Google said it had successfully ‘slowed down’ European privacy rules
nytimes.com
nytimes.com
Yet right now all I've seen from EU and California regulations have been friction upon friction both for the end user and the service provider:
Every website I visit I need to go adjust cookie settings (enable essential and telemetry and remove targeting).
So I'd vote for repealing all these useless laws
> So I'd vote for repealing all these useless laws
This is called malicious compliance, and you're falling right for it. The entire goal of these "settings" is to trick/tire users into accepting fake consent that has not been freely given. They are a priori illegal under most privacy laws as well as common law principles. But enforcement takes time and resources. Meanwhile companies can play dumb, straight up lie about the necessity of such dialogs, and get users to mistakenly assign blame to those pesky laws rather than the malicious companies themselves.
This reminds me of California prop 65 which is as useless if not more than the cookie law. You see it at every random place with the note that "this product may contain a chemical known to the state of California to cause cancer or birth defects ..." People have become fully desensitized to it because it shows up at the parking garage of their work place. If it was a real deal well perhaps it should've been banned.
I'd like to repeal both prop 65 and these cookie laws. Either ban something or fine the perpetrators if it's harmful or stfu /rant
The actual problem is the inability to update the law as companies iterate on their malicious compliance. And ascribing the bad faith actions of companies as consequences of government helps erode the political will required to enact sane updates.
The prop 65 issue is somewhat orthogonal as it's the result of an impossible ask by California's citizen initiative process. Ideally that too would have been updated as its failings became apparent.
As an aside, I do have some experience with California paints and they're terrible. I'd much rather have a day or two of leaving the windows open after painting, than to have paint that never really dries and releases low level VOCs for a month.
- Third-party cookies disabled with a few exceptions (disqus)
- A filter list to hide cookie notices
If browsers block cookies by default, websites will just use other methods to store and correlate the information.
Many of the dark patterns used today are already illegal. Noyb actively reaches out to the owners of those sites and threatens (and probably will) sue them if they don't fix it.
Funny, the most annoying offenders I find myself just ultimately avoiding. I'm glad. It's a proper chilling effect. The web is a crappy, overweight timesink populated primarily with the most meager scraps of information wrapped in an ad-laden turd sandwich, and all these cookie popups just remind me how much carnival barking and creepy stalking is going on, and I just don't want it.
The web was so great in the 1990s, but now it just doesn't deserve my time anymore--ok, HN, har har--and maybe it will just implode....and we can sneak off to something better. Like what? A new kind of BBS, who knows....Imaginations are so weak these days. We couldn't possibly do anything different, or over. Oh wait, those hundreds of billions of dollars aren't going to make themselves.
Easiest way to not care about the cookie notices much is to always use incognito or private mode with each website on their own container. It’s not foolproof of course as multiple fingerprinting tests will reveal but combined with tracker blockers at system level it’s better than most and don’t have to worry about those cookie notices.
The goal was indeed to make a label similar to nutrition labels (or energy usage labels). It cannot be done. Privacy is not something you can distill to kcal, grams of salt or kWh.
It is extremely complex and the industry will never fully align on a shared definition.
e: Another article in the front page suggests this is highlighted because it draws attention to Google's supposed pro-privacy position as a sham. I hadn't realized they had one but OK.
(Though enough people point out that the ability for groups to effectively "represent their interests" differs dramatically between groups)
However, the memo sounds as if they didn't simply stated their position - but also used their power to sabotage the lawmaking process itself and undercut all the usual mechanisms of democratic will formation. That's abuse of power and rightly seen as a scandal - even though google is likely far from the only one doing it.
So if the law were changed to legalize bribery, and then someone influenced lawmakers by promising to pay them a lot of money, that would be okay? Does this philosophy also extend to, to pick a deliberately extreme example, murder?
I personally don't quite agree with that. I think there is a place for "transparent" lobbying - e.g. openly stating the concerns of your interest group as part of normal public debate. However, this is a power that must be available to all interest groups. Additionally, groups must be willing to make compromises or accept if their arguments are dismissed by the public.
What I think is not ok is for a group to use power, connections and manipulation to push through their interests even against public opinion. That's what bribery or obstructive tactics are doing.
Then you should be opposed to lobbying tout court and, honestly, perhaps even regular grassroots advocacy.
I can say it a third time, I'm not against political advocacy.
There is "astroturfung", i.e. pretending you're a grassroots movement when it's actually orchestrated. There is also uber-style "grassroots" campaigning, where you use your existing reach to push your narrative to a broad number of people who are dependent on you.
