Live data from Hacker News

Big Tech to EU: "Drop Dead"

eff.org

251–260 of 348 posts

Re: Big Tech to EU: "Drop Dead"

#251

Earlier quoted context omitted.

Because most people have little knowledge about the EU and are easily influenced. Direct democracy doesn't work well because of that if you ask me

So you'd say it has to be foisted on the common woman from up high?

Advancements are always foisted upon the common man without their consent.

Re: Big Tech to EU: "Drop Dead"

#252
post #125

Earlier quoted context omitted.

Apple - and the rest of the large companies manage to order their payments so that their profits are offshored out of Europe. Which means they are not paying the corporate tax an EU resident company would. So EU is not getting their fair share.

Don't they send the profits to Ireland which is within the EU?

Yes first. But the company is in the US and Ireland pays to the main company for various things - so the parent company makes the most profit

Re: Big Tech to EU: "Drop Dead"

#253
post #246

Earlier quoted context omitted.

well, not like the platforms currently promote European values :/

This is the EU. Like most governments, if they thought they could get away with it they would not just outlaw Tech Giants, they would outlaw the internet itself, along with any source of information that they cannot easily sue out of existence. Hell, they would outlaw people talking to each other without permission. It was worst with Jose Manuel Barroso at the head of the EU commission, who needed to hide ... well, w…

Edit: This comment is wrong. I mixed up the EEC (direct predecessor to the European Union) and the EEA (like the EU, except it has Iceland, Norway and Liechtenstein).

> used to be named "The European Union of Coal and Steel producers", and hasn't forgotten

The “European Coal and Steel Community” predates the European Economic Community, which it was separate from until the 1967 merger (a decade after the EEC was founded). The EEC is related to, but not the same as, the European Union.

Re: Big Tech to EU: "Drop Dead"

#254
post #55
post #29

Earlier quoted context omitted.

I feel the same. The GDPR appears super difficult to comply with, even impossible in some cases, and very restricting. I just hope negative effects of (in my opinion) overregulation wont hurt the EUs economy too badly, but that wont be visible for another couple of decades

It's not that hard for any competent organization: document what PII you store, who has access to it, and what you do with it. Also have an internal procedure to scramble someone's PII on request. If you have a direct or indirect contractual relationship with the person whose PII you are storing, there is nothing more to do. If you don't, ask for permission and store the timestamp of the authorization. That's all. Re…

I must say you really do make it sound simple, and I generally like it. I think the part where I struggle most are the details though.

> document what PII you store

that part seems doable, the hardest part here are probably figuring out what PII is, and then take care of numerous services logging IP addresses. That's PII, isnt it? What about IPs of phone calls over IP? Or phone numbers stored in phones of numerous employees? Do companies delete those, or is it not necessary?

> who has access to it

I personally try to self-host as much as possible with as little third-parties involved as possible. But I think here are edge cases too, a lot of people might not think about, such as time tracking tools, calendaring, accounting software etc. What happens if employees just use online tools the employer doesn't know about? I am sure it's defined, but it's not entirely clear to me

> what you do with it

that's probably the easiest part, if you do something with it you probably know it

> Also have an internal procedure to scramble someone's PII on request.

I think that sounds good. It's just not entirely clear to me what that procedure should look like? How deep do we go with that? I could be nitpicking and say that physically information can not be destroyed. What if a SQL Server uses MVCC and doesn't delete data but just marks it as such? What about event sourcing architectures with kafka that rely on keeping the data? Or how about backups? Probably no deletion needed, but how to handle cases where backups are restored and previously deleted data reappears? I just think a clear set of rules would be great here, and a lot of people like to oversimplify things (or me, overcomplicating things here, probably)

Re: Big Tech to EU: "Drop Dead"

#255
post #168

Earlier quoted context omitted.

> They can't, Apple management have a responsibility to its shareholders and pull out of the EU or even threatening to do so would hurt the stock price. This isn't how "responsibility to its shareholders" works. While it's true activist shareholders often launch lawsuits over issues they don't like in the US, they are rarely successful and more often looking for a settlement involving a secondary, less significant is…

Anything is in the realm of possibilities. Apple could shut down all of their business tomorrow - just because it’s possible it’s still extremely unlikely. Apple will 100% never turn its back on the EU and I’m willing to take any bet on that.

Sure. I'm certainly not arguing against that - just the limited point where the OP is misunderstanding what "responsibility to its shareholders" actually means under law and in practice.

Re: Big Tech to EU: "Drop Dead"

#256
post #136
post #67

Earlier quoted context omitted.

What other rule do you find impossible? Data portability? The users right to delete data? Data processing agreements? Data security? Article 30? They are all fairly trivial unless you do shady stuff really. Step one if is really looking at what you process as stipulated by article 30, a lot of the other stuff is much easier after that. One of my roles is as a DPO in a bank in Europe, and it's far from impossible to c…

I understand you are an expert on the field, and I am sure it's trivial for you. IMO the complexity arises from the many small things, imagine a smallish startup without having someone hired full time to deal with it. I am not an expert on the field, I tried a couple of times to get into the topic but found it difficult to navigate and left me with more questions than answers personally. What exactly does deleting us…

There is a ridiculous amount of material to read online and you can answer all those questions fully in about 30 minutes of searching and you could have relevant the policies written up by lunchtime.

