back

by padolsey·8y ago·view on hn ↗
I feel really bad for smaller companies/orgs. I've received countless emails from various businesses I've had interactions with over the years. I've seen the full gamut of messaging -- from "changes in our privacy policy" to "please fill out this entire sign-up form again with your details" to "please send us an email if you wish to unsubscribe". It's obvious that it's entirely unclear to businesses what they should be doing here. So they're all just cargo-culting off each-other, hoping that they're sufficiently covered. I feel bad because I know those who don't have the time, money or knowledge to properly deal with this are going to end up losing their only communication avenue with customers. Customers, too, do not understand the gravity of these new opt-in affirmations.

It seems utterly beholden on our regulators to not only regulate, but to regulate clearly so that the 'reasonable person' has a chance in hell of abiding to-the-letter.

4 comments
> I feel really bad for smaller companies/orgs.

Why? I've seen most places (big and small) adopt a very simple page with one button on it asking if you want to opt in or out. Takes 5 seconds at most.

Too many 'smaller' and larger companies have gotten my details buy buying data from resellers, and then they have the gall to plead with me to let them keep mailing their crap?

I'm happy to opt-in to companies that I like doing business with.

I understand the point about the data resellers, and I agree. But TBH I'm more concerned about the minority of 'good actors' in this space, who have gotten my information the correct way, but now, due to various constraints or ignorances, are left at a great disadvantage and may end up losing a vast chunk of their diligently acquired subscribers.
> I feel really bad for smaller companies/orgs.

Just like everywhere else, the (continuous) addition of regulations favors the larger, entrenched actors who can afford to deal with them. That's always the pernicious effect of too much regulatory load that states should be really aware of.

I don't buy this argument. Those smaller orgs had the choice to not hoover up their user data, in which case GDPR would be a snap.
> It's obvious that it's entirely unclear to businesses what they should be doing here.

What's obvious is that many of them were ignoring the existing DPA and PECR law, and were slurping as much data as they wanted from a variety of sources, and sending marketing email to those contacts.

And now GDPR is coming in a lot of them have realised that they don't have a lawful basis for holding or processing that data, and certainly not for sending marketing to the contacts, and so they're cleaning their databases.

This is a feature, not a bug.

Companies that only held the data they needed; knew why they were holding it; and had correct permissions (if that was needed) are not having much problem with GDPR.

European companies don't appear to be having this problem. This seems more like a case of US companies having no experience with being forced to follow other groups laws if they want money. We've gone off of what, 60-70 years of the US forcing other countries time make it easier for our businesses? The only other time I've seen something similar is when China started enforcing their laws heavily, and many companies just pulled out
> European companies don't appear to be having this problem

Did you miss the articles of EU based small projects shutting down operations? Also, do small web based tech companies even exist in Europe? When I look all I see are medium to large 90s era b2b tech companies.