I think the former is deceptive and the latter is unfair. However both are distinct enough from normal awareness campaigns or organic grassroots movements that I don't see a problem.
To make an analogy, consider a game like soccer. Soccer is inherently competitive, so it makes no sense to get upset about the fact that there is competition. However, mostly, that competition is restricted by the rules of the game. Even this is not the whole picture: There are a number of rules violations which are generally accepted as part of the game and are even part of strategy, such as tackling other players or drawing out the clock. However, there are other rules violations which are clearly outside the acceptable territory, such as defending the goal with a handgun or bribing the referee. I think a similar case can be made for lobbying.
Good question. Fatigue, cynicism, better media spin. There can be a lot of reasons why we're not sufficiently shocked about the other scandals.
However in general, if you look at statistics about the trust of the general population in politics (and magacorps), you can see a decline in the last decades. Seems to me, a lot of people are simply reacting to all of this by losing trust - because there is not much else for them to do.
Ah, yes. Fair enough. I agree that there are many other cases of legal but unconscionable lobbying that also need to be criminalized and prosecuted (but won't be).
0: I don't think "shocked" per se is a reasonable characterization, but that doesn't seem to be your point.
Trading law for campaign cash is not illegal in the US, at least not in any meaningful way.
Nor is that sort of bribery objectionable to most US voters or news orgs - again, in any meaningful way.
Where did you get that idea?
AFAICT, most Americans are for getting money out of politics[0][1][2][3].
Am I missing something here?
[0] https://www.citizen.org/article/polls-on-citizens-united-and...
[1] https://www.issueone.org/new-poll-shows-money-in-politics-is...
[2] https://www.pewresearch.org/fact-tank/2018/05/08/most-americ...
[3] https://www.pri.org/stories/2018-05-10/study-most-americans-...
> Where did you get that idea?
Voters overwhelming vote for incumbent pols of their party - pols who passed law in response to campaign donations they received. Reelection is a pretty solid approval indicator.
Likewise, the dearth of coverage about pols passing laws for campaign cash shows news orgs' ongoing lack of interest.
Do voters feel they have an actual choice here? If the impression is that all candidates engage in this, voting results might not mean much here, especially if direct opinion polling states there is interest in the topic.
> Likewise, the dearth of coverage about pols passing laws for campaign cash shows news orgs' ongoing lack of interest.
Indeed, but this is the interest of news orgs, not voters.
> Reelection is a pretty solid approval indicator.
I think this is the same logic trap like the common argument "We added feature X to our product and people are still buying it, therefore people must like feature X." That's not true - product decisions are a result of a multitude of factors. People may buy the product despite feature X because it's outweighted by other factors.
Similarly, corruption scandals may be outweighted by other motivations when voting - but that still wouldn't mean that voters approve of bribery.
I agree. However, it's not about choice or whether or not certain candidates raise money.
In the current system, all candidates, incumbent or not, spend a significant portion of their time and energy fundraising. Not because they're necessarily corrupt, but because if they don't, they can't compete with those who do.
The problem is that our political system pretty much requires it unless you're extraordinarily wealthy. And even then, most will fund-raise anyway.
The system we have incentivizes money over all else. Which is counterproductive and creates the avenues for prioritizing the well-heeled and wealthy special interests.
Voters understand this, which is why most want to get the running sewer of filthy lucre out of our politics and elections.
What is necessary is public funding of elections, with strict limits on spending and much more regulation of lobbying.
Doing so would allow a much broader cross-section of folks to run for office and give those who are elected much more leeway in servicing their constituents.
And that's, IMHO, what most Americans want.
What is the voter scenario that you're visualizing here? Do you see voters considering the instances where their pols have traded law for cash, gritting teeth and voting anyway?
I'm fairly sure that first part never happens - because voters know ~0 instances where their pols have traded law for cash - because cash-for-power rarely catches news orgs' interest.
That last bit is to counter where you infer the lack of concern by news orgs isn't related to the lack of concern by voters.
A substantial number of people did this as recently as 2014. https://en.wikipedia.org/wiki/Mayoral_elections_in_Providenc...
[I do not speak for my employer.]
A company in the EU has to design the whole model with no private data which means they will have more difficulty competing with Google rather than less.
>Google can then use non-private data to adjust the model to the EU market.
Google can do everything a EU-only company can do. They can also do things a EU-only company cannot do. The reverse is not true. So at worst they'll be roughly as good and at best much better.
