How the GDPR Will Disrupt Google and Facebook(pagefair.com)
pagefair.com
How the GDPR Will Disrupt Google and Facebook
https://pagefair.com/blog/2017/gdpr_risk_to_the_duopoly/
346 comments
While I see some of the concerns about the _technicality_ of the law as completely legitimate, it still bothers me that so many people reject the whole spirit of this law, and cannot put the negative of "tax on startups" against the much greater good of personal privacy.
I've just started a business myself, and this regulation affects my company too. It makes development costlier; it'll take from the precious little time we have to spend on compliance paperwork rather than work on our core business. In the short run, it does hurt our chances of success.
Yet, none of the trouble is even comparable to what's to be gained here. And it bothers me (though doesn't surprise me) that some people don't see that.
It also bothers me that such vocal opposition barely comes up when the discussion is just about bigger companies such as Google and Facebook. How can we expect "un-evilness" from bigger companies when we're barely willing to do anything in that regard ourselves?
I've just started a business myself, and this regulation affects my company too. It makes development costlier; it'll take from the precious little time we have to spend on compliance paperwork rather than work on our core business. In the short run, it does hurt our chances of success.
Yet, none of the trouble is even comparable to what's to be gained here. And it bothers me (though doesn't surprise me) that some people don't see that.
It also bothers me that such vocal opposition barely comes up when the discussion is just about bigger companies such as Google and Facebook. How can we expect "un-evilness" from bigger companies when we're barely willing to do anything in that regard ourselves?
I encourage a little more thought before cheering this on as a win. While GDPR isn't as ridiculous as the Cookie Law, it still shows that the EU/EC don't understand the technology they are trying to regulate, and it comes at a huge cost to tech companies.
Take the right to be forgotten. First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't like the content, but that is what the EU has ruled should happen.
I get the desire to have a company forget about you, and remove all the personal information they have. It makes sense from a personal standpoint. But how do you do it technically?
If you follow GDPR strictly you would need to be able to purge the data from your backups. Now most backups are considered immutable, so you aren't going to do that, meaning you need a way to ensure that "forgotten" users never get restored.
But how do you even delete the live data? Does the tech company you work for have the ability to delete all traces of a user from their system, cleaning severing all relationships with other objects in your system? Do you have the ability to retrieve everything you know about a specific user, and provide it to them? You will need to write the code to do this.
There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.
Do you sell a SaaS service to businesses, and those businesses send you their customer's data? Then you are the processor and they are the controller. Cool, less for you to do, sort of. Except that controller must agree to every sub-processor you use. Want to switch from AWS to GCP? You can only do it if all your customers agree. Want to use try out a new metrics or logging service? If it will have any PII you can't do it without customer (controller) permission.
You will basically need to hire full-time compliance officers to deal with this. The big tech companies already have compliance officers, but GDPR is so massively invasive to businesses that even small companies now need compliance officers.
Take the right to be forgotten. First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't like the content, but that is what the EU has ruled should happen.
I get the desire to have a company forget about you, and remove all the personal information they have. It makes sense from a personal standpoint. But how do you do it technically?
If you follow GDPR strictly you would need to be able to purge the data from your backups. Now most backups are considered immutable, so you aren't going to do that, meaning you need a way to ensure that "forgotten" users never get restored.
But how do you even delete the live data? Does the tech company you work for have the ability to delete all traces of a user from their system, cleaning severing all relationships with other objects in your system? Do you have the ability to retrieve everything you know about a specific user, and provide it to them? You will need to write the code to do this.
There is a good chance your little startup that isn't cash flow positive will have to spend $1 million of its VC money on becoming GDPR compliant.
Do you sell a SaaS service to businesses, and those businesses send you their customer's data? Then you are the processor and they are the controller. Cool, less for you to do, sort of. Except that controller must agree to every sub-processor you use. Want to switch from AWS to GCP? You can only do it if all your customers agree. Want to use try out a new metrics or logging service? If it will have any PII you can't do it without customer (controller) permission.
You will basically need to hire full-time compliance officers to deal with this. The big tech companies already have compliance officers, but GDPR is so massively invasive to businesses that even small companies now need compliance officers.
