4 ms·
> You might go and check how many companies did get those 10Mi euro "scary" GDPR fines before panicking again The EU has levied over 2.7 BILLION euros worth of
by fidgewidge 4y ago
> You might go and check how many companies did get those 10Mi euro "scary" GDPR fines before panicking again
The EU has levied over 2.7 BILLION euros worth of GDPR fines in the past 5 years alone, and possibly much more as not all fines are made public. It is distributed over more than 1,500 separate fines. That is a staggering amount of money that went straight into its own treasury based on the enforcement of a very vague law, for example the top category of fine is "Non-compliance with general data processing principles".
More relevant to the CRA, there have been over 375 million EUR worth of fines for "Insufficient technical and organisational measures to ensure information security".
There's background to all this. The EU is incredibly hungry for money which it can then use to expand its own power. Historically it was restrained by the member states refusal to give it more, as they were wary of exactly that outcome. In recent years the Commission has found ways around the treaties to unlock new revenue sources, specifically:
- Megafines that are impossible to avoid. How much money do you think the big tech firms spent on GDPR compliance? A massive effort. All for nothing because the EU can simply declare your efforts "inadequate" in their subjective estimation and please hand over a few hundred million more.
- Issuing debt. This is a plain-as-day treaty violation but the EU does not have the rule of law, so the institutions and member states just ignore it. Dystopically the EU Council website was even updated after they started doing this to remove the references to Commission debt issuance being illegal.
You do not want to hand these people even more ways to tax the software industry, because they will use it regardless of what the written rules appear to say.
- raverbashing 4y agoI am sympathetic to companies caught on a technicality, not to most of the non-compliance cases > How much money do you think the big tech firms spent on GDPR compliance? A lot. They spent more in pretending they were compliant with it though Here's a better idea, don't actually capture data you don't need and it will be very cheap Meanwhile I have little sympathy for those who abuse user data collection
- fidgewidge 4y agoYou'll understand how the game is played one day, I just fear it'll be too late for the EU by then. Here's the trick: "need" is utterly subjective, along with "consent". No matter what definition you think is reasonable and obvious, the EU officials have a billion Euro payoff waiting for them if they just interpret these words differently. There is no amount of money or business changes these firms can ever make that will stop them being fined because using them as piggy banks to evade the treaties is the goal. The EU doesn't give a crap about your privacy and never has, see how keen it is on vaccine passports for just one example of how quickly their rhetoric vanishes the moment it gets in the way of more power.