GDPR After One Year(truthonthemarket.com)
truthonthemarket.com
GDPR After One Year
https://truthonthemarket.com/2019/05/24/gdpr-after-one-year-costs-and-unintended-consequences/
408 comments
"GDPR has been the death knell for small and medium-sized businesses [...] Here is a partial list: [...] Unroll.me, inbox management app"
Don't know for the other companies, but for this one, good riddance, they had a notoriously scummy business model[1].
[1]:https://www.nytimes.com/2017/04/24/technology/personal-data-...
Don't know for the other companies, but for this one, good riddance, they had a notoriously scummy business model[1].
[1]:https://www.nytimes.com/2017/04/24/technology/personal-data-...
Color me surprised, scammy business are losing millions and exiting the EU. I'm totally happy about the outcome.
Though there is still a lot of abuse and dark patterns going on, I believe most of them should make it as easy to "opt all in" as "opt all out" for the cookies for instance.
Though there is still a lot of abuse and dark patterns going on, I believe most of them should make it as easy to "opt all in" as "opt all out" for the cookies for instance.
This all is a reflection of the old talks about the costs of doing technical things right. One way of looking at them is that if something works for business, we should not pursue better software architecture or improve security or usability. Another way is to analyze and estimate the technical debt and eventually start paying it. This is exactly what happens with privacy now: business may cry about "removed incentives", "prohibiting costs", "eliminated opportunities" and other BS, but in the end it's just a compliance debt that they are not willing to pay. GDPR identified that debt and the mechanisms for claiming it, that's it. After the dust settles, there will be plenty of best practices and educated people which will make compliance easy, certain business models unpractical and the business will go as usual. Yes, compliance isn't a piece of cake, but there's nothing written in that law which a sane engineer or manager would not implement. Even the right to be forgotten makes sense: information about past crimes distributed via search is a kind of extrajudicial punishment which makes it much harder for people who already served their sentence to find a job and return to normal life. It's a job of a government to prevent them from committing another crime, it's not a job of a search engine or a news website.
This is a very interesting list, especially the part about the GDPR increasing the attack surface and where the data gravity center is.
The part about "compliance cost" should be taken with a grain of salt. If you were compliant before, because you respected the users‘ privacy, the effort was relatively low.
The study about VC having dropped by 50% in the EU because of the GDPR sounds pretty weird to me. Unless of course there’s selection bias and we’re talking AdTech companies mostly.
An interesting number would be: how many people closed down forums and moved their discussion boards to Facebook?
The part about "compliance cost" should be taken with a grain of salt. If you were compliant before, because you respected the users‘ privacy, the effort was relatively low.
The study about VC having dropped by 50% in the EU because of the GDPR sounds pretty weird to me. Unless of course there’s selection bias and we’re talking AdTech companies mostly.
An interesting number would be: how many people closed down forums and moved their discussion boards to Facebook?
My question is, if you're a US startup, and you simply ignore GDPR requests, what happens?
Does Europe have some way to require its ISP's to firewall you off or blackhole your DNS? Can they force Amazon to shut off your AWS account? Do your executives risk being taken away in handcuffs to a European jail when they go to Europe on vacation?
If there are no consequences, why don't US tech companies just completely ignore it? (Of course, big players like Google probably have EU-based datacenters and other assets that could be seized to pay their fines. I'm thinking of small, cloud-hosted startups whose employees, bank accounts and physical assets are all on US soil.)
Does Europe have some way to require its ISP's to firewall you off or blackhole your DNS? Can they force Amazon to shut off your AWS account? Do your executives risk being taken away in handcuffs to a European jail when they go to Europe on vacation?
If there are no consequences, why don't US tech companies just completely ignore it? (Of course, big players like Google probably have EU-based datacenters and other assets that could be seized to pay their fines. I'm thinking of small, cloud-hosted startups whose employees, bank accounts and physical assets are all on US soil.)
I never understood how anyone thinks being forgotten is a right. Wrong, false, liable, limited set of privacy related information should be correctable, removable. But facts about you and what you’ve done, no. I’m sorry you made embarrassing mistake. But it’s not worth losing so much public information and enabling bad actors to save yourself from your own actions.