This has nothing to do with the size of your company/startup and it has nothing to do with regulatory compliance. It is a pretty simple at its core: if your company/startup gets breached and as a result PII data leaked, then you are liable for the penalty according to the general rules. I don't think anybody will argue this is a bad thing. If anything, it will help companies to be a little bit more careful with what sort of data they collect because frankly, at the moment almost every company is perhaps guilty of collecting far too much personal data under the assumption that one day it may become useful. If you collect PII data then you are liable for damages if you happen to mishandle it.
So here is how to avoid the GDPR penalties.
1. Get compliant - it is pretty much ISO27001 and it will cost you money 2. Don't collect excessive PII data and if you do, store it securely - after all it is a very basic ask 3. Avoid collecting PII data at all cost - think of it as another form of PCI
Frankly, there is no need to panic.
So here is how to avoid the GDPR penalties.
1. Get compliant - it is pretty much ISO27001 and it will cost you money 2. Don't collect excessive PII data and if you do, store it securely - after all it is a very basic ask 3. Avoid collecting PII data at all cost - think of it as another form of PCI
Frankly, there is no need to panic.
> The critical question for both businesses is whether users will click “yes”, when asked to consent.
Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's traffic after the first week?
Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's traffic after the first week?
I see this as yet another tax on (European) startups who have to invest even more resources into regulatory compliance.
This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation.
I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society. This includes allowing businesses to use all the data they can get their hands on. People can produce infinitely more data than any google can realistically process.
I cannot understand why people who are otherwise for transparency and against prohibition are celebrating this as a big win against FB/AMZ/GOOG, as those players can easily shell out another $10M here and there to be compliant with this regulatory monster.
This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation.
I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society. This includes allowing businesses to use all the data they can get their hands on. People can produce infinitely more data than any google can realistically process.
I cannot understand why people who are otherwise for transparency and against prohibition are celebrating this as a big win against FB/AMZ/GOOG, as those players can easily shell out another $10M here and there to be compliant with this regulatory monster.
> Nor can they deny access to their services to users who refuse to opt-in to tracking.[1]
Taken literally this means it's illegal to provide a service in exchange for tracking. Can someone elaborate on whether this is true and what else it applies to or what else other business models are made outright illegal?
Taken literally this means it's illegal to provide a service in exchange for tracking. Can someone elaborate on whether this is true and what else it applies to or what else other business models are made outright illegal?
The author believes that users have little incentive to allow Google to provide personalized Google Search results.
I don't think any technical-oriented people in this thread would agree that they have "little incentive" to allow Google Search personalization. When I turn off Google Search personalization, I get inferior search results that are less likely to be what I was searching for.
If you don't want your results personalized, there is an option in the search results to turn personalization off.
The problem I have with this law is that Google will need to default to non-personalized results and then prompt users if they want personalization. Google probably doesn't want to increase UI friction, so they will most likely just disable personalization and not prompt to enable. This will result in less-engaged users and inferior search results for the average EU citizen.
I don't think any technical-oriented people in this thread would agree that they have "little incentive" to allow Google Search personalization. When I turn off Google Search personalization, I get inferior search results that are less likely to be what I was searching for.
If you don't want your results personalized, there is an option in the search results to turn personalization off.
The problem I have with this law is that Google will need to default to non-personalized results and then prompt users if they want personalization. Google probably doesn't want to increase UI friction, so they will most likely just disable personalization and not prompt to enable. This will result in less-engaged users and inferior search results for the average EU citizen.
I'm going to read thoroughly through the terms and conditions and get a case going in European Courts when this comes into play, because you know for a FACT Google and Facebook will put in some vague term to let them collect data for "future" improvement of the service. Watch and see.
In case you are puzzled the same way as me, GDPR stands for General Data Protection Regulation.
Sweet. How to I inform google that I moved to europe (even though I didn't)? VPN tunnel?
We [technology dept at a non-computer business in the UK] got the lecture about this at work. Turns out geeks are fans of this approach!
I've been using "GDPR hazard" as a useful way to kill bad ideas at work. "Sure you can do that! We just need you to confirm that your business unit accepts responsibility for this user-identifying data and ... oh, we can delete it? I'll do that now then."
We have lots of user-identified data, going back years. I can't see it as a bad thing for us to behave properly with regard to it, and to be required to do so.
