8 ms·
GDPR fines were meant to rock the data privacy world
- probo23 7y agoGDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble in thought, weak in action
- mooman219 7y agoBeing honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records on an un-restricted FTP server...
- McDev 7y agoI work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.
- DaiPlusPlus 7y agoMy experience with startups lately is if it’s a greenfield project that started within the past 3 years then they’ll do everything by the book: sometimes even down to storing email addresses as hashes in the database, requiring a user to login first for the software system - and the company - to know their email address). Older systems which depend on having PII and even financial information as cleartext in the database are the problem - and its essentially technical debt with far-reaching consequences, so no-one will fix a system that uses tenants’ customers’ SSNs as a primary-key (yup).
- baroffoos 7y agoI am aware of a legacy system powering a local business which runs on Rails 1 on a version of debian from 2012 and stores users passwords in plaintext, downcased. I have tried to explain so many times that this system needs to be replaced urgently not for security reasons but because no one actually knows how to use rails 1 anymore.
- dwoozle 7y agoI have a Rails 1 product making $10K a year but I don’t have even the ability to log into the box anymore so if even the tiniest thing falls over that revenue is permanently gone for me.
- baroffoos 7y agoIts funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"
- Mirioron 7y agoBut that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then they'll likely be outcompeted.
- bjelkeman-again 7y agoBut I don’t think McDev above was talking about a software startup in the poorest part of the world. I have implemented GDPR in a small non profit open source SaaS business. A funded startup should have no issue doing the same.
- Mirioron 7y agoBut I wasn't talking about poorest parts of the world either. China is richer than some EU countries, eg Bulgaria.
- em-bee 7y agothey can and they do enforce it. street vendors are much less common in china than they used to be.
- Jommi 7y agoYes, in now richer cities. But they still thrive in lower gdp cities.
- 7y ago
- beher 7y agoDo you consider it difficult to survive as a startup while protecting the privacy of users?
- Mirioron 7y agoYou're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email addresses or first names then that should be far less strict than if a company handles medical information, home addresses or credit card information. On the other side, we should have audits in companies to see how the personal data is handled. Particularly in ones that deal with sensitive information.
- phs318u 7y ago> they probably can't afford to do it right Two things occur to me here. 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. 2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ https://privaon.com/ (first search hit). > here should be some exceptions to it for small companies This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.
- Mirioron 7y ago>1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. Except that foreign companies won't have this same limitation. The end result is that all of your online services will be provided by foreign companies, which ironically is already the case in the EU. A foreign company that's beyond the jurisdiction of the EU can abuse GDPR as much as they want. If they get caught then they'll just lose their business. The EU can't actually fine them, but that same company likely outcompeted EU companies for years. >This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability. They can do the same thing with foreign companies though. If you can set up a system where you would use your small companies to escape regulation, then the same can be done with companies run by foreigners. >2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ https://privaon.com/ (first search hit). And said business opportunity is additional inefficiency on businesses in the EU that their global competitors don't have to follow.
- kevingadd 7y agoJust because they're small and weak doesn't mean bad data policies can't cause harm. If you have 100 customers you're the little guy, but if your 100 customers are political activists in authoritarian states, it's kind of a big deal if you leave a .csv file containing their personal info on your http server, isn't it? In the end whether a penalty is just depends on the significance of the offense and whether the bad actor has reformed. The GDPR does give regulators discretion over whether to issue fines or take legal action, they don't immediately wreck people. People need to remember that while laws are very rigid in drafting, they typically grant a lot of flexibility to the humans that enforce them... and humans often just opt to ignore them. So you can't just look at the law in terms of what it appears to read as, you have to also look at how it's applied in the real world. That can of course mean that a law like the GDPR has unintended negative impact, but it also means that sometimes the impact is not the negative you'd assume from reading it.
- thrower123 7y agoAt the time, everybody who pointed out that this was exactly what was going to happen got flamed hard. I hate that cynicism usually proves the correct stance.
- EdwardDiego 7y agoThe article you're commenting on mentions reasonably large firms being held accountable. What's your basis for the "smallest and weakest" claims?
