Here in Europe, we are in a paradoxical downward spiral. And unfortunately, I see no end to it. Understandably, we don't want our citizens to be spied upon by the US and have all that data stored in the US. Unfortunately, our "solution" is to create regulations which cause so much disadvantage to European tech companies, that we will see our citizens use even more US built tools in the future. We already live in a mo…
EU regulations are not a monolith of good or bad. The cookie law is dumb beyond comprehension. On the other side GDPR is just great and I have yet to hear a good argument against it. The criticisms usually sound like listening to creationists talk about how silly evolution is (by that I mean they don't understand it). The only way I see Europe develop it's own internet tech and big businesses, is to copy what China d…
New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
11–20 of 36 posts
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#12It still doesn't help EU businesses navigate the clash between the US Cloud Act and the EU's GDPR, and seems more focused on appeasing US interests than safeguarding European rights.
Yeah, looks like this will be valid for just as long as it takes Schrems to drag it through the courts. Again.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#13Earlier quoted context omitted.
EU regulations are not a monolith of good or bad. The cookie law is dumb beyond comprehension. On the other side GDPR is just great and I have yet to hear a good argument against it. The criticisms usually sound like listening to creationists talk about how silly evolution is (by that I mean they don't understand it). The only way I see Europe develop it's own internet tech and big businesses, is to copy what China d…
The cookie law is partly dumb, but also frequently implemented in a way that violates the law and rarely subject to meaningful enforcement or significant penalties. So mostly the same practical problem as the GDPR.
I don't see how this relates to GDPR. Please explain.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#14Here in Europe, we are in a paradoxical downward spiral. And unfortunately, I see no end to it. Understandably, we don't want our citizens to be spied upon by the US and have all that data stored in the US. Unfortunately, our "solution" is to create regulations which cause so much disadvantage to European tech companies, that we will see our citizens use even more US built tools in the future. We already live in a mo…
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#15Here in Europe, we are in a paradoxical downward spiral. And unfortunately, I see no end to it. Understandably, we don't want our citizens to be spied upon by the US and have all that data stored in the US. Unfortunately, our "solution" is to create regulations which cause so much disadvantage to European tech companies, that we will see our citizens use even more US built tools in the future. We already live in a mo…
> Unfortunately, our "solution" is to create regulations which cause so much disadvantage to European tech companies, that we will see our citizens use even more US built tools in the future. What is the "disadvantage" to European tech companies who don't want to spy on anyone? What advantage do Europeans who don't want to be spied on gain by using US services that will spy on them instead of using European ones that…
There's also less of a culture of "pour billions into tons of startups and see what sticks", which is a market distortion of its own. That aspect is drying up in the US though, thankfully.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#16Earlier quoted context omitted.
The cookie law is partly dumb, but also frequently implemented in a way that violates the law and rarely subject to meaningful enforcement or significant penalties. So mostly the same practical problem as the GDPR.
Blaming cookies for tracking people is like blaming a bullet for a murder. It's the trackers installed on pretty much every single website that are the thing that tracks people, using cookies of course. The Google analytics or Facebook pixels, to name the top two offenders. I don't see how this relates to GDPR. Please explain.
Yes. I agreed that the cookie law is partly dumb. The part of the cookie law that’s dumb is that it’s too narrowly scoped and should apply to all tracking technologies and techniques, for whichever purposes and vendors are or aren’t okay with the user. And it needs a systematic way for user-specified defaults across all websites, instead of leaving that to browser extensions.
Ideally this would be opt-in rather than opt-out for privacy reasons, but I do understand the valid argument that the subset of people who would explicitly opt in to tracking are not representative of the whole user population.
Probably the best balance of hassle vs privacy vs statistical validity is to require the major browsers to force a one-time explicit choice per purpose and/or per vendor without dark patterns involved, save those as defaults that get sent to the sites in a way that is legally mandatory for sites to respect, and allow per-site overrides using the same mechanism - instead of the current mess of shady consent pop-ups.
> I don’t see how this relates to GDPR. Please explain.
Both have more user-friendly requirements than people expect, both are widely violated in user-hostile ways, both are rarely enforced by regulators, and what rare enforcement does exist is slow, often reluctant, and with inadequate fines to change industry norms and sometimes not even much of the behavior of the fined company. They’re separate laws but with the same practical enforcement / incentive problems.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#17Earlier quoted context omitted.
