Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

21–30 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#21
post #5

The politicians cite competitiveness as the motivator for relaxing the GDPR. The real reason for the EU lagging behind the US in "big tech" is of course the lack of venture capital and the red tape in registering corporations. The GDPR does not prevent US big tech from operating in the EU. As it stands, this is just another attack on EU citizens' rights. It is also the least of the EU's current problems. De-industria…

> The GDPR does not prevent US big tech from operating in the EU.

Of course it doesn't, that'd be stupid. But it does require them to be compliant, otherwise they'll face fines and eventually they'll chose to either be compliant, or exit the market.

As a EU citizen with rights, I love this, exactly what I want from my inter-continent union of countries.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#22
post #16

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN).

To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#23
post #2

Uh oh. I'm all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you're not doing nasty stuff with people's data, 2) actually needed. Any opposing views?

It's easy as long as you're a corporation. It's onerous for a human person. Like the EU's excellent Digital Markets Act, GDPR should be altered to only apply to corporations. It'd be better if like the DMA it only applied to very large corporations, but just corporations is still way better than the status quo.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#24

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

The cookie banners are largely a cargo cult and don't have to be nearly as annoying as they are.

Websites just love to say "we have to do this" rather than improve their UX because the latter just means more work while the former gets people to be wrongfully upset at GDPR.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#25
post #7

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> do away with the worthless cookie banners requirement Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. > cut some generous but reasonable slack to small organizations Some more slack you mean, since they already have a lot of slack compared to larger organizations? What exactly is so cumbersome for a small business to comply with? They're genera…

> Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly.

Companies will never "understand the regulation correctly" because it's not in their interests. That is why the regulation should be bulletproof: as concise as possible while forcing the exact behaviour regulators intend.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#26
post #16

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

No. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#27
post #16

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

> You are required to have a cookie banner if you use cookies

Feel free to (re)read the regulation, there is no such requirement at all.

> you must serve a cookie banner even if you are only using functional cookies

Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#28

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations.

Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent.

It doesn't help the situation that a large number of sites seem to maliciously comply with these regulations.

[0]: https://gdpr.eu/cookies/

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#30
post #25
post #7

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. > cut some generous but reasonable slack to small organizations Some more slack you mean, since they already have a lot of slack compared to larger organizations? What exactly is so cumbersome for a small business to comply with? They're genera…

> Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. Companies will never "understand the regulation correctly" because it's not in their interests. That is why the regulation should be bulletproof: as concise as possible while forcing the exact behaviour regulators intend.

> possible while forcing the exact behaviour regulators intend

That's what I'm seeing happened?

1. Companies store personal data willy nilly

2. Regulators create directives that force companies to stop doing that, or at least be upfront about it

3. Companies who still want to do it, are at least up front about it, telling users what is happening

4. Users now complain about regulators that companies are letting them know, missing the fact that the only companies who are adding those banners, are companies who are hellbent on doing these things anyways.

The blame seems misdirected to me.

Post reply on HN