10 ms·
Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for si
by grepnork 8y ago
Having spent this week doing compliance for my small business customers, the cost is not zero but it's really not much at all - I've done full compliance for six companies and it cost less than £250 each (one of those clients is a large NGO).
This guy doesn't like regulation and is playing to the crowd for sympathy.
- legitster 8y agoWe have spent 3 months and aren't done yet. I would love to know your secret.
- enedil 8y agoPerhaps having legitimate purpose for data collection in the first place helps.
- tchock23 8y agoWhy are so many commenters on HN presuming that companies that struggle to comply with the regulation are doing something shady with user data? You are aware that there is a time and monetary cost to comply for those with legitimate data collection purposes, right?
- adventured 8y agoIt's a deflection tactic by people who are emotionally invested into GDPR. Note the extreme emotionalism that GDPR draws out of its supporters. That makes it difficult for some of the supporters to have a rational discussion when it comes to the flaws of GDPR. They don't have a legitimate response to the context in question, so the easy approach is to attack the credibility of the person stating that they've struggled with compliance, rather than engaging in substantive discussion about the problems that GDPR generates for small businesses. The fear for the supporters is that if they admit to there being any flaws in GDPR, that will then act as a threat to GDPR (which they view as a monumental victory for privacy). They don't want to give an inch of ground, no matter the issue, because they're afraid of having GDPR diluted, taken away, and or not spread to the rest of the planet. This is also why in all cases you'll see the GDPR supporters go after the character of the site/service owner (including always questioning their motives to muddy the waters). It's an attempt to short-circuit any reasoned debate, to destroy the credibility of the opponent. This has happened numerous times on HN in the last month or two.
- deleted 8y ago[deleted]
- repolfx 8y agoThey struggle with it for the same reason people on the political left always struggle to understand why some people oppose new regulations: the question of whether and how to regulate commercial activities is always a proxy for deeper underlying differences in how people view the world. GDPR is just a proxy fight between the left and the right and is showing all the same characteristics. Consider adventured's sibling post - it quite astutely points out that GDPR discussions are much more vitriolic than you'd expect for discussions of the minutiae of data handling. People who say that GDPR compliance is hard are being attacked on a personal level. He explains it as 'emotional investment' in GDPR but I don't think that's a good explanation; the people arguing most strongly for it are also those saying it's not much work, so that seems backwards. You'd expect people who put in the most effort to be most emotionally invested in it. There's a much better explanation available: your view on GDPR is a direct consequence of your assumptions about human nature. If you believe in the existence of benign and enlightened technocrats then GDPR seems like excellent progress towards building a better world - it's extreme vagueness and severe penalties are exactly what's needed to foster obedience to technocratic elites. People who complain about this are just being unnecessarily awkward ... just be reasonable after all, and you'll be fine! The EU are reasonable so if you're reasonable too, you have nothing to fear! From this perspective, anyone who objects to GDPR or actually decides compliance is impossible must - almost by definition - be being unreasonable. What are they hiding? Why can't they just get on board; the only answer available is that they have flawed characters and any points they make about gray-area debatable things like cost:benefit ratios must be some sort of obfuscation. If on the other hand you believe the whole idea of wise and beneficent bureaucrats is naive, then GDPR looks like a hell of a lot like a power grab by the very sort of people who shouldn't be able to grab power. Vagueness is of deep concern because it's in the shadows of vagueness that abuse can be found, and when a law is nothing but vagueness, it even makes sense to question to motives of those who created it - that's a problem because lots of self-styled Europeans have bought into the EU's utopian rhetoric and can't separate criticism of the EU from criticism of themselves and their desired future. There's no real scientific way to prove whose assumptions about human nature are right. The USSR was a rare example of a real-life experiment in who was right and for a long time it proved the American style, conservative, small weak government is better mentality to have superior results. But that was decades ago and many have forgotten or weren't alive back then, so now rule by technocratic dictatorship seems attractive again. As a consequence GDPR discussions will always have the same flavour as Clinton v Trump debates, or Brexit debates, or whether to restrict spending on political campaigning. They are ultimately about the same issues.
- sunir 8y agoYou still have data hygiene policies to enact which are confusingly legislated. Also legitimate interest is a loophole created to appease some lobbyists but the legislators declined to make clear anywhere because they don’t give a shit about commercial needs.
