6 ms·
GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target. Noble i
by probo23 7y ago
GDPR: A well-intentioned EU measure that unfortunately hurts the smallest and weakest and fails to have an impact on the big ones that it should target.
Noble in thought, weak in action
- mooman219 7y agoBeing honest, some of the most egregious handling of PII is by small companies who don't have the resources to understand that it is PII, or how to store it, or how to be in compliance. I don't think it's failing in that case. A small company wouldn't google how to build a bridge then DIY it, but that's what's happening with storing PII. If I had a dollar for every article I read where a doctor's office had records on an un-restricted FTP server...
- McDev 7y agoI work at a lot of startups as a contractor. The disregard for privacy and user data everywhere I go is astounding. They're all in survival mode.
- DaiPlusPlus 7y agoMy experience with startups lately is if it’s a greenfield project that started within the past 3 years then they’ll do everything by the book: sometimes even down to storing email addresses as hashes in the database, requiring a user to login first for the software system - and the company - to know their email address). Older systems which depend on having PII and even financial information as cleartext in the database are the problem - and its essentially technical debt with far-reaching consequences, so no-one will fix a system that uses tenants’ customers’ SSNs as a primary-key (yup).
- baroffoos 7y agoI am aware of a legacy system powering a local business which runs on Rails 1 on a version of debian from 2012 and stores users passwords in plaintext, downcased. I have tried to explain so many times that this system needs to be replaced urgently not for security reasons but because no one actually knows how to use rails 1 anymore.
- dwoozle 7y agoI have a Rails 1 product making $10K a year but I don’t have even the ability to log into the box anymore so if even the tiniest thing falls over that revenue is permanently gone for me.
- baroffoos 7y agoIts funny how we let this all slide when it comes to tech. Imagine if someone said "Food safety regulations only hurt the small businesses, they don't have the resources to wash a cutting board after cutting chicken while McDonalds serves unhealthy but legally safe food"
- Mirioron 7y agoBut that's exactly what happens in the world though. In some poorer countries like China, street vendors are literally using gutter oil to make food. If you want rules to be respected then you must be able to enforce them. Poorer places just can't afford to enforce those rules. If rules aren't enforced equally then people won't follow them, because if they have additional costs that their competition doesn't then they'll likely be outcompeted.
- bjelkeman-again 7y agoBut I don’t think McDev above was talking about a software startup in the poorest part of the world. I have implemented GDPR in a small non profit open source SaaS business. A funded startup should have no issue doing the same.
- Mirioron 7y agoBut I wasn't talking about poorest parts of the world either. China is richer than some EU countries, eg Bulgaria.
- em-bee 7y agothey can and they do enforce it. street vendors are much less common in china than they used to be.
- Jommi 7y agoYes, in now richer cities. But they still thrive in lower gdp cities.
- 7y ago
- beher 7y agoDo you consider it difficult to survive as a startup while protecting the privacy of users?
- Mirioron 7y agoYou're right, but they probably can't afford to do it right. And since enforcement on this is lackluster it makes sense for the companies to just ignore it altogether, because if they get caught then it probably doesn't really matter if they took some steps to help privacy or none at all. I think there should be some exceptions to it for small companies based on the impact of the PII. Eg if the company handles email addresses or first names then that should be far less strict than if a company handles medical information, home addresses or credit card information. On the other side, we should have audits in companies to see how the personal data is handled. Particularly in ones that deal with sensitive information.
- phs318u 7y ago> they probably can't afford to do it right Two things occur to me here. 1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. 2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ https://privaon.com/ (first search hit). > here should be some exceptions to it for small companies This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability.
- Mirioron 7y ago>1) it's a cost of doing business. Costs of doing business change over time. Step changes as a result of regulation are typically introduced with windows to allow businesses time to respond. If you can't reasonably cover the cost of the change then...capitalism. You will fail and someone else will succeed. No one is guaranteed a profit. Except that foreign companies won't have this same limitation. The end result is that all of your online services will be provided by foreign companies, which ironically is already the case in the EU. A foreign company that's beyond the jurisdiction of the EU can abuse GDPR as much as they want. If they get caught then they'll just lose their business. The EU can't actually fine them, but that same company likely outcompeted EU companies for years. >This would effectively become a get out of jail for companies that want to outsource their (lack of) privacy with sufficient arms-length plausible deniability. They can do the same thing with foreign companies though. If you can set up a system where you would use your small companies to escape regulation, then the same can be done with companies run by foreigners. >2) Sounds like a business opportunity? GDPR/Privacy as a Service. e.g. https://privaon.com/ https://privaon.com/ (first search hit). And said business opportunity is additional inefficiency on businesses in the EU that their global competitors don't have to follow.