It seems like a biased list, but it's good that someone is collecting links about these incidents.
The article vaguely links Cambridge Analytics to GDPR. Is there really a connection or is the article merely trying to frame GDPR negatively by comparing?
Meanwhile, people started to believe that Google reads their mind and society evolved the way they behave as The Internet transforms the consequences for acts such as chatting or posting things in public (or having certain opinions in public)... I think GDPR same as other laws protecting citizens from The Internet failed to protect the user, even if it was a good first try, to begin with. Hope some standardization will come in the future to prevent all cookies or some HTML tag standard or whatever.
I have an interesting question about GDPR and all legal compliance efforts. When GDPR was first announced, I studied it in-depth because I'm the CTO of a company involved in first-party content analytics, and I wanted to ensure we complied.
In addition to making changes internally and technically to ensure compliance, I also prepared a long Google Slide presentation that basically summarized my technical understanding of GDPR, after receiving the advice of several privacy attorneys. The information in this slidedeck was presented to my whole company, as a way to further ensure compliance -- to make sure my employees understood the policy at least as well as I did, since I had spent countless hours discussing the implications of the law -- as well as reading the raw text, which is excellently published/annotated by Algolia here: https://gdpr.algolia.com/gdpr-article-1
My inclination was to publish this deck I had painstakingly prepared publicly, because certainly it would be valuable to others. I publish a lot of stuff publicly on our blog, for example: https://blog.parse.ly/post/author/andrew-montalenti/ -- with the only goal being to share information with the community.
But then, one of my attorneys advised me against this. Basically, the concern was that if I publish something publicly about my understanding of GDPR, and it contains an error of understanding (after all, IANAL), then I could be held accountable for that. That felt really crappy to me -- after all, I'm just doing the best I can, and it seems like there's a lot of misinformation about GDPR out there on the web. Does anyone know anything much about this? To what degree can a company executive get him or herself in trouble for publishing a document that summarizes his or her own understanding of the effect of regulation, if the executive's company is potentially affected by said regulation?
In addition to making changes internally and technically to ensure compliance, I also prepared a long Google Slide presentation that basically summarized my technical understanding of GDPR, after receiving the advice of several privacy attorneys. The information in this slidedeck was presented to my whole company, as a way to further ensure compliance -- to make sure my employees understood the policy at least as well as I did, since I had spent countless hours discussing the implications of the law -- as well as reading the raw text, which is excellently published/annotated by Algolia here: https://gdpr.algolia.com/gdpr-article-1
My inclination was to publish this deck I had painstakingly prepared publicly, because certainly it would be valuable to others. I publish a lot of stuff publicly on our blog, for example: https://blog.parse.ly/post/author/andrew-montalenti/ -- with the only goal being to share information with the community.
But then, one of my attorneys advised me against this. Basically, the concern was that if I publish something publicly about my understanding of GDPR, and it contains an error of understanding (after all, IANAL), then I could be held accountable for that. That felt really crappy to me -- after all, I'm just doing the best I can, and it seems like there's a lot of misinformation about GDPR out there on the web. Does anyone know anything much about this? To what degree can a company executive get him or herself in trouble for publishing a document that summarizes his or her own understanding of the effect of regulation, if the executive's company is potentially affected by said regulation?
Well that's a rather biased account with cherry picked and anecdotical evidence.
The major benefit that GDPR has brought (at least in our company, and I suspect in other companies as well), is an increased emphasis on not storing user data that is not needed. The idea that user data is useful, but it’s also a liability.
This likely will lead to certain private data that companies would otherwise have saved, because why not, not being saved anymore, which would reduce the damage caused by a breach, which will never show up in numbers and stats.
This likely will lead to certain private data that companies would otherwise have saved, because why not, not being saved anymore, which would reduce the damage caused by a breach, which will never show up in numbers and stats.
When GDPR first came out, I found the terms pretty vague. I don't know how I can implement it.
For example, a user's email is Personally Identifiable Information. When the user wants to delete her account, I shall remove her email. This is ease.
