Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

231–240 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#231

We need to have a conversation about jurisdictions in the digital age. The way governments have decided that having a website accessible in a country makes you liable to respect the law of this country is a convulted and hacky notion that has been accepted way too fast. The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the…

My favorite example is: If a purchaser calls a suppler from state Y from state X and ask to buy something. Which laws do I follow? * The purchaser follow laws from state X * The supplier from state follows laws from state Y * We then pay any duties to ship from state Y to state X This is the way things have been done, since, well... forever. No one thinks it's weird if this kind of business is conducted in person or…

You can't have two partners in a transaction following different sets of laws. That's why contracts routinely specify a jurisdiction. Otherwise you couldn't even agree on a court to hear your case.

In B2B transactions, there are often international standards. Even where the supplier's location is set to be the relevant jurisdiction, this only follows from the assumption that a purchaser of industrial goods tends to have the experience to navigate foreign law. This cannot be assumed for consumers.

Re: Silicon Valley is terrified of California’s privacy law

#232

Earlier quoted context omitted.

Good laws put bad people out of business. I don't see the issue here.

The reason there are so many wonderful services available for free is because they make money selling your data. If the service is free, the product is you. For many, many people, that is _fine_. The real issue I see here is how this law is written and how we're interpreting it. If the law makes it so that people who want to opt out of free internet services because of privacy concerns are free to do so, then we're a…

> For many, many people, that is _fine_.

I would argue this isn't the case. For many people it is out of sight and out of mind. They don't realize what's happening.

I came to this conclusion after talking with people about it. Numerous people didn't believe it. I had to show people documents and articles for them to believe me. Most of the people I've spoken with do not like this behavior and would rather not use a service or pay for it if they had known.

The average person is unaware. That does not make it ok.

Re: Silicon Valley is terrified of California’s privacy law

#233

Earlier quoted context omitted.

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. This just means your service always costs money, but you can refund the full amount for allowing you to collect data.

Is there a difference between offering, say, $12 monthly opt-out & $10 plan for opt-in vs flat $12 with a $2 discount to opt-in?

Yep, people are generally lazy. Having something be two steps instead of one make a big difference on your overall conversion rate.

Re: Silicon Valley is terrified of California’s privacy law

#234

Earlier quoted context omitted.

Opt-out for GDPR is under 1%. Most people don't care at the moment, sadly. However, a mass movement to opt-out would absolutely affect them. This lays the groundwork for that, and thats what they should be afraid of.

> Opt-out for GDPR is under 1%. Most people don't care at the moment, sadly. Correct. On top of that, many people on HN, aware of the privacy implications, continue to have a Google Home / Alexa in their homes. Myself included. Sadly, I (and many people) simply don't care about privacy. The probability/expected negatives of surveillance abuse is far less than the benefit of being able to turn my lights on and off wit…

>The US will for sure become like China in 10-20 years, with regards to surveillance.

I very much doubt it. It is one thing when a bunch of small and big companies collect pieces of data about you, and another when the centralized governmentt does it.

Also, it really matters what that data is used for. I would be hard-pressed to compare the onslaught of personalized ads with "disappearing" people who speak out against the government. Just look at US-related political posts on twitter. Why would you even need surveillance if people feel perfectly safe to publicly air out their negative feelings towards the government to a giant audience.

Re: Silicon Valley is terrified of California’s privacy law

#235

Lot's of (mis)information floating around regarding CCPA. I recommend taking the time to read the actual text[1]. The text is not particularly long or dense. There has been a lot of speculation about complex compliance procedures, but the main thrust of the bill is to provide users with information about how their data is collected, who it is shared with, and the rights to prevent certain types of selling or sharing…

The main problem is that the bill is rushed and the legal bits have a lot of ambiguity. source: CCPA and its potential compliance has been a big PITA

No argument there; just pointing out that many of the common complaints around ambiguity are explicitly addressed in the text of the bill already.

Re: Silicon Valley is terrified of California’s privacy law

#236

Earlier quoted context omitted.

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. > - Businesses can, however, offer “financial incentives” for being allowed to collect data. This just means your service always costs money, but you can refund the full amount for allowing you to collect data.

Is there a difference between offering, say, $12 monthly opt-out & $10 plan for opt-in vs flat $12 with a $2 discount to opt-in?

Given how hidden opt-out settings tend to be, yes. If the user has to opt in explicitly, it’s much less likely they’ll consent unintentionally.

Re: Silicon Valley is terrified of California’s privacy law

#237

Earlier quoted context omitted.

Broad wording means companies have to be conservative (collect less data) and less loopholes. That's a win for the ordinary person.

Or realistically it means they will collect the same and wait for clarification. Since it's worded so poorly they won't be punished for it or going by past examples in California the fine will be so small it was worth it.

The US has a common law system. What is not specified in the statute will be slowly clarified by the courts.

Re: Silicon Valley is terrified of California’s privacy law

#238
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

> The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free.

The service isn't free. The exchange just isn't money. When money is involved a price is put forth. It's an agreed to and published exchange mechanism. When it's data on someone the price isn't shared. It's kept secret. There's always a price. It's just not always money or public. This will make more information public.

I wonder if this will start to change how business operate. Right now they are skewed against consumers towards businesses. I wonder if consumer protections, like this, will cause businesses to re-evaluate business models.

Re: Silicon Valley is terrified of California’s privacy law

#239
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

I think the idea is that regulation always has unexpected side effects, some of which can be abused to actually do the perverse inverse of what they're intended to protect against. This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations. The la…

Wrt the laws benefiting incumbents with more resources: in this case I think it’s simple. If you don’t have the resources, just don’t collect the data! If your business model absolutely depends on it, then you should have the resources to do it correctly anyway, so the extra burden of this law shouldn’t be too much on top of that. This is definitely a simplified view, but I think it’s worth noting that following these regulations may actually be easier and cheaper than breaking them (which isn’t the case for, say, some finance and trade regulation).

Re: Silicon Valley is terrified of California’s privacy law

#240
post #172

Earlier quoted context omitted.

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

Good laws put bad people out of business. I don't see the issue here.

This statement is too broad brush for me to actually understand where you're coming from. Let's try a few variations of the theme and see if we can suss out why we perceive this so differently. If none of these touch on your perspective, I'd appreciate it if you could propose some of your own.

Please note that these are deliberately constructed as strawmen; I am not advocating for them or saying you do.

1/ Would you approve of a law which forbade companies (perhaps outside of eg healthcare or finance) from collecting or storing PII?

2/ Would you approve of a law which forbade a company which bought or sold PII (perhaps with the above exemptions) from doing any other kind of business?

3/ Would you approve of a law which required companies to explicitly price and purchase PII from consumers?

4/ Would you approve of a law holding employees or executives criminally responsible for data breaches?

5/ Would you approve of a law standardizing the requirements for anonymizing data?

6/ Would you approve of a law banning online advertising?

7/ Would you approve of a law which placed the same requirements on any company which stored PII as are currently imposed on credit agencies?

Post reply on HN