Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

531–540 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#531
post #347
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Do you really think that clicking on any button on cookie consent popups actually does anything? It's just an illusion of choice. The reality is that these sites will still track you, whether that's via cookies or, more commonly today, fingerprinting. When they list thousands of "partners" with "legitimate interest", it's a hint that there's a multi-billion-dollar industry of companies operating behind the scenes tha…

I very much doubt, that the practice of putting hundreds or thousands of partners into the legitimate interest category is legal. I wish this was more challenged and brought in front of the courts. And not just wristslaps dished out. Such practices need to have business threatening punishments attached to them.

Re: Europe is scaling back GDPR and relaxing AI laws

#532
post #443

Earlier quoted context omitted.

FTA: “Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly.”

GDPR allows for essential cookies with no popup. Implied consent is valid for most functionality, just not selling peoples tracking data or giving it to a third party who could. Its entirely possible to have no pop-up. Someone once told me they wanted one anyway because it made the site seem more legitimate than if I removed it (the only thing I would have needed to change was the embedded video from youtube and I co…

No pop-ups on apple.com!

Re: Europe is scaling back GDPR and relaxing AI laws

#533
post #408
post #327

Earlier quoted context omitted.

Regulations are like lines of code in a software project. They're good if well written, bad if not, and what matters more is how well they fit into the entire solution

A major difference with regulations is there’s no guaranteed executor of those metaphorical lines of code. If the law gets enforced, then yes, but if nobody enforces it, it loses meaning.

The problem with laws that both the enforcer and the subject (enforcee?) agree are bad, is that enforcement is variable. And that leads to corruption. Every damn time.

Re: Europe is scaling back GDPR and relaxing AI laws

#534
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

I wish we standardized on Do Not Track headers. Cookie banners are a plague. Thanks Europe.

There is nothing stopping the industry from standardising on an alternative form of expressing consent, for example on browser installation. GDPR is agnostic to the form the consent takes, as long as it's informed and freely given.

However, by far the biggest browser is funded by a corporation that wants tracking data across the web. I'm not very surprised that the corporation haven't made it easy to refuse just once.

Thanks Google.

Re: Europe is scaling back GDPR and relaxing AI laws

#536
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Why not accept and let cookie autodelete delete it after closing the site?

Expecting any industry to follow the law is foolish, if it gets big enough, they will wear down and overturn any annoyance against it, malicious compliance is the only way.

https://adnauseam.io/

Re: Europe is scaling back GDPR and relaxing AI laws

#537
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

And when they use our data to profit, we don't get a royalty cut.

Re: Europe is scaling back GDPR and relaxing AI laws

#538
post #34

> users would be able to control others from central browser controls that apply to websites broadly. Great to see this finally. It’s obviously the way it should have been implemented from the beginning. We still see this technically myopic approach with things like age verification; it’s insane to ask websites to collect Gov ID to age verify kids (or prove adulthood for porn), rather than having an OS feature that c…

> We still see this technically myopic approach with things like age verification; it’s insane to ask websites to collect Gov ID to age verify kids (or prove adulthood for porn), rather than having an OS feature that can do so in a privacy-preserving way. Now these sites have a copy of your ID! You know they are going to get hacked and leak it! An OS feature is also a terrible option - remember when South Korean bank…

Sure, ideally we can decouple the provider implementation and use a yubikey-type device if we want, or let the OS Secure Enclave handle it for the 99% of users that don’t care.

The main point is it should be a protocol from the PoV of the consuming site, rather than a cop-out requirement enacted on the easiest place to legislate.

Re: Europe is scaling back GDPR and relaxing AI laws

#539

Earlier quoted context omitted.

I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.

I strongly agree with this position. This is basically the foundation of Control Theory! https://en.wikipedia.org/wiki/Control_theory This is like arguing if "heater on" or "AC on" is better, which is a pointless argument. That entirely depends on what the temperature is!

Reminds me of the book Thinking in Systems.

Thanks for the link.

Re: Europe is scaling back GDPR and relaxing AI laws

#540
post #443

Earlier quoted context omitted.

FTA: “Under the new proposal, some “non-risk” cookies won’t trigger pop-ups at all, and users would be able to control others from central browser controls that apply to websites broadly.”

GDPR allows for essential cookies with no popup. Implied consent is valid for most functionality, just not selling peoples tracking data or giving it to a third party who could. Its entirely possible to have no pop-up. Someone once told me they wanted one anyway because it made the site seem more legitimate than if I removed it (the only thing I would have needed to change was the embedded video from youtube and I co…

embedding youtube is enough to be non-cookiebanner-compliant??
Post reply on HN