4 ms·
For me the question that a lot of people will be asking after 25th May, is what happens if they don't? I would bet on nothing. The GDPR is there to catch the w
by davidjgraph 9y ago
For me the question that a lot of people will be asking after 25th May, is what happens if they don't?
I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing.
- mschuster91 9y ago> I would bet on nothing. The GDPR is there to catch the worst offenders, the other 99% of offenders will feel nothing. No. The danger is that Internet goliaths will use the GDPR to intimidate or even shut down smaller competitors. Think of patent trolls, just worse - because the GDPR has really huge fines attached and is damn easy to get wrong in implementations. While the GDPR was intended to be beneficial to EU consumers, I fear it will end up being most beneficial to lawyers.
- deleted 9y ago[deleted]
- dpwm 9y agoI'm interested in how you think this would work. As far as I can tell, the enforcing authority for the country where the individual affected resides would need to investigate. And frankly, where a smaller entity was playing fast and loose with data, I would want the authorities to investigate. For instance, in the UK the plan appears to be for the ICO to work with companies and fine where there's a major breach and appropriate security wasn't implemented. Now, perhaps some individuals will band together and complain, but they do not stand to gain from the enforcement in the same way that patent trolls do. We're going from an era where companies can claim AES encrypted at rest and AES encrypted over the wire whilst running an ancient stack full of vulnerabilities and, above a certain scale, not even worry about it. I personally have high hopes that the GDPR will at least make people running companies like that worry a bit.