Remix.run Logo
throw8484949ii 2 days ago

US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!

Try to do marketing ad campaign as small eshop owner in EU!

scott_w 2 days ago | parent | next [-]

As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.

tzs 21 hours ago | parent [-]

How about if someone asks for copies of all their data?

I thought that was not complicated, but then there was that post here a while back where someone asked McDonald's for their data.

It included a vast amount of things that the company had inferred from the data. I hadn't realized that would be in scope, and did some Googling on just what has to be included.

According to a few sites I found, and Google's LLM concurred, it is basically everything I have about them, regardless of if I got it from them, a third party, or produced it internally.

Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them? That should be in the GDPR response (I can redact the names of the rep and supervisor).

I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists. That's supposed to be in the GDPR data, if the sites I found are to be believed.

Heck...if some customer calls to update their credit card and calls the wrong number, and leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data. (If they call customer support and leave such a message it would go to a number handled by the expensive outsourced customer service system, which has voice transcription software that looks for things like that and deals with it, but the internal phone system used by other departments doesn't so if the wrong number went to some random person in some other department it won't have that automated handling of this).

If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer.

I'm hoping the sites I found and the LLM were wrong and it is not this bad.

scott_w 17 hours ago | parent [-]

> If that's right than handling a GDPR data request 100% according to the rules would require having some way to search nearly every computer we've got looking for anything concerning any particular customer.

You’re only half right. If you habitually store data and never delete it from those stores, yes, you have to find and provide it. If they’re temporary (voicemail, fixing a specific issue) and you remove it as soon as it’s no longer needed, you’ll be fine.

> It included a vast amount of things that the company had inferred from the data.

If you’ve tied it to that person, it’s in scope. It’s literally part of GDPR.

> Customer service rep sends an email to their supervisor saying the customer won't take reasonable advice and then gets abusive and asking the supervisor how to deal with future calls from them?

Possibly but you could argue not because that could be business risk.

> I make a list on my computer of customers that I think are exploiting a bug in our billing system to get a lower price, print out that list and assign it to someone to investigate and fix the bug if it exists.

No, you have a valid reason to not share that, as long as you remove the PII once you’re done.

> leaves a voice mail where they include "my new credit card number is <xxx> with security code <yyy> and expiration date <zzz>", that's supposed to show up in their GDPR data.

If you’re deleting voicemails as you address them you’re fine, you won’t need to include this just because you didn’t get round to deleting it yet.

9dev 2 days ago | parent | prev | next [-]

I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.

throw8484949ii 2 days ago | parent [-]

[flagged]

9dev a day ago | parent | next [-]

You don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?

You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.

We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.

If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .

throw8484949ii a day ago | parent [-]

> You don’t need to hire such a person since you’re way too small for the thresholds

> You also have to keep up with other regulations; that’s the price of doing business

Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)?

Keep on mind I get lower salary than garbage man!

> they absolutely value if you’ve tried your

I do not "store data",. I have a free gmail account, I do not have a "data retention policy". But by GDPR i have to follow the same rules a s facebook!

> they absolutely value if you’ve tried your best....

My absolute best is to check once every a few years. That is not going to fly with goverment!

The only real help I got in past 5 years was AI! It can explain new changes, and audit my workflow, without paying 100x my salary to some consultant!

9dev a day ago | parent [-]

> Which one is it then?

You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality here, right? Or do you consider filing your taxes as unpaid regulatory bullshit work too?

> Keep on mind I get lower salary than garbage man!

It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite, but if you don’t have a reasonably good income from your company, why do you put up with all the hassle in the first place..?

> I do not "store data",.

Sure you do, if you sell anything. You need to know where to ship stuff, customers contact you, pay you, all that. And as your customer, I don’t want you to store that longer than necessary or sell it to someone else.

throw8484949ii a day ago | parent [-]

> You don’t need a dedicated data protection officer, because your company is too small for that.

But I do need dedicated comliance officer! The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!

And if do notmp comoly goverment will fine me to oblivion!

> So unpaid doesn’t really match the reality here, right?

It absolutely matches the reality. You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?

Luckily AI can now automate this shit, so now I spend cents instead of dozens hours of labour!

> It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite,

Because I have social responsibility to make some rare stuff available, as you would put it! But EU is not making it any easier!

> If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best

So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!

9dev a day ago | parent [-]

> But I do need dedicated comliance officer!

There is no compliance officer required by law, at least not in any regulation introduced by the EU.

> The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!

If you have more than 250 employees, you really should have both a higher salary than a garbage man and be able to afford someone to take care of your compliance duties.

> You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?

I don't expect anything. You run a business. Anything you do related to that business is your own working time, just as anything I do in regard to compliance or data protection is of course billed working time. You file your taxes in your working time, you pay your bills in your working time, and of course you also read up on laws you need to comply to in your working time. Those are table stakes for doing business everywhere. Do you think American companies don't have to comply to regulations?

> Because I have social responsibility to make some rare stuff available, as you would put it!

All props to you for making that choice, then, but it's still your decision to have a company and that means you have to abide the law.

> But EU is not making it any easier!

The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of, because you never cared to look.

Just because you have a responsibility to think about and extra work to enable handling data your customers entrust you with carefully doesn't invalidate all of these efforts.

> So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!

You should try to think about protecting the personal data you handle responsibly and be ready to demonstrate that when somebody asks. Again, I am in the same spot and have been for years. This is doable.

throw8484949ii a day ago | parent [-]

> I don't expect anything. You run a business.

> And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?