There are regional differences between the same language that can be pretty severe, all the way down to the pronoun level.
So, no they can't.
They can also get US data that doesn't follow EU privacy requirements. So Google has two source of data they can combine into a better product.
In the US the dialects are very similar and usually separated mostly by accent.
When dealing with different countries, entire groups of words do not mean the same thing because either (a) the language has changed, or (b) those things literally did not exist at the time the split occurred. Training an AI on Parisian French will result in an utterly broken experience for Haitian French and Cajun French.
Also, the biggest difference would be the pronunciation differences vs words being different. The word differences are easily modeled after any ASR, if the developer understands the differences and plans for it in their NLU models.
It could even extend to most consumer product. e.g. Some obscure chemical compound for plastics is much more costly to produce in an environmentally friendly way, therefore it’s nearly all produced in the least regulated jurisdictions, therefore the compound and all derivative products have to be tariffed from those jurisdictions?
I’m not convinced that large amounts of personal data is required for search to work well, at the very least I’m not convinced the personal data must leave an individuals control.
We don’t see a lot of innovation in this direction as hyper personalized search seems to work reasonably well and the startup costs to compete are massive.
Doesn't the cost of compliance inherently favor larger companies with better lawyers and deep experience in passing audits?
Also, arguably, shoddy financial regulation. In many countries, large private companies have to submit audited accounts to the regulators, and that would likely have raised alarms about the other problems with the business earlier.
Frankly, dodgy companies screw over the people unwise enough to invest in them every day. Theranos was unusual in that it also directly screwed over members of the public.
Relatively speaking, this is as it should be. There are ways to cope with arbitrarily-convincingly fake lab reports (most generically, do multiple tests and compare them), whereas there's not a procedural fix for your X-ray machines occasionally going THERAC. Those measures generally aren't actually in place, but they should be anyway to cope with eg human error.
But the regulations actually in place on both patient-proximate and lab-based equipment are insufficiently stringent. (Annoyingly, they're also gratuitously burdensome.)
Understanding full well each standard solves different problems, for some of us in tech achieving compliance is a non-trivial amount of critical work and maintaining it similarly isn’t always something you easily drop everything and make happen in a day or two.
I think that’s 100% relevant and shouldn’t be immediately responded to as others have by assuming the relevance comes from a position of opposing the regulation or standing against user privacy
The problem with this is twofold:
a: 'Most' (by loudness or other perception) of the complaints are known to be bad faith because they're coming from malicious actors like Facebook or Google which we know are against user privacy (since that's their business model).
b: You have to go out of your way to build a site that interferes with actual user privacy, for example by actively adding Google Analytics scripts or faux-CAPTCHAs, or actively demanding a real name and actively doing something about it if the user lies to you. (Technically you get IP addresses by default, but much like mailing addresses, obscuring these pretty much has to be the user's responsibility, since how else would you respond to them.)
So if you want a assumption of good faith, you need to be clear that you're complaining about the bureaucratic compliance overhead (eg having a particular data processing officer or whatever GDPR calls it), rather than about having to change your object-level service to eliminate spyware that you went out of your way to incorporate in the first place.
Is this a bad thing? If we take privacy seriously then it shouldn’t be. We don’t see too many people fighting food or drug regulations intended to keep us safe because it might be costly for companies to comply. Maybe if a company cannot afford to comply with privacy regulation they should not be handling our personal information. I guess the reason it seems heavy handed in the tech/web world is that the barrier to entry started at next to zero and so much of what we put on the web is not monetised that any cost/compliance seems like a massive burden.
If you had less intervention with respect to privacy would there be more dynamic market-driven initiatives to fill the gaps? Would there be more incentive to develop technology that would be effective for privacy? I don't know.
Regulation is just hard because reality is complex and dynamic and regulation is often complex but not very dynamic.
This is hilarious. Because we had that, and it was lacking, to put it mildly. And some people still have that, in a way that's easy to compare (e.g. EU vs US, CA vs other states). For me, the results are in and obvious. Privacy regulations are the only thing that reflects the privacy externalities they might impose on society back onto them (and the shareholders).
However it does serve as a moat for players with more capital, and that's something we should also be mindful of. For instance, maybe we could have some of the requirements scale and only kick in when a product meets certain thresholds in terms of numbers of users.
[ And even with all of those cutbacks, I'm still not really compliant on all my sites... (legacy software/not knowing what exactly my data server is logging/etc.) ]
But, as a direct answer to your question: I don't think many things in principle are impossible with the current privacy laws. But that doesn't mean it's not having a chilling effect.
