8 ms·
Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the
by taylorswift_ 8y ago
Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to focus on the critical period of acquiring users and instead would be forced into building compliance features.
I firmly believe that the majority of people still don't care about their privacy in the first place or they wouldn't use such platforms. IMO this is government overreach and anti-competitive.
- j32fun 8y agoI think a few blogs have touched on this: * https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce... * https://www.smashingmagazine.com/2018/02/gdpr-for-web-developers/ https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo... * https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ * https://pagefair.com/blog/2018/granular-gdpr-consent/ https://pagefair.com/blog/2018/granular-gdpr-consent/
- taylorswift_ 8y agothanks, wow responding to a letter like your first link could significantly bog down resources for a young company... you can imagine if you launched and even received moderate user growth early on, but then started receiving such letters, your productivity could go down the tubes.
- j32fun 8y agoI think so too. It certainly makes one question what kinds of app I would want to build.
- deleted 8y ago[deleted]
- ryandrake 8y agoHonestly, those questions should be pretty easy to answer especially if your company is small. If as a business you can’t answer these basic questions about the data you want to collect from me, I’m going to be hesitant to share it. People keep sharing that “nightmare letter” link but won’t point out which question gives them nightmares and why.
- Kalium 8y agoA couple of things stand out to me as potentially scary. First, the hard one-month timeline. For a brand new baby startup, a month is a lot of time and any distraction potentially killer. Second, a list of everything across all types of storage in any and all systems stands out. Even large companies often lack the ability to search ZenDesk, Salesforce, email, AWS S3, and Slack logs all at once. Third, there's a clause that asks quite specifically for a thorough list of any and all potential future plans. That's a lot, especially given how startups are subject to pivoting. Fourth, the section about third parties is essentially asking for the outcome of a vendor assurance process. A lot of small companies can't pass a reasonable vendor assurance process. They often can't afford the time and assurance specialists to manage one for their vendors. Even large companies often have trouble maintaining the level of control required for thorough vendor assurance. The bit about legal reasoning implies the involvement of a lawyer as well. Fifth, there's a strong implication that no matter what you might say in response, it's not going to be good enough. There's always something that can be pointed to as not enough. With all of the above combined, I can see where some might view GDPR as intimidating and favoring big companies over small ones through sheer costs.
- Fradow 8y agoI'll point out which question gives me nightmares, as the founder of a EU startup: - the requirement to have a DPO. Based on the requirements for the DPO, no one in the company can fill the role (conflict of interest), so we must hire an employee or consultant (expensive either way for a small startup) - one month to respond. That's a lot of informations to collect the first time, and I might have other fires to put out (or I have to be pro-active and have a prepared respond, which has the take the place of something else important to do) - the sheer amount of informations to collect. In the age of plug and play solutions, that's a LOT of things to audit (Mailchimp, AWS, GA, Heroku, various Wordpress plugins, logging solution I don't even remember the name, just to name a few) - tracking every single PI of a user. If your systems are not built for this, it's going to be lengthy. If you were created before the GDPR, they are probably not. - tracking down the usage of those PI may be complicated depending of the expected scope and usage you do (fortunately for me, there is no ad nor data resell, so really only the scope is the problem) - some process asked for have a serious implication you should have some and do some sort of things. This is not feasible for a small startup. It boils down to: it takes time, and time is something I'd rather use for something else, and it also requires to do things that have huge fixed cost that the size of a small company can't absorb (at least not until there is a ready-made solution). I define small startup as startups with less than 20 employees, that might have received Seed funding but not more. Those points might not all be applicable to a new startup created with GDPR in mind.
