Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

61–70 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#61
post #17

The US needs a law that exempts American businesses from GDPR if they have no presence in Europe.

If you don't do business in the EU you don't really have to care?

We'll see how this pans out but I'm not confident the legal system will prove logical, especially with something as vague as the GDPR.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#62

Earlier quoted context omitted.

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

And if you tried to sketch out what should be in that EULA, you'd probably want to know: - What data is being collected about you - What they're doing to keep that data reasonably secured - Who to contact should have you detect some security issue - How to request that the company stop using your data .....and we've reinvented the GDPR.

Well, GDPR requires that you do those things. A clear EULA that says we don't do any of those things so if you don't like it don't use our service would still be illegal under GDPR, right?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#63

Such a law will not survive a Constitutional challenge. Just rent seeking by an incumbent.

These recently-discovered European "rights" are probably non-starters, but the ability to get a Google-takeout style package of your own data, and some reasonably protections regarding consent and the way your data is used would clearly Constitutional. We already force some industries to follow most of these precepts in other laws that haven't been challenged: credit agencies have to explain your credit score to you, HIPAA manages how medical data is used. The core of GDPR is really just expanding those laws to all companies.

The only sticky one is really the "right to be forgotten," which just isn't a right, and possibly has constitutional (1st amendment) problems.

IMO though, a "conservative GDPR" could get Republican backing by basically framing it as a question about property rights, which their base is all about: your data is valuable, and it's YOUR property, not Google's. Some of the other provisions could be sold as a "sunshine law" for big business.

Also resumably, given US politics, there would be plenty of exemptions for small businesses (and industries that have strong lobbying firms).

(note that I'm not a lawyer, so this may be bullshit)

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#64

Earlier quoted context omitted.

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

It is a guaranteed right enshrined in the EU's Constitution[0] (Charter of Fundamental Rights of the European Union[1]). Specifically Title II Freedoms: privacy, protection of personal data. That's like claiming the 1st Amendment in the US is just a "magic right." [0] https://en.wikipedia.org/wiki/Treaty_establishing_a_Constitu... [1] https://en.wikipedia.org/wiki/Charter_of_Fundamental_Rights_...

interesting that hardly any eu governments respect that right

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#65

Earlier quoted context omitted.

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

>You don't own information about you. What are your credit card numbers? :)

A better analogy is - what is your credit score?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#66

Earlier quoted context omitted.

It is a guaranteed right enshrined in the EU's Constitution[0] (Charter of Fundamental Rights of the European Union[1]). Specifically Title II Freedoms: privacy, protection of personal data. That's like claiming the 1st Amendment in the US is just a "magic right." [0] https://en.wikipedia.org/wiki/Treaty_establishing_a_Constitu... [1] https://en.wikipedia.org/wiki/Charter_of_Fundamental_Rights_...

See above my comment about practicality. It takes no effort for me to not violate your first amendment rights. It's a negative right, not a positive right.

It takes no effort for you not to violate Title II, just don't ask for other people's personal information.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#67

Earlier quoted context omitted.

And if you tried to sketch out what should be in that EULA, you'd probably want to know: - What data is being collected about you - What they're doing to keep that data reasonably secured - Who to contact should have you detect some security issue - How to request that the company stop using your data .....and we've reinvented the GDPR.

Well, GDPR requires that you do those things. A clear EULA that says we don't do any of those things so if you don't like it don't use our service would still be illegal under GDPR, right?

No, that wouldn't be illegal. Please can you point to the bit of GDPR which you think would make it illegal?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#68

Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?

Why? For residential users a single IP address is connected to either a single person or a small set of individuals.

When websites use IP addresses as an authentication factor because they change so infrequently that it's when it does it's hard to argue that you can't identify users by the source of their traffic.

Plus the addresses themselves betray personal information. If you use my service I can know a great deal about you by your source addresses.

* You shop at Target, but sometimes Wal Mart when you're in a rush.

* You get coffee at the Starbucks on 5th every morning.

* You live on 2365 Chestnut Dr.

* I know where all your friends live and how often you visit them.

* You used to go to this one apartment a lot late at night, but not anymore. How are you dealing with the breakup?

* You work in the office building on Main.

* You went to a Mercedes dealership. You deserve it after all emotional stress you've been though.

* You went to a fancy restaurant yesterday, date night?

* You're coming from a couples retreat in Cali, I'm so happy for you! Getting back out there.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#69
post #3

A consumer protection law like GDPR would probably be a good thing for US, but it's hard not to see this as SFDC saying, "As a multibillion-dollar SaaS vendor, we welcome regulation that might slow down or prevent a competitor from unseating us."

What you don't realize is that the lawlessness around user data hurts big corporations too. If you're a big corporation collecting significant data than you've taken on a significant liability but the nature of this liability is amorphous. How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? How much can you share in your api? What if you sell the data to a foreign firm and that firm turns out to be the Russian government? What happens when a client sues you and claims you caused harm to her because you have the wrong data about her?

Every corporation has to answer these questions but right now they have to do it with no real guidance from the government. This makes the data a ticking time bomb. It's not clear what can be done with it or even how much it's worth. It's not clear what best practices exist in terms of technologies and ethical guidelines.

That said nobody expects something like the GDPR too happen in America. Pretty much every other country will adopt similar laws though. If Americans are lucky they'll get some benefit from that.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#70
post #44

Earlier quoted context omitted.

Considering that these rules don’t apply to governments, and that European governments generally seem to be slipping towards jailing people for thought crime, I’m skeptical as to how serious they are about privacy and control of personal data.

Please if you can, give one example of a European government jailing someone for a thought crime. To save us both time and aggravation please keep the actual definition of “thought crime” in mind, and don’t conflate it with something people actually did .

Expression of thoughts can definitely be a crime. Saying that you support X Y or Z organization or ideology can definitely see you jailed.

There is also a trend, even in the US, towards keeping some prisoners behind bars for thinking certain thoughts. Sex offenders in many US states can be held long after their sentences based on mental health determinations, determinations that turn on their response to questions: their thoughts. Whereas expression of thoughts can be clearly illegal (ie hate speech) simple consumption, reading, of such thoughts can land the reader in jail too. Governments aren't yet crawling into people's heads, but they are certainly willing to criminalize the communication of illegal thought.

Post reply on HN