14 ms·
There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (wh
by mnkypete 8y ago
There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case.
At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-you-know-about-the-gdpr-and-why-you-may-be-wrong https://privacylawblog.fieldfisher.com/2016/what-you-think-y...
- dmacedo 8y agoAnother good read on DPO role: http://www.ascentor.co.uk/2017/06/gdpr-data-protection-officer-dpo/ http://www.ascentor.co.uk/2017/06/gdpr-data-protection-offic...
- zerostar07 8y agoHaving an app that is non compliant out there induces anxiety. Having 10-20 old or fire-and-forget projects out there, it's anxiety multiplied. There is a non negligible chance that One disgruntled or trolling user or competitor will report you to their country's DPA . There are 28 DPAs and they are not all as good and fair as Germany's or the UK's , they may fine you even if there is no good reason. Example: in my country the DPA fined a company last week (3000 euros) because they searched a company's computer while the employee was not present, even though they found that the computer did not contain any personal information.
- hvidgaard 8y agoOnly the DPA of your country will handle complaints against you.
- zerostar07 8y agoBut for those outside the EU, any of the 28 DPAs can fine their company. Also, i think the DPAs can fine any company in the EU, not just the companies of the country the DPA is in.
- ucaetano 8y agoDirected or not at large companies, it applies to all companies. It introduces a fixed cost for operating with any user-related data, which effectively kills any companies operating below that cost.
- Y_Y 8y agoMaybe companies that are so flimsy didn't have long left anyway. You're required to have a fire safety officer at these companies too, but it's not a full-time position.
- kasey_junk 8y agoI think this is a legitimate cultural difference. I’m fairly left leaning for a US citizen & find the idea that the default should be big companies abhorrent. But I recognize my bias & am not st all convinced it’s in any way objectively correct.
- ucaetano 8y ago> You're required to have a fire safety officer at these companies too, but it's not a full-time position. AFAIK, most of the "safety committee" regulations usually have waivers for small companies.
- Sean1708 8y agoWell that's terrifying...
- skrause 8y agoFrom my German perspective this whole GDPR panic is so interesting. The GDPR is basically a carbon copy of the data protections laws that have evolved in Germany since 1977. Yet we still have many thousands of small companies dealing with data, individuals running web forums etc. It's especially funny when small to medium German companies suddenly panic because of the GDPR and when you look at their situation all you can say is "yeah, you should have implemented that 15 years ago, it's already been German law that long". In Germany not much will change, but at least companies like Facebook can no longer just move to another country with worse privacy laws (like Ireland) and call it a day. For us the GDPR means that protecting user data will no longer be a competitve disadvantage. But if you're a small company and handling data reasonably, the GDPR won't hurt you anyway.
- liveoneggs 8y agothese assurances from internet forums are great and all, but hwy take such risk?
- Hamuko 8y agoDo you think you're going to be slapped with a 20 million euro fine on day three?
- liveoneggs 8y agohow do I know that I will not be? that's the issue
- jdietrich 8y agoBecause European courts and regulatory authorities are not run by gibbering morons. The Data Protection Directive was materially similar to the GDPR and was enforced by the same supervisory authorities. The DPD gave member states total discretion as to the level of fines, with no upper limit. I have found no evidence whatsoever of irrationally large or unreasonable fines under the DPD. You could be breaking the law in any number of countries. What steps are you taking to comply with the laws of Saudi Arabia or North Korea?
- woolvalley 8y agoWell usually they aren't any kind of social or economic hubs, so I don't really worry if I can't enter or do business with north korea in my day to day life. The EU on the other hand... Also almost all laws stay in one jurisdiction, they don't go beyond their own country.
- Hamuko 8y agoSo your preferred way would be to have 28 different data protection laws?
- fencepost 8y ago
- jbob2000 8y agoWhen it's a one man show, you can't afford these kinds of unknowns. And by afford, I don't just mean monetary, I also mean mental costs, like your mind spinning at night wondering of the ways you might be harmed, or the ways you might develop a solution to the problem, etc.
- craigsmansion 8y ago> When it's a one man show, you can't afford these kinds of unknowns. One really can. It took me all of a few seconds to shrug of the GDPR when I first heard of it. Then, with all the scare mongering (webserver logs will be illegal!), I spent a few minutes reading up on it. It's all more than reasonable: if you're not doing anything shady, or are being negligent bordering on incompetent, you can just shrug it off and sleep soundly.
- quietdean 8y agoThis is what Limited Companies, LLC's and Corporations are for. The monetary and time cost is minimal, but the mental benefit is pretty damn good.