- deleted 8y ago[deleted]
- lucideer 8y agoI disagree. Here's an outline of what a response to the letter in that first link should look like for a small, well-meaning* startup: The letter is nicely formatted into 9 bullets. All are optional for small companies, and all can be automated - the answer should be the same for all users. 1. This is a "yes" or "no" question. If the answer is "no", you can ignore the rest of the letter. If yes, the answer is the same for all users. 2. Simple, short, same for all users. 3. You can avoid doing if you want. If you are doing this, you're signing up to take on this additional burden of informing your users. Consider this when making this decision. This is the only bullet in the list that is in any way burdensome as you will need to update this text in your automated response whenever you take on 3rd-parties (if at all). 4. Simple, short, same for all users. 5. and 6. are "if" conditionals that you shouldn't be doing. The answer should be "No". 7. Amounts to "has my data been hacked". If yes, that's unfortunate, but obviously you have a moral obligation to respond here regardless. Presuming you're hacked once, you provide full details once and send automatically to any users who ask. 8. and 9. are out of place. GDPR doesn't require you to respond to these questions within this quoted 1 month time limit (you do have to have what's detailed within them in place to comply with GDPR but that's tangential to info requests). These seem to have been put into this blog post as extra scaremongering. * by "well-meaning" I basically mean "not selling all of your users personal data to myriad nefarious 3rd-parties"
- Kalium 8y ago> 3. You can avoid doing if you want. If you are doing this, you're signing up to take on this additional burden of informing your users. Consider this when making this decision. This is the only bullet in the list that is in any way burdensome as you will need to update this text in your automated response whenever you take on 3rd-parties (if at all). Pretty much everyone is going to. Google Analytics, Zendesk, Salesforce, and more all qualify. Hell, even AWS qualifies... > 5. and 6. are "if" conditionals that you shouldn't be doing. The answer should be "No". Why do you say that? Given that we're discussing technical companies, I fully expect that automated decisions will be made. > 7. Amounts to "has my data been hacked". If yes, that's unfortunate, but obviously you have a moral obligation to respond here regardless. Presuming you're hacked once, you provide full details once and send automatically to any users who ask. And "detail all your security measures". Which, for a small company that doesn't have an InfoSec group, probably means next to nothing. An admission that feels a lot like liability... > 8. and 9. are out of place. GDPR doesn't require you to respond to these questions within this quoted 1 month time limit (you do have to have what's detailed within them in place to comply with GDPR but that's tangential to info requests). These seem to have been put into this blog post as extra scaremongering. It's the sort of thing an angry consumer might do, and most startup founders subject to GDPR are not deeply knowledgeable about it.
- josephagoss 8y agoBased on the first link, that letter scares me a lot. I have a feeling that this level of regulation will destroy any social startup. You'd need a compliance department larger than engineering just to remain legal. This is clearly a win to Facebook.
- vorpalhex 8y agoOr you just build your permissions and opt-in platform as a base for the social app. We wouldn't let a self driving startup ignore traffic laws because it's "too hard". Likewise we shouldn't let a social startup ignore privacy laws and auditing.
- Spivak 8y agoAt least on the surface it doesn't seem that bad. You just have an opt-in data collection with (type-of-data, purpose-of-data) tuples and let users actually delete data on request. Allow Socially to collect the following information for the purposes of providing you service: - Minimal Account Information: email address and password To prevent spam if you don't provide additional profile information you will be required to verify your account with a valid government ID. Only the expiration date will be stored. - Information posted to your timeline. Without this you will be unable to post updates. - Messages sent to others. Without this you will be unable to send messages. - Profile Information: Name, Address ... Allow Socially to collect the following information for the purposes of protecting your account: - Network Addresses used to access the service. - Login location - Login times After a short time using the service if we see a login that doesn't match the information on record we will notify the primary email for approval. - Links to other sites you click. We will check links you click against our list of known phishing sites and scams and warn you before redirecting you. Allow Socially to collect the following information for running internal studies and improving our service. - Features you use. - Posts you read. - Links to other sites you click. Allow Socially to collect the following information to help make ads more relevant to you: ...
