10 ms·
Where's the problem? To me it shows what an excellent job the creation of the GDPR was. It makes companies think in depth about the data they hold on me and how
by davidjgraph 9y ago
Where's the problem? To me it shows what an excellent job the creation of the GDPR was. It makes companies think in depth about the data they hold on me and how they process it. It also provides clear ways to question and challenge it.
I've seen a number of articles trying to frame the GDPR as some kind of shambles. The shambles is the way too many companies have abused and mis-processed the data for too many years and somehow the EU lawmakers are bureaucratic imbeciles. Yet, everyone I know is fully in favour of this as consumers.
And, for context, I am the person who will have to deal with these at our company. Our customers are absolutely entitled to expect us to process their personal information is a responsible manner and I hope a number of these letters are sent to every company, it's about time there was a power shift in this area.
- jcriddle4 9y agoAbout 50% of small business survive their 5th year and roughly 30% survive to their 10th year. The concern is the drip/drip effect of more and more regulation making those numbers even worse. In addition you may be saying to a poor or middle class person that the money costs of starting certain types business are not longer in reach due to much higher costs. A large well established business is in a much better position to weather these costs so the wealthy get wealthier. What are the costs compared to the benefits?
- EnFinlay 9y agoEverything there might be true. Everything might also be false. It might be cheaper to start a business because PPI information will be handled properly from the start and not be a cost centre. This might increase new business viability. Maybe there are no "costs". Just benefits and benefits?
- dsjoerg 9y agoIn general I strongly agree that regulations can be one of the slow drip/drips that crush a society over time. However there are two forms of complexity at war here; complexity for business (regulation) and complexity for ordinary people (having data about you everywhere, about everything, forever). So we have to decide which kind of complexity is worse, or how to strike the right balance.
- DenisM 9y agoYour logic applies to fire codes and food sanitary rules just as well. Doing the right thing is a burden, that’s why it’s called the right thing and not the convenient thing.
- jcriddle4 9y agoYes you are correct. What are the costs compared to the benefits? Is the additional privacy going to be worth it? If we discover a few years from now that European companies are sharing roughly the same amount of data with other companies as their American counterparts, just documenting it better, have you gained anything?
- bjelkeman-again 9y agoYes, because I can request it and ask for deletion.
- briandear 9y agoAre you willing to pay more for products and services? Because ultimately you will.
- jadedhacker 9y agoIf hiring one person changes the calculus that much, it's nonetheless easy to afford if profitable companies paid their workers more instead of sending it to shareholders or doing stock buybacks. The proportion of wealth held by the managerial class exceeds the Roman Empire at its height. https://persquaremile.com/2011/12/16/income-inequality-in-the-roman-empire/ https://persquaremile.com/2011/12/16/income-inequality-in-th... For reference, the gini coefficient of the united states in 2016 was 0.48. Rome at its population peak was between 0.42-0.44 according to the article. A gini coefficient of 0 is a perfectly equal society and a coefficient of 1 is perfectly unequal. Small startups also often get the benefit of reduced regulatory burden, which is fitting because they have less overall impact on society. Once they become large, it is fitting that they play by rules that benefit the majority.
- davidjgraph 9y agoYou hear the advice for new startups; only recruit the best from the start, cut away the fat from your task lists to only focus on the critical issues that generate business. Here's another, bake privacy into your company from the start. Create a culture that takes it seriously and threads it through everything it does. Once you have this culture you'll find it costs less than when you try to retrofit it after 3 years. In terms of the benefits, I can only assume you're American to ask this. In Europe we view our privacy as a human right and that our lawmakers should protect that right, it's that simple.
- nine_k 9y ago> bake privacy into your company from the start. Create a culture that takes it seriously and threads it through everything it does. Replace "privacy" with "security" above, and you'll get the widely accepted best practice approach: "you cannot bolt on security later", etc. Likely it will work for privacy equally well.
- fvdessen 9y agoIt also works for performance, reliability, UX quality, etc. What GDPR does is forcing business to make privacy their core concern. Since time & budgets are inherently limited, this will come at the expense of something else.
- def_true_false 9y agoAs it should.
