Live data from Hacker News

Google Emerges as Early Winner from Europe’s New Data Privacy Law

wsj.com

41–50 of 94 posts

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#41
The perverse effect of these consent buttons is that people who configured their browsers to flush all cookies and session data on closing the session get harassed much more as websites do not remember their choice, even if they are the ones actually least likely to be tracked (save for browser fingerprinting).

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#42
post #7

While GDPR in itself has accomplished the goal of raising awareness on data security and transparency, probably only temporarily, the mind numbingly idiotic push-button based consent model is an utter failure. 99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle have to read through. It's an extension of th…

If you have a dialog where the only option is to consent then either that is not real consent according to the GDPR or the consent was not really needed.

In the first, you may just end up with a database for full of data that you may have to throw out when somebody complains. In the second case, why bother your users?

If there is a real request to consent, then it is easy enough to decline. But so far, real requests for consent are quite rare. Most dialogs are basically: we are going to feed you cookies and violate your privacy; do you want to agree now or later?

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#43
post #22
post #7

While GDPR in itself has accomplished the goal of raising awareness on data security and transparency, probably only temporarily, the mind numbingly idiotic push-button based consent model is an utter failure. 99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle have to read through. It's an extension of th…

While all the 'yes I consent' buttons might be annoying (maybe even on a similar level to the inane cookie warnings) the real value of the GDPR lies in the granting people the right to recall that consent later and the companies being forced to comply. Facebook certainly wouldn't have an 'actually delete my profile' feature if they hadn't been forced to make it.

My only gripe is with the sea of meaningless "i consent" buttons that gets increasingly diluted.

Profile delete buttons, user data overview pages and the rest of GDPR i think is very welcome.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#44

Earlier quoted context omitted.

>No offense, but this feels like a “99%” and “most” that is something less than rigorous. I've read the contracts I have to sign, and generally this throws people off drastically. When I ask, they tell me I'm the first to read them. Things like leases at a place that has been around decades and I'm the first to sit down and read before signing. While it isn't rigorous, from my experience with wet ink legal documents,…

I think that indicates that the legal documents weren't written to be read, more than people are too lazy to read them. They were written for a lawyer and for use in court, and it's not realistic to bring in a lawyer for every EULA and contract we encounter. And just as honestly, what are we going to do - say no? Saying no is more and more simply not allowed if you want to use a service. I've had job offers who would…

And that is why I think the core of the issue is consent. The power difference between the lawyers who understand the legal system and write these documents and the users who are forced to agree to use the service is so great that consent cannot exist between the two parties. We legally allow it, much like some countries will legally let a 9 year old sign some document and then hold them to it, but that is a legal fiction that needs to be done away with. Of course this would be a massive shock to how we do things (how would you sign up for a loan), but that alone doesn't justify allowing such abuse of consent to continue.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#45
post #3

GDPR is yet another moat for established companies. It may take them some time to adapt their data models and engineer systems for data deletion, but once they have done so, it becomes something every startup will have to implement in order to compete. I'm not saying GDPR isn't good for privacy (we need it); it just makes competition harder.

Alternatively, start-ups that bake in privacy by design, have a substantial advantage over lumbering established companies that have to adjust their existing processes and may - in some cases - discover that their business models are funadementally at odds with the regulations.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#46
post #26

Earlier quoted context omitted.

> The worst I’ve heard about it is that it makes some people feel a little icky. Yeah sure, all that privacy, who needs it anyway? /s

Its interesting how one of the most frequent uses of the right to be forgotten is used by politicians cleaning up their search history. Who would have thought that legislators had something to gain from a proposal they push?

Who would have thought that legislators would be aware of legislation.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#47
post #7

While GDPR in itself has accomplished the goal of raising awareness on data security and transparency, probably only temporarily, the mind numbingly idiotic push-button based consent model is an utter failure. 99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle have to read through. It's an extension of th…

99% of people don't read anything before they push yes. Most people get increasingly annoyed at the mountain of e-mails, and the hundreds of pages they in principle has to read through. No offense, but this feels like a “99%” and “most” that is something less than rigorous. I don’t think sound arguments for or against GDPR can come from the “Ah Reckon” space. Throwing out made-up numbers that just represent personal…

> I’d add that GDPR explicitly forbids just the kind of “press yes to forfeit all of your rights” crap we’ve seen before. I realize that some sites are still trying to get away with it, it it’s non-compliant.

I have yet to see a non-terrible GDPR screen, and I'm an American. Every single one so far has been either a giant box of doom, or a giant modal of doom with a dozen checkboxes and a freakin' contract on it.

Nope, don't care, I just want to read the one paragraph of your blog - that's it.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#48
post #34

Earlier quoted context omitted.

There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…

And if your MVP makes money, you're on the hook for a lot of taxes and income reporting. It's part of the cost of doing business. For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.

> It's part of the cost of doing business.

In a jurisdiction. GDPR means a dollar can buy more MVPs outside Europe than inside. Keep in mind that this has no bearing on the privacy stance of the ultimate product. Just the fixed cost of iteration.

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#49
post #34

Earlier quoted context omitted.

There's a consistent strain of conflation of this issue in all the GDPR threads, along the lines of "well, if you can't comply with the GDPR, you must be a evil company selling my data to bad people for bad reasons!" You don't have to be doing anything shady with data for the GDPR to be a threat to you and your business. You can be collecting a bare minimum of data that you only use with the purest of intentions and…

And if your MVP makes money, you're on the hook for a lot of taxes and income reporting. It's part of the cost of doing business. For better or worse, entrepreneurs only have their peers to blame for this, the peers who fucked up so badly that the government felt it had to step in.

The sum total requirement for reporting taxes on a hobby project in the US is filling out a single 1099-MISC at the end of the year, during a process that you'll already be doing anyway. It's not an onerous burden which introduces significant friction to the process of bringing a new idea to fruition.

I'm not saying "hobbyists shouldn't have to comply with the law", I'm saying "the law is disproportionately punitive to hobbyists in terms of burden imposed".

Re: Google Emerges as Early Winner from Europe’s New Data Privacy Law

#50
post #13

Earlier quoted context omitted.

I think of it like outlawing chemical pollution of rivers. Yes, a Corporation that manages not to dump toxic waste in rivers is going to have a moat against smaller companies that do dump toxic waste in rivers. But I'd rather it be illegal than have companies competing for who can externalize their costs more effectively by passing their problem of waste management to the state / local area.

I'm not talking about corporations which have the means and the resources to engineer data pipelines that can be scrubbed and lawyers to deal with compliance. I'm speaking to the issue of you or I creating an MVP with a few months of dedicated hard work. How much extra time has to be spent on putting in place a process for data deletion? I'm working on GDPR right now at my company, and it's not a small effort.

> How much extra time has to be spent on putting in place a process for data deletion?

Account for deletion when designing the product. When considered from the beginning, the cost is typically negligible. It's only when shoehorned on the end that it gets expensive.

But... companies have had two years of notice about this. Any projects that have been running for fewer than two years have had plenty of notice. And it's not only the government who requires data deletion - it's your data sources (like Twitter) and your big customers who write it into their contracts.

Just plan for being able to delete data. You are gonna need it.

Post reply on HN