6 ms·
Obviously, IANAL, but my company talked to a few over the past week. This move is, in my opinion, a bad read on the odds and European culture. First, culture.
by Fradow 8y ago
Obviously, IANAL, but my company talked to a few over the past week.
This move is, in my opinion, a bad read on the odds and European culture.
First, culture. The goal (at least in France, but that's probably the same in other countries) is to get you in compliance, NOT to fine you. What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant.
Second, the odds. Unless you are a big company that thrives on GDPR violations (doesn't seem to me Instapaper is one, but I could be mistaken as I never used the service), you aren't likely to be targeted before a while, at least until a big case is done and over (let's take the odds Facebook is first).
Third, the delay. While the GDPR takes effect tomorrow, you have a grace period of a year for part of it (for example, getting consent for newsletter). I would really be surprised if enforcement start tomorrow.
Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come.
- TomK32 8y agoWikipedia disagrees on the enforcement start and claims that is tomorrow. But I agree with you, the way most interpret the regulation and its sanction is not how Europeans do laws. The "administrative fines up to ..." as you can read in the text http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#d1e6226-1-1 http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE... Those high fines are meant for large ill-meaning companies, but the small 2-ppl-SaaS that doesn't report or act on a data breach will get a slap on the wrist and a fine proportionally to their size.
- Fradow 8y agoActual quote of the GDPR: (171) Directive 95/46/EC should be repealed by this Regulation. Processing already under way on the date of application of this Regulation should be brought into conformity with this Regulation within the period of two years after which this Regulation enters into force. [...] I can't say for sure what's the scope, but I stand by my point that PART of it have a delay to get into conformity.
- juki 8y agoThe GDPR was adopted in 2016. The two year grace period in your quote ends on the 25th.
- wastedhours 8y agoAs mentioned, GDPR has been in force for 2 years - Friday is the end of the grace period. But, as I referenced in another comment, it doesn't just "end" tomorrow, the expectation is that you have a plan in place to address future privacy issues and that you're acting in good faith. If you're not compliant, but aren't deliberately not compliant, and are active in trying to address that, and report anything you might be breaching, then they're not going to go after you like hounds (in the UK at least). The ICO seems to be a fair and reasonable body, they just now have some extra teeth.
- y_molodtsov 8y agoInstapaper is owned by Pinterest btw. Not a 2-ppl SaaS.
- sebazzz 8y agoAs far as I understand the grace period was the last two years. Tomorrow is the big day. But whether or not that it is true, I believe that if Europeans have used Instapaper and they now temporarily shut off access they still are not compliant and in violation of the law. Because they did serve Europeans, so they have their data.
- iovrthoughtthis 8y agoExactly this.
- wastedhours 8y agoTo further that point, this is a quote [0] from the UK's ICO on that: > It’s an evolutionary process for organisations – 25 May is the date the legislation takes effect but no business stands still. You will be expected to continue to identify and address emerging privacy and security risks in the weeks, months and years beyond May 2018. > That said, there will be no ‘grace’ period – there has been two years to prepare and we will be regulating from this date. > But we pride ourselves on being a fair and proportionate regulator and this will continue under the GDPR, as I set out in my first myth busting blog. Those who self-report, who engage with us to resolve issues and who can demonstrate effective accountability arrangements can expect this to be taken into account when we consider any regulatory action. [0] https://iconewsblog.org.uk/2017/12/22/gdpr-is-not-y2k/ https://iconewsblog.org.uk/2017/12/22/gdpr-is-not-y2k/
- seanmcdirmid 8y agoThe law doesn’t actually target Europeans, but anyone in Europe. Since it is based on geolocation rather than nationality, not being in Europe might be relevant legally (IANAL).
- rhacker 8y agoIt's funny that the law entered the global knowledge about 2 weeks ago... Seems like the grace period should have started 2 weeks ago.
- zhdc1 8y ago'European' - e.g., EU - culture is still quite new in this regard, and plenty of companies have gotten very large fines for gross non compliance of other regulations/directives. Since GDPR compliance is enforced by EU members, many small companies are exposed to (have customers in) most or all EU jurisdictions, and the EU is very heterogeneous when it comes to regulatory enforcement by member states, I think that they're correct to be worried about the ambiguity around the GDPR. I'm not arguing against the GDPR - I'm in favor of data protection - but the if/ands/and buts (e.g., speculation) about who is going to get fined, and for how much, is uncomfortable.
- detuur 8y ago> plenty of companies have gotten very large fines for gross non compliance of other regulations/directives Gross, wilful, intentional, deceptive non-compliance. To be honest you have to put quite a lot of effort into managing to get fined for non-compliance with EU regs/dirs.
- zhdc1 8y agoI don't know why people think this. The European Commission Directorate General for Competition lists around 35 thousand cases in their Antitrust and General Registry alone. EU directives are transposed to member states, who are the ones who enforce EU policy. If you're talking about EU members getting hit for non compliance with directive implementation - sure. If you're talking about private sector non compliance with transposed EU directives, that's largely up to how individual member states enforce EU requirements, since EU directives effectively become separate laws once they're transposed by each EU member. As far as I'm aware, there's little aggregated data on how individual member states enforce (as in, number of cases and total amount of fines per year) EU directives. The EU takes in ~4-5 billion Euros per year in assessed fines, but the total amount should be significantly higher once you account for all of the cases/fines that are assessed on private companies, by individual member states, for non compliance with individual state laws implemented to enforce EU directives.
- protomyth 8y ago> What this means is that before you get lawsuit and fines, someone will talk to you and work with you to see how you can get compliant. Can you point to the section of the legislation that says this? It would probably go a long way to stopping folks from freaking out.
