Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

111–120 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#111
post #35

Earlier quoted context omitted.

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

> GDPR...creates magical rights where none exist. You don't own information about you. Data is data. You could literally say that about any property right ever. For instance: common law creates magical rights where none exist. You don't own your toothbrush. Matter is matter. The law can create rights. That's how most rights are created.

I'm a fan of privacy legislation, but your comparison is a little strained in my opinion.

You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me.

Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service.

In general, I think we want services to collect no more data than necessary, discard it as soon as possible, protect what they must store, and disclose it to others as rarely as possible. But all of those things are murkier than "don't take my toothbrush."

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#112
post #99
post #3

A consumer protection law like GDPR would probably be a good thing for US, but it's hard not to see this as SFDC saying, "As a multibillion-dollar SaaS vendor, we welcome regulation that might slow down or prevent a competitor from unseating us."

This is exactly why he's saying it. Anyone who follows Benioff and the Oracle ilk knows this. Which is why GDPR needs to be scaled appropriately so that it fosters innovation while still protecting customers interests. Having a lower bound of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.

€10M is not the lower bound in penalties. It's the upper bound for breaches of data protection obligations (except for very large companies, with turnover >€500M/y).

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#113

Earlier quoted context omitted.

It is a guaranteed right enshrined in the EU's Constitution[0] (Charter of Fundamental Rights of the European Union[1]). Specifically Title II Freedoms: privacy, protection of personal data. That's like claiming the 1st Amendment in the US is just a "magic right." [0] https://en.wikipedia.org/wiki/Treaty_establishing_a_Constitu... [1] https://en.wikipedia.org/wiki/Charter_of_Fundamental_Rights_...

See above my comment about practicality. It takes no effort for me to not violate your first amendment rights. It's a negative right, not a positive right.

There are plenty of rights that aren't "practical". The right to vote is a HUGE pain in the ass, you have to organize massive elections. Property rights means you have to have huge police forces. The right to protest comes with enormous practical difficulties. The right to education means that you have to have expensive public school systems. The right to an attorney in a criminal trial means that the court has to provide one, at some expense. All of these are "rights", in all modern free countries, and they are all "magical rights created by law". That's what a right IS.

You're making the wrong argument. You're saying "this is not a right that can logically exist", which is nonsensical. Of course it can. What you should be arguing is "this right is far too burdensome on society and should not have been passed". I personally disagree with that, but it's at least a valid argument.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#114
post #75

Earlier quoted context omitted.

I 100% agree. The problem is that practically rights have to be reasonably respectable (able to be respected) by people at little cost to them. Like, it's not difficult for me to not steal something from you. Erasing everything I ever wrote down about you is difficult. But also: > Seems like Europe has decided that privacy and control of data personal data is something they want. The problem here is that governments…

> Erasing everything I ever wrote down about you is difficult. It is not difficult to avoid storing data you don't need. You don't need a user phone number? Easy, don't ask for it. Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this…

>It is not difficult to avoid storing data you don't need.

Access logs for one thing are pretty unreasonable to force people to avoid storing.

>Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.

Can you point out a specific example of somebody suffering actual damages from this "abuse?"

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#115
post #72

Earlier quoted context omitted.

When can Congress pass a law requiring newspapers to delete information it has collected about somebody?

They've done so in other industries a couple times with HIPAA and FERPA. What makes newspapers different?

FERPA's tied to federal funding.

The constitution specifically calls out for a "free press."

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#116
post #83

Earlier quoted context omitted.

The general claim people make suggesting things like Right To Be Forgotten or Right To Privacy is that it violates "free speech", and particularly, that via Citizens United, the US currently claims corporations have the right of free speech. Google believes, for instance, all limitations on how it provides search results as an infringement on Google's right to "say" whatever they want. Of course, we already have a va…

> [a] Right To Privacy is that it violates "free speech" Copyright is settled law that definitely limits the kinds of speech people can engage in. Couldn't you construct a right to privacy by first saying an individual has an automatic ownership right to certain kinds of personal data [1], and that data can't be used without an appropriately constructed license [2]? [1] You might be able make this strong and compatib…

I, personally, do not believe there is any disagreement between the Constitution and GDPR. In fact, a right to privacy has long been inferred by combining traits of a few amendments: https://en.wikipedia.org/wiki/Right_to_privacy#United_States (Of course, that constructed right is a right to privacy specifically from government actions.) And generally, we've recognized that some rights such as speech, may need to have limits to avoid encroaching upon other rights, such as privacy.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#117
post #72

Earlier quoted context omitted.

When can Congress pass a law requiring newspapers to delete information it has collected about somebody?

They've done so in other industries a couple times with HIPAA and FERPA. What makes newspapers different?

The way that works (and in fact the way that classification of government secrets works in the US) is that this information is 'born secret'.

This information is has to be kept away from the public, including journalists, but there is no law preventing journalists from publishing information about someone's health. HIPAA doesn't cover journalists, it just prevents covered entities from giving journalists information.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#118

Earlier quoted context omitted.

See above my comment about practicality. It takes no effort for me to not violate your first amendment rights. It's a negative right, not a positive right.

It takes no effort for you not to violate Title II, just don't ask for other people's personal information.

It takes effort to set up server access log rotation. It takes effort for a non-technical person to make sure their wordpress installation isn't storing cookies or logs.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#120
post #99

Earlier quoted context omitted.

This is exactly why he's saying it. Anyone who follows Benioff and the Oracle ilk knows this. Which is why GDPR needs to be scaled appropriately so that it fosters innovation while still protecting customers interests. Having a lower bound of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.

€10M is not the lower bound in penalties. It's the upper bound for breaches of data protection obligations (except for very large companies, with turnover >€500M/y).

I've got a gut feeling that judges will be pretty reasonable here, but I guess only time will tell.
Post reply on HN