Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

761–770 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#761

Earlier quoted context omitted.

Having coded multiple such buttons in the past, I'd like to ask to consider that the person doing the coding is barely the person making the decision. It's hard to reject such a request when your lifelihood depends on the job

It might be hard in some places, with especially toxic higher ups. A good start is pointing out the law a few times. If that doesn't get them to stop, what you can do is ask them to give you a signed piece of paper, where it says, that against your objection and warning about this being illegal, they want you to still do that. Usually at that point they will find someone else, or stop trying to do it.

I agree with everything you say, except

> Usually at that point they will find someone else

is not really something a lot of people can afford to risk

Re: Europe is scaling back GDPR and relaxing AI laws

#762

Earlier quoted context omitted.

Which is why we need professional licensure: You get to tell your boss "If I tell you to go fuck yourself, then I risk this job. If I implement your feature, I risk losing every future job by losing my license. And everybody you can hire to do this will tell you the same thing".

I don't want to live in your hellscape where my government tells me I can't program a website without a license. Grow up and tell someone you won't implement a feature because you don't like it. I do it all the time - "that's a bad idea, I'm not doing that". I still manage to eat, it's not either/or, you have agency, you can refuse without resorting to regulation saying you must.

Lucky you. In my experience it ends up with talks to HR, where they will explain that "you are being difficult to work with" and "things are going to have to change" or "we are going to have to look for alternative avenues"

Re: Europe is scaling back GDPR and relaxing AI laws

#763
post #665
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

The problems are in the details: why are news organizations exempt from this rule in Europe? You can’t read news websites unless you accept all cookies or pay to read. Who decides these things? How is such a rule in favor of privacy? Why is my site where I regularly post news not eligible? Who decides which sites are eligible? It’s these kind of moral double standards and cognitive dissonances that people have to end…

Are you sure they are exempt? I was always under the impression that their practice is pretty obviously illegal. I just did a quick google search and didn't find anything about exemption. So they are as exempt from the GDPR as much as Al Capone was exempt from taxes ;)

What they seem to be exempt from is getting consent if they require the data for journalistic purposes.

IANAL, but I think they are simply not following the law and waiting for a definitive decision by a court.

ed: So I kept reading and from my understanding it's TBD whether the practice is lawful. The European Data Protection Board has issued an opinion against it a year ago.

Re: Europe is scaling back GDPR and relaxing AI laws

#764
post #209

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

Why did you use an LLM to write a comment?

In my case it is rarely that I use LLM to write comments but rather I frequently use an LLM on my finished comment to fix things I miss as a non native speaker.

The content of the comment is my unique opinion and my unique writing and I mostly also make sure to remove stupid things like directional quotation marks.

But yes, it is possible to be very much human but also trigger certain peoples AI detectors.

Re: Europe is scaling back GDPR and relaxing AI laws

#766
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

There is an infinitely more effective and trustworthy solution: an adblocker that blocks trackers. You don't have to spend minutes daily on dark-pattern banners. You don't risk the broken implementations that still track you no matter what you click, that regulators can't oversee on billions of websites.

They should just keep the thing that lets you request full deletion of your account and data, the rest is total security theater. The EU's top #1, #2, #3, #4, and #5 priority right now should be achieving digital sovereignty and getting a strong homegrown tech industry (ban American social media and force local alternatives?) so the US can't coerce it. That'll require some additional, different regulations, and that's the kind they should focus all efforts on for the foreseeable future. They put the cart before the horse.

Look at the sanctioned ICC judges (EU-based). Can't use any credit/debit cards (all American). Can't do any online e-commerce (there's a US entity somewhere in the flow). No Google/Apple accounts (how useful is your iPhone without the App Store?). "Regulate" foreign companies all you want, ultimately you still have no power over them. Cart before the horse.

Re: Europe is scaling back GDPR and relaxing AI laws

#767
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

The problem is paternalism and assuming the user is too dumb to take control their privacy preferences.

The compliance of the cookie banner regulation has measurable negative externalities - one estimate suggests a EUR 14B/year productivity hit in the EU

Most modern browsers allow you to disable all cookies if you like. You can always use incognito mode if you want to be selective about it.

In an ideal world, the EU could have simply educated their constituents about privacy controls available in their browser.

Re: Europe is scaling back GDPR and relaxing AI laws

#768
post #182

From Europe, I agree with big tech getting it. But i dont agree with random flower shop somewhere getting fined because they dont know how to deal with a f cking complicated, ever-changing law that is designed for megacorps who have the cash to just keep paying the fine and abusing everyone. I also dont agree with dealing with f cking cookie banners on every other website either. The law got SO convoluted over 9 year…

> The law got SO convoluted over 9 years of interpretation by the European courts that its now impossible to be 100% compliant

It absolutely isn't. I set up a blog for a friend where she shows her art and publishes an appearances itinerary/schedule. It doesn't collect ANY info from visitors, therefore requires no cookie banner at all. Simple as that.

HTTP logs are retained for 7 days for security analysis and then wiped. No analytics available, although my understanding is that a self-hosted Matomo instance set to anonymize the last 2 IP bytes of every logline it ingests would still be considered exempt from a banner.

Re: Europe is scaling back GDPR and relaxing AI laws

#770

Earlier quoted context omitted.

I agree in theory but in practise, this just results in even more regulations. There are very few or no real world examples of stricter regulations being written in clearer terms. The reasons are numerous, but a big one is that people often have a financial incentive to circumvent these regulations. They attack the edge cases and the ambiguity between each word. If the regulations are not written sufficiently prescri…

> Ultimately this means fewer regulations generally are good for startups - and larger businesses. Yeah, forcing companies to write food ingredients on the package is bad for business. And I don't care about business more than about the well-being of society and myself. Same with tracking.

I think that when I wrote that fewer regulations help small businesses, but that there are costs for this, you read, "all regulations are bad and I think they should all be removed." Since you didn't read my whole comment, I'm going to paste the important sentence again now:

> Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.

Post reply on HN