But what if in my comment system, another user mentioned her email in a comment. Do I need to remove this comment too? What if this comment has replies too, should I remove all the replies?
What if a competitor make use of these undocumented gray areas to attack my business?
For example, a user's email is Personally Identifiable Information. When the user wants to delete her account, I shall remove her email. This is ease.
But what if in my comment system, another user mentioned her email in a comment. Do I need to remove this comment too? What if this comment has replies too, should I remove all the replies?
What if a competitor make use of these undocumented gray areas to attack my business?
I think we went in the wrong direction in terms of public data. It really isn’t in my best interest as a citizen that our public sector can’t use my data to run more effective, spot health issues sooner or perform city planning based on citizen-mobility rather than educated guesses.
I think it’s absolutely the right direction for private companies though. I know, I know, a lot of you are distrustful of government, but I’m Danish and we generally trust our public sector in to an extend that would truly surprise a lot of you.
So with that out of the way, I think it’s a shame that we spend so much public funding burying public data in silos. I think we should absolutely keep citizen data safe, but I think we should also use it and perhaps work to make some of it less sensitive. Because some of it frankly doesn’t have to be sensitive.
In my country we have a social security number. You get it 1-5 minutes after you’re born, and in the olden days, it was used to identify you when you wanted to do things like open a bank account. It’s still used for that to some extend, but in the meantime we’ve created this thing called NemID (soon to be mitID), which is a national 2-factor secure digital identity, that we use to enter online agreements because it turned out that your social security number wasn’t actually safe. We’ve also had leaks and hacks exposing nearly half of the current social security numbers over the past 25 years.
Because a social security number is deemed sensitive by the GDPR, we’re spending hundred of millions on the bureaucracy around it. It’s by far the most reported thing to our national data protection agency, I think almost 80% of the public cases involve it. And it makes no sense.
Why the hell didn’t we make it illegal to use it as an identifying number instead? It would have saved us so much money.
And that’s just one issue with the GDPR. Another is machine learning and data. This is obviously a sensitive area. I don’t personally think we should troll through citizen cases to try and find possible alcoholics. Maybe someday, but society has to deem it morally acceptable first.
I do think we should use citizen data to schedule shifts though. It makes no sense to me, to have 10 nurses and 15 teachers do full time scheduling in a city of 60,000-100,000 citizens when an algorithm can do it instead. But we can’t, because the GDPR prevents us from using data that way.
I like the GDPR, but I think it needs a revision for the modern public sector, and I think we should really ask ourselves what we want with our data.
Do we want to spend trillions on a bureaucracy guarding it, or do we want to demystify some of it and put it to good use, so we can spend the trillions on nurses, teachers and better infrastructure?
/disclaimer I work in the public sector.
I think it’s absolutely the right direction for private companies though. I know, I know, a lot of you are distrustful of government, but I’m Danish and we generally trust our public sector in to an extend that would truly surprise a lot of you.
So with that out of the way, I think it’s a shame that we spend so much public funding burying public data in silos. I think we should absolutely keep citizen data safe, but I think we should also use it and perhaps work to make some of it less sensitive. Because some of it frankly doesn’t have to be sensitive.
In my country we have a social security number. You get it 1-5 minutes after you’re born, and in the olden days, it was used to identify you when you wanted to do things like open a bank account. It’s still used for that to some extend, but in the meantime we’ve created this thing called NemID (soon to be mitID), which is a national 2-factor secure digital identity, that we use to enter online agreements because it turned out that your social security number wasn’t actually safe. We’ve also had leaks and hacks exposing nearly half of the current social security numbers over the past 25 years.
Because a social security number is deemed sensitive by the GDPR, we’re spending hundred of millions on the bureaucracy around it. It’s by far the most reported thing to our national data protection agency, I think almost 80% of the public cases involve it. And it makes no sense.
Why the hell didn’t we make it illegal to use it as an identifying number instead? It would have saved us so much money.
And that’s just one issue with the GDPR. Another is machine learning and data. This is obviously a sensitive area. I don’t personally think we should troll through citizen cases to try and find possible alcoholics. Maybe someday, but society has to deem it morally acceptable first.