- woolvalley 8y agoCorporate veil piercings happen a lot more when your a small or one man shop, and officers can often be directly liable for the actions of the company. It's not as bulletproof as you think.
- jacquesm 8y agoBut the usual requirement for piercing the corporate veil is that the owner/operator of the business is using the business with the sole reason of insulation from having their private assets in the line of fire. If the business is otherwise legit and a fine were levied against the business there would be a fairly strong barrier before the assets of the shareholder become part of the story. A good precaution against this is to have more than one shareholder (preferably more than a token percentage for the second shareholder).
- kybernetikos 8y ago> 9. Profiling activities always require consent: WRONG! Well that's a disappointment.
- merijnv 8y agoWell, it's wrong in the sense that profiling activities require a "lawful basis", consent is one of the possible lawful basis available. So you can profile without consent IFF you can convincingly justify said profiling via one of the other lawful bases. But those won't really let you do blanket profiling willy-nilly either and come with other strings attached.
- deleted 8y ago[deleted]
- drewbuschhorn 8y agoThe op seems to be motivated more by politics than the reality of this as I understand it. The "reasonable" qualifier in most of it, while it will need to be litigated, does a lot to assuage my concerns about overreach from it. Could you be sued to the poor house from it? Maybe. But that's the risk of operating a business in the US every single day.
- jimnotgym 8y agoNo, you can't be sued except by the regulator, who will only do so if you ignore them! Their role is to make you compliant, not punish you.
- kodablah 8y agoWhere in the law does it say they only do this when ignored? Surely if this were the case, they'd put it in the law like they did punishment limits. Or are you banking on subjective enforcement?
- opencl 8y agoRight here. You get a month to comply with any deletion request and can extend it to 3 months if needed. https://gdpr-info.eu/art-12-gdpr/ https://gdpr-info.eu/art-12-gdpr/ "The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests."
- kodablah 8y agoThat seems like a request from a data subject. I was responding to a comment that said you will only be sued by a regulator if you ignored them. There are multiple blog posts and articles that regulators have posted about what they will and wont do that is not codified.
- 8y ago
- greglindahl 8y agoOne misconception about GDPR is that you can ignore it if your company is small. And that's basically what you're saying. And then the next would be that it's inexpensive to "make your case" if you get reported.
- mnkypete 8y agoNo - you cannot ignore it when you are a small company that's true. But you can (probably, we'll see) ignore it if you don't do shady shit with your customer data. You are allowed to process data, if it's used to fulfill the service you provide. That's reasonable, and probably applies to most of what OP is doing.
- greglindahl 8y agoSo when I get reported, I'll say I didn't worry because some guy on Hacker News said I'd be OK? That's not how it works. You can be as confident as you want without affecting the reasonable worries actual businesses have about this regulation.
- mnkypete 8y agoI have an actual business, thank you. And I did my homework by talking to a lawyer about it. What I got from this talk is, that most of the stuff that is going around is pure panic mode. Please, don't take my words as granted but talk to an actual lawyer. You'll probably even find a free session for startups somewhere in your city, at least in Europe.
- jdietrich 8y agoAsk the regulators. The ICO provide comprehensive guidance documents, a wide range of tools to facilitate compliance and a dedicated helpline for small organisations. They're extremely busy at the moment, but they'll be more than happy to explain your obligations under the GDPR and the best way of achieving compliance. https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/ https://ico.org.uk/for-organisations/guide-to-the-general-da... https://ico.org.uk/global/contact-us/advice-service-for-small-organisations/ https://ico.org.uk/global/contact-us/advice-service-for-smal...
- cft 8y agoFalse: when Poland proposed to exempt small business under 250 employees, it sparked an "outrage": https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spark-outrage/ https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
- Hamuko 8y agoProbably because that's a dumb exemption. Number of employees is pretty fucking irrelevant when it comes to data. By this standard, Cambridge Analytica would have had lessened burden on regarding objections to processing, demands for data deletion and so on.
- deleted 8y ago[deleted]
- viraptor 8y agoAnd it's good that it wasn't allowed. Otherwise we'd just have medium sized companies worrying about GDPR while large companies spawn one-man shell companies that "specialise in data processing".
- woolvalley 8y agoThat is resolved today by subsidiary clauses in laws. If owned or controlled by big-co in an non arms length manner, then it wont be considered a 'small company' in terms of the GDPR. Edit: These corporate control laws have teeth, otherwise every small & large business owner would do something similar by making all of their corps 'offshore' in some zero tax jurisdiction and pay 0 tax locally except for business done actually in the territory itself.