- annabellish 8y agoI kind of feel like every question in the first link is entirely reasonable and people _should_ be able to get those answers, though. Nothing in there is onerous if you're following good practices anyway. I really feel like the answers to all of those questions are going to be basically identical between people, and all you really need to do is be able to export whatever data you have on somebody quickly in order to be able to respond to that email in under quarter of an hour. I guess it could make a decent DoS tactic against a small company, but lots of other things would too.
- mi100hael 8y ago> respond to that email in under quarter of an hour. Let's take an app like Instagram as an example. Instagram had over 1 million users within two months and 10 million within a year, and no profits. You're running on a shoestring trying to keep servers online without any serious budget to speak of. It's probably you and a few friends/associates working closely together. All of a sudden with GDPR, you have to pay a lawyer to help you understand what you need to do to comply with the regulations. You also have to spend engineering time developing solutions to enable the queries in that letter, enable purging records from long-term backups, etc. And people have to spend the 15 minutes responding to each request. Now, let's say each request does only take 15 minutes like you suggest (which I find highly unlikely). If a small fraction like 0.5% of your customer base sends such a letter, then that's 50,000 letters. At 15 minutes each, that's 12,500 hours which is over 6 full-time employees. Many small business don't even have 6 employees to conduct the entirety of their business right now!
- annabellish 8y agoIf the concern is that business owners can no longer cut costs by being lax with people's data... isn't that the whole point of the GDPR? That we've collectively decided that letting people cut those costs is having too many negative concequences too often and that we need to stop?
- mi100hael 8y ago
- AJ007 8y agoI would strongly recommend reading what Pagefair has been putting. They have been one of the few sources I've found that is take GDPR literally. It isn't even clear what level Google's compliance will be - https://pagefair.com/blog/2018/googles-nonpersonal-ads/ https://pagefair.com/blog/2018/googles-nonpersonal-ads/ There are a lot of extremely serious questions that arise regarding network security, anti-fraud, and anti-abuse measures. Just looking at basic bot detection measures, all of the sophisticated methods are now illegal. It certainly requires a major re-think of how websites serve content as well as the sustainability of advertising as a revenue channel. I can't even wrap my head around how someone would run a GDPR-compliant dating website/app. If you think Pagefair's interpretations of the GDPR are correct then Google and others are calling the EU's bluff. They are implementing part of the GDPR strictly but the parts which invalidate their business models are being interpreted more liberally or ignored altogether. I'm not saying that the GDPR is a good idea, bad idea, morally right or wrong. Rather, a lot of things we have come to view as a given -- such as how we detects bots, fraud, and abuse -- are no longer valid. Infrastructure, both technical and business, will need to be re-designed either to comply with the GDPR or evade it.
- maaaats 8y agoRead about what GDPR actually entails. Following it should be simple for a new player.
- arkh 8y agoBut how can you have enough user-growth to get vast amount of money from investor if you can't play fast and loose with the data you collect on your users? Fuck the users! They're not the clients.
- TAForObvReasons 8y agoYou forgot the key Silicon Valley ethos: "Move fast and break things", where things include ethics and users' privacy expectations
- taylorswift_ 8y agoWell the world has changed clearly. When facebook/myspace started out, would they have been able to achieve success if they were bogged down with data privacy compliance?
- deleted 8y ago[deleted]
- Kalium 8y agoYou're right! All the stuff about right to be forgotten, right to view, right to make corrections, and so on should be very straightforward and easy for any company of any size interested in being honest. Especially for new players, who don't have ugly legacy systems to wrangle. Yet... I've read through GDPR. All ninety-nine articles are chock full of "reasonable measures" and similar verbiage. Unless you can afford a compliance specialist - which isn't automatic for a new player - it's intimidating as all hell. What are reasonable security measures, as seen from by a careerist somewhere in Brussels? The text is silent on what exactly that means. It's possible that respecting users and having good intentions may not be enough...
- deleted 8y ago[deleted]
- ryandrake 8y agoA lot of people don’t care about fire safety either (until their house is burning down) which is why we have regulations, building codes, mandatory sprinklers in offices, etc. I am starting to look at privacy like it should be treated as a public safety concern, since it’s invisible to people until it’s not.
