Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

31–40 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#31

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

or, you could not start a business that requires you capture every single facet of a person's life as a data point.

But you'll start a business which captures some data, and you're on the hook for proving that everything captured is necessary and compliant in hundreds of jurisdictions.

Re: Silicon Valley is terrified of California’s privacy law

#32

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them?

Thats a bad metaphor. If you open a grocery store in one country you follow the relevant law of said country. If you extend you business to another country the new store has to follow the law of the other country.

The problem with physical establishment is that it could create a 'race to the bottom', similar to tax laws. With non-tangible elements like privacy, what stops big players like the USA to implement weak privacy protections to get a competitive edge?

Re: Silicon Valley is terrified of California’s privacy law

#33

Earlier quoted context omitted.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem.

If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

Re: Silicon Valley is terrified of California’s privacy law

#34

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

And that's how privacy compliance as a service was born.

Re: Silicon Valley is terrified of California’s privacy law

#35

Earlier quoted context omitted.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

And what's to stop you from selling that data about what was in my shopping cart to a third party? Would you be compelled to notify me, or ask for my permission? After all, I agreed to share that with you in exchange for the product in the shopping cart. But I didn't agree to anything else.

It's not for the operator of a website to decide what is an invasion of _my_ privacy. It's for the consumer to decide. And that's precisely why we can't rely on website administrators, or the "recipients" of data to determine whether something is private.

I'm one of those website administrators who wholeheartedly welcomes something like GDPR here, even though it would make my job harder. But hey, that's fine. Putting privacy back in the hands of consumers is the right thing to do.

Re: Silicon Valley is terrified of California’s privacy law

#36

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's government dictating the technical architecture.

Re: Silicon Valley is terrified of California’s privacy law

#37

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them

Can you imagine a grocery chain who wants to profit from potential customers all over the world but doesn't want to obey local laws in the jurisdictions it operates in?

If people don't want to serve people outside their jurisdiction, do an IP lookup as some US outlets chose to do.

Hacky US start-ups don't get to dictate the rules of the game to the world.

Re: Silicon Valley is terrified of California’s privacy law

#38

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

This is not true, unless by “respect” you mean “do not collect any at all”. I would argue that you could respect users’ data without implementing data takeout, for instance. I would also argue that cookies not used for tracking do not need disclosure for users to be respected

Anyway, the only companies that will end up being able to collect data at all are there very biggest ones. Everyone else will have to just fly under the radar or use some kind of SAAS solution to comply with the patchwork of regulation. Not sure that’s really the desired outcome

Re: Silicon Valley is terrified of California’s privacy law

#39

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

Yeah... CCPA and GDPR have proved that large enterprises will do just fine, because Amazon can always afford enough lawyers to handle regulatory overhead and confusion across territories. The startups end up either (1) ignoring the laws or (2) giving up. Good job EU, if making the FAANGs the only companies with the clout to hold customer data or break into new markets was your primary goal.

GDPR is not a difficult law to comply with for an EU company, unless you're adtech.

Re: Silicon Valley is terrified of California’s privacy law

#40

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

No, a federal law that's as good as or better than CCPA would be great. But they know that's not what will happen.
Post reply on HN