3 ms·
The reason the fines are low is because they exist to push for compliance, not to punish. That's also why they are increasing up to 4% global revenue. If that's
by _v7gu 5y ago
The reason the fines are low is because they exist to push for compliance, not to punish. That's also why they are increasing up to 4% global revenue. If that's not enough, the maximum can always be increased. More money for the EU countries.
It's really funny how US-oriented thinking made HN go up in arms about how GDPR fines were too excessive to how ineffective they are meanwhile the fine structure didn't change at all.
- Nextgrid 5y ago> they exist to push for compliance, not to punish Well that clearly doesn't seem to be working. > It's really funny how US-oriented thinking made HN go up in arms about how GDPR fines were too excessive to how ineffective they are meanwhile the fine structure didn't change at all. Just FYI I'm UK-based and never had any of these US-centric concerns regarding the GDPR.
- _v7gu 5y agos/US/common law/ The fines are not enough right now, but they'll just keep on increasing until compliance is satisfied. There's no reason to start high and bringing small companies to ruin when everything will work out in the long term
- pgeorgi 5y ago> Well that clearly doesn't seem to be working. Those "privacy score cards" for apps on both iOS and Android, filled out for 1st to 3rd party apps? GDPR in action. The ability to reject tracking (which might cost money for a subscription or something - which will actually be tracking-free, instead of earning on both ends of the market, by selling a subscription _and_ tracking the hell out of their customers)? GDPR in action. There are some dark patterns around the cookie consent popups, but it's up to people to report them, there's no EU privacy police squad digging up these cases on their own. There are only so many hours Max Schrems can spend every day (it's rumored to be 24hs or less, except maybe for one day a year) on running his non-profit to do that for you, me and everybody. That stuff has ramp-up time, and as mentioned, the goal is compliance, not collecting fees. As practices _under GDPR_ are becoming established, and stuff went through court a few times, I'd expect schedules for compliance to shorten. It would be a PR disaster for all things privacy if DPAs were to go all in on some case (taking 4% of global annual revenue), then losing the case in court. Given how many media companies are big in advertising and surveillance tech as well (with media mostly existing to attract eyeballs for their "real" business[0]), there'd be no end to the assault on privacy. Rather take it slow. [0] e.g. https://venturebeat.com/2015/09/29/business-insider-buyer-axel-springer-just-lost-its-case-against-adblock-plus/ https://venturebeat.com/2015/09/29/business-insider-buyer-ax... "Adblock Plus said Axel Springer’s lawyers asserted that “The core business of the plaintiff is to deliver ads to its visitors. Journalistic content is just a vehicle to get readers to view the ads.”"
- Nextgrid 5y ago> Those "privacy score cards" for apps on both iOS and Android The GDPR already requires clear disclosure for data processing. If the "privacy score cards" were due to the GDPR then we should've seen them 3 years ago. The privacy score cards actually demonstrate the lack of enforcement of the GDPR. A private company (Apple) successfully did something in a few months that the regulation couldn't in years. That shows how these potential "4% of global revenue" are really seen and they're not as threatening as they sound. > The ability to reject tracking Where? The vast majority of apps and websites still include Facebook SDK malware and similar, and in the rare cases where they actually do ask for consent there's no easy "decline" option, or the decline option is a sham (as in "disable cookies in your browser so we fall back to browser fingerprinting"). > but it's up to people to report them, there's no EU privacy police squad digging up these cases on their own [...] There are only so many hours Max Schrems can spend every day [...] on running his non-profit to do that for you, me and everybody. This seems like a problem if the effort of investigating breaches is offloaded to laypeople, especially when finding out non-compliant cookie banners can be done automatically with a trivial web scraper. > It would be a PR disaster for all things privacy if DPAs were to go all in on some case (taking 4% of global annual revenue), then losing the case in court. Why is doing nothing considered better then? In either case nobody is complying with the regulation. At least an in-progress court case (that's likely to take years) is going to be a much bigger threat than current situation of nothing.
- pgeorgi 5y ago> A private company (Apple) successfully did something in a few months that the regulation couldn't in years My point was that Apple started that effort only due to GDPR. And given that such work takes a while (the UI might be simple, but the decisions on what to model in the first place and how to represent it, and how to do that so that the same model can ideally be reused when other regions enact their own, slight different regulations, OMG...) the timeline might add up to this happening in direct response to GDPR. > offloaded to laypeople ... offloaded to people with the specialized knowledge. DPAs are filled to the brim with lawyers and similar folks that I wouldn't want to let near a web scraper (or have them do app traffic analysis) > Why is doing nothing considered better then? "nothing" is not what happens. This is a wild mix of technology, legal considerations, politics and PR. https://www.reuters.com/technology/german-privacy-tsar-tells-ministries-shut-facebook-pages-2021-06-29/ https://www.reuters.com/technology/german-privacy-tsar-tells... cites the German federal DPA in a single paragraph: "there is no time to waste" and "I strongly recommend[0] you switch it off by the end of the year." "no time to waste" vs. "half a year" (plus at least 1-2 years in which they already discussed with Facebook how to make their product compliant) is how schedules work in governance, and it's not out of laziness: It's simple to turn a tiny ship but that doesn't say much about the flexibility of a supertanker. The fun thing about the German DPA is that he's actually a computer scientist by training, so yeah, I guess he could run a web scraper. He's using this role (and the authority it offers) somewhat different: His office's social media presence is on a self-run Mastodon install. According to what he wrote (on his personal account he had before already) it took them several months of auditing, writing legalese etc to ensure that they could do that, and that Mastodon can be configured in a fully compliant way. So now there's a show case that a few more offices joined (social.bund.de is open to German federal offices and for state Parliaments), and I seem to remember that they mentioned that the legalese and audit work is available to their clients in case they want to set up their own. "Anybody" can run a web scraper (not necessarily doing a good job, but script kiddies do it all the time), but it takes a DPA to do _that_. I'd rather have his (modestly sized) team work on things that I simply cannot do. [0] It's not a demand but a "strong recommendation", but not because there won't be consequences. I fully expect Kelber to start investigations into this first thing in 2022 but I guess this leaves the recipients of that recommendation the option to find a different way to come into compliance. Unlikely, but not entirely impossible.