Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

651–660 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#651

Earlier quoted context omitted.

So can’t abuse people’s data without their consent is being strangled? Is that like I’m strangled with my start up of “cheapdvds.com” because I can’t sell someone else’s data?

You have a funny definition of the word “abuse,” and “sell.” “25% of our users that arrived from the newest ad came from Facebook and 85% of those were mobile users.” So abusive. So much selling.

And when someone visits your website, you don't tell anyone about their visit, right?

RIGHT?!

Re: Europe is scaling back GDPR and relaxing AI laws

#652
post #644

Europe should make business registration a single one page one step operation first. There are dozens of stories how registering a business alone can take several months and tons of paperwork.

> There are dozens of stories how registering a business alone can take several months and tons of paperwork.

What does this even mean? You have examples from ALL of Europe? Each country has its own process, and at least in "my" country it is very easy.

Re: Europe is scaling back GDPR and relaxing AI laws

#653
post #408

Earlier quoted context omitted.

A major difference with regulations is there’s no guaranteed executor of those metaphorical lines of code. If the law gets enforced, then yes, but if nobody enforces it, it loses meaning.

Bad law enforced perfectly is also undesirable.

I'm not convinced. Perfect enforcement would be a great signal exposing bad law much more clearly, so it can be rewritten/scrapped.

Re: Europe is scaling back GDPR and relaxing AI laws

#654
post #43

Earlier quoted context omitted.

> no need for notaries and in-person verbal agreements, etc. With the advancement of AI being used to commit fraud through chat, video, and audio calls I think we're at the precipice of needing to in-person verbal agreements again. And I thought the harmonization of markets in the EU would have reduced the red tape but some industries are built on it and will complain quite vocally if their MP makes any move on it.

The law in Germany comes from when many people couldn't read, so all contracts must be read by a notary to both parties in-person. The bizarre thing is now they advertise how fast they can read! Like it serves no purpose other than giving notaries and lawyers a slice of all transactions. Europe is full of backwards stuff like this - where the establishment interests are so strong, it cannot be adapted for modern time…

> to blocking self-driving cars.

This part seems mis-informed.

https://www.arenaev.com/mercedes_gets_level_3_autonomous_dri...

https://www.arenaev.com/bmw_ix3_gets_handsoff_motorway_assis...

European cars from almost every brand, already have emergency braking, adaptive cruise control, lane keeping, lane switching, etc., which get us 70% of the way there in terms of road safety.

I don't want to be experimented on by companies like Tesla:

Let them kill US citizens and keep lying and hiding things:

https://www.arenaev.com/tesla_robotaxi_troubles_grow_with_se...

> Understanding exactly whose fault these crashes are is tricky because of how Tesla fills out its forms. Automakers must send reports to the National Highway Traffic Safety Administration (NHTSA). Most companies explain the crash in a written section called the narrative. This narrative tells the public whether another driver ran a red light or if the computer made a mistake.

> Tesla chooses to block out this information and redacts the narrative section entirely. This prevents the public from knowing the truth, but it is entirely legal, even if it frustrates data analysts. Without the story, nobody knows if the Robotaxi caused the crash or if it was a victim. Fans of the brand often argue that other drivers cause these wrecks. That might be true. But since the company hides the proof, nobody can say for sure. Other autonomous companies like Waymo share these details openly.

Re: Europe is scaling back GDPR and relaxing AI laws

#655

Earlier quoted context omitted.

I strongly agree with this position. This is basically the foundation of Control Theory! https://en.wikipedia.org/wiki/Control_theory This is like arguing if "heater on" or "AC on" is better, which is a pointless argument. That entirely depends on what the temperature is!

It is the perfect and correct antidote to any slippery slope argument. If the consequences of the law turns out to be as bad as you say they will be then we adjust the law.

> they will be then we adjust the law.

Bizarrely horrible approach. A lot of damage would already be done, most importantly changing the status quo is inherently much harder than doing nothing. So going back won’t necessarily be straightforward.

Claiming that “slippery slope” is always a fallacy is a gross misconception and misinterpretation. It varies case by case, very often it can be a perfectly rational argument.

“Let’s restrict democracy and individual freedoms just a bit, maybe an authoritarian strongman is just what we need to get us out of this mess, we can always go back later..”

