It is downvoted because you say something is a failure without backing it up, when GDPR is actually a success for privacy and consumers everywhere.
1. Marketing consent has now to be explicitly asked for when signing up for any service. Companies cannot enrol you to one if you didn't ask for it.
2. Right to be forgotten. You can request a company to erase all your private data they hold on you.
3. Companies have to legally report data breaches within 72 hours after becoming aware of it.
4. Penalties for companies who do not take privacy seriously.
5. Companies can no longer just hoard sensitive/private data unless they have a reason for it.
6. Selling private data from company to company now requires original consent from the user (this stopped a lot of businesses selling lists for lead gen, call centres, etc)
7. Companies treat private data as a liability now, making them ask themselves additional questions whether it needs to be stored or processed at all, and if so, put additional security fences around it.
This list can go on for ages. I don't see these benefits and additional rights for hundreds of millions people out there as a failure. It's a win win for consumers.
One example is data retention. Previously, data could and and was just keep around forever. With the GDPR, when you delete stuff, you can now expect it to actually be deleted from backend storage, usually within 30 days or less (yes, there are exceptions). This is nice, since it does limit your exposure in case of a breach. Speaking of breaches, they also have to be reported in a timely manner. Without the GDPR or equivalent, companies are free to suppress that as long as they want, and have done so.
Comments
Good for them, I wish EU did it too. GDPR is such a failure.
Edit: Why is this downvoted? What exactly did GDPR accomplish except for making our web experience a mess, both for businesses and users.
It is downvoted because you say something is a failure without backing it up, when GDPR is actually a success for privacy and consumers everywhere.
1. Marketing consent has now to be explicitly asked for when signing up for any service. Companies cannot enrol you to one if you didn't ask for it.
2. Right to be forgotten. You can request a company to erase all your private data they hold on you.
3. Companies have to legally report data breaches within 72 hours after becoming aware of it.
4. Penalties for companies who do not take privacy seriously.
5. Companies can no longer just hoard sensitive/private data unless they have a reason for it.
6. Selling private data from company to company now requires original consent from the user (this stopped a lot of businesses selling lists for lead gen, call centres, etc)
7. Companies treat private data as a liability now, making them ask themselves additional questions whether it needs to be stored or processed at all, and if so, put additional security fences around it.
This list can go on for ages. I don't see these benefits and additional rights for hundreds of millions people out there as a failure. It's a win win for consumers.
The web "experience" was already a mess.
One example is data retention. Previously, data could and and was just keep around forever. With the GDPR, when you delete stuff, you can now expect it to actually be deleted from backend storage, usually within 30 days or less (yes, there are exceptions). This is nice, since it does limit your exposure in case of a breach. Speaking of breaches, they also have to be reported in a timely manner. Without the GDPR or equivalent, companies are free to suppress that as long as they want, and have done so.
I advise you to go back and read the law again. What you describe doesn’t happen and it’s not even enforced by it.
Storage limitation: https://ico.org.uk/for-organisations/guide-to-data-protectio...
Personal data breaches: https://ico.org.uk/for-organisations/guide-to-data-protectio...
Right to erasure: https://ico.org.uk/for-organisations/guide-to-data-protectio...