4 ms·
> However, GDPR currently creates a lot of uncertainty. How is it creating any uncertainty? Just make sure you use opt-in and be ready to scrap the data. Even
by romanovcode 8y ago
> However, GDPR currently creates a lot of uncertainty.
How is it creating any uncertainty? Just make sure you use opt-in and be ready to scrap the data.
Even if you are doing business in U.S. and want to have EU clients you have to take GDPR into account. How is it related to Germany or Berlin?
- BjoernKW 8y agoThe new regulation isn't just about opt-in and data deletion. Those are just the aspects consumers typically will be aware of. In addition to that a company also needs to: - have data processing agreements with every 3rd party that processes personal data for them - document technical and organisational measures with regard to privacy and security - have records of data processing activities While these are useful - GDPR or not - many aspects of those are left intentionally vague. In the past few months, data protection experts and company owners alike have been racking their brains as to how to implement the details entailed by those requirements. A government spokesperson only just recently has been quoted that although there's "some uncertainty" regarding the implementation of the new regulation the government doesn't intend to do anything about that right now but rather wants to wait and see how civil servants and courts are going to interpret the new law. In my opinion, that's a recipe for disaster waiting to happen. On top of that, Germany is particularly notorious for its 'liberal' regulation regarding cease-and-desist letters. There's a whole industry of shady lawyers that make a living by sending these out en masse to small companies that supposedly don't comply with regulations such as the equally notorious legal notice requirement for websites. They're perhaps already waiting with bated breath because GDPR opens a whole new 'market' for them. Many of my fellow entrepreneurs are worried about this right now and these are people who are both well-prepared and normally not easily spooked by bureaucracy.
- deleted 8y ago[deleted]
- hluska 8y agoFirst, these regulations aren't new and if you've been remotely compliant with European privacy laws in the last decade, these aren't a massive step forward. With regards to these specific ideas you cite, any company that gives an iota of a shit about its users already does all of these things. I can't even call this a security fundamental, it's just basic respect. It's odd to me that, in the lead up to GDPR, so many people are making these exact same FUD-like arguments on the exact same kinds of questions, worded in remarkably similar English (down to agreeing that the law could be a good thing), on a variety of social sites. It makes me wonder if I'm watching a foreign power trying to undermine the EU. > In the past few months, data protection experts and company owners alike have been racking their brains as to how to implement the details entailed by those requirements. If this is true, they're not experts. Or rather, they're the kinds of experts who say they're experts on Twitter. Nothing in GDPR is particularly complicated.
- BjoernKW 8y agoThe problem with these laws is that while they're mainly targeted at large corporations - because frankly that's all regulators and politicians usually know or care about - small companies bear the brunt of complying with them right now. Many of the questions the owners of these companies are facing right now haven't even been considered by legislative bodies. These are questions such as: - How will I be able to operate my small company website in the future in a legally compliant manner? Some companies even consider turning off their websites completely and - of all things - only use a Facebook page in the future. Hence, ironically we might very will see GDPR actually benefitting companies like Facebook at the detriment of small companies that consequently won't have complete ownership of their content anymore. - How exactly does a privacy policy have to be worded so I don't get sued on day 1 (in some EU countries this is a very real problem already with legal notice requirements for websites)? - In which way will I still be able to store data for contacting my existing B2B customers (such as email addresses and phone numbers)? - Will I still be able to use anti-spam and security plugins for my website? These tools might store users' IP addresses, which in some jurisdictions are considered personal data. Dismissing these very real concerns by very real people as FUD or even suggesting a foreign power might be trying to undermine the EU is nothing but a preposterous conspiracy theory.