Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

381–390 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#381
post #339

Earlier quoted context omitted.

What constitutes data about people? If I save your comment, am I a digital stalker? Is Google a digital stalker because they archived this page? Is HN a digital stalker because they didn't get your explicit permission to show a profile page with your karma on it?

You're being deceptively dense. PII has a very clear definition. Posts on a public forum are not part of it.

> PII has a very clear definition.

It doesn't, actually, as many would-be DoD IT system owners are surprised to find that simply generating a 32-bit random UUID as a user ID is, per the regs, PII, and therefore makes your proposed IT system IL4 with a Privacy Overlay (and a requirement to go into GovCloud with a cloud access point) instead of IL2 and hostable on a public cloud.

Oh and now you need to file a System of Records Notice into the Federal Register (which is updated only by DoD, and only infrequently) before you can accept production workloads.

There is a separate concept of "sensitive PII" (now Moderate or High Confidentiality impact under NIST 800-122) which replaces what people used to call the "Rolodex Business Exemption" to PII/privacy rules.

But PII is very clear: "Personally Identifiable Information". Any information that identifies a specific individual, like for example, your HN username. Unless a collective is posting on your handle's behalf?

Re: Europe is scaling back GDPR and relaxing AI laws

#382
People here act as if GDPR was some kind of big reason why all the digital tech is from US. But come on it's not like the game hasn't been rigged forever. To be more specific it's been part of the deal with europe being close US ally. None of the european digital tech is ever supposed to be relevant. And in case some european digital tech is relevant it has to be absorbed by US or at least made to look irrelevant so nobody sees or cares about it.

If anything this recent lobby and political pressure to remove GDPR/AI laws is there to help US in time when it needs it. To allow some US big tech software to sweep in exploit what they can and help to keep the line up as much as possible.

But if you really look at digital tech in europe... it's doing fine. Why? Because making software and compute is cheaper every year to a point of nothing. It's hard keep insane growth in that environment. Sure if you make some unique breakthrough (like AGI) then tech keep going again. But what if not? Then you just have to squeeze everyone more including your allies, especially your allies.

Re: Europe is scaling back GDPR and relaxing AI laws

#383
post #16

Incredible to see the 180 both from EU and also from the HN sentiment. HN was cheering on as EU went after Big Tech companies, especially Meta. Meta is no perfect company, but the amount of 'please stick it to them' was strong (I reckon that is still a bridge too far for a lot of folks here). Even extreme proponents of big tech villanery in the US (Lina Khan's FTC) is also facing losses (They just lost their monument…

There has been a change in the community here over the last decade, we've lost a lot of the hacker spirit and have a larger proportion of "chancers", people who are only in tech to "get rich quick". The legacy of ZIRP combined with The Social Network marketing.

As this is the message board of a VC fund it's not that surprising that it doesn't only attract hackers in the original sense?

Re: Europe is scaling back GDPR and relaxing AI laws

#384

Earlier quoted context omitted.

This. Sure, it's X% more difficult to do Y in Europe, because Europe doesn't want you to do Y, either at all, or unless you clean up after yourself so the costs aren't just eaten up by the environment or whatever, or unless you do it without causing harm. That's not a problem. That's the system working as intended. Sure, Europe doesn't have it's own Microsoft, probably because of regulations like this, but I don't wa…

> That's not a problem. That's the system working as intended. You really think that supra-national legislators regulating the fine-print of unfathomably complex systems manage to have everything working "as intended"? Why do Draghi or the EC want to roll back this mess then, other than the evident loss of competitiveness respective of the blocs who did not do this? Was that intended or foreseen?

> You really think that supra-national legislators regulating the fine-print of unfathomably complex systems manage to have everything working "as intended"?

For values of, yes. Things obviously aren't perfect, but I at-least generally prefer them over their proposed alternatives. I find they have made things better.

> Why do Draghi or the EC want to roll back this mess then, other than the evident loss of competitiveness respective of the blocs who did not do this? Was that intended or foreseen?

From the article:

> Under intense pressure from industry and the US government,

I think that says what needs to be said. And my opinion is that they shouldn't yield to US government and industry interests, since they clearly aren't the same as European interests.

Re: Europe is scaling back GDPR and relaxing AI laws

#385
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

I think I should be able to collect whatever publicly available data I can find.

Re: Europe is scaling back GDPR and relaxing AI laws

#386

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

AI should also be seen as an opportunity for small actors to actually understand and follow numerous complex rules. You don't need a huge legal and compliance team anymore, you just need to feed chatgpt the right amount of legal and ruling documentation, and then consult it on how you can actually comply.

Re: Europe is scaling back GDPR and relaxing AI laws

#387
post #375

I don't get why people conclude from the cookie hell that "regulations are bad". If those goddamn websites got actual fines for those dark patterns, they wouldn't do it. The EU should just be stricter with the regulations.

I m not sure I follow your logic; are you saying that the regulation is not that bad because you are not fined enough if you don't follow it ? Some of us just follow regulations because it's the law - regardless of the fine. I feel like we should be allowed to express our opinion about their merits or shortcomings without considering the penalty aspect which is an entirely separate conversation.

Re: Europe is scaling back GDPR and relaxing AI laws

#388
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

> I get that too many regulations is a bad thing

Well yeah, cause your sentence relies on itself.

_Too many_ regulations is a bad thing.

But to have a lot of regulations, especially in fields where there is not much to be gained but oh so much being lost in the interest of capital gains like in generative AI, is a blessing rathr than a curse.

Re: Europe is scaling back GDPR and relaxing AI laws

#389
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Europe has much more fatal startup-killing regulation problems than cookies, however. Who cares about cookies? I am on your site, you are going to plant/collect cookies. These goddamned banners are a solution in search of a problem, and it's yet another hurdle a company of, say, 3 has to go through, for very little reason.

Re: Europe is scaling back GDPR and relaxing AI laws

#390
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Most baffling thing is that sometimes you can't opt-out from "always active" stuff that still involve hundreds of "partners"; see: https://news.ycombinator.com/item?id=45844691

Users can opt-out by not using the service or buying an ad-free version if available.

One would think that developers should not be forced to offer for free a version monetized with 60% less effective ads. And I understand currently this is indeed not the case for small developers, they can offer paid ad-free or free but with personalized ads. Large platforms apparently cannot.

Post reply on HN