[HN Gopher] The Missing Stakeholders
       ___________________________________________________________________
        
       The Missing Stakeholders
        
       Author : zoobab
       Score  : 30 points
       Date   : 2021-02-05 12:09 UTC (2 days ago)
        
 (HTM) web link (meshedinsights.com)
 (TXT) w3m dump (meshedinsights.com)
        
       | Daho0n wrote:
       | >"For example the GDPR takes the best of intentions around
       | citizen privacy and ends up causing unintended harm by layering
       | ambiguous and extensive responsibilities and liabilities on small
       | businesses and individuals with web presence. They either comply
       | at great cost (relative to their turnover) or ignore it all,
       | intentionally or out of bewilderment."
       | 
       | What a load of BS. I own a small business with "a web presence".
       | GDPR is _extremely_ easy. What is hard is wanting to collect data
       | legally. Just don 't do it if it is too hard. Times have changed
       | - change or die. If you write such FUD I won't trust a single
       | word written.
        
         | webmink wrote:
         | I'm glad for you. Your experience is not shared by small
         | businesses for which ICT is a mystery rather than a delight.
        
           | p_l wrote:
           | Most harm from GDPR to small business actually happened
           | thanks to armies of "GDPR consultants" who smelled money in
           | the market and, in my experience, often heavily skewed
           | perception in order to increase their own profits.
           | 
           | Majority of small business never have to deal with GDPR
           | unless they gather personal information - and for most of
           | them the limited cases that a small business might gather
           | information were already covered by previous laws, and for
           | most cases can be done on simple process of human action.
           | 
           | Data privacy laws applied whether you used computers or not,
           | and GDPR doesn't change that.
           | 
           | Ultimately, the simplest way of not having to deal with GDPR
           | is to not store private data, or storing the minimal possible
           | set. The archetypical smallest possible business already
           | outsources a lot of such operations to aggregate eShop
           | vendors, which are a good place to place controls. Those who
           | run B2C sales directly in ways that require private
           | information can spend a bit of time on getting compliant,
           | generally with a set of cookie-cutter processes.
        
         | onlyrealcuzzo wrote:
         | One does not simply "not collect data". You could potentially
         | be in violation of GDPR from server logging that you don't even
         | know about.
         | 
         | Sure, if you're intimate with your entire stack and have turned
         | off all logs - you're for sure good to go. But that's not most
         | small business owners, and also, good luck debugging if you
         | ever need to.
        
           | TheCoelacanth wrote:
           | Normal server logging is going to be covered under legitimate
           | interests. Apply a reasonable retention period to it (5 year
           | old logs are not necessary for any legitimate business
           | purpose). Disclose it to users. Done.
        
         | zoobab wrote:
         | What about copyright filters? Are you ready to install them?
        
           | diggan wrote:
           | Again, you don't want to deal with the "huge complexity" of
           | making sure you keep your users personal data secure, don't
           | store any of your users personal data, just like what Daho0n
           | said.
           | 
           | GDPR is something you have to follow if you meet the
           | requirements (like collecting personal information about your
           | users and more), not something you have to follow as soon as
           | you publish a HTML file on the internet.
           | 
           | I understand that businesses don't have the time (or maybe
           | care?) to fully understand GDPR before jumping to solutions,
           | but I would think the crowd here on HN to do better than
           | that. Read through GDPR and you'll see it's much easier to
           | follow than you think, it is surprisingly small and easy to
           | approach: https://gdpr.eu/tag/gdpr/
        
             | datavirtue wrote:
             | Yeah. GDPR is an example of very good legislation and
             | regulation. I have read through the entire text and it is
             | comprehensive and focused on the rights of individuals.
             | There is next to nothing wrong with it at all.
        
       | gumby wrote:
       | > For example the GDPR takes the best of intentions around
       | citizen privacy and ends up causing unintended harm by layering
       | ambiguous and extensive responsibilities and liabilities on small
       | businesses and individuals with web presence.
       | 
       | This happens in spades in the finance industry, which has
       | addressed it by outsourcing it: small companies start up that do
       | nothing but compliance for regulation X or Y. You can see this,
       | for example, in US retirement funds: if you put a dollar into
       | your 401(k) various people touch it before it is actually
       | invested, certifying that the 401(k) fits this or that
       | qualification restriction, certifying various arms length rules
       | etc, each taking a small fraction of a percent as a fee. In then
       | end only perhaps 97* cents of asset is purchased with your
       | dollar.
       | 
       | In case it is not clear: I am not advocating this system! Just
       | saying that the market can adapt to it, and favoring big
       | incumbents is not the only way/consequence. Each of these little
       | entities of course becomes a protected incumbent themselves.
       | 
       | * I don't remember the precise amount but it was more than a
       | percent and I think it ended up added up to three or four. But it
       | was many many years when I looked at this, and it was when I was
       | evaluating a company's tech stack for an investor, so my focus
       | wasn't on these details. But it was fascinating how the market
       | had adapted.
        
       | scribu wrote:
       | The observation that regulation usually ends up helping the
       | incumbents is not new.
       | 
       | That said, I find the "meshed society" concept useful. It
       | highlights the radical level of collaboration possible between
       | individuals, enabled by the internet.
        
       | paulie_a wrote:
       | It is important to note that it only matters to businesses doing
       | business in europe or located in europe
       | 
       | A pretty good chunk of the web doesn't need to comply with it at
       | all.
       | 
       | That is why the rush to add those stupid cookie notifications was
       | so unnecessary and quite frankly just dumb
        
       ___________________________________________________________________
       (page generated 2021-02-07 23:02 UTC)