Article 13 is fundamentally different from the GDPR. The fundamental problem is that I think (and most people hopefully do) user privacy is an ethical good, and I don't believe (much of) copyright law is an ethical good. If you fundamentally believe copyright must be defended vigilantly Article 13 is not an unreasonable consequence at all - I just don't agree with that premise one bit.
Websites that don't want to comply with GDPR, I say good riddance. If you really feel you cannot uphold the basic privacy principles posited, then screw you too. But for Article 13, the laws are only in the interest of big corporations. I don't care about those.
Besides, there is also a cost to me: the never-ending pop-ups and acceptance dialogues, inability to access information in a straightforward manner for those that choose to block, etc.
What is the percentage of users who actively control their privacy as a result of GDPR (and still happily use the website)? What is the percentage of badly -behaving businesses who will be prosecuted?
> There is a cost to businesses in complying with and implementing regulations, regardless of the size of the business and how good or bad their behaviour has been with respect to the intention of those regulations. You can't deny over-regulation by assuming only the badly-behaving people are burdened by it.
Indeed - the lack of this cost of business was causing (1) reckless and (2) (deeply) unethical behaviour to become rampant [0]. I think it was fair to say it was not acceptable anymore, and I think the GDPR does a good job of formalizing rules of basic common sense about personal data protection. There's really nothing in the GDPR that I can point to that is overbearing, although of course many businesses do implement unnecessarily overbearing UX on top of it.
Processing personal data should be a risk to business, and I think some basic rule of law was warranted for this risk to be clear to business.
I'm not saying there is no cost to regulation. But the cost needs to be proportional to the good it achieves and I think the GDPR does that quite well. Article 13 - in my opinion - clearly will not.
[0]: E.g. in unregulated countries: https://news.ycombinator.com/item?id=17081684
The law doesn't ask for any popups, blocking is a dumb option that not many take, and for prosecutions we'll have to wait a bit longer before we see.
I don't. I find it an egregious example of over-regulation. I think not recognizing the obviously large scope of such regulation is extremely suspect.
> The GDPR does a good job in codifying basic privacy principles of what you can do with personal data
By what measure do you define "good job"?
> The only reason to call it over regulation is if you're spoiled about not being regulated beforehand
I admit being this kind of spoiled. But it's ridiculous to say that's the only reason. There are measured ways to go about things and to so blatantly say that this is the only reason one might view it as over-regulation (despite real reasons such as size and scope and ineffectiveness of predecessors/enforcement) destroys our ability to have real conversations about the many alternative ways to solve some of the problems we have. Such a black-and-white absolutist view is harmful.
> I don't understand why I hear so few Americans about wanting this in their own country.
Can't speak for all, but for many, it's because they recognize the difference between what would be ideal and what would actually happen. Large anti-company (especially against companies that users prefer to use) laws have a chance to be frowned upon, despite ridiculous promises/optimism/naivete by the hopeful.
> Websites that don't want to comply with GDPR, I say good riddance. If you really feel you cannot uphold the basic privacy principles posited, then screw you too.
These are not how chilling effects work. You don't get to say "well, if they choose not to do business where a law is, they must not be able to uphold that law". There are compliance costs/risks. The amount of assumptions concerning this topic, whether assumptions that the law is good or assumptions that those disagreeing with it are of a certain ilk, need to stop. You only hurt your cause discussing things in this manner.
If you have specific problems with GDPR or that it goes too far, I'd like to know what those specific aspects are. In my view, there's some basic rules on how to deal with personal data that the GDPR codifies, and it does that surprisingly (for the EU) reasonably. It starts from simple principles of citizen rights and ethical behaviour and writes a complete rulebook on how to apply them - that's my definition of a good job.
It might be difficult for business to adapt to actually now considering processing personal data a risk. But that by itself does not make GDPR "overregulation" - that just makes it a difficult regulation change to process. I won't shed a tear about business having a difficult time going through that process - I'm incredibly happy that they are forced to consider processing personal data a risk, because it is.
Also note I specifically said "Websites that don't want to comply with GDPR" - not "Companies that are not sure they can comply with GDPR yet". There's a reasonable difference, I agree. But, yes, if you find that your business intrinsically cannot comply with GDPR or you don't want to - it's time to take a good hard look in the mirror.
GDPR did not really change the media landscape in the EU. Business as usual here. Mostly companies went through a brief period where they had to consult lawyers and expensive agencies on how to cover their asses. Mostly good things have started happening after that. Some companies that were doing technically unacceptable things under pre-GDPR legislation have now grudgingly stopped doing those things.
Of course, I’ve seen even more that give you only an accept option... that, or as sibling commenter said yes/wilderness of options.
This is pre-GDPR, but it feels like since GDPR there's been a real uptick in this.
because if the tracking/ad/shit/any cookies are not fundamentally required for the page to show, then denying you the usage of the site is a violation of your privacy (because you can't give selective consent to specific data uses)
sure, a lot of sites throw up the ugly banner, but now you can click fuck cookies, because fuck cookies if you only want to read a fucking HTML page with pictures. they can still make stats about your visit and aggregate them, but tracking cookies are absurd. (they can filter out repeated visits by looking at IP addresses and browser fingerprinting and/or they can ask you nicely to help them get better stats, but now they have to unbundle that from the ad tracking purpose.)
This button doesn't exist in 90% of cases. Websites tend to dump you into a complex, deliberately tedious to edit options UI rather than providing a "No" button.
Their are major complaints outstanding against Google, Facebook & the IAB that will define how online publishers can be funded once they are litigated.
All these big blanket OK consent buttons we see on landing pages have already been shown in court do not constitute informed and freely given consent. The real impact has het to come, hopefully after some stiff fines are handed.
And you are right: I also wonder about enabling large scale VAT dodging by sites like aliexpress.
Even if you are, I'm not actually sure that would be better for anyone involved. Seems like it would essentially stop or severely diminish online commerce between US/EU as too much hassle.
The regulation itself forbids their main income source
FB has to show who they sell data to, that's the new part basically. They will probably show a long list of random companies. It'll look a bit scary, people will get accustomed to it. (FB will find a dark pattern that minimizes the attrition due to any permission/consent step in their money machine.)
The identifiable information still has to be encrypted. They still need to specify exactly where the information will go and why. And if a new company wants to access the data or even wants to use the provided Information for something new, Facebook has to ask permission again. Once again telling the user why that company needs permission and why as well.
It's doubtful that the current blanket prompt is enough. But it remains to be seen wherever the law will be enforced and it's of course possible,that nothing will change and regulator's never act on the law
That said, I hope the EU courts will look at them the first time they fuck up. (And that might be right now. But so far I'm not aware of any recent FB data/privacy abuse.)
Good talk from a few weeks ago: https://media.ccc.de/v/35c3-9941-how_facebook_tracks_you_on_...
(that's just android, but they do just as much web tracking through their pixel for example).
It's like saying that criminal laws prevented people from getting happily scammed.
No idea if such a thing would happen though.