It’s still profitable enough with data silos that this is not happening yet
American sites on the other hand tell me either "tough, take our spyware if you want to see this site, or to to a restricted list of five pages" (which I'm pretty sure isn't legal under GDPR); throw up the gauntlet of 1000 tick-boxes, infinitely nested, or say "you're from the EU and we can't serve you page".
The problem is cultural. I've de-googled myself as much as possible, but I don't like the fact that all of my real mobile device choices are written in California and made in china.
As a side point, I work in a tech startup in the EU that was founded post GDPR. We have no issues being competitive and also complying with the GDPR, however we do not make our revenue by selling personal data.
Not to mention the reduced happiness from working with GDPR.
If Google could help remove GDPR and the Cookie law i would welcome it.
My company had about a week of design of our data handling infographic and policy page and that was it for GDPR. The transition was incredibly simple, as we just didn't keep such data in the first place.
Because we did collect voluntarily submitted items from users which might contain such protected data, we simply explained our retention process to users and documented in full the data's life-cycle once it hit our servers. I think we had to add a few extra S3 regions for uploads also, but that was just a few clicks.
GDPR is anything but a headache unless you're trying to do the things the GDPR doesn't want you to be doing; then yeah, it's probably quite a headache.
I'm of the opinion it should be even more onerous to deal with people's data than it currently is. GPDR doesn't go far enough.
If you care about privacy at all you should be very happy that is possible today. It is how we got all those articles showing what data Google and all other companies collects about you, since they asked about this referring to this EU law and the companies has to comply. So even if you don't use it yourself it greatly helps you anyway.
This is the problem with EU regulation. Good intentions, bad implementations and unforeseen consequences. In fact this goes so far into the reasons why EU cannot harbor a growing startup scene or make rockets. I am not against regulations but if you lay a landmind in front of every endeavor in the form of regulations, it bears down on people that want to disrupt existing and overweight companies that can afford to abide by regulations. I've talked to many Europeans and they resonate with the same sentiments.
I own a small business and I've gone through the process GDPR compliance. It is not too bad but there is a reason why there are upteen number of GDPR compliance consulting firms and checklist makers out there.
What should have happened is a complete solution to privacy in the browser instead of playing cat and mouse games with businesses that will find loop holes.
Cookie banners has nothing to do with GDPR.
> I own a small business and I've gone through the process GDPR compliance. It is not too bad but there is a reason why there are upteen number of GDPR compliance consulting firms and checklist makers out there.
The reason is that GDPR compliance gets more expensive the more technical debt you have. For big enough companies with bad engineering practices it can costs hundreds of millions of dollars. For a small business with a straightforward product they likely are all but compliant without even trying.
> What should have happened is a complete solution to privacy in the browser instead of playing cat and mouse games with businesses that will find loop holes.
GDPR has nothing to do with browsers, it has to do with forcing companies to ask for and track data they keep on you no matter where it comes from. It applies to apps, to hiring interviews, to storing transaction data when you buy groceries etc. What you are talking about is a completely different issue.
> The proliferation of such alerts was largely triggered by two different regulations in Europe: the General Data Protection Regulation (GDPR), a sweeping data privacy law enacted in the European Union in May 2018; and the ePrivacy Directive, which was first passed in 2002 and then updated in 2009. They, and the cookie alerts that resulted, have plenty of good intentions. But they’re ineffectual.
https://www.vox.com/recode/2019/12/10/18656519/what-are-cook...
What you probably meant is the user data banners/popups you have to click on that are new since GDPR. They are not cookie banners, they are a different thing, calling them cookie banners gives people the wrong impression.
The fact that you mix these two makes it look like you don't understand what you are talking about here. Especially since you talk as if this was the only thing GDPR changed. The cookie law is stupid, but GDPR is not.
This matters to the nerds on HN and Reddit,some clout chasers on Twitter, and no one else.
People don't care about most data, you are right about that, but they care a ton about some data.
GDPR is just about that, make you own your own data rather than companies owning it. Companies has to ask for it rather than just taking it, and you can revoke that right at any moment and the company has to comply.
There should be a no track law that disallows any company to hold private data without an explicit direct customer relationship. Data would have to deleted completely at end of any business relationship with a short grace period.
There should also be a digital fast track process to report and receive damages when companies are fast tracked with similar legal penalties to illegally harboring medical information.
The acceptance of data trading should end yesterday.
Laws must be technically possible to implement.
