Earlier quoted context omitted.
> Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so How is this an argument against the law? It doesn't make it illegal to share data but requires that users can opt out. If said large majority is fine with surveillance, I guess Silicon Valley can relax.
He's saying being able to "opt out" is absurd. It's equivalent to getting the product for free in most cases. "Hey, I want to use your free service but I want to go ahead and opt out of the part that enables it to be free " You don't see a problem with that? It would be like if there were a restaurant that gave free food in exchange for filling out surveys (data collection). So you eat the free meal and then "opt out…
Silicon Valley is terrified of California’s privacy law
511–520 of 553 posts
Re: Silicon Valley is terrified of California’s privacy law
#512I see a lot of comments deriding this law, can someone explain to me why these are bad things? Quoting from this article - https://techcrunch.com/2018/06/28/landmark-california-privac... - Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with. - Businesses would be required to comply with official consumer requests to delete that d…
Every state will end up having a different law like this, and it will be terrible adhering to each one.
Re: Silicon Valley is terrified of California’s privacy law
#513Earlier quoted context omitted.
I agree and this seems to be the main problem: we are losing privacy today but we will suffer most of the consequences tomorrow. So most of us are not aware of the real cost we're paying and unable to make an informed decision.
Welcome to democracy, where an individual with zero understanding of an issue can vote on it and is legally entitled to have their opinion taken seriously.
Re: Silicon Valley is terrified of California’s privacy law
#514Earlier quoted context omitted.
> "Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data? Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell the…
I think you’re missing the point. At least I know where my data is. Have you ever read a GDPR popup partner list? Do the people you mention understand how gmail business model works?
Re: Silicon Valley is terrified of California’s privacy law
#515Earlier quoted context omitted.
> At the point of sale, in order to figure out whether or not GDPR applies, a business needs to figure out whether or not someone is an EU citizen. Why? If you have decided to become GDPR compliant then you don't need to know which customers are EU residents. If you really want to know if some customers are not EU residents, you can ask them. There is nothing in the GDPR that requires GDPR residence to prove their re…
You're circling around the point. > Like most things, you need to comply with the laws of every country you do business in How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you? If I'm selling a digital product, how do I know whether or not EU citizens are buying it? You suggest below: > As long as you don't target EU residents, you don't need to comply w…
> How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you?
The GDPR lays out guidelines for what qualifies as doing business in the EU and it has nothing to do with verfying the nationiality of your customers (or doing geoip blocking). It has to do with the sorts of things I already explicitly mentioned such as advertising that specifically targets EU residents, localization into EU languages, shipping to EU addresses, etc.
> The first option has sovereignty problems -- it doesn't work in a multi-nation, multi-state world.
Why not? We have plenty of other types of regulation that differ between countries. Companies that wish to do business in multiple countries have to comply with all the laws for those countries. If you want to make a single car model that you can sell in two different countries, it has to meet both countries safety standards. If a company has no legal presence in a country, there is not much those countries can do to enforce the laws. (This last point is the actual weakness of these privacy laws and will have to be addressed by international treaties. This is an issue with enforcing rules in general (i.e. copyright) and doesn't just apply to privacy laws.)
> because consumers will lie, which gives companies plausible deniability over violations.
How so? At worst all this might mean is that consumers who choose to lie won't be protected. Plenty of other people would be.
A combination of #1 and #3 should work just fine.
Re: Silicon Valley is terrified of California’s privacy law
#516Earlier quoted context omitted.
I just wanted to piggy-back onto the parent’s comment with a concrete example. I’ve always been told that it’s good practice to take periodic backups. In the absolute worst cases, you can simply restore directly from these. If a customer requests that their data are deleted, in addition to my production instance, does that mean that I have to remove their data from my backups? If so, I’m uncertain of the best way to…
Not sure about the legal framework in the US but over here across the pond, it's enough if you remove the data when restoring the backups (reasonably easy to do; took me about a day to implement that on an old codebase that I wrote more than ten years ago, and I haven't touched either PHP or that codebase since then...). IANAL but the guy who told us how it's done was, and in addition to all the legal stuff, of which…
Implementation-wise, is the best approach to do this to store some token for "user XX requested YY data be deleted" and check those tokens whenever you restore a backup?
I feel like that'd run befoul of a true solution because, in the event of a leak, it could be used to tie the information in the backup to the user who requested their data be deleted. Or am I misunderstanding such that that'd actually be acceptable under GDPR?
Is there a better way to do it?
Re: Silicon Valley is terrified of California’s privacy law
#517Earlier quoted context omitted.
This law's implementation is bad for the same reason GDPR's implementation is bad: the people it's meant to target are easily capable of complying (and likely already do) and it's good for "the people" on paper, but disproportionately affects (hurts) small businesses that don't have the means to comply (or even know if they're properly complying to the extent of avoiding a lawsuit).
Most of these requirements are perfectly reasonable and i don’t see any that are technologically difficult to implement unless you underlying business model relies on selling user data without regards, in which case, good riddance.
Re: Silicon Valley is terrified of California’s privacy law
#518Earlier quoted context omitted.
If it is a fact then show me the proof. Just because people use a service doesn’t mean they have read the terms and conditions. Therefore, your anecdote is just that.
Using the service is generally an acceptance and agreement to the terms of service. A similar analogy is that I may not want to read my credit card bill, that doesn't eliminate the responsibility I have to pay it. Or, I may not want to read my visa card notice they send informing of a change in the APR or other conditions for service. however, my continued use of the card is the standard way one accepts new or change…
Not really relevant to a change in the law.
Re: Silicon Valley is terrified of California’s privacy law
#519Earlier quoted context omitted.
Is this anecdotal or do you have empirical evidence?
No one's performed a proper survey AFAIK, but the GDPR opt-out rate is very very low, which provides weak evidence. This is not evidence of numbers, but I have an existence proof in that I also personally know a lot of people who know and insist on not opting out.
Re: Silicon Valley is terrified of California’s privacy law
#520Earlier quoted context omitted.
You're circling around the point. > Like most things, you need to comply with the laws of every country you do business in How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you? If I'm selling a digital product, how do I know whether or not EU citizens are buying it? You suggest below: > As long as you don't target EU residents, you don't need to comply w…
I am not circling around the point, you seem to have an incomplete understanding of both GDPR and COPPA that are leading you to make unwarranted assumptions such as: > How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you? The GDPR lays out guidelines for what qualifies as doing business in the EU and it has nothing to do with verfying the nationiality of…