4 ms·
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder. If easy competition is being paid for through shady practices, then
by dbasedweeb 8y ago
I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.
If easy competition is being paid for through shady practices, then it should never have been that easy. It’s a no-brainer that a large, established business has certain advantages over up-and-comers; GDPR didn’t make that the case either. It’s easier for a large, rich company to do almost anything, including respecting our privacy as enforced by regulation or law.
- hyperpape 8y ago> It’s easier for a large, rich company to do almost anything, including respecting our privacy as enforced by regulation or law. And also including doing creepy things with our private data that stay just on the right side of the law.
- cheald 8y agoThere's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and still be in violation of the law and subject to its penalties. Just asking for an email that will literally be used for nothing but to send a registration confirmation - you know, to sign up users, the same way we've been doing forever - puts you in its compliance crosshairs. You're now legally liable for a whole raft of additional compliance measures that probably necessitate paying a lawyer a decent chunk of change to make sure you're above board with. Your "MVP" has now expanded from "here's a simple idea I cranked out this weekend" to "here's a simple idea and a legal contract and audit trails that prove consent and an obligation to exfil data from my database on demand in perpetuity and data portability endpoints and data exchange contracts with every API provider I use and my database has to be encrypted at rest and highly redundant and I have to set up regular vulnerability scans and if I want to back up my database to a non-EU datacenter I have to obtain consent from all my users first and a bunch of additional requirements that possibly make it illegal to not age out my Apache access logs and why am I doing this at all again?" GDPR significantly increases the friction for moving new ideas from concept to product, even if there is absolutely zero nefarious happening in the product. If it only made life hard on the people engaged in shady practices, there'd be a lot less concern over it, but that's just not the case. It doesn't just punish the misuse of data, it punishes the lack of proactive compliance to a set of criteria which are frankly beyond many hobbyists. Some see this as a good thing. But I think that it's also fair to guess that it's going to cause otherwise good and benign ideas, products, and even entire companies to die on the vine as a result.
- matthewmacleod 8y agoGDPR significantly increases the friction for moving new ideas from concept to product, even if there is absolutely zero nefarious happening in the product. I would personally consider “not knowing where users’ data is, or being able to tell them” to be a nefarious act in itself.
- falcolas 8y agoAnd if your MVP makes money, you're on the hook for a lot of taxes and income reporting. It's part of the cost of doing business. For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.
- JumpCrisscross 8y ago> It's part of the cost of doing business. In a jurisdiction. GDPR means a dollar can buy more MVPs outside Europe than inside. Keep in mind that this has no bearing on the privacy stance of the ultimate product. Just the fixed cost of iteration.
- falcolas 8y agoI hate to break it to you, but the idea behind the GDPR is gaining traction outside the Europe. Fighting this trend is only going to hurt more in the long run.
- JumpCrisscross 8y ago> the idea behind the GDPR is gaining traction outside the Europe I hope it does. Europe, however, has a unique penchant for unnecessary bureaucracy. Nobody is complaining about GDPR’s requirements. It’s the ancillary administration which is destructive.
- falcolas 8y agoWhat enforces compliance if there is no administration - the administration is the teeth of the compliance. Companies have had years in which they were receiving warnings and recommendations for best practices - they ignored them. This is the piper coming with the bill.