logoalt Hacker News

epihelixtoday at 2:35 PM2 repliesview on HN

Companies don't really care about rules per se. They care about their risk appetite, and whether the consequences of their actions create risk above that appetite level.

The simple calculus is: will it cost me more to comply, or more to ignore? If a company chooses the more costly option, they are betraying their shareholders and being managed poorly.

If you do not fine early and often, you are almost mandating that companies ignore the legislation. If this continues for several years, then you almost make it impossible to turn around later and fine, as businesses will want to know what's changed now. You will create an impression of uncertainty and instability, which is the last thing businesses want, and the last thing you want to do to encourage investment.

If you just set and enforce the rules from the start, then everyone can relax, do the right thing and be happy about it. It's funny how rarely this actually seems to happen.


Replies

maccardtoday at 3:38 PM

I will say;

> will it cost me more to comply, or more to ignore?

Is an (unfortunately) American view of things. The vast majority of European businesses I’ve worked with attempt to comply with the _spirit_ of the laws, while my experience with most American companies is they try to skirt the letter of the law to do whatever the hell they want.

I’m not saying one is better, or that all companies in both places are like that. But it rings true in my experience.

herbsttoday at 3:36 PM

Don't get me wrong but it sounds like you are applying a foreign logic to the EU system without understanding how these things usually work here.

I personally happily followed GDPR rules, so did many others. Making it generally a better place. That wasn't because of fines but because we now had a framework to follow to make the world a safer place.