> Do I have to search the weblogs for the users IP?

No, because you don't keep web logs with any PII in them longer then you have to, right? The time you need to keep them for is a legitimate interest that you need to be able to justify.

Do I have to search the mail servers for his emails - of all employees? What if he used multiple emails to communicate?

Write an Email Retention Policy, there are templates. Follow that.

Am I in breach if an ISP decides to route internet packets through the US?

Isn't it encrypted?

If I put people on CC in a mail, I am leaking everyone's email, probably without their consent - is that a breach?

You said it yourself: it's a data leak, so yes, it is (assuming this is some bulk email list). Depending on the sensitivity of the list, you may need to disclose the leak to the affected parties.

If you want to profit from being a data controller you really should already have done this homework, even before the GDPR and friends required it by law. A responsible company would already be taking care of it's customers' (and employee) data and at most just needs make sure the existing processes are documented. Demonstrably, companies don't do this, through laziness, incompetence or malice, and that's how we end up with these regulations. Just like how companies injuring people in unsafe workplaces is how you get H&S regulation.

And really all you have to do is just actually make a decent effort. If you find that extremely onerous it's usually because you actually want to use the data for something that you know deep down is not something the information owner would want you to use it for.

Re: Big Tech to EU: "Drop Dead"

#257
post #13

Earlier quoted context omitted.

Apple should play their Trump card and threaten to pull out of the EU. The EU would blink first because the public backlash would be career ending.

Right, get rid of their 2nd largest market, at size ~⅔ of the US one. Yes, that will definitely show the EU who's the boss. /s

you seriously think the people of EU will accept policies that makes apple leave? the government will lose. People must have their retarded icrap and facebook, its the sedation the governments need to do all the crap they do. take their facebook away and they will dissolve the governments in 1 second

Re: Big Tech to EU: "Drop Dead"

#258

Earlier quoted context omitted.

This is the EU. Like most governments, if they thought they could get away with it they would not just outlaw Tech Giants, they would outlaw the internet itself, along with any source of information that they cannot easily sue out of existence. Hell, they would outlaw people talking to each other without permission. It was worst with Jose Manuel Barroso at the head of the EU commission, who needed to hide ... well, w…

Edit: This comment is wrong. I mixed up the EEC (direct predecessor to the European Union) and the EEA (like the EU, except it has Iceland, Norway and Liechtenstein). > used to be named "The European Union of Coal and Steel producers", and hasn't forgotten The “European Coal and Steel Community” predates the European Economic Community, which it was separate from until the 1967 merger (a decade after the EEC was foun…

This is the internet. DON'T trust anything I've written. Look it up.

You started well, missed the point that the EU commission is extremely capitalistic, protecting "their" own market, pro-immigration TO DEPRESS WAGES (not for any other reason), using money for policy targets, pro-free-trade otherwise (ie. when it comes to anyone but themselves), and generally extremely capitalistic in the usual deceitful way ...

As for "The EEC is related to, but not the same as, the European Union" ... suuure. In the same the the CPC is not China, it's related. The EU commission IS the EEC, and controls the EU. It has overriding power on any and all decision made and controls all 3 branches of EU government (Parliament, itself, and the EU courts)

Look, I get that people generally like the EU commission. On Hacker News, because of their Google and Apple actions. In the EU, because of them forcing democracies to accept the EU border situation and the Euro (both were rejected in democratic votes, both were forced through in less-than-democratic ways). Doesn't change their nature.

Look it up. Decide. Form your own fine opinion.

Re: Big Tech to EU: "Drop Dead"

#259

Earlier quoted context omitted.

I can vote for who decides things in the EU. I have no say in how Google, for example, does their business. I'm way too poor for that. I'd need literal billions of stock to get Satya Nadella's phone number =)

Good for you, I can’t and now I have to deal with endless pop ups about cookies.

The only reason you get the pop ups about cookies is because the sites you visit that display those popups prefer to do that instead of respecting your privacy.

It’s literally malicious compliance.

Re: Big Tech to EU: "Drop Dead"

#260

Very valid points. In my view they miss the mark however. Blaming Apple for optimizing their platform model isn’t the problem, it became a problem. Imagine 2007 and the following years already with the EU act in full effect. AppStore would be dead on arrival. In my view Apple’s AppStore went from feature some people have when they buy a smartphone to necessity. 2007 and even 2016 was a perfect time to opt for a live…

> Imagine 2007 and the following years already with the EU act in full effect. AppStore would be dead on arrival. No, it wouldn't have been, as the DMA only applies to 'gatekeepers' and if you're new, you're simply not a gatekeeper. You need at least 45 million monthly active users and 7,5 billion of revenue for three years. > So EU should change Apple’s and Google’s status from producer to provider of essential serv…

> You need at least 45 million monthly active users and 7,5 billion of revenue for three years

Minor nitpick that does not really changes the point but might provide context: these are the criteria to automatically be classified as gatekeeper. You can be a gatekeeper even if you do not meet them, but the EU needs to prove that you meet some other more detailed criteria.

Post reply on HN