- manigandham 7y agoFines for larger companies are either too small to matter or will be negotiated down. Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. This can be seen by the constant consent popups on every website. Users click yes on the major sites, then deny the rest.
- tsimionescu 7y ago> Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. I feel the opposite may be true. When the law came to pass, I took some time to review my privacy options on Google and Facebook, since they are a big impact for me. On the other hand, when I click on a link on HN to some random news paper, and get presented with a five-step process to start to see my options, I don't usually bother and dismiss it as soon as I can, probably with some 'opt-in' consent. Since I'm not planning on viewing the site again, I consider it a minor annoyance.
- deleted 7y ago[deleted]
- barry-cotter 7y agoThe GPDR is a large compliance burden. The bigger your company is the less this hurts you because it’s very approximately a fixed cost. So the GPDR kneecaps small companies while being a painful but bearable expense for large ones. On net it helps the internet giants by reducing competition.
- jacobolus 7y ago
- sleepyhead 7y agoThat’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/ http://www.enforcementtracker.com/
- twblalock 7y agoThey paid the fines, but and what changed? Are users any better off now because those companies got fined? Did those companies stop collecting user data? Has online privacy improved because of those fines? Nope!
- asdfasgasdgasdg 7y agoI think there's an argument to be made that GDPR had some effects. For example, you can now enable or disable ads personalization on Google at https://adssettings.google.com https://adssettings.google.com. I don't think that was there before GDPR. Google also presumably did explicit opt-in for EU users, since otherwise they'd have already faced some pretty massive fines. It may be that most users consented, but I think the take away from that should be that most users do not consider ads personalization a significant violation of their privacy.
- rndgermandude 7y ago>Are users any better off now because those companies got fined? Yes >Did those companies stop collecting user data? Maybe not google so much, but other companies certainly stopped or collect a lot less. And it's still early, and there is plenty of low hanging fruit for GDPR enforcement to hit. >Has online privacy improved because of those fines? The full effects remain to be seen, but yes, it has improved. Maybe not for you, but for me it certainly has, in particular with German businesses I use. Aside from regulations, it also fueled and still fuels public discussion, especially in the tech space. Where half a decade back everybody would have ignored e.g. GitLab's email informing users and customers that they are going to roll out third party tracking, but this time around the backslash was so swift and hard GitLab went back to the drawing board (goof for them!). On top of that, the EU inspired similar laws around the world including most the (somewhat lenient) California Consumer Privacy Act that comes into effect next year.
- disabled 7y agoDude if you are intelligent enough to run a successful small business, then you are adaptable enough to learn the PII storage requirements of GDPR.
- ossworkerrights 7y agoMuch like a bulk of eu regulation, made by people who have no clue how the real world works. No longer wondering why the uk wants to leave, and why those who stay have to kept in by fear.
- jacquesm 7y agoHow about some examples of the smallest and the weakest that have been hurt?
- 100011 7y ago"A well intentioned" is a complete miss of a description. The bill is doing exactly what intended. It's evident a bigger corp. can pay bills easier than smaller.
- eru 7y ago> Noble in thought, weak in action I might be tempted to agree, but the impact was all too predictable. In general, complying with regulations often has economies of scale.
- rndgermandude 7y ago>hurts the smallest and weakest No, fuck small companies playing fast and loose with other people's data. The smallest and weakest is not the small company or website operator, but the individual consumer, aka me and you. Complaining that your small startup cannot collect and sell data nillywilly is like complaining that you can cannot run a startup from your garage that sells homemade miracle cancer vaccines you have vicariously tested, but only on stray cats in your neighborhood. On top of that, the actual big fines so far for the most part targeted big and/or well-established and/or serial abusers. The small companies only have been "inconvenienced" in so far that they now have to think about what data to collect, about how to collect it and how to get consent, about whom to share it with and about how to store it reasonably secure. Something they should have done in the first place.
- Angostura 7y agoNo. They weren't GDPR was meant to get conpanies to take the user security and data ownership seriously and change their ways. Unless you are being egregious, you will get a warning and guidance and hit with fines if you continue being stupid. As is sensible.
- balfirevic 7y agoFun fact: in my country (Croatia), police officials cite GDPR as a reason they consider recording police officers in public illegal.