Blaming cookies for tracking people is like blaming a bullet for a murder. It's the trackers installed on pretty much every single website that are the thing that tracks people, using cookies of course. The Google analytics or Facebook pixels, to name the top two offenders. I don't see how this relates to GDPR. Please explain.
> Blaming cookies for tracking people is like blaming a bullet for a murder. It's the trackers installed on pretty much every single website that are the thing that tracks people, using cookies of course. The Google analytics or Facebook pixels, to name the top two offenders. Yes. I agreed that the cookie law is partly dumb. The part of the cookie law that’s dumb is that it’s too narrowly scoped and should apply to a…
As long as it's about cookies, the law is nonsense. Asking laypeople to "opt-in to tracking" so they can log into a website would render most websites inoperable.
> They’re separate laws but with the same practical enforcement / incentive problems.
I disagree with this. The cookie law popups pretend to ask users whether they consent to being tracked or not. Which is entirely misleading. With GDPR the pressure is on the companies to disclose what data they are collecting on you and give you the option of deleting it.
> Both have more user-friendly requirements than people expect, both are widely violated in user-hostile ways, both are rarely enforced by regulators, and what rare enforcement does exist is slow, often reluctant, and with inadequate fines to change industry behavior.
If I understand you correctly, you're saying the main downside to GDPR is it's not properly enforced. I agree with that.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#18Earlier quoted context omitted.
Blaming cookies for tracking people is like blaming a bullet for a murder. It's the trackers installed on pretty much every single website that are the thing that tracks people, using cookies of course. The Google analytics or Facebook pixels, to name the top two offenders. I don't see how this relates to GDPR. Please explain.
> Blaming cookies for tracking people is like blaming a bullet for a murder. It's the trackers installed on pretty much every single website that are the thing that tracks people, using cookies of course. The Google analytics or Facebook pixels, to name the top two offenders. Yes. I agreed that the cookie law is partly dumb. The part of the cookie law that’s dumb is that it’s too narrowly scoped and should apply to a…
A recent definition of the German authorities clarifies that with „cookies“, they don’t interpret it narrowly as the specific browser technology but any kind of beacon or mechanism for tracking[0]:
> Gemeint ist damit beispielsweise der Einsatz von Cookies und anderen Technologien wie LocalStorage, Web Storage, das Auslesen von Werbe- und Geräte-IDs, Seriennummern, aber auch der Einsatz von ETags oder TLS-Session-IDs zum Zwecke des Trackings, Fingerprinting (z.B. durch das Auslesen von installierten Schriften oder Anwendungen) und vieles mehr. Der Einfachheit halber wird das im Folgenden i.d.R. unter dem verkürzenden Begriff „Cookies“ zusammengefasst.
They name as explicit examples not only cookies but LocalStorage, Web Storage, reading of any kind of serial numbers, ETags, TLS Session IDs (if used for tracking), and any other method for fingerprinting such as font profiling.
[0] https://www.baden-wuerttemberg.datenschutz.de/faq-zu-cookies...
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#19Here in Europe, we are in a paradoxical downward spiral. And unfortunately, I see no end to it. Understandably, we don't want our citizens to be spied upon by the US and have all that data stored in the US. Unfortunately, our "solution" is to create regulations which cause so much disadvantage to European tech companies, that we will see our citizens use even more US built tools in the future. We already live in a mo…
EU regulations are not a monolith of good or bad. The cookie law is dumb beyond comprehension. On the other side GDPR is just great and I have yet to hear a good argument against it. The criticisms usually sound like listening to creationists talk about how silly evolution is (by that I mean they don't understand it). The only way I see Europe develop it's own internet tech and big businesses, is to copy what China d…
Just one.
Re: New Trans-Atlantic Data Privacy Framework Largely a Copy of “Privacy Shield”
#20Earlier quoted context omitted.
EU regulations are not a monolith of good or bad. The cookie law is dumb beyond comprehension. On the other side GDPR is just great and I have yet to hear a good argument against it. The criticisms usually sound like listening to creationists talk about how silly evolution is (by that I mean they don't understand it). The only way I see Europe develop it's own internet tech and big businesses, is to copy what China d…
Can you provide me an example of a single EU regulation that is an unambiguous uncompromising good, that could not be accomplished in a better way on a national level? Just one.