Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

101–110 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#101
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

Because then they'll have to be up front about "why" they're charging you a lower amount, which puts a real dollar value on the data for the user, something which previously was never disclosed.

Re: Silicon Valley is terrified of California’s privacy law

#102
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I don't think lawmakers have thought through the ramifications. Here are a few:

Way too hard to enforce, the definition of 'customer data' is going to be a constantly moving target. Does every click count? How about aggregated clicks important for general product optimization?

What constitutes 'selling' user data? Very few companies actually sell your data, instead they place ads based on your data. Will that be banned as well? Many companies, including Google would have to significantly change their pricing model if so.. yet that is apparently illegal.

Re: Silicon Valley is terrified of California’s privacy law

#103
post #33

Earlier quoted context omitted.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

By your rule, companies should not engage in A/B testing to figure out how to make their sites easier to use. Because that involves tracking users for a purpose that is not actually essential to delivering content and services.

Does this outcome make sense to you?

(Disclaimer, I have worked in adtech a little bit, but I have worked a lot more with A/B testing.)

Re: Silicon Valley is terrified of California’s privacy law

#104
post #69
post #27

Earlier quoted context omitted.

This. Imagine if you said the same thing with taxes. "Gee, why do I have to pay taxes differently in every country?" Well, because that's what you have to do if you want to do business there. You're not forced to do anything in here if you don't want to; if the opportunity is worthy, others will take your place. Same with the laws, especially those that remove agency from the users.

But you don't. If I am from South Africa and I buy a US product from a smaller website I don't pay South Africa sales taxes. If I buy from Amazon I would because they have offices or a physical presence. When you buy a product from a website hosted/incorporated in a different country you are literally going into another country and buying a product under their laws. Your local taxes (national/stat wide/city wide) sho…

If this is your experience buying things internationally from smaller websites, that surprises me greatly. When I purchase items from US retailers in European countries, before the item arrives, I get a little slip to pay the duties on the item. If I don’t pay, the item doesn’t arrive.

Re: Silicon Valley is terrified of California’s privacy law

#105
post #33

Earlier quoted context omitted.

Totally disagree. Complicate is not the same thing as following the spirit of the rules. Compliance is proving you followed the rules. Totally different. Also, you have to define what you mean by “respecting privacy”. Something that I do on my website, like basic retargeting marketing for abandoned shopping carts doesn’t feel to me like an invasion of privacy. To you, it might. The rules have to be defined clearly.

If you don't collect any information that's not essential to delivering content and services, there shouldn't be any problem. If you have a shopping cart, you must collect billing and shipping information. But you don't need to use it for any other purpose.

Do you have an error log on your web server? Does that only collect data that is essential or do you do something like log a referer or IP address or user id in hopes that it might be useful un debugging. Is there an access log? What happens if a user asks to delete their data. Do you go back and scrub all such logs? What about if you have a backend service that logs errors about what data it had problems accessing. Or an SQL server that logs bad queries?

It's not so straight forward as you make it seem.

Re: Silicon Valley is terrified of California’s privacy law

#106
It’s jarring to see such headlines on TechCrunch. They fed the valley by giving every little news a place and are ne of the original hype masters for startups. They profit off the area by hosting the disrupt conference as well, which is again a huge pat each other on the back event. So now they turn around and post a headline like that is just somehow ugly to me. It’s absolutely in their right obviously.

Re: Silicon Valley is terrified of California’s privacy law

#107
post #80
post #46

Earlier quoted context omitted.

Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like. It'd be nice if this was unified but it ain't because: 1. Tech companies lobby like hell at a national level 2. The national government is sort of broken right now so that's how the cookie crumbles. The fact that a number of companies have ski…

> Each state can choose to be as restrictive as they like in their laws, and each startup can chose to invest in compliance on a wide scale or in the narrow scale as they'd like. There's a special hell that exists where one state mandates records must be held for at least seven years and another mandates deletion at five. When the two states border one another and you may not have home addresses, how do you determine…

Is this a hypo or a real example?

Re: Silicon Valley is terrified of California’s privacy law

#108

Earlier quoted context omitted.

I am on board with this law, but I’m curious how these two points will shake out: > - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. Seems to me that it’s a distinction without a difference. Is there something I’m missing?

Its intended to fuck over Facebook. If you're charging for a service you can simply offer a discount for allowing data collection after bumping prices for everyone by the same amount, Facebook however isn't charging. Facebook can't offer a discount on free, and they can't just force only users who opt-out to go pay (because that falls afoul of the first quote you put). Basically this puts Facebook in a real tight sit…

They can start charging everyone and offer a "data-share discount" back to free.

Re: Silicon Valley is terrified of California’s privacy law

#109
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I think the idea is that regulation always has unexpected side effects, some of which can be abused to actually do the perverse inverse of what they're intended to protect against.

This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations.

The law does sound great as a consumer, but I think the question is still up in the air about how will it be enforced and what will be the unexpected side effects?

Definitely something to watch for.

P.S. We've been working on a developer-friendly SaaS that helps companies automatically comply with jurisdictional controls + data security / privacy controls. Feel free to email me: mahmoud - @ - https://verygoodsecurity.com and I can dive deeper to answer any questions.

Re: Silicon Valley is terrified of California’s privacy law

#110

Earlier quoted context omitted.

How is that different than, well -- anything? In the United States all 50 states can make their own laws; it's a fundamental part of our legal system. As for every country making their own laws - well, yeah? That's what sovereignty is all about?

In cases where the Feds have decided there should be a uniform standard, states can’t make their own law. https://en.m.wikipedia.org/wiki/Federal_preemption

I don't think that works quite like you think it does. The Federal government generally does not restrict states from making stronger laws than the equivalent Federal law. Take the Federal minimum wage, for instance: they set one level, but states are free to set a higher minimum wage.

This case follows the same pattern: whatever meager privacy protections in place at the Federal level will continue to apply, but California law will take precedence in the case where it's stronger.

There are certainly exceptions, like how currently Trump and the EPA are attempting to disallow CA's higher vehicle emissions standards, but, again: exceptions. (In this case, the relevant law has specific language that makes the EPA the final authority on this sort of thing, and requires states to get waivers for going their own way. That's not a general, common thing, though.) And I expect that bit to be tied up in court for a while.

Post reply on HN