back

by sensanaty·3y ago·view on hn ↗
That's the beauty of these types of EU laws though, they require inaction in order to be compliant. Literally just stick to the data you absolutely, vitally need for the running of your app or website or whatever, and you're fine. It's legitimately harder to be non-compliant, since it means you're putting your devs to work to implement some idiotic metric tracking that is ultimately useless.

Also it's not really my experience having worked for a few EU tech companies. The small guys have 0 issues following the regulations, even without a single lawyer working there, since they're usually not so blinded by the prospect of infinite money and usually just stick to collecting what is necessary and nothing more. My company has 1 or 2 lawyers, but they're more there for things wholly unrelated to GDPR or anything like it, and we've never been on the sharp end of the legislation and likely never will be, assuming the suits don't drop 100IQ points and decide to go for "infinite" growth.

1 comments
The amount of inaction you’d need to be guaranteed to comply with the GDPR would be equivalent to never starting a business at all.

Even a cash-only business with no electronics anywhere would still need nontrivial GDPR compliance efforts because it has employees. Just because you need the data to run your business doesn’t automatically make you exempt without further paperwork. Your lawyers definitely do occasional GDPR compliance work.

https://www.dickinson-wright.com/news-alerts/the-gdpr-covers...

It’s a bit like accounting. You can structure your business operations is ways that make the accounting easier or harder, but unless you shut the business down you will always have done enough somewhere to need to think about (and probably file paperwork for) accounting/GDPR. And much like accounting, I’m not saying the GDPR is bad, but it’s also not a business activity that you can just ignore because you’re not running an adtech data vacuum or whatever.

Not in line with what I have seen in terms of required GDPR work in small businesses. Pretty minimal as far as I have observed it.
> The amount of inaction you’d need to be guaranteed to comply with the GDPR would be equivalent to never starting a business at all.

Tell that to GitHub for instance: https://github.blog/2020-12-17-no-cookie-for-you/

I mean you /do/ understand that they're just switching the means collecting data, right? You /do/ understand that Alphabet doesn't need to care about cookie banners and web fonts when they can simply tell their gigantic user base to keep logged in to not see any banner anymore? You /do/ understand that webpages switched to dark UI patterns luring their visitors into "yes to all" clicks taking those as a charter to push them into even more ad networks? You /do/ understand that you will need to consult a lawyer's advice for anything touching PII data to be on the safe side and don't want your small business to potentially going bankrupt? You /do/ understand that this costs additional money that won't go into product development?

Edit: In addition with AI act and its very broad definition of what an AI is and a classification like "Education" you might end up in level "highest risk" just for calculating statistics on your quiz app (no one knows until a court rules). With Cyber Resilience Act and its application of the (physical) supply chain direction, your open source repo from 5 years ago might end up being a footgun with you being personally accountable for other companies using it in their product. And so on...

Cookie banners are only a very small part of the GDPR.
That's true. They are a good start though.

And for a startup it's trivial to comply with GDPR because:

- you start from scratch, so you know not to collect more data than you need

- you don't need that much data to begin with