Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

471–480 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#471
post #205
post #131

Earlier quoted context omitted.

The main thing I have in mind is machine learning algorithms that optimize for engagement. Those aren't necessarily biased in favor of a specific political position, but tend to amplify rumors over well-sourced reporting, demagoguery over reasoned debate, and often malicious false claims. Off the top of my head, I don't have a good way to differentiate those algorithms in legal terms. As another comment points out, e…

OK, that's at least a more reasonable thing to be worried about [0], but as you say trying to use the law there would be damn near impossible. Take the case of a law against airplanes/cats again. I'd definitely feel very, very strongly about such an effort, and want very, very much to defeat it. In the democratic system that means rallying a critical mass of fellow citizens. If it so happens my airplane/cat platform…

I'm also wary of solving issues with speech or information technology[0] through regulation. That said... if I run a microblogging site HN-rumors.com, somebody might post "xoa is a thief", and harm might come to you because of that. You could sue the poster, but you could not sue me. This holds true even if I moderate the site and remove other content. Good so far, right?

Now what if I hand-curate a front page? If I feature this libelous rumor on it, I'm acting like an editor/publisher rather than a platform and the chances you can successfully sue me go up. What if I pick the users who have been most responsive to that sort of content and email it to them in the hope they'll visit my site and spend more time there as a result? I see my legal risk increasing even more.

Of course it's easy to hold a person responsible when a person is making the decisions. It's harder to say exactly what criteria an algorithm can use, and not the sort of thing I'd want a politician or bureaucrat deciding. Perhaps what I really want is for people to voluntarily stop using corporate social media so much, but I don't know how realistic that is.

[0] Other technologies are better-suited to regulation; I think I wouldn't want to fly on an airplane that got only the maintenance the market demanded.

Re: Your compliance obligations under the UK’s Online Safety Bill

#472
post #463

Earlier quoted context omitted.

They're decisions by the governments of Germany, France, and Italy: * https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/ * https://www.cnil.fr/en/use-google-analytics-and-data-transfe... * https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/d... So far they've just been enforced against companies that use Google Analytics, but the reasoning behind it has been that having users connect to a US server e…

How does any of those things make it "essentially impossible for any US-owned or US-hosted site to comply with GDPR"? Is it legally required in the US, for example, to use Google Analytics?

No, but that's irrelevant. It's illegal for an American to host a home server with EU visitors for the same reason it's illegal for them to use AWS or Google Analytics. A GDPR-compliant website can't embed Google Analytics or Google Fonts or a US-hosted image because then the host could log those IP addresses and the host could be subject to a US warrant. Likewise, a GDPR-compliant site can't be operated or hosted by an American because then the operator/host could be logging visitor IP addresses and be subject to a warrant and be compelled to give the government the evidence.

Re: Your compliance obligations under the UK’s Online Safety Bill

#474
post #463

Earlier quoted context omitted.

How does any of those things make it "essentially impossible for any US-owned or US-hosted site to comply with GDPR"? Is it legally required in the US, for example, to use Google Analytics?

No, but that's irrelevant. It's illegal for an American to host a home server with EU visitors for the same reason it's illegal for them to use AWS or Google Analytics. A GDPR-compliant website can't embed Google Analytics or Google Fonts or a US-hosted image because then the host could log those IP addresses and the host could be subject to a US warrant. Likewise, a GDPR-compliant site can't be operated or hosted by…

> Likewise, a GDPR-compliant site can't be operated or hosted by an American because then the operator/host could be logging visitor IP addresses

Because you "could" be logging visitor IP addresses? First, why would you have to log them? Is this a legal requirement in the US? You can't serve a page over HTTP unless you log a crapton of stuff for the government? And second...I don't believe it's illegal to log IP addresses under GDPR as log as the user consents to it...or is it?

Re: Your compliance obligations under the UK’s Online Safety Bill

#475
post #448

Earlier quoted context omitted.

Another version: no I am not. I'm impressed with how many people really do not understand the meaning of these terms. The idea that the US is culturally divided makes a lot more sense to me now, reading all of these responses.

> I'm impressed with how many people really do not understand the meaning of these terms. When multiple people tell you that you’re wrong and no one else is taking your side, the rational response is to consider that you may be wrong. But, as humans, we sometimes lack the willingness (or perhaps ability) to do so.

It's a losing battle - people are wise not to jump in. I'm even restraining myself from providing my own reasoning.

"eppur si muove"

Re: Your compliance obligations under the UK’s Online Safety Bill

#476
post #474

Earlier quoted context omitted.

