Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

121–130 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#121

Earlier quoted context omitted.

It takes no effort for you not to violate Title II, just don't ask for other people's personal information.

It takes effort to set up server access log rotation. It takes effort for a non-technical person to make sure their wordpress installation isn't storing cookies or logs.

The GDPR doesn't require any of that. All you need to do is show a legitimate need to store data if challenged, and access logs have a legitimate purpose (diagnostic and abuse monitoring).

Larger businesses (250 employees or more) may need a privacy policy though.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#122
post #14

Earlier quoted context omitted.

Like I said the last time this subject came up, fine. That's totally fine. I don't care which incumbents will be okay in a world with better laws around privacy. I want better laws around privacy. If your startup to unseat Salesforce requires doing tricky or infelicitous shit with my personal data, I don't want you to be able to operate, full stop. Your business shouldn't exist, if its existence requires schlepping o…

> If your startup to unseat Salesforce requires doing tricky or infelicitous shit with my personal data, I don't want you to be able to operate, full stop. Yeah, I'm onboard (like I said, I think the intent of the law is good) -- but regulatory compliance is expensive and in general creating a SaaS business is not. Compliance is more than just doing the right thing, BTW, it's creating processes, audits, attorneys, et…

There's a tendency to think of well-intentioned regulations that serve whatever purpose someone wishes to advance as cheaply and easily complied with by an honest actor.

This tends to not be maximally congruent with reality.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#123
post #47

Earlier quoted context omitted.

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

GDPR is happening because silicon valley and the adtech industry have been taking the absolute piss for years and Europe is fed up.

Europe sure is fed up with free services and relevant ads. What motivated them to this point, who knows - were tracking ads coming into their houses at night and making a mess of their pots and pans? Do Europeans take some strange enjoyment in having to spend more money, the same as they do for everything from food to taxes?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#124
post #3

A consumer protection law like GDPR would probably be a good thing for US, but it's hard not to see this as SFDC saying, "As a multibillion-dollar SaaS vendor, we welcome regulation that might slow down or prevent a competitor from unseating us."

That's exactly what this is. GDPR is untenable and creates magical rights where none exist. You don't own information about you. Data is data. The only reasonable thing I can see out of it is getting companies to clarify (simplify) their EULAs.

In other news HIPAA apparently doesn't exist because "Data is data".

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#125
There has already been a lot of discussion about GDPR in the recent weeks, but one thing that shocked me is that the regulation is seriously described like this:

From https://ico.org.uk/for-organisations/guide-to-the-general-da... :

> The GDPR does not specify how to make a valid request. Therefore, an individual can make a subject access request to you verbally or in writing. It can also be made to any part of your organisation (including by social media) and does not have to be to a specific person or contact point.

> A request does not have to include the phrase 'subject access request' or Article 15 of the GDPR, as long as it is clear that the individual is asking for their own personal data.

> This presents a challenge as any of your employees could receive a valid request. However, you have a legal responsibility to identify that an individual has made a request to you and handle it accordingly.

In a normal world, I think only officers or registered agents can be addressed legal requests, how here any government though it was a good idea that "any of your employees could receive a valid request" and that it's a legal responsibility to handle it correctly. This is just mind blowing to me.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#126
post #99
post #3

A consumer protection law like GDPR would probably be a good thing for US, but it's hard not to see this as SFDC saying, "As a multibillion-dollar SaaS vendor, we welcome regulation that might slow down or prevent a competitor from unseating us."

This is exactly why he's saying it. Anyone who follows Benioff and the Oracle ilk knows this. Which is why GDPR needs to be scaled appropriately so that it fosters innovation while still protecting customers interests. Having a lower bound of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.

> Having a lower bound

This is exactly the opposite of what GDPR says. If I am Satan himself and I do terrible things with the data of millions of people the maximum possible fine available is €20m or 4% of turnover, whichever is higher.

There is no lower bound. When a penalty is applied they're likely to be about €1000. But often penalties won't be applied, the regulator will ask the company to come back into compliance and give advice on how to do so.

> of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.

...and GDPR is full of caveats about how much data is held, and how it's held, and how the company responds after a leak.

https://gdpr-info.eu/art-83-gdpr/

> When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:

> the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;

> the intentional or negligent character of the infringement;

> any action taken by the controller or processor to mitigate the damage suffered by data subjects;

> the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;

> any relevant previous infringements by the controller or processor;

> the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;

> the categories of personal data affected by the infringement;

> the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;

> where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;

> adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and

> any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#127
post #44

Earlier quoted context omitted.

Considering that these rules don’t apply to governments, and that European governments generally seem to be slipping towards jailing people for thought crime, I’m skeptical as to how serious they are about privacy and control of personal data.

European countries don’t typically have American-style free speech, no. People can and do get punished with fines and jail time in England for “insulting” various religions, for example. But this isn’t news to legal scholars or historians.. For all of America’s faults, free speech is one thing we do pretty well.

It's true that US free speech is generally more expansive than European free speech (though that's not universally true: Sweden's freedom of the press laws are more expansive than the US's, for instance), but it's important to note that it is in no way an absolute right even in the US. There are "time, place and manner" restrictions on free speech in the US (yelling fire in a crowded theatre, having to get permits for public protests, etc.) and there are whole categories of speech that are outlawed fully (like libel, slander and intimidation).

European countries draw a slightly different line than the US does (for instance including hate speech in the list of banned speech), but it's a difference in degree, not in kind.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#128
post #17

The US needs a law that exempts American businesses from GDPR if they have no presence in Europe.

This is already the case.

The EU gets to do this the same way that the US can use secondary sanctions to enforce its will on Iran despite the EU notionally still being in the JCPOA. There've been noises about protecting European companies doing business in Iran from US sanctions - note that they have been coming from people on the margins, this isn't going to happen. That kind of power is just the privilege of being a large, wealthy trading block and it's basically the reason the EU exists.

What would happen if The Netherlands or Poland tried to individually enforce a regulation as onerous as the GDPR on all companies holding data on their citizens? Nothing. Either companies would just withdraw from those markets or they would rely on the impossibility of enforcement. The EU is a sovereignty compromise that gives up some local de jure sovereignty for greater EU-wide de facto sovereignty.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#130
post #69

Earlier quoted context omitted.

What you don't realize is that the lawlessness around user data hurts big corporations too. If you're a big corporation collecting significant data than you've taken on a significant liability but the nature of this liability is amorphous. How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? How much can you share in your api? Wh…

> How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? Historically, these numbers have been $0.0+/-0. Executives aren't exactly bumbling around with hazardous materials.

Tell that to Equifax.
Post reply on HN