Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

131–140 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#131
post #37

Nothing says GDPR is something that can't be improved upon. Better enforcement, refinement of laws, everything is possible. It has to begin somewhere and that beginning is rarely perfect. Every failure is also an opportunity to learn what to do better. As some other people have commented, the intent is right, the execution has to be improved. Edit: Fixed grammar and some words

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

I see this argument every so often but I'm wondering, what did we actually lose?

Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents.

As a counter-argument, Europe and especially the UK has a thriving fintech scene that produces solutions light-years ahead of what's currently in the US, despite the stronger consumer protection laws that we have.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#132
post #9

Earlier quoted context omitted.

The majority of these aren't actually compliant. Tracking should be opt- in and consent should be freely given . If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach. A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either. These websites can be detected very easily…

Here's an example of a broken site: https://www.europarl.europa.eu/privacy-policy/en The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and…

Maybe all these websites are simply taking the EU Parliament's site as an example on how you should do it? They made the regulation, surely you should follow their example.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#133

Earlier quoted context omitted.

The true hallmark of an ill-conceived law.

In this case you could say anti-drug-trafficking laws are ill-conceived because they go against the cartels' business models.

You may want to choose another example. US drug law is a case-study in how law divorced from consideration of ramifications to existing businesses and societal norms is a disastrous way to craft law.

https://www.aclu.org/other/american-drug-laws-new-jim-crow

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#134
post #20

I think GDPR has its heart in the right place. I don't think it really helps and I suspect that is because users themselves really don't know what is actually happening behind the scenes and no amount of banners or otter things changes their level of knowledge. And I fear even if they know, users don't care and are happy to click past a banner / trade their privacy for free things. GDPR seems to play out as a strange…

> users don't care and are happy to click past a banner / trade their privacy for free things. The GDPR explicitly mandates that consent should be freely given (it should not be more difficult to decline than to accept) and that consent should be informed, so you can't bury the information in 30 pages of ToS or privacy policies. The problem is that there is currently zero enforcement around those things. I'd argue th…

It gets even better: consent needs to be possible to be taken away as easy as its granted. Where are all the banners that nag me to take away ma consent?

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#135
post #79

Earlier quoted context omitted.

Providing the service assumes staying in business, no?

No, there's no protection for failed business models, as there should not be.

A business model that fails because you explicitly make them illegal isn't exactly a failed business model. The lawmakers made them fail and they either knew it was going to happen or were incompetent.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#136

Earlier quoted context omitted.

> users don't care and are happy to click past a banner / trade their privacy for free things. Are we discounting the possibility that users make a rational choice that we happen not to like?

Tough question. For some things, I'd say that informed consent is hard to give - if you consent, you're not informed. I don't believe that the average user is making informed choices. The choices may be rational as long as the users don't understand the consequences. It's perfectly rational to trade in your life savings for a fancy meal if you don't understand what "life savings" means.

I wonder how much information can be provided, much of the "giving your data" is really about the side effects and possible consequences....

But you can only tell people so much. Just saying "hey you're giving google your location" (just a generic example here) ... honestly if that's all I know ... so what?

But really the larger issues are other implications.

That's a hard thing to explain.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#137

Earlier quoted context omitted.

I thought that’s what everyone thought back then. At least all my friends were like, the lawyers will have a good time and be the only ones benefiting from this

That's a pretty default thing that most educated people know though. Regulation and bureaucracy usually benefit the established behemoths with enough lawyers, while gray zones, sluggish laws or easy processes benefit new players or small ones without all the legal armor. No wonder that Facebook is lobbying for getting regulated and Microsoft proposed regulating some computer vision uses (faces) etc. Some people of co…

Most of my Euro friends didn't think this. There's a huge difference in approach to regulation between the EU and the US.

I would guess that this article is written from a US viewpoint - the "isn't it strange how everyone is approaching enforcement of this differently?" attitude isn't even remotely strange to a European.

As lots of people pointed out at the time, GDPR in Europe isn't that groundbreaking - almost all EU countries had/have data privacy laws that approach the GDPR (not least because the GDPR itself is a continuation of EU regulation in this area). It came as a shock to US companies because of the sudden "well, none of you paid any attention when we didn't give this regulation teeth, so here's the fangs" enforcement change.

And yeah, I'd love to take part in retrospective reviews of old news to work out who was right :)

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#138
post #22

Earlier quoted context omitted.

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

The argument goes, if the monetization model is unethical, then it shouldn't exist. I'll demonstrate this by taking your post and rewriting it about a different industry. I am NOT saying these are the same situation, because most people have different views on tracking vs child labor. I am demonstrating that the argument makes sense IF you think tracking is similarly immoral. > Ok, that's nice in a fantasy world, but…

The child worker is a third party that has nothing to do with the customer and the merchant. If the merchant is offering me content for the exchange of information, why should the government able to stop this transaction between parties that mutually agree?

It's already legal to "force" your customers to exchange money for content. If anything, it's even worse because a lot of children end up malnourished because their parents spent to much money on entertainment.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#139

GDPR was known to be, is known to be, and will known to be a shit law that's not tied to reality. It did have some good (allowing you to know what they have on you in general, and asking them to delete some of that), but the rest is just bad, bad, bad. I wish people would be rational when supporting privacy increasing things. GDPR could have been much better and it saddens me that it was ruined, and defended by, zeal…

[deleted]

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#140

Earlier quoted context omitted.

The true hallmark of an ill-conceived law.

Letting companies opt-out of a regulation purely because it hurts their business model sounds much more ill-conceived to me.

Good law doesn't "let companies opt-out;" it is crafted with consideration for what is already happening and the consequences of the law.

it doesn't appear, 2 years in, GDPR passes that test. If the goal was to minimize "privacy violation" by FB and Google, it's failing. FB and Google are stronger than ever, but their competitors are starved out of the market trying to comply with an onerous suite of policies.

It's such a ladder-pulling set of laws it's surprising Google and Facebook didn't craft it.

Post reply on HN