You Know GDPR Is Good Based on Who Hates It

(matduggan.com)

81 points | by latexr 1 hour ago

19 comments

  • blfr 56 minutes ago
    Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things.

    It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.

    With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.

    At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.

    • veeti 18 minutes ago
      I think GDPR is more good than bad, but the author's example of surveillance capitalism is easily repeated on most EU news sites. Visit bild.de and watch the network inspector light up like a christmas tree. Do you really feel your privacy is being respected?

      The 996 partners banner is just the piss take that supposedly makes this legal.

    • ezst 38 minutes ago
      > It is also definitely true that the regulations are largely written by people who do not understand the tech

      I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".

    • varispeed 35 minutes ago
      The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense.

      Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.

    • nonethewiser 33 minutes ago
      You know GDPR is bad based on what it is
      • contubernio 0 minutes ago
        As a dual American-European (citizenship in both, lived in both) I celebrate the EU data privacy laws and lament the absolute lack of protection of data or privacy that prevails in the US. Because of US based websites the genealogical history of my extended family (to many degrees), my past US residence history, etc. are easily available online, while in the EU it is very difficult to obtain any information online whatsoever about me or my immediate family (based in the EU), where we live, or even what we do for a living.

        Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.

        All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.

    • Semaphor 34 minutes ago
      I disagree with several points, but you already made clear that you are right and I'm wrong, and so there's no point in debating anything. Must be nice to know everything
      • mft_ 30 minutes ago
        Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?
        • roenxi 12 minutes ago
          It's a social manoeuvre, the idea is basically like standing up and clapping to show support. For example, maybe someone wants to support/oppose a position but is genuinely not the sort of person who believes in making an argument. From that perspective a little public "I disagree and question your character" post is an obvious tactic. The idea isn't to make a point so there isn't normally much reason to respond.
  • blainm 21 minutes ago
    The reasoning treats a correlated characteristic as a causal mechanism.

    successful person → unusual trait And infer: unusual trait → success

    The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.

    FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.

    If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."

    Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.

    • ahartmetz 11 minutes ago
      TFA talks exclusively about being hated by the right people. If you are only hated by the right people (yes, I made an adjustment there), it's probalby not because you are a jerk. Come on.
  • sourcecodeplz 55 minutes ago
    there is a whole campaign online about hating on the EU & its regulations.
    • unsupp0rted 27 minutes ago
      I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself.

      I very much support their ideals and their people-centered mindset.

      But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.

    • leokennis 44 minutes ago
      Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
    • whatsThisBtn4 47 minutes ago
      I made a physical product and upon learning European regulations, I quickly decided I was going to spend 0 time designing it for Europe.

      If I made millions, sure, pay someone to figure it out.

      But I was not going to waste design time early on.

      I can't imagine how much this affects small business in Europe.

      • foldr 38 minutes ago
        These are just general barriers to international trade, though. Small manufacturers in Europe may likewise decide not to design for US regulations.
        • mft_ 24 minutes ago
          No (what I’m fairly sure is being referred to is that) there are (very recent) significant additional barriers to trade between EU member states, which disproportionately impact small businesses.
          • foldr 22 minutes ago
            I don't think so. The most natural reading of OP's post is that they are outside Europe. You wouldn't say "I can't imagine how much this affects small business in Europe" if you were yourself running a small business in Europe.
            • setsewerd 14 minutes ago
              Unless you were in Europe and didn't run a small business
              • foldr 11 minutes ago
                Ok, but their post talks about making a product in small volumes. It doesn't explicitly say that it's a small business, but together with the first person singular language, that's definitely the impression given.

                Also, their other posts suggest they are in the US: https://news.ycombinator.com/item?id=49477186

    • seydor 19 minutes ago
      Are you sure about it?

      In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.

      https://www.facebook.com/ads/library/report/?source=onboardi...

      Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious

    • Sharlin 37 minutes ago
      There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
    • mft_ 26 minutes ago
      Maybe it’s all a misinformation campaign… or maybe even people who live in, recognise and benefit from the good sides of the European experience, can also legitimately criticise bad aspects? It’s not binary - there are shades of grey.
    • gman83 22 minutes ago
      I mean this isn't some hidden agenda. The Heritage Foundation has an active plan to dismantle the EU from within.
  • marcle 42 minutes ago
    Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
    • nonethewiser 31 minutes ago
      Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.
  • bsian 6 minutes ago
    "You know x is good based on who hates it" is too generic an argument to be useful. It applies to so many things.
  • scott_w 1 hour ago
    As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.

    Was it a PITA? Sometimes, yes.

    Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.

    But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.

    • nraynaud 14 minutes ago
      Well, it's the cost of collecting data. A lot of businesses don't really need to collect data. It's only the cost of doing business if you are in the personal data business.

      For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.

  • sajithdilshan 43 minutes ago
    I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.

    Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect

    • em-bee 29 minutes ago
      except the package law as it stands is going to force many small businesses to close because they can't afford the cost.
      • sajithdilshan 19 minutes ago
        I think there will be more small businesses that would be created to handle all the package regulations and they will provide it as a service to all those businesses. I agree that it’s another unnecessary layer of bureaucracy, but maybe that was the intention of the lawmakers
  • bryanrasmussen 42 minutes ago
    I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.

    That said I am generally happy with GDPR.

    • nonethewiser 29 minutes ago
      It might have sounded clever but if you aren't concluding GDPR is good/bad based on what it is you are not reasonable.
  • stephantul 39 minutes ago
    Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.

    The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.

    Shame on the people making stuff like this.

  • ChrisSD 1 hour ago
    Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
    • brainwad 1 hour ago
      The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
      • maccard 1 hour ago
        They do come from the ePrivacy directive but;

        > if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

        No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.

        • nraynaud 11 minutes ago
          in particular, if you store stuff in the browser, and don't send it to the server later (local storage or one of the other 1000 JS APIs), there is no reason to present a cookie banner.
        • brainwad 1 hour ago
          No cookie is strictly necessary, you can encode it all into request tokens in the URL, so this is a meaningless exception.
          • jampekka 53 minutes ago
            The law is not about cookies specifically, it's technology neutral. The law doesn't even include the word cookie anywhere.

            https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

          • rcxdude 8 minutes ago
            The ePrivacy directive basically defines it as 'any data your site gives to the user's terminal that the terminal then passes back to your site'. Request tokens in the URL would qualify, but notably storing something in localStorage with javascript that is never sent back would not.
          • bryanrasmussen 25 minutes ago
            let me guess: you're some sort of programmer?!

            For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.

            I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.

            If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.

            If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.

            As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.

      • snackbroken 58 minutes ago
        You don't need explicit consent for functional cookies, e.g. a session cookie or to store what preferences the user has selected on your settings page. It is implicitly given by the user telling you to treat them a certain way. For that you just need a notice somewhere on the page that reads along the lines of "this website uses cookies". It can be an unobtrusive note in your footer.
        • brainwad 25 minutes ago
          You do need consent even for the necessary exemption in practice because of how that is defined; the user must have explicitly asked for the function that requires the cookie:

          > strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.

          But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.

          • amiga386 15 minutes ago
            If you're in a shopping site and "add to basket" -- explicity requested.

            If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested.

            If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested.

            No consent needed.

            On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed.

            Javascript measuring which sub-parts of the page they lingered on -- consent needed.

            Tracking how often they come back without buying anything -- consent needed.

            Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED.

            See the difference?

      • speedgoose 1 hour ago
        No you don’t need a cookie banner or consent to store normal data in the user browser.

        You do if you want to track your users. Very different thing.

      • amiga386 29 minutes ago
        The banner is not needed for the website to work, otherwise how would the "decline" button work? They can store cookies, otherwise how would they remember your choice? They can track a functional session just fine, full shopping cart and checkout if they want.

        What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.

        The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.

      • jampekka 59 minutes ago
        The ePrivacy directive did/does not require the nag for "necessary cookies", i.e. most of the cookies that are serving the user's interests.
      • andai 1 hour ago
        So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal.

        Because if it is, I also want to do it that way.

        • IanCal 58 minutes ago
          It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this.

          If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.

          Keep only what you need, for the time you need to keep it, in an appropriately secure way.

          • jampekka 52 minutes ago
            I don't understand why this was downvoted. It's informative and factual.
      • 9dev 1 hour ago
        It was always possible to ask the user for permission when you actually want to store something on their device, ie. go for an opt-in model.
    • petcat 1 hour ago
      Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?

      https://european-union.europa.eu/

      • orwin 56 minutes ago
        Yes. Basically the shop they used to make their website are shit, with shit incentives.
    • maccard 58 minutes ago
      I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.

      The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.

    • DarmokTanagra 52 minutes ago
      Everyone understands this, it doesn't matter.
  • jampekka 1 hour ago
    GDPR itself is quite a good law. It's implementation and enforcement are not.

    E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.

    EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.

    • foldr 33 minutes ago
      The do-not-track header is a nice idea but could never have worked. The GDPR is based on the idea that you can only store certain data about users if you have their consent to do so. Bearing in mind that most users have no idea what a header is and no idea how to configure their browsers, a user simply not sending a particular header does not imply consent to store information beyond that which is absolutely necessary for use of the site.
      • jampekka 22 minutes ago
        Lack of do-not-track header is not a consent to track of course. It's just signaling non-consent.
        • foldr 16 minutes ago
          I take your point. It would be nice to have a header that effectively just automatically canceled all the consent pop ups for you. But there are still some issues.

          1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.

          2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.

  • roenxi 57 minutes ago
    Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...

    > If the rules are so terrible, why did nobody choose market exit?

    Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.

    The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.

    EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.

    • bryanrasmussen 39 minutes ago
      >The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started

      essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.