I do think we should use citizen data to schedule shifts though. It makes no sense to me, to have 10 nurses and 15 teachers do full time scheduling in a city of 60,000-100,000 citizens when an algorithm can do it instead. But we can’t, because the GDPR prevents us from using data that way.
I like the GDPR, but I think it needs a revision for the modern public sector, and I think we should really ask ourselves what we want with our data.
Do we want to spend trillions on a bureaucracy guarding it, or do we want to demystify some of it and put it to good use, so we can spend the trillions on nurses, teachers and better infrastructure?
/disclaimer I work in the public sector.
This overlooks one of the biggest under-reported problems GDPR has created: a large percentage of all industrial sensor data is "personal data" under GDPR. These are systems and companies that nobody associates with collecting or using personal data, because their business isn't about people, but the regulations have defined the scope broadly enough that there is universal agreement among their legal experts that are liable for not treating this data as "personal" under GDPR.
This raises some difficult challenges that the average Internet business doesn't have to deal with:
- Compliance with GDPR requirements for personal data in many industrial settings is operationally impossible. These aren't Internet ad tech databases.
- Some industrial systems aren't the kinds of things you can trivially upgrade to make them compliant in any case. We are talking embedded systems with operational lifespans measured in decades. In many cases there are other strict regulatory compliance requirements around the design and modification of these systems.
- The workloads and data models for some high-scale sensor data models make it technically impossible, given the current state of computer science and hardware, to comply with some obligations under GDPR when handling "personal" data. And for a much larger set of systems, it would be economically implausible even though theoretically possible.
- Sensor data infrastructure software often lacks the basic functionality required to support compliance, as the functionality that the regulators assumed exists for other purposes has no purpose in this context and therefore has never been implemented. There is a disconnect between what is required of the software users and what the upstream vendors can or are willing to provide. These aren't software companies.
- For some specific industry sectors, compliance costs disproportionately fall on EU-based companies by virtue of the fact that their primary operations are in a European country, even though they sell into a global market. That's an economic own goal.
This has become a Sword of Damocles over some industrial companies because their legal teams have studied their exposure to GDPR, identified substantial compliance obligations, and realized that compliance is effectively impossible. It is pretty clear to me that the regulators were so focused on Internet advertising companies and similar that they were completely oblivious to the unintended consequences for unrelated industrial sectors.
I've been studying this problem for a few industrial sectors for a couple years now. You have companies scrambling to find technology that often doesn't exist and in some cases requires hardcore computer science R&D before it could exist. And this is a business opportunity for someone to add a tax to what these companies produce. But the worst part is that this extremely expensive compliance exercise does almost nothing for personal privacy because most of this data was being collected for boring industrial applications.
This raises some difficult challenges that the average Internet business doesn't have to deal with:
- Compliance with GDPR requirements for personal data in many industrial settings is operationally impossible. These aren't Internet ad tech databases.
- Some industrial systems aren't the kinds of things you can trivially upgrade to make them compliant in any case. We are talking embedded systems with operational lifespans measured in decades. In many cases there are other strict regulatory compliance requirements around the design and modification of these systems.
- The workloads and data models for some high-scale sensor data models make it technically impossible, given the current state of computer science and hardware, to comply with some obligations under GDPR when handling "personal" data. And for a much larger set of systems, it would be economically implausible even though theoretically possible.
- Sensor data infrastructure software often lacks the basic functionality required to support compliance, as the functionality that the regulators assumed exists for other purposes has no purpose in this context and therefore has never been implemented. There is a disconnect between what is required of the software users and what the upstream vendors can or are willing to provide. These aren't software companies.
- For some specific industry sectors, compliance costs disproportionately fall on EU-based companies by virtue of the fact that their primary operations are in a European country, even though they sell into a global market. That's an economic own goal.
This has become a Sword of Damocles over some industrial companies because their legal teams have studied their exposure to GDPR, identified substantial compliance obligations, and realized that compliance is effectively impossible. It is pretty clear to me that the regulators were so focused on Internet advertising companies and similar that they were completely oblivious to the unintended consequences for unrelated industrial sectors.
