"Most startups will fail": I do not see that happening. You will first receive a warning. The EU won't really care if you are a tiny startup. Unless you are running a shady business, there's not much to worry about.
Hence, the blocking of the EU - its better to block at the beginning and then expand to the EU once we have revenue to support someone handling this as an employee.
You know this is not what would happen, right, that you'd be given advice and the opportunity to towards an amicable resolution?
Uber versus Night School is an example of this. Uber: Ignore taxi regulations, get tons of VC, get rich while being awful people. Night School: try to work with government and play by the rules, fail, get used as a cautionary tale.
Source: https://psmag.com/economics/night-school-failed-because-it-f...
I think something akin to GDPR is necessary and good, but GDPR as written probably isn't it. I look forward to seeing how it works out in practice, and how it develops/is replaced, and in the meantime feel bad for the developers and customers that suffer through the unintended consequences and misfeatures of it.
After the law gets clarified some, I think you're right that it won't be bad for small players. But I wouldn't want to be one of the test cases.
Calling the data protection agencies "government" may be correct in some very legalistic sense, but is utterly wrong under any colloquial meaning of the word.
I know nothing about European legal systems though
And as a member of a EU country that for the last year has been constantly bending (when not breaking) the rules to repress and attack legitimate political reivindications, the relativism in the application of GDPR is something that I find very worrying.
You don't know this.
How many $300kEUR fines (the maximum in Germany until yesterday) served by a German DPA (we have 17: one federal, one per state) have you heard about in the last 5 years?
From April 2015 to March 2017 there were 124 proceedings, with 47 leading to fines.
The aggregate sum of all those 47 fines was... 174.226 Euros.
[1] http://www.dw.com/en/germany-fines-man-208000-for-stealing-c... [2] https://www.thelocal.de/20170405/germany-to-fine-social-medi...
The second one is a law very much like GDPR (notice the little words "up to"?). Not a single fine has been given based on that, not even a small one.
GDPR is the PCI of the privacy world, 99% of companies will be non compliant if audited, but 99% of companies wont be audited. The difference is unlike PCI anyone can launch claims against companies, including for malicious reasons like taking out a competitor, and political reasons like a eurocrat taking a disliking to a particular company.
I've been involved in GDPR efforts at work and all the policies seem fairly straight forward to me. If you're not doing shady shit and you're upfront with your users what you are collecting the data for, how long you keep it and what access policies you have set up.
Not a problem if you ask me.
Enforcement guidelines are ill-defined, and the definition relies on vague terms. For example, is retaining an IP critical to running your business? What if you're getting DDos'd? Now it is up to someone else to make that distinction, and you're dependent on them "being reasonable."
You can even self-report if you're not sure you handled the privacy well, and they will point you the stuff you have to work on (and give you month to do that).
I Understand Americans are afraid of fine and lawsuits, but please don't be afraid. Read GDPR statement from regulatory instances, they are here to help business too.
I think GDPR is short-sighted from a game theory perspective and will short-change European citizens.
When I sold software online, Europe was < 5% of my sales. Why take on business-ending liability risk for that amount of sales? Sure, maybe I'd do these things anyway, but once you open that pandora's box, you're relying on favorable interpretation and the goodwill of regulators.
Having seen what happened in the US with civil asset forfeiture, well-meaning laws can have their purpose bent, and goodwill can be perverted. Why take on that exposure?
Why would you hand of the data of your customers to someone that won't/can't prove to you that they will be in compliance with the current legal requirements?
Honestly that is the entire point of the GDPR, don't misuse customer data and don't hand it over to 3rd. parties unless the customer allows you to.
Good. Outsourcing violations, ethical or legal, shouldn't get you off the hook for them.
Besides which, what are you doing handing off stuff that's important to your business without knowing what's being done with it? Not a recipe for success. And if it's not important, then...
Most large banks and insurance companies are listed.
We had two major expenses: liability insurance for meetings and SOX insurance for the officers. Everything else was in the noise.
Are you just making this stuff up, or has this actually happened?
You didn't (as hundreds of others), so now the EU forces you to. So now you have an opportunity to become a better company: https://medium.com/tsengineering/the-gdpr-blog-post-9a571b13...
I think assuming the EU won't care about tiny startups is irrelevant - I want to follow the letter of the law, it's why I'd opt to block EU users instead of just ignoring the existence of the law.