6 ms·
I wanted to send you an email or a twitter DM, but your HN profile doesn't list contact info. (I'm anonymous because I am a moderately visible figure in the tec
by gdpr_throwaway 9y ago
I wanted to send you an email or a twitter DM, but your HN profile doesn't list contact info. (I'm anonymous because I am a moderately visible figure in the tech community and don't want what I say to result in my company getting flamed.)
I wanted to tell you how impressed I am with how patiently and clearly you've responded throughout this comment section.
I likewise think the intent of the law is admirable: prevent future Equifax-es, give people control over their data, and centralize the requirements so that companies need to comply with a single EU standard, instead of 28 country-specific ones. But the amount of discretion left to regulators and the lack of any sort of proportionality built into the law make this all very scary. We are expecting a fifteen person small business to have a totally impractical degree of _documentation_ and _formal_ processes, which are 1) very expensive to produce, 2) totally unnecessary for an otherwise reasonable and well-intentioned group of people, and 3) crucially, basically orthogonal to actual data privacy and security best practices.
And even if you comply with the letter of the law, just reading and understanding an email like the one in this post will require hundreds of dollars of company time – beyond reading it, it will need to be escalated, someone will need to loop in a few other people to help with any new technical details, and so forth. If the fully-loaded cost of a white collar employee is $75/hr, this all gets expensive very quickly, and that cost can be levied on a company by an email that can be sent in one minute. Nobody is going to bring down Google with GDPR-spam but it would not be hard to do serious damage to a company of ten people.
There are a lot of well-meaning thoughts in this thread from people who are frustrated at the status quo but unfortunately don't understand how little this law will do to change it and how huge its costs will be.
When you try to deliver a novel product and build a business around it, you are forced to develop a strong sense of practicality and an understanding of the machinery of a business. Most people have never done this. Despite being very intelligent, a lot of these people haven't experienced the realities of creating a business, and as a consequence they don't really understand just how harmful this kind of law can be.
I admire how patient and articulate you are. (And I think your thoughts are clear and your point of view is correct and badly needed.) Would love to buy you a beer sometime.
- lagadu 9y agoI disagree with you in the burden that GDPR places on a company. If a company takes data protection seriously handling such a letter would be a matter of minutes because they already have the processes in place. The GDPR is almost two years old now and it's just an update of the DPR which has been in place since the mid-90s: nobody should be caught by surprise by now except companies that deliberately decided that making sure you're compliant with the law is something that should be ignored right until the cops are knocking at your door.
- Silhouette 9y agoThank you, that's nice of you to say. The ability to contribute honestly to this sort of controversial discussion is exactly why I have a pseudonymous account, so sadly I won't be able to take you up on that beer, but I do appreciate the thought.
- gingerlime 9y agoCouldn't agree more. It's not just that I can totally relate to everything Silhouette was saying, but he/she definitely presented their thoughts calmly and thoughtfully, even in the face of quite blatant trolling in a few instances. Since Silhouette (and gdpr_throwaway) want to keep their anonymity, I opted for virtual beers by upvoting :) But happy to convert those karma points to real food or drink -- and hopefully an insightful conversation -- if you feel like getting in touch (my details aren't so private).