I've been using "GDPR hazard" as a useful way to kill bad ideas at work. "Sure you can do that! We just need you to confirm that your business unit accepts responsibility for this user-identifying data and ... oh, we can delete it? I'll do that now then."
We have lots of user-identified data, going back years. I can't see it as a bad thing for us to behave properly with regard to it, and to be required to do so.
Google and Facebook will find a way. Problem are small/young startups
So, how long until this one also also gets neutered when European governments realize they can't even bring their own websites into compliance with the new law? ;)
What does the first footnote mean?
> "Nor can they deny access to their services to users who refuse to opt-in to tracking.[1]"
> "[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1. See Recital 42’s reference to “without detriment”, Recital 43’s discussion of “freely given” consent, and Article 7(2) prohibition of conditionality. See also the UK Information Commissioner’s Office’s draft guidance on consent, 31 March 2017, p. 21, which clearly prohibits so-called “tracking walls”."
What, in this regulation, prevents the company from denying users (who opt out) access to a service they provide free of charge or a downgraded experience? And how would a court measure the level of service?
> "Nor can they deny access to their services to users who refuse to opt-in to tracking.[1]"
> "[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1. See Recital 42’s reference to “without detriment”, Recital 43’s discussion of “freely given” consent, and Article 7(2) prohibition of conditionality. See also the UK Information Commissioner’s Office’s draft guidance on consent, 31 March 2017, p. 21, which clearly prohibits so-called “tracking walls”."
What, in this regulation, prevents the company from denying users (who opt out) access to a service they provide free of charge or a downgraded experience? And how would a court measure the level of service?
Would one way "around" this be, "Welcome to ABC Service, it costs X€/month to use, or if you allow us to use your data to sell to our advertisers we will waive this fee."?
How might one make sure their accounts get classified those that fall under the scope of the GDPR regulation? Would it be sufficient to set your location to an EU country?
I have been thinking that the ad bubble is a problem for a while now. Ads are basically to encourage consumption, and the US economy has been debt based for decades now.
Throwaway since I don't want to involve my employer.
I actually work for a platform that is squarely in the GDPR crosshairs (digital marketing). There are a lot of things where our lawyers' perspective is different from what most people say here (I didn't talk directly to lawyers, but I presume product managers did).
- You don't have to comply in 2018, you have to show that you started seriously working on a solution, even if you're not fully prepared. - You don't have to have automated processes for everything (e.g. delete from backups), it's actually perfectly reasonable to say "we'll process your request" and do it manually (ref: startups spending inordinate amounts of effort for GDPR compliance). - Opt-in is not as "game changer" as suggested here, my understanding is that you can do implicit consent (notify the user about what you do, give them a link to take action; crucially, that link might even be the link to your privacy policy which contains the link to the opt-out interface... if I got this right - and I think that I did - this may not amount to much more than a slightly modified "this site uses cookies" thingy). - Delete requests may be handled by "de-identification" (don't delete the data, delete the association with you). - Related to that, while I don't have a definitive answer, I strongly suspect that GDPR only applies to information that can be positively associated with you (e.g. authenticated activity). I'm not obliged to show you anonymous browser activity/information that I've probabilistically associated with you, for the simple reason that I might be wrong and I might disclose sensitive information (think about girlfriend looking up "what does Amazon know about me" and finding up that "she is interested in an engagement ring" because you anonymously browsed from her computer, thus spoiling your surprise even though you were careful to delete your browser history/ browse anonymously. Yes, incognito mode doesn't necessarily help you - we do efforts to identify server-side the incognito sessions and de-link them from the probabilistic marketing profiles, because we don't want to negatively-surprise the customers; but I suspect not all players are that careful).
Overall... despite what many people think, I think big players are actually fairly careful/sensitive about your privacy (well, if we exclude Facebook here :D ). It's the startups that would concern me more... they have very little incentive to guard your data well, because there are so many OTHER reasons why they might fail, that "privacy disaster" is very low on their list of concerns.
I actually work for a platform that is squarely in the GDPR crosshairs (digital marketing). There are a lot of things where our lawyers' perspective is different from what most people say here (I didn't talk directly to lawyers, but I presume product managers did).
