4 ms·
GDPR was supported by the biggest EU corporations as well - not much could help them more :-)
by TomMarius 6y ago
GDPR was supported by the biggest EU corporations as well - not much could help them more :-)
- dijit 6y agoThe idea the GDPR as a regulation helps established companies 'who can afford a gdpr team' more than joe the shoemaker is a weird meme.. GDPR hurts large companies that abuse data; the actual legislature is one of the most proportional regulations I've ever seen. You have the right to store peoples personal data if it's used and not processed for non-implied purposes (IE; generating profiles of people after sale) and not sold to another company. So when someone throws up a big "GDPR NOTICE" and you have to press the big "i agree" button, it behooves to read it; because that's often not required for the service, it's what's required for the company to sell on your data. Joe the Shoemaker can take your email address or phone number and call you, he's not going to have a hard time under GDPR. If you're abusing data, you're going to have a hard time- and that's good.
- TomMarius 6y agoMost companies don't (and never did nor are or were in position to) abuse data, but all companies now must adhere to GDPR. ;-) The world really isn't either Facebook or Joe the Shoemaker. There's a lot in between.
- dijit 6y agoSure, but after dragging the lawyers in and figuring out how we were impacted; (hint: we were barely impacted other than allowing people to download their data which was trivial) I am now truly skeptical of anyone who says that GDPR is a barrier to entry. Unless the "entry" is doing something nefarious.
- horsawlarway 6y agoI think this is pretty case specific I worked at a small company that made software to allow behavioral therapists to collect and analyze data about patients and visualize it more easily. Helped a lot when the patient was a young student and you're working with parents or guardians, and it replaced a lot of time therapists had previously been spending in Excel (or in some situations, hours with pen and paper). GDPR hit hard. We weren't selling any data at all, but because data was often stored grouped by classroom, or by therapist, or by org/admin, providing an easy way to give a patient a data dump of just their data (rather than the data a clinician was approved to view) was very expensive. I left for other reasons, but the company is still struggling with the added costs, and last I heard was going to be acquired.
- dijit 6y agoEveryone in this comment chain is being downvoted hard, I have no idea why; I can only assume trolls have finally hit the karma threshold for downvoting: To answer your case (and risk downvotes in doing so, gah): I think that the situation your company was in was almost exactly the reason GDPR was conceived, data custodians have an obligation to treat that data with the value it actually has, especially in the medical industry. GDPR was not, actually, invented with google/facebook in mind, it was due to the fact that people were selling data, and _also_ not taking care of it when they had it.. Imagine a world where there was no such thing as, idk, PCI compliance, say.. and while some people were treating card info as something they didn't want or stored very well--- the vast majority of people were instead saving them into text files and passing them around on open windows shares in order to process payments. For a lot of companies, GDPR just exposed their shortcomings, and yes, it's expensive to fix, but the point is that it's unhealthy in the first place, much like destroying the planet will destroy us all; unless there's a financial impact to the company itself, the company will continue to salt the earth without regard for anything. (contrived example, I know).
- horsawlarway 6y agoSure, and in a lot of ways, I agree with you. That said - I think my point still stands. This company wasn't storing data poorly, it was storing data in a format designed for its primary users - Clinicians/Therapists. It was also complying with all current legislation when the system was designed and implemented. (and I say this knowing full well the company had previously reported clinics where we knew of or suspected HIPAA violations) When you're tiny (right around the 250 employee limit, mostly non-engineering) having to re-implement a system that's seen 9 years of development/bugfix/features is prohibitively expensive. At best, you're paused entirely on feature work while you do it, at worst you're re-introducing issues/bugs that have been fixed before and adding new ones. But it's cool, because Google has all that fitbit data now and they totally wouldn't be interested in competing in this space. And we've all seen how effectively this law curbs malicious behavior of these large companies (read: Not at all). So from my end - the result in this case was that a small company that sold no data at all, had no vested interest in marketing, and was previously complying with regulation went out of business. Instead it was eaten by a much larger player in the field that was better positioned to absorb those costs (and which does make money by selling data). I'm hard pressed to see that as win. --- So, all that said - I still think we agree more than we disagree. I'm not really upset GDPR exists. I'm upset that it's been mostly ineffective at curbing real abuses by large players, but that's not a problem with the law - it's a problem with its enforcement. I also find it telling when the large players in the industry are in favor of regulation - It almost always means they expect it to reduce competition.
- theptip 6y agoThere are two factors at play here; both you and the GP are making points that are correct. 1) As you say, "If you're abusing data, you're going to have a hard time- and that's good." Companies that are built on selling your data (e.g. data brokers in the marketing / finance industry) or sharing it without your consent (e.g. Facebook with Cambridge Analytica) will have to stop those practices. GDPR working as designed, win. 2) For business models that are viable under GDPR, then at the margin GDPR is going to prevent small companies from entering the space, to the benefit of larger companies. Your example of Joe the Shoemaker is the trivial case. What if your business has a need to collect PII, banking information, perform Know Your Customer checks, and retain that data for 5 years under the US Banking Secrecy Act? Or collect electronic personal health information? Or submit to any other conflicting regulatory regime? You're missing the fact that lots of businesses have a legitimate need to collect more than just an email, and that other regulations directly conflict (per country) with GDPR. In these cases, adhering to GDPR is more than just slapping a GDPR dialog onto your email submission modal; it might require a significant amount of time talking to expensive lawyers to figure out how to comply with all of the applicable regulations. This is the basic dirty truth about regulation; large companies can typically afford to lobby to make sure the regulation isn't going to ruin them, and then they can afford to implement the regulations even if they are very complex. After implementation, regulation like GDPR becomes a moat. Consider how hard it is to start a company in highly-regulated spaces like finance or healthcare. Though I don't claim that GDPR is as deep a moat as those industries' regulation, it's the same idea. The regulations as a whole can still be net-positive to society, but the risk is that when regulators (and those commenting on regulation) don't understand the real costs of complexity, it's easy to pile on rules that have the opposite effect than intended. Note, a common misconception about Google is that it sells/shares your data; it does not in general do that. Google sells targeted ads, and your data is Google's competitive advantage; Google built Gmail, Android, and a host of other products in order to get data that others cannot; your data is Google's moat. GDPR just talks about sharing your data with other companies; Google is fine under the GDPR. Sure, the death of Privacy Shield might make Google's various international entities less able to share data, but the fundamental business model they follow of collecting first-party data on users is alive and well.
- IanCal 6y ago