Live data from Hacker News

EU data protection law after the Safe Harbour judgment

eulawanalysis.blogspot.com

1–10 of 80 posts

Re: EU data protection law after the Safe Harbour judgment

#2
In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

Re: EU data protection law after the Safe Harbour judgment

#3

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

The cost will also be massively reduced profits at companies that handle small volumes of data globally.

Re: EU data protection law after the Safe Harbour judgment

#4

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

> The main outcome will be that more engineers will be needed to do more work

https://en.wikipedia.org/wiki/Parable_of_the_broken_window

Artificially creating additional work by imposing additional requirements does not necessarily improve the situation just because it employs people to do that work, whether you personally like those requirements or not.

Re: EU data protection law after the Safe Harbour judgment

#5
post #3

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

The cost will also be massively reduced profits at companies that handle small volumes of data globally.

If those companies can't remain profitable without being irresponsible with sensitive private data then maybe they shouldn't exist at all.

Re: EU data protection law after the Safe Harbour judgment

#6

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

> The main outcome will be that more engineers will be needed to do more work https://en.wikipedia.org/wiki/Parable_of_the_broken_window Artificially creating additional work by imposing additional requirements does not necessarily improve the situation just because it employs people to do that work, whether you personally like those requirements or not.

This is a good thing, IMO. It's like having a shoddy builder who builds a poorly insulated house and then screams - hey, your house will be more expensive if I build it properly. But the builder has plenty of profits with which to take the hit. Consumers are already trading off their data for services (like Facebook). If the costs were so high that Facebook or Google needed to pass on real costs to consumers, there might be an issue. But the costs won't be that high. It's just a bit more work to build it right.

Re: EU data protection law after the Safe Harbour judgment

#7

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

> The main outcome will be that more engineers will be needed to do more work https://en.wikipedia.org/wiki/Parable_of_the_broken_window Artificially creating additional work by imposing additional requirements does not necessarily improve the situation just because it employs people to do that work, whether you personally like those requirements or not.

In contrast to the parable you are citing, the only thing broken in this case is the privacy of european citizens.

The ruling to declare "Safe" Harbor invalid is not breaking anything but a step to fix a system that is systematically violating constitutional rights.

In the light of US companies not effectively safeguarding european data against access by US authorities, judgements are needed to rectify the situation.

Re: EU data protection law after the Safe Harbour judgment

#9

In general, this is a very good thing. The main outcome will be that more engineers will be needed to do more work to ensure that data is handled more carefully. The cost will be slightly reduced profits at companies that handle large volumes of data globally. What's bad about that?

> The main outcome will be that more engineers will be needed to do more work https://en.wikipedia.org/wiki/Parable_of_the_broken_window Artificially creating additional work by imposing additional requirements does not necessarily improve the situation just because it employs people to do that work, whether you personally like those requirements or not.

The parable of the broken window weighs what is seen (the payment to the glazier) with what is not seen (the missed payments to other things that could've been purchased had the window not been broken).

In the case of safe harbour, the window was already broken. Data being passed from Europe to the US was not being handled correctly, despite the promises inherent in Safe Harbor.

If protections had already been in place (i.e. if data service providers were actually adhering to the promises of safe harbour) then service providers have already fixed the window. Those that were safeguarding data correctly have no further engineering work to do (although there might be further regulatory/compliance effort to prove it depending on how individual nations implement the stopgap safeguard laws to replace Safe Harbor).

The only engineering work required to "fix the window" is work that should already have been done according to the safe harbour agreements, and threads like this prove how broken Safe Harbor was to begin with.

Re: EU data protection law after the Safe Harbour judgment

#10
> Since the Court refers frequently to the primary law rules in the Charter, there’s no real chance to escape what it says by signing new treaties (even the planned TTIP or TiSA)

Oh good, I was worried a little about that one.

> Undoubtedly (as the CJEU accepted) national security interests are legitimate, but in the context of defining adequacy, they do not justify mass surveillance or insufficient safeguards.

Another good thing. I wasn't sure if this ruling affects spy agencies, too, or just companies.

Post reply on HN