The final law was finalised in 2016 and was expected since at least 3-4 years ago when the agreement was made in the EU parliament.
Startups:
It costs money to develop the systems to process personal data in the first place. I don't see any unreasonable restrictions in GDPR. If new startups plan for GDPR while developing the systems it should not add too much costs. It is basically about managing data responsibly and documenting how you utilise that data.
Established companies:
I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. This has happened to other industries as well, such as the tobacco industry who had to adjust to anti-smoking laws when the politicians could no longer ignore the negative effects.
I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market.
Some commenters in these discussions write as if all businesses deserve the GDPR and all its attendant overheads as some sort of punishment for assumed past transgressions. And yet I work with small businesses, and so unsurprisingly I also know many other people who do, and not one of those businesses operates with any sort of data-hoarding, privacy-invading model, nor would any of us ever want to.
All that attitude teaches the next generation of startups is that they'll be penalised whether they try to act ethically and responsibly or not, so they might as well do the questionable things and make more money anyway. Surely that is exactly the opposite of what should be happening?
GDPR has been known for 3-4 years and was finalised in 2016. They should have had 2-3 years to go through their systems. If a business can't do that, it indicates that they don't have control of the information in the first place. Most of the regulation is about adding routines, documenting the data management and updating user consents. Smaller companies under can skip some of the documentation.
The only major requirement that can not be fixed by documentation or updating user consent, is the requirement to not store data more than necessary, which depends on your business. If you need to store data for a longer time period than absolutely required, you need to either anonymise it or delete. If you run a business and need to store purchase histories to meet other legal requirements, you have a valid reason to store it. If you use it to track which purchases a specific user has done to optimise targeted advertisement you will probably have to anonymise it.
This can of course be a complex task, but I don't think it is a good argument against GDPR. Why should I lose control of my personal information just because it costs money to process it responsibly? At some point a regulation has to be implemented and some companies will unfortunately be impacted even if their intentions were good.
GDPR has been known for 3-4 years and was finalised in 2016. They should have had 2-3 years to go through their systems.
Was it posted in their local planning department in Alpha Centauri as well? Because to most people running microbusinesses -- which is most businesses, remember -- it might as well have been.
If a business can't do that, it indicates that they don't have control of the information in the first place.
Not at all. It's quite possible that an organisation has been reasonable and responsible about handling personal data and its staff know exactly what it's doing and why, but that the formal documentation and automated processes referred to throughout today's discussion aren't in place because they have never been necessary before.
Why should I lose control of my personal information just because it costs money to process it responsibly?
The trouble is that different people will have different interpretations of "responsibly". For example, I'm not sure it's irresponsible to have been storing and processing data for legitimate purposes and entirely with the subject's informed consent for years, and also to be concerned about the cost of updating or replacing all of those systems because the subject is now being given a retrospective right to withdraw that consent that they didn't have before. While this might be considered desirable in terms of reining in data hoarders like Facebook or Google, it also imposes burdens on organisations with different models and lower risks to data subjects. Some sort of balance is needed between these competing priorities.
At some point a regulation has to be implemented and some companies will unfortunately be impacted even if their intentions were good.
Right, but this is exactly why both unambiguous rules and proportionality are important.
When you move fast and break things, sometimes what ends up broken is you. That’s probably a lesson which needs to be painfully re-learned by some. As you said, too many have been outrunning real consequences for a while, but that’s not some inherent right, it’s a con.
If personal info is worth what a lot of companies seem to think it’s worth, then governments have been downright negligent in their lack of regulation. Playing fast and lose with people’s identities should never have been acceptable, and complaining that the first wave of consumer protections is anti-business mostly tells you what kinds of businesses we’re dealing with.
Startups: It costs money to develop the systems to process personal data in the first place. I don't see any unreasonable restrictions in GDPR. If new startups plan for GDPR while developing the systems it should not add too much costs. It is basically about managing data responsibly and documenting how you utilise that data.
Established companies: I don't have much sympathy for existing companies. They have exploited the slow reaction time of the legal system to make money in an unregulated market. This has happened to other industries as well, such as the tobacco industry who had to adjust to anti-smoking laws when the politicians could no longer ignore the negative effects.