I believe there are sequel MMOs to it and they likely didn't want to pay any developers to deal with the changes that they would otherwise pay to work on their new stuff.
I'm sure that's true. But Ragnarok Online is probably the first GDPR affected business I've heard about that I would believe:
1) Paid some actual lawyers to look at compliance
2) Looked at the revenue they are currently getting in the EU
3) Looked at the engineering effort and cost they would have to expend to come into compliance
4) Compared 2 & 3 and decided to pull the plug
It's interesting to me because this is the first solid evidence that GDPR does have a real cost to a business isn't a bad actor in spite of what many people otherwise claim.
I work at a big company and we are expending huge effort and expense to become GDPR compliant, even though we weren’t really doing anything sketchy beforehand.
I can totally see the sites that caused the GDPR to become a thing on the list. What an incredible job EU bureacrats, keep it up, it's not like the economy here doesn't need more rules.
GDPR is a double-edged sword. On one hand, it's a great step toward enforcing accountability on international companies and the data they have that gives them incredible influence over the world.
On the other hand, I can attest to the pain its caused to smaller companies having to implement support for it, and while some of the companies that have shut down were apparently using user data in detestable ways, I'm sure it's got a lot of companies scrambling.
Can we stop with the "not complying means you're using data badly" meme? That's true for some, but most people who aren't the compliance officers for their companies don't know how much documentation and detail work this law involves that has nothing whatsoever to do with how the data is being used. Hell, I spent at least half my week sending out DPAs and guiding clients through the signature process.
The GDPR has massive costs, and the 90% of companies that aren't villains are going to bear about 90% of them.
It's more like a hall of shame, unless you were doing something bad with user data on purpose you should have covered 90% of the GDPR anyway.
A few things might have been missed because they are not super common:
1. Data export
2. DPO or DPO-ish person (which simply might be you, the developer)
3. Actually writing down somewhere what data you store, how, where and why (which is a lot easier to do than you'd think -- again unless you are trying to hide that on purpose)
We really need something like the GDPR, and it can't be opt out. There is far too cavalier an attitude by almost all businesses toward your information and they never really suffer any penalty for their recklessness. And there are quite a few genuine bad actors who really need to get reined in.
I also hope that once the GDPR is in effect, there will be some adjustments to it when everybody starts figuring out what works, what doesn't, and what's expensive.
However, the GDPR probably should have had some sort of "grandfather" clause that would have applied to something like Ragnarok Online. Bringing a code base of that age into compliance would probably require a massive engineering effort that completely swamps the revenue they are currently getting.
Lots of people are, at least in spirit. The current American internet is a convoluted panopticon, and many want to see more transparency and simplicity around where information about them is going.
The costs may be large and many companies may leave, but China has shuttered out these same companies and they've done well to solve their needs from within the country.
Of course China's goals were much different than citizen's rights.
Cointouch.com looks like it also could have seen some unwanted attention from the SEC, and any number of state securities agencies, as well as FinCEN, due to the nature of facilitating unlicensed financial services and unregistered securities. Looks like the site's owner was genuinely trying to help facilitate p2p transactions that help people, so I appreciate the conservative approach to minimizing further risks. This next month will be full of interesting examples of how this gdpr saga will unfold.
27 comments
[ 4.1 ms ] story [ 89.5 ms ] threadEDIT: D'oh, just noticed the "Fork me on GitHub" banner. Okay, then!
That's one site that I wouldn't regard as either "good riddance" or "grandstanding".
I wonder what went into their calculation that caused them to decide to shut down.
1) Paid some actual lawyers to look at compliance
2) Looked at the revenue they are currently getting in the EU
3) Looked at the engineering effort and cost they would have to expend to come into compliance
4) Compared 2 & 3 and decided to pull the plug
It's interesting to me because this is the first solid evidence that GDPR does have a real cost to a business isn't a bad actor in spite of what many people otherwise claim.
(E.g. the linked article for ragnarok mentions that just eu access is being closed)
What’s funny is that some folks think that highlighting the problems with GDPR, things might change. That is laughable. The politicians. Don’t. Care.
You reap what you sow, Euros.
On the other hand, I can attest to the pain its caused to smaller companies having to implement support for it, and while some of the companies that have shut down were apparently using user data in detestable ways, I'm sure it's got a lot of companies scrambling.
Interested to see what happens after the 25th.
The GDPR has massive costs, and the 90% of companies that aren't villains are going to bear about 90% of them.
A few things might have been missed because they are not super common:
1. Data export
2. DPO or DPO-ish person (which simply might be you, the developer)
3. Actually writing down somewhere what data you store, how, where and why (which is a lot easier to do than you'd think -- again unless you are trying to hide that on purpose)
Sure, the companies might be "hysteric", but I don't think this list is aimed to spread that hysteria.
Edit: removed remark about reaction
We really need something like the GDPR, and it can't be opt out. There is far too cavalier an attitude by almost all businesses toward your information and they never really suffer any penalty for their recklessness. And there are quite a few genuine bad actors who really need to get reined in.
I also hope that once the GDPR is in effect, there will be some adjustments to it when everybody starts figuring out what works, what doesn't, and what's expensive.
However, the GDPR probably should have had some sort of "grandfather" clause that would have applied to something like Ragnarok Online. Bringing a code base of that age into compliance would probably require a massive engineering effort that completely swamps the revenue they are currently getting.
The costs may be large and many companies may leave, but China has shuttered out these same companies and they've done well to solve their needs from within the country.
Of course China's goals were much different than citizen's rights.
You have a few hundred customers and maybe 10 of those are in Europe.
Would that company need to worry about complying? How much should they worry?