7 ms·
The GDPR gives authorities various ways to deal with corporations that are breaking the regulations. When a corporation is compliant and only has minor infract
by tscs37 8y ago
The GDPR gives authorities various ways to deal with corporations that are breaking the regulations.
When a corporation is compliant and only has minor infractions, they will (most likely) write a sternly worded letter.
But if you're constantly and repeatedly or willfully ignoring or breaking the regulation they definitely won't leave it at a simply tap on the fingers.
Plus, I don't think any regulatory body is looking for bankrupting a corporation. They will obviously size the fine according to how much the corporation has in turnover or profit.
- downandout 8y agoSo we are just supposed to hope that they will be nice to us when inevitable violations occur under one of the 28 unique interpretations that this law will be subject to?
- tscs37 8y agoI don't think I've heard of many EU regulatory bodies that will immediately go for the maximum punishment the moment anyone does a minor infraction. First you get a letter, then a sternly worded letter, then a tap on the finger, a hard tap on the fingers and if you still refuse to learn the lesson then they break your knees. If you have minor infractions caused accidentally and you cooperate I have doubts that any regulatory body for the GDPR will go beyond sending a simple letter asking you to fix a problem.
- downandout 8y agoThat’s not what the law says they have to do. All reasonable businesses have to assume the worst case, not the best case. These governments have a built-in financial incentive to not be lenient in any way, shape, or form.
- tscs37 8y agoThat's the US, yes. EU regulatory bodies are generally rather lenient when you attempt to follow the regulation. And unlike you say the law does say the regulatory body for the GDPR has to consider the business needs of smaller businesses and adjust their fines accordingly if they even hand them out. There is a good flowchart in this thread too, I recommend to study it.
- downandout 8y agoBut they have never had the extraterritorial reach that they are claiming under the GDPR either. This could easily be used to suck money out of foreign countries. I don’t think they’ll play nearly as nice with people that don’t vote in their own countries. I am hopeful that the US will pass legislation exempting US firms from enforcement of fines under GDPR on US soil, but I am not optimistic. Under current law, it is likely that they can be enforced. Either way, the net result will be that EU residents will have access to a far smaller universe of content and services. Most businesses just won’t take the risk.
- tripletao 8y ago> I am hopeful that the US will pass legislation exempting US firms from enforcement of fines under GDPR on US soil, but I am not optimistic. Under current law, it is likely that they can be enforced. What would be the mechanics of enforcing the GDPR against a US company with no EU presence? I'd understood the opposite, and that the EU's best options to enforce were probably indirect (via customers, vendors, etc. with EU presence).
- downandout 8y agoApparently, existing treaties that the US has allow for the domestication of EU civil judgments in US courts. The prevailing logic right now is that nothing new would need to be passed to allow for that to include judgments issued under the GDPR. Here is one article, there are many more: https://community.spiceworks.com/topic/2007530-how-the-eu-can-fine-us-companies-for-violating-gdpr https://community.spiceworks.com/topic/2007530-how-the-eu-ca...
- cft 8y agoPerhaps it's a cultural difference but here in the US we interpret all laws literally, fully expecting maximum penalties. And yet they are trying to apply this law to American startups who can barely afford a lawyer here, let alone a EU counsel.
- riffraff 8y agolaws are interpreted literally in Europe too, or they wouldn't be laws. But most laws have a range of penalties, and often account for intent and attitude. E.g. in US law you have "manslaughter" (voluntary or not) and "murder", for example. And you have different penalties for first offense and repeated offence. I am not one to say "trust the EU government, it is good". But the intent of the legislator is obviously not to kill businesses willy nilly, it is to punish certain behaviours, they have no reason to willingly cause a business to shut down, which is why the GDPR explicitly accounts for collaboration. In the end, it is up to you to decide not to abide to the law. There have been local regulations forever, this won't change much.
- Sacho 8y agoThis does not resonate with my experience. In the US, reporters will often describe sentences as "up to 1024 years", but the actual sentences are different. See https://www.popehat.com/2013/02/05/crime-whale-sushi-sentence-eleventy-million-years/ https://www.popehat.com/2013/02/05/crime-whale-sushi-sentenc... Note that, in parallel to the EU regulation, the statutory maximums can be enacted(ever since Booker judges can use their discretion again), but in reality most judges rule within the sentencing guidelines.
- whataretensors 8y ago> I don't think I've heard of many EU regulatory bodies that will immediately go for the maximum punishment the moment anyone does a minor infraction Yet. Wait until the company is another political organization that is identified as an enemy or competition. Then these laws become tools for shutting down dissenters with selectively applied fines, even to companies outside of the EU.
- tscs37 8y agoCould you provide an example of such a thing happening? Preferably for minor regulatory infractions in startups since that is the topic here.
- deleted 8y ago[deleted]
- matthewmacleod 8y agoYes, because that will certainly be the case, like any GDPR lawyer or consultant will tell you.
- deleted 8y ago[deleted]