Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

171–180 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#171
post #145
post #110

Earlier quoted context omitted.

> How much will it cost you if your data gets hacked? If I understand it correctly (IANAL), there are no penalties for getting hacked. Rather there are penalties for not having proper procedures for how to respond to a hack.

It depends what data you had; why you had it; whether you knew you had it; and how it was hacked. https://ico.org.uk/about-the-ico/news-and-events/news-and-bl... > The data was taken from an underlying customer database that was part of TalkTalk’s acquisition of Tiscali’s UK operations in 2009. The data was accessed through an attack on three vulnerable webpages within the inherited infrastructure. TalkTalk failed to…

That's not a GDPR fine, that's an ICO fine under a different (but similar and related) regulation (Germany and France have similar ones IIRC). The suggestion is that the US adopt GDPR-style regulation, which penalizes for infringement to procedures of data governance, NOT whether data is actually breached. (EDIT: obviously a breach will trigger a GDPR investigation)

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#172
post #157
post #153

Earlier quoted context omitted.

To me it seems the reason people are being so pedantic about the meaning of “thought crime” is that they’re actually glad this sort of thing happens. I don’t even agree with Tommy Robinson but this sort of thing is incredibly dangerous. We cannot be free if the state has the power to arrest people who disagree with them. Period. This must be an absolute right regardless of your fee-fees being hurt, or the next thing…

Can you tell me which country allows people to threaten witnesses at trial?Which country allows reporters to call a defendent a muslim child rapist before the verdict is reached?

If it had been the other way around and some white guy was being called a “Nazi child rapist”, I’d expect them to get away with it in pretty much any western country. It’s true that his behavior was illegal, but the reason he was prosecuted was ultimately the content of his speech in my opinion. There have been other right wing figures who’s names I don’t recall who were also recently convicted, and they weren’t speaking in a court room at all. Other anecdotes mentioned above were French pro-Palestine activists.

You’re right that Robinson was in the wrong on this one and that he did commit a crime; I wouldn’t have used him as an example had he not been brought up specifically.

Even in the U.S., there are people actively lobbying to use the government, usually state governments, to restrict the BDS movement. In my opinion there’s been a lot of media attention around silencing right wing speech in order to get the left to comply in undermining the underlying legal principles. But at the same time, quieter work is being done to restrict left wing speech as well. This has already been put in place in Europe and there seems to be bipartisan support for it in the U.S.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#173
post #131

Earlier quoted context omitted.

I don't think things like GDPR and "free press" are in conflict like you think they are.... at least you haven't explained how they are supposedly in conflict. HIPAA exists... and it doesn't prevent the press from using that information.

Part of free speech is being able to gather and record information. Observation.

The press can do that... that's allowed.

I'm not sure your really have a good grasp on what any of these laws actually do, let alone 'free speech'. You keep alluding to complications that don't exist and don't explain what you're talking about.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#174
post #17

The US needs a law that exempts American businesses from GDPR if they have no presence in Europe.

That already exists, it's called GDPR. It doesn't apply to you if you have no presence in Europe.

Unless you track or profile natural persons within the EU, or you "envisage" offering them services. Then you're in scope.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#175

Earlier quoted context omitted.

> I am all for protecting the consumer but GDPR is going too far with what I would call optics rather than actual consumer protection Too far from what? Thanks to the GDPR, I received 100s of emails of services I never signed up for who scrapped my details from LinkedIn with bots. The industry went way too far with what would have been acceptable and that's why we need laws like this.

The law could simply punish those who do harm. All you are getting now is further boltering for those you end up being gamed to sign up for. I understand the pupose and intent of the law but it could have been done much more elegantly. Those who want to missuse your data will still do that they will just find another way to do it.

> The law could simply punish those who do harm

That's exactly what the GDPR is doing I feel, you get punished for data misuse, it looks a good idea to reduce this kind of abuse.

> All you are getting now is further boltering for those you end up being gamed to sign up for.