- taylorswift_ 8y agocan social media kill you though? I mean all this talk of regulating social networks is under the assumption that it's something you need to have. I would argue that safe shelter is a true human need, but posting cat gifs or pictures of drunken escapades or political musings does not seem equally comparable and thus I do not see how regulation does anything other than hamper competition.
- matthew349hall 8y agoUm yes, yes it can. Think about all of the times you here of bullying/suicide cases prompted by social media.
- webbles 8y ago1 million people genocided in Myanmar, you ignorant cunt.
- mannschott 8y ago> can social media kill you though? I assume you're aware of this: https://techcrunch.com/2018/03/13/un-says-facebook-is-accelerating-ethnic-violence-in-myanmar/ https://techcrunch.com/2018/03/13/un-says-facebook-is-accele...
- taylorswift_ 8y agoI don't think it's an equal comparison... the effects of social media on societies is a somewhat subjective matter. It's more likely that social media is just another tool that exposes the underlying human nature. That said, if a fire occurs in my shelter and I don't have sprinklers installed, I could die.
- ggg9990 8y agoIt’s not really as bad as that. Practically, the EU lawyers are not going to prosecute some dumbass no-revenue “Tinder for cocktails” or similar. They are out for money and only going after the guys who are big enough to pay but haven’t complied yet.
- arkh 8y agoThe more I read people against GDPR the more I get the feeling they're the same kind of people behind mail based scams.
- Matticus_Rex 8y agoIt depends on what part of the GDPR you're against. I'm generally in favor of a lot of the GDPR's goals, but the execution is pretty clumsy and a few of the provisions are at best useless and impose unnecessary costs.
- ozim 8y agoI wonder which ones specifically? I am reading into it because I am onto implementing it in our small company. Everything is as in citation from GDPR: "Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes ... implement appropriate technical and organisational measures ..."
- Matticus_Rex 8y ago1. Most things fall into this category: Lack of clarity in the law (and a remaining lack of clarity from WP29 and the Commission) about dozens of issues. The Privacy Professional community has been proactive about trying to get info on a lot of these items, but there's just not much coming, and in a few cases what has come out has either departed from what seemed like more obvious meanings or in some cases has muddied the waters further. 2. The essential ban on offering services, downloads, etc. in exchange for consent to use data reduces consumer autonomy and will decrease the availability of free resources. 3. It will be extremely easy to use SARs maliciously, and the law includes NO check whatsoever on this. All it would take to cripple many SMBs is for some jerk to spin up a website that provides a nasty SAR template (that the users don't even realize is such a burden) that random people on the Internet can auto-send to every business they've ever used under some innocuous-sounding reason like "See what information businesses have on you!" 99% aren't using data against subjects' interests, so the net effect of this alone (in the way it is designed) is potentially-immense costs for small benefits. As a recommendation, the $250 my company spent on buying me a membership to the IAPP has been one of the highest ROI decisions in recent memory. It has saved me a ton of time and effort (and the company quite a bit of money) from the member resources available, and the members listserv is essentially free light consulting from people who have already dug into everything.
- kristjankalm 8y ago>> with limited resources they wouldn't be able to focus on the critical period of acquiring users and instead would be forced into building compliance features If you cannot comply with privacy rules you should not do social media, whatever you growth phase
- deleted 8y ago[deleted]
- rmc 8y agoThe GDPR makes some things easier for start ups. Users now have a right to their personal data in a "commonly used" digital file. Now the start up can have a "Import your Facebook data" feature. Currently a provacy conscious start up is competing with those who aren't, making it harder. But with this law, you won't have as many shady companies like Facebook. Storing less private data makes you less liable to get hacked and get bad PR.
- adventured 8y agoYou've been able to download your Facebook contents in a zip file for nearly six years. It made absolutely no difference in competition.