- You don't have to comply in 2018, you have to show that you started seriously working on a solution, even if you're not fully prepared. - You don't have to have automated processes for everything (e.g. delete from backups), it's actually perfectly reasonable to say "we'll process your request" and do it manually (ref: startups spending inordinate amounts of effort for GDPR compliance). - Opt-in is not as "game changer" as suggested here, my understanding is that you can do implicit consent (notify the user about what you do, give them a link to take action; crucially, that link might even be the link to your privacy policy which contains the link to the opt-out interface... if I got this right - and I think that I did - this may not amount to much more than a slightly modified "this site uses cookies" thingy). - Delete requests may be handled by "de-identification" (don't delete the data, delete the association with you). - Related to that, while I don't have a definitive answer, I strongly suspect that GDPR only applies to information that can be positively associated with you (e.g. authenticated activity). I'm not obliged to show you anonymous browser activity/information that I've probabilistically associated with you, for the simple reason that I might be wrong and I might disclose sensitive information (think about girlfriend looking up "what does Amazon know about me" and finding up that "she is interested in an engagement ring" because you anonymously browsed from her computer, thus spoiling your surprise even though you were careful to delete your browser history/ browse anonymously. Yes, incognito mode doesn't necessarily help you - we do efforts to identify server-side the incognito sessions and de-link them from the probabilistic marketing profiles, because we don't want to negatively-surprise the customers; but I suspect not all players are that careful).
Overall... despite what many people think, I think big players are actually fairly careful/sensitive about your privacy (well, if we exclude Facebook here :D ). It's the startups that would concern me more... they have very little incentive to guard your data well, because there are so many OTHER reasons why they might fail, that "privacy disaster" is very low on their list of concerns.
Are all companies beholden to this or those with legal entities in Europe.
For instance, can a Chinese company with ZERO legal presence in the EU completely ignore these requirements? The internet has no real borders, after-all.
For instance, can a Chinese company with ZERO legal presence in the EU completely ignore these requirements? The internet has no real borders, after-all.
Just wondering, would an European residing in the US be able to request EU compliance for their data?
So, are ad clicks "personal data" ? That would basically destroy all adtech startups.
My first instinct was to be pretty happy about these laws, which surprised me quite a bit. I generally identify on the libertarian/pro-capitalist side of things and "as a general rule" subscribe to the belief that government regulations are often more problematic than problem solving[0]. So I had to take a moment to analyse why I felt this way.
Here's the problem as I see it: I know all of the things that are collected, how they're collected, what shady practices are used[1] and I'm completely aware that there is no anonymity left on the internet. The old "when the product is free, you're the product" isn't lost on me. In reading this, though, I was still finding myself a little outraged[2]. I look at it this way: if yesterday, we had an web with plain old "dumb advertising" techniques limited in sophistication in the manner of television advertising in the 90s, and today we ended up with this, there would be rioting (in the USA, anyway[3]). This didn't necessarily happen slowly but it happened gradually and quietly. I remember when Facebook announced that it was adding the ability to track you on other sites that you visited while you were logged out -- that was announced and it was met with criticism (briefly, though I quit the platform about a month later in a quiet, personal, revolt).
Here's the thing - if you ask an average non-technical individual if they understand that they're being tracked on the internet, they'll shrug and say "yes". If you dig a little deeper, you'll discover that they haven't the faintest idea how deeply they're being tracked and that they don't even have an analogy in their own lives to equate that tracking to. I couldn't come up with anything to describe the extent of tracking short of extremely lengthy explanations of what's being done and used[4].
And then there's me - I understand I'm being tracked and have basically chosen the head-in-the-sand approach. I use adblock, and a few extensions that supposedly "limit tracking" (doubtful) but I know they're worthless. Here's the thing, though, what choice do we have? And that's where I concluded how I was able to land in favor of some form of regulation on this behavior[5]. It is becoming increasingly impossible to avoid interacting with companies like Google and Facebook[6]. I look at it this way -- a company that becomes a monopoly in such an important industry can exert as much, if not more, control over the citizenry than their own government[7] but without the limitations imposed by democracy.
What should be done? I'm not sure. Self-regulation isn't working. I have zero faith in government crafting any kind of law related to technology that won't be some combination of horribly ineffective, worse than what we have today, utterly breaks something really important, or is used as a means to insert something horrible (watch them try to pop in a line-item around key-escrow). I'm kind of surprised to find myself thinking that approach that looks the best, out of the options, is probably forced-competition through breaking up the companies involved and I hate that idea in principal and in practice -- it's worked just-about as well in the past.
