Hacker News new | ask | show | jobs
by timr 3 days ago
Likely has little relationship to what is actually in the page. They had to do GDPR, didn't or couldn't spend a lot of time on it -- or had an especially conservative corporate counsel -- and ended up just getting a list of every company they've ever worked with, for any reason, "to be safe".

For most companies this can easily be thousands of partners, and going through that list and figuring out exactly who might get data in reality, through every possible permutation of workflow, is a horrendously expensive proposition.

You might be surprised how many well-meaning regulations leave even the best-intentioned implementers in an impossible situation.

2 comments

Oh yeah, that combination of fear and lack of knowledge probably plays a big part. I was once involved with creating a privacy policy for a B2B(!) web application. What a farce. In the end, the process was cut short (counsel too expensive and not nearly familiar enough with tech). The resulting document was at least 50 % stuff the app simply does not do.
> or had an especially conservative corporate counsel

And once again we shall see how being conservative sounds like it might save you money but costs you dearly in the long run.

Yeah, but again, see the other part of what I wrote -- doing it "right" can be insanely expensive, and so you get an incentive to be conservative.
I read what you wrote.

Ultimately that is what they are having to do though, it's just costing them twice as much by pretending that being conservative and not actually looking at the problem saved them.