4 ms·
Most companies don't (and never did nor are or were in position to) abuse data, but all companies now must adhere to GDPR. ;-) The world really isn't either Fa
by TomMarius 6y ago
Most companies don't (and never did nor are or were in position to) abuse data, but all companies now must adhere to GDPR. ;-)
The world really isn't either Facebook or Joe the Shoemaker. There's a lot in between.
- dijit 6y agoSure, but after dragging the lawyers in and figuring out how we were impacted; (hint: we were barely impacted other than allowing people to download their data which was trivial) I am now truly skeptical of anyone who says that GDPR is a barrier to entry. Unless the "entry" is doing something nefarious.
- horsawlarway 6y agoI think this is pretty case specific I worked at a small company that made software to allow behavioral therapists to collect and analyze data about patients and visualize it more easily. Helped a lot when the patient was a young student and you're working with parents or guardians, and it replaced a lot of time therapists had previously been spending in Excel (or in some situations, hours with pen and paper). GDPR hit hard. We weren't selling any data at all, but because data was often stored grouped by classroom, or by therapist, or by org/admin, providing an easy way to give a patient a data dump of just their data (rather than the data a clinician was approved to view) was very expensive. I left for other reasons, but the company is still struggling with the added costs, and last I heard was going to be acquired.
- dijit 6y agoEveryone in this comment chain is being downvoted hard, I have no idea why; I can only assume trolls have finally hit the karma threshold for downvoting: To answer your case (and risk downvotes in doing so, gah): I think that the situation your company was in was almost exactly the reason GDPR was conceived, data custodians have an obligation to treat that data with the value it actually has, especially in the medical industry. GDPR was not, actually, invented with google/facebook in mind, it was due to the fact that people were selling data, and _also_ not taking care of it when they had it.. Imagine a world where there was no such thing as, idk, PCI compliance, say.. and while some people were treating card info as something they didn't want or stored very well--- the vast majority of people were instead saving them into text files and passing them around on open windows shares in order to process payments. For a lot of companies, GDPR just exposed their shortcomings, and yes, it's expensive to fix, but the point is that it's unhealthy in the first place, much like destroying the planet will destroy us all; unless there's a financial impact to the company itself, the company will continue to salt the earth without regard for anything. (contrived example, I know).
- horsawlarway 6y agoSure, and in a lot of ways, I agree with you. That said - I think my point still stands. This company wasn't storing data poorly, it was storing data in a format designed for its primary users - Clinicians/Therapists. It was also complying with all current legislation when the system was designed and implemented. (and I say this knowing full well the company had previously reported clinics where we knew of or suspected HIPAA violations) When you're tiny (right around the 250 employee limit, mostly non-engineering) having to re-implement a system that's seen 9 years of development/bugfix/features is prohibitively expensive. At best, you're paused entirely on feature work while you do it, at worst you're re-introducing issues/bugs that have been fixed before and adding new ones. But it's cool, because Google has all that fitbit data now and they totally wouldn't be interested in competing in this space. And we've all seen how effectively this law curbs malicious behavior of these large companies (read: Not at all). So from my end - the result in this case was that a small company that sold no data at all, had no vested interest in marketing, and was previously complying with regulation went out of business. Instead it was eaten by a much larger player in the field that was better positioned to absorb those costs (and which does make money by selling data). I'm hard pressed to see that as win. --- So, all that said - I still think we agree more than we disagree. I'm not really upset GDPR exists. I'm upset that it's been mostly ineffective at curbing real abuses by large players, but that's not a problem with the law - it's a problem with its enforcement. I also find it telling when the large players in the industry are in favor of regulation - It almost always means they expect it to reduce competition.