[0] I don't want this to devolve into a flame-war of whether regulating is "good or not", though I fear I may have just stoked that flame, I'm simply providing background for contextual purposes.
[1] I half- admire the creative uses of WebRTC with STUN on what are otherwise regarded as highly reputable major news sites. It's difficult for me to not see that practice as poking a hole in my firewall and I feel no less outrage when I see that happening than I do when a piece of malware does the same thing.
[2] Part of me had forgotten the idea that when GMail was "scanning e-mails for advertising purposes", they were scanning e-mails that were coming inbound from non-GMail users who couldn't have possibly consented to that. I'm sure there's a really good counter argument, but I'd have a hard time not feeling a little violated by that practice if I weren't a GMail user, already.
[3] Probably elsewhere, but my experience is that some European countries' citizens (particularly the UK, where I have the most experience outside of the US) are more tolerant to this sort of thing whereas when I was a child, you'd have seen people gathering in militias the moment the government tried to propose something like Real ID.
[4] I can only speak anecdotally since I had this conversation with family members who are non-technical and after about two hours, had them quite disgusted -- asking how is that legal ... and these are some of the most government-skeptical conservative people you'd ever meet.
[5] And I have zero faith in the US government being able to craft a law that works. Minimally the "they must still offer the service if the user opts out" will be removed, entirely, turning the "agree to be tracked" button into the moral equivalent of the "Cookie Warning" -- something you click because you have to. And philosophically, if we weren't talking about monopolies or near-monopolies here, I'd agree with that approach.
[6] Yes, DuckDuckGo is my default search engine, everywhere. And I've now trained myself to use the shortcut to get to google for the 60-70% of searches that DDG returns unworkable results. I think it's my search patterns, which tend to be very narrow in results, causing Bing/DDG to "broaden" and ignore terms (or when used with parameters, simply yield nothing). My parents (both retired) use DDG and rarely anything else since I switched all of their browsers around (they didn't even realize I had changed it -- they don't think of Google as a company, they think of search as something "the internet just has ..."). They are perfectly happy with it.
[7] Or can work in concert with it. Requirements to hand over Facebook credentials at the border are becoming common. I'm waiting for the day when I say "yeah, I don't use that" and end up back in a little room with an angry looking man asking me a bunch of (the same; slightly rephrased) questions and responding to them with the assumption that I'm lying (personal experience on that one; not fun). I mean, after all, I'm a programmer/live on the internet/et. al., surely I must use Facebook and I'm trying to hide something! /s
Here's the problem as I see it: I know all of the things that are collected, how they're collected, what shady practices are used[1] and I'm completely aware that there is no anonymity left on the internet. The old "when the product is free, you're the product" isn't lost on me. In reading this, though, I was still finding myself a little outraged[2]. I look at it this way: if yesterday, we had an web with plain old "dumb advertising" techniques limited in sophistication in the manner of television advertising in the 90s, and today we ended up with this, there would be rioting (in the USA, anyway[3]). This didn't necessarily happen slowly but it happened gradually and quietly. I remember when Facebook announced that it was adding the ability to track you on other sites that you visited while you were logged out -- that was announced and it was met with criticism (briefly, though I quit the platform about a month later in a quiet, personal, revolt).
Here's the thing - if you ask an average non-technical individual if they understand that they're being tracked on the internet, they'll shrug and say "yes". If you dig a little deeper, you'll discover that they haven't the faintest idea how deeply they're being tracked and that they don't even have an analogy in their own lives to equate that tracking to. I couldn't come up with anything to describe the extent of tracking short of extremely lengthy explanations of what's being done and used[4].
And then there's me - I understand I'm being tracked and have basically chosen the head-in-the-sand approach. I use adblock, and a few extensions that supposedly "limit tracking" (doubtful) but I know they're worthless. Here's the thing, though, what choice do we have? And that's where I concluded how I was able to land in favor of some form of regulation on this behavior[5]. It is becoming increasingly impossible to avoid interacting with companies like Google and Facebook[6]. I look at it this way -- a company that becomes a monopoly in such an important industry can exert as much, if not more, control over the citizenry than their own government[7] but without the limitations imposed by democracy.
