Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Monday, 27 May 2019

Some take-aways and personal after-thoughts on competitiveness, financing and platform ecosystems following IBA's Global Entrepreneurship Conference


For various reasons, I have not posted anything here in ages. I have been active otherwise and, for example, have written our firm's M&A and Corporate Finance Update. Anyways, this time I decided to focus on some issues other than ICT agreements or M&A and generally look at the market trends and views from the Nordic point of view. The main topic was discussed at the 5th IBA Global Entrepreneurship Conference "The Nordic model—rising up to the global challenge in Copenhagen" earlier this week.

One of the most interesting discussions was about how in Norway start-ups were able to get funding relatively easily, but the problem was that exits take place too early. After the panel, we actually continued discussions on the topic with my fellow colleagues from Sweden. I do not think that the question about the early exits was approached from the financing point of view. My personal view is that the exit stage usually coincides with hitting the "funding cap". By this I mean a stage when it is difficult for a growth company to get additional funding. Naturally, this stage where this funding cap exists, e.g., from €2 million upwards or something else, just varies slightly depending on the Nordic country in question. So in Finland, the exit stage is reached earlier than in Sweden for example. This would also explain why valuations in M&A context are higher in Sweden than in Finland—the companies in Sweden are developed further before exit as the funding cap is higher. Of course, there are other reasons as well, but it would seem to be quite human a trait that if there is a funding cap, additional growth starts feeling difficult and burdensome and next financing round would seem to require massive efforts and so forth, and therefore you start considering that it might be a good time to exit. Also by that time you might have already achieved enough to cover your personal expenses and paid your home mortgage, so this decision is even easier. On the other hand, it has been said that at least in Norway 2/3 of hirings are done by private firms so these entrepreneurs are also serving a valuable purpose. I would encourage anyone to find solutions to keep entrepreneurs interested in growing their companies even further and postponing this exit stage.

One of the main concerns we should all have is the low level of investments in R&D, especially in this global competitive environment in which we in Europe are lacking behind the US and China. While companies such as Amazon and Google have massively grown during the past few decades, we have not been able to establish quite similar success stories here in Europe. This can also be further be illustrated by looking at the R&D budget figures and activities of FANG (Google, Facebook, Netflix & Amazon):


And here, in this era of large platforms and massive concentrations of data why large platforms prevail and so many companies fail in data sciences? Well, in data sciences area it is not sufficient to have only one of the four described above, but you most likely need all four elements to create a winning strategy. 


Let’s take another topic that was discussed a lot in the conference as an example—GDPR, data protection and data security. This is an important subject but in the context of this blog posting when talking about Nordic firms and their competitive position in the global market, taking into account the insufficient investments in R&D, one can validly ask whether we have made a smart decision to invest such a large sum of resources in the protection of personal data and whether this investment is something that European firm can actually turn as a competitive advantage? One firm mentioned that they have spent approximately €3 million on GDPR compliance here in Europe, and therefore the valid question is whether the company will be able to earn back this investment? How long will it take? Or, if the company had spent, perhaps together with some other firms, the same amount on R&D focusing on the creation novel business models based on advanced data analytics or artificial intelligence, would it be in a better competitive position against its US or Chinese counterparts? In case of GDPR, this decision to invest has already been made so now it would be time not to be scared about the consequences and focus on sanctions and sanction levels, which I understand are interesting at least for lawyers but, instead, to focus on the creation of additional value, ways of turning data protection and privacy and the legislative framework into a competitive advantage for European firms. For Finnish firms, I do find it difficult to compete against these global platforms with our limited resources, but there are so many things to do "on top" of these platforms.

Looking forward to hearing your views on this and, in the meanwhile, have a splendid continuation of your week and greetings to all familiar and new faces at the IBA, we'll see you in Amsterdam next year!

Regards,

Jan



Friday, 27 April 2018

Onko väite “cookiet käsitellään vasta ePrivacy Regulationissa” totta ja mitkä ovat 5 keskeisintä korjauskohtaa?

Yllä mainittu väite tulee usein esille yrityksien kanssa keskustellessa. Lähtökohtaisesti väite sisältää kaksi erillistä kysymystä: a) millä edellytyksillä cookie tai kotimaisesti eväste on tietosuoja-asetuksen mukaan henkilötieto itsessään tai yhdessä muiden tietojen kanssa; ja b) miten cookieihin tulisi GDPR:n aikana suhtautua vai tarvitseeko? Tässä käsitellään jälkimmäistä eli tulisiko evästeitä koskevat ohjeistukset uusia jo nyt vai voiko asian käsittelemisen siirtää tulevaisuuteen noin vuoteen 2020, kun ePrivacy ehkä tulee voimaan? 