- viraptor 8y agoOh, but they're completely "independent", I don't understand what's the problem, Mr regulator ;-) This already exists in many ways for financial aspects. Sure, it's not super legal/moral, but... Or the could be completely legitimate small businesses doing this device for anyone.
- emilfihlman 8y agoSo it's a law that's arbitrarily enforced? Kinda like giving limitless power to discriminate to someone? There is no misconception on GDPR: the idea is good, the implementation is horrible and retarded and it is lead by people who do not understand a single thing about technology.
- matthewmacleod 8y agoNo, you are wrong. 1. Enforcement is not arbitrary, but like all regulation the goal is compliance rather than punishment. 2. The idea is good, and the implementation is widely regarded as good by anybody familiar with data protection regulation. 3. Most of the panic seems to be from woefully misinformed US tech companies.
- TheRealWatson 8y ago> you can make your case What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.
- s73v3r_ 8y ago"What if you don't want to deal with any of that." What if you don't want to deal with the rules of the road?
- zerostar07 8y agoThere is a big cost to regulating the internet and we know that. If the internet was regulated in the 90s we 'd still be watching Teletext.
- lagadu 8y agoIn other words: "protecting people's rights is expensive, therefore we shouldn't do it". That's your argument? Really?
- zerostar07 8y agono it is not. please dont make strawmen
- s73v3r_ 8y agoI entirely reject that argument in all its forms.
- lagadu 8y agoIf you don't want to follow the law you're welcome not to and will have to deal with the courts when they come knocking. This has always been true for all laws, not just GDPR. Try violating fiscal laws in the US just because "you don't want to deal with any of that" and let us know how well that works out for you.
- dominotw 8y agoIt's just A speculation about what it's directed at. We just can't take any chances given the steep fines.
- gray_-_wolf 8y ago> It is cleary directed at large data-tracking corps, not single person IM apps. Sure, but that's not actually written anywhere.
- fencepost 8y agoIf there is a complaint against my small software company, are there limits on how much I'm required to spend on defense? Do I have to travel to Europe to defend my company or will investigators from Europe travel to my location at their own expense? Will I be reimbursed for reasonable expenses if the complaint is groundless? Are there parts of the regulation that act like strong anti-SLAPP laws in some states? Can my small company be trivially bankrupted by any sociopathic gamer skid with an EU address and a grudge when DDOS attacks fail? "You can beat the rap but you can't beat the ride."
- unreal37 8y agoWhat can Europe do to you? Assuming you are American, the only court you need to worry about is American court. Your company is American? Your bank is American? What's the actual liability here? Worst case?
- chii 8y agoas soon as you have assets or steps foot on EU soil, you may be asked to go to court, or pay a fine or some such.
- lagadu 8y ago> Can my small company be trivially bankrupted by any sociopathic gamer skid with an EU address and a grudge when DDOS attacks fail? Your dude with a grudge can only lodge a complaint with the relevant regulatory entity, they're the ones who will verify whether you complied or not with his GDRP requests and if they deem that you are in violation fine you after negotiation fails. This isn't the US: you can't be sued by random people for anything.
- orwin 8y agoWell, in europe, it work like this: (1)A random person complain to his regulator that you are not complying with GDPR. If he asked for his personal data, jump to (3) (2) His regulator contact you, tells you that wht you're doing is bad: you have some stuff in opt-out, not clicking "opt-in" cause a degradation of service, or you are sending him 3rd party cookies he did not accept. (3) Depending on the complexity and your ressources, you have X months to comply. (4) You got caught again, you are fined.
- sfifs 8y ago> It is cleary directed at large data-tracking corps, Then the law should say that. For instance when India implemented uniform goods and services tax processes, it explicitly excluded businesses below a certain revenue threshold and gave them a simple % of gross alternative to all the processes. GDPR doesn't make any such distinction, so such decisions to drop EU support are to be expected.
- plandis 8y agoBy law it is enforceable and directed at any entity that tracks European data. There is no clause the limits GDPR to large companies, just like there is no clause that limits or restricts fines outside of the 4%/20M number. It would be entirely possible for someone to not be compliant with a side project and get fined 20M because there is nothing that explicitly forbids this it is entirely up to interpretation. Given that US companies have already been targeted in the EU, unfairly [1], I find that law terrifying because I have to trust regulators that don’t have my best interests in mind with possible penalties that are very high. [1] https://www.treasury.gov/resource-center/tax-policy/treaties/Documents/White-Paper-State-Aid.pdf https://www.treasury.gov/resource-center/tax-policy/treaties...