- kevingadd 7y agoJust because they're small and weak doesn't mean bad data policies can't cause harm. If you have 100 customers you're the little guy, but if your 100 customers are political activists in authoritarian states, it's kind of a big deal if you leave a .csv file containing their personal info on your http server, isn't it? In the end whether a penalty is just depends on the significance of the offense and whether the bad actor has reformed. The GDPR does give regulators discretion over whether to issue fines or take legal action, they don't immediately wreck people. People need to remember that while laws are very rigid in drafting, they typically grant a lot of flexibility to the humans that enforce them... and humans often just opt to ignore them. So you can't just look at the law in terms of what it appears to read as, you have to also look at how it's applied in the real world. That can of course mean that a law like the GDPR has unintended negative impact, but it also means that sometimes the impact is not the negative you'd assume from reading it.
- thrower123 7y agoAt the time, everybody who pointed out that this was exactly what was going to happen got flamed hard. I hate that cynicism usually proves the correct stance.
- EdwardDiego 7y agoThe article you're commenting on mentions reasonably large firms being held accountable. What's your basis for the "smallest and weakest" claims?
- manigandham 7y agoFines for larger companies are either too small to matter or will be negotiated down. Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. This can be seen by the constant consent popups on every website. Users click yes on the major sites, then deny the rest.
- tsimionescu 7y ago> Larger companies also have a much easier time gaining consent (like Google and Facebook) that clears their usage while smaller companies struggle. I feel the opposite may be true. When the law came to pass, I took some time to review my privacy options on Google and Facebook, since they are a big impact for me. On the other hand, when I click on a link on HN to some random news paper, and get presented with a five-step process to start to see my options, I don't usually bother and dismiss it as soon as I can, probably with some 'opt-in' consent. Since I'm not planning on viewing the site again, I consider it a minor annoyance.
- deleted 7y ago[deleted]
- barry-cotter 7y agoThe GPDR is a large compliance burden. The bigger your company is the less this hurts you because it’s very approximately a fixed cost. So the GPDR kneecaps small companies while being a painful but bearable expense for large ones. On net it helps the internet giants by reducing competition.
- jacobolus 7y ago
- sleepyhead 7y agoThat’s not true. Google, BA, Marriott and other big companies have got huge fines. http://www.enforcementtracker.com/ http://www.enforcementtracker.com/
- twblalock 7y agoThey paid the fines, but and what changed? Are users any better off now because those companies got fined? Did those companies stop collecting user data? Has online privacy improved because of those fines? Nope!
- asdfasgasdgasdg 7y agoI think there's an argument to be made that GDPR had some effects. For example, you can now enable or disable ads personalization on Google at https://adssettings.google.com https://adssettings.google.com. I don't think that was there before GDPR. Google also presumably did explicit opt-in for EU users, since otherwise they'd have already faced some pretty massive fines. It may be that most users consented, but I think the take away from that should be that most users do not consider ads personalization a significant violation of their privacy.
- rndgermandude 7y ago>Are users any better off now because those companies got fined? Yes >Did those companies stop collecting user data? Maybe not google so much, but other companies certainly stopped or collect a lot less. And it's still early, and there is plenty of low hanging fruit for GDPR enforcement to hit. >Has online privacy improved because of those fines? The full effects remain to be seen, but yes, it has improved. Maybe not for you, but for me it certainly has, in particular with German businesses I use. Aside from regulations, it also fueled and still fuels public discussion, especially in the tech space. Where half a decade back everybody would have ignored e.g. GitLab's email informing users and customers that they are going to roll out third party tracking, but this time around the backslash was so swift and hard GitLab went back to the drawing board (goof for them!). On top of that, the EU inspired similar laws around the world including most the (somewhat lenient) California Consumer Privacy Act that comes into effect next year.
- disabled 7y agoDude if you are intelligent enough to run a successful small business, then you are adaptable enough to learn the PII storage requirements of GDPR.
- ossworkerrights 7y agoMuch like a bulk of eu regulation, made by people who have no clue how the real world works. No longer wondering why the uk wants to leave, and why those who stay have to kept in by fear.
- jacquesm 7y agoHow about some examples of the smallest and the weakest that have been hurt?
- 100011 7y ago"A well intentioned" is a complete miss of a description. The bill is doing exactly what intended. It's evident a bigger corp. can pay bills easier than smaller.
- eru 7y ago> Noble in thought, weak in action I might be tempted to agree, but the impact was all too predictable. In general, complying with regulations often has economies of scale.
- rndgermandude 7y ago>hurts the smallest and weakest No, fuck small companies playing fast and loose with other people's data. The smallest and weakest is not the small company or website operator, but the individual consumer, aka me and you. Complaining that your small startup cannot collect and sell data nillywilly is like complaining that you can cannot run a startup from your garage that sells homemade miracle cancer vaccines you have vicariously tested, but only on stray cats in your neighborhood. On top of that, the actual big fines so far for the most part targeted big and/or well-established and/or serial abusers. The small companies only have been "inconvenienced" in so far that they now have to think about what data to collect, about how to collect it and how to get consent, about whom to share it with and about how to store it reasonably secure. Something they should have done in the first place.