Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

181–190 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#181
post #69

Earlier quoted context omitted.

What you don't realize is that the lawlessness around user data hurts big corporations too. If you're a big corporation collecting significant data than you've taken on a significant liability but the nature of this liability is amorphous. How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? How much can you share in your api? Wh…

> How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? Historically, these numbers have been $0.0+/-0. Executives aren't exactly bumbling around with hazardous materials.

Interesting you should use the hazardous materials analogy - Bruce Schneier made a pretty convincing case two years ago that data should be considered a toxic asset.

https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#182

Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?

Doubly so when legal precedent exists that IP isn’t sufficient enough to identify a person.

Not to conclusively for all time identify a person, but that's not what we're talking about. It's still PII: personally identifiable information. Things that can be used to identify a person.

A first and last name is also insufficient to identify a person, are you going to argue that names aren't personal?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#183
post #7

Earlier quoted context omitted.

I don't think he's lying. But the reasons he wants GDPR are probably just as calculating as you would expect: 1. They already had to do most of this work for GDPR already so the cost will be lower 2. By saying this, he can be invited to meet with legislators who will shape the law. 3. Smaller competitors or startups will be discouraged from entering the market due to an increased regulatory environment (similar to PC…

There are three reasons in addition: 1. Insulating himself from future lawsuits. Judges look very favourably towards corporations that try to work with regulators before a crisis. 2. Legislating a fix reduces market demand for a technical fix. Imagine a world where a competitive platform to the internet / the web arises. In such a case if the public feels safe because of legislation then they're less likely to abando…

> ...would be devastating for Salesforce would be devastating for the US ... intelligence apparatus

GDPR exempts law enforcement and the court system so I'm not sure why we'd expect US legislation to be any different.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#184
post #87

as an american, no thank you. compelled speech is not okay

wtf? How is requiring you to be responsible for other people's information that you collected "compelled speech"?

If you don't want the law to affect you, don't spy on people, it's that simple.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#185
post #35

Earlier quoted context omitted.

> GDPR...creates magical rights where none exist. You don't own information about you. Data is data. You could literally say that about any property right ever. For instance: common law creates magical rights where none exist. You don't own your toothbrush. Matter is matter. The law can create rights. That's how most rights are created.

I'm a fan of privacy legislation, but your comparison is a little strained in my opinion. You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me. Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service. In general, I…

GP's point isn't that they're the same; rather, they're both arbitrary "rights" created by law. Why is it your toothbrush? Matter is matter. Data is data.

Obviously, we as a society have decided that property rights are more advantageous than not, and we're deciding the same thing about information rights. There's not anything inherent to either one that precludes us from regulating it.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#186

For big companies, this is a small problem to implement. For small companies, it's a big problem. I am all for protecting the consumer but GDPR is going too far with what I would call optics rather than actual consumer protection. I.e. things that look and sounds like they are protecting the user when they are really just adding more bureaucracy to the companies.

How is it a big problem? What about GDPR is so hard to implement? Is it really that difficult to not collect data on people that you don't need?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#187
post #63

Such a law will not survive a Constitutional challenge. Just rent seeking by an incumbent.

These recently-discovered European "rights" are probably non-starters, but the ability to get a Google-takeout style package of your own data, and some reasonably protections regarding consent and the way your data is used would clearly Constitutional. We already force some industries to follow most of these precepts in other laws that haven't been challenged: credit agencies have to explain your credit score to you,…

If you actually read up on the "right to be forgotten" you will see that "free speech" is always an exception to it. You cannot demand to be forgotten in order to censure others.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#189
post #133

Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? It seems like there’s room for an enterprise framework that does all the compliance work for you (for US gov contacts, i18n, user info download etc). Maybe calling it enterprise is a misnomer. Maybe it’s a spec that framework’s can target or comply with?

> Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? I understand why you think this way! It's an obvious approach, where there's a bunch of stuff that needs to be done and it's the same everywhere. Why not just have a framework that handles it all for you? It's so clear! It's perhaps possible that many of the requirements of GDPR are beyond the scope of…

I get the process parts, that make more sense to have a human interface, can’t be abstracted out.

However, maybe they can? Compliance as a service? Sounds like just the kind of Bay Area centric idea that VC’s love to fund.

But it seems like there’s some commen sense patterns that our tooling should take up. A framework can take up the transparency, and user control aspects. Framework might be too narrow, platform might be more like it. Things like Wordpress, Magento or Shopify can be “GDPR compliant”.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#190

Earlier quoted context omitted.

> Access logs for one thing are pretty unreasonable to force people to avoid storing. Store them for a limited time, it's not hard.

Not "hard" for us, no, even if an unnecessary burden. Now go make some small veterinary clinic with no "computer person" on hand, with a small website they had set up years ago that lets you schedule appointments, figure all this out. They'll probably either stay uncompliant or have to drop the website.

That's a shame, but it's a side effect of anything ever that requires an update. Any small business commissioning a site in 2019 will get something that's compliant, so it's not like this is a permanent drain.

Sometimes it's important to update regulations, despite the inertia of existing implementations.

Post reply on HN