5 ms·
I work in an large euroepan enterprise and our GDPR compliance is... absymal. And we're not even investing that much into becoming more compliant. My impression
by killtimeatwork 6y ago
I work in an large euroepan enterprise and our GDPR compliance is... absymal. And we're not even investing that much into becoming more compliant. My impression is that the board is in a state of denial, as doing GDPR properly would probably cost us billions.
- throwaway210222 6y agoExactly, once Europe realises that the USA's 2018 Cloud Act makes its *impossible* for every USA registered cloud provider, every Office 365 account, every Google doc, every Gmail account, and every Dropbox account to be GDPR compliant, it will just quietly fade away. A nice idea, but no one will care that much.
- Daho0n 6y agoAll those are "fading away" in every area of enterprise I have seen that deal with private data. When GDPR is causing US states to follow suit and create GDPR-like laws I'd say it is the US's woefully bad privacy laws that are fading the most. Of course I don't believe for a second that it will matter inside the US but that is not the EU's problem.
- throwaway210222 6y agoWith secret FISA courts, the is no way you will ever be able to know. You have no idea who they have approached, nor what they have asked [= insisted] for. And to be clear, because of the CLOUD Act, this reaches all EU citizens on US owned platforms.
- Daho0n 6y agoSadly this is the state of things which is why privacy shield isn't there anymore.
- tubularhells 6y agoBig talks for a throwaway account.
- dependsontheq 6y agoThat my be true - but I work with a lot of companies and they way the legal departments are hunting down problems has changed dramatically. I have customers that are asking "Do we really need this kind of data".
- Freak_NL 6y agoAlso: “Did we do a PIA?” “Is this a data leak and should we contact their privacy officer?” These are common questions now. GDPR changed a lot of things. The basic idea that you'd just send and receive any data you have that seems useful from a technical standpoint to third parties and see what you would actually end up using is gone. Step one is as you say: “do we really need this kind of data?”
- ethbr0 6y agoThis, 100%. GDPR and California et al. turned data privacy from a technical-moral issue into a legal one. And healthy companies have a robust, empowered legal department to keep them on the right side of the law. When Technical Architect says "We shouldn't do this," few listen. When General Counsel says "We can't do this," things change.
- l33tman 6y agoPlease tell us the name of that European enterprise that breaches the GDPR and we can put the EU enforcement procedures to a test :) Let's call it an experiment..
- tubularhells 6y agoYCombinator does business in Europe and doesn't adhere to GDPR on HN, for a start.
- Nextgrid 6y agoGoogle and Facebook's tracking consent flows do not comply with the GDPR. All the mobile apps that implement tracking & analytics SDK do not comply unless they request explicit consent. You can start there. The GDPR's spirit is great but the entities tasked with enforcing it are absolutely incompetent.
- XCSme 6y agoThe thing about enforcing the law is that it's still just politics. You can't suddenly start fining everyone without expecting a backlash. A law only works well when most people are respecting it, not when most people are breaking it.
- Nextgrid 6y agoWhy will there be a backlash? Unlike some other laws where the general public typically contains both winners and losers, when it comes to the GDPR I can't see why the general public would be against it - the law doesn't restrict anything per-se, it just requires data processing to be made transparent to the user and allow them to decline.
- XCSme 6y agoBecause most of the people who actually understand GDPR are the people who have to implement it, business owners. Threre a lot of business and website owners, which might make them the majority of general public in this case. Plus, as a politician you rarely want to upset an entire category od voters, especially a wealthy one.
- username_my1 6y agothere is usually annual report by some law firms talking about the state of GDPR, and so far the EU or states hasn't been keen on charging high fines as the law suggest instead closer to slap on the wrist kind of fines for transgressions that sounds big when you read the law. I think most corps by now realize that and are willing to live with the risk rather than lose a lot of data and introduce a lot of processes.
- himinlomax 6y ago> My impression is that the board is in a state of denial, as doing GDPR properly would probably cost us billions. It may cost some money, but not that much by far. The reality is that in the long term, you'd save some as well by virtue of having clearer, cleaner and simpler processes.
- killtimeatwork 6y ago> virtue of having clearer, cleaner and simpler processes. We are a large bank, most of our processes are decades old and are an impossible mess. For reference, we have a total of around 5000 systems running in the bank... Till GDPR and also some post-2008 regulation, I guess the strategy was to mostly accept the mess we're in (it's basically an absolutely extreme version of technical and organizational debt), with some targeted initiatives to make some areas slightly cleaner. Now, GDPR would require a major redoing of a lot of stuff, most of which is not really redoable - who wants to touch critical code written in COBOL, which is powering the significant parts of economies of a couple of European countries? I suspect most of the world's top20 banks are like that. In this realm, full GDPR compliance (for example, the right to be forgotten, when the data is copied willy-nilly across 5000 apps, with no one knowing exactly where and how the data flows) is a fantasy that could only be enforced by multibillion fines. It's essentially similar problem to global warming - till recently, all of bank's depratments were solving problems locally, but now a new threat (global warming/GDPR legislation) requires global coordination, which is extremely costly given that the bank was basically not designed for it.
- himinlomax 6y agoThere's no reason for a bank to be particularly impacted by GDPR. That makes no sense.
- killtimeatwork 6y agoThe reasons are: 1. Business and IT in big banks are both extremely complex. Business just because of regulations making everything difficult and because the business people have had centuries of time to come up with complicated schemes on how to make money and/or serve customers in a competitive way. IT because paying off tech debt is not something that banks do for the most part. 2. IT in banks is often old and undocumented, making deep modifications very hard and risky. 3. Big banks are parts of the country's (or, in case of biggest banks, world's) critical infrastructure. Hence, they're REALLY risk averse. I.e. if Google Ad words goes down, the the only impact is that people's browsers around the world start running faster without all the ads... If the bank's transactional system goes down (or worse, transfers money where it shouldn't go), then the whole social order is at risk. There are other industries that are similar - are also old, complex and critical - like for example the utilities, but unlike banks they don't make money off of people's private data like the banks do, so they don't transfer customer's details back and forth between their systems - so the GDPR impact is much lesser.