5 ms·
You hear the advice for new startups; only recruit the best from the start, cut away the fat from your task lists to only focus on the critical issues that gene
by davidjgraph 9y ago
You hear the advice for new startups; only recruit the best from the start, cut away the fat from your task lists to only focus on the critical issues that generate business.
Here's another, bake privacy into your company from the start. Create a culture that takes it seriously and threads it through everything it does. Once you have this culture you'll find it costs less than when you try to retrofit it after 3 years.
In terms of the benefits, I can only assume you're American to ask this. In Europe we view our privacy as a human right and that our lawmakers should protect that right, it's that simple.
- nine_k 9y ago> bake privacy into your company from the start. Create a culture that takes it seriously and threads it through everything it does. Replace "privacy" with "security" above, and you'll get the widely accepted best practice approach: "you cannot bolt on security later", etc. Likely it will work for privacy equally well.
- fvdessen 9y agoIt also works for performance, reliability, UX quality, etc. What GDPR does is forcing business to make privacy their core concern. Since time & budgets are inherently limited, this will come at the expense of something else.
- def_true_false 9y agoAs it should.
- arkh 9y ago> What GDPR does is forcing business to make privacy their core concern. Not really. It will mostly be a problem for companies which use a lot of SaaS services with no on-premise solution and companies in the business of selling their users data. Not gonna shed a lot of tears for those.
- shiven 9y agoWhat's your beef with using "a lot of SaaS services, with no on-premises solution"? Why waste money by locking it into on-premises hardware?
- inetknght 9y agoYou missed the entire point. How do you guarantee that the SaaS you chose is enforcing the privacy of the data you're paying them to process?
- ethbro 9y agoIn the same way that AWS wasn't originally certified for government work, and then developed GovCloud: they realized there was a lot of money in it. If supporting GDPRs is a requirement for having European B2B customers, SaaS providers are going to start certifying against and architecting around that.
- ajbetteridge 9y agoAnd AWS is already well on this https://aws.amazon.com/compliance/gdpr-center/ https://aws.amazon.com/compliance/gdpr-center/ https://aws.amazon.com/blogs/security/aws-and-the-general-data-protection-regulation/ https://aws.amazon.com/blogs/security/aws-and-the-general-da...
- tekknik 9y agoActually what it did for me was allow me to ignore the EU entirely. This makes my implementation more simple since I don’t have to focus on the GDPR and can ignore the localization crap from having 2 versions of English.
- rmc 9y agoCareful, the EU is a big market. If you exclude the EU, and get big enough, someone can just copy your business, but abide by EU law. Suddenly you have a compeditor who has access to a large market that you don't have access to.
- walrus01 9y agothis is extremely true from a network security perspective for new ISP infrastructure as well. It is very "easy" to start forming layer-2 and layer-3 adjacency between things geographically distributed around a city/state sized area without much regard to security. Will create a huge amount of work to come back and fix later. Whereas if you design the architecture from the start with security in mind (how you're going to deal with your management VRFs, monitoring systems, OOB authentication, NOC and neteng access to stuff in private IP space, etc) it will be much easier to scale.
- nitwit005 9y agoYou can't engineer this sort of thing away. A business that gets 1000 of these letters will have to hire someone to handle it, regardless of how good a job they did designing things.
- Gaelan 9y agoI mean, if those records are being kept, it shouldn't be that hard to make them easily user-accessible, right? Support people that got the letters could just give users the link to the page with the data.
- rebuilder 9y agoIt seems to me that could easily create a privacy issue of its own. Certainly just a link would be terribly insecure, you'd need to authenticate the user. And whatever you do, you've now created a web-facing portal to the private data you're supposed to protect. Seems risky to me.
- smartbit 9y agoIf you don’t keep the records of your customers, you’d answer those requests in no time. Aldi has become extremely succesfull without knowing their customer. Ikea probably the same.
- photon-torpedo 9y agoWhat about their employees? Aren't employees, or ex-employees, also entitled under GDPR to be informed about what personal data the company stores or processes? Honest question!
- Kliment 9y agoOf course, but they're entitled to this under pre-GDPR legislation as well, as I understand it.
- vsl 9y agoWrong. Even if I didn’t store anything besides absolutely necessary (does your product involve usernames or emails - bam, personal information) and was absolutely above board, it would take me hours to respond to this.
- briandear 9y agoWhen the EU bans telemarketing or sending me junk mail without my consent, then I might think the EU cares about my privacy.
- eropple 9y agoNeither of those represent threats to "privacy" in a typical legal sense. Both suck, but you're saying that you'll think the EU cares about car safety when they ban juggling.
- llukas 9y agoIt already does. Go figure.
- vsl 9y agoMy mailbox (the physical one) disagrees with your claim. There are mechanisms to opt-out (at the cost of uglyfying my mailbox with highly visible label), but they are not banned.
- samuellb 9y agoIn practice, no. The legislation has major loopholes, such as allowing unsolicited business-to-business marketing. And spammers still send junk to individuals with a disclaimer such as "This message is addressed to a business, if this is in error click here to opt out". And they seem to get away with it.