[HN Gopher] The Missing Stakeholders
___________________________________________________________________
The Missing Stakeholders
Author : zoobab
Score : 30 points
Date : 2021-02-05 12:09 UTC (2 days ago)
(HTM) web link (meshedinsights.com)
(TXT) w3m dump (meshedinsights.com)
| Daho0n wrote:
| >"For example the GDPR takes the best of intentions around
| citizen privacy and ends up causing unintended harm by layering
| ambiguous and extensive responsibilities and liabilities on small
| businesses and individuals with web presence. They either comply
| at great cost (relative to their turnover) or ignore it all,
| intentionally or out of bewilderment."
|
| What a load of BS. I own a small business with "a web presence".
| GDPR is _extremely_ easy. What is hard is wanting to collect data
| legally. Just don 't do it if it is too hard. Times have changed
| - change or die. If you write such FUD I won't trust a single
| word written.
| webmink wrote:
| I'm glad for you. Your experience is not shared by small
| businesses for which ICT is a mystery rather than a delight.
| p_l wrote:
| Most harm from GDPR to small business actually happened
| thanks to armies of "GDPR consultants" who smelled money in
| the market and, in my experience, often heavily skewed
| perception in order to increase their own profits.
|
| Majority of small business never have to deal with GDPR
| unless they gather personal information - and for most of
| them the limited cases that a small business might gather
| information were already covered by previous laws, and for
| most cases can be done on simple process of human action.
|
| Data privacy laws applied whether you used computers or not,
| and GDPR doesn't change that.
|
| Ultimately, the simplest way of not having to deal with GDPR
| is to not store private data, or storing the minimal possible
| set. The archetypical smallest possible business already
| outsources a lot of such operations to aggregate eShop
| vendors, which are a good place to place controls. Those who
| run B2C sales directly in ways that require private
| information can spend a bit of time on getting compliant,
| generally with a set of cookie-cutter processes.
| onlyrealcuzzo wrote:
| One does not simply "not collect data". You could potentially
| be in violation of GDPR from server logging that you don't even
| know about.
|
| Sure, if you're intimate with your entire stack and have turned
| off all logs - you're for sure good to go. But that's not most
| small business owners, and also, good luck debugging if you
| ever need to.
| TheCoelacanth wrote:
| Normal server logging is going to be covered under legitimate
| interests. Apply a reasonable retention period to it (5 year
| old logs are not necessary for any legitimate business
| purpose). Disclose it to users. Done.
| zoobab wrote:
| What about copyright filters? Are you ready to install them?
| diggan wrote:
| Again, you don't want to deal with the "huge complexity" of
| making sure you keep your users personal data secure, don't
| store any of your users personal data, just like what Daho0n
| said.
|
| GDPR is something you have to follow if you meet the
| requirements (like collecting personal information about your
| users and more), not something you have to follow as soon as
| you publish a HTML file on the internet.
|
| I understand that businesses don't have the time (or maybe
| care?) to fully understand GDPR before jumping to solutions,
| but I would think the crowd here on HN to do better than
| that. Read through GDPR and you'll see it's much easier to
| follow than you think, it is surprisingly small and easy to
| approach: https://gdpr.eu/tag/gdpr/
| datavirtue wrote:
| Yeah. GDPR is an example of very good legislation and
| regulation. I have read through the entire text and it is
| comprehensive and focused on the rights of individuals.
| There is next to nothing wrong with it at all.
| gumby wrote:
| > For example the GDPR takes the best of intentions around
| citizen privacy and ends up causing unintended harm by layering
| ambiguous and extensive responsibilities and liabilities on small
| businesses and individuals with web presence.
|
| This happens in spades in the finance industry, which has
| addressed it by outsourcing it: small companies start up that do
| nothing but compliance for regulation X or Y. You can see this,
| for example, in US retirement funds: if you put a dollar into
| your 401(k) various people touch it before it is actually
| invested, certifying that the 401(k) fits this or that
| qualification restriction, certifying various arms length rules
| etc, each taking a small fraction of a percent as a fee. In then
| end only perhaps 97* cents of asset is purchased with your
| dollar.
|
| In case it is not clear: I am not advocating this system! Just
| saying that the market can adapt to it, and favoring big
| incumbents is not the only way/consequence. Each of these little
| entities of course becomes a protected incumbent themselves.
|
| * I don't remember the precise amount but it was more than a
| percent and I think it ended up added up to three or four. But it
| was many many years when I looked at this, and it was when I was
| evaluating a company's tech stack for an investor, so my focus
| wasn't on these details. But it was fascinating how the market
| had adapted.
| scribu wrote:
| The observation that regulation usually ends up helping the
| incumbents is not new.
|
| That said, I find the "meshed society" concept useful. It
| highlights the radical level of collaboration possible between
| individuals, enabled by the internet.
| paulie_a wrote:
| It is important to note that it only matters to businesses doing
| business in europe or located in europe
|
| A pretty good chunk of the web doesn't need to comply with it at
| all.
|
| That is why the rush to add those stupid cookie notifications was
| so unnecessary and quite frankly just dumb
___________________________________________________________________
(page generated 2021-02-07 23:02 UTC)