Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

631–640 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#631

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Yes, the solution is clearer rules. What drives compliance costs up is rarely the compliance itself, it's usually the uncertainty about your being in compliance or not. That's also true for tax laws, labor laws, environment laws, almost every safety code out there, building zoning...

And the answer should be self-served, ideally, with an automated authoritative self-served approval. It could have a lag time of a few days or even a week for a person to approve.

Apple App Store review is a nightmare but still better than these regulations. They say yes or no clearly.

These EU regulations are more like: if you fuck up, you wouldn't know until the sentence might be really really high.

Re: Europe is scaling back GDPR and relaxing AI laws

#632
post #615
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Every regulation has some unforeseen consequences. Most of the time it's impacts are worse than the effect we wanted to regulate from the start. Us humans discard the effects we can't predict as benign even over smaller inconveniences we can see.

> Every regulation has some unforeseen consequences.

This argument would feel a lot less insincere if the people who always trot it out also used it every time something gets deregulated.

> Most of the time it's impacts are worse than the effect we wanted to regulate from the start.

Are they though? Or do you only hear a disproportionate amount of complaints because of manufactured consent? Because I sure as hell don't trust the talking heads on TV backed by billionaires who don't like to see people push back at their greed and lust for power.

Re: Europe is scaling back GDPR and relaxing AI laws

#634
Here's a story about how the mere perception of "regulations exist and are strict" is dragging down my european AI start-up:

Our product makes it easy to capture and share knowledge on the factory floor, which is very important when many of your workers about to retire. Interest is enormous. It is a simple SaaS. You'd think selling would be easy. And it is: In the USA. In Europe the mere existence of the regulations (not what's in them) delays us by 6 months at least per deal.

No european executive really understands what is in the GDPR, and eventhough we are 100% compliant, there is nothing we can do to take away this fear. This means that when we talk to European companies, IT and Legal departments always have to be closely involved, leading to all sorts of political games; each department conjures up non-existing risk by talking vaguely about data privacy, just so they appear important. Half a year later when the dust has settled, the executive buys the product, or their mind has moved to other things.

My point is this: What is in the laws is not important to me. What is important is that current perception of laws turn companies into slugs. I want us to mentally move back to 2018 where we could "just buy SaaS" without worrying endlessly about data privacy. I understand hesitency when it comes to cyber security, but that is not what is slowing us down.

One of our workarounds currently is simply never to mention we use AI.

Re: Europe is scaling back GDPR and relaxing AI laws

#636
post #527

Earlier quoted context omitted.

> Doesn't that describe SV in general, and big tech in particular? Absolutely! It's just that the hopeful hacker/nerd culture used to be more dominant here (slashdot had the more cynical types). Now there are a generation who don't know anything but Javascript but think that they're God's gift to programming. I can understand it as ZIRP resulted in the bar being dropped to the floor for jobs which paid SV salaries. I…

This sounds too much like a 'good old days' argument, which is actually in the HN guidelines (something like, 'don't say HN is becoming Reddit').

No. It's reflecting on an overall culture that embraces taking chances. Even if 50% of those chances lead to failure it still beats the paralyzing fear of moving forward.

Re: Europe is scaling back GDPR and relaxing AI laws

#637
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.

I agree

People bemoan bureaucracy (which is a totally fair criticism) without understanding its deeper meaning:

Bureaucracy is how it works

That's it. Digital government is also bureaucracy. Applying to YC is also bureaucracy.

Of course the meaning drifted with the times, but it still means that

First definition here https://dictionary.cambridge.org/dictionary/english/bureaucr...

Re: Europe is scaling back GDPR and relaxing AI laws

#638
post #28

Earlier quoted context omitted.

It's pretty telling that people here think enforcement of anti-trust laws that are already on the books is "extreme". The implicit goal of half of tech startups is basically becoming the platform for whatever and getting a soft monopoly, so I guess it's not surprising that that people who are temporarily embarrassed monopolists have these views.

Look at what happened to iRobot vs. Roborock though.

can someone explain what happened? how is it relevant to EU laws?

Re: Europe is scaling back GDPR and relaxing AI laws

#640
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

That cookie banner needs to be standardized and offered by the browser. It should be like a certificate popup. Why is every website forced into doing a shoddy job ?

I assume it's because a business has different ideas about what to collect from their users and users are more or less willing to share some data with some specific businesses. Hence, every business needs their own consent rules. The fact that this is achieved with a cookie banner for 99,9% of all businesses is a side-effect. Could there be a better solution? Probably. But the law and the incentives aligned to cookie banner hell.
Post reply on HN