No, but that's irrelevant. It's illegal for an American to host a home server with EU visitors for the same reason it's illegal for them to use AWS or Google Analytics. A GDPR-compliant website can't embed Google Analytics or Google Fonts or a US-hosted image because then the host could log those IP addresses and the host could be subject to a US warrant. Likewise, a GDPR-compliant site can't be operated or hosted by…

> Likewise, a GDPR-compliant site can't be operated or hosted by an American because then the operator/host could be logging visitor IP addresses Because you "could" be logging visitor IP addresses? First, why would you have to log them? Is this a legal requirement in the US? You can't serve a page over HTTP unless you log a crapton of stuff for the government? And second...I don't believe it's illegal to log IP addr…

Yes, the EU says it's illegal if you could be logging them, regardless of whether you are or not.

And yeah, it's not illegal if a user consent to it, but the issue is that the user has to connect (with their IP address) to give you his consent or not. That's why I said theoretically you could use some international service to handle all primary routing and get users to waive their rights under the GDPR before connecting to your website proper, but I'm not aware of such a service at this time.

Re: Your compliance obligations under the UK’s Online Safety Bill

#477

Earlier quoted context omitted.

Our system for our kids was no smart phone until ~14 and not taking it to bed until senior year. With all computers, each person has their own, in a shared family office. That and answering questions and talking to our kids about the internet, the good and the bad. No filters or other bullshit. So far (oldest is about to head to university) so good.

I plan to take it further. No smart phones at all until 18, and only a dumb phone (calls, texts, etc) whenever they start high school, or possibly a bit earlier if they're on public transport by themself. I see absolutely no reason for somebody till in school to need a smart phone.

This sounds like what my religious nut parents would have done if smartphones had existed when I was a teen.

Their efforts to shelter me didn't work and caused me to feel guilt about seeking information about the outside world as I aged.

If you're really religious then you're not going to listen to me anyway, but if you're not then please reconsider depriving your children like this.

Re: Your compliance obligations under the UK’s Online Safety Bill

#478
post #171

Earlier quoted context omitted.

If the article is to be believed, then simply ignoring this law would open your company's leadership up to criminal liability in the UK. This probably doesn't matter too much, assuming they never fly through Heathrow or something.

I mean you can just ban all UK IPs and be done with it. Its clearly not a sensible law, and blocking users will send a clear message to them that they should complains about it.

According to the article, you'd still need to document the technical process you use to ban the IPs, and also the business processes you haven in place to govern the technical process. That all has to be sent in to the British government with a filing fee, and it's unclear whether even that is enough to appease their regulators or not.

Re: Your compliance obligations under the UK’s Online Safety Bill

#479
post #474

Earlier quoted context omitted.

> Likewise, a GDPR-compliant site can't be operated or hosted by an American because then the operator/host could be logging visitor IP addresses Because you "could" be logging visitor IP addresses? First, why would you have to log them? Is this a legal requirement in the US? You can't serve a page over HTTP unless you log a crapton of stuff for the government? And second...I don't believe it's illegal to log IP addr…

Yes, the EU says it's illegal if you could be logging them, regardless of whether you are or not. And yeah, it's not illegal if a user consent to it, but the issue is that the user has to connect (with their IP address) to give you his consent or not. That's why I said theoretically you could use some international service to handle all primary routing and get users to waive their rights under the GDPR before connect…

> Yes, the EU says it's illegal if you could be logging them, regardless of whether you are or not.

Wait, what? Where do they say that?

> That's why I said theoretically you could use some international service to handle all primary routing and get users to waive their rights under the GDPR before connecting to your website proper

Why would you do such a complicated thing?

Re: Your compliance obligations under the UK’s Online Safety Bill

#480

Earlier quoted context omitted.

The fundamental core of conservatism is exemplified in Chesterton's Fence, the meaning of which comes down to "make changes with extreme caution", not "don't make changes at all". The inverse of conservatism is the desire for revolutionary change, which is not the same as progressivism (though it's certainly a popular idea with some). Anti-industrialism (e.g. the Ludites) was conservative. Environmentalism can be con…

I've heard the fundamental position of conservatism slightly differently: "if something doesn't have to change, then it must not change". As such, the opposite may well be "let's change this and see if it helps". But behind this fundamental position, there still lies the position that the current state of affairs is fundamentally ok, or very close to it (or if not the current one, then some previous one that you aspi…

You don't need to believe that the current state of affairs is "fundamentally ok, or very close to it", quite to the contrary. What you need to believe is that the current state of affairs could be made much worse if one is not careful.

I think most people agree that through history we've made a slow climb up a mountain. And it's always easier to fall down, than it is to continue climbing. One could look down into the abyss and say "we must be careful not to trip", or one could look up at the top of the mountain and say "we must get there at any cost". In this metaphor I'd say the revolutionary would be looking at another peak in the mountain range and say "we must descend into the abyss if we want to make it there".

Post reply on HN