- lonelappde 7y agoMotivated reasoning can invent an excuse for anything.
- ossworkerrights 7y agoFun fact: in east eu laws are bent to protect criminals, as they are essentially those in “power”. In Romania GDPR was used as means to threaten investigative journalists (see Rise Project and GDPR). There are other criminally bent laws that predate gdpr. For instance the government used some obscure privacy “concerns” mandated by the eu (not sure which) to remove ALL traffic monitoring cameras. The result is one of the highest road deaths in the EU and naturally easier to bribe traffic police. Organised crime members are also protected by bogus human rights interpretations, where a mobster gets more rights than and old lady stealing an egg for food.
- Thiez 7y agoThe GDPR doesn't cover processing of personal data "by a natural person in the course of a purely personal or household activity". So I imagine that at least some instances of recording police officers in public are exempt, especially if you don't follow them around or upload the videos to your local police recordings online community. Of course I also wouldn't argue with the people with the batons.
- lidHanteyk 7y agoDon't worry, CCPA is on the way, and the Bay-dle will rock.
- detail-oriented 7y agoThe only companies worth fining are rich as F, unless you plan to take 10% of market cap they won't care. The other companies will just go bankrupt, which might be desirable.
- twobat 7y agoGDPR as applied is a joke. At one of the places I work they keep talking about "we can't backup this data anymore because it has personal info".
- tsimionescu 7y agoThat's not enforcement, that's misreading...
- akvadrako 7y agoNot really - you need a way to scrub user data on demand from backups and they should also have limited duration.
- matthewmacleod 7y agoYou do not require a way to “scrub user data on demand from backups”. This is just untrue; please don’t spread it.
- akvadrako 7y agoWhat are you talking about? Part of GDPR is deleting personal data on demand.
- matthewmacleod 7y agoYou have misunderstood the requirements of the GDPR. CNIL, for example, has made it explicitly clear that so long as an effective retention policy is in place then PII does not need to be removed from backups on demand.
- akvadrako 7y agoIf by that you mean backups need to be deleted after a certain period then it's effectively the same thing.
- mgliwka 7y agohttps://www.reuters.com/article/us-austrian-post-fine/data-privacy-fine-to-hit-austrian-posts-2019-profit-idUSKBN1X81R7 https://www.reuters.com/article/us-austrian-post-fine/data-p... Austrian Post sold voter preference data without having the right processes in place and was fined 10% of last years profits. Noyb.eu is also an interesting organization to watch. They are a non profit taking lawsuits against large incumbents with egregious privacy practices with the backing of the GDPR. They triggered the 50 million € Google fine.
- blub 7y agoDeutsche Wohnen, the much criticized apartment rental company from Berlin just got smacked with a fine of 14 Million EUR for collecting credit rating data after being warned several times.
- pbreit 7y agoHas any web site been fined for not displaying the cookie notice?
- tirpen 7y agoOf course not. There is no law requiring cookie notice popups, there never was.
- fyfy18 7y agoThat's not true. It is law in the EU and companies have been fined: https://www.cookielaw.org/blog/2014/2/5/spanish-cookie-law-fines/ https://www.cookielaw.org/blog/2014/2/5/spanish-cookie-law-f...
- matthewmacleod 7y agoIt is exactly true. Companies have been fined for not complying with law. Law does not require a “warning” of the sort being discussed.
- akvadrako 7y agoThere was before gpdr. I think it’s obsolete now.
- tirpen 7y agoNo, storing cookies needed to make your site work was always needed. Sending tracking information to third parties required a notice of some kind, no matter if it was in the form of cookies or some other mechanism. So, no there was never a EU cookie law, it was just a major FUD operation and a lot of people put up completely unneccessary cookie consent popups without understanding why.
- schpaencoder 7y agoIt’s enough that your site respect the cookie settings of the browser, which they all do as far as I know. So the warnings are not needed.
- tjoff 7y agoIt's the starting point we needed. Every time some company tries to get away with being unreasonable (see gitlab and ubiquiti from just last weeks) GDPR is one aspect that is quickly brought up. One they can not ignore as easily. The privacy options we suddenly ot from large companies from companies such as facebook were unheard of before GDPR. It have already drastically changed how the world handles data, but it is a slow process. It will take decades and more work. Massive success all in all, thanks to GDPR there is now hope for the future.