I've been studying this problem for a few industrial sectors for a couple years now. You have companies scrambling to find technology that often doesn't exist and in some cases requires hardcore computer science R&D before it could exist. And this is a business opportunity for someone to add a tax to what these companies produce. But the worst part is that this extremely expensive compliance exercise does almost nothing for personal privacy because most of this data was being collected for boring industrial applications.
Listing Klout as a casualty of the GDPR is like listing polio as a casualty of vaccination. Ditto for the vast swamp of ad intermediaries. It shows the legislation working as intended.
I am pretty ok with most of those. However, article 17, the right to be forgotten sounds extremely problematic.
every GDPR request I've seen has been public figures (actors, etc) asking to be forgotten from commercial acts (movies) they were in and no longer like. It's ridiculous.
I am sure I will get downvoted to oblivion, but I think GDPR is a colossal waste of time and money.
I think mandatory do not track settings are great, but the right to be forgotten is to onerous to implement and not present in other domains.
They do make it harder for smaller businesses to compete.
I can't go to my school or a credit bureau or an insurance company and say that all my past history should be forgotten.
Why should we enforce such a regulation online?
I think mandatory do not track settings are great, but the right to be forgotten is to onerous to implement and not present in other domains.
They do make it harder for smaller businesses to compete.
I can't go to my school or a credit bureau or an insurance company and say that all my past history should be forgotten.
Why should we enforce such a regulation online?
Does GDPR mean blockchain based records are illegal? If a user's data is in the blockchain, there is no way to delete it...
>Startups: One study estimated that venture capital invested in EU startups fell by as much as 50 percent due to GDPR implementation. (NBER)
https://www.nber.org/papers/w25248
That is massive. This will just further brain drain even more.
https://www.nber.org/papers/w25248
That is massive. This will just further brain drain even more.
Glad I live in and do business from the US where we don’t have to deal with this wasteful and oppressive law.
Pottery Barn, owned by Williams-Sonoma, is a weird mention. They sell household goods from mall stores and their online catalog. There exposure to GDPR should be pretty minimal. Ship the product and don't sell your customer list and basic security work that they should be doing already.
This seems like a pretty even-handed analysis of the consequences of GDPR. I correctly predicted most of them, and have been highly criticized for it.
It’s truly stunning to me that a community like HN that consists of many current and future startup executives can be so adoring of regulation that has “been the death knell for small and medium-sized businesses“ and for which “compliance costs are astronomical” according to the article. I sense that it is mostly the vocal minority making these comments that ignore the seriously negative consequences of GDPR and paint any company or person that is critical of it as a privacy abuser. I suspect that it is the same small group of abusive users that downvote any comment critical of GDPR into oblivion. Still, it is a very bad look for a community that claims to be so invested in startup culture.
It really is OK to recognize that something with good intent (privacy legislation) can be poorly written and consequently fraught with problems (like GDPR). Any idiot could have predicted that the fine structure they imposed meant potential death for small businesses and a mere speed bump for large ones. GDPR should be torn up and rewritten. The fine structure should be a percentage of revenue, period - not 4% of revenue or €20 million, whichever is higher. That is ludicrous and was designed specifically to drive small businesses out of the market.
It’s truly stunning to me that a community like HN that consists of many current and future startup executives can be so adoring of regulation that has “been the death knell for small and medium-sized businesses“ and for which “compliance costs are astronomical” according to the article. I sense that it is mostly the vocal minority making these comments that ignore the seriously negative consequences of GDPR and paint any company or person that is critical of it as a privacy abuser. I suspect that it is the same small group of abusive users that downvote any comment critical of GDPR into oblivion. Still, it is a very bad look for a community that claims to be so invested in startup culture.
It really is OK to recognize that something with good intent (privacy legislation) can be poorly written and consequently fraught with problems (like GDPR). Any idiot could have predicted that the fine structure they imposed meant potential death for small businesses and a mere speed bump for large ones. GDPR should be torn up and rewritten. The fine structure should be a percentage of revenue, period - not 4% of revenue or €20 million, whichever is higher. That is ludicrous and was designed specifically to drive small businesses out of the market.
