Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

131–140 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#131
post #72

Earlier quoted context omitted.

They've done so in other industries a couple times with HIPAA and FERPA. What makes newspapers different?

FERPA's tied to federal funding. The constitution specifically calls out for a "free press."

I don't think things like GDPR and "free press" are in conflict like you think they are.... at least you haven't explained how they are supposedly in conflict.

HIPAA exists... and it doesn't prevent the press from using that information.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#132

Earlier quoted context omitted.

It takes effort to set up server access log rotation. It takes effort for a non-technical person to make sure their wordpress installation isn't storing cookies or logs.

The GDPR doesn't require any of that. All you need to do is show a legitimate need to store data if challenged, and access logs have a legitimate purpose (diagnostic and abuse monitoring). Larger businesses (250 employees or more) may need a privacy policy though.

The consensus I've seen has been that you can't keep around server logs, especially not forever, just for abuse monitoring. GDPR considers IPs PII.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#133

Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? It seems like there’s room for an enterprise framework that does all the compliance work for you (for US gov contacts, i18n, user info download etc). Maybe calling it enterprise is a misnomer. Maybe it’s a spec that framework’s can target or comply with?

> Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling?

I understand why you think this way! It's an obvious approach, where there's a bunch of stuff that needs to be done and it's the same everywhere. Why not just have a framework that handles it all for you? It's so clear!

It's perhaps possible that many of the requirements of GDPR are beyond the scope of what any kind of framework or code pattern or generator might be reasonably expected to handle. Code cannot readily become a Data Protection Officer or respond to inbound requests. Code cannot address the need to identify and inform users affected by any breach. Code will likely struggle to do the vendor assurance required of all your Data Processors.

You're absolutely right! There's excellent reason to have the technical requirements handled for you by a framework so you can focus on the important parts of your business. It's just perhaps possible that this could be less than the whole of GDPR.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#134

Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?

With nothing but an IP address it’s possible to purchase data append services that reveal a user’s email address, physical address and more. Large sites sell login data to data brokers, keying user account info to IPs. Marketers upload lists of IPs and get back an enriched list with a full profile. Obviously it can get fuzzy with multiple people under the same IP. But in many cases it’s all that is needed for identification.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#135

Earlier quoted context omitted.

Is it really so hard to believe that people are all out of trust and goodwill at this point? It’s like having a classroom full of toddlers who all play with matches, and every few weeks they burn the whole school down. Finally the teachers makes rule: no one gets to play with matches. A couple of kids say they’re very responsible and never set fire to anything. Nobody cares.

I could say the same thing in reverse about regulations. Every few weeks some regulation ruins the internet even more and finally people are sick of the regulations. Name one way your life was ever negatively impacted, in a concrete way and not just in your head, by companies using your data to create value in the form of targeted ads and such to keep websites free. I'm waiting.

I suppose you don't count strangers having my personal data as "concrete"?

But I can't think of any internet regulation that's ever harmed me. Which ones are you talking about?

Edit: I can think of a small number of regulations (much less than one per year) that cause problems, but they still don't meet the personal concrete harm threshold you've proposed.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#136

Earlier quoted context omitted.

> How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? Historically, these numbers have been $0.0+/-0. Executives aren't exactly bumbling around with hazardous materials.

Tell that to Equifax.

Elizabeth Warren thinks it may end up making money for Equifax:

https://www.marketplace.org/2018/02/28/tech/sen-elizabeth-wa...

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#137
post #35

Earlier quoted context omitted.

> GDPR...creates magical rights where none exist. You don't own information about you. Data is data. You could literally say that about any property right ever. For instance: common law creates magical rights where none exist. You don't own your toothbrush. Matter is matter. The law can create rights. That's how most rights are created.

I'm a fan of privacy legislation, but your comparison is a little strained in my opinion. You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me. Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service. In general, I…

Why does harm matter to the question raised?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#138
post #96

Earlier quoted context omitted.

The hope is that in a new regulatory landscape we will see the emergence of new companies. Just because the tech unicorns of the last 10-15 years, like uber and facebook, were backed on odious behavior doesn't mean that a more palatable business model won't be discovered.

Since when has more regulation translated in more entrepreneurship?

How is an entrepeneur with a sense of ethics supposed to compete in the current environment? When there is no regulation, the people with less scuples are the winners, not the people with better product.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#139

Earlier quoted context omitted.

Please if you can, give one example of a European government jailing someone for a thought crime. To save us both time and aggravation please keep the actual definition of “thought crime” in mind, and don’t conflate it with something people actually did .

You seem to be under the impression that the act of communicating thoughts in some way precludes it from being "thoughtcrime". This is a ridiculously narrow and pedantic definition; we can't read minds. The term as it's generally used means being punished for expressing a particular viewpoint.

It's not a narrow and pedantic difference at all! It's the entire thing!

You seem to be under some mistaken impression that you can say whatever you want whenever you want in the United States. You can't. There are many categories of speech that are banned in the US as well: if I think to myself "Tom Smith is a liar and a drunkard and he's cheating on his wife", that's perfectly fine, but if I communicate that to a large group of people in order to stain his reputation, that's illegal.

See the difference? In neither the US nor the EU is thinking things illegal, but in both countries, expressing stuff can possibly be illegal. It's true that the US and the EU has slightly different categories of banned speech, but that's a difference in degree, not in kind. but neither region has anything close to "thoughtcrime". You have a poor understanding of these issues if you think that is the case.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#140

Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?

Doubly so when legal precedent exists that IP isn’t sufficient enough to identify a person.

Current guidance, although not definitive, is that IPs and similar identifiers are personal data iff the processor/controller can identify a natural person by combining them with other data it can legally access.
Post reply on HN