Sadly, the USA has gutted scientific and technical review. Which makes policy makers more dependent on industry funded think tanks and lobbyists.
https://en.wikipedia.org/wiki/Office_of_Science_and_Technolo...
https://en.wikipedia.org/wiki/Office_of_Technology_Assessmen...
You need no cookie banner if you only use cookies as required by the service you provide to the user.
For instance if a user is trying to log in, you don't need to ask for permission to set a cookie for that. The consent is implicit.
If you want to set tracking cookies on the other hand...
Thought experiment: if the cookie consent banner was a payment form, things would be A LOT easier to understand. They are ambiguous on purpose. From a UX perspective, most of them don’t make sense at all.
If the cookie banner satisfies the regulations and is the path of least resistance, then companies are going to use it.
If the EU doesn’t want the cookie banner everywhere then the regulations need to not allow it.
It is much, much easier to put a banner up than to audit every application and technology used to ensure nothing tracks the user.
That's joke though. Most of them don't. And upon getting called out and/or fined, corporations right now just edge a bit further towards an actually compliant implementation - rinse and repeat. Currently we're in the state of "what if we made it really sloooow and convoluted to opt out?" - which is also not compliant because that makes not giving consent harder than giving consent.
At some point we're going to be there, but right now we're not.
The cookie banners as they are implemented right now are mostly wishful thinking by adtech: "Hopefully this will be enough?"
It's not. But nobody wants to be the first to stop widely tracking people and going back to good old contextual ads. They're going to wait until the EU turns the heat up to 100 and maybe even then wait for a competitor to blink first.
[1] https://noyb.eu/en/noyb-files-422-formal-gdpr-complaints-ner...
It is REQUIRED to audit every application and technology to determine what tracks the user. That isn't negotiable, it's the law: you must know where, when and for what purposes you are handling personal data.
After that audit, you can either show a cookie banner etc, or remove the problem applications/technologies.
When you see such banner, don't get angry at the law, get angry at all those websites that are tracking you.
Also, if you were chief evil at bigco, wouldn't you keep some people without any backlink around precisely for situations like these?
Be careful what you wish for.
Which is better?
Cookies "without consent" (which you can trivially clear with the click of a button, or have the browser clear automatically) every time you visit YouTube or Google search.
Or no YT or Search for you unless you make a Google account tied to your real email (no 10minutemail) and real phone number.
GDPR is privacy snakeoil.
GDPR is leverage.
Device fingerprinting is still something you (or the browser vendor) can mitigate.
At Google's scale, I wouldn't be surprised if this was a factor.
You break up companies, I think, in order to make room for innovative competitors, and to make corruption more difficult by making the lines of communication lengthier (and forcing them to stretch between companies.) When it comes to politics, industries aren't afraid to "unionize" amongst themselves and speak with a pretty singular voice. Most of their interests will always be identical.
Those massive accumulations of power aren't actually located in supercorporations or ideal groups of competing companies making up an industry, but in individuals. The problem is that there's such an wealth/income disparity that small groups of people are going to be more powerful than larger groups of people by orders of magnitude, and that they're naturally going to use that power to increase that disparity. Their ideal world has the people who have accumulated the most ruling the rest through a system of benevolence and patronage. That's what libertarianism is.
edit: The breakup of Standard Oil made Rockefeller far more wealthy and influential than he was pre-breakup.
We have this concept called progressive taxation that's supposed to help with that. (Not it's actually used in practice, but it is a known thing.)
Taking some inspiration from geo-libertarian thinking the key would be to figure out if, and how, those capital assets can be made into a commons rather than privately owned.
That’s not privacy concerns but it piggybacks on privacy concerns via GDPR.
https://www.theregister.com/2020/11/23/european_recommendati...
There’s still a lot to work out for these privacy laws.
That’s also why I’m currently extremely negative about new SaaS solution presented on HN. We can’t use ANY of them. There’s a huge market for anyone who care to built and ship on-prem software right now. Atlassian for instance just left a massive hole in the EU market, by killing Jira and Confluence server products.
They still provide the Data Center product for those who really want to self-host, but the cost is a lot higher.
https://edpb.europa.eu/sites/edpb/files/consultation/edpb_re...
...It would look like using GSuite or Office365 would also not be allowed.
Although I am strongly in favor all possible privacy measures, the move to onsite solutions is likely to cause an decrease in privacy safety. Most data center and private companies are completely unable to match anything near the SOC controls and internal procedures of most cloud providers.
