Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

71–80 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#71
post #36

Earlier quoted context omitted.

The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.

Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's governme…

> Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous.

Boohoo and cry me a river. Good riddance. Other companies who take care of customer data from the start will take over.

> It's government dictating the technical architecture.

No, the government doesn’t dictate technical architecture. The government dictates: be careful with personal data.

Re: Silicon Valley is terrified of California’s privacy law

#72
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

It sounds like this means it'll have to be clearly disclosed up front as a bonus, rather than being charged after the fact as a penalty and hidden somewhere in the ToS.

Re: Silicon Valley is terrified of California’s privacy law

#73
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

Maybe something like the advertised price of the service must be the price without data collection.

Re: Silicon Valley is terrified of California’s privacy law

#74

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

> Nobody said your movie has to be viewable in China. You will of course forgive me if I do not find economic favoritism that benefits politically connected industrialists, the restriction of freedom of thought by oppressive governments, and the general Balkanization of the Internet, to be things that we ought to celebrate. Once upon a time the memes of Internet culture would suggest that "information wants to be fre…

> Once upon a time the memes of Internet culture would suggest that "information wants to be free!" Oh, sweet halcyon days of yore!

Turns out it’s not free — it’s actually very valuable, and the cost is borne by society writ large.

Re: Silicon Valley is terrified of California’s privacy law

#75
Lot's of (mis)information floating around regarding CCPA. I recommend taking the time to read the actual text[1]. The text is not particularly long or dense. There has been a lot of speculation about complex compliance procedures, but the main thrust of the bill is to provide users with information about how their data is collected, who it is shared with, and the rights to prevent certain types of selling or sharing of said data. The leginfo site also includes non-partisan analysis (under the "Bill Analysis" tab) of the bill and amendments as it moves through the legislature, which is useful for getting an understanding of how specific issues are being considered and addressed. Something to consider is that bills change substantially through the amendment process, so often critiques you read are based off old versions of the text that have already been addressed.

[1] https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...

Re: Silicon Valley is terrified of California’s privacy law

#76

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

Not everyone has data mining and adtech as a business model. Why should people running legit online businesses that do not involve mining data be punished for unscrupulous actors in the adtech biz?

Re: Silicon Valley is terrified of California’s privacy law

#77

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

[deleted]

Re: Silicon Valley is terrified of California’s privacy law

#78
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

It's all about marketing and perception. See how credit card companies set rules regarding surcharges and cash. Before credit card companies tried to prevent a discount being offered if a customer paid cash as stipulation for taking credit cards. Durbin Act of 2010 changed that which made it legal in all 50 states.

Re: Silicon Valley is terrified of California’s privacy law

#79
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

It might be a matter of semantics? You can quote a standard price, and then give a discount for allowing data collection, but you can't quote a standard price, and then add a surcharge for disallowing data collection.

I agree that there is no practical difference between the two, but given how deceptive companies can be when disclosing various pricing and hidden fees, this might be an attempt to curb that behavior?

Re: Silicon Valley is terrified of California’s privacy law

#80
post #46

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like. It'd be nice if this was unified but it ain't because: 1. Tech companies lobby like hell at a national level 2. The national government is sort of broken right now so that's how the cookie crumbles. The fact that a number of companies have ski…

> Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like.

There's a special hell that exists where one state mandates records must be held for at least seven years and another mandates deletion at five. When the two states border one another and you may not have home addresses, how do you determine how to comply for a given user?

You're absolutely right, in every way, that tech companies have brought this regulatory backlash on themselves. Yet, it might still be worth considering the potential costs.

Post reply on HN