You build houses - think of it like fire safety rules. "What do you mean I have to keep track of all the fire safety rules for the country I build the houses in? Can't I just keep track of a set of rules of my choosing instead?" -- well, no, for one and even if you could, that'd be a bad idea. Almost universally, there's good reasons behind specific rules in the fire code. (And in the rarer cases the rules really are broken, that's a problem with the law, but not one that can't be fixed).
Unfortunately, most companies don't give a rat about their customers' privacy (we care deeply about it we swear). What really should happen instead is that US customers demand laws like the ones we have in Europe.
It screams laws written by politicians for special interest groups none of whom have the first clue about technology or how it works.
You could just have the web browser show an alert when a site wants to set a cookie and the user can click that alert or always allow it. Which is what we used to have in every web browser. Until users got sick of seeing the stupid warning because every single website uses cookies. And they got blind to the warning and paid no attention to it. Which made any other warning a browser shows more likely to just be clicked through.
So browsers removed the warning because we all realized it was stupid and pointless and ineffective and served no purpose any longer. But politicians with no idea how the technology works and no understanding of the fact that we already went through all this decide that everyone should see the dumb, stupid, ineffective warning on every single website and have it show up every single time for the people who understand how to manage their cookies and only show up once for the people who have no idea how to use their cookies. Just brilliant. It serves no purpose and everyone just clicks it away just like any other popup ad.
Fun fact, the EU excluded "third-party social plug-in content-sharing", which are used for more tracking than any of the other cookies.
Cookie notifications and censorship of the news under the guise of the "right to be forgotten" come to mind as obvious counterexamples.
I also didn't talk about startups, i mean small business in general.
This could be a reason not to launch your business in europe, if the cost of "deployment" is to high. Sure, someone else will fill that hole for you, but that's less money in your bank account. :)
There will be an enormous burden on new businesses satisfying these laws - previously we've got away with privacy policies but could still code the same. If we need to maintain N servers for N countries customers could be from, that's a massive operational overhead that is bound to do nothing other than stifle innovation.
Now, I'm all for privacy, but if each country starts fragmenting the internet on country boundaries - to the level of physical servers and data storage locations, bringing a new idea to market is going to much much harder. This is different to, e.g. different tax regulations, etc, because you can still benefit from centralised computation while processing orders for different localities.
And while today this might be just about Europe, it sets a trend. Before it was just Russia and China. How long before all countries want to see the code a la the Chinese?
So the NSA has screwed things up for all of us now who are trying to start businesses.
If my costs go from: developer -> developer + global devops team + legal, etc., that's a massive burden that will affect the "bedroom/garage" startups.
Plenty of popular apps don't require anything like bank account/post code, etc. that could be assumed to prove which country someone is from.
Now, if your app does not become popular in Italy, you just have five users there, do you still have to comply? No you don't, because de minimis non curat lex.
China is good example of how that works: they have their own search engine, blog platforms, website analytics software, video sharing sites, IM software. So Chinese users do not send their data (and money) to USA and goverment can protect personal data from NSA while EU cannot.
Of course I do not approve other things like censorship in China but having local services is a good thing both economy-wise and privacy-wise.
Basically the EU is creating a PR stunt that in theory could force them to enact some minimum veneer of standards and that PR stunt is going to have higher short term costs for the small private sector players than the large ones.
It is entirely possible the stunt will instead pay off for the other EU governments and against the privacy of their population by getting them invited further into the club.
Are you saying that the ECJ ruled without looking at the case merits?
I am also very skeptical that private data in Germany was or is any safer from the problems with the safe haven as far as data intentionally illegally shared with institutions in the US, not due purely to issues on the ground when defending the data in good faith.
Collecting data which is routed internationally is a well documented method that NSA et al have used to skirt domestic law and grab/share the data. If you already live in country "C", and by statute your data must never leave country "C", then your data are more protected than if it had been sent outside the legal jurisdiction of country "C"'s courts.
With prevalent encryption on-the-wire, fibre tapping is less useful. So the way people get their privacy leaked is via hacking or other compromises. Saving to disks in a person's country of origin is probably rather far down on threats to their privacy. (Yeah, I know, if you host it all on disks in the US, then the FBI can come steal those disks. But that's less a risk than a hacking group dumping your DB on pastebin.) And a compromise to the company will compromise the data no matter where the disk are.
If countries were really concerned, they'd mandate strong security for personal info. Not like PCI where technical details are spec'd, but somehow offload it so that companies must make reasonable steps. Then have enforcement to fine companies that misbehave. Perhaps make it something where companies will want to get insurance.
That way, a startup, instead of grabbing everything, they'll ask themselves: "Hey, do we really wanna capture this info?" Just like PCI shot a lot of plans to store card numbers and CVV, a strong law could make companies think twice and plan around handling private info.
Location of storage devices might end up on the list of requirements, somewhere. Like once you store info on more than X people, you're required to address how you handle differing jurisdictions or something.
EDIT: fixed wording
At this point, upvotes and downvotes are mostly driven by a reddit-esque crowd with political grudges.
As an employee of a small software startup, but also as a citizen, I welcome this move.
(for some context, I'm a French SaaS bootstrapper; I am as careful with my customers data as I can be, and found that starting a SaaS has been a major pain already - VAT rules, finding a SafeHarbor provider which doesn't suck at security, too etc).
I was talking about this to someone just now and it strikes me that all these regulations are very much wasted on startups during their creation. Maybe what we need is a way for startups to be able to playtest their idea and only have to worry about all the extra responsibilities once they're more certain about the results.
How many times a day is this phrase written in Hacker News? How many times is it found on reddit?
The poster, in this specific case is not being downvoted.
The issue I think is understanding about how commenters and viewers use HN and reddit and upvote and downvote over time. If you understand this process you will no longer want to write "I don't know why" because you will understand the process.
I hope more people would understand the voting processes of these various discussion forums.
I almost never complain about downvotes (as mentioned in HN guidelines), yet felt that there was a misunderstanding and a lack of full perception of the implications of what the downvoted message conveyed.
Truth is (again, as someone who is privacy-sensitive, and running a EU SaaS) this is going to be complicated to run an international SaaS, as a bootstrapper.
Because they are two different things.
Or just host everything in Europe.
Or lobby Congress to stop shitting all over privacy so that the US can be considered a safe harbour again.
And think about it: is there a really huge increase to privacy? What exact attack scenarios does this defeat, and how likely are such scenarios compared to run-of-the-mill privacy breaches (lax security)?
http://www.theguardian.com/technology/2014/apr/29/us-court-m...
Those are two entirely different scenarios. There's no reason both couldn't (and shouldn't) be handled in parallel. For example starting next year companies within the EU are held liable for data loss, with up to IIRC 3% of their global revenue. That policy handles the lax security concerns; no reason to not tackle other problems, like the one described on this thread.