- arkh 9y ago> What GDPR does is forcing business to make privacy their core concern. Not really. It will mostly be a problem for companies which use a lot of SaaS services with no on-premise solution and companies in the business of selling their users data. Not gonna shed a lot of tears for those.
- 9y ago
- sameline 9y agoIf a business cannot afford to properly handle and audit customer data then it should avoid any sort of collection. Businesses that produce value from customer data should be able to pay for necessary protections.
- cleansy 9y agoI usually register on non essential websites with a custome address like website.com@domain. Over the years I experienced several hidden data breaches as I look once in a while into my spam folder. This regulation gives me as a customer a good feeling as businesses are required now to think hard about their data protection strategy. As a business owner I have no problem answering these requests as I designed my software with data protection from the get go. Now it’s at least a requirement for all businesses which is good. This is a huge benefit for the consumer.
- mirimir 9y agoYes, this also gives great insight on who's selling data.
- bunderbunder 9y agoI wouldn't be at all surprised if it's actually cheaper for smaller businesses to properly handle personal data than it is for big ones. Big ones tend to have much bigger, more complex data systems that require complicated oversight and governance, and are presumably much more likely to engage in risky behaviors like dumping stuff into a data lake. This might have an outsize impact on startups that deal primarily in data about people. I'm actually pretty OK with that. Some kinds of activities really should have high barriers to entry.
- spanktheuser 9y agoThe benefits are to me as a consumer, of course. Just because companies would prefer to treat data and security as burdensome doesn't mean that I should let them. As an argument to reverse this regulation, this seems unconvincing.
- groby_b 9y agoI don't give a fig about startup survival rates. I care about the fact that they're currently making money by externalizing costs. Yes, it makes it harder to get into some areas. If that means a net positive for society, I'm surprisingly OK with that. There's no intrinsic reasons why we should care how many companies survive.
- Jach 9y agoOf those small businesses how many had business in Europe? You can aggregate or split by success/failure.
- kartan 9y ago> The concern is the drip/drip effect of more and more regulation making those numbers even worse. There are industries, like construction, that have a lot more regulations that this one. And small companies survive. > What are the costs compared to the benefits? Benefit: Citizens have the right to protect their privacy, to not be tracked without reason, to be notified when a data breach put their safety at risk, etc. Cost: Companies need to have reasonable data governance that will increase short-term cost, but probably have a long-term positive impact on cost as bad data governance is just technical debt.
- _o_ 9y agoIf you have taken GDPR into account from the start, the costs are trivial, it only means you will organize data differently so this "startup worrying" thing is a nonsense. Those worries are trying to do PR from companies/developers that are used to capture as much as possible from customers (potentially also sell those data) and are basing their bussiness model on that. The real cost comes in "old" companies. Those should complain, but those are also responsible for need for GDPR.
- frozenport 9y agoHow does a company with 3 employees respond to this? It would be good if, like FDIC insurance, small companies could opt out, with the obvious disclaimer they do not comply.
- closeparen 9y agoThis website is inherently an egregious GDPR violation. It collects the most highly protected data category, political views, stores it forever, shares it with everyone on the internet, makes opaque automated decisions related to ranking, vote weighting, and anti-spam, and provides no mechanism for takeout or deletion. Because it's publicly available, an unlimited number of unregulated third parties can obtain your data and process it for undisclosed reasons without your opt-in. Can anyone explain how it's possible to be positive about GDPR and HN at the same time? I'm not surprised that some people like it. I'm stunned to see them commenting here.
- sushibowl 9y ago> It collects the most highly protected data category, political views It collects user comments and posts. What you post to this website is entirely under your own control, and there is plenty of opportunity to meaningfully participate here while offering not much more than technical opinions. Furthermore, none of the information you post here needs to be personally identifiable, under the definition of the GDPR. It is identified by a username, which can be completely arbitrary and unique. You could even use a new one for every post you make.
- cromwellian 9y agoI'm pretty sure HN is holding onto PII, including IP and Email, which is enough to tie your account to others and de-anonymize you.
- yorwba 9y agoYou don't have to tell HN an email address. They should have appropriate privacy protections in place for the PII they do store, but they should have that even without GDPR.