[deleted]
Highlighting the cost of privacy is the very point of GDPR. This is the only way companies will stop collecting personal data by default and think very carefully about the consequences of what they keep.
Several specifically pre-GDPR issues are mentioned but still attributed to GDPR.
GDPR is a win for the consumer. Not perfect, but overall a great step forward. But I do think The Right To Be Forgotten is a terrible idea. However, it was NOT introduced with GDPR, and there are several cases prior to GDPR.
Perhaps there are good points to be made. But the article fails to stay sober with the misleading and sensational claims.
GDPR is a win for the consumer. Not perfect, but overall a great step forward. But I do think The Right To Be Forgotten is a terrible idea. However, it was NOT introduced with GDPR, and there are several cases prior to GDPR.
Perhaps there are good points to be made. But the article fails to stay sober with the misleading and sensational claims.
Yes, an economy based on deception that uses it's customers in unknown ways, most of the time in ways entirely unrelated to the product, is failing after appropriate regulation.
All consequences seem entirely acceptable.
Businesses must act with responsibility for society. the regulator is usually lax, until all hell break loose.
All consequences seem entirely acceptable.
Businesses must act with responsibility for society. the regulator is usually lax, until all hell break loose.
> If your account gets hacked, the hacker can use the right of access to get all of your data.
If your account gets hacked, the hacker has access to your account. Duh.
> The right to be forgotten is in conflict with the public’s right to know a bad actor’s history (and many of them are using the right to memory hole their misdeeds).
People can change. Newspapers can exaggerate one's misdeeds.
> And the right to opt-out of data collection creates a free-rider problem where users who opt-in subsidize the privacy of those who opt-out.
Opting out of data collection isn't a thing under the GDPR. Breaking business models that involve people selling their privacy is an intended consequence of the GDPR.
> “Amazon sent 1,700 Alexa voice recordings to the wrong user following data request” (The Verge)
Doesn't sound like a company that can be trusted to ensure people's privacy without regulation.
> “The problem with data portability is that it goes both ways: if you can take your data out of Facebook to other applications, you can do the same thing in the other direction. The question, then, is which entity is likely to have the greater center of gravity with regards to data: Facebook, with its social network, or practically anything else?” (Ben Thompson)
Freedom includes the freedom to make bad decisions.
> “Presumably data portability would be imposed on Facebook’s competitors and potential competitors as well. That would mean all future competing firms would have to slot their products into a Facebook-compatible template. Let’s say that 17 years from now someone has a virtual reality social network innovation: does it have to be “exportable” into Facebook and other competitors?
No more than Facebook has to create a search engine so you can export your search history into Google.
> “About 220,000 name tags will be removed in Vienna by the end of [2018], the city’s housing authority said. Officials fear that they could otherwise be fined up to $23 million, or about $1,150 per name.” (The Washington Post)
The data protection authorities later told them that this is bullshit.
> As of March 20, 2019, 1,129 US news sites are still unavailable in the EU due to GDPR. (Joseph O’Connor)
"Losing" businesses that don't respect privacy is intended. It's kinda flattering that so many US news sites specifically cater to EU residents, making them subject to the GDPR. But frankly: We don't care much about your local news.
> During a Senate hearing, Keith Enright, Google’s chief privacy officer, estimated that the company spent “hundreds of years of human time” to comply with the new privacy rules. (Quartz)
> However, French authorities ultimately decided Google’s compliance efforts were insufficient: “France fines Google nearly $57 million for first major violation of new European privacy regime” (The Washington Post)
The French authorities rightfully didn't care how much time Google spent on not complying with the GDPR.
> Tradeoff between privacy regulations and market competition
Oh no, we might lose the ad market.
> GDPR has been the death knell for small and medium-sized businesses
Companies that cannot safeguard their users' privacy shouldn't exist, not to mention those whose business model is based on infringing on their users' privacy.
---------------------------------------------
The "arguments" ad companies use against the GDPR are just absurd.
EU 2016: We don't want businesses based on violating our citizens' privacy to operate anymore. You have two years two comply.
