3 ms·
> Don't sell user data left and right, and boom! Your poor small business is in the clear. It’s possible that I just misunderstand the landscape, I suppose. Fo
by JoshuaRogers 4y ago
> Don't sell user data left and right, and boom! Your poor small business is in the clear.
It’s possible that I just misunderstand the landscape, I suppose. For my particular case though I work at a small business in the US that uses AWS cloud services for deployment of our application. One of the dependencies of our tech stack is an industry standard application (it’s ubiquitous in our space and has no accepted alternative in our industry) whose per-instance licenses cost are nearly half my yearly salary. After factoring in a second instance for HA, it’s a full engineer‘s pay. In order to make sure that we have a cloud offering that can be used without any data leaving the EU or talking to a US company, our overhead increases to the point that we’re running with one less engineer than if we could all use the same stack.
We do not collect any PII for longer than is needed to fulfill requests and we have no other revenue stream (no ads or connection to ads) other than customer subscriptions.
So, for my team, the impact of compliance has been painful.
If it turns out that I misunderstand some aspect of compliance here, I’m happy as that is good news for me.
- JoshuaRogers 4y agoOne more thing I would like to add: I generally think that some form of regulation limiting the abuse of personal data was long overdue and I must respect your zeal and vigor. I simply note the cost as I think it is important that we realize that this law (nor any law) is not without undesirable side-effect that should still be considered.
- BlueTemplar 4y agoNow consider how Office 365, Windows, Intel CPUs and Ryzen+ CPUs... have similar issues in the sense that they have more or less likely backdoors for US intelligence agencies. https://news.ycombinator.com/item?id=10458318 https://news.ycombinator.com/item?id=10458318 So, what is a reasonable way to deal with this if you're running a government agency or a company that has something worth spying on / getting remote control of for the USA ?
- dmitriid 4y agoBetween "no, we don't want either US companies or US government to have full unlimited access to any data they want" and "EU requires you to be extremely careful with user data, not siphon it willy-nilly and not transfer it to other jurisdictions just because" I chose option two. The "undesirable side-effects" are being sold as undesirable first and foremost by US companies (and US government!) who assume that everything and everyone belongs to them. Does it suck to be stuck between a rock (GDPR) and a hard place (the US' continuing desire to not care about user privacy)? Yes. What amazes me though is that the only side that gets blamed is GDPR.
- iso1631 4y ago> If it turns out that I misunderstand some aspect of compliance here, I’m happy as that is good news for me. There is a vested interest amongst people that profit from users data to attack the GDPR and similar laws and spread FUD whenever possible. It could be helpful to switch "user data" with "child labour" and see if your perspective changes. The problem you likely have is while you don't exploit child labour, you are responsible for ensuring your supply chain doesn't either, and your supply chain may use the profits from that child labour to subsidise their product to you. A competitor which doesn't use child labour charges more, so you think "the cost of compliance is high", rather than "my profits are being subsidised by child labour"