Live data from Hacker News

Two years in, GDPR defined by mixed signals, unbalanced enforcement

complianceweek.com

181–190 of 216 posts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#181
post #165

Has anyone beyond big tech actually figured out what the rules are yet?

Informally, EU citizens own their personal data, and only ever grant revocable licenses to it. More precisely, to collect any personally identifiable (PII) of an EU citizen, you need their consent. PII includes things like name and email, but also anything like an IP address that can be used to "unmask" a person. Consent must be freely given and can be withdrawn at any time. If requested by a citizen, you must turn o…

Except on any servers entirely out of EU control. China and Israel for instance, have flatly refused to comply with GDPR and furthermore refute any claimed authority the EU has over anyone or any servers residing in their respective nations. I know I refuse to comply with my small US customer-only physical data storage company even though I regularly get visitors from the EU on my company site (And my site says I specifically only serve US customers mainly because I refuse as an owner to deal with the bullshit surrounding the storage and shipping of encrypted tapes and drives full of data belonging to other people outside of the USA).

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#182
post #22

Earlier quoted context omitted.

> Don't stalk people, and if you want to stalk them you need to ask them nicely and allow them to decline Ok, that's nice in a fantasy world, but in the real world a lot of people/sites rely on ad revenue, and ad revenue for the most part, requires tracking built in. So now if you legally force me to allow users to decline "stalking" you are basically allowing users to decline my monetization model and use my website…

The argument goes, if the monetization model is unethical, then it shouldn't exist. I'll demonstrate this by taking your post and rewriting it about a different industry. I am NOT saying these are the same situation, because most people have different views on tracking vs child labor. I am demonstrating that the argument makes sense IF you think tracking is similarly immoral. > Ok, that's nice in a fantasy world, but…

I'll bite that bullet and argue that child labor laws, like GDPR, are well-intentioned but cause more harm than they prevent. Let me explain.

First: If child labor laws were abolished tomorrow, almost no parent in a developed country would encourage their children work, and almost no employer would accept child labor. Parents want their children to succeed in life, and in developed countries that means sending them to school until they have enough knowledge to work a lucrative job. So a parent must be desperate for money or have a very low opinion of formal schooling if they're willing to let their child leave school at age 14 and find employment. Such instances are exceedingly rare in developed countries with social safety nets, but they're not as uncommon in poorer countries. In those places, a parent must sometimes choose between their child going hungry or their child going to work. It's a terrible choice, but we should let families make that decision. The state doesn't have as much information as the parents do, and parents care about their children far more than the state does. A blanket policy prevents families from choosing what they think is best.

Second: As we've seen with laws banning drugs and prostitution, the net effect is to drive the practice underground. This means that anyone involved can't rely on the police and courts. It encourages violence and discourages victims from reporting worse crimes for fear of being prosecuted themselves. It means that banned products aren't subject to controls on quality or safety (as they would be if they were regulated like everything else). So too with child labor. In poor countries, child labor laws mean that children work illegally. They have no protection from hazardous working conditions or abusive practices. The fact that their labor is illegal also means they can't join a union.

Third: In the US, there are exemptions to child labor laws. The Amish are allowed to leave school and work full-time at 14. They work on farms. They use power tools[1]. Some even work in woodshops and sawmills (though usually less hazardous jobs such as cashier or stacking wood). As young as 10 years old, they drive horse-drawn buggies on public roads. Compared to other children in the US, Amish kids don't seem to be particularly unhappy or have worse life outcomes overall.

I think people should have more rights sooner in life. That includes the right to vote, the right to leave school, and yes the right to exchange labor for money. There are plenty of successful people who left school early. Heck, the former Prime Minister of Australia quit school at 14.[2] Scroll through Wikipedia's list of autodidacts[3] and you'll find quite a few high school dropouts.

