Live data from Hacker News

Europe is scaling back GDPR and relaxing AI laws

theverge.com

771–780 of 1001 posts

Re: Europe is scaling back GDPR and relaxing AI laws

#771

Earlier quoted context omitted.

I strongly agree with this position. This is basically the foundation of Control Theory! https://en.wikipedia.org/wiki/Control_theory This is like arguing if "heater on" or "AC on" is better, which is a pointless argument. That entirely depends on what the temperature is!

It is the perfect and correct antidote to any slippery slope argument. If the consequences of the law turns out to be as bad as you say they will be then we adjust the law.

Nothing is more permanent in politics than temporary solution. As a Norwegian, for example, I am still paying a temporary 25% on all spending that was enacted as a "temporary" measure over 100 years ago.

Control Theory does not work (in the general) for politics for the simple reason that incentives are misaligned. That is to say that control theory itself obviosuly works, but for it to be a good solution in some political context you must additionally prove the existance of some Nash equilibrium where it is being correctly applied.

Edit: See https://www.youtube.com/watch?v=rStL7niR7gs (CGP Grey - Why Do All Governments Work the Same Way?)

Re: Europe is scaling back GDPR and relaxing AI laws

#772

Earlier quoted context omitted.

I totally agree with this view! I understand why the rules are vague to an extent, simply because it is hard to impossible to cover every aspect of data collection. But the GDPR is super vague on some very technical datapoints as well. Is an IP Address PII? Is there a difference between an IPv4 or an IPv6 address being PII? What constitutes as legitimate interest specifically? Can I use data for legitimate interests…

IP addresses are PII. This has long been determined.

This is a perfect example of uncertainty causing compliance overhead.

You say IP addresses are PII and this has long been determined.

Literally a week ago I read this reply on HN to someone mentioning IP addresses being PII:

> > logging an IP address.... > Untrue. IP is an category of PII but its not PII in itself unless you're a law enforcement. > Separately, if you log IP addresses you're doing it to prevent abuse and to provide security to your server, you're already permitted to do so. > More on that: https://missinfogeek.net/gdpr-consent/

So it seems like it’s not so determined, and this kind of uncertainty is exactly what makes compliance expensive.

Re: Europe is scaling back GDPR and relaxing AI laws

#773
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

Perhaps if you had some engineers write the laws they’d work better

Re: Europe is scaling back GDPR and relaxing AI laws

#775

Europe learn the hard way that you cant have a cake and eat it too

EU citizens: WE DEMAND XYZ PROTECTIONS EU: WE SHALL BUILD XYZ FOR EVERYONE (years pass) EU citizens: WE HATE XYZ PROTECTIONS

Who demanded cookie banners?

Re: Europe is scaling back GDPR and relaxing AI laws

#776

Earlier quoted context omitted.

I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.

I strongly agree with this position. This is basically the foundation of Control Theory! https://en.wikipedia.org/wiki/Control_theory This is like arguing if "heater on" or "AC on" is better, which is a pointless argument. That entirely depends on what the temperature is!

> This is like arguing if "heater on" or "AC on" is better, which is a pointless argument. That entirely depends on what the temperature is!

I think the problem here is more that _some_ people want the heater to be on and _other_ people want the heater to be off.

Re: Europe is scaling back GDPR and relaxing AI laws

#777
post #270

I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Se…

That cookie banner needs to be standardized and offered by the browser. It should be like a certificate popup. Why is every website forced into doing a shoddy job ?

I mean, websites don't need to use non-functional cookies in the first place. If they use it, they have to declare it. It's a problem created by website owners themselves.

GitHub doesn't have a cookie banner: https://github.blog/news-insights/company-news/no-cookie-for...

That said, looks like what you asked is happening: https://www.macrumors.com/2025/11/19/europe-gdpr-cookie-chan...

Re: Europe is scaling back GDPR and relaxing AI laws

#778

Earlier quoted context omitted.

I just don't see the issue. The GDPR isn't exactly difficult to comply with, nor does it hamper any of the clear successes of the last 25 years outside of the ad industry. What's the benefit of backing out on it? Is this just an effort to make a homegrown surveillance network?

Ughhh here we go again. Every time GDPR is brought up on HN, the same "it's super simple to comply, just read it yourself!" religious incantation gets repeated ad-nauseam. I think it's because people love the idea of what they think GDPR actually represents (the fuzzy abstract idea of "privacy"), without ever diving into any of the implementation details. Almost nobody on this forum has ever talked to a lawyer about…

As with many laws people think its what is sold as.

There are a lot of good ideas in the GDPR, but once you start looking into implementation it gets a lot more complex.

Its not just business. A community organisation (like my local amateur theatre, or a sports club, or a parish church etc.) is subject to pretty complex rules. Often things run by volunteers that keep very little data. Here is the guidance for UK GDPR (which is still pretty much identical to the EU version) compliance for small organisations:

https://ico.org.uk/for-organisations/advice-for-small-organi...

Read it all, and tell me its simple for an organisation with a limited budget, or for someone without either a technical or legal background to understand.

Re: Europe is scaling back GDPR and relaxing AI laws

#779
post #327

Earlier quoted context omitted.

Regulations are like lines of code in a software project. They're good if well written, bad if not, and what matters more is how well they fit into the entire solution

And lines of code is like the mass of an airplane.

Just put all code on one line then. Statements (or tokens) is what matters.

Re: Europe is scaling back GDPR and relaxing AI laws

#780

I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.

European startups will not profit if this deregulation goes through. US and Chinese corporations will.

While everyone talks about souvereign data processing in the EU, both the commission as well as the governments of its member states completely failed in pampering a domestic cloud industry during the last 15 years. Mercy killing.

Post reply on HN