6 ms·
> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really w
by pfg 8y ago
> But because the fines are so steep — violating GDPR will cost a company 4 percent of its global turnover or $20 million, whichever is larger — no one really wants to be caught non-compliant.
Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.
- cortesoft 8y agoI don't think 'likely' is enough to stop concern. You have to act under the assumption that you will get the worst, not just hope that you will get the best.
- freeone3000 8y agoWhy would a government impose anything other than the maximum?
- dragonwriter 8y ago> Why would a government impose anything other than the maximum? Because it's bound to apply a bunch of other rules in setting penalties by the same regulation that set the maximum cited. Saying that every offense will get the maximum is saying that the government will ignore the regulation, in which case you can just as justifiably say that any behavior, even if it isn't a violation of the rules, will get a fine of €1.337 quintillion, or 1,000% of global combined GDP, whichever is greater. Heck, even ignoring the casd-by-case factors that must be considered, the 4% or €20 million maximum is much greater than the maximum for many violations, there are only certain GDPR violations that have that maximum.
- marvin 8y agoBecause the regulation is meant to enforce lawful behavior, not make the government richer. If they break out the maximum penalty for a minor violation, it will obviously stifle business and cause economic harm to the EU. But they do need a credible threat to really punish wilful disregard of the law, for companies that profit from breaking the rules. We see how well it works when the fine costs less than the profits from breaking the rules. The EU is making sure that this will not be the case for the GDPR.
- ars 8y agoIs what you say actually written into the law, or is it left up to the discretion of the enforcer? Because I'm sure EU companies will be given lots of leeway, but non EU companies will not, and no one wants to be the example.
- stordoff 8y agoFines must be "effective, proportionate and dissuasive", and there are various factors that the authorities must take into consideration. If you feel they _haven't_ taking the relevant factors into account, you can take it to the courts (especially if there is a history of fining non-EU companies more, as that would suggest they are taking irrelevant factors into consideration. https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/art-83-gdpr/
- ars 8y agoUm, those three words "effective, proportionate and dissuasive" together mean "as high as possible". So yah, people are right to block the EU first, and figure out the details later.
- orf 8y ago> Um, those three words "effective, proportionate and dissuasive" together mean "as high as possible". No they absolutely do not.
- ars 8y agoReally? "effective" = large amount, so company won't do it again, "proportionate" = relative to revenue, "dissuasive" = make them an example so no one else will dare. I bet you are going to tell me proportionate somehow makes it all better, but for companies that make money this way, the amount of money they make this way in proportion to their income is basically all of it. So you can bet regulators will go for the full amount. No company in their right mind is going to rely on the mercy of an EU court toward a non-EU company.
- hobbe80 8y agoWhy doesn’t petty theft carry the death penalty? Penalties for any crime must be, in a democracy, be reasonable to the general population (which of course contains a lot of people who both are data subjects and data controllers via owning smaller and larger businesses) - otherwise the legislative body will be voted out, laws changed, etc. Equilibrium. Yes, EU laws might have more red tape around them, but we still vote for our representatives.
- Tomte 8y agoBecause having every single fine rescinded by the courts looks bad and brings you exactly no money.
- oldcynic 8y agoArticle 49 of the EU Charter of Fundamental Rights. All penalties under EU law must be proportionate. As a result there is already considerable case law, from multiple individual laws and countries, at the CJEU to define the extent of proportionate.
- seanwilson 8y ago> Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand. I find this really ridiculous as well. To run a business, there's lots of rules you have to follow which can result in fines and even jail time if you make mistakes (taxes for example where the rules are complex). If every small transgression for every rule was hit with the maximum penalty, nobody would be able to risk doing anything. The large GDPR fines to me seem to be aimed at big companies so more than a slap on the wrist can be issued for abusing vast amounts of personal information. I don't think small companies need to be blocking EU users because they're worried they might make a mistake in how they implement their newsletter consent checkbox for example.
- jdminhbg 8y agoI’m sorry, but blind trust in the benevolence of regulators in a country you’re not even a citizen of is no way to run a business. I don’t blame US companies unwilling to deal with GDPR uncertainty any more than I blame EU banks unwilling to deal with American customers because of our insane FATCA regulations.
- guitarbill 8y agoI'm pretty sure even in the US, sentences for breaking the law vary depending on the case. And what's the point living in civilisation if you can't trust the judiciary? There are options to appeal, so you're not at the mercy of one regulator/judge/<x>. Europe and the GDPR are no different. EU banks not dealing with Americans/FATCA is simply down to it not being worth the effort. Luckily, the GDPR wasn't written in such an absolute way. It doesn't apply to non-EU companies doing business outside the EU, even if they might get the occasional European using their services (unless they specifically go after EU subjects). For example, a Japanese company selling specialty arcade joysticks and I, as a UK resident buy one using yen, not pound sterling. Even though they might ship to the UK, as they ship to loads of places, they aren't doing business in the Union, and they don't have to follow the GDPR.
- AmericanChopper 8y agoYou seem so incredibly confident in this that you must be able to point to some evidence or a case study to support your claims?
- DanBC 8y agoHere's the law. Notice that there's a bunch of stuff taken into account before setting the fines. https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/art-83-gdpr/ Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/articles/2018-04-26/u-k-healthcare-startup-cera-is-said-to-have-posted-fake-reviews https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt... Here's an organisation that had video interviews with children who were the victims of sexual abuse. The organisation put these videos on DVDs with no encryption, and sent them through regular mail. The DVDs were lost. This is a repeat of a previous data loss from this organsition. Despite the severity of this breach, and the repeat, and the lack of protective action, the organisation was not fined the maximum available fine. https://ico.org.uk/action-weve-taken/enforcement/crown-prosecution-service/ https://ico.org.uk/action-weve-taken/enforcement/crown-prose...
- AmericanChopper 8y agoThere is no caselaw on the GDPR and no way to predict how fines will be levied. You can speculate how it will be enforced (as you have), but businesses tend to avoid speculation when assessing risk.
- zimpenfish 8y ago> You can speculate how [GDPR] will be enforced (as you have) Since the GDPR will be enforced in the UK by ICO, there's very little speculation in the parent post.
- AmericanChopper 8y ago
- izacus 8y agoBlocking access to EU citizens while keeping their data in violation of GDPR sounds like a case for this maximum penalty. It doesn't seem the company is showing good faith in data protection.