Live data from Hacker News

Silicon Valley is terrified of California’s privacy law

techcrunch.com

451–460 of 553 posts

Re: Silicon Valley is terrified of California’s privacy law

#451
post #428
post #386

Earlier quoted context omitted.

> Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so How is this an argument against the law? It doesn't make it illegal to share data but requires that users can opt out. If said large majority is fine with surveillance, I guess Silicon Valley can relax.

He's saying being able to "opt out" is absurd. It's equivalent to getting the product for free in most cases. "Hey, I want to use your free service but I want to go ahead and opt out of the part that enables it to be free " You don't see a problem with that? It would be like if there were a restaurant that gave free food in exchange for filling out surveys (data collection). So you eat the free meal and then "opt out…

The idea that free is only possible by trading data is absurd. E.g. Google search and maps can provide sponsored results without knowing everything about you. News sites can have ads related to their content and general target audience.

Re: Silicon Valley is terrified of California’s privacy law

#452
post #323

Earlier quoted context omitted.

> The "anonymous" side's solution here is, "anybody should be able to convincingly and legally lie about their physical location to (virtually) any business." If that solution is implemented, GDPR and Right to Be Forgotten don't work because it's impossible to verify jurisdiction. How is that? GDPR protects EU residents when they are outside the EU, so you already can't just look at someone's location and decide not…

GDPR protects EU residents (even abroad) when a business sells to them (or when a website targets them). At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen. You have a couple of choices with a law like this: 1. Just comply with GDPR anyway. That's honestly the easiest choice, especially if you're already privacy conscious. B…

> At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen.

Why? If you have decided to become GDPR compliant then you don't need to know which customers are EU residents. If you really want to know if some customers are not EU residents, you can ask them. There is nothing in the GDPR that requires GDPR residence to prove their residency before you must comply with the GDPR.

> "I'll just comply with every country, and that way I'll never need to figure out who my customers are."

Like most things, you need to comply with the laws of every country you do business in or face the prospect of penalties (which may or may not be enforceable without a legal presence in that country). This is nothing new.

> If you don't want to verify, you can just ask the person if they're European and block them if they say 'yes.'

You could, and some companies have thrown a hissy fit and decided to do location based blocking when there is no evidence that this is sufficient or necessary to indicate that you don't do business in the EU.

This isn't strictly necessary. As long as you don't target EU residents, you don't need to comply with the GDPR. Just don't advertise to europeans, don't talk about having european customers, don't ship to european adresses and/or don't localize to languages from countries where you don't do business.

> In the US, the most direct analogy here is COPPA. COPPA is a set of privacy restrictions for what information can be collected about children under the age of 13. There are traditional ways you can fall foul of COPPA (some sites are just obviously targeting children). But for the most part, the US went with option 3 -- you ask people their age before they sign up for your site, and you block them if they're under 13.

This is not very accurate. COPPA covers more than just what data can be collected. It also has provisions that require the ability to opt-out of the data being shared with 3rd parties and provide notices that clearly detail what your and 3rd parties will use the data for (and who they are and what they do). Additionally, COPPA requires parental consent to collect this data.

COPPA is IMHO a flawed law, the general privacy protections should have just been extended to everyone. Age verification and consent validation were never going to work and it seems patently ridiculous to require companies to collect more dat a to protect privacy.

Re: Silicon Valley is terrified of California’s privacy law

#453
post #380
post #332

Earlier quoted context omitted.

> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…

General population is simply not aware of how much surveillance is involved and how much of their private information said companies collect, use or sell to 3rd parties. Many are happy to get "free" service in exchange for "some data", but most people people would be very much against someone data mining their health or pregnancy status, using some sophisticated algorithm to selling something harmful to their kids or…

I agree and this seems to be the main problem: we are losing privacy today but we will suffer most of the consequences tomorrow. So most of us are not aware of the real cost we're paying and unable to make an informed decision.

Re: Silicon Valley is terrified of California’s privacy law

#454

Earlier quoted context omitted.

I like that the webshit data robbers downvote me for saying what they're doing is evil, yet if I showed any particular one what kind of information I have access to about them, just as a random private citizen interested in these things, they'd freak out and call me a creep. It's a shame what money does to people.

> yet if I showed any particular one what kind of information I have access to about them This is where the line is drawn for most - if people from Facebook, Amazon or Google look at information other than machines. Totally fine if it's just a computer with a strong law like GDPR safeguarding it.

People are looking.

Re: Silicon Valley is terrified of California’s privacy law

#455
post #452

Earlier quoted context omitted.

GDPR protects EU residents (even abroad) when a business sells to them (or when a website targets them). At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen. You have a couple of choices with a law like this: 1. Just comply with GDPR anyway. That's honestly the easiest choice, especially if you're already privacy conscious. B…

> At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen. Why? If you have decided to become GDPR compliant then you don't need to know which customers are EU residents. If you really want to know if some customers are not EU residents, you can ask them. There is nothing in the GDPR that requires GDPR residence to prove their re…

You're circling around the point.

> Like most things, you need to comply with the laws of every country you do business in

How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you? If I'm selling a digital product, how do I know whether or not EU citizens are buying it?