What should be done? I'm not sure. Self-regulation isn't working. I have zero faith in government crafting any kind of law related to technology that won't be some combination of horribly ineffective, worse than what we have today, utterly breaks something really important, or is used as a means to insert something horrible (watch them try to pop in a line-item around key-escrow). I'm kind of surprised to find myself thinking that approach that looks the best, out of the options, is probably forced-competition through breaking up the companies involved and I hate that idea in principal and in practice -- it's worked just-about as well in the past.
[0] I don't want this to devolve into a flame-war of whether regulating is "good or not", though I fear I may have just stoked that flame, I'm simply providing background for contextual purposes.
[1] I half- admire the creative uses of WebRTC with STUN on what are otherwise regarded as highly reputable major news sites. It's difficult for me to not see that practice as poking a hole in my firewall and I feel no less outrage when I see that happening than I do when a piece of malware does the same thing.
[2] Part of me had forgotten the idea that when GMail was "scanning e-mails for advertising purposes", they were scanning e-mails that were coming inbound from non-GMail users who couldn't have possibly consented to that. I'm sure there's a really good counter argument, but I'd have a hard time not feeling a little violated by that practice if I weren't a GMail user, already.
[3] Probably elsewhere, but my experience is that some European countries' citizens (particularly the UK, where I have the most experience outside of the US) are more tolerant to this sort of thing whereas when I was a child, you'd have seen people gathering in militias the moment the government tried to propose something like Real ID.
[4] I can only speak anecdotally since I had this conversation with family members who are non-technical and after about two hours, had them quite disgusted -- asking how is that legal ... and these are some of the most government-skeptical conservative people you'd ever meet.
[5] And I have zero faith in the US government being able to craft a law that works. Minimally the "they must still offer the service if the user opts out" will be removed, entirely, turning the "agree to be tracked" button into the moral equivalent of the "Cookie Warning" -- something you click because you have to. And philosophically, if we weren't talking about monopolies or near-monopolies here, I'd agree with that approach.
[6] Yes, DuckDuckGo is my default search engine, everywhere. And I've now trained myself to use the shortcut to get to google for the 60-70% of searches that DDG returns unworkable results. I think it's my search patterns, which tend to be very narrow in results, causing Bing/DDG to "broaden" and ignore terms (or when used with parameters, simply yield nothing). My parents (both retired) use DDG and rarely anything else since I switched all of their browsers around (they didn't even realize I had changed it -- they don't think of Google as a company, they think of search as something "the internet just has ..."). They are perfectly happy with it.
[7] Or can work in concert with it. Requirements to hand over Facebook credentials at the border are becoming common. I'm waiting for the day when I say "yeah, I don't use that" and end up back in a little room with an angry looking man asking me a bunch of (the same; slightly rephrased) questions and responding to them with the assumption that I'm lying (personal experience on that one; not fun). I mean, after all, I'm a programmer/live on the internet/et. al., surely I must use Facebook and I'm trying to hide something! /s
Cool. 88 more pages of functional specs on every project.
Will GDPR allow me to delete my Apple-ID?
Thanks
I need to move to europe.
[deleted]
Site will not render properly with Google Analytics blocked. Web site renders with text on top of text. Grey on black text. Is this some fake site by a Google front intended to give this idea a bad reputation?
Might be easier for small niche companies with no offices in the EU but willing EU customers to ask for payment via a cryptocurrency.
It just seems to me in the long run, more and more laws like this will pop up, and using cryptocurrencies will get easier/ more familiar.
It just seems to me in the long run, more and more laws like this will pop up, and using cryptocurrencies will get easier/ more familiar.
[deleted]
It is pretty simple, only 3 levels (strikes for the fellow Americans):
Strike 1 - Stern warning letter
Strike 2 - 2% of your TOTAL GLOBAL REVENUE
Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher)
And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got axed due to a lawsuit of a single student from Vienna against Facebook. So all you need is a single pissed off German customer you ignored when asking for their data report card and you're fucked.
For startups - GDPR is like Y2K at the time, a GOLDMINE. So much opportunity to sell solutions, from real to snake oil. GDPR compliance is already and will continue to trigger a massive wave of investment.
Enjoy :)