One can criticize a practice while still arguing against blunt laws that outright ban it. I'm certainly not a fan of child labor, but I think that many of the laws around it are counterproductive, especially in developing countries. I also think many drugs are dangerous, but imprisoning people who engage in such practices causes more harm than allowing it. And I'm worried about how governments and large companies are collecting information, but I'm also convinced that GDPR doesn't help. If anything, it makes the problem worse because larger companies can more easily afford to comply. And there's the issue with GDPR's exceptions for government agencies such as law enforcement and intelligence. Funny how that works.

1. The Amish use compressed air or hydraulic tools. Some sects allow electricity if it's from self-sufficent sources. For more info, see https://www.tested.com/tech/453794-how-amish-are-adopting-po...

2. https://en.wikipedia.org/wiki/Paul_Keating

3. https://en.wikipedia.org/wiki/List_of_autodidacts

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#183

Earlier quoted context omitted.

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

> I see this argument every so often but I'm wondering, what did we actually lose?

All the old comments on Raymond Chen's Old New Thing blog for example.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#184

Earlier quoted context omitted.

The issue is the collateral damage. The EU doesn't have a thriving web/tech sector to begin with when compared to the US or China. These kinds of things likely make it worse.

I see this argument every so often but I'm wondering, what did we actually lose? Nasty social media that makes their money on outrage and exposing people to scam ads? That's about the only thing I can think of, and I don't think it's a big loss. The legal environment of the EU might actually pave the way for better social media, if the market wasn't already monopolized by the current incumbents. As a counter-argument…

I see this argument every so often but I'm wondering, what did we actually lose?

As many of us pointed out two years ago: time and money.

The collateral damage aspect is all the businesses that weren't doing dodgy things in the first place but still had to spend that time and money, because documentation had to be rewritten according to new formats, and policies had to be expressed in terms of the new sets of acceptable X, Y and Z, and so on.

I was not happy back then to find that despite having run businesses that were scrupulously respectful of privacy and security, we still ended up wasting weeks just on figuring out what we had to change (spoiler: nothing of substance, it was all red tape) and for a small business that is a nasty blow.

If you assume, probably rather naively, that all small businesses here in the UK had a similar minimum cost to ours just to review everything and dot the i's and cross the t's to ensure compliance with the new letter of the law, that alone would represent a cost of billions of pounds for little if any benefit to anyone in many of those cases.

The fact that the typical response from many posters on HN was to dismiss that cost as being somehow necessary or justified, with no regard at all for the very direct effects it would have on many small, bootstrapped businesses, showed an astonishing lack of perspective. The number of people in various forums around that time who just straight-up accused me of lying about my businesses being privacy-conscious already, for no other reason than that I run tech businesses and they treated all tech businesses as the enemies of privacy, was also pretty disappointing. There was very little objectivity in the discussions then, the much-lauded benefits to individuals faced with privacy intrusions by certain big players have almost entirely failed to materialise, and the costs and legal ambiguities for everyone are still there two years later.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#185

Earlier quoted context omitted.

> Nasty social media that makes their money on outrage and exposing people to scam ads? Last I checked Facebook and friends still exist. > what did we actually lose? * Many europeans lost access to various publishing sites (another win for the big guys) * Collectively who knows how many millions went to lawyers to reverse engineer the vague GDPR standards

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

Somewhat agreed but this seems to be a side-effect of companies trying to lawyer their way out of the law

Not necessarily. One of the main criticisms of the GDPR was that it was vague and ambiguous on several very important points, and in theory deferred to more concrete guidance from the national regulators, which in turn was then either inconsistent or absent in some of the most important areas anyway.

The GDPR penalty regime was also heavily stacked against smaller businesses: for a large business, the costs are capped at the 4% level, but for any business earning less than half a billion each year, the absolute cap takes precedence and means that a regulator can literally threaten the very existence of any business earning less than probably 100M.

In that environment, you need proper legal advice on interpretation and possibly, as absurd as it seems, just to show that you have made a serious, good faith attempt at compliance, as a preemptive defence if a regulator does subsequently take a different view to yours.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#186

Personally I am just annoyed by the cookie warning on every site. Gdpr does not apply to vast portions of the internet.

