Europe's most famous technology law, the GDPR, is next on the hit list as the European Union pushes ahead with its regulatory killing spree to slash laws it reckons are weighing down its businesses.
The European Commission plans to present a proposal to cut back the General Data Protection Regulation, or GDPR for short, in the next couple of weeks. Slashing regulation is a key focus for Commission President Ursula von der Leyen, as part of an attempt to make businesses in Europe more competitive with rivals in the United States, China and elsewhere.
@EUCommission@ec.social-network.europa.eu are you trying to become the USA? Deregulation will make us just like them! Don't undo all the good work you did!
Von der Leyen is a member of the so-called "Christian Democratic Union" party, so yes, I'm pretty sure becoming the USA is the point. Christian Conservatives of a feather will flock together and all that.
They intend to simplify compliance, not axe the law. And this is needed if Europe wants to make itself independent of USA and China on the tech front.
You who are against this, have you ever had to deal with GDPR? It is a nightmare and I am certain American big tech is secretly celebrating it, because it kills any European startup alternatives, because they cannot afford to employ enough people to be compliant with the law and if they try to do it with existing personnel they don't have enough time left over to actually run their business.
If you have ever complained that there aren't enough European alternatives, GDPR and other legislation is the reason why. USA shoots itself in the foot with tariffs and we Europeans shoot ourselves in the foot with regulations. I am just really glad the EU commission has realized this and are fixing it.
have you ever had to deal with GDPR? It is a nightmare and I am certain American big tech is secretly celebrating it, because it kills any European startup alternatives, because they cannot afford to employ enough people to be compliant with the law and if they try to do it with existing personnel they don’t have enough time left over to actually run their business
Am DPO. What do you mean? GDPR is trivial to deal with and you do not need to employ additional personnel beyond a DPO. They don't even have to do it full time.
There are certain few business models that explicitly rely on exploiting personal data, but them being slowed down is very much the intention.
It is not trivial, the existence of you job makes that self-evident. If it was trivial companies wouldn't need a DPO, would they? I would love to see you walk up to your employer and tell them that your job is trivial and anyone can do it...
You might not see this yourself, but the fact that even a small company needs a DPO in order to interpret data protection regulation IS the problem! But I am sure you are not complaining... It needs to be simplified so a small company can be GDPR compliant without requiring a DPO.
This problem is recognized in the report from the EU commission linked in the article, which is why they are acting.
The fact that small startups cannot even take off because they cannot afford to hiring the bureaucrats required to interpret and be compliant with regulation is a massive problem and one of the reasons Europe's economy is stagnating. It is not about exploiting personal data, it is about the cost of bureaucracy killing European startups in their infancy.
Finally!!! GDPR strongly needs a revision. I work in healthcare in Sweden, where many hospitals recently have gotten a new digital journal system. In theory it would be a really good one, but because of GDPR we still have to rely on printing papers, and sending them to other clinics via post or fax. How in the world does that protect our privacy better than just using the digital services that are built to do this?!
All my patients expect me to have ready up on their medical history, and know what medications they take, so that I am up to date about what they need. But in order to do that, I first have to ask for their permission, and THEN open their journal. It has to be the other way around - that you can actively block healthcare personnel from reading your journal if you for some reason don’t want them to.
Revising the GDPR to make it less intrusive in healthcare, would increase our ability to see more patients and spend less time on administrative tasks, which I think everyone is positive to.
but because of GDPR we still have to rely on printing papers, and sending them to other clinics via post or fax
I don't know who told you this but that is certainly not mandated by GDPR. Could you elaborate on the situation?
All my patients expect me to have ready up on their medical history, and know what medications they take, so that I am up to date about what they need. But in order to do that, I first have to ask for their permission, and THEN open their journal. It has to be the other way around - that you can actively block healthcare personnel from reading your journal if you for some reason don’t want them to.
That is also not mandated by GDPR. I don't know who you DPO is, but at some point of the communication chain there must be a misunderstanding.
Lots of ad companies and other data harvesters who wanted to keep being evil put out a lot of misinformation about things the GDPR would outlaw, and some of it stuck, so plenty of people think the GDPR says things it doesn't. In general, you're safe as long as you don't do anything obviously dodgy or send data to a company likely to do evil things with it, but in a world where nearly everyone uses Google analytics to monitor if their site goes down, everyone had to change something and there was plenty of opportunity to scare people by telling them they needed to change more than they really did.
One thing that's symptomatic for anti-GDPR sentiment in general are "cookie banner" discussions. As if the EU had ever told anyone they need cookie banners! You absolutely don't need them if you're not randomly throwing around data. And people should know better, just from seeing titles on said cookie banners like "Your privacy is important to us and our 1234 partners" (and that's not even exaggerated!). In addition, "cookie banner" is a misnomer too, as the thing you're really setting up is not cookie behavior but data-spreading behavior.
As an addendum: At a former employer, we ran an online survey which we announced through a small notification on the page. I didn't want it to be too annoying, so included a "go away" button in the notification. That button wrote an extremely GDPR-compliant cookie that simply stored the preference. One of my co-workers was careless enough to casually mention this to a high-ranking American employee who then questioned me whether we shouldn't include that cookie on the cookie banner, etc. It took a while to set that straight.
That American was the same person who was responsible for combining browsing behavior on employer's website with a third-party chat provider, so either AI or human agents could open a chat box on specific people's screens and ask them creepily specific questions about whether they'd like to buy any of the products they'd been looking at on former employer's site over the past months.
There are a lot of people who don't even understand the basics of what GDPR is trying to do but whose job it is, to create GDPR-compliant things.
Actually, it's quite easy to comply with. Don't collect any data you don't need in order to conduct legitimate business with the person you're collecting data from. Delete collected data once you don't need them anymore. And you're done.
Maybe in your field? Tell that to healthcare workers. Don’t you want your doctor to know about your medical history and what medications you’re taking, without having to wait and see you first to be able to ask you? GDPR HAS to be revised.
Its not that complex in practice. The problem is that there it’s industry is trying to make it seem more complicated than it is so you’ll have to hire one of those contractors.
Seems to me like the EU wants to pander to the USA to get market access. Alphabet, Microsoft and Meta are licking their lips.