Interview, Podcast
a16z Podcast | What to Know about GDPR
- GDPR enforcement is imminent, with long-arm jurisdiction expected to regulate nearly all companies, including U.S. entities without elected representation, by merging 28 member state laws into a single regime of 260 pages, 99 sections, and 173 recitals.
- Companies face broad scope coverage for EU citizens regardless of location, triggered by offering goods/services (e.g., translations, EU contact numbers), monitoring, or profiling activities, potentially affecting over 80–85% of the U.S. population identifiable by just three data points.
- The definition of personal data is expansive, covering online identifiers, location data, genetic information, and combinations of data that enable identification, while fully anonymized data remains out of scope but is increasingly challenged by machine learning triangulation.
- Startups possess a strategic advantage due to organizational nimbleness, enabling rapid infrastructure changes and self-directed risk assessments, whereas large enterprises risk paralysis from coordinating 400 disparate groups with varying data sets and policies.
- Both data controllers and processors face strict liability where third-party contractors are classified as subprocessors, requiring the original company to ensure compliance, with no liability reduction achieved by hiring external vendors.
- EU regulators anticipate a "bottom-up" enforcement model relying on individuals to file complaints regarding data subject rights, which include access, portability, erasure, objection to direct marketing, and human review of automated decisions.
- Compliance requires embedding "privacy by design" and "data protection by default" into engineering, prioritizing defaults that facilitate data deletion, transparency, and user-centricity, with a 72-hour mandatory notification window for data breaches.
- Penalties may reach up to 4% of global turnover, though fines are a last resort; regulators prioritize investigation and corrective actions, with fines influenced by negligence or intent.
- Organizations must prepare for breach responses via checklists, call lists, and scenario testing, fostering a "speak up culture" to avoid deferred prosecution agreements resulting from poor reporting habits.
- No official GDPR certification exists, yet compliance is expected to become a standard feature in sales contracts and EULAs using Standard Contractual Clauses for data transfers.
- Infrastructure type (cloud, on-premise) is irrelevant to applicability if a user can sign on, and a detailed inventory of usernames, addresses, and account histories is required to reveal unassessed risks.
- Effective leadership for compliance projects requires a "risk sentinel" with a detail-oriented, forward-thinking background in fields like engineering, risk, or audit, rather than solely dedicated compliance roles.
- Core principles mandate that data collection be adequate, necessary, and non-excessive, with consent as the foundation, while specific data types like IP addresses, email addresses, and genetic information are classified as personally identifiable.