3 ms·
Its predecessor regulation capped fines at around $750k. Guess how many were levied at or near the maximum? Zero. The only large fines were for serious, deliber
by ascorbic 8y ago
Its predecessor regulation capped fines at around $750k. Guess how many were levied at or near the maximum? Zero. The only large fines were for serious, deliberate abuses, such as a group maintaining a secret blacklist of construction employees. This isn't like the massive fines from US regulators on foreign companies. The rules say that fines should be proportionate to the scale of the breach and the harm caused. The large fines are for serious, deliberate, repeat offenders. It's also to stop a company like Google deciding that they'd rather not comply, and treat a fine as a cost of business.
- mseebach 8y agoWhen a new law is enacted, it's not prudent analysis to assume anything about how it will be enforced based on the previous law, especially not when fines were increased 25x - GDPR is not a minor clarification of a few bits and pieces, it's a whole new thing. The previous law was specifically criticised for having no teeth, and the new law has specifically been highlighted for it's new teeth. Of course it's possible that regulators will just sit on their hands, it's just not very likely. The only reasonable assumption is that those new teeth will be tried out, and whoever they will be tried out on first will have a bad time. Do not assume that the first cases will be Google and Facebook, the regulators aren't stupid enough to try their luck first on the two organisations that has spend the most on being technically compliant, and has bottomless warchests to fight it.
- ascorbic 8y agoThat doesn't mean lawyer up or shut down at the first request. Of course you should be prepared, by doing sensible things like having an up to date privacy policy, and only keep the data that you need and that you have permission for. However when it comes to compliance, if you get a request, be sensible. The time to lawyer up is if you get a notice from the ICO, if you think it's unreasonable and/or you don't think you can comply with it. I've dealt with the ICO quite a bit, as I've appealed a few FOI requests, and they've always been very reasonable, if a little overworked and slow to respond.
- LamaOfRuin 8y agoThat's not a realistic decision for companies to make in the face of actually aggressive regulators, because regulators will simply levy the relatively smaller fines every day the company remains in violation (which EU regulators have threatened/done to US tech companies). Instead of making that decision, Google just stopped operating services (Google News) in countries that tried to aggressively control how they did business. You're right though, that it is always a relatively pure cost/benefit calculation for the company.