- tannhaeuser 7y agoThe effect that GDPR has as far as I'm concerned as a user is that many or even most sites accessed from EU come with a prominent banner warning about PII data collection for targetted ads, including a large portion of sites linked from HN. Maybe this isn't noticed on the other side of the pond, but it has a very profound effect on my usage, as I'm immediately turned away from such sites. OTOH, platform sites without ads such as github, where you supposedly already have agreed to their ToS, and where data isn't being used for ads (for the time being) don't suffer from this effect, yet.
- thrower123 7y agoAll that I have seen is that now there is one more popup window obscuring the content I'm trying to view, which is especially egregious on mobile. At this point, I might see one or two lines of text for a news article on initial load between their gommy sticky header, a couple of ads, and their "We're using cookies here, if you don't like it, go screw" popup. Of course that's assuming it's not paywalled. The net effect of the GDPR, from my perspective as a user, has been to make the internet even shittier to use. There's also the developer side that I have to deal with, but to be honest, after an initial flurry a year or so ago, nobody even asks about whether the software we provide is GDPR compliant anymore.
- TazeTSchnitzel 7y agoI am still convinced fines will, but big investigations take a long time. There's an ongoing case about Google's real-time ad auctions for example.
- blub 7y agoThe data protection commissioners have their work cut out for them for the next decade. It's just that the current privacy abuses of software companies are so complex and egregious that it takes a long time to sort things out. Essentially every US company was doing things wrong for example. Just the other day I was reading LinkedIn's cookie notice which can be paraphrased as "accept our tracking commoner". And this is a bug company owned by MS, the new heroes of open source (and spyware). It's the wild wild west out there.
- joaodlf 7y agoIt might not have "rocked" the data privacy world, but it is having an impact on how businesses operate. A lot of businesses (big and small) were getting too cozy with collected data. With little regard to what was being collected and how long it was stored for. GDPR forced businesses to take a hard look at their data and ask some difficult questions, and I genuinely believe it has changed the way people look at data. Personally, I was professionally shocked to find how some businesses dealt with data - If anything, GDPR forced common sense down some technologically inept management teams.
- piokoch 7y agoYeah, they were meant. Yet wherever I go on the web I am being asked to opt-out from tracking since default I am opted-in - this is clear violation of GDPR, however is seems nobody is trying to enforce this. Opt-out is typically covered by a ton of shady UI patterns, so it is hard to do this. Another clear violation of GDPR is punishing those who does not agree for tracking by serving them crippled content or no content at all. And just to make it clear: I am strongly against extraterritorial laws like GDPR or FATCA. US does not have any rights to enforce their regulations outside US, similarly EU does not have any rights to tell people outside EU how their websites should look like. This is clear abuse of the economic and military power that US/EU have. GDPR has some good points (like PII data storage rules), however some of its regulations, like the once that force open forums to provide "right to be forgotten" for posts, are pure crap. The unfortunate vagueness of this regulation does not help either - real live example from Poland: if school teacher takes home pupils copybooks, which are signed with a pupil first and last name, does this mean that GDPR rules apply to the teacher (getting consents, proper handling and storage for copybooks, etc.)? Some lawyers claim they does not, some say they does, some have no idea. As a result in some schools pupils are forbidden to sign anything that enters the school building with a full name... Overreaction? Probably. But you never know when some mean parent would want to use GDPR against the school.
- blub 7y agoHave you considered that almost everyone was abusing your privacy before and it takes a long time to sort things out? At least now you know you're dealing with assholes. I don't see why your example from Poland is bad. Teachers are now thinking about the privacy of their pupils - this is mandatory in today's world.
- Tomte 7y ago> if school teacher takes home pupils copybooks, which are signed with a pupil first and last name, does this mean that GDPR rules apply to the teacher I don't see how you could possibly claim that this is a kind of automated processing or a structured filing system. So it's another example of fear without knowing the basic principles of the GDPR.
- randomcarbloke 7y agoit was never about principles or good intentions it was always a tax because the various governments felt they had missed the boat on making money from their subject's data.