3 ms·
> paperwork notwithstanding thats the main point for me. Some of GDPR is good: right to delete in a reasonable fashion is great. Right to not be personally ide
by zerostar07 8y ago
> paperwork notwithstanding
thats the main point for me. Some of GDPR is good: right to delete in a reasonable fashion is great. Right to not be personally identified is awesome, but that's much easier to do in the ISP level. Adtech creates problems - that should mean you have to regulate adtech. But GDPR is more about documentation, bureaucracy and Vista-style popups than about how to protect data. You need a lawyer just to put ads on your site. It's a draconian law designed by a single-issue Green leftist, which relegated IP addresses to the status of some kind of fatally dangerous information. It breaks the web from a "web" to a series of tubes with doors in between. The severity of the law is out of proportion with the average internet user's concern about privacy: time and again people have shown they just don't value it as much as the law suggests.
After a few days, when the cheerleading has stopped people are going to be faced with some unpleasant realities: small business switching to facebook (because otherwise their website would contain more legalese than content) and ecommerce turning more towards the large marketplaces. In this sense, Facebook, Google and ebay/amazon become one-stop shops for GDPR-compliant solutions. The reason: GDPR removes options but offers no alternatives.
- lomnakkus 8y agoThis is paperwork you should already have in some form if you're actually following (and I hate this phrase) "best practices" for customer data and trying to explain to your employees how to handle a (suspected) security breach, etc. IMO, it's good to actually at least try (as a company) to come with some sort of consistent set of guidelines as to how a security breach should be handled. And a company-wide policy on how company laptops should be treated (disk encryption, etc.). It's just that nobody actually bothered to actually do these things because the potential penalties were absolutely trivial. I know of at least one company which chose to just pay the regulator in their country a monthly fine instead of fixing the problem because it was cheaper than paying developers to fix the issue. How is that not broken? (I should say that I have problems in which this was "released", so to speak, since there hasn't been time for any establishment of practice based on the intent of the law, etc. It should definitely have been a gradual rollout, but that's not really relevant now that it has been "released".)