4 ms·
Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to com
by fcbrooklyn 8y ago
Every time something like this comes up, we see similar objections. They normally take one of three forms:
1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity.
This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enforcement? I suspect not, but perhaps there's a business opportunity in giving them the opportunity to do so. Sort of a GoFundMe for peer-to-peer insurance.
2) The GDPR is all about not being a jerk with your users' data. As long as you don't do that, and do relatively minor things X, Y and Z, you're totally fine.
This flavor of argument might actually be true, but if I'm assuming the risk I'm probably going to want to hear it from someone with skin in the game, like a lawyer, who I can point to if it turns out to be false. Even if I had the desire to read through the law (I don't) and understand the specific implications for my project (I wouldn't), the very act of doing this represents a cost that I could more simply avoid by excluding EU residents from my service. I'd choose the latter path every time, and put "support EU residents, check into the legal implications of GDPR" on the roadmap, for "someday".
3) You're exposed to millions of risks anytime you do anything. This is just one more and you're making a big deal of it.
Often this accusation comes with a subtext that you're trying to prove some political point, suggesting that you're making a decision in bad faith to "punish" the EU. Well, I personally think something like the GDPR is needed, and have no particular axe to grind, but I also have no idea if the legal exposure is serious, and no particular desire to put in the work to find out.
Yes, business, or really any activity, involves legal risk. In this case though, the risk is pretty serious, first of all because the penalties (20M Euros max) are serious, and secondly because it will be very difficult to claim that you've never heard of the GDPR. If Tonga creates some law impacting side hustles on the internet, at a minimum I can credibly claim to be unaware of that law. The GDPR on the other hand has been all over the news for weeks. I've clearly heard of it (especially now that I've commented on a discussion of it on HN).
My feeling is there's a real risk that this law will lead to a general practice of non-EU individuals, and non-EU startups launching MVPs to at least temporarily block the EU to avoid unnecessary risk. That's not the intended purpose of the law, but laws have unintended consequences all the time. If the EU wants to avoid this unintended consequence they should provide a clear, objective, and cheap (in terms of both time and money), set of instructions that will allow projects like monal to continue operating there. If such a set of instructions exists, I haven't seen it.
- ozim 8y ago"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.
- fcbrooklyn 8y agoYou have pointed me to the entire content of the GDPR. It's 11 chapters, with 99 articles. I'm unashamed to admit that I don't consider even skimming such a document "easy". I was imagining something more along the lines of a one pager with 4-8 bullet points, each of which was easy to address.
- zerostar07 8y agoShould add to that that the law (which is generally abstract) will be interpreted by 28 different legal systems. EU legal system is not homogeneous and there are definitely different sensitivities between countries (e.g. Germans seem very happy about GDPR - the Poles less so). That's an extra risk factor imho.
- ozim 8y agoHACCP has nice 7 points, are you comfortable with implementing it on your own? Each country has its own regulator making rules. Restaurants are fined on violations all the time. (20M fine for GDPR violation is upper bound, if you have 10K/month revenue, you are not going to be fined with millions) https://en.wikipedia.org/wiki/Hazard_analysis_and_critical_control_points https://en.wikipedia.org/wiki/Hazard_analysis_and_critical_c...
- tathougies 8y agoThis is a manual by one particular consulting firm, and the text of the law. While reading the law may be good, it is really not feasible to understand all the repercussions without consulting a lawyer. While this consulting firm may have a good interpretation of key provisions, they are not actually your attorney, and their incentives cannot be known to really align with yours. I mean, this isn't rocket science. More regulation is always going to lead to businesses leaving the market. This is not a bad thing, if your country is willing to put up with it. My guess is that the EU will not care about monal exiting the IM market, and their legislature has decided that they want to prioritize this regulation over the efficiency of the IM market. That's fine -- that's the EU's choice to make.