Mitä cookiet ylipäänsä ovat ja miten ne toimivat? Teknisenä johdatuksen aiheeseen ohessa eräs verkosta löytynyt sitaatti:

"Cookies allow a Web site to store information on a user's machine and later retrieve it. The pieces of information are stored as name-value pairs.

For example, a Web site might generate a unique ID number for each visitor and store the ID number on each user's machine using a cookie file.

If you type the URL of a Web site into your browser, your browser sends a request to the Web site for the page (see How Web Servers Work for a discussion). For example, if you type the URL http://www.amazon.com into your browser, your browser will contact Amazon's server and request its home page."

Evästeet alun perin kuuluivat sähköisen viestinnän tietosuojadirektiivin alaan (direktiivi 2002/58 / EY ja vuoden 2009 päivityksestä, direktiivi 2009/136 eli ns. "ePD"). Siitä tuli EU: n jäsenvaltioissa kansallista lainsäädäntöä asteittaisella täytäntöönpanolla johtaen kansallisiin eroihin ja toisin sanoen melko epäyhtenäiseen täytäntöönpanoon eri maissa. Tietoyhteiskuntakaaren 205§:n mukaan: 

"Evästeiden tai muiden palvelun käyttöä kuvaavien tietojen tallentaminen käyttäjän päätelaitteelle ja näiden tietojen käyttö on sallittua palvelun tarjoajalle, jos käyttäjä on antanut siihen suostumuksensa ja palvelun tarjoaja antaa käyttäjälle ymmärrettävät ja kattavat tiedot tallentamisen tai käytön tarkoituksesta. Edellä säädetty ei koske tietojen sellaista tallentamista tai käyttöä, jonka ainoana tarkoituksena on toteuttaa viestin välittämistä viestintäverkoissa tai joka on välttämätöntä palvelun tarjoajalle sellaisen palvelun tarjoamiseksi, jota tilaaja tai palvelun käyttäjä on nimenomaisesti pyytänyt. Edellä tässä pykälässä tarkoitettu tallentaminen ja käyttö on sallittua ainoastaan palvelun vaatimassa laajuudessa ja sillä ei saa rajoittaa yksityisyyden suojaa enempää kuin on välttämätöntä."



On olemassa useita aloja, joilla nykyinen ePrivacy Regulation luonnos ja GDPR ovat epäjohdonmukaisia ja aiheuttavat näin sivustojen omistajille monimutkaisuutta. Cookiet ovat yksi näistä. Teoriassa GDPR korvaa evästeiden kansalliset lait, mutta se koskee vain evästeiden osajoukkoa, joka käsittelee henkilötietoja, joten muut evästeet kuuluvat edelleen ePrivacy-direktiivin piiriin. GDPR:n soveltamisalaan kuuluvat evästeet voisivat vedota oikeusperustaan, joka ei ole suostumus, josta ilmeisimmin oikeutetut edut. Koska suostumus on ainoa oikeusperusta voimassa olevan ePD:n sisällä välttämättömiä evästeitä lukuun ottamatta, syntyy mielenkiintoinen tilanne, jossa ei-henkilötietointensiivisellä evästeellä, esimerkiksi eväste tallentaen tietoja näytön koosta, voi olla GDPR:ää tiukempia suostumusvaatimuksia. Tämäntyyppinen eväste ei tallenna riittävästi tietoja, jotta sitä pidettäisiin henkilötietoina, joten GDPR ei sovellu, mutta se ei myöskään todennäköisesti ole "ehdottoman välttämätöntä", sillä sivuston tarvitsisi vain nämä tiedot yhteen istuntoon. Se voi olla hyvä optimointia ja suorituskykyä varten, mutta se ei ole "välttämätön eväste".

Miten käytännössä GDPR:n voidaan arvioida vaikuttavan henkilötietointensiivisiin evästeisiin käytännössä ja mitkä viisi asiaa tulisi huomioida evästepolicyjä mietittäessä:

1) Implied consent eli "käytökseen perustuva suostumus" ei riittävä
2) Suostumuksen tapauksessa oltava oikeus peruuttaa
3) Peruutuskeinon oltava yhtä helppo kuin suostumuksen antamisen
4) Evästepolicyjen uusiminen huomioiden edellä kuvatut lainsäädännön jaon mukaiset erityyppiset cookiet tuntuu perustelluimmalta vaihtoehdolta
5) No track – asetuksia kunnioitettava

Nyt ei muuta kuin uusimaan cookie policyjä ja samalla erinomaista Wappua kaikille! Lisätietoja cookie policyistä ja niiden uusimisesta tästä linkistä!

Yt.

Jan