are not the regulator. The regulation itself is in plain language. What do you consider is not thought through?
- amarkov 9y agoI must delete personal data "without undue delay". This opens up a few questions, which as far as I can tell the text of the regulation provides no guidance for. * I (like most companies) have a variety of unstructured and/or immutable logs. I can't just DROP FROM table WHERE. Is it acceptable to delete this data by waiting a few days for a retention period to expire, or do I have to retrofit deletion functionality in? * What if the retention period is a week, or a month? What if I've been advised to establish those longer retention periods for other reasons? * If a bug is found in the data deletion workflow, is it an undue delay to say we'll tackle it next sprint? Do we need to drop everything and make it a priority now? * Once we've resolved a personal data deletion bug, is it an undue delay to roll it out slowly over a week? Does it matter if this is our standard rollout process, or if there's a risky hotfix process we're deliberately choosing not to use?
- vidarh 9y agoFor logs, I'll suggest you aim to avoid personal data in the logs, and if necessary only log an anonymous id and separately keep a mapping to a user for the bare minimum amount of time needed, and in a way that let you explicitly delete it easily. A lot of the "problems" of the GDPR goes away if you minimize the amount of personal data you process and retain, which incidentally generally will be good for your security as well.
- amarkov 9y agoA lot of the problems of the GDPR do indeed go away if you're building your systems from scratch, using data privacy standards significantly beyond what GDPR mandates. Surely you see why this doesn't weaken the claim that it's hard for existing companies to understand what must be done to comply.
- analog31 9y agoDid my insurance costs go down when companies started gathering and storing my personal information? I figure, if this stuff starts costing them more than a token amount, they can direct their IT manager to systematically erase the personal information that isn't utterly vital to their immediate business needs.
- jl6 9y agoOne example of the increased costs due to GDPR are that data subject access requests are now free to make. In the UK they used to cost £10. A small amount which never really covered the cost of fulfilling the request, but enough to deter frivolous mass use. Now that such requests are free, there is no deterrent and companies must introduce a scalable process for dealing with them (or risk being swamped and unable to meet the 30 day deadline). This will actually be easier for companies like Google and Facebook to comply with, as they are digital natives. Financial services is an industry struggling with a burden of legacy systems, and even paper-based processes still. This one GDPR provision alone is causing much expense and heartache.
- lagadu 9y ago> Financial services is an industry struggling with a burden of legacy systems, and even paper-based processes still. This one GDPR provision alone is causing much expense and heartache. That's a good thing. If it's causing much expense and heartache it means that our private data wasn't being handled with the necessary care and attention to value that it needed to be.
- qw 9y agoThe final law was finalised in 2016 and was expected since at least 3-4 years ago when the agreement was made in the EU parliament. Startups: It costs money to develop the systems to process personal data in the first place. I don't see any unreasonable restrictions in GDPR. If new startups plan for GDPR while developing the systems it should not add too much costs. It is basically about managing data responsibly and documenting how you utilise that data. Established companies: I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. This has happened to other industries as well, such as the tobacco industry who had to adjust to anti-smoking laws when the politicians could no longer ignore the negative effects.
- Erlangolem 9y agoWhen you move fast and break things, sometimes what ends up broken is you. That’s probably a lesson which needs to be painfully re-learned by some. As you said, too many have been outrunning real consequences for a while, but that’s not some inherent right, it’s a con. If personal info is worth what a lot of companies seem to think it’s worth, then governments have been downright negligent in their lack of regulation. Playing fast and lose with people’s identities should never have been acceptable, and complaining that the first wave of consumer protections is anti-business mostly tells you what kinds of businesses we’re dealing with.
- Silhouette 9y agoI don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. Some commenters in these discussions write as if all businesses deserve the GDPR and all its attendant overheads as some sort of punishment for assumed past transgressions. And yet I work with small businesses, and so unsurprisingly I also know many other people who do, and not one of those businesses operates with any sort of data-hoarding, privacy-invading model, nor would any of us ever want to. All that attitude teaches the next generation of startups is that they'll be penalised whether they try to act ethically and responsibly or not, so they might as well do the questionable things and make more money anyway. Surely that is exactly the opposite of what should be happening?
- FridgeSeal 9y agoI think you're viewing this as a blocker not an opportunity: if.youre a startup now, why wouldn't you be building your tech with GDPR in mind? Doing so makes it super easy to comply with from the get-go and puts you ahead of incumbent players and their inertia and legacy systems. You're going to have to do this at some point, may as well do it early and give yourself an advantage?