Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

221–230 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#221
post #214

Earlier quoted context omitted.

It does do that.

No. Here's the full text of the right to erasure. Pay attention to all the reasons given for why processors can ignore the request to erase data. https://gdpr-info.eu/art-17-gdpr/ But then look at para 3. > Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: > for exercising the right of freedom of expression and information;

Then I'm going to store all the information I want, for the purpose of expressing it to others. Oh wait, I can't do that? Somehow the EU has a different definition of "freedom of expression" in mind than what the words actually mean.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#222

Earlier quoted context omitted.

>Why do the rest of HN users have to educate you about the abuses perpetrated by various companies? Burden of proof lies on the one making the claim. >Facebook famously did an emotion manipulation experiment on 500k randomly selected users. I don't really find that abusive or ethically troubling. >There's a trial now alleging that Facebook used profile data to discriminate against older programmers in job postings: M…

Burden of proof lies on the one making the claim. I didn’t make a claim, you did, then flipped it around and made one for me. ;)

[deleted]

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#223
post #87

as an american, no thank you. compelled speech is not okay

Is the HIPAA[1]'s privacy rule compelled speech? Do you believe corporations have a right to unlimited surveillance derived from their right to free speech? [1] See https://en.wikipedia.org/wiki/Health_Insurance_Portability_a... "The Privacy Rule gives individuals the right to request a covered entity to correct any inaccurate PHI." "The Privacy Rule requires covered entities to notify individuals of uses of their PH…

HIPAA does a lot of damage to innovation in healthcare research and industry. Still, I don't know why you assumes every law that exists is perfect justification for the a more expansive law. This is exactly why slippery slope is not a fallacy. The state always wants more power under the guise of providing safety.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#224

Earlier quoted context omitted.

Please if you can, give one example of a European government jailing someone for a thought crime. To save us both time and aggravation please keep the actual definition of “thought crime” in mind, and don’t conflate it with something people actually did .

US has absolute free speech. Being from Europe, I tend to disagree with this form, as I believe meaningful free speech is precious, and we shouldn't allow some right wing extremists to take advantage and ruin it by using it as an excuse for hateful language that contributes precisely nothing to political debate.

You’ve been duped if you think this is about right wing extremists. The same laws have been used to silence pro-Palestine activists.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#225

Earlier quoted context omitted.

Which is information you might want to keep and share. So that you can talk about people. Example: if I want to say Brian accessed my website last Thursday.

You can do journalism about Brian specifically, but you can't preemptively store information about everybody just in case.

Then you can't keep information around necessary to defend yourself against defamation.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#226

Earlier quoted context omitted.

> Access logs for one thing are pretty unreasonable to force people to avoid storing. Store them for a limited time, it's not hard.

Not "hard" for us, no, even if an unnecessary burden. Now go make some small veterinary clinic with no "computer person" on hand, with a small website they had set up years ago that lets you schedule appointments, figure all this out. They'll probably either stay uncompliant or have to drop the website.

Running a single server for a small business is hard anyway they’re occasionally going to need support.

As the first offense only seems to result in a warning, they have a chance to figure things out. Then is asking their webdev to schedule a cron job to delete logs really such a burden?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#227

Earlier quoted context omitted.

There are three reasons in addition: 1. Insulating himself from future lawsuits. Judges look very favourably towards corporations that try to work with regulators before a crisis. 2. Legislating a fix reduces market demand for a technical fix. Imagine a world where a competitive platform to the internet / the web arises. In such a case if the public feels safe because of legislation then they're less likely to abando…

> ...would be devastating for Salesforce would be devastating for the US ... intelligence apparatus GDPR exempts law enforcement and the court system so I'm not sure why we'd expect US legislation to be any different.

Much of the data that our intelligence agencies collect is through collaboration with private industry. If Salesforce employs hundreds of people to clean up data then that (and other companies like them) going away would make a measurable difference to what the intelligence agencies are capable of doing.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#228

Earlier quoted context omitted.

I'm a fan of privacy legislation, but your comparison is a little strained in my opinion. You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me. Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service. In general, I…

GP's point isn't that they're the same; rather, they're both arbitrary "rights" created by law. Why is it your toothbrush? Matter is matter. Data is data. Obviously, we as a society have decided that property rights are more advantageous than not, and we're deciding the same thing about information rights. There's not anything inherent to either one that precludes us from regulating it.

I understood the point. I don't agree that rights are entirely arbitrary. The United States Declaration of Independence takes the view that government exists to protect the rights we naturally have.

> We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness. — That to secure these rights, Governments are instituted among Men...

But I understand that "rights" such as copyright are somewhat arbitrarily bestowed.

My point was that a right to one's possessions is more obvious and definable than a right to one's data. My hands are mine. My toothbrush is mine because I made it with my hands or bought it with money I earned with my hands. Etc.

It's much more nebulous to say that I own information about myself. If you see me, is your knowledge of what I look like "mine"? What about if you write down what I look like? What if you take a picture? What if you write down a detailed account of all my movements and sell it? At some point it starts to seem wrong, but it's fuzzy.

You may say these are both arbitrary. I don't think all rights are arbitrary, and to the extent that things are fuzzy, I think rights to physical possessions are less so.

But again, I'm in favor of privacy regulation. It's just less obvious what it should protect and how.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#229

Earlier quoted context omitted.

I'm a fan of privacy legislation, but your comparison is a little strained in my opinion. You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me. Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service. In general, I…

Why does harm matter to the question raised?

Maybe "sole ownership" is a better way to say it. If I have my toothbrush, you don't. My ownership necessarily means that you can't possess it without my permission. Also, if you take it, you can be made to give it back.

Data isn't that clear-cut. Your knowing my name and address doesn't take that knowledge from me. It's not obvious that you know it, nor how to make you "give back" that knowledge. So it's less clear what my ownership of that data would mean.

Unlike possessions, there's some fuzzy continuum from "clearly it's fine for someone to look at me when I walk past and know what I look like" to "clearly it's not fine for someone to track my every move and sell that knowledge for profit without my consent."

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#230

Earlier quoted context omitted.

Please if you can, give one example of a European government jailing someone for a thought crime. To save us both time and aggravation please keep the actual definition of “thought crime” in mind, and don’t conflate it with something people actually did .

US has absolute free speech. Being from Europe, I tend to disagree with this form, as I believe meaningful free speech is precious, and we shouldn't allow some right wing extremists to take advantage and ruin it by using it as an excuse for hateful language that contributes precisely nothing to political debate.

The US does not have absolute freedom of speech. The canonical example of shouting fire in a crowded theater is illegal. You also cannot call 911 for non-emergencies, distribute child pornography, threaten or harass another person, defame an individual or organization, etc.
Post reply on HN