The legislation, at least the one coming from Brussels, is nearly always reasonable in scope, extent, impacts, penalties, and tends to strike a fair balance between specificity and vagueness as to allow the courts for some wiggle room for interpretation
As an example, with interoperability, the final legislation might stipulate something similar to this:
* once a software service reaches sufficient market size
* the core functionality of the service must be exposed for interoperability
* any breaking changes to core functionality must allow for sufficient period of backwards-compatibility and deprecation warnings. Exceptions for security breaches or other emergencies
So, for Youtube, this would mean logging in, viewing videos and history. It doesn't mean that every single feature of every single web site must be publicly exposed and be backwards-compatible for eternity
> Your wild edge case is someone else's life and living.
Yes, the person whose name is mangled by a shitty bank's IT systems. Or the people who can see what a shitty data vacuuming company has on them( that now has to ask for consent beforehand).
Regulations are there to protect people like that, not just for fun.
The article you've linked is obviously biased ( why does it make a point of talking about totalitarian communist regimes and their death toll and not any other totalitarian regimes'? Some of the most infamous and deadly totalitarian regimes aren't communist - Iran's Islamic one, Saddam in Iraq, Hitler, Mussolini). And the argument that totalitarian regimes are bad because they wage war and that democracies can't even execute serial killers falls apart when the US is brought in. I won't even bother with the rest.
EU privacy law is so vague that people routinely 'discover' new impacts of the rules only when some judge pulls them out of thin air. The fate of EU tech firms is pretty much well described above: endless agonizing over how these rules might be interpreted, followed by maximally damaging interpretations, because the nature of such law making is that enforcement is arbitrary.
It is a similar death spiral to how we deal with the housing problem. People have a hard time finding affordable apartments in the city centers? Create more laws that limit rents! Does this create more apartments? No