9 ms·
I think the ridiculous thing is every mom and pop site and blog and website needs to be gdpr compliant? insane. If the true intent was to make sure large player
by cdevs 8y ago
I think the ridiculous thing is every mom and pop site and blog and website needs to be gdpr compliant? insane. If the true intent was to make sure large players have their system in check then they should have simply said if you have 50,000 or more users giving you data a month or something to protect anyone interested in software from being afraid of having 2 users because now they need to read every international law. I know someone will fire back at this but what stop the United States from coming up with some law as well on the internet against how logins should be and then filing a lawsuit against every other country company that doesn’t comply. A business should follow the laws of based on the owners location and if other countries don’t like it then that’s for allies to group up and ask that minority country for change. gdpr to me is of reaching on the internet in a scary way.
- JumpCrisscross 8y ago> A business should follow the laws of based on the owners location This cuts against centuries of sovereign tradition and precedent. GDPR's constraint to users in Europe is reasonable. (As is refusing to do business in Europe by blocking the continent.)
- optimalKEK 8y agoEU is great and you anglos don't understand the visionary nature of this law and our leader, Jean-Claude Junker. Additionally, this law will create so many jobs, think about it for a second!
- JumpCrisscross 8y agoCan't tell if you're trolling, here or when you said "authoritarianism is the only way to protect the people from runaway capitalism" [1]. [1] https://news.ycombinator.com/item?id=17099952 https://news.ycombinator.com/item?id=17099952
- tome 8y agoSurely both.
- optimalKEK 8y agoI leave that for you to figure out. It's AMAZING that some Europeans back me up when I make statements that argue for regulatory overhead. These guys are absolutely clueless.
- deleted 8y ago[deleted]
- rdlecler1 8y agoYes, every US company must hire an EU representative to be compliant. Create jobs through regulatory overhead!
- gcthomas 8y agoMost companies do not need an EU resident DPO at all.
- rdlecler1 8y agoHave a source on that? If you use Google Analytics you need to provide one.
- gcthomas 8y agoYou need a DPO if you are a public authority (eg government body or public school) or if you carry out "regular and systematic monitoring of data subjects on a large scale or when processing special categories of data …". If you receive data from Google Analytics that is aggregated into categories or regions (ie not identifiable) or on a small scale, then you are not in the realm of large scale, systematic monitoring, so no DPO needed.
- jacquesm 8y agoAlmost. You do need an EU Designated Representative. https://gdpr-info.eu/art-27-gdpr/ https://gdpr-info.eu/art-27-gdpr/ There is no such thing as a 'EU resident DPO'. I think you are confusing the two roles.
- gcthomas 8y agoThanks. I mixed up the name, though, not the role. Your link says that the requirement for an EU rep "shall not apply to: processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) …" Most companies will not need an EU Designated Representative, in the same way local companies will not need a DPO.
- lightbyte 8y ago>I think the ridiculous thing is every mom and pop site and blog and website needs to be gdpr compliant? insane. The even more ridiculous thing in my opinion is that these mom and pop sites are not already GDPR compliant. What could they possibly be doing that makes not abusing a handful of user's privacy an insurmountable issue?
- JumpCrisscross 8y ago> What could they possibly be doing that makes not abusing a handful of user's privacy an insurmountable issue? Nothing. Doesn't mean they have nothing better to do than respond to letters and regulatory enquiries. (To be clear, I'm not disparaging regulators asking questions. I'm simply observing that such questioning-and-answering has a cost. That cost is reasonable for a large company. It may not balance favorably for something smaller.)
- zentiggr 8y agoLike TFA describes pretty in depth, that response burden, for sites that have no saved data and process nothing personal can be as simple as a form letter response pointing to a properly detailed GDPR statement. Or might have to be expanded on a bit, point is the response cost can be scaled as well.
- gcthomas 8y agoIt will likely be years before any small business gets a routine regulatory enquiry, unless there is a complaint. And that is how it should be, isn't it?
- dorgo 8y agoSo, a pragmatic approach then. Everybody violates the laws a little (maybe without knowing) and regulators pick big violations first. Software developers like to handle each edge case up front - which is not possible on this scale I guess.
