Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

261–270 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#261

Earlier quoted context omitted.

The cookie thing sounds good at first but then it shows that they rant to reduce cookiewalls by making more things ok without asking :(

Yes. I don't think you should have to show a popup to track the user's language preferences, whether they want a header toggled on or off, or other such harmless preferences. Yet, the EU ePrivacy directive (separately from the GDPR) really does require popups to inform users of these "cookies".

[deleted]

Re: Europe is scaling back GDPR and relaxing AI laws

#262

Earlier quoted context omitted.

Far less than 1% of people would care about either.

But far more than 1% are harmed by it. Sometimes the harm is severe. Vast oceans of poorly handled personal data collected in exquisite and unnecessary detail by dark patterns, copied around to everyone who might be interested with low regard for security, kept forever, analysed by the best algorithms and sold to whomever will buy it, raise the risks and consequences of identity theft and fraud for everyone. Those ar…

Most people don't care about these things. Who are you to say that the harm is severe to people who don't care?

Re: Europe is scaling back GDPR and relaxing AI laws

#263

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Browser level consent primitives would be a significant improvement on the status quo.

Do Not Track was a spectacular failure.

You can still turn cookies off in your user agent though.

Re: Europe is scaling back GDPR and relaxing AI laws

#264

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Innovation isn't worth it for innovation's sake, though. Europe could easily profit watching others innovate and taking what makes sense for europe. I don't see anything about GDPR that would harm innovation or long-term success for europe.

> I don't see anything about GDPR that would harm innovation or long-term success for europe.

It's the same thing as any other regulation -- regulatory burden. Laws aren't code, they need interpretation. That means you need your own lawyer to tell you an interpretation that they feel they can defend in front of a judge.

There is a cost to that. In both time and money. I am the CEO of a startup who is subject to GDPR. The amount of time and money we've spent just making sure we are in compliance is quite high, and we barely operate in Europe and don't collect PII.

You can wing it and say "this looks easy, I can do this on my own!" and maybe you can. For a while. But no serious business is going to try to DIY any regulations.

Re: Europe is scaling back GDPR and relaxing AI laws

#265

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Yes, the solution is clearer rules. What drives compliance costs up is rarely the compliance itself, it's usually the uncertainty about your being in compliance or not. That's also true for tax laws, labor laws, environment laws, almost every safety code out there, building zoning...

Well, compliance itself is costly, but the cost is stuff that society decided it wanted to spend money on.

But uncertainty in compliance and time spent navigating compliance is nearly pure waste.

Re: Europe is scaling back GDPR and relaxing AI laws

#266

Earlier quoted context omitted.

Those “cookie banners” are nonsense aimed at getting this outcome. This is a loss for European citizens and small businesses and a win for the trillion dollar ecosystem of data abuse.

How can you comply with the current requirements without cookie banners? Why would EU governments use cookie banners if they are just nonsense meant to degrade approval of GDPR?

By not tracking and setting any third party cookies. Just using strictly functional cookies is fine, just put a disclaimer somewhere in the footer and explain as those are already allowed and cannot be disabled anyway.

Re: Europe is scaling back GDPR and relaxing AI laws

#267
Too late , and it's not just because of the regulations but the whole mentality. This will probably lead to a series of committees about how to scale back the laws which will create new rules which will be put in place, and then the career eurocrats will move on to their next job, without anyone ever being held accountable for the mistakes of the past. Without such accountability every regulation will be excessive, even the scaling-back regulation. Such a process oriented, and feels-over-reals environment is not attractive to competitive business

Re: Europe is scaling back GDPR and relaxing AI laws

#268

Earlier quoted context omitted.

How can you comply with the current requirements without cookie banners? Why would EU governments use cookie banners if they are just nonsense meant to degrade approval of GDPR?

> Why would EU governments use cookie banners They generally don't, because you don't need banners to store cookies that you need to store to have a working site . In other words, if you see cookie banner, somebody is asking to store/track stuff about you that's not really needed . Cookie banners were invented by the market as a loophole to continue dark patterns and bad practices. EU is catching flak because its ext…

you CAN use analytics! Just need to use first party analytics... it is not so hard to set up, there are many opensource self-hosted options.

I hate how everyone and their mother ships all my data to google and others just because they can.

Re: Europe is scaling back GDPR and relaxing AI laws

#269

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Smarter rules and clear rules are kind of contradictory. GDPR is smart but not clear(as it operates on intent). Tax laws are clear, but not smart(as the interpretation is literate and there are multiple loopholes).

Re: Europe is scaling back GDPR and relaxing AI laws

#270
I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Seeing news about relaxing these laws with the "AI" going after this leaves a bitter taste. And with them also trying to push the Chat Control thing, it gets even worse.
Post reply on HN