- mirimir 9y agoI do agree that we all can choose what to share on HN. Usernames can be as arbitrary as you like, and not linked in any way to meatspace identity. HN allows registration and posting via VPN services. And maybe even via Tor. However, it does appear that GDPR will require that HN delete a user's posts upon request. It might even require that HN delete posts that mention other people, including nonusers. Edit: Yes, also via Tor. It did ask for an email address, for password resets.
- bobcostas55 9y ago>It makes companies think in depth about the data they hold on me and how they process it. Except, of course, if your company is one of those favored with an exemption from the GDPR. Because we can't have everyone playing by the same rules in the EU.
- zapt02 9y ago> exemption from the GDPR Who has received that? Can't find anything by searching.
- bobcostas55 9y agoHere's one set of exemptions: https://gdpr-info.eu/art-85-gdpr/ https://gdpr-info.eu/art-85-gdpr/
- chasb 9y agoProposed, not yet effective: https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spark-outrage/ https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
- pnathan 9y agoTo be completely honest, from everything I've seen, I'd love to see the GPDR be copy-pasted into US law and made a part of international treaties. It seems like The Right Thing to do.
- Tomte 9y agoThat would be great because even we Europeans would profit from it: US regulators and law enforcement can be incredibly brutal.
- rmc 9y agoThere's a good chance that a lot of big US tech companies are going to apply the GDPR to everyone. It'd be too hard for (say) Facebook to have 2 databases.
- aazar 9y agoTo create the data subject access request, you first need to understand your own internal process. For that, you need to comply with article 30 i.e. records of processing activities. We help you create at that ecomply.io and then once you're done, we will help you create data subject access request as well.
- ryandrake 9y agoReading through the "nightmare" letter, I was looking for something I'd consider unreasonable for a user to be concerned with or ask about, and couldn't find anything. Honestly, this seems like a pretty low bar. If you can't answer these questions about your business, I'd be loathe to continue doing business with you. I'd surely be reluctant to let you collect my personal information.
- rebuilder 9y agoI'm not very familiar with the legislation. Is a company receiving such requests required to respond to them individually, regardless of merit? If so, it seems blasting a few thousand requests at a small company would be a fairly simple act of sabotage. Even if the requests are fake, it would take the company time to figure out that they don't have any relevant records and to figure out whether to respond and how to respond.
- chasb 9y agoGDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/ https://gdpr-info.eu/art-15-gdpr/ The right can only be enforced against a "controller," which is the entity that "determines the purposes and means of the processing of personal data." It's worth noting that GDPR does not give the data subject the right to request everything in the letter. Only a more limited set of things. The practical effect for SaaS companies is that they should keep track of data and the systems and services where data is processed. With good preparation and a system of record for security/privacy management data, you can prepare for this kind of request very well. My company does just that - helps others prepare.
- piokoch 9y agoTrue, the only issue I see here is that big company will manage to adjust to GPDR rules or cleverly trick users of the service to allow for all they want (I guess the number of users who does not agree for changes in terms and conditions that keeps showing up on Facebook or Google pages is not large). Small e-commerce sites (someone sells socks, hand made goods, used pianos, etc.) are different story here. Usually such sites were put together on some ready-made PHP + MySql solution hosted on a 100 bucks a year hosting and that was done by some small IT shop specialized in this kind of business. Owners of such small firms are going to have really hard time with GPDR. I suspect there will be a lot of scummy law firms that will go after them and blackmail them either to use their "service to be GPDR compliant" or be sued under GPDR. Such people are an easy target, they don't even realize that maybe software that was installed for them by some third party that no longer exists puts to logs customer first and last name, or there is somewhere backup with customer e-mails. This law will have zero impact on say, Facebook, people would give them their data freely as they do now, average FB user will not risk to "get imperfect Facebook experience" (or some other similar clause that clever FB lawyers will figure out) if they block permission to be tracked and their data cannot be sold to advertisers.
- rmc 9y agoOne requirement of EU data protection law is "informed consent", which must be freely given. Pages of legalese that we all know no-one reads, then you could say it's not informed consent. And you have to be able to revoke consent, at any time, and it has to be as easy to revoke consent as to give consent.