4 ms·
Every damn time I warned that it was impossible for small businesses to follow the GDPR I got shouted down. Now it turns out companies with massive legal depart
by scoot_718 6y ago
Every damn time I warned that it was impossible for small businesses to follow the GDPR I got shouted down. Now it turns out companies with massive legal departments can't do it?
GDPR is mental, just block the EU, it's the only way to be sure of compliance and no risk with a law that massive, with penalties that high.
- olliej 6y agoAll you have to do is not track people. It's only hard to follow the gdpr if you are wanting to track people, which is because that is the whole point of the gdpr.
- erik_seaberg 6y agoThat's not all. There is a list of slow and expensive process burdens you have to take on even if you never did anything bad.
- olliej 6y agoThey aren't slow and expensive - they specifically limit the amount of separation you need to do if you're a small business. If you deal with, or store, information about users why shouldn't you be held to reasonable standards for protecting that data? Why should you be allowed to keep that data for however long you want to? Businesses used to run without stalking people, just because it's become the norm doesn't mean that it is required, or even just ethical.
- GordonS 6y agoSmall business owner here. The GDPR does not put any strain on us - I'd love some more detail on what you believe these "slow and expensive process burdens" are? All the GDPR does is hold companies to follow a reasonable standard about PII and consent. We only need something like the GDPR in the first place because so many companies hoover up PII and tracking information without consent, using and selling it as they want, and not even taking sane measures to secure it. If you want to capture and process PII, you should legally have to first gain consent, and you should have to take care to secure it. If you can't comply with that, you're not responsible enough to hold such information.
- erik_seaberg 6y agoI’m talking about a data protection officer bottleneck, keeping records of all processing, impact assessments, and waiting on prior consultation with government. Those are all ongoing costs and schedule risks that hurt even teams that have always complied. “Don’t track people” won’t save you from these.
- GordonS 6y agoThis particular thread was about small businesses, and the things you have listed exist only in large businesses. I would also add that they also existed before the GDPR.
- erik_seaberg 6y agoThere’s an exemption for “a natural person in the course of a purely personal or household activity” but I haven’t see any size cutoffs below which an organization can ignore GDPR process friction. 20M EUR fines are explicitly allowed no matter how low your revenue is.
- benjaminjosephw 6y agoData protection rules might prevent some current advertising and tracking practices from taking place but they are not impossible to implement. The principles are actually quite simple and boil down to "treat other people's data as an asset you hold in trust for them for a specific purpose". That seems to me to be a cornerstone principle for individual liberty in a digital age. I'm surprised so many Americans are against it.
- Shared404 6y agoI believe you may have misinterpreted the article.
- jfk13 6y ago> Now it turns out companies with massive legal departments can't do it? No, it turns out they don't want to.
- GordonS 6y agoYou've got this completely the wrong way around. The problem is not that companies with large legal departments can't follow the law, but rather that some of such companies are pathological choosing to break the law. They think they can get away with it because few breaches are prosecuted, and based on highly dubious legal interpretations concocted by their large legal departments. GDPR is not difficult to follow (or indeed "mental"), and is a huge boon for consumers. In a way it's even a boon for businesses - it can reduce their legal risk by encouraging them to only collect PII when they have a good reason to do so.
- corobo 6y agoIt's pretty damn easy though. Current minimalist method I use is to load all the guff that business depts want in with Google tag manager. Then only load that code when the person accepts third party tracking The problem here is they just don't give a crap. The fine is a cost of doing business. Someone needs to stick some bollocks on the GDPR and start issuing fines in the billions. Big billions.