4 ms·
What hasn't worked: Expensive bureaucracy that big incumbents can easily afford to navigate but new entrants would be easily crippled by? Shocked. /s
by jp555 6y ago
What hasn't worked: Expensive bureaucracy that big incumbents can easily afford to navigate but new entrants would be easily crippled by?
Shocked. /s
- cultus 6y agoIt's damn near impossible for very small organizations to follow the GDPR in good faith, especially without a lawyer. The intent is good, but not the execution.
- modo_mario 6y agoWhat bs. There's plenty arguments against it but people act like it's some arcane thick book with legalese written in runes. That's very far from the truth and a quick read-trough the law to identify where it applies to you won't leave many with much if any questions
- derekp7 6y agoA quick read through doesn't necessarily make it easy to follow. For example, Sarbanes Oxley compliance is a huge business, that is fairly expensive for a company to implement correctly. And the compliance requirements of it stems from essentially one paragraph of law.
- blibble 6y agoquick read through the law? it's 72 pages of extremely dense legal text, where meaning of every singe word is important https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- renewiltord 6y agoHonestly, GDPR is fine. I love the power of interoperability it's given me. That part is wonderful. But if what you're saying is so obvious, then GDPR experts should be very cheap. But they aren't. If you're so good at it that it's easy, why don't you just go make your million dollars as a consultant in the next couple of years?
- adrianN 6y agoBeing compliant with GDPR is not that hard if you just take care not to store personal information without explicit consent.
- henriquez 6y agoI don’t know whether you’re naive or flippant, but the reality of transacting on the Internet requires companies to handle their customers’ personal information. “Explicit consent” (and the intricacies of how it can later be revoked) is only part of the voluminous surface area of the regulations. GDPR certainly will have a chilling effect on tech startups. The jury is out on whether it’s a net benefit to society.
- flohofwoe 6y agoI do hope the GDPR has an extremely chilling effect on tech startups that are built around the idea of sucking up as much personal information as possible in order to monetize that data. E.g. "chilling" as in: either go bust or don't get funding in the first place. That's the entire point of GDPR. If you just have a user login, that's quite trivial to implement in a GDPR conforming way.
- hackeraccount 6y agoHow about if you don't save state it's easy to implement the GDPR. My blog is covered but beyond that ...
- drusepth 6y agoThere's a HUGE middle ground between "just having a login" and "sucking up as much personal information as possible in order to monetize that data". Unfortunately, that's where most of the chilling effect will be.
- thu2111 6y agoAs far as I can tell, everyone who supports GDPR knows nothing about it. GDPR is vastly more complex than "if you just have a user login it's easy". To pick just one non-login related problem that has cropped up for me in the past month, a job candidate got upset after a rejection and asked us to "erase him from our database" - probably meaning our recruitment mailing lists. But the recruiters decided this was a GDPR "right to be forgotten" request and proceeded to erase all mention of him from our applicant tracking database. I was then quite confused when he approached me and said he'd been interviewed, because as far as I could tell we'd never talked to him about it. Of course, the whole idea that job candidates can simply make a company "forget" that they interviewed them is absurd to start with but it's the sort of thing that happens due to GDPR. And then there's the perenially enjoyable question of whether backups are now illegal, or to what extent they're illegal. Oh, and please don't give me any lectures about how GDPR doesn't require this. GDPR is such a badly written piece of law that it's impossible to say what it does or doesn't require. Anyone who thinks they know just doesn't understand how the regulation works.
- axegon_ 6y agoActually a lot of large companies are not compliant with GDPR on many levels and while in some cases that's not true, in many it's not necessarily due to malintent. A ton of data is collected by thousands of developers in their products all across the globe and the data is never really cleaned or checked in any way. And in some cases the data that is being collected is so enormous that no one can really answer for certain what goes in there. I know dozens of companies which have thousands of products and each one of them has at least one database behind it. I doubt anyone in the company will be able to tell what a product with 2000 users called Xx developed by two people in Sri Lanka for instance complies to all GDPR guidelines. Frankly most of the people in the company would go "Xx? What's that?". But that product could very well be storing users' location, IP address and so on without their explicit consent in /var/log/debug_connect.log on a server somewhere.
- tree3 6y agoExactly. Reminder that big companies like Google and MSFT helped write GDPR... They wouldn't haven written in terms that could actual affect them