Another country we deal with doesn’t agree and has no legal path, despite customer controlled keys and SGX, to use a US cloud.
And I really, really want to know exactly what happened at that meeting. Did someone sit there and say something like 'Look, I'm not saying we should "be evil"...'? How does that conversation start?
Maybe at the time it seemed intuitive, not representative of the _positive_ goals of the company, and just something people could point at whenever there was a minor disagreement. In hindsight they may have been able to avoid the dumpster fire that they're in now if they had kept it.
Better yet, I'd take them there if their motto was "don't be evil".
Google's old motto wasn't "we don't kill our users", so I don't really see what you're getting at here...
I bet most people would just find other forms of entertainment for their children.
> Google's old motto wasn't "we don't kill our users", so I don't really see what you're getting at here...
My point is that corporate evil is a concept that is too abstract for most people to understand, therefore I made it more concrete, at the same time showing how nonsensical the motto really is.
Same, it's puzzling to me what is the mechanism that creates people like this.
I think it's pretty straightforward: take one part a person who sees an opportunity to earn a sizable income, and one part a person with ethics different than yours. And there you go. It's not complex.
Edit: This question isn’t about compliance. That’s easy. It’s about the downstream impact of “missing” data in the advertising ecosystem.
Some posters have pointed out that the EU still has a viable local press and a history of supporting smaller businesses. All true and something that sets it apart from the US.
Also, my original question is a admittedly cheeky, but I am interested in how smaller companies actually compete if their options for targeted marketing are limited.
Sales people, well agencies, are just super pissed that they now have to do actual work. For years they’ve been able to make money by clicking around in AdWords and Facebook ads, now the real sales people has to get back to work.
As for the comment about "consolidation of goods/services into larger and larger corporations", that's very much an Americanisation. It's usually the American firms that go for global monopolies. I'm not saying we don't have large multi-nationals in the Europe as well but there is a real culture for supporting independent businesses here which I've not noticed in America (it might exist there but I've not seen it as prevalent there during my visits).
Frankly, the only people GDPR affects is those it's expressly there to protect us from. So I consider that a win.
Europe also retains strong local press operations so advertising in newspapers is actually viable. That’s dead in the US.
But yes, I'm fine with it. Compliance is really not that hard until you reach the scale of those same dominant players.
Probably true in Europe. Regulation and taxation schemes are onerous there. Only the large can survive.
Also advertisements is more than just spending money, you need to mesh with the local culture as well. An American multinational doesn't really mesh well with most people and people reject their marketing, while local companies understand much better what the local people wants. In theory the giants could just hire locals, but in practice that has been really hard for them to do, as we can see every country has their own grocery store chains, brands etc.
Anyway, we can't refute all your points. It is really easy to just ask more and more questions, but at the end the results is what matters. And the real world results says that Europe is very good for small new businesses.
The EU laws and regulations are quite simple to follow, and I dare say that it's much more difficult for those large corporations you mentioned because they usually have much more responsibilities. Smaller companies with a smaller scope do not have to worry about rules which do not concern them and their business.
So, to answer your question, yes, this is exactly what I want personally. For-profit actors need to be scrutinized.
Ultimately my question isn’t about compliance. That is relatively simple. It’s about the downstream effects.
Tech isn't magic. It's still just a business.
No, you don't
> This is one of the potential factors why the EU loses out to other markets in startup-friendliness.
No, it doesn't.
What it "loses out on" is on price dumping through unlimited investor money and wholesale private data collection
I used to be think GDPR was a good thrust for user privacy but years later what I see is an adorned web already suffering under the weight of its own crap super-adorned with these cookie banners that impact my actual, day to day life of the net.
That's not a failure of the companies doing the tracking, that's a failure of regulation. The EU could have legally enforced the existing Do Not Track flag but instead we get a worse web that has literally shaved off hours (days?) of my life clicking through cookie forms. And no number of uBlock scripts that promise to erase them from the web has been enough to stop them.
So, report these privacy invading companies to your local data protection body, you say! Sir, madam or epithet of your choice, have you tried reporting a breach to the Danish Data Protection Agency? They will do everything in their power to invalidate your claim. That was the last straw for me. Our protectors are indolent or powerless and here we proclaim victory!
All I've seen from these rulings is spinning wheels, wasted labor, money set fire and pain.
