3 ms·
Being compliant with regulations such as the GDPR is expensive. Lawyers, security, and annual third party testing. I don't profit off EU users so I block all no
by mozman 3y ago
Being compliant with regulations such as the GDPR is expensive. Lawyers, security, and annual third party testing. I don't profit off EU users so I block all non-USA traffic and avoid the issue entirely.
- ahoka 3y agoIt’s like saying complying with criminal law is expensive because lawyers are expensive.
- mozman 3y agoIf you've been responsible for implementing GDPR compliance I think you may have a different perspective.
- hnbad 3y agoIt's like saying complying with truth in advertising laws is expensive: most companies barely have to think about it because they comply by default but for some companies it is extremely expensive. Of course it's extremely expensive for them because they're trying to get as close to breaking the law as they can without actually breaking it. That requires expensive lawyers, constant monitoring and extremely fast response cycles. E.g. there are a lot of big companies making good money of exaggerated but legal health claims and their claims are all not just vetted by a team of expensive lawyers but also documented and tracked in such a way that if they do end up getting sued they can immediately find out where they are using that particular claim and withdraw all advertising material using it to comply with a cease and desist. So, yes, if you want to run a business that is either intended to be willfully negligent for no good reason or exploit users with as little informed consent as you can get away with (likely because what you want to do is not in their best interest), you'll need a team of expensive lawyers. But compared to actual nuclear storage (which is highly regulated for good reasons), or storing certain financial data (which requires PCI compliance), or storing medical records (which in the US requires HIPAA compliance) or filing your taxes correctly, GDPR compliance does not actually require an expensive external audit and certainly not a regular one. Of course SOC2 compliance or ISO compliance are different matters and they may be involved in demonstrating GDPR compliance to business customers but they're neither necessary nor sufficient to comply with the GDPR or the ePrivacy directive.
- hnbad 3y agoWell, you could have had that for cheap: being US-based currently makes you non-compliant by default thanks to your government's warrantless surveillance (look up Privacy Shield and why it died). But, no, none of these things are required to be GDPR compliant. Of course if you want to build a business on processing PII (and especially if it's any of the protected categories, e.g. you want to process personally identifiable medical data) the GDPR requires more effort from you because it's harder to maintain your users' privacy while doing this. And if you actually have no business doing this but still need to find a way to coerce your users into surrendering their data against their own interests (e.g. behavioral analytics, insurance risk scoring, etc), it's even harder to do this in a compliant way and opens you up to more scrutiny (rightfully so, I might add). These things are not required to be compliant. These things may be involved in demonstrating compliance. But the lengths you have to go to to demonstrate compliance is very much a function of how privacy invasive your business is. A nuclear power plant will have more detailed radioactive waste management and radioactive material containment plans than a watch repair shop that occasionally handles radium-coated mechanical parts. Specifically, other companies may insist you go to greater lengths to demonstrate your compliance to them if they want to do business with you, the same way you don't just buy nuclear waste containment equipment from some guy on eBay. I did mean it literally when I said treat PII as radioactive.
- nness 3y agoI do love this argument against GDPR (or any data protection) because it often comes down to "Screw the US consumer, I'm profitable because they have no protections, so no one should have any." ... which is kinda the US business sentiment in general, I suppose.