“Let’s try scanning all personal communication in a non intrusive way, if it doesn’t solve CSAM problems we can always adjust the law”, right.. as if that was ever going to happen.

Some lines need to be drawn that can never be crossed regardless of any good and well reasoned intentions.

Re: Europe is scaling back GDPR and relaxing AI laws

#657
post #644

Europe should make business registration a single one page one step operation first. There are dozens of stories how registering a business alone can take several months and tons of paperwork.

How is Europe, much less the EU, supposed to do that? Registering a business in Estonia is famously relatively straightforward, while it is an absolute pain here in Germany. But business registration is the responsibility of the countries themselves and it should remain that way

There's the idea of creating a so-called 28th regime under which a streamlined registration process would allow the creation of business entities in all EU countries. See: https://www.eu-inc.org/ - https://en.wikipedia.org/wiki/28th_regime

Re: Europe is scaling back GDPR and relaxing AI laws

#658
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Europe has much more fatal startup-killing regulation problems than cookies, however. Who cares about cookies? I am on your site, you are going to plant/collect cookies. These goddamned banners are a solution in search of a problem, and it's yet another hurdle a company of, say, 3 has to go through, for very little reason.

Since you asked: I care. I leave sites which insist on tracking me and appreciate that it is now mandatory for said sites to inform me about their intentions. So this is a solution to a problem I actually have. There are sites which place a "reject all" button above all and make this easy for me. Others try it the sneaky way, by making me turn off every single tracking vendor and then a lot more hidden under legitimate interest. Those are the sites I leave and never come back. The hurdle in question has a lot of simple solutions. 1, don't use cookies. Github does that AFAIK. 2, be transparent about your tracking intentions and use one of the several premade solutions. 3, design a dark pattern UI that hides the important switches in technical named lists and count on the laziness and confusion of users to use them. That is probably the most expensive way for a 3 person company, as you need devs and UX designers and lawyers to judge if you bended the regulation requirements just enough without breaking them.

Re: Europe is scaling back GDPR and relaxing AI laws

#659
post #284

Anonymization unfortunately is completely broken under GDPR. In principle it providesa clean path for personal data to become usable outside of the restrictions of GDPR, but in practice it turns out to be impossible based on current definitions. The key issue is that anonymization under GDPR requires that a link to a real person can never be re-established even considering the person doing the anonymization. Consider…

You should probably look into pseudononymization in your case, not actual anonymization. Look into C‑413/23 P in more detail to see if it's applicable in your situation, it's essentially the first case law around it. You probably do need some extra controls (like contract that the data is not shared) just in case to avoid the data coming in hands of someone else who could identify the people depending on how detailed the data is.

Re: Europe is scaling back GDPR and relaxing AI laws

#660
post #642
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

I'm 100% on the same page as you. I just wanna point out that apparently, the enforcement of said regulation just failed. There are way too many businesses that don't give you a single "reject all" button and get away with their dark patterns. A regulation that can't be enforced consistently is not desirable and failed to some degree.

I recently registered a complaint with my local data protection authority. This then got routed to their colleagues in North Rhine-Westphalia that are responsible, as the company in question had their business location there.

What the company did? They showed a consent banner - but already sent my data to all manner of analytics and marketing companies. Before I even denied consent. They also did not mention all of those trackers/companies/cookies in their consent solution nor on their privacy page.

The result from the authorities was a clear: Go f*k yourself e-mail to me (I had screenshots attached in my complaint). Basically stating: We do not see any way you are personally affected and we also have too much to do, so we won't go after a company, just because they tracked you and sent your data to a bunch of marketing companies and tracking firms, even as you denied consent. And we also don't care, that they actually did not mention quite a bunch of those receivers of my data in their data privacy page.

So yeah - when governments actually have no interest in enforcing the rules in place to protect citizens, I am lost for words. Might have been, because the company in question being in violation of the law here was a former state-owned business, that while privatised is still run by politicians (like currently by the Chairman of the FDP Federal Committee for Justice, Home Affairs, Integration, and Consumer Protection to be precise).

What pisses me off about this the most, though is, that companies that actually follow the regulations, treat customers well and respect their data privacy concerns, they are at a disadvantage. It is not that our government and those EU conservative ars**es are for a free market. They want a market in which their buddies and the ones providing the juicy jobs after governmental terms come to an end, to win. As always, conservatives follow Wilhoit's Law.

Post reply on HN