back

by Panoramix·8y ago·view on hn ↗
If a company does not understand GDPR it's fair to say I don't want them handling my personal data. And it's not like this is new, there was a 2 year period to prepare for this.

"Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.

3 comments
The problem is not with the spirit of GDPR. I am totally with that. The problem is the liability of it - as a small startup it is seriously scary to think that all it takes is one insane customer to pull the fire alarm and we'd have regulators and fines raining down on us even if we believe with all of our hearts we are doing it right.

Hence, the blocking of the EU - its better to block at the beginning and then expand to the EU once we have revenue to support someone handling this as an employee.

> as a small startup it is seriously scary to think that all it takes is one insane customer to pull the fire alarm and we'd have regulators and fines raining down on us even if we believe with all of our hearts we are doing it right.

You know this is not what would happen, right, that you'd be given advice and the opportunity to towards an amicable resolution?

That's an optimistic view of dealing with government, that they would actually be reasonable and helpful. Many in the US have a decidedly pessimistic view of dealing with regulations and bureaucracy.

Uber versus Night School is an example of this. Uber: Ignore taxi regulations, get tons of VC, get rich while being awful people. Night School: try to work with government and play by the rules, fail, get used as a cautionary tale.

Source: https://psmag.com/economics/night-school-failed-because-it-f...

I think something akin to GDPR is necessary and good, but GDPR as written probably isn't it. I look forward to seeing how it works out in practice, and how it develops/is replaced, and in the meantime feel bad for the developers and customers that suffer through the unintended consequences and misfeatures of it.

After the law gets clarified some, I think you're right that it won't be bad for small players. But I wouldn't want to be one of the test cases.

> That's an optimistic view of dealing with government

Calling the data protection agencies "government" may be correct in some very legalistic sense, but is utterly wrong under any colloquial meaning of the word.

Perhaps in Europe, but "government" has meant "the state" in the US for most of two centuries.
If they’re set up pursuant to legislation and paid for by taxes they’re the government.
Can you point me to where in the GDPR it talks about being given "advice and the opportunity to towards an amicable resolution"? (I'm not being facetious, I'm genuinely curious to read about it, if it exists)
Article 83 in general and specifically Art. 83 (2) state that "the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement" should be taken into account when determining penalties. We'll have to see what this means in practice though.
I wonder if their definition of 'should' is in line with RFC 2119 https://www.ietf.org/rfc/rfc2119.txt

I know nothing about European legal systems though

The GDPR doesn't use "should"; it states that "[w]hen deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to" that factor. Basically, if you can show that they _didn't_ take that into account, or that you tried to cooperate and were stone-walled, you will have good grounds for having the fine overturned.
My understanding is that the measures taken against GDPR infringements will very much depend on the good will of the relevant national authority.

And as a member of a EU country that for the last year has been constantly bending (when not breaking) the rules to repress and attack legitimate political reivindications, the relativism in the application of GDPR is something that I find very worrying.

No, he doesn't know that. And you don't either, although you might believe you do.
>> You know this is not what would happen

You don't know this.

We have 20+ years of dealing with tons of national and regional DPAs following national rules. Now these DPAs play by a single rule book, but other than that, little changes.

How many $300kEUR fines (the maximum in Germany until yesterday) served by a German DPA (we have 17: one federal, one per state) have you heard about in the last 5 years?

I haven't found the statistic about fines levelled by the Hamburg DPA that I read recently, but just found something about the Saxony DPA:

From April 2015 to March 2017 there were 124 proceedings, with 47 leading to fines.

The aggregate sum of all those 47 fines was... 174.226 Euros.

The first one was handed out by a court based on criminal law. This is not comparable to administrative fines. He got fined 260 days of his income (which is the basis on which such fines are assessed). He had two previous, very recent convictions. I'd say this is not a very harsh sentence but your opinion might vary.

The second one is a law very much like GDPR (notice the little words "up to"?). Not a single fine has been given based on that, not even a small one.

The challenge is absolutely not technical, so 2 years makes no difference. The challenge is that GDPR is essentially impossible to comply 100% with, and absolutely impossible to comply without incurring extra costs.

GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, including for malicious reasons like taking out a competitor, and political reasons like a eurocrat taking a disliking to a particular company.

What are these companies doing that makes it so hard to comply?

I've been involved in GDPR efforts at work and all the policies seem fairly straight forward to me. If you're not doing shady shit and you're upfront with your users what you are collecting the data for, how long you keep it and what access policies you have set up.

Not a problem if you ask me.

It includes liability for any and all data handed off or handled by 3rd parties. In other words, google analytics, facebook ads, salesforce customer data, mailchimp, constant contact, that really useful startup. How can you guarantee they are in compliance? If they aren't, you are now liable.

Enforcement guidelines are ill-defined, and the definition relies on vague terms. For example, is retaining an IP critical to running your business? What if you're getting DDos'd? Now it is up to someone else to make that distinction, and you're dependent on them "being reasonable."

And if IP is the only PII you keep and if you destroy IP logs after let's say 6 month and write something about that in your TOS, you're good. And even if you're not, if hey contact you and are not happy with your way of handling data, they will warn you then offer solution.

You can even self-report if you're not sure you handled the privacy well, and they will point you the stuff you have to work on (and give you month to do that).

I Understand Americans are afraid of fine and lawsuits, but please don't be afraid. Read GDPR statement from regulatory instances, they are here to help business too.

> I Understand Americans are afraid of fine and lawsuits, but please don't be afraid.

I think GDPR is short-sighted from a game theory perspective and will short-change European citizens.

When I sold software online, Europe was < 5% of my sales. Why take on business-ending liability risk for that amount of sales? Sure, maybe I'd do these things anyway, but once you open that pandora's box, you're relying on favorable interpretation and the goodwill of regulators.

Having seen what happened in the US with civil asset forfeiture, well-meaning laws can have their purpose bent, and goodwill can be perverted. Why take on that exposure?

>It includes liability for any and all data handed off or handled by 3rd parties.

Why would you hand of the data of your customers to someone that won't/can't prove to you that they will be in compliance with the current legal requirements?

Honestly that is the entire point of the GDPR, don't misuse customer data and don't hand it over to 3rd. parties unless the customer allows you to.

> It includes liability for any and all data handed off or handled by 3rd parties.

Good. Outsourcing violations, ethical or legal, shouldn't get you off the hook for them.

Besides which, what are you doing handing off stuff that's important to your business without knowing what's being done with it? Not a recipe for success. And if it's not important, then...

Take a look at article 82, a DPA and legitimate interest legal basis.
The policies required for PCI compliance are all straightforward too. But enforcing large sets of policies across an organization is a challenge, no matter how simple the actual policies are.
it’s a problem cos the regulation is vague and what you just said is Your interpretation of it... that doesn’t mean it would stand up in court of law...
It's not possible for a financial institution to exist without incurring 'extra costs' for SOX and KYC compliance. And yet they all do. That pesky regulation seems to be useful.
Actually this has been a big problem in the cryptocurrency space. It's entirely too onerous to comply with the rather extreme regulations in the finance space so exchanges had to ignore them for the longest time. Some exchanges even have to move countries because it would be nearly impossible to operate "legally". Yet their services are still needed and if they didn't have this freedom and flexibility then the cryptocurrency space might not have had the tools it needed to grow and innovate.
But isn’t SOX for publicy traded companies only?
Yes, but some of it applies to privately held companies as well.

Most large banks and insurance companies are listed.

Oddly, Sarbanes-Oxley also had implications if you were a 501(c)(3) non-profit.

We had two major expenses: liability insurance for meetings and SOX insurance for the officers. Everything else was in the noise.

> political reasons like a eurocrat taking a disliking to a particular company

Are you just making this stuff up, or has this actually happened?

It's not 2 years though. European countries have had variations of the law for decades. If you ever bothered to comply with those, you'd have had literally decades and very little cost to comply with GDPR.

You didn't (as hundreds of others), so now the EU forces you to. So now you have an opportunity to become a better company: https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...

Not wanting to use non-GDPR compliant services is completely fair. I think it should be the user's choice.

I think assuming the EU won't care about tiny startups is irrelevant - I want to follow the letter of the law, it's why I'd opt to block EU users instead of just ignoring the existence of the law.