Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

121–130 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#121
post #7

A significant part of the fear comes from how poorly worded it is.

Broad wording means companies have to be conservative (collect less data) and less loopholes. That's a win for the ordinary person.

Broad wording usually has a higher risk of being ambiguous thus violating the vagueness doctrine. This is not a strictly better thing; all the efforts invested to the law can be easily invalidated by 9 justices due to the poor wording.

Re: Silicon Valley is terrified of California’s privacy law

#122

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

As a user, I want to be able to access any website online without providing them my location data (even approximate).

As a user, I want to be able to pay or donate to a company or individual without providing them my identity or location data. This is already an extremely hard thing to do because of tax laws like VAT. Please don't make it harder for me.

As an activist, I want everyone to use technology that by-default masks their physical location from websites they access. I want them to feel free not to provide their physical location to anyone online, including businesses like Facebook.

As an activist, I want the majority of popular online payment systems to avoid revealing a buyer's physical location by default, and I want users to feel free to not provide their physical location when paying for a digital product or giving money to another individual. This is already a (nearly) impossible goal because of the sheer amount of tax and money-laundering laws that need to be addressed first. Please don't make it harder.

Laws that force websites to geo-lock based on consumer location are going to be (in the long run) bad for privacy and bad for the open Internet. I don't care about what businesses do or don't want, but the strategies we use to take down advertisers and data-hungry corporations matter.

My less-charitable reading of this situation is that people are generally fine with using user-location as an indicator of jurisdiction because the laws working on that principle are primarily pro-privacy right now. If these laws were being passed in other areas, I wonder if people would be more nervous about the precedent they set.

Re: Silicon Valley is terrified of California’s privacy law

#123
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Jeff Hammerbacher: ‘The best minds of my generation are thinking about how to make people click ads… That sucks.’ Those best minds are now having to change the way they generate revenue..

When I first wrote that comment, it was at -2 after three minutes. Which is interesting because usually HN users claim they care about privacy.

Re: Silicon Valley is terrified of California’s privacy law

#124
post #81

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

You are dead wrong. A completely friction free experience is exactly what you should expect. Every political obstacle we create for data traveling through wires undermines the entire point of having an internet, and cedes more power to legislating bodies who are clueless about technology. An individual should be empowered to serve data to another individual anywhere in the globe without barriers, period. If people ca…

Isn’t this just anarchism?

Re: Silicon Valley is terrified of California’s privacy law

#125
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

You're on a web site chock-full of people whose income or dreams of wealth depends on unfettered surveillance capitalism.

“It is difficult to get a man to understand something, when his salary depends on his not understanding it.”

Re: Silicon Valley is terrified of California’s privacy law

#126
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I don't think lawmakers have thought through the ramifications. Here are a few: Way too hard to enforce, the definition of 'customer data' is going to be a constantly moving target. Does every click count? How about aggregated clicks important for general product optimization? What constitutes 'selling' user data? Very few companies actually sell your data, instead they place ads based on your data. Will that be bann…

European here, I can help:

Yes a click counts as personal data if you can reference it back to a real person. Aggregated clicks probably wouldn't.

Selling ads based on personal data is selling your personal data. The personal data provides the value to the transaction.

Yes lots of companies may need new business models, but for the most part what I've seen is dark patterns, non compliance or wriggling to avoid any real change.

In Europe at least, it's back to the regulators to make a move.

Re: Silicon Valley is terrified of California’s privacy law

#127

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

The GDPR doesn’t apply to European IPs, it applies to Europeans. It would be like a French guy showing up at the grocery store you run and now you have to obey EU regulations or be subject to massive fines. Also, half of the grocery stores in the US now flat out refuse to do business with the French, or any American expatriates. The other half make people with French accents fill out a disclaimer form before they can enter which is also somehow against EU regulations in some cases... but it’s mostly OK for now, because the law weirdly seems to only be enforced against large US multinational food chain suppliers who were able to out compete local French companies. To top it everyone thinks this was such a success that they are racing to pile on with California leading the charge.

Re: Silicon Valley is terrified of California’s privacy law

#128
post #69

Earlier quoted context omitted.

But you don't. If I am from South Africa and I buy a US product from a smaller website I don't pay South Africa sales taxes. If I buy from Amazon I would because they have offices or a physical presence. When you buy a product from a website hosted/incorporated in a different country you are literally going into another country and buying a product under their laws. Your local taxes (national/stat wide/city wide) sho…

If this is your experience buying things internationally from smaller websites, that surprises me greatly. When I purchase items from US retailers in European countries, before the item arrives, I get a little slip to pay the duties on the item. If I don’t pay, the item doesn’t arrive.

Duty is imposed at the country level. In my country things we make have additional duty but products we don't are not.

I would assume importing milk might trigger 50% duty but receiving a dnakit from 23andme wouldn't.

Re: Silicon Valley is terrified of California’s privacy law

#129
post #55

Earlier quoted context omitted.

GDPR is not a difficult law to comply with for an EU company, unless you're adtech.

We've already had this discussion. We've already seen non-adtech companies simply shut down EU access if they don't have enough revenue. That's probably not a good thing. I support the GDPR, but complying with it is far from simple and the jurisprudence is not yet clear.

> That's probably not a good thing.

That's debatable. I imagine that many EU residents who are tired of having their data collected and sold by US companies consider this to be a very good thing.

It also means that an EU-based company can come a long and fill the void left by the former incumbent that doesn't want to play ball, which is likely good for the EU's economy.

Maybe it's not good for the US company, or for the US economy, but the EU (in theory) exists to further the interests of EU citizens.

As a California resident, if the same happens with the CCPA, I will not shed a single tear.

Re: Silicon Valley is terrified of California’s privacy law

#130
post #110

Earlier quoted context omitted.

In cases where the Feds have decided there should be a uniform standard, states can’t make their own law. https://en.m.wikipedia.org/wiki/Federal_preemption

I don't think that works quite like you think it does. The Federal government generally does not restrict states from making stronger laws than the equivalent Federal law. Take the Federal minimum wage, for instance: they set one level, but states are free to set a higher minimum wage. This case follows the same pattern: whatever meager privacy protections in place at the Federal level will continue to apply, but Cal…

Actually, I think you're the one that's incorrect here. California can set a higher minimum wage because it's explicitly allowed to by 29 U.S. Code § 218.

https://www.law.cornell.edu/uscode/text/29/218

That's an exception that's written into the law, while federal preemption is the usual rule.

Post reply on HN