Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

151–160 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#151

Earlier quoted context omitted.

There has been a change in the community here over the last decade, we've lost a lot of the hacker spirit and have a larger proportion of "chancers", people who are only in tech to "get rich quick". The legacy of ZIRP combined with The Social Network marketing.

The hackers are still here, lurking in the shadows. Bananas. They are just tired of being berated by fanboys anytime they criticize the will of the tech bros. There is no fun in typing out a well-researched answer only to face a torrent of one-second "nah, you are wrong" replies mixed in with AI slop. Bananas.

> There is no fun in typing out a well-researched answer only to face a torrent of one-second "nah, you are wrong" replies mixed in with AI slop. Bananas.

That "AI slop replies" excuse you mentioned would only apply to the past 3 years at most (aka ChatGPT 3.5 release on Nov 30th 2022). While the grandparent comment's take felt true to my perception for at least the past 10-15 years, way before "AI slop replies" were even a remote concern.

Re: Europe is scaling back GDPR and relaxing AI laws

#152
post #70

Earlier quoted context omitted.

It worked to highlight the insane amount of tracking every fucking website does. Unfortunately it didn’t stop it. A browser setting letting me reject everything by default will be a better implementation. But this implementation only failed because almost every website owner wants to track your every move and share those moves with about 50 different other trackers and doesn’t want to be better.

The cookie law made this worse. I used to use an extension that let me whitelist which sites could set cookies (which was pretty much those I wanted to login to). I had to stop using it because I had to allow the cookie preference cookies on too many sites.

uBlock blocks most of those for me lately.

Re: Europe is scaling back GDPR and relaxing AI laws

#153

> One change that’s likely to please almost everyone is a reduction in Europe’s ubiquitous cookie banners and pop-ups. Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly. Finally!

So they finally admit that it was a mistake. Even EU government websites had annoying giant cookie banners. Yet, some how the vast majority of HN comments defend the cookie banners saying if you don't do anything "bad" then you don't need the banners.

> Yet, some how the vast majority of HN comments defend the cookie banners saying if you don't do anything "bad" then you don't need the banners.

There are a LOT of shades of gray when it comes to website tracking and HN commenters refuse to deal with nuance.

Imagine running a store, and then I ask you how many customers you had yesterday and what they are looking at. "I don't watch the visitors - it's unnecessary and invasive". When in fact, having a general idea what your customers are looking for or doing in your store is pretty essential for running your business.

Obviously, this is different than taking the customer's picture and trading it with the store across the street.

When it comes to websites and cookie use, the GDPR treated both behaviors identically.

Re: Europe is scaling back GDPR and relaxing AI laws

#155
In comparison with healthcare information systems the GDPR is really not that hard to follow. You can get guides for business owners which can be read and understood in under an hour.

If you design your system according to the guidelines you usually end up with a product where it's easier to service your customer (eg. with full account exports). Deleting inactive accounts is great because it means less migration headaches in the future.

This is also why our privacy statement starts with "We […] don’t really want your personal data."

Re: Europe is scaling back GDPR and relaxing AI laws

#156

> One change that’s likely to please almost everyone is a reduction in Europe’s ubiquitous cookie banners and pop-ups. Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly. Finally!

Those “cookie banners” are nonsense aimed at getting this outcome. This is a loss for European citizens and small businesses and a win for the trillion dollar ecosystem of data abuse.

There's the confusion about whether ePD (which is all cookies even functional ones) was superseded by GDPR or whether it wasn't and both rules apply. Personally I think common sense is that GDPR replaced ePD or at least its cookie banner rule, but I'm also not a company with billions of euros to sue.

Re: Europe is scaling back GDPR and relaxing AI laws

#157

> One change that’s likely to please almost everyone is a reduction in Europe’s ubiquitous cookie banners and pop-ups. Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly. Finally!

Those “cookie banners” are nonsense aimed at getting this outcome. This is a loss for European citizens and small businesses and a win for the trillion dollar ecosystem of data abuse.

How can you comply with the current requirements without cookie banners? Why would EU governments use cookie banners if they are just nonsense meant to degrade approval of GDPR?

Re: Europe is scaling back GDPR and relaxing AI laws

#158
post #68

Earlier quoted context omitted.

You can just set your browser not to send whichever cookies you don't want to. Cookies are a client-side technology. Why does the government need to be involved?

Because it's not like the browser has two thousand cookies per website, it only has one and then they share your data with the two thousand partners server-side. The government absolutely needs to be involved.

To begin with that isn't true, because the worst offenders are third party cookies, since they can track the user between websites, but then you can block them independently of the first party cookies.

Then you have the problem that if they are using a single cookie, you now can't block it because you need it to be set so it stops showing you the damn cookie banner every time, but meanwhile there is no good way for the user or the government to be able to tell what they're doing with the data on the back end anyway. So now you have to let them set the cookie and hope they're not breaking a law where it's hard to detect violations, instead of blocking the cookie on every site where it has no apparent utility to you.

But the real question is, why does this have anything to do with cookies to begin with? If you want to ban data sharing or whatever then who cares whether it involves cookies or not? If they set a cookie and sell your data that's bad but if they're fingerprinting your browser and do it then it's all good?

Sometimes laws are dumb simply because the people drafting them were bad at it.

Re: Europe is scaling back GDPR and relaxing AI laws

#159
post #120

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

> clearer safe harbors for small actors Different rules for different people huh? Just because you like the group you're benefiting and dislike the group you're harming doesn't mean that is good policy.

Regulation is a moat designed by and benefitting big corporations. Removing it for small businesses specifically would actually be fair.

Re: Europe is scaling back GDPR and relaxing AI laws

#160
post #120

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

> clearer safe harbors for small actors Different rules for different people huh? Just because you like the group you're benefiting and dislike the group you're harming doesn't mean that is good policy.

Almost any corporate rule I am aware of has differences in how they apply depending on the size of the company. And as an entrepreneur and startup consultant I think that is a good principle. I don’t even see how society could function without it.
Post reply on HN