Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

201–210 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#201

Earlier quoted context omitted.

Not "hard" for us, no, even if an unnecessary burden. Now go make some small veterinary clinic with no "computer person" on hand, with a small website they had set up years ago that lets you schedule appointments, figure all this out. They'll probably either stay uncompliant or have to drop the website.

That's a shame, but it's a side effect of anything ever that requires an update. Any small business commissioning a site in 2019 will get something that's compliant, so it's not like this is a permanent drain. Sometimes it's important to update regulations, despite the inertia of existing implementations.

This attitude reminds me of a quote: "Some of you may die, but it's a sacrifice I am willing to make."

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#202
post #139

Earlier quoted context omitted.

It's not a narrow and pedantic difference at all! It's the entire thing! You seem to be under some mistaken impression that you can say whatever you want whenever you want in the United States. You can't. There are many categories of speech that are banned in the US as well: if I think to myself "Tom Smith is a liar and a drunkard and he's cheating on his wife", that's perfectly fine, but if I communicate that to a l…

I'm not under that impression; I've spoken a lot here on HN about the limits of free speech. Legal limitations on freedom of speech almost always stem from pragmatic consequences, e.g. unfair damage to Tom Smith's reputation. When people speak of "thoughtcrime", they refer to cases in which expressing an idea itself is seen as reason for punishment, regardless of whether any consequences occur. Here's my question: un…

Man, you guys should really read 1984, it's a great book!

This is one of the central themes of 1984, that Ingsoc ("the Party") tries to control not just the speech and actions of their subjects, but their very thoughts. Literally: in 1984, having thoughts that goes against the party is illegal. That is why it's called "thoughtcrime", because it's the thought itself, even if it goes totally unexpressed in any way. Such crimes are punished by the "Thought police", who quite literally police thoughts. When a dangerous thought presents itself, you're supposed to use "crimestop", a technique for ridding yourself of that thought. Here's a quote from 1984:

> The mind should develop a blind spot whenever a dangerous thought presented itself. The process should be automatic, instinctive. Crimestop, they called it in Newspeak.

Oh, and yes: Newspeak! The language developed by the party with restricted vocabularies and grammar so that some thoughts will be literally unthinkable.

I took that quote from the wikipedia page on "thoughtcrime", which helpfully begins like this:

> A thoughtcrime is an Orwellian neologism used to describe an illegal thought. The term was popularized in the dystopian novel Nineteen Eighty-Four by George Orwell, first published in 1949, wherein thoughtcrime is the criminal act of holding unspoken beliefs or doubts that oppose or question Ingsoc, the ruling party. In the book, the government attempts to control not only the speech and actions, but also the thoughts of its subjects.

Feel free to look in any other dictionary or reference work, they will all say the same thing, some variation on "a thought that is illegal". I could go on with many more examples of how 1984 talks about thoughts (you should google "doublethink"! or maybe just read the book), but you get my point.

Your reaction, "how could 'thoughtcrime' possibly be detected, let alone punished?" is what the book is about. Every reader of 1984 reacts that way in the beginning, and the book is an exploration about what that very concept means, and what the implications are.

Look, the argument you are making is something like "European hate speech laws are an unacceptable abridgment of free speech and democratic rights". Which is a fine argument to make: I personally don't think so, but reasonable people can disagree on it and discuss it. What it is not is "thoughtcrime". It's just not what the term means.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#203

Earlier quoted context omitted.

That's a shame, but it's a side effect of anything ever that requires an update. Any small business commissioning a site in 2019 will get something that's compliant, so it's not like this is a permanent drain. Sometimes it's important to update regulations, despite the inertia of existing implementations.

This attitude reminds me of a quote: "Some of you may die, but it's a sacrifice I am willing to make."

Better than the idea that we can never change any law because someone will have to adjust to it.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#204
post #63

Earlier quoted context omitted.

These recently-discovered European "rights" are probably non-starters, but the ability to get a Google-takeout style package of your own data, and some reasonably protections regarding consent and the way your data is used would clearly Constitutional. We already force some industries to follow most of these precepts in other laws that haven't been challenged: credit agencies have to explain your credit score to you,…

If you actually read up on the "right to be forgotten" you will see that "free speech" is always an exception to it. You cannot demand to be forgotten in order to censure others.

The American interpretation of “free speech” is much more broad than in the EU. Here, laws banning hate speech or flag burning or corporate campaign donations are unconstitutional for example. Libel lawsuits are much harder to pull off here as well.

A law requiring businesses and individuals to delete any personal data at the request of the data subject, as the GDPR requires, would have to be extremely narrowly written to survive constitutional muster here, I think.

If I do business with you and write down your name, the GDPR requires that I delete your name if you ask me to (and even if you don’t if our relationship ends). That wouldn’t survive a First Amendment challenge here.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#205
post #172
post #157

Earlier quoted context omitted.

Can you tell me which country allows people to threaten witnesses at trial?Which country allows reporters to call a defendent a muslim child rapist before the verdict is reached?

If it had been the other way around and some white guy was being called a “Nazi child rapist”, I’d expect them to get away with it in pretty much any western country. It’s true that his behavior was illegal, but the reason he was prosecuted was ultimately the content of his speech in my opinion. There have been other right wing figures who’s names I don’t recall who were also recently convicted, and they weren’t spea…

I'd have a bit more sympathy if he hadn't previously done exactly the same thing, and been given a suspended sentence and a clear unambiguous warning from a judge not to do it again.