You were very clear as a business owner i have tons of extra responsibilities. I should go extra mile to "demonstrate". I am single guy, with a few houndred euro a month (lower salary than garbage man), and I have the same obligations as company of 249 people!

> There is no compliance officer required by law

> and be ready to demonstrate that when

> they absolutely value if you’ve tried your best as opposed to not caring at all;

Again, most companies hire an office to "demonstrate best efford" and to offload personal responsibility from company owner. This still applies to one person business!

> The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of

Are you even in EU my friend? I was unable to sell into germany becauee of some local BS. Every country has their own taxes, localization and regulations, there is no single market! EU has several currencies! EU does not protect from foreign traders, it pushes contaminated chicken from outside EU that contains salmonela!

Public infrastructure, education and art is responsibility of national goverment, EU sponsors maybe 2% of that!

> just as anything I do in regard to compliance or data protection is of course billed working time

Here is the core problem! You are not eshop owner! You are consultant who directly benefits from more regulations!!!

Of course you will push for more regulations and more "social responsibility"!

Luckily normal people can replace consultants with AI!

contubernio a day ago | parent | prev | next [-]

Part of running a profitable business is doing the right thing. Following socially obligated rules is a cost just like buying drywall.

The profits at all cost mentality is a criminal mentality. Maybe it gets away with not being formally criminal because laws or enforcement are weak (as is the case in the USA) but that doesn't justify the mentality.

throw8484949ii a day ago | parent [-]

> Part of running a profitable business is doing the right thing. Following socially obligated rules is a cost

Exactly! But there is a fixed cost of doing a right think! It is much easier for facebook to do the "right think", than some single guy with no employees!

> just like buying drywall.

I do not have a dry wall. Houses in EU usually do not have a dry wall.

scott_w a day ago | parent | prev [-]

> GDPR is easy to implement once, but it is constantly changing every year.

No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that.

If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if you’re informed they changed.

For store analytics, your cookie banner covers you, the major players all integrate into standard tools, and they keep their compliance up to date, so you’re fine there.

Small mistakes are very much not punished. Your country’s Data Commissioner equivalent will want to see you try to be compliant first. You’re only going to get put out of business on a first offence if you’re taking the piss. I guarantee any example you provide me as evidence will be exactly that, but feel free to try.

throw8484949ii a day ago | parent [-]

> the major players all integrate into standard tools, and they keep their compliance up to date,

I am not major player! I do not have dedicated team of people to keep "compliance up to date".

> if you’re informed they changed

Yet more extra work!

> see you try to be compliant first

Sounds like work for extra GDPR officer! I do not have that kind of money!

scott_w a day ago | parent [-]

By “major player” I meant the analytics companies that you pay, not you.

> Yet more extra work!

If “customer asks me to update my records on them, so I do it,” is too much work then you really shouldn’t be in the business that requires it.

> Sounds like work for extra GDPR officer!

Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”

Seriously, all your answers here tell me you’re trying to do some shady shit and not even making money from it. If you were a simple retailer, as your original post implied, you would not be worried about the complexity of handling GDPR.

throw8484949ii a day ago | parent [-]

just because I have small profits, does not mean i sell drugs! (But drug dealer would probably get better deal from police for breaking GDPR). I am worried about several thousands euro fines!

I have my own eshop, i do not use "major player"! Too expensive.

> Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”

And than you get different offical, with different opinion. Their advice have same weight as weather forecast!

scott_w a day ago | parent [-]

> just because I have small profits, does not mean i sell drugs!

I never said anything about drugs. I’m talking about doing illegal things with people’s data.

> And than you get different offical, with different opinion. Their advice have same weight as weather forecast!

If you’re getting audited this often you are DEFINITELY playing fast and loose with the rules. I have no sympathy for you.

throw8484949ii a day ago | parent [-]

You said "shady shit"! Deleting some data a few days/weeks or months latter too late is not "shady shit"!

You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides!

Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects. And small eshops are easy targets for fines. Large corporations are untouchable.

scott_w a day ago | parent [-]

> You said "shady shit"!

Look, I don’t think English is your first language, so I’m trying to give you the benefit of the doubt but it’s getting really tiring having to explain basic things like “context” to you. I’m obviously meaning in the context of data governance. I’m accusing you of selling customer data to unscrupulous characters, to be precise.

> You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides!

Either you’re bullshitting me or you live in Eastern Europe and need to give kickbacks to stay in business. If the latter, that’s not the GDPR’s fault. It’s the fault of your government for not being able to draft law.

> Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects.

That’s not the GDPR, that’s your country having a poor grasp of how to make law. It’s a different problem and I’d recommend either lobbying your local representative or just leave to a sane country which will let you do business.

throw8484949ii 19 hours ago | parent [-]

> The official tells you, you do it, they say “thank you.”

> or just leave to a sane country

So first you tell me to blindly trust officals, now i should leave country! Great advice!

> That’s not the GDPR

GDPR is drafted by EU. They went way too far, and made it imcompatible with local laws!

scott_w 17 hours ago | parent [-]

> So first you tell me to blindly trust officals, now i should leave country! Great advice!

Again, context. I’m bored of explaining it to you like a toddler so I’ll just tell you to reread my comments very slowly and figure it out.

> GDPR is drafted by EU. They went way too far, and made it imcompatible with local laws!

This is just a nonsensical statement. GDPR has been in force for 7 years. You haven’t given an example of where it changes, because it fundamentally hasn’t.

Barrin92 2 days ago | parent | prev [-]

>US companies like Meta or Google __LOVE__ GDPR

If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.

This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.

throw8484949ii 2 days ago | parent [-]

Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.

As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.

All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.