6 ms·
EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually
by priansh 7y ago
EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I know a lot of people love GDPR but I would be beyond shocked if the EU actually managed to hit Google with something that sticks. I very much hope I'm proved wrong!
This sort of resolution was inevitable.
I said it before and I'll say it again: GDPR is an annoying measure for developers, small businesses and startups. It doesn't do much other than put in place so many steps that growth tools for startups become risky to use. For big businesses that (ab)use big data, it's not much of a hassle because they can afford the legal steps as well as the change in infrastructure. They can even work around it and keep abusing data without consequences.
If they're able to beat Google's lawyer army and actually prosecute them, then Google will take a whopping fine in the millions of dollars that'll be more than covered by their daily revs.
- kd5bjo 7y agoFrom my (admittedly limited) understanding, this is not actually legal under the GDPR. Certainly the alleged (but not demonstrated) behind-the-scenes trading of personal info isn’t, but the shared id is also personally-identifying information, and directly regulated.
- hexadec 7y agoIt is very not legal, but I think the parent was saying these regulations are more onerous to small dev shops rather than Google and the fine for this will be minuscule. Hopefully companies will find paths to revenue that do not require selling out there users to this level, maybe by just having ad auctions without any identifying information at all.
- estel 7y agoThe first GDPR fines handed down by the ICO have been hundreds of millions of pounds for negligent breaches - I don't think it would be out of the realm of possibility for breaches by _design_ to result in multi-billion pound fines.
- priansh 7y agoSeveral billion pounds is still not much! They already broke GDPR once (or twice I think?) And received a 57MM$ fine. 57MM$ is nothing to Google. They've escaped even antitrust cases with minimal injury, it would be a truly shocking event if the EU actually managed to touch them.
- ntp85 7y agoFrom gdpr.eu: "The more serious infringements go against the very principles of the right to privacy and the right to be forgotten that are at the heart of the GDPR. These types of infringements could result in a fine of up to €20 million, or 4% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher." For Google that would be 4% of its worldwide annual revenue, I'd assume. Taking into account that it's not one infringement but multiple that could mean a pretty hefty fine.
- hexadec 7y agoThat is the worst case, no GDPR fines have been near there maximum yet.
- v7p1Qbt1im 7y agoLike it or not. Currently the internet would not exist without the ad-supported business model. Regular users expect everything on the internet to be free. I know people that categorically refuse to buy a 1-dollar app. It‘s starting to change now with people getting used to subscription models (Netflix, etc). But it will take a while until we start paying for news again, for example. Apple news + and google news initiative are a step in the right direction. Even if it‘s just for aggregate sub management.
- luckylion 7y ago> Currently the internet would not exist without the ad-supported business model. In it's current form, yes. However, I'm not so sure that everybody here would agree that "the web today" is fundamentally better than the web ten years ago, technological advances aside. Everybody smelling gold and starting a blog to mindlessly shill for products in hopes of getting a commission, super low quality texts written/generated/spinned entirely for SEO reasons to place ads between the paragraphs etc doesn't come to mind when I ask myself "what could be better on the web?" If those things disappear tomorrow, I don't think a lot of us would miss them. We'd notice them being gone because it might feel like being able to breath freely after a strong cold, but I don't think many would miss them. > But it will take a while until we start paying for news again, for example. Plenty of people pay for news. They won't pay for Gawker or Buzzfeed though. I don't think that's a problem for anybody not invested in or working for those companies.
- gpderetta 7y agoGDPR does not prohibit ads.
- ummonk 7y agoThis has always been absurd. Large companies have way more code and features in general which need to be checked for compliance, whereas small shops with small sets of data and features will have a far easier time complying with GDPR.
- cameronbrown 7y agoEven from the basic point of view: People go to Facebook, Amazon and Google daily. They accept the GDPR privacy policy once. Every single other website is bombarding users with popups, so there's a far greater chance users will click off from a startup's website.
- drusepth 7y agoLarge companies have the means to pay for the manpower (lawyers/consultants, developers, etc) to certify compliance with GDPR. Small companies often don't. I paid $2K for my first GDPR consulting session for a $7K MRR app and was quoted ~$25K for consulting while I would personally implement what needed to be done. $25K is nothing for a large company, but it's prohibitively expensive for a lot of small companies. This cost also doesn't include the (probably hundreds of) man hours required to implement and certify GDPR compliance, which are also disproportionately valued when it's being done by 1 person in a <5 person company versus N people in a >5K person company. Hopefully these costs will fall as more people become lawfully knowledgable about what GDPR entails and the market of people available to help grows. Unfortunately there's no "feel free to wait if you can't afford it yet" clause in GDPR.
- rjf72 7y agoAnother issue is that as a small company you generally lack the resources to effectively contest violations. Google can, and will, drag these things out in court for years. And ironically for free. Their legal costs are going to be covered by inflation on the fines themselves. 2% inflation on a $1 billion fine reduces it by $20 million a year. And also factor in the interest Google is earning on that $1 billion on top of the 2% 'principal' reduction per year. The whole penalty system is quite silly. The fines destroy small companies who are the ones struggling to comply, and do little more than offer extremely gentle pokes on the wrist for megacorps that have relatively unlimited resources available for complete compliance, if they actually wanted to comply.
