Kyle Harrison
concept

GDPR

GDPR

GDPR (the EU’s General Data Protection Regulation) surfaces in Kyle’s notes through Todd McKinnon’s Todd McKinnon — Creating and Defining a New Market Category interview as a case study in how privacy regulation can backfire against the small players it was meant to protect. McKinnon’s argument: GDPR “really was not directly, but really in a lot of ways came down because of the big social media companies and what they do with data,” yet “GDPR in a lot of ways has hurt the small providers because they’re the ones that don’t have the resources to comply with handling this data and doing it in a secure and scalable way.” The net effect, in his telling, is to put “the big platforms at an unfair advantage” — the opposite of the regulation’s ostensible intent.

McKinnon ties this to Okta’s ambition in Customer Identity & Access Management (CIAM): rather than owning every login, Okta wants to reach enough scale to help “set this standard in the world” so that compliance, privacy, and security become uniform and more controllable by the end-user — easing exactly the burden GDPR-style regimes impose on smaller technology companies.

Context: The General Data Protection Regulation is the European Union’s data-privacy law, in force since May 2018, governing how organizations collect, store, and process the personal data of EU residents, with large fines for non-compliance.

Where this appears