Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not baking security/privacy in from the start that's the problem, it's the need to have a "compliance officer" and have to handle these requests. Small companies don't have time or resources for this.

Look at the American Disabilities Act, an act that has done enormous good in many ways, but that has also lead to an entire industry of lawyers hassling tiny businesses over insignificant infractions. (e.g. https://www.mercurynews.com/2016/04/10/serial-ada-lawsuit-fi...)

Startups in the US won't have this hassle. You don't have to serve EU customers to reach mid size/product market fit, you can concentrate on iterating on your core product. When it's time to scale, then you can look at GDPR. So limited resources stretch further.

But if the lawyers in Europe start becoming a nuisance to startups there, it's just going to force more and more services to be located overseas, and more and more government complaining about the dominance of overseas tech, a problem they're probably going to make worse.



> Startups in the US won't have this hassle.

Startups in the US are what got us into this privacy nightmare in the first place. Of course, they are no longer startups, but they still didn't fix shit once they got bigger, so I don't see how this argument holds.

I like to think of privacy like internationalisation or security. When I started programming, Unicode/UTF-8 was niche and not well supported at all. Now, for new languages, it's a given. The same with decent crypto libraries. Databases now offer pretty great unicode support (except for the old ones where it had to be bolted on, coughMySQLcough). It isn't inconceivable that privacy tools become standard in databases and data processing frameworks.

Personally, I see this as a brilliant opportunity for people/companies who want to do the right thing for their customers (whether that's consumers directly, or a company using them).

My prediction is you'll see this with cloud providers strongest. Some are putting a lot of effort into GDPR, and a properly compliant provider will become a huge value-add, and not a liability.


> Startups in the US are what got us into this privacy nightmare in the first place.

Com'on. The internet and web when they started were a wild wild west that operated on the honor system. Most people were just starting to feel their way around what kinds of businesses could even exist on it. The Morris Worm was the canary in the coal mine about how the honor system wouldn't scale.

EU startups are no different than US startups, we just have more of them, there is a greater concentration of investment in that area here.


You don’t think BNP bank or AXA insurance play loose with sharing personal data? I had my Peugeot dealer share my purchase information with a third party “extended warranty” vendor without my permission. The vendor called me and sent letters. I never told Peugeot that they could sell my data. I have never given any business permission to call me — yet they do.

Blaming US tech is naïve. European companies have been engaged in non-digital forms of privacy invasion long before Google even existed.


I agree, but people on HN don't seem to care about those as much as US startups. Plus who is worried about car dealerships going under just because they can't pass on your data to some scummy vendor? (Also, some countries have laws close the the GDPR already, where this wouldn't fly.)

Having said that, shunning one car dealership is way easier than trying to stop Facebook or Google slurping your data, even with ad blockers et al.


> Startups in the US won't have this hassle

If I have a choice between an US startup that has no pressure to handle my data responsibly, and an EU startup that has a legal requirement to do so, I would choose the EU startup. The US startup may claim it takes care of my data and ask me to trust their word, but I know that the EU startup is forced to by law.

Perhaps it could end up as a competitive advantage for EU businesses.


You don't have to hire someone new. You just label an existing employee "compliance officer" and give him the relevant authority. Chances are he won't have to reply to a single letter, because unlike the web board imaginations, next to nobody will be motivated enough to actually send such a letter.

And all bigger companies already have a data protection officer, so he just gets this new job title.


If you look at what google does, they already offer you an admin panel where you can see all the information recorded about you, and you can download it, etc.

How is this much more of a hassle than being required to send people are receipt as proof of purchase...

Ensure customers can see what you record about them when logged in (probably in their user profile), then minimize what you record to what you need.


Every time any new regulation comes out, doesn't matter what law it is, Small Business™ trots out the same sob story: "Woe is us, we are too small to follow this new burdensome law!" I get it--it's going to be costly. This cost is one of many that founders will need to consider when they decide between go and no-go. If founders can't afford to follow (and prove they follow) the law, I think they should re-think their start-up idea. The ADA has done enormous good, in part, because of that industry of lawyers keeping a close watch for opportunities to sue. Same is probably true for HIPPA. Same will, hopefully, be true for GDPR.


The cost of compliance will fall drastically. My company (Aptible) started in HIPAA and is doing a lot with GDPR. They are very similar in a lot of ways, including the emergence of new systems of record for privacy and security management data.


The data protection officer does not have to be a full-time role. It can be part of someone's other duties, or performed by a contractor (Art 37 ¶ (6): https://gdpr-info.eu/art-37-gdpr/).


"Just look at the GDPR when you get above a certain size" probably won't be so easy. You'll have already committed to lots of things, lots of services, business model(s) etc. It's much much much easier to think about it from the start.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: