5 ms·
> A flat minimum, say 5,000€ per violation, no matter how small the company It's hard to imagine a practice more hostile to starting and operating a business t
by throwmeaway820 8mo ago
> A flat minimum, say 5,000€ per violation, no matter how small the company
It's hard to imagine a practice more hostile to starting and operating a business than such a policy
- deleted 8mo ago[deleted]
- mattjhall 8mo agoIf you open a business you should be responsible enough to comply with the laws. A business that became large enough where this would become a time sink would be able to afford to hire someone.
- jbverschoor 8mo agoAnd why not make the fines 0.1% - 1% of a venture's revenue? Because that's what you're talking about.
- tpxl 8mo agoWhy not make it 4%? Because the highest fine per GDPR is 4% of global revenue or 20 mil, whichever is higher.
- y42 8mo agocan you explain why? I mean a company ignoring common and simple rules of law... why you want to "protect" that?
- raverbashing 8mo agoYou really think mom & pop business that have limited IT skills have 5k laying around for some minor violation like not deleting an older email?
- troupo 8mo agoThey will not get that fine for a looooooooong time
- latexr 8mo agoMom and pop businesses with limited IT skills are not collecting emails and private information. At worst they’d be using some external service (e.g. Mailchimp) which does it for them, and those have an obligation to be familiar with the law.
- throwmeaway820 8mo ago> Mom and pop businesses with limited IT skills are not collecting emails They absolutely are!
- mmh0000 8mo agoThe GDPR really isn't that hard to follow, for a "mom & pop" business, it really comes down to: * Limit data retention — Don't keep personal data longer than necessary * Honor data subject rights — Allow individuals to access, correct, delete, or port their personal data Simply, don't collect personal information if you don't need it. If you do need it, add a delete button.
- matkoniecz 8mo ago" simple rules of law..." - sadly, EU regulations in their totality are far from simple
- Ylpertnodi 8mo agoWhich ones? I've had no problems - especially with gdpr.
- worksonmine 8mo agoPlease elaborate, what's so complicated about it?
- goshcoding 8mo agoHow is a fine for mishandling personal information "hostile" to business? A true Hacker News and YCombinator moment.
- michaelsshaw 8mo agoNot allowing reckless disregard for the rights of people = literally fascism.
- testing22321 8mo agoIt gets in the way of ever increasing profit. The most important thing ever.
- nilslindemann 8mo agoYes, especially as the company could just implement a button "Delete your data" on their website. An automated task initiated by the user. No work for them. Companies could also make clear before any registration, on one page, which data they will ask for and later collect. If they were honest. Then the user had a chance to opt out _before_ they have given any data to them. Well, they are not honest, because what do they do instead? Page 1: "Please, your E-Mail". Page 2: "We also need your phone number (we may call you)". Page 3: "Great, nearly done. Now please, your address, your credit card, a fingerprint copy and a picture of your penis". I am in favor of appending a zero to those 5.000 Euros.
- Ylpertnodi 8mo agoTil there are a lot of penis pictures on the internet. A gdpr goldmine!
- Apreche 8mo agoIf compliance is so difficult for a business that they will fail if the law is enforced, good.
- petcat 8mo agoCalifornia has the exact same penalty structure in the CCPA: > (b) A business shall be in violation of this title if it fails to cure any alleged violation within 30 days after being notified of alleged noncompliance. Any business, service provider, or other person that violates this title shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation, which shall be assessed and recovered in a civil action brought in the name of the people of the State of California by the Attorney General. The civil penalties provided for in this section shall be exclusively assessed and recovered in a civil action brought in the name of the people of the State of California by the Attorney General. $7,500 per intentional violation, $2,500 per unintentional. [1] https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB1121 https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
- patja 8mo agoBut the California law only applies if your business has more than $25m revenue or does a lot of selling of PII. See SEC. 9. Section 1798.140 in the page linked.
- petcat 8mo ago> [receives] the personal information of 50,000 or more consumers, households, or devices. That's a trivially small bar to clear in order to be regulated under the CCPA where large-scale data harvesting is the focus.
- patja 8mo agoThere is more to that clause: Alone or in combination, annually buys, receives for the business’s commercial purposes, sells, or shares for commercial purposes, alone or in combination, the personal information of 50,000 or more consumers, households, or devices. So it only applies if you are buying or selling or sharing PII. Not if you just have 50,000 users/visitors to your website and keep it all private.
- WheatMillington 8mo agoAll you have to do is respect the law and respect your customers. Absolutely the most basic thing we can ask of a new business.
- 7bit 8mo agoThe issue lies somewhere in between. I agree that businesses who unlawfully sell your data or do not implement a minimum of security measures should be punished hard. I also agree that a flat 5000 € is problematic. Not because I believe that breaking the law shouldn't be punished. It's because you also get punished if you protect the data and respect your customers, but you don't document the thousand things you must document as a small business. I don't know if you ever looked at GDPR, but that does not distinguish between a company with five employees and 50,000 employees. The company with 5 employees must exactly (!!!) implement the same audit trail and processes that the 50,000 employee company has to do. Or worse, there's literally no difference between you founding a company and Facebook. This shit gets extremely overwhelming extremely fast and that's just killing small businesses.
- latexr 8mo agoAs someone with experience with it, I heartedly disagree. It’s not that hard to not invade user privacy. You have to go out of your way to be invasive, just respect your users and collect as little data possible. That’s truly the way to go and reduces your liability in a multitude of ways, including protecting you of data breaches (if you don’t keep the data, there’s nothing to steal).
- ivan_gammel 8mo agoPrivacy by design is easy. If you are incapable of dealing with GDPR, don’t start a company, because you lack survival skills amyway.