5 ms·
>Please explain how. Assuming you legitimately want to know, and aren't just trying to ask a pointed rhetorical question, ok: >>Why not throw your trash on a
by axlprose 8y ago
>Please explain how.
Assuming you legitimately want to know, and aren't just trying to ask a pointed rhetorical question, ok:
>>Why not throw your trash on a neighbor's lawn?
Because unless you like having other people's trash on your lawn, a simple tit-for-tat strategy in game theory would suggest that it's in your best interest to not do that yourself either. In other words, the most sustainable course of action in this case is to follow The Golden Rule ("do unto others as you would like them to do unto you").
The thing with the GDPR, is that the parties involved in the game are you and the EU government, and you not complying with the GDPR by just refusing to serve EU customers doesn't put you in line for any kind of equivalent retaliation if you delete all your EU user data first.
>>Why not enslave your workers so you don't have to deal with turnover and hiring replacements?
Because in a developed free market economy, that business strategy is doomed to fail, since your workers can choose to go work somewhere else that has more favorable conditions, and will likely warn any potential future workers against working for you. If you maintain these sorts of business practices long enough, eventually your pool of workers to choose from will shrink to the point where you'll no longer have enough viable candidates to replenish your workforce.
Similarly, if your business is in fact collecting sensitive data and abusing its use of it for shady purposes, your customers will eventually start looking for a way out of dealing with you (as is possibly the case with facebook right now).
However, the key distinction that seems to be missed by a lot of people here, is that not complying with the GDPR does not inherently guarantee that a business is either collecting dubious data, nor that it's doing shady things with it. And this is a result of the fact that companies around the world are not obligated to conduct business in the EU. If they magically were obligated somehow, it'd be a different story, but that's never going to be the case.
For example, if a new business starts up in the US right now, it will not actively have any EU user data yet, but could still opt to not comply with the GDPR purely because of the overhead costs, and just block EU users altogether in order to avoid any hassles in the future. Does this mean that the business is doing questionable things with user data? Obviously not, since it hasn't even had a chance to collect any data yet, but clearly it positioned itself in a way that it found to be the most advantageous for its given resources, at the detriment of any potential future EU users, without risking any obvious repercussions other than having a slightly smaller potential market. If all of its competitors decide to comply with the GDPR and serve EU customers however, then the strategy could turn out to be a losing one, but it's far from a given that this will happen.
>>Why dont you stop paying taxes so you don't have to do work to get the same amount of income as you would without taxes?
Because not paying taxes will get you jail time and/or non-trivial fines in pretty much every country you could possibly be based out of. I know there are quacks in the US that claim you can "legally" not pay any income taxes, but none of those crazy arguments have ever stood up in court, and have historically landed tax avoiders that tried to argue for them in jail. Regardless of how you feel about taxes, needlessly incurring large fees and/or landing yourself in jail, just isn't gonna be good for business, so it's in your best interest to pay them even if you're a raging psychopath/narcissist.
>Not complying with the GDPR doesn't have any obvious consequences because every company that sells user data is pushing their negative externalities onto others.
Not complying with the GDPR != selling user data.
This argument is moot because it doesn't logically follow that not complying with the GDPR necessarily produces these "negative externalities" that you're referring to. Therefore, it doesn't explain anything about why not following the GDPR doesn't have obvious consequences. Refer to my hypothetical startup example above for elaboration, because this is an example of conflating "data collection/dubious practices" with "GDPR compliance", which are two very different things.
>The GDPR is trying to make it so that the people creating the negative externalities are the ones paying for them
I agree that that's what it's trying to do. Unfortunately, it seems like it might be having some unintended consequences along the way regardless.
- lovich 8y ago>Because unless you like having other people's trash on your lawn, a simple tit-for-tat strategy in game theory would suggest that it's in your best interest to not do that yourself either. That's why company's trash the commons instead of someone's direct property, and then zealously guard their property rights. With actual trash it's dumping into a river instead of a front yard. With personal data they spend millions to suck up and infer personal data and then spend more millions guarding all of their information with lawyers crafting NDAs, obfuscateing their information with accounting tricks, and suing people or trying to bring criminal charges against people who gain access to their information. When a company puts a secret tracking pixel on a website that users don't know about, it's good business. When an individual puts a secret program in an email the company doesn't know about, that's hacking and they need to go to jail. >Because in a developed free market economy, that business strategy is doomed to fail, since your workers can choose to go work somewhere else that has more favorable conditions, and will likely warn any potential future workers against working for you I'm not sure you know what enslave means. People wouldn't be allowed to leave. To the rest of your point there, the argument that, "the market will respond to people's preferences" doesn't work with such one sided information. Sure people are leaving Facebook, but to go where? Instagram, another Facebook property that steals data? Snapchat, a different company this time but still stealing data. Cambridge Analytical has had to close up shop due to outrage, so they just reopened under another name so that most people will be unaware. Same with Blackwater -> Xi -> Academi. The entire Industry is engaging in these tactics and only dealing with the cost of renaming or a PR push because it is so lucrative. The GPDR is the EU's attempts to make it not lucrative anymore and allow for other business models to now be viable because they don't have to deal with shitty companies making a ton of money off of stealing data from people. >Because not paying taxes will get you jail time and/or non-trivial fines in pretty much every country you could possibly be based out of. And now not following the GPDR will get you serious fines followed by jail time if you continually flaunt the regulators. Literally everytime you said "pay taxes" in that paragraph could have been replaced with "comply with GPDR" and it would have been just as accurate >This argument is moot because it doesn't logically follow that not complying with the GDPR necessarily produces these "negative externalities" that you're referring to. It's not moot. Even if you don't sell the data, you are creating a pool of user data that is valuable to steal, and the constant stream of breaches from companies ranging to startups to enterprise is evidence that security is extremely difficult if not impossible. Look at the Equifax breach. They didn't have to sell any of that data for the breach to have caused actual damages to both users who had done business with them, and people who had never even entered into an agreement with Equifax. That is a negative externality generated entirely by the company. The GPDR allows individuals to now say, "no I don't trust you to hold my data". >I agree that that's what it's trying to do. Unfortunately, it seems like it might be having some unintended consequences along the way regardless. Everything humans do has unintended consequences, that's a feature of not being omniscient, but using that as an argument for not trying something like the GPDR is disenguous. If this was the governments first warning shot against data collection companies I'd probably be in the camp that thought it was going to far. It's not though, there was the cookie law, the DPD, and warnings from the government. The corporations have ignored the intent of all of them and gone on with business as usual. So now that trying a weaker form of regulation has already been done and failed the options are to let companies continue as usual and continue to harm society, or create a regulation that has actual teeth to it and starting doing a governments job of protecting it's people. Everyomes entitled to their opinion, but I am firmly in the camp of actually forcing companies into stopping this practice