11 ms·
>If your guestbook is physical and substantial, this may be limiting without additional systems, but GDPR also is rather vague in the pushback you're allowed to
by test525 8y ago
>If your guestbook is physical and substantial, this may be limiting without additional systems, but GDPR also is rather vague in the pushback you're allowed to give if you're completing the export with best intentions, so this will likely not be settled until precedent occurs;
And then you are fined 4% of revenue when you are the scapegoat setting a precedent for a vaguely defined law...
- kazen44 8y agosigh.. the 4% is the maximun fine allowed.. its not a minimum.. this FUD is getting idiotic.
- test525 8y ago>the 4% is the maximun fine allowed.. its not a minimum.. I think it's always safe to assume the worst from bureaucrats. Especially when no sentencing guidelines exist.
- jdietrich 8y ago>I think it's always safe to assume the worst from bureaucrats. No it isn't. As a law-abiding web developer, I have had frequent contact with European data protection authorities for many years. Without exception, they have been thoughtful, reasonable and gone out of their way to help me comply with the regulations. The regulatory authorities exist to ensure compliance, nothing more. They are not a revenue-generating scheme or a Kafkaesque bureaucracy. The GDPR explicitly states that penalties must be proportionate and sets out no fewer than eleven factors that must be considered before any penalty is issued. It also explicitly establishes a mechanism for ensuring that enforcement is consistent across all member states, by means of the European Data Protection Board. The regulations simply do not allow a member state to "go rogue" and start handing out €20m fines for trivial infractions. https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/chapter-7/ https://gdpr-info.eu/chapter-7/
- test525 8y ago> The GDPR explicitly states that penalties must be proportionate Proportionate to what? The max fine is 4% or revenue or $20 million dollars, whichever is larger. So is it proportionate to the $20 million dollar fine? If my infraction was small they can just fine me a small proportionate fine of 1% of the maximum. Why couldn't the EU bureaucrats have stated in clear terms what infractions would receive what fines? Why couldn't they have released a sentencing guideline? And there will be 28 countries applying this law and setting fines in a thousand different ways. > They are not a revenue-generating scheme or a Kafkaesque bureaucracy. This law is absolutely kafkaesque and you can't point to any written case law or section of the law that can concretely dispel my doubts since it does not exist. All you and other posters can do is state that I'm spreading FUD and give me feel good assertions about how I can trust in the benevolent EU bureaucracy and that I should have faith in the system. Can you not understand why I can't take that seriously when millions of dollars and my entire way of life are at stake?
- Macha 8y ago> Why couldn't the EU bureaucrats have stated in clear terms what infractions would receive what fines? Why couldn't they have released a sentencing guideline? And there will be 28 countries applying this law and setting fines in a thousand different "So, using customer email addresses for marketing lists and not infringing any other way is a worth a 0.1% of revenue fine but our analysts project a 0.5% increase in revenue from our marketing list, so let's do it anyway". It's to give authorities scope to punish organisations making calculations like the above, more than "Your local library decided to tell everyone who took out a book last year about their new book club, not realising it's an illegal use of personal data".
- orwin 8y agoAnd you are allowed to take it to the european court if you think the fine is bullshit. And if you don't already know, european court don't take bullshit very well. Anyway, all regulatory instances are working together (in a group named G29, imagination is not their strength) to draw guidelines for fines and warnings. They will also discuss together ongoing cases (to avoid multiple prosecutions i guess). If you are not trying to cheat data from your customers and if your security is up to date, you risk nothing.
- curun1r 8y agoActually, the maximum fine is 4% of revenue or €20m, whichever is more. For a small business or organization, the 4% number isn't the scary one. You can say that in practice this would never happen, but calling it FUD also doesn't seem right since the regulation is super vague and only mentions maximum fines, not likely actual fines.
- s73v3r_ 8y agoThat will never, ever, ever, ever happen. I guarantee that no inn will ever be fined 4% of revenue over a simple paper guestbook.
- test525 8y agoYou really don't think it's possible that one of the 28 member nations of the EU will pass down an absurdly large fine for some minor infraction? This happens all the time... The fact is, if I am not GDPR compliant in any way there is no mechanism built into the law to limit the amount I am fined and some judge that is in a bad mood or hates the idea of my business can simply fine me 20 million to kill my business and still be abiding by the letter of the law.
- craigsmansion 8y ago> You really don't think it's possible For signing a guestbook or something similarly trivial? No. If you truly believe that (if it really escalated) the European Commission, and then the European parliament, and then ultimately the European Court of Justice is going to put up with 20-million-fine-for-a-guestbook shenanigans, I don't know what to tell you, except that I think your definition of "reasonable" is not reasonable. Maybe I'm not jaded enough, and I can believe in a single bad actor, but all of them? Including an entire institution that has direct public accountability? As an aside, I think it would be helpful if participants in GDPR discussions would indicate if they approach it from a USA or EU angle (or even a non-EU and non-USA perspective. I've haven't really noticed any specific opinions from outside the USA/EU).
- s73v3r_ 8y ago"You really don't think it's possible that one of the 28 member nations of the EU will pass down an absurdly large fine for some minor infraction?" For the infraction of having a guestbook? Absolutely not. "The fact is, if I am not GDPR compliant in any way there is no mechanism built into the law to limit the amount I am fined" I don't see that as a problem. " some judge that is in a bad mood or hates the idea of my business can simply fine me 20 million to kill my business and still be abiding by the letter of the law." Then you appeal. You're acting like there's no recourse or appeals mechanism for you.
- orwin 8y agoStop spreading FUD please. 1: fines are up to (4%? thought it was 2%) depending on the offense (i dont think even Cambridge analytica would qualify to max fine, even if they were a persistant offender). 2: Yes some terms are vague, some part are vague too (what is considered "big scale"...) but if you want to cry about a vague law that enable government to shut down businesses, look at FOSTA-SESTA. This law is also vague to allow european countries to tinker around. Moreover, a vague law is often in favor of the defendant on european courts (if a litigation is ever taken to european court), so this is an advantage for owners. 3. A warning will be issued before any fine, then some time would be given to comply. If complying is difficult, regulatory instances have to help you by giving you ideas/examples/advice. 4. In the case of a physical guestbook, i'm pretty sure the regulatory instances will just laugh at the demand and ignore it anyway. 5. We had a CNIL contact before the GDPR was even drafted (we host health data) and we store non-hashed IP address of our customers (for ip whitelisting), name, surname, email address and phone number. Everything seems good for him as long as our security audits every year are good. I'm pretty sure we hold more client data than almost every small to medium shop whose business is not selling customer data, yet members of regulatory instance say we are okay. This panic is ridiculous.
- test525 8y ago>Stop spreading FUD please. 1: fines are up to (4%? thought it was 2%) depending on the offense (i dont think even Cambridge analytica would qualify to max fine, even if they were a persistant offender). I have to laugh since you are telling me to stop spreading FUD and you can't even cite off the top of your head if the fine is 4% or 2%. The fine is 4% of worldwide revenue or $20million (whichever is larger). >(i dont think even Cambridge analytica would qualify to max fine, even if they were a persistant offender). Can you cite the section of the law that makes you so confident in making this assertion? All the people telling me to stop worrying don't seem to have any ground to stand on. I've read so many feel good assertions about how "this is not how EU law works" and I can't trust any of them since none of the assertions people are stating so confidently are written into the actual law. All I know is what is possible. If I am violating GDPR in any way I could be fined $20 million dollars and frankly I don't want to be one of the legal pioneers to find out how each of the 28 member states of the EU will interpret how to apply this law.