- mikekchar 8y agoNot the OP, but it's pretty straight forward for most people (including the author of TFA). You need to identify what private information you collect. You need to decide what lawful basis you are using to collect that data. If you have no lawful basis, you have to stop collecting that data. When you collect the data you need to notify the user under what lawful bases you are collecting the data. If you are using consent lawful basis, you need to get consent in an opt-in manner. You need to record what statement you have shown to the user and any consent that you receive. If you are using only contract basis for the data it's really easy. You tell them that you are using their data for purposes of fulfilling the contract. The great thing about contract basis is they can't object. The only thing you need to do is to inform the customer of any 3rd parties you send their information to in order to fulfil the contract. It only gets complicated if you want to use the data for other things. For legitimate interest (which is essentially exactly the same as the laws that are currently on the books) you need to be able to exclude processing the data if someone objects. You also need to make sure that you don't delete their data if they exercise their right of removal (which is completely bass-ackwards, but whatever). Consent is similar actually, but you have to get the consent up front. The other lawful bases are very unlikely to show up in most organisations. I think the main problem with most organisations (and it's the case with the company I work for at the moment) is that control of private information is very loose. For example, we use several SaaS systems for our marketing. Some of them are clearly unnecessary and so we either have to remove that functionality or get consent. So there's lots of discussions about whether it is worth a huge wad of text thrown at the user in order to have cat emoji's or some stupid thing like that. The other main problem is that if you want to use something other than contract basis, you need to build something that allows the user to exercise their rights. It can be a manual process, but if you have a lot of users it might threaten the margin. Anyway, long story short: If you are only gathering the information that you need to do the work you are doing, there is likely very little (or in a lot of cases I bet nothing) to do. If you are gathering the information to use for your own purposes, then there may be a lot that you need to do. Not to put too fine a point on that, personally I highly approve of this. I really could care less if somebody's business model is destroyed because it is now too expensive to collect information that you don't need to do the job. Even in the company I work for, where we don't actually use the data for nefarious purposes (AFAICT ;-) ), we're finally having some long overdue conversations about what stupid SaaS crap we're using under the hood. Not to be unkind, but I utterly fail to understand how marketing people fall for the same lies that they spew out themselves... "If only we send our customer's data to this service, they will find a way to drive more business our way! And we don't even have to pay them!" Yeah... right...
- x0x0 8y agoThe secret is bald faced lying. The quoted price may barely cover an updated privacy policy from a lawyer. And nothing else. Not one line of code changed. Let alone full review of every system and legal review of the DPAs you have to sign and or create with every single co and processor.
- zitterbewegung 8y agoCan you send me an email? I am working for a startup and I would like more information about your services . (It’s in my profile).
- leereeves 8y agoIs that £250 each just for GDPR compliance? That's one law in one region. Now multiply it by the number of legislative bodies worldwide and the number of relevant laws passed by each - how much does that cost?
- genma_it 8y agoBefore it was £250 for each EU country. Now it is £250 to comply in all 28 states (27 soon). So, it saves £6750?
- lagadu 8y agoIf a business doesn't want to be compliant with the laws of all ~200 sovereign states in the world, they're most welcome to just select a single one and do business there (not the US though, as laws often change for each state so that's right out the door). I'm sure the competitors in the space will love having one fewer competitor.
- leereeves 8y agoComplying with the laws of 200 countries is negligible for a big business like Google, a significant burden for a small startup, and a prohibitive expense for a new open source project.
- bkirkby 8y agodid that $250 include an audit to verify that you are actually in compliance?
- jacquesm 8y agoThere is no such thing as a GDPR audit. Anybody that tries to sell you one is full of it.
- ryanwaggoner 8y agoHow could this possibly be true? You claim to know a lot about the GDPR, I’m not sure my business is compliant. Can you take a look and tell me? What’s that called if not an audit?
- jacquesm 8y agoAn audit without certification will never give you anything that you could not have come up with yourself. So feel free to buy a GDPR audit but realize that you are just buying an opinion.
- tripletao 8y agoIn the USA, the word "audit" is used to describe any process by which a company tries to determine if it's in compliance with some set of rules. Sometimes that process has special legal consequences, but it usually doesn't. The final deliverable is often literally called an opinion. No lawyer or accountant has ever given me anything that I couldn't have come up with myself, with sufficient study. I still paid them, because the law is very complex and I have other things to do with my time. That's how any country with a nontrivial legal system works. You seem to have great confidence that you understand how the GDPR will be enforced. I'd suggest that: 1. Not everyone knows as much about EU law as you do. This is especially true for people who don't live in the EU. 2. You might be wrong. Maybe GDPR compliance really is dead simple, and the lawyers who keep answering "it depends" are just cheating their clients; but from my experience in complying with similarly complex regulations, I wouldn't bet 20M EUR that's the case.
- Silhouette 8y agoWhat exactly did that less than £250 get your customers in return? Even if you had a business that was whiter than white in terms of compliance with previous data protection laws and had perfect documentation of all its data collection and processing activities, it would surely cost far more than that just for the time to write some basic notes on the extra things you now have to tell data subjects and/or your regulator, get them reviewed by a lawyer, incorporate them into the relevant policies, and send notifications to anyone affected about your updated privacy policy.
- sudhirj 8y agoCould you contact me at sudhir.j@moviebuff.com - would like a consult.
- nicbou 8y ago> I've done full compliance for six companies and it cost less than £250 each What about your salary?