5 ms·
GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes: I have a profitable, bootstra
by throwaway974 8y ago
GDPR has effects way beyond better user privacy. Sorry I've been pasting this in multiple GDPR related threads, but here it goes:
I have a profitable, bootstrapped SaaS business based in US. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication.
I've been talking to a very well known giant corporation (also based in US, but has many global offices) for months. The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. They are putting some draconian clauses, (various ISO certifications and such) in the contract that I, as a small company, cannot comply. That's their interpretation of GDPR. It doesn't matter whether it's right or wrong.
The VP and Director are really nice people and I've developed very good rapport with them. But I'm afraid their patience will run out soon and they'll go back to using spreadsheets. A lose-lose situation.
This is the side-effect of GDPR.
I'm all up for GDPR. I have uBlock, have blackholed all Facebook domains, etc. But don't assume that GDPR doesn't affect normal business transactions. Of course, blocking European users doesn't do anything for me since I want to do everything I can to protect user privacy.
But anyone who says, "Oh, how hard could it be?" has no idea what they are talking about.
- briandear 8y agoThe loudest GDPR advocates don’t care about you. 90 years ago they would have been the ones helping collectivize the farms, unintended consequences be damned. And this law’s effects are all about the unintended consequences. Anyone thinking government regulators are reasonable and benevolent has never dealt with said regulators beyond any trivial level. To make it more fun each member country handles enforcement, so now you have a risk of 28 different interpretations of the law. It’s madness. Even if you do everything right there is still a compliance risk. It’s like HIPAA in the US — HIPAA is pretty “easy” to comply with, but the consequences are so severe that it necessarily drives up operational costs significantly. Unless Europe is a significant part of your revenue, better to block Europe and decrease your risk to near zero rather than have a potential risk of catastrophic, company-ending fines. Because the fine isn’t against profit, it’s against total, worldwide revenue. So unless your European profit exceeds 5% of your worldwide revenue, no sane person would take that risk. Even without the enforcement risk, you still have to deal with potentially hundreds or thousands of information requests — even if you are doing everything by the book.
- djhworld 8y ago> 90 years ago they would have been the ones helping collectivize the farms This is possibly the strangest comment I've seen about this whole ordeal.
- olavk 8y agoI guess they are just saying you are a communist if you like GDPR. Maybe even a Stalinist.
- isostatic 8y agoA large number of tech-inclined americans believe that you're a commumist if you don't consider Ayn Rand to be 'a bit left wing'
- ravar 8y agoThat part is spot on, he's showing how history rhymes. It's an example of humans historically making the same mistake of not reasoning about unanticipated consequences.
- IncRnd 8y agoWell said.
- maxsilver 8y ago> The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. (snip) That's their interpretation of GDPR. It doesn't matter whether it's right or wrong. This is the side-effect of GDPR. I understand it's frustrating on your side, because you have no control over the response of your customers. But understanding what GDPR is (and not falling for FUD) is why the VPs and Directors get paid the big bucks and get the fancy titles. If they can't or won't work with legal to become compliant, they should resign and let someone else do the job properly. I'm not saying, "oh it's easy" -- it's not easy. But that doesn't make the law wrong either. And it's not OK to blame GDPR as being "bad", when those rules are mostly just putting some real enforcement around stuff all moral and ethical organizations should have already been doing anyway.
- PKop 8y agoIt is your opinion that the law is not "bad" because you view the positive intentions of the law as bigger than the negative unintended harmful effects is has.. on people exactly like the OP. Your points don't "make the law right". In whose view? Right or wrong for whom? In his example he listed all the ways he is handling user data in a respectful way. And yet, he is still harmed by this law. That the VP and President may be doing their jobs wrong (in your view) is no recourse for OP, he is harmed all the same. And ... are they doing their jobs wrong? At the end of the day, they are limiting their risk. What threshold of risk of harm to their business and livelihoods would you feel is an acceptable tradeoff to comply?
- mrep 8y agoIt doesn't make the law right either. Also, those VP's might be doing their job perfectly and the net effect could be that they cannot share data with any non-EU companies stifling their competitive advantages. There are many real world effects of GDPR and we are just starting to see the pros/cons of it.
- pjscott 8y agoIf you judge a law on what its effects should be rather than what they will actually be when applied to imperfect people, plenty of terrible laws will look good.
- loup-vaillant 8y agoWait a minute… You provide a service, and your users are afraid the GDPR could come to them?!? Please tell me I've read something wrong. Otherwise, this is just panic induced stupidity. I expect they will grow out of it (though maybe not before you go bankrupt, which obviously sucks big time).
- matwood 8y agoIt's pure FUD and panic. I think the only item most people have actually read is 4% revenue or 20M fine which ever is greater. It's unfortunate, but was the only way to get the Googles and FBs of the world to pay attention.
- tialaramex 8y agoDepending on exactly what the service is, this makes total sense under GDPR. The GDPR regulates both Data Controllers, and Data Processors Suppose I'm excited to hear about Hats.example, a site that sells hats. I visit, but they don't have any hats for my ostrich. Damn. But, they do have a box where I can leave my email address "to be contacted about future products". Great, maybe they'll introduce Ostrich hats. I fill out the box. Hats.example uses famous email deliverability company WeSpamPeople.example to ensure their marketing emails have "industry best in class reach". I soon get an email every week featuring different styles of hat, but they're all for people, disappointing. But then, WeSpamPeople's VC runs thin, and they cut a deal with OutrightFraudAndScams.example, which tricks people into making dubious "investments" and wants a lot of "leads". Now as well as the hats newsletters I asked for but don't really care about, I'm getting stuff inviting me to invest in Venezuelan Bitcoin mining and a project to make "Green cyber-organic goats for the blockchain". Ouch. Hats.example are a Data Controller. The GDPR says they are responsible for looking after the data that I gave to them, even if "technically" that form I filled out is a Javascript frame injected by WeSpamPeople.example, it's part of the Hats.example business, so it's their responsibility to ensure my email is not abused by a processor like WeSpamPeople.example, for example through contractual terms requiring WeSpamPeople.example to delete my email, never to send it elsewhere, etcetera. WeSpamPeople.example are a Data Processor because they were given my email address and other details to send me "marketing" information. They have a duty under the GDPR to get reasonable assurance that this was OK with me, for example maybe Hats.example did some paperwork that promised they're legitimate and they got sign-off for these email addresses. Regardless of whether they were given terms requiring them to do so by the Data Controller, the GDPR says they have to take care not to abuse the data, for example they can't sell it to anybody, since they obviously don't have permission to do that. OutrightFraudAndScams.example are also a Data Processor, and maybe also a Data Controller they know they didn't have permission to touch this data, but presumably they also routinely violate all sorts of other anti-fraud or anti-scam laws. Maybe the GDPR will help add to the fines and charges and put them out of business. [Edited: minor typos / fixes]
- carapace 8y ago> This is the side-effect of GDPR. And the GDPR is the side-effect of people running hog-wild with PII etc. I feel for you but I see your situation as collateral damage of the privacy crisis.