>Gdpr does not apply to vast portions of the internet Europe wants it to apply to anything a European might touch.

Of course they do, and just like my ancestors did in 1776 I am free to tell them to mind their own business on their own side of the pond.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#187

The worst effect the GDPR had was on offline bureaucracy. "Data protection" has become the go-to excuse for blocking every single goddamn thing.

Beyond the impact of crushing knowledge transfer, it’s going to kill a lot of people.

In companies with world-wide products/solutions/support, older employees tend to have a broad base of knowledge and learning from being exposed to all customer experiences and issues. Now, everything is in a protected silo and new employees will only learn through a soda-straw looking glass. Older employees are learning to say “not my problem” when getting cleared to look at something overseas because there are 3 layers of data protection officers and it cant be proven there’s not 1 bit of PPD in that 10GB dump.

Some day soon, an industrial or other large-scale accident will kill people and someone in the back office will say “That team didn’t know about X? Doh!”

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#188

We value your privacy. Like, it's valuable. We sell it for money. We're going to nag you until you click this button so we can't get in trouble for profiting off the data you give us. Good legislation is important to let us penalize bad actors—does any one know of any accounts of some bad actors getting stopped by the GDPR? What do you guys think: are there laws that should be in place to incentivize privacy-preservi…

> We're going to nag you until you click this button so we can't get in trouble for profiting off the data you give us. That is explicitly against the regulation. Consent should be freely given otherwise it's invalid. The problem is that there is no enforcement around this (despite it being very easy to detect this behavior at scale by running a web scraper) so they keep doing it and profiting off it.

You're right; I'm exaggerating a bit. I do find it annoying when the banners take up a significant section of the screen though. On mobile is especially bad; I've had banners take up a good 1/3 of the screen.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#189
post #165

Has anyone beyond big tech actually figured out what the rules are yet?

Informally, EU citizens own their personal data, and only ever grant revocable licenses to it. More precisely, to collect any personally identifiable (PII) of an EU citizen, you need their consent. PII includes things like name and email, but also anything like an IP address that can be used to "unmask" a person. Consent must be freely given and can be withdrawn at any time. If requested by a citizen, you must turn o…

Part of the problem with the GDPR is that although many people believe that what you wrote is roughly what the GDPR says and although much of what you wrote is probably more true than not, almost nothing there is strictly correct and in a few places it is wildly misleading. It's not just about collection of data but also about how you process it. Consent is only one of several possible lawful bases for processing, and in practice it's one that many experts have advised against relying on any more than necessary. The right to erasure is actually quite limited in scope. There are multiple mechanisms by which data may be legally shared with other parties, and there's a whole controller/processor system you haven't touched on in relation to that. There are grey areas and ambiguities all over the place, and there are widespread misunderstandings even on points where the GDPR itself is reasonably clear, not helped by media reports often getting the facts wrong themselves around two years ago.

Re: Two years in, GDPR defined by mixed signals, unbalanced enforcement

#190

Earlier quoted context omitted.

> Last I checked Facebook and friends still exist. Last I checked there are studies that suggest the current social-media solutions have a negative effect on mental health, and those effects are likely because of the platforms' efforts to drive up "engagement" levels. Regarding the ads, I have first-hand experience of my non-technical friends falling for outright scams (requiring a chargeback), dubious snake-oil bein…

> This doesn't seem to significantly impact me or anyone in my network. If this was a big problem we'd notice it and/or a EU-based, compliant competitor will step in to fill the void. Access to fewer news sites is access to fewer news. The new site isn't going to replace the old. Also, we're not getting replacements for them in the EU because the business model for these sites doesn't work with GDPR. Making their lif…

I've also seen a ton of people complain about it on this website alone [0, 1].

[0]: https://hn.algolia.com/?dateEnd=1590782149&dateRange=custom&...

[1]: https://hn.algolia.com/?dateEnd=1590782149&dateRange=custom&...

Post reply on HN