- rmc 8y agoYes, and that was due to existing EU data protection law, which gives you the right to access your personal data. The GDPR states that it must be accessible in a common digital format which is new.
- xenomachina 8y agoWould this data file include the user's friend connections? In other words, if I exported my data, and my "Facebook friend" also expected their data, would it be possible to determine from the two files that the two users are friends?
- EpicEng 8y agoI don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? There's nothing inherently wrong with a high bar to entry if that bar exists for a very good reason. If it were hard to break into this space due to regulation (I don't believe it is or will be) then yes, competition will be less, but the alternative is worse.
- AnthonyMouse 8y ago> We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? Safety critical code and health care technology are life and death situations. It's also important to understand that the regulations in those sectors have destroyed (or deterred) an incredibly large number of startups, and the net lives saved as a result is quite likely negative because the value of life-saving technological advances generally exceeds the cost of mistakes in developing them. People have severe emotional reactions to this. A doctor's experiment may kill fifty already-terminal patients but uncover a cure that goes on to save five million. But the families of the fifty dead patients can blame a specific person for their deaths while the five million aren't even aware what they lost, so the regulations are biased against progress. This is obviously not a good template for making decisions in other industries where emotions don't run so high.
- richardwhiuk 8y agoThat's a very optimistic view. It's fairly clear that giving away people's data without any care is unsafe.
- chc 8y agoPeople's personal info can be a matter of life or death too. If yours isn't, you can count yourself fortunate.
- AnthonyMouse 8y ago
- idrios 8y agoI equate the events right now surrounding Facebook to Upton Sinclair's book "The Jungle", and GDPR being the privacy-analogue to the creation of the FDA. The FDA makes the medical field hard to break into for startups, but for good reason. New medical devices need to go through rigorous verification and validation to show that they work as intended. If a company making pacemakers had the same "move fast and break things" attitude as most of SV seems to have, I might never trust medical companies again. As a consumer, I'm extremely content with the quality of pharmaceuticals and devices, and I wish I could trust Facebook or Google as much as I trust Medtronic or Philips Healthcare.
- JunkDNA 8y agoAs someone who works in a startup in the healthcare space, I will point out that nobody lets health startups off the hook for HIPAA. You don’t get to be sloppy with people’s protected health information just because it makes your life easier.
- taylorswift_ 8y agoI'm sorry but I don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger... it's not apples to apples
- JunkDNA 8y agoThe content of the data is not the issue. The point is that society has decided to pass a law stating that certain data needs to be treated a certain way or there are serious penalties because of past abuses. We in the US take for granted that this law exists, but there was much complaining in the medical establishment about how burdensome it is to them conducting their work because of all the extra protections it required. This was especially true in biomedical research where patient data was pretty carelessly treated in many cases. Not because the people involved were bad people, but because society as a whole had not thought through the consequences of walking around with an unencrypted list of cancer patients on a floppy disk.
- CaptainZapp 8y agoI don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger There is, or at least there was a Facebook project for exactly that [1] The thing is that none of those "anonymized" subjects would have ever been asked for consent if they really knew about the consequences. Such behavior has really, really bad real world implications: When I got a knee operated one of the questions on the questionaire you need to fill is if you agree that your data can be shared in anonymous form for research. At that point (and given that this was a fairly benign condition) I didn't see a problem with consenting. After that revelation about what Facebook was up to my answer in the future is a clear NO! Facebook handling medical data. What could ever go wrong with that? [1] https://www.cnbc.com/2018/04/05/facebook-building-8-explored-data-sharing-agreement-with-hospitals.html https://www.cnbc.com/2018/04/05/facebook-building-8-explored...
- AJ007 8y agoA big part of the problem is we have a brand new set of very vaguely written rules with no case law. Given time, I expect we should see case law and software change to be more GDPR friendly. I am very curious to see what happens to EU ad revenue after GDPR. If it doesn't drop (outside of Google & Facebook's internal platforms), I'm guessing there isn't much GDPR compliance going on.