- x0x0 8y agoThere is none. BTW: our privacy counsel, at a very good law firm, rates France as amongst the most aggressive of the regulators, given to assessing large fines.
- Fradow 8y agoI can't, since I'm pretty sure it's not in the legislation. The law is enforced by humans, not robots, and those persons have a culture and habits. Of course I could be wrong and they could start enforcing heavily on everyone on day one. But they just don't have the manpower to do that, for starter. And that's just not in the culture either. Law is enforced differently in different part of the world. The US is known for punishment. Other parts are focused on redemption.
- taysic 8y agoRunning on 'i would be really surprised if', and 'aren't likely to be' aren't really how businesses work.
- hobbe80 8y agoRisk management is part of every decision a business faces, legal or compliance risks aren't any different. Can we risk the CEO and chairman travelling on the same airplane? Can we risk having our disaster recovery site in the same city as our main? Same country? Same continent? Can we risk buying all this trends-sensitive inventory? Etc. (Potential savings or revenue) - (Somewhat easy to calculate cost) * (Difficult to assess risk) = Profit. More or less.
- deleted 8y ago[deleted]
- taysic 8y agoThat's not what I was referring to at all. I mean that the sentiment of 'probably'/'likely' from a random stranger online, to a business which might have EU users but never interacted with EU regulators doesn't mean much.
- Fradow 8y agoOf course Instapaper shouldn't take advise from me, a random stranger online, but from lawyers. But from my shoes (someone that run a business in the EU, is not compliant right now and is talking to a lawyer), Instapaper decision is a bad risk-management decision.
- kalleboo 8y agoIsn't it? We're in talks with lawyers right now about some stuff (not GDPR) and they've used both those phrases. We have to assess a risk and do what seems like the best risk/reward assessment, and the lawyers can only give us advice and guidance not 100% solid answers. With GDPR not having a single enforcement action yet I can imagine the guidance there being even more vague.
- reidrac 8y agoI agree with you, fines will happen in extreme cases, based in my experience with similar laws. Currently GDPR is news and there's a lot of hype around it and Instapaper is getting some attention because they failed to prepare AND, by the looks of it, decided to implement some unnecessary measures. I'm sorry to say that this looks like a PR stunt. Are they going to block EU users for months? I think any legal action against them was very unlikely, they could have solved the situation quietly.
- nemothekid 8y ago>Well, at least that's my read on the situation. And that's how I intend to do it: pro-actively work into getting in compliance without rushing it too much, and handle things properly as they come. A lot of the responses to the GDPR shutdowns have been like this - "you don't need to shutdown, because you won't be fined yet." But I have to ask, isn't shutting down a better alternative to knowingly breaking the law? Weather the fine is $2 or $20M, shouldn't following the law be most important?
- pjc50 8y ago> shouldn't following the law be most important? More or less everyone has given up on following the letter of the law on copyright and has resorted to all sorts of "fair use" ideas that probably wouldn't stand up in court. Instapaper makes copies of web pages. Does it have permission from the copyright holders for every copy of every web page? No. Are they going to enforce this? Almost certainly not.
- hobbe80 8y agoProblem is - a shutdown doesn't really make any difference. Dropping the data would make a difference, but just shutting down access could potentially (very unlikely though) mean additional infractions - the customers' requests for data access, corrections, removals etc. still need to be handled, and this could be seen as an attempt to skirt those rights.
- donarb 8y agoI would say that a shutdown essentially freezes the data and prevents it from being used internally, hacked, misused, disseminated, etc. For all intents and purposes, at the moment it doesn't exist. Once they believe they are back in compliance with the law, it will be "unfrozen" and users will be able to retrieve their data or opt-out completely by cancelling their accounts. And who's to say that Instapaper did not contact the authorities and discuss a plan such as this to mitigate the problem temporarily?
- chopin 8y ago
- merinowool 8y agoIt is not the same in all the countries - for example in Poland the goal is to get you to pay fine and if you go bankrupt then civil servants get special points. There is a culture of hatred towards private businesses coming back from the communist times. Second, you don't know that - bored civil servants eager to hit targets and get bonuses for scoring big fines could have gone for a low hanging fruit that is small companies without legal teams scared and paying instantly. Third, as its current state GDPR doesn't feel like ready "for production", so why would companies want to implement something with so many unknowns?
- alerighi 8y agoSo, if that is the real intention of the EU, why they didn't write that in the law instead of threatening everyone with a 20M fine ? Because for how the law is written now you could in theory get a 20M fine for the smallest violation, and it's obvious that a lot of companies will be scared of that and will simply cut out European users, especially small companies that don't have money to spend in lawyers and other stuff. The EU should clarify the situation, put limits on fines based on the company size (it's foolish that a person that has a blog that doesn't generate any revenue risks a 20M fine!), and give a transition period (yes, the law was approved 2 years ago, but what did the Europe to inform companies of that law and so permit them to be compliant in time ? Nothing, given the fact that everyone began to know about it some weeks ago) As an European citizen I'm really concerned about this law, it risks to cut out a lot of internet services, and that is bad, also now I'm scared to even put Google Analytics on my personal website, because well you know a 20M fine is not a good thing, sure it's unlikely to get it, but in theory you can, and I don't want to risk.
- deleted 8y ago[deleted]
- orf 8y agoDishing out a 20 million euro fine tomorrow would be completely against both the spirit and the wording of the law (fines must be proportional). So, no, it's not unlikely, it's definite.
- ggg9990 8y agoIt’s absolutely not true that the goal is compliance rather than fines: https://mobile.nytimes.com/2018/05/05/world/europe/margrethe-vestager-silicon-valley-data-privacy.html https://mobile.nytimes.com/2018/05/05/world/europe/margrethe...