Our German clients have screamed and hollered (thanks, Schrems II!) to bifurcate our clouds so that one side is AWS and the other is a German cloud that moves with the glacial pace of the 90s and with that decade's service portfolio. Don't even get me started on the service level difference:
AWS: how can we literally give you everything you need to build your successful business? How about these free recruits who just graduated out of our program that specifically re-trains people from disadvantaged backgrounds to be cloud all-stars? How about regular consulting sessions with our teams to identify how you can save money with us?
German cloud: let's make setting up a managed DB the most horrifically onerous process possible that's unreliable and flaky with your data and then charge you thousands of euros for support fees fixing the things that were our fault to begin with.
Additionally, let's break out out of the HN bubble and assume the role of somebody who is not a tech aficionado. E.g. the C-level exec of small and medium sized producing company in Germany (e.g. automotive). Now they not only face the burden of having to modernize their often dated tech system but also get the handicap of having a whole new sea of GDPR complexity before them which, if something goes wrong, can be business ending. I've seen this being a preoccupying topic for meetings for years for companies which really should not have to care (producers of automobile parts). It's a significant part of the IT budget going down the drain which could've been spend improving existing processes.
Let's start with this question: how are they running their business?
> also get the handicap of having a whole new sea of GDPR complexity before them which, if something goes wrong, can be business ending.
1. There's nothing complex about GDPR
2. GDPR is not business ending, as data controllers are expected to help and guid the companies who are found to be in breach of GDPR
> I've seen this being a preoccupying topic for meetings for years for companies which really should not have to care
It means they don't care in the least. GDPR is an amalgamation of the various data protection laws that existed before GDPR. So, these "poor companies who are in meetings for years" didn't care about data protection then.
Then companies were given two years of transition to get in shape and get their act together. Omg, these "poor non-technical companies" are still "in talks for years".
GDPR has been in force since May 25 2008.
So. At least a decade of data protection laws (and German laws have always been quite strict) + 2 years of transition period + 3.5 years of the law being in effect. And it's still " preoccupying topic for meetings for years"?
> It's a significant part of the IT budget going down the drain which could've been spend improving existing processes.
Yes, indeed. If 15 years later they still can't figure out why they shouldn't keep personal data around, they definitely need to improve their processes. And IT has nothing to do with it.
I did. And I do.
> Because I do and the amount of money we need to throw at compliance, both in direct costs and dev hours, is immense.
It's not immense, with emphasis. It's just the cost of doing business.
If you run into having to do compliance or certification, it means that you're doing something that requires you to be, you know, compliant.
For example, financial institutions have to be compliant. And we, as society, really-really want them to be compliant and responsible for what they are doing. Not like Equifax in the US.
> And we're not doing ads, user targeting, or any other such "nasty" industry practices.
It doesn't matter, if you do it or not. The "immense" cost of compliance is just your business deciding to cut corners and then realising that no, you shouldn't cut corners, and then scrambling to fix that when you were most likely caught red-handed.
I worked at a company which was a bit lax with its practices, and then had a run-in with an unexpected audit. Omg, you wouldn't believe, but the cost of compliance with laws was immense as we rushed to meet al requirements before the deadline imposed on us. Had we not been lax, this wouldn't even be a problem.
> I used to be think GDPR was a good thrust for user privacy but years later what I see is an adorned web already suffering under the weight of its own crap super-adorned with these cookie banners that impact my actual, day to day life of the net.
Ah yes. Another person who complains about compliance, and then immediately pretends that the state of the web is the result of a law.
No, the web is the way it is now precisely because these companies flaunt and break the law. All those cookie banner with dark patterns? They are illegal. The only real downside of GDPR is that it's not enforced as rigidly as required, and nowhere on the required scale.
As for compliance with GPDR, it's essentially zero added cost for small companies with greenfield projects. For small-to-medium companies the cost of GDPR compliance is the function of data practices. If it's "immense" for you, this only means that you were already siphoning user data you didn't need and did nothing to protect it. I can't feel sorry for you.
> Our German clients have screamed and hollered (thanks, Schrems II!) to bifurcate our clouds so that one side is AWS and the other is a German cloud that moves with the glacial pace
Once again, you blame your own technical decisions on the law. Of course German customers would want their data in Europe. Why wouldn't they? Data on American servers is basically forfeit, and can be examined, analysed, and seized by the US at any moment. Wow, I can only imagine why German customers would not want that. Whatever might be the case, hm?
> German cloud: let's make setting up
Once again: it was your decision. AWS (and GCP, and Azure) literally provides a service to European customers where they keep data in Europe only, and that is more than enough for most any compliance (I know banks in Europe who use AWS and/or GCP). [1]
So, your poor technical decisions have lead you to suffer increased costs, and you blame that on laws. Keep it up, it's a good way to stay in business.
