4 ms·
Sorry for being cynical, but from your message it sounds like you were working hard with regulators to comply as little as possible not to get sued. Which makes
by maxcoder4 3y ago
Sorry for being cynical, but from your message it sounds like you were working hard with regulators to comply as little as possible not to get sued. Which makes sense - I mean it was probably just business - but doesn't mean you were not being "your evil selves" (whoever your were).
Maybe I'm underestimating the complexity at scale, but I've read GDPR in original (it's not long), and the intentions and what's required seem pretty clear. I only have practical experience with it from a regulator side, though.
- alsothrowawaydm 3y agoGenuinely not, though I can understand that you're cynical. How do you prove intention anyway? As context with these kind of regulations it's not always bad for the big players when it gets implemented across the market. Many smaller companies will not have the regulatory bandwidth to figure out compliance, and as the regulation acts as a way to level or cap what everyone can do, it's not like you will lose customers to someone else. Complexity was mostly either definitional, e.g. some markets (ironically Germany's big publishers in particular) were absolutely convinced that almost anything they did on their sites fell under legitimate interest, even though we tried to convince them many times that would not fly. Or it would be on specifics such as how many non-essential data providers can you reasonably ask a user to review? Keep the number too small and you'll be accused of favoring the big players, make it too big and you'll swamp users. Who decides? By the way I agree that GDPR is pretty well written. Just that implementing these type of things and getting stakeholders to agree to it can be extremely complex. Fun days