6 ms·
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporatio
by throw8484949ii 19d ago
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!
Try to do marketing ad campaign as small eshop owner in EU!
- Barrin92 19d ago>US companies like Meta or Google __LOVE__ GDPR If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf. This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
- throw8484949ii 19d agoMicrosoft also hated windows piracy and "fought" against it, later they admitted it helped their business. As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons. All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
- scott_w 19d agoAs someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
- tzs 18d agoHow about if someone asks for copies of all their data? I thought that was not complicated, but then there was that post here a while back where someone asked McDonald's for their data. It included a vast amount of things that the company had inferred from the data. I hadn't realized that would be in scope, and did some Googling on just what has to be included. According to a few sites I found, and Google's LLM concurred, it is basically everything I have about them, regardless of if I got it from them, a third party, or produced it internally. Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them? That should be in the GDPR response (I can redact the names of the rep and supervisor). I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists. That's supposed to be in the GDPR data, if the sites I found are to be believed. Heck...if some customer calls to update their credit card and calls the wrong number, and leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data. (If they call customer support and leave such a message it would go to a number handled by the expensive outsourced customer service system, which has voice transcription software that looks for things like that and deals with it, but the internal phone system used by other departments doesn't so if the wrong number went to some random person in some other department it won't have that automated handling of this). If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer. I'm hoping the sites I found and the LLM were wrong and it is not this bad.
- scott_w 18d ago> If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer. You’re only half right. If you habitually store data and never delete it from those stores, yes, you have to find and provide it. If they’re temporary (voicemail, fixing a specific issue) and you remove it as soon as it’s no longer needed, you’ll be fine. > It included a vast amount of things that the company had inferred from the data. If you’ve tied it to that person, it’s in scope. It’s literally part of GDPR. > Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them? Possibly but you could argue not because that could be business risk. > I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists. No, you have a valid reason to not share that, as long as you remove the PII once you’re done. > leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data. If you’re deleting voicemails as you address them you’re fine, you won’t need to include this just because you didn’t get round to deleting it yet.
- 9dev 19d agoI'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
- throw8484949ii 19d ago[flagged]
- 9dev 19d agoYou don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you? You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month. We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can. If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .
- throw8484949ii 19d ago> You don’t need to hire such a person since you’re way too small for the thresholds > You also have to keep up with other regulations; that’s the price of doing business Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)? Keep on mind I get lower salary than garbage man! > they absolutely value if you’ve tried your I do not "store data",. I have a free gmail account, I do not have a "data retention policy". But by GDPR i have to follow the same rules a s facebook! > they absolutely value if you’ve tried your best.... My absolute best is to check once every a few years. That is not going to fly with goverment! The only real help I got in past 5 years was AI! It can explain new changes, and audit my workflow, without paying 100x my salary to some consultant!