4 ms·
> What this means in practice is that if you collect any personal data of people in the EU, you are required to comply with the GDPR. In practice almost everyo
by orangeoxidation 5y ago
> What this means in practice is that if you collect any personal data of people in the EU, you are required to comply with the GDPR.
In practice almost everyone in and out of the EU violates the GDPR because it is simply not enforced.
Not because it's impossible to hold foreign companies responsible, but because the authorities aren't even trying (except the very occasional headline grabber).
- remus 5y ago> In practice almost everyone in and out of the EU violates the GDPR because it is simply not enforced. > Not because it's impossible to hold foreign companies responsible, but because the authorities aren't even trying (except the very occasional headline grabber). I think this is a fairly cynical take. I think data privacy as a whole is greatly improved since the introduction of GDPR, and difficult questions are being asked of companies doing dodgy things with personal data (e.g. google, facebook). I have some sympathy for the enforcement authorities who are relatively small organisations trying to enforce large changes across a huge swath of companies. They need to pick their battles, and going after lots of little fish is probably not a great strategy.
- di4na 5y agoKeep in mind too that a lot of company registered to the Irish DPC which is quite... lax. And the rest of the EU enforcement agency and the ECJ are both in a constant fight to close that loophole. Which they are slowly winning. Ramping up regulations take time, but they work on tax schedule. They will win in the end.
- OneTimePetes 5y agoIt should have been standardized, so it can be auto-negotiated. Not these dark patern menues, but a popup screen: This site overreaches regarding privacy, in addition what you are usually willing to give - it demands: - List Are you willing to give in to the demands: - Just once - Fake my data - Always - Never This could and should have been all you see of GDPR. Maybee technical laws should also enforce a standard for consent interfaces.
- remus 5y agoI assume you're talking about cookie consent notices? If so I agree, but they're a relatively small part of what GDPR does. In my opinion the rights[1] and principles[2] it lays out are much more important in giving individuals control over their personal data. [1] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/ https://ico.org.uk/for-organisations/guide-to-data-protectio... [2] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- BizarroLand 5y agoHonestly, this should be handled at the browser level. You select in your browser what cookies and information you are willing to share with companies and they can only take what you give them. Then they can offer incentives to you to justify you giving them more. That would be non-invasive, privacy centered & make the web a better place.
- the_gipsy 5y agohttps://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- Nextgrid 5y agoCompare how many cookie/data processing consent banners are in breach (because the "decline" option - if it even exists - isn't as easy to use as the "accept" option) with the number of fines. Compare the total fine amount for Facebook to its revenue (of which a sizeable chunk is earned by breaching the GDPR).
- the_gipsy 5y agoI am just saying that “no enforcement is happening” is not true. It is true that if the fine is smaller than the revenue (Facebook’s case, probably) then it’s just an entry in the ledger for these companies.
- Nextgrid 5y agoWell my first point is that if you compare the amount of breaches vs the amount of enforcement happening, "no enforcement is happening" becomes true unless you want to be pedantic and count 0.1% as enforcement worth talking about.
- bennyp101 5y agoBut on the plus side, it has made a lot of people think more about what information they hand over, and what is being done with it. So if anything, at least it brought the conversation about personal data to the public and splattered it left right and centre for a while!