- priansh 7y agoIt's not legal but there isn't much the EU can really do. It would be shocking if they actually managed to prosecute Google which has so far avoided much hassle in antitrust and the like, taking I think a billion dollar fine which sounds like a lot but is basically a slap on the wrist. That's why, IMO, GDPR sucks for small businesses that can be outed to the ICO for a minor oversight and not so much for big data abusers that can take on GDPR and come out unscathed.
- yifanl 7y agoThat sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR? A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/ https://www.gdpreu.org/compliance/fines-and-penalties/
- hvidgaard 7y agoEU have shown that it's willing to scale up the fines all the way if the company in question keep on violating the law. Alphabet global revenue 2018 was $136.8 billion, so the maximum fine is $5.5 billion which is in the vicinity of fines they've already received. It's a separate post in their yearly financial report. The gain must be significant if they continually keep violating the laws.
- priansh 7y agoThis is being quoted in every comment but if you have enough lawyers anything is possible. Google has come out of antitrust cases relatively unscathed. They've even violated GDPR itself once before explicitly, and got out with a 57MM$ fine. This case won't be any different than all the other times that Google has blatantly violated laws and walked away with a slap on the wrist. I would be very very very shocked if the EU actually managed to touch Google. I welcome and hope to be proved wrong.
- yifanl 7y ago
- simias 7y agoAnd I'm very annoyed that your initial reaction to reading this article is to blame the GDPR instead of blaming Google for these shady practices. Boycott that crap, move to other services. This shouldn't be acceptable. I'm very happy that the GDPR exist, if only because it forced all these websites from explicitly giving me a list of the literally hundreds of partners they want to share my data with, along with a way to say "hell no". Of course Google and friends will try to work around it but hopefully that won't come to pass and they'll have to actually bother changing their crappy business model. I think the spirit of the law is fairly clear, I wonder why Google thinks this scheme can work. Maybe they're just trying to buy some time. As for startups that sink because they can't be bothered to sanely handle my personal data: good riddance.
- priansh 7y ago- my initial reaction is to blame GDPR, yes, because it's just security theater that does so little to actually ensure privacy. Sure Google is at fault but GDPR was supposed to regulate this and it is clearly failing to do so. And if you want to boycott it you're welcome to but they've built an empire with their cloud, search, email, etc to the point where that would be pretty difficult and annoying to the average consumer. They're effectively too big to be boycotted at this point. - It doesn't explicitly force them to do that. And most sites aren't explicitly sharing the data either; i.e. almost every site uses Google analytics which doesn't really comply with do not track all too well, and Google will then share their data with everybody else (which is part of their violations in this article). Also saying "no" doesn't do much either as most of these big sites either already stored the cookie or won't do much to delete it. And it's not that they'll try to work around it, they either don't put forth the effort because GDPR is like a pebble for them, or they already worked around it in a way that changes nothing. Their business model is still the exact same. I think the spirit of this law is fine, but the actual law does nothing and is just privacy theater. Google isn't buying time, almost 4 years later nothing has changed -- they just know they can't be touched. - They're not going to sink, they'll just grow much slower and thus won't be an alternative to the big data abusers you hate so much. And they're not failing to handle your data, most of the time startups aren't selling you out they're just trying to figure out who their customer is internally. To do this they collect some data that is usually optional and very much with your consent; GDPR just puts a bunch of hoops in front of this so that it's an enormous pain to do so. I run a startup that collects basically no data (literally, we do not have a database for 2 of our products). It was a pain for us to become GDPR compliant because that disables our metrics entirely and requires a bunch of banners and checkboxes everywhere even though we literally store nothing. I'm all for the spirit of the law. I just think the execution sucks and they definitely didn't think it through enough. I think the evidence for this is clear based on the sheer number of privacy violations we've had since GDPR was enacted alone, and how little enforcement and regulation has actually gone on.
- mola 7y agoThe European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more power you have to break the law, the bigger the stakes should be.
- Sean1708 7y agoUnless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative: > The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements. From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties https://www.itgovernance.co.uk/dpa-and-gdpr-penalties
- sokoloff 7y agoIn context, "relatively bigger" would mean something like a progressive tax bracket. $20MM up to $500MM rev, 4% up to $1BB rev, 5% up to $2BB rev, 6% up to $5BB rev, etc... A straight 4% would be absolutely bigger, but relatively the same (once beyond $500M).
- mamon 7y agoI think it's not about "income brackets", it is about profit margins which can vary a lot between industries. 4% of revenue is enough to bankrupt traditional business, like Wallmart with profit margins of 2,48%. Google is a low-cost business, with profit margin of 25%, so even the maximum GDPR fine is something they can just write off.
- inlined 7y agoSo just make the fine a portion of profit? Maybe a three layer system that takes into account flat euro rate, a percent of revenue, or a bigger percent of profit; whichever is highest.
- ceejayoz 7y ago> If they're able to beat Google's lawyer army and actually prosecute them, then Google will take a whopping fine in the millions of dollars that'll be more than covered by their daily revs. This is why the 4% of global annual revenue fine option exists. A few of those add up quick.
- ht_th 7y agoFurthermore, if organizations are explicitly accepting penalties to keep on violating the law, that law will be adjusted accordingly. It might take a while, but it will happen. Laws with the intention to change behavior / culture cannot "work" from day one. This is a continuous process steered by politics, courts, governments, and public opinion.
- fmajid 7y agoPenalties can be applied repeatedly if the violation continues. It's not a 4% lifetime cap, it's 4% per enforcement action. The DPA can just churn them once a week and then we're at 204% of annual turnover.