Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

71–80 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#71
GDPR is not complex because it is hard to comply with but because seemingly no one wants to.

EU-US data transfers have been declared illegal numerous times [1], but instead of supporting European cloud providers those decisions are barely enforced and quickly circumvented by a new data transfer act.

Cookie banners are not hard to implement if you don't try to share user data with your "864 most trusted partners", there are clear guidelines [2] now on how they need to be designed, but instead of criticising these not being properly enforced, the requirement for them itself is criticised.

How is it that Meta can regular break the law, with 7 of the 10 highest fines (or probably around a third of all fines) going against them [3] with seemingly no action taken to prevent this from continuing onwards.

noyb has managed to achieve more than a billion euro in fines with only 6 million euros in funding, we could be focusing on supporting NGOs doing incredible work for their budget and getting our DPAs to probably enforce the law.

The issue with GDPR is not the law but the seeming unwillingness to enforce it leading to unclarity what is expected and what not. [4]

[1]: https://noyb.eu/en/23-years-illegal-data-transfers-due-inact... [2]: https://noyb.eu/en/noybs-consent-banner-report-how-authoriti... [3]: https://www.enforcementtracker.com/?insights [4]: https://noyb.eu/en/data-protection-day-only-13-cases-eu-dpas...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#72
post #59

Earlier quoted context omitted.

They should not be careless, but they can be spared some paperwork as long as they stay compliant with the spirit of regulation.

If you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.

This pretty much. I've had a lot to do with GDPR in the projects I'm involved with. It's largely trivial if you aren't already doing terribly risky things, in which case yeah, it's a pain, but it doesn't change the necessity of fixing issues that put user private data at risk (with or without the GDPR existing). GDPR just puts more incentive on solving issues in regards to privacy instead of just letting companies shrug and move on because it's not their problem if data is stolen or leaked or letting them do what they want with the data without permission.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#73
post #19

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

auto-accepts? We just go back to square 1 in 2011 in that case.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#74
post #71

GDPR is not complex because it is hard to comply with but because seemingly no one wants to. EU-US data transfers have been declared illegal numerous times [1], but instead of supporting European cloud providers those decisions are barely enforced and quickly circumvented by a new data transfer act. Cookie banners are not hard to implement if you don't try to share user data with your "864 most trusted partners", the…

> How is it that Meta can regular break the law, with 7 of the 10 highest fines (or probably around a third of all fines) going against them [3] with seemingly no action taken to prevent this from continuing onwards.

Because until now we've been treating American companies very leniently, with an occasional slap on the wrist. For example, when Poland wanted to regulate Uber, the American ambassador warned the Polish government that if they do that, they will regret it.[0] And because at that time the USA was in the business of of protecting the East NATO flank, the Polish government turned turned a blind eye on Uber.

Now that the USA turned away from Europe, nobody cares about the interest of American companies. When Trumps ambassador (Tom Rose) threatened the current government in the same way recently regarding planned "digital tax", the minister answered "We're nobody's fief".

[0] https://phys.org/news/2019-04-hundreds-cab-drivers-protest-u...

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#75
post #18

Cookie consent banners might be one of the most frustrating aspects of modern web browsing. A better solution could have been a thoughtful extension or fork of HTTP, specifically for EU implementations, something that handles consent through HTTP headers instead. That would allow users to easily opt in or out, either globally or per tab, without the clutter. Ideally, technical regulations like these should be designe…

cookie consent banners are a workaround GDPR, not a requirement from GDPR. If companies just stopped trying to track people by default, then we'd have the best of both worlds.

But as we see with Apple and DMA, they will instead do their best to drag it out.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#76
post #48
post #3

> The GDPR is seen as one of Europe's most complex pieces of legislation by the technology sector Really? Now I'm no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document ( https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... ) is only 88 pages long, this cannot realistically be "one of Europe's most complex pieces of legislation". A lot of privacy-conscio…

Eh, you can see in this thread how all sorts of things are confusing. What, exactly, requires a cookie banner? Does an IP address in a log count as personal information on its own? And so on. I can see why it was intended to be generic, but the lack of clear guidance and especially the lack of de minimis exemptions (one of the things mentioned to be addressed!) are a very real problem. "What tests do I have to perfor…

That's part of the issue. A cookie banner isn't a requirement to begin with. It's their workaround to try and get some tracking data back

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#77
post #59

Earlier quoted context omitted.

They should not be careless, but they can be spared some paperwork as long as they stay compliant with the spirit of regulation.

If you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.

>If you're careful about how you store personal data in the first place

Unfortunately this is a really big "if" looking at typical businesses. They have no idea about how compliance should work and they also hire barely qualified people to marketing teams (often interns), who may accidentally add some privacy-breaking stuff. To prevent that they hire an external DPO and then deal with the paperwork for that DPO, who never visits the company onsite and never meets real people touching privacy topics.

So no, it's not a breeze, because there's generally no enough expertise and temptation to use American non-compliant MarTech is high.

One possible solution to that could be a pan-European registry of data processors with enough metadata to a) generate privacy policy, b) request correct consent, c) provide a compliance implementation checklist for non-trivial cases. There could be a small fee for adding services to this registry, but that would make maintaining compliance much easier.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#78
post #2

Uh oh. I'm all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you're not doing nasty stuff with people's data, 2) actually needed. Any opposing views?

You're on a forum supported by a startup accellerator for entrepreneurs who want to get stuff up and running with as little friction as possible. It's fairly obvious that Sinclair's quote would ring true here.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#79
post #2

Uh oh. I'm all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you're not doing nasty stuff with people's data, 2) actually needed. Any opposing views?

It's easy as long as you're a corporation. It's onerous for a human person. Like the EU's excellent Digital Markets Act, GDPR should be altered to only apply to corporations. It'd be better if like the DMA it only applied to very large corporations, but just corporations is still way better than the status quo.

It's also easy if you simply stop trying to track users and only store the most necessary data. Like, no one ever seem to consider this.

Meanwhile, this same community a few days back were discussing the idea of trying to abolish advertisement. That's truly bluesky thinking if we're still justifying user tracking in 2025.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#80
post #28

Earlier quoted context omitted.

>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. It doesn't help the situation that a…

If your salary would drop 95% tomorrow if you didn't tell everyone at the office 'I may remember this conversation' every time you see them, what would you do? Non targeted ads pay 90+% less than targeted. Sure it's not 'required', but the vast majority of businesses would fail overnight if their revenue dropped 90%.

If you heavily rely on performance marketing, your business model is anyway in trouble. In the past businesses survived with non-digital marketing channels just fine.
Post reply on HN