I did not get gamed to sign up, they just scrapped my data and added me to their database, I did not do any action and they did not made me sign up with a trick (I also had a few of those yes but the majority are just data scrapping)

> Those who want to missuse your data will still do that they will just find another way to do it.

That's the argument you could make with every law basically. I also hear the same argument for car speeding "they could just drive faster at another place and not get caught". It's indeed true but it's not because there's still ways of misuse that we should abandon everything.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#176
post #151

Earlier quoted context omitted.

Why do the rest of HN users have to educate you about the abuses perpetrated by various companies? Facebook famously did an emotion manipulation experiment on 500k randomly selected users. There's a trial now alleging that Facebook used profile data to discriminate against older programmers in job postings: https://news.ycombinator.com/item?id=17178565 Many types of abuses are subtle and remain unknown for the victim…

>Why do the rest of HN users have to educate you about the abuses perpetrated by various companies? Burden of proof lies on the one making the claim. >Facebook famously did an emotion manipulation experiment on 500k randomly selected users. I don't really find that abusive or ethically troubling. >There's a trial now alleging that Facebook used profile data to discriminate against older programmers in job postings: M…

Burden of proof lies on the one making the claim.

I didn’t make a claim, you did, then flipped it around and made one for me. ;)

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#177

Earlier quoted context omitted.

I could say the same thing in reverse about regulations. Every few weeks some regulation ruins the internet even more and finally people are sick of the regulations. Name one way your life was ever negatively impacted, in a concrete way and not just in your head, by companies using your data to create value in the form of targeted ads and such to keep websites free. I'm waiting.

Equifax breach and stolen identities? Cambridge Analytica and the 2016 US Presidential election? Ashley Madison and affairs being revealed? We can go back and forth about the best way to deal with this, but it's crazy to think that this systemic gobbling up of personal data doesn't have real consequences.

I don't see it as fair to say those are consequences of the companies being allowed to have the data in the first place. They're consequences of poor security. We don't blame spam on email or food poisoning on food, do we? A GDPR-like approach to solving spam would be outlawing all automated or business-related use of email.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#178

There has already been a lot of discussion about GDPR in the recent weeks, but one thing that shocked me is that the regulation is seriously described like this: From https://ico.org.uk/for-organisations/guide-to-the-general-da... : > The GDPR does not specify how to make a valid request. Therefore, an individual can make a subject access request to you verbally or in writing. It can also be made to any part of your…

I suppose this is blowback from most of the large tech giants making it almost impossible to contact them as a user.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#179
post #168
post #163

Earlier quoted context omitted.

This is what I don't understand...how do you present two cases of "up to" and then say "whichever is higher"?! https://gdpr-info.eu/art-83-gdpr/ "Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:…

What's the problem with that? The "whichever is higher" doesn't refer to the fine, but to the limit it can be "up to". Something a bit more verbose could have been easier to understand, true, but there's no doubt about what it means.

> but to the limit it can be "up to".

So then why not just set it to a percent of revenue? If you're just going to slap a small company with minimal turnover with €1k fines anyway, then why the need for the "up to €10M" amount?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#180
post #38

Earlier quoted context omitted.

> You don't own information about you. Data is data. This seems like a strange stance. Clearly some data is not just data and must be protected, for example Top Secret information. From a broad consumer perspective, we have FERPA and HIPAA, which place restrictions on educational and health information. Have you considered the wild west of no data restrictions was the anomaly, not the other way around? Or, are you of…

Well, I liken it to window shades. You don't own the photons bouncing off of you so if someone looks in your window and the shades aren't closed, then they aren't stealing your image. If they try to circumvent the protections you put in place, that's different. Same thing with data.

Well, I liken it to doors. You don't own the air flowing through so if someone reaches in and grabs something, they aren't stealing it.

Here's a helpful tip: in our society, the responsibility is on the criminal for doing bad things, not on the individual for not going to enough lengths to stop the criminal.

Post reply on HN