[1] AWS: https://aws.amazon.com/compliance/eu-data-protection/, Azure: https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boun..., GCP https://support.google.com/cloud/answer/6329727?hl=en
We're working, willingly and early, with an independent auditor we hired.
As for the German cloud, no AWS Outpost or anything else we (and AWS' legal team) pitched was enough.
> The only real downside of GDPR is that it's not enforced as rigidly as required, and nowhere on the required scale.
Whose actual fault is this? The EU pushed through a ruling without teeth. It's a lose-lose for everyone from business all the way down to the person assaulted by these cookie notices.
> So, your poor technical decisions have lead you to suffer increased costs, and you blame that on laws. Keep it up, it's a good way to stay in business.
This is just rude, please don't.
> If it's "immense" for you, this only means that you were already siphoning user data you didn't need and did nothing to protect it.
Why are you continuing to state things as fact you don't have a clue of? This is completely false.
You've asked if I worked at small-to-medium company in the EU. I told you I did. My experiences are significantly different from yours. This only tells me that there's definitely something wrong you're doing, and blaming it on the law. Since you're not giving any details, it's pure speculation at this point.
> Whose actual fault is this?
I think no one could even predict the scale of the issue. No one could imagine that:
- even well-to-do commercial companies would include literally hundreds of trackers on their web pages
- almost literally everyone would decide to break the law instead of, you know, stopping wholesale data consumption
The ad industry played a nice trick: now everyone believes the EU with its GDPR is the bad guy, and not the motherf@ers who siphon your data to 500 advertisers on every page.
As for the teeth, GDPR can fine you for a significant chunk of your global turnover. So yes, it has teeth.
> Why are you continuing to state things as fact you don't have a clue of?
Are you the only one allowed to state things?
For example, a government which ensures that you don't go to jail for some bs reason is a government which I would be more trustful of as an enterpreneur.
This seems to be a premise you are working with, but as someone with my feet in Europe, it just is not true. Lack of targeting data may make it a bit more expensive to market goods, not "financially impossible". I see ads from small companies all the time. Some are even related to my interest, specially when they are located close to things related to the ads.
Not sure why you think this wouldn't work in Europe.
Additionally, the EU seems to be big enough of a market for corporations to still bother with providing privacy-friendly variants of their products that mostly function in exactly the same way.
How could they possibly have acquired customers back then?!?
Smaller companies using the services provided by the bigger fish have caused a self-perpetuating circle of ever increasing imbalances in many areas.
The resources that are being spent on not only keeping this machine in tact, but as seen in the article, grow it even further, show that this machine isn't going to stop itself and that higher intervention is required.
This is going to be costly and hurt in other ways, but with it being a massive stap towards a sort of post-scarcity society as was shown in Star Trek and by the Venus project, it's worth every tear and every penny.
I mean, it seems the US has completely abandoned their policy of breaking anti-competitive companies in favor of what essentially looks like surveillance mercantilism.
In that context, your question is ambiguous: are you, as often happens here, arguing that EU attempts at regulation entrench monopolies, or are you arguing that the EU should take significant actions to break US tech monopolies' presence in Europe?
In the first case, I believe there is ample evidence that anti competitive behaviour by tech companies is widespread enough that regulation doesn't significantly improve their position.
As for the second argument, the US government has always vigourously pushed back against any EU attempt at unfavourable regulation.
For example, Apple rolls out privacy controls in iOS 14. The story is about big adtech vs Apple privacy, but the downstream impact is that smaller businesses can no longer target effectively.
GDPR and similar privacy moves in Europe have the same impact.
The result is that smaller companies either evaporate or move to marketplaces because they can no longer acquire customers at acceptable rates.
I am a bit stuck here, what do you call smaller businesses? Rolling out effective targeted advertising is hard in the first place. It's even more so in an environment like Europe where potential buyers are fragmented across countries with different languages, cultures, and so on.
If anything, effective privacy laws levels the playing field. That's good for companies that can't afford a large marketing budget.
After the initial scare of the GDPR, most organisations found a way to live with them.
But obviously, it will become very tricky, and potentially costly if you want to violate people's privacy.
A similar example is that many banks outside the US prefer not to have US citizens as customer. This is also because complying with US laws is more costly than the money made from US citizens.
When it comes to smaller retailers, that is probably due to the EU tax rules. That's a pity. But possibly hard to improve.