He's not being silenced because he's right wing. He's being silenced because he's jeopardising trials and threatening witnesses.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#206
post #171
post #145

Earlier quoted context omitted.

It depends what data you had; why you had it; whether you knew you had it; and how it was hacked. https://ico.org.uk/about-the-ico/news-and-events/news-and-bl... > The data was taken from an underlying customer database that was part of TalkTalk’s acquisition of Tiscali’s UK operations in 2009. The data was accessed through an attack on three vulnerable webpages within the inherited infrastructure. TalkTalk failed to…

That's not a GDPR fine, that's an ICO fine under a different (but similar and related) regulation (Germany and France have similar ones IIRC). The suggestion is that the US adopt GDPR-style regulation, which penalizes for infringement to procedures of data governance, NOT whether data is actually breached. (EDIT: obviously a breach will trigger a GDPR investigation)

Yes, that's an ICO fine under the previous data protection law in the UK.

Now that we have GDPR and the new data protection law ICO will be issuing fines under the new law.

This old case is an example of how the ICO regulate, and the things they'll take into account. GDPR wouldn't make much difference for this case.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#207
post #179
post #168

Earlier quoted context omitted.

What's the problem with that? The "whichever is higher" doesn't refer to the fine, but to the limit it can be "up to". Something a bit more verbose could have been easier to understand, true, but there's no doubt about what it means.

> but to the limit it can be "up to". So then why not just set it to a percent of revenue? If you're just going to slap a small company with minimal turnover with €1k fines anyway, then why the need for the "up to €10M" amount?

What if the company has huge cash reserves/holdings but artificially low turnover?

Depending on how quickly regulators can act, and how they would determine the date of precedence for 'the preceeding financial year', it's just about conceivable that a company might have >1 year of warning to do some financial trickery to minimise their fines.

Having a range(0..max($turnover_amount, $fixed_amount)) reduces the scope for that sort of trickery.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#208
post #202

Earlier quoted context omitted.

I'm not under that impression; I've spoken a lot here on HN about the limits of free speech. Legal limitations on freedom of speech almost always stem from pragmatic consequences, e.g. unfair damage to Tom Smith's reputation. When people speak of "thoughtcrime", they refer to cases in which expressing an idea itself is seen as reason for punishment, regardless of whether any consequences occur. Here's my question: un…

Man, you guys should really read 1984, it's a great book! This is one of the central themes of 1984, that Ingsoc ("the Party") tries to control not just the speech and actions of their subjects, but their very thoughts. Literally: in 1984, having thoughts that goes against the party is illegal. That is why it's called "thoughtcrime", because it's the thought itself , even if it goes totally unexpressed in any way. Su…

If what you took from the book was "thoughtcrime is only when someone's literal thoughts are illegal, and whenever those thoughts manifest themselves, it's something else", then you are missing the forest for the trees. Is Winston arrested when he thinks subversive thoughts about the Party? Of course not; he's arrested when he colludes with whom he assumes are allies of Goldstein. By your own definition, there is no instance of thoughtcrime detected or punished in 1984. Even Parsons was actually reported by his daughter for denouncing Big Brother in his sleep.

I am not making any argument about European hate speech laws whatsoever. My issue is solely with the pedantic definition of the word "thoughtcrime" that is at odds with how it's actually used.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#209
post #87

as an american, no thank you. compelled speech is not okay

wtf? How is requiring you to be responsible for other people's information that you collected "compelled speech"? If you don't want the law to affect you, don't spy on people, it's that simple.

if you don't want to agree to my terms of service, don't use my service. don't force me to implement features and increase costs on other voluntary users. don't use products you don't want to use, its that simple.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#210
post #133

Earlier quoted context omitted.

> Can’t all this GDPR stuff be abstracted away into a framework? Or at least some kind of pattern/generator tooling? I understand why you think this way! It's an obvious approach, where there's a bunch of stuff that needs to be done and it's the same everywhere. Why not just have a framework that handles it all for you? It's so clear! It's perhaps possible that many of the requirements of GDPR are beyond the scope of…

I get the process parts, that make more sense to have a human interface, can’t be abstracted out. However, maybe they can? Compliance as a service? Sounds like just the kind of Bay Area centric idea that VC’s love to fund. But it seems like there’s some commen sense patterns that our tooling should take up. A framework can take up the transparency, and user control aspects. Framework might be too narrow, platform mig…

You're once again completely right! Some of this could be farmed out with compliance-as-a-service!

However, it's perhaps possible that certain parts of GDPR impact core businesses processes involving the handling of customer data. None of this can be farmed out in a hands-off manner. It requires deep integration into your daily business. I cannot think of any framework that could handle such a thing, or a compliance service that could handle it for you.

You could definitely offer GDPR-compliance Wordpress or Magento as a service! It's just possible, however, that some things your customers could do with your offering might hold the potential to violate GDPR. As a result, you could not guarantee that you assume all the compliance requirements on their behalf in all cases.

In short, you're right! There is definitely room for some compliance services to be offered as a service! It's just, barely, possible that some small fraction of the items concerned might not be well-suited to this approach is all.

Have you considered reading the text of GDPR? You might find it to be an educational and informative experience. I did.

Post reply on HN