- Fradow 8y ago
- mrtksn 8y agoSo how exactly it's O.K. for customers if their privacy is breached by mom&pop businesses but not O.K. if it's breached by businesses that have 50K or more users? It's common theme here on HN to think that users are just some kind of resource and the regulations are anti-climactic things that slows down the party. Seriosly, As a user, I don't want my information to be sold to random people that I have no information about even if the seller is a tiny business because my feelings are not against the business but against the practice. The size of the violator is irrelevant to me. If not breaching my privacy and my rights makes your business unprofitable, then simply you don't have a business. Users are people, not just pageviews or hits or goals - despite what your analytcs software says.
- JamesBarney 8y agoIf you die in a fire or building collapse it's equally bad whether that building was a large commerical building or a single family. But we have two sets of building code rules because the regulatory burden is very different. The cost of complying with lots of regulation are fixed, and don't necessarily scale linearly with the size of the company. So to prevent these laws from wiping out small businesses they usually phase on these rules with increasing size.
- organsnyder 8y agoWhich locality are you talking about? Building codes vary quite a bit from one region to another. I'm pretty sure my municipality (Grand Rapids, MI, US) does not have differing commercial building codes based on the size of the organization utilizing the space.
- JamesBarney 8y agoNot the size of the organization using the building but the size of the building.
- JamesBarney 8y agoI wrote organization but I meant to write building
- crankylinuxuser 8y agoSigh, you don't get it, do you? In software, if you want to skirt the law, its easy to do so with small team/companies. Just spin up shell companies under the limit and use that to skirt the law. It certainly defeats the spirit, but this is capitalism.. No holds barred, and do illegal moves till you get caught.
- deleted 8y ago[deleted]
- budu3 8y agoWe as the collective tech community brought this onto ourselves. We did not self regulate ourselves. We did not take out customer's privacy serious enough. Therefore, big government stepped in and regulated us.
- blub 8y agoThe intent is to give people a way to control the information which will be used to influence their lives instead of being at the mercy of every corporation, start-up or mom & pop operation which is trying to make a buck. Private life is such an essential part of human nature and our societies, no matter what the "nothing to hide" camp will say. There will be collateral damage and that's unfortunate yet tolerable, given the extensive abuses.
- stunt 8y agoThat is exactly the way it should be. people should stop storing user data because they don't do anything to protect it for you. Keeping user information just became so normal in the past few years. it is not just about ads but also security. You have all your information all over internet. Websites without minimum security requirements store everything just because it is cheap to do it and they just believe they should store it even they don't need it because maybe they need it in the future. Hackers can do way more than you can imagine with your data if they want. Storing user data should be expensive. Companies should only store it, if they accept and understand the responsibility and they must feel accountable for it.
- deleted 8y ago[deleted]
- swat535 8y agoI think the issue here is that GDPR is really broad. We have had our legal team review it to perform a cost/benefit analysis on whether we should comply with GDPR or block the EU region for the time being. At the end, while we all agreed that the idea behind this law is reasonable, it would benefit us to ignore the EU region. (We reviewed our database to ensure we don't have any EU users currently on the system before doing this) That being said, we branched out and started to slowly implement some GDPR requirements that can benefit our existing users privacy and we will certainly remove the EU blockage when the scope of this law becomes more apparent to our legal team. I strongly believe software is due for some serious regulation, just like all other branches of engineering, we need to take responsibility for the systems we create and I feel like this is a sign that our industry is maturing from it's infancy stage. Kudos to EU for making an attempt to keep Europeans safe.
- taysic 8y agoI also think the requirement to provide the same service 'without detriment' if a user doesn't want personalized ads - should only apply to companies over 500,000 users. It should only apply to companies that are ubiquitous that people feel they can't live without.
- riquito 8y agoGDPR Art. 2 par 2 This Regulation does not apply to the processing of personal data ... by a natural person in the course of a purely personal or household activity
- dorgo 8y agoSo I am allowed to collect and store personal data for my toy project without consent?
- riquito 8y agoIANAL As long as there's no connection to a professional or commercial activity it should be outside of the scope of GDPR. This is identical to the previous legislation, directive 95/46 art. 3.2. Note that any external service processing the data must still abide by GDPR.
- Bromskloss 8y agoEqual before the law.