Ad companies 2018: Evil government! If you force us to stop violating our customers' privacy, we will stop violating our customers' privacy! You will regret this! And why didn't you warn us?
---------------------------------------------
GDPR: You must ask your customers to opt into data collection, letting them opt out is not sufficient.
Ad companies: The evil EU fined us for not complying with the GDPR! That's unfair! How could we know that "letting them opt out is not sufficient" means that letting them opt out is not sufficient? The GDPR is so vague! And we spent so much money on not complying!
If your account gets hacked, the hacker has access to your account. Duh.
> The right to be forgotten is in conflict with the public’s right to know a bad actor’s history (and many of them are using the right to memory hole their misdeeds).
People can change. Newspapers can exaggerate one's misdeeds.
> And the right to opt-out of data collection creates a free-rider problem where users who opt-in subsidize the privacy of those who opt-out.
Opting out of data collection isn't a thing under the GDPR. Breaking business models that involve people selling their privacy is an intended consequence of the GDPR.
> “Amazon sent 1,700 Alexa voice recordings to the wrong user following data request” (The Verge)
Doesn't sound like a company that can be trusted to ensure people's privacy without regulation.
> “The problem with data portability is that it goes both ways: if you can take your data out of Facebook to other applications, you can do the same thing in the other direction. The question, then, is which entity is likely to have the greater center of gravity with regards to data: Facebook, with its social network, or practically anything else?” (Ben Thompson)
Freedom includes the freedom to make bad decisions.
> “Presumably data portability would be imposed on Facebook’s competitors and potential competitors as well. That would mean all future competing firms would have to slot their products into a Facebook-compatible template. Let’s say that 17 years from now someone has a virtual reality social network innovation: does it have to be “exportable” into Facebook and other competitors?
No more than Facebook has to create a search engine so you can export your search history into Google.
> “About 220,000 name tags will be removed in Vienna by the end of [2018], the city’s housing authority said. Officials fear that they could otherwise be fined up to $23 million, or about $1,150 per name.” (The Washington Post)
The data protection authorities later told them that this is bullshit.
> As of March 20, 2019, 1,129 US news sites are still unavailable in the EU due to GDPR. (Joseph O’Connor)
"Losing" businesses that don't respect privacy is intended. It's kinda flattering that so many US news sites specifically cater to EU residents, making them subject to the GDPR. But frankly: We don't care much about your local news.
> During a Senate hearing, Keith Enright, Google’s chief privacy officer, estimated that the company spent “hundreds of years of human time” to comply with the new privacy rules. (Quartz)
> However, French authorities ultimately decided Google’s compliance efforts were insufficient: “France fines Google nearly $57 million for first major violation of new European privacy regime” (The Washington Post)
The French authorities rightfully didn't care how much time Google spent on not complying with the GDPR.
> Tradeoff between privacy regulations and market competition
Oh no, we might lose the ad market.
> GDPR has been the death knell for small and medium-sized businesses
Companies that cannot safeguard their users' privacy shouldn't exist, not to mention those whose business model is based on infringing on their users' privacy.
---------------------------------------------
The "arguments" ad companies use against the GDPR are just absurd.
EU 2016: We don't want businesses based on violating our citizens' privacy to operate anymore. You have two years two comply.
Ad companies 2018: Evil government! If you force us to stop violating our customers' privacy, we will stop violating our customers' privacy! You will regret this! And why didn't you warn us?
---------------------------------------------
GDPR: You must ask your customers to opt into data collection, letting them opt out is not sufficient.
Ad companies: The evil EU fined us for not complying with the GDPR! That's unfair! How could we know that "letting them opt out is not sufficient" means that letting them opt out is not sufficient? The GDPR is so vague! And we spent so much money on not complying!
That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies
Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (Amazon sending data to the wrong person, Spotify not asking for 2FA/email confirmation for the bulk download, companies deleting articles even when there would sufficient public interest, Ad vendors failing to ensure compliance and therefore seeing drops in demand, ...), that is, market failures - something this site would probably not call out but rather attribute it to the legislation.