Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

161–170 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#161
post #118

Earlier quoted context omitted.

I think the idea is that regulation always has unexpected side effects, some of which can be abused to actually do the perverse inverse of what they're intended to protect against. This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations. The la…

On the flip side, the downsides of regulations don’t outweigh their utility. We don’t scrap seatbelt and airbag regulations just because they’ve had some unintended side effects. Regulations aren’t set in stone forever, either, and a functional legislative body can always modify and update them as their effects become more well known. Or, well, maybe I sound too idealistic. But...I think most of us can all agree that…

I live in Washington and this is the last year I'll have to do emissions testing for my vehicle registration. I'm still kind of amazed (my default is pessimism) that this was put into motion in 2005 and nothing seems to be in the way of stopping the removal of the requirement next year: https://ecology.wa.gov/Air-Climate/Air-quality/Vehicle-emiss...

My only point is to support your case that it's not always idealistic to believe that some regulations, even ones that have been in place for decades, even with today's questionably functional government, can go away.

Re: Silicon Valley is terrified of California’s privacy law

#162

Earlier quoted context omitted.

> Will that be banned as well? I sure hope so. > Many companies, including Google would have to significantly change their pricing model if so Good. It would be even better if they have to change their business model.

Are you willing to pay to use a search engine? How much?

Depends on the search engine, of course, but I am not opposed to the notion.

That said, I am also not arguing against advertising as a funding model. I'm arguing against business models that rely on invading people's privacy.

Re: Silicon Valley is terrified of California’s privacy law

#163
Besides the tremendous onus laws like this may place on small startups and side projects:

Does anyone know how companies are supposed to comply if “user data” literally cannot be deleted? I’m thinking in the case of blockchain type applications, where one users’ actions feed into another users’ actions, and you can’t deleted user A’s actions without deleting potentially tons of other stuff and destroying the application.

Like does this law basically ban GitHub and code collaboration too?

Re: Silicon Valley is terrified of California’s privacy law

#164

Earlier quoted context omitted.

> We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self servi…

The GDPR doesn’t apply to European IPs, it applies to Europeans. It would be like a French guy showing up at the grocery store you run and now you have to obey EU regulations or be subject to massive fines. Also, half of the grocery stores in the US now flat out refuse to do business with the French, or any American expatriates. The other half make people with French accents fill out a disclaimer form before they can…

This happens with brick-and-mortar banks already. They will ask "Are you an American citizen?" and then follow up with "Sorry FATCA is too complicated, can't serve you".

Re: Silicon Valley is terrified of California’s privacy law

#165
post #83

So the author would rather see each state/country implement it’s own laws so that a small startup needs to ensure they comply with hundreds of regulatory jurisdictions... awesome.

Just don't do stupid privacy violating shit and you'll be fine anywhere. Collect no information. Share no information. You are good - everywhere . And that really ought to be the default behaviour..

How are you supposed to do any business over the internet without collecting information?

Re: Silicon Valley is terrified of California’s privacy law

#166
How is this not a violation to the first amendment? Does the first amendment not extend as follows: (?)

As a citizen don't I have the right to create a business and privately take notes on whatever I'd like to about my customers? If i run a dry cleaners and take notes about my customers, should I be obligated to disclose these notes or even the existence of these notes to my customers? I don't see why extending the dry cleaning business to a mobile app or website effects anything. What about journalists, are they required to disclose what data they're collecting about people as they do their job?

I feel like the state constitution granted right to privacy does not supersede the federally mandated right to freedom of speech both the right to take internal notes and documentation and the violation of one's speech rights by forcing this disclosure.

however IANAL and I don't live in California. Could someone share some insights onto the first amendment side of this?

Re: Silicon Valley is terrified of California’s privacy law

#167
post #163

Besides the tremendous onus laws like this may place on small startups and side projects: Does anyone know how companies are supposed to comply if “user data” literally cannot be deleted? I’m thinking in the case of blockchain type applications, where one users’ actions feed into another users’ actions, and you can’t deleted user A’s actions without deleting potentially tons of other stuff and destroying the applicat…

>Besides the onus laws like this may place on small startups and side projects:

Startups and side projects are a non-issue. They can just comply from the get go. It's the too small to afford compliance but too big to easily change their business model that are going to be hurt by this. However, that brings up the question as to whether those business models should be able to exist profitably in the first place.

Re: Silicon Valley is terrified of California’s privacy law

#168
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

Some problematic scenarios: - How do you identify what is customer data? There may be information stored in logs somewhere. Do you now have to write log parsers to extract personal data for everything that previously you just stored for general debugging and security purposes? How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal…

There are a (very) few hard edge cases. But most of this stuff is easily addressed by 1) having good designs around data handling in your system and 2) treating customer data and PII as data you only have limited rights to in the first place.

Re: Silicon Valley is terrified of California’s privacy law

#169
post #129
post #55

Earlier quoted context omitted.

We've already had this discussion. We've already seen non-adtech companies simply shut down EU access if they don't have enough revenue. That's probably not a good thing. I support the GDPR, but complying with it is far from simple and the jurisprudence is not yet clear.

> That's probably not a good thing. That's debatable. I imagine that many EU residents who are tired of having their data collected and sold by US companies consider this to be a very good thing. It also means that an EU-based company can come a long and fill the void left by the former incumbent that doesn't want to play ball, which is likely good for the EU's economy. Maybe it's not good for the US company, or for…

> That's debatable. I imagine that many EU residents who are tired of having their data collected and sold by US companies consider this to be a very good thing.

Until that game you like simply shuts down in the EU. Or until that website you visit simply blocks all EU access.

Just because someone can't prove they comply with the GDPR doesn't automatically mean they aren't in compliance.

You've added a bunch of friction to the little guys in order to punish Google, who won't really notice. Maybe you agree with that, maybe you don't. But you have already made that trade whether you like it or not.

Re: Silicon Valley is terrified of California’s privacy law

#170
post #118

Earlier quoted context omitted.

I think the idea is that regulation always has unexpected side effects, some of which can be abused to actually do the perverse inverse of what they're intended to protect against. This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations. The la…

On the flip side, the downsides of regulations don’t outweigh their utility. We don’t scrap seatbelt and airbag regulations just because they’ve had some unintended side effects. Regulations aren’t set in stone forever, either, and a functional legislative body can always modify and update them as their effects become more well known. Or, well, maybe I sound too idealistic. But...I think most of us can all agree that…

The US scrapped alcohol prohibition due to its unintended side effects, and is increasingly scrapping marijuana prohibitions.

Often the downsides do outweigh their utility.

Post reply on HN