Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

161–170 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#161
post #142
post #104

Earlier quoted context omitted.

Currently, honest companies that respect the user's data cannot compete with companies that try to profit as much as possible from our it. I see this as similar to regulating pollution. Forbidding companies from cutting costs by polluting the air and the rivers allows for innovation and entrepreneurship in cleaner alternatives.

What? Apple's stance on user data privacy is a selling point in the market. They're not really hurting against other companies.

Apple can only do that because they rule their hardware platform with an iron fist.

They also position themselves as a premium product and do not / cannot compete with google in terms of price. While apple products (and iOS specially) are very popular in the US, here in Brazil you almost never see them.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#162
post #105
post #71

Earlier quoted context omitted.

What if my startup does not require tricky or infelicitous shit with your personal data, but due to strict regulation I now require to hire a full time lawyer just to redact the company terms and keep up with regulations, and since my company does not yet make any revenue and I have no investors that means a lot more risk on my side, which in turns leads me to not start or not go on with that company at all? And what…

I don't understand why you think GDPR is any different from all the other laws that you must obey.

And I don’t understand why you think that all laws have the exact same clarity, compliance burdens, and potential fines.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#163
post #99

Earlier quoted context omitted.

This is exactly why he's saying it. Anyone who follows Benioff and the Oracle ilk knows this. Which is why GDPR needs to be scaled appropriately so that it fosters innovation while still protecting customers interests. Having a lower bound of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.

€10M is not the lower bound in penalties. It's the upper bound for breaches of data protection obligations (except for very large companies, with turnover >€500M/y).

This is what I don't understand...how do you present two cases of "up to" and then say "whichever is higher"?!

https://gdpr-info.eu/art-83-gdpr/

"Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:"

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#164

Earlier quoted context omitted.

>It is not difficult to avoid storing data you don't need. Access logs for one thing are pretty unreasonable to force people to avoid storing. >Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry. Can you point out a specific example of somebody suffering actual damages from this "abuse?"

> Access logs for one thing are pretty unreasonable to force people to avoid storing. Store them for a limited time, it's not hard.

Not "hard" for us, no, even if an unnecessary burden. Now go make some small veterinary clinic with no "computer person" on hand, with a small website they had set up years ago that lets you schedule appointments, figure all this out. They'll probably either stay uncompliant or have to drop the website.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#165

For big companies, this is a small problem to implement. For small companies, it's a big problem. I am all for protecting the consumer but GDPR is going too far with what I would call optics rather than actual consumer protection. I.e. things that look and sounds like they are protecting the user when they are really just adding more bureaucracy to the companies.

> I am all for protecting the consumer but GDPR is going too far with what I would call optics rather than actual consumer protection Too far from what? Thanks to the GDPR, I received 100s of emails of services I never signed up for who scrapped my details from LinkedIn with bots. The industry went way too far with what would have been acceptable and that's why we need laws like this.

The law could simply punish those who do harm. All you are getting now is further boltering for those you end up being gamed to sign up for. I understand the pupose and intent of the law but it could have been done much more elegantly. Those who want to missuse your data will still do that they will just find another way to do it.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#166

Earlier quoted context omitted.

The GDPR doesn't require any of that. All you need to do is show a legitimate need to store data if challenged, and access logs have a legitimate purpose (diagnostic and abuse monitoring). Larger businesses (250 employees or more) may need a privacy policy though.

The consensus I've seen has been that you can't keep around server logs, especially not forever, just for abuse monitoring. GDPR considers IPs PII.

A "consensus" reached by a bunch of programmers who haven't even read the law has no merit in this discussion. What's clear is that GDPR prohibits using IP addresses to target content at particular individuals. But we aren't talking about that, we're talking about generic access logs.

For example the law itself says: The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned.

The UK's IPO for one example definitely doesn't agree with your assessment of the GDPR and it is their job to help companies adhere to it.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#168
post #163

Earlier quoted context omitted.

€10M is not the lower bound in penalties. It's the upper bound for breaches of data protection obligations (except for very large companies, with turnover >€500M/y).

This is what I don't understand...how do you present two cases of "up to" and then say "whichever is higher"?! https://gdpr-info.eu/art-83-gdpr/ "Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:…

What's the problem with that? The "whichever is higher" doesn't refer to the fine, but to the limit it can be "up to". Something a bit more verbose could have been easier to understand, true, but there's no doubt about what it means.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#169
post #131

Earlier quoted context omitted.

FERPA's tied to federal funding. The constitution specifically calls out for a "free press."

I don't think things like GDPR and "free press" are in conflict like you think they are.... at least you haven't explained how they are supposedly in conflict. HIPAA exists... and it doesn't prevent the press from using that information.

Part of free speech is being able to gather and record information. Observation.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#170
post #47

Earlier quoted context omitted.

GDPR is happening because silicon valley and the adtech industry have been taking the absolute piss for years and Europe is fed up.

Europe sure is fed up with free services and relevant ads. What motivated them to this point, who knows - were tracking ads coming into their houses at night and making a mess of their pots and pans? Do Europeans take some strange enjoyment in having to spend more money, the same as they do for everything from food to taxes?

You're spamming the thread with the same misinformed comment.

There are many instances where abuses had real-world consequences, you just need to have the will to find them.

Post reply on HN