Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

61–70 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#61
post #49

Earlier quoted context omitted.

> Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them Can you imagine a grocery chain who wants to profit from potential customers all over the world but doesn't want to obey local laws in the jurisdictions it operates in? If people don't want to serve people outside their jurisdiction, do an IP lookup as some US outlets…

It's more like an international customer calling a US business on the telephone and placing an order. That's not 'serving outside their jurisdiction'.

I mean... An international customer can call a US business to place an order, that doesn't mean the US business needs to follow through with or accept this order. Lots of US small businesses I know about don't serve international markets in the hobbyist circles I come from, even though they most definitely have demand there.

Re: Silicon Valley is terrified of California’s privacy law

#62

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

Not sure why you think this is so odd. This is how interstate commerce has worked in the US long before the Internet came around. Mail- and phone-order businesses were (and are) required to obey the laws of the state they're shipping to.

> The physical establishment rule was the only sound approach.

The only reason that rule exists is because enforcement was much more difficult when your target doesn't have a physical establishment within your own borders. If you can enforce it for foreign entities (via some kind of side leverage, like a trade treaty, threat of sanctions, etc.), then, at face value, you should: why should the law behave differently based on physical presence? You yourself point out that things are different in the Internet age; that includes the acknowledgement that commerce can now trivially cross borders without having to have satellite offices everywhere.

Re: Silicon Valley is terrified of California’s privacy law

#63
post #36

Earlier quoted context omitted.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's governme…

>Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous.

Bummer dude. As an engineer type, I say, bring it on. Hard for me to have much sympathy ZuckerBrin can't afford another island or whatever because they made unethical decisions in the past. And if companies blow up because of it: good, that's the idea. There needs to be consequences.

Re: Silicon Valley is terrified of California’s privacy law

#64

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

My favorite example is: If a purchaser calls a suppler from state Y from state X and ask to buy something. Which laws do I follow? * The purchaser follow laws from state X * The supplier from state follows laws from state Y * We then pay any duties to ship from state Y to state X This is the way things have been done, since, well... forever. No one thinks it's weird if this kind of business is conducted in person or…

> The reality is that my only burden is the state in which I operate, otherwise we're interfering with the sovereignty of the state in which I reside... don't think they'll like that. Good luck challenging that one.

I mean, that's exactly what's going on. You can choose to follow State Y's laws when serving customers in State Y, or you can choose to not serve customers in State Y. But if you choose to not follow State Y's laws while serving customers in State Y, then State Y can use whatever leverage they can get their hands on to keep you out of State Y. That's State Y flexing their own sovereignty when it comes to protecting their citizens, which is the flipside of your argument about your state protecting you.

Re: Silicon Valley is terrified of California’s privacy law

#65

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them Can you imagine a grocery chain who wants to profit from potential customers all over the world but doesn't want to obey local laws in the jurisdictions it operates in? If people don't want to serve people outside their jurisdiction, do an IP lookup as some US outlets…

> If people don't want to serve people outside their jurisdiction, do an IP lookup as some US outlets chose to do.

Are you sure your comment you've just made comply with the law of all the 200 countries in the world?

Re: Silicon Valley is terrified of California’s privacy law

#67
While I think CCPA is a step in the right direction from the status quo, which is basically a free-for-all, it's still a mediocre privacy law. GDPR remains the gold standard because it's opt-in, CCPA is opt-out.

The only reason it was even passed was because some guy was going to force the issue with a ballot initiative so lawmakers scrambled to do something. If not for that, California would be the last state to pass meaningful privacy regulation.

Re: Silicon Valley is terrified of California’s privacy law

#68

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

We need a principle-based approach, sound societies can only be built with sound principles.

If I have interesting ideas, I could write a book and sell it in every country of the world. Then this product would be taxed and would need to respect the publication-related laws of that country. On the other hand, if someone reads my book and then travels across the country to hold free seminaries to teach my ideas to the masses, it is not reasonable to try to tax this value transfer, but this is exactly what governments have decided to do.

You see: values vs principles. We can have values but we need to articulate sound principles to give life to these values. What you describe are values.

And what I contend is that we already had sound principles, principles developed across decades and even centuries. The physican establishment rule is the only sound and workable principle.

What we have now is a mess encouraging anti-democratic dynamics (centralization, fingerprinting, and ironically data collection since you need to know more about consumers to know how to apply the laws), in addition preventing innovation and making business difficult.

All of this while for every non-taxed value under traditional principles, a taxable value is actually created... but for some reason nobody is interested in investigating this correlation... for example, the person holding seminaries pays a tax on the room he rents for the seminary. But government prefer to go hard on their propaganda.

If a country wants to tax the books royalty, it should focus on upping its game to attract intellectuals instead of hacking together unsustainable notions to tax "learning".

Similar things could be said for advertising company. When an advertiser advertises in a country, it is by definition to sell a product that most of the time will be taxed into the country (and even if it doesn't, this value transfer will at the 2nd or 3rd degree lead to an activity that can be taxed).

This is why principles based on physical presence and not abstract fictions are not only sufficient and sound but they are also fair. The same is true for privacy, which are after all transactions of their own kind. If you want to regulate data, make sure people use services based in your country by creating the proper environment instead of hacking together extraterritorial laws based on wacky principles.

Just compare these new frameworks, with the readability of the physical establishment principles, that been able to accomodate even the most complex business models for centuries.

Principles should be a foundation, not something you throw out of the window as soon as you start losing to avoid confronting your difficult challenges at the cost of creating an international mess. Digital is not complex, and does not require complex regulations. Trying not to adapt to the world and not to confront your true problems is the only that is complex.

Re: Silicon Valley is terrified of California’s privacy law

#69
post #27

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

This. Imagine if you said the same thing with taxes. "Gee, why do I have to pay taxes differently in every country?" Well, because that's what you have to do if you want to do business there. You're not forced to do anything in here if you don't want to; if the opportunity is worthy, others will take your place. Same with the laws, especially those that remove agency from the users.

But you don't.

If I am from South Africa and I buy a US product from a smaller website I don't pay South Africa sales taxes. If I buy from Amazon I would because they have offices or a physical presence.

When you buy a product from a website hosted/incorporated in a different country you are literally going into another country and buying a product under their laws. Your local taxes (national/stat wide/city wide) shouldn't matter and don't.

The same should apply for eu privacy law.

Re: Silicon Valley is terrified of California’s privacy law

#70

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

I heavily disagree that the physical establishment rule was the only sound approach. It's certainly a valid approach, but not the only sound approach.

The problem with the physical establishment rule is that it leaves the end user with no leverage to actually protect themselves or their data.

The EU and California taking a stance that you must obey their data handling rules in order to do business there is a direct result of the lack of a robust system between states and nations to give users the ability to control their own data when the company's physical establishment is in a different legal system. This approach is the most immediately practical one: I vote for the politician who is willing to enact laws that actually have teeth to regulate the use of my data.

The industry has certainly shown a lack of desire to put teeth into any sort of self-regulation. I worked in ad tech - that industry standard body (the IAB) pretended to care at best, and actively lobbied to erode privacy rights most of the time. Real privacy enforcement mechanisms that actually respected users only started to show up once the GDPR boogeyman showed up.

At the time when we were generally happy with the physical establishment rule, the set of problems we were dealing with was very different. We were more worried about individual freedom in terms of access to services and communications, not individual freedom in terms of safety from bad actors.

Post reply on HN