You suggest below:

> As long as you don't target EU residents, you don't need to comply with the GDPR. Just don't advertise to europeans, don't talk about having european customers, don't ship to european adresses and/or don't localize to languages from countries where you don't do business.

This is the COPPA strategy, choice #3. It suggests that as long as you can pretend you don't know your customers are EU residents, it's fine to collect data on them. If that's the case, that's a much less effective law then we could otherwise have.

In regards to COPPA, you bring up the central problem yourself:

> COPPA is IMHO a flawed law, the general privacy protections should have just been extended to everyone. Age verification and consent validation were never going to work and it seems patently ridiculous to require companies to collect more data to protect privacy.

You're right, age requirements are a joke. We still don't have a reliable way to validate age without violating privacy. These types of laws only work if they're based on one of the three choices I listed in my post:

1. Universally applying the law to everyone, regardless of context.

2. Accepting that validation requires collecting and managing data, and being OK with the fact that we're going to collect and manage data to do validation.

or

3. Trusting consumers to self-validate and self-sort themselves.

The first option has sovereignty problems -- it doesn't work in a multi-nation, multi-state world. Even with something like COPPA, this strategy falls apart because a big part of COPPA is parental consent, and there's no way to universally apply a parental consent law. At some point, you have to decide whether or not you're going to validate the relationship between the child and the parent.

The second option is fine if you want to control your data, but means that we need to give up some anonymity -- maybe make a national database, or have some kind of proof-of-age or digital passport or something.

The third option is fine if you want to stay anonymous, but means that data protection laws have fewer teeth, because consumers will lie, which gives companies plausible deniability over violations.

What we can't do is have both 2 and 3. We can't say, "we won't require anyone to do any invasive validation, and also the validation will be really good and accurate." With GDPR, we either accept that many EU residents will unwittingly (or deliberately) do business with companies that are not beholden to GDPR, or we accept that businesses will need to validate the citizenship of their customers.

Re: Silicon Valley is terrified of California’s privacy law

#456
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

This explains it, I think that California took same diction.

Giovanni Buttarelli, European Data Protection Supervisor “There might well be a market for personal data, just like there is, tragically, a market for live human organs, but that does not mean that we can or should give that market the blessing of legislation.”

Privacy is fundamental human right that you cant trade for. Same as you cant sign a lawfull contract that you want to be someones slave, even if you want to.

Re: Silicon Valley is terrified of California’s privacy law

#457
post #450

Earlier quoted context omitted.

> The privacy agreements of gmail, facebook and what not, serve like a poll for this I don't think they do, given that most people don't read them, and a large percentage of them are written so it's very hard to tell what they are really saying unless you're a lawyer.

That nobody gives a damn and doesn’t even read it kinda proves the point, no?

No, because it presupposes that people understand what they might be implicitly allowing by not reading them. Without first knowing whether or not people understand the extent of surveillance that is possible and the possible consequences we can not know what it means that people ignore the privacy agreements.

It's possible people genuinely don't care. It's also possible they don't understand the implications, and/or that they trust these companies more than they ought to.

Re: Silicon Valley is terrified of California’s privacy law

#458

Earlier quoted context omitted.

> People will pay 5$ for 50 cents of coffee beans and enough sugar to drown a fly a day, but they will never pay 5$ a month to access nearly the entirety of mankind's collective knowledge at their fingertips in milliseconds I pay a lot more than $5/month for Internet service.

Would you pay $5 on top of that ISP charge to Google, so that your search experience is ad-free? Would you pay $5 for fastmail.com's standard plan over gmail?

$5 for a tracking free Google, including no Google ads on any site? Maybe. But then it would be $5 to any other tracking network and there will probably be some other tracking with no opt out. I'll be still running adblockers and privacy extensions, so paying is pointless.

Re: Silicon Valley is terrified of California’s privacy law

#459
post #172
post #52

I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…

> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service. This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason…

> Making it illegal to withhold services if you don't give up your data is crazy.

Maybe you can show me generic ads based on your content instead of targeting them based on where I've been on vacation last month, etc.

Or simply stop building businesses based on people data. Sell something people want to pay for. Humankind has been able to do that for thousands of years, did we forget how to do it?

Re: Silicon Valley is terrified of California’s privacy law

#460

Earlier quoted context omitted.

No this is one of the most verified facts. The privacy agreements of gmail, facebook and what not, serve like a poll for this: if you use the service you agree to this. Majority of people use Gmail, Facebook, etc. So this is not anecdotal. On the other hand the desire to "protect" privacy at the expense of free services is based on anecdotal data at best.

If it is a fact then show me the proof. Just because people use a service doesn’t mean they have read the terms and conditions. Therefore, your anecdote is just that.

Using the service is generally an acceptance and agreement to the terms of service.

A similar analogy is that I may not want to read my credit card bill, that doesn't eliminate the responsibility I have to pay it. Or, I may not want to read my visa card notice they send informing of a change in the APR or other conditions for service. however, my continued use of the card is the standard way one accepts new or changed TOS.

Maintaining ignorance doesn't excuse the actions.

Post reply on HN