  • amriksohata 31 minutes ago
    If someone hates something doesnt mean that the other thing is good, thats a bizarre assumption. Im all for GDPR but has it helped stopped our data truly getting out? No just look at social media companies using subversive tactics.
    • Timon3 8 minutes ago
      I have relevant personal experience here:

      At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.

      I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...

  • varispeed 38 minutes ago
    GDPR is good for corporations because it legitimises data trade. Population trained to agree to cookies now also agree to data processing just to get the banner go away and corporations have legal basis to process and sell the data.

    It is all working as intended.

    The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.

  • Razengan 58 minutes ago
    Same as with Apple's In App Purchases and low-friction refund process, that scummy companies like Match.com (the parent of Tinder etc) loudly opposed.
  • DarmokTanagra 1 hour ago
    I hate the banners, and I am a major privacy advocate.

    The web has gotten so much uglier as a result of GDPR.

    • Symbiote 48 minutes ago
      My employer's site has no banners, since we decided not to use any tracking.

      We measure our success based on enquiries, orders and so on, not the number of hits to the website.

      • DarmokTanagra 42 minutes ago
        so you don't track your bounce rate or effectiveness of your advertising?
    • gruturo 1 hour ago
      Shaka, when the walls fell.

      I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.

      GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.

      • DarmokTanagra 54 minutes ago
        I also read the post, and have handled multiple GPDR adjacent migrations in Asia.

        The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.

        The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.

    • intothemild 1 hour ago
      The cookie banner isn't actually specified in gdpr, it was just how everyone else tried to build the solution to the problem at the last minute.

      I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"

      Nope

      • gmerc 55 minutes ago
        It's a case of industry malicious compliance
      • sourcecodeplz 54 minutes ago
        i was thinking the same thing. it could be like an actual element of your page.
      • brainwad 1 hour ago
        Browsers already had a way to consent to cookies, since the invention of cookies themselves. But the EU didn't consider that _real_ consent.
        • 9dev 58 minutes ago
          Treating the browser's "disable cookies" feature as a way to reject consent is not real consent. That cripples many legitimate use cases outright; it's neither accessible nor understandable by normal users; it's a technical defence measure, not a way to consciously reject contractual consent.

          In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.

          There is clearly a difference here, and IMHO the EU is quite correct here.

          • DarmokTanagra 43 minutes ago
            Correct in principle, completely ineffectual and annoying in practice.
          • brainwad 34 minutes ago
            Most browsers in the 00s had a "always ask" option for cookies. Nobody used it, because it's as annoying as gdpr dialogs now are. But it existed.
          • intothemild 54 minutes ago
            Correct.. the gdpr isn't the anti cookie law. It's the data privacy law.

            If it wasn't cookies it would be something else.

  • throw8484949ii 1 hour ago
    US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!

    Try to do marketing ad campaign as small eshop owner in EU!

    • 9dev 57 minutes ago
      I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
      • throw8484949ii 47 minutes ago
        I am trying to run profitable business, not to "do the right think"! My shop had 5% profit margin and fimal net profit was bellow minimal salary! I do not have a money to hire "ethical compliance officer!"

        GDPR is easy to implement once, but it is constantly changing every year. Keeping up with regulations is constant energy drain. And small mistakes are punished by heavy fines (thousands of EUR). If you compare fines Meta is getting by revenue, small business should get maybe 10 euro fine for violations (not thousands).

        • 9dev 2 minutes ago
          You don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?

          You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.

          We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.

          If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .

    • Barrin92 1 hour ago
      >US companies like Meta or Google __LOVE__ GDPR

      If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.

      This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.

      • throw8484949ii 53 minutes ago
        Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.

        As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.

        All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.

    • scott_w 1 hour ago
      As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
  • larodi 1 hour ago
    GDPR has one single goal - to allow aggregated presumably anonymous data markets. Period. Everything else surrounding it is diversion in a plain sight.
    • 9dev 56 minutes ago
      Sure buddy. And it's all orchestrated by the Rothschilds, right?
  • seydor 1 hour ago
    Cookie banners are already obsolete in the age of AI. Who is wasting time defending it? People don't even care to hate GDPR these days, it's an anacrhonistic regulation from a different era that some EUrocrats like to boast about
    • dgellow 1 hour ago
      > Who is wasting time defending it?

      I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules

      • IanCal 56 minutes ago
        Often complaints about it boil down to either not understanding what’s in it, or annoyances that would be solved if sites stopped doing all this shady stuff. “We value your data, our 1644 partners…” yeah you definitely have a value you assign to my data.
    • bgarbiak 1 hour ago
      The point of the article is not that banners are good; it’s that they would not be needed at all if websites didn’t share all the possible data about their users with hundreds of vendors.

      Fun fact: the OP blog doesn’t display a GPDR banner.

      • whatsThisBtn4 45 minutes ago
        But did it do anything? I get fingerprinted anyway. I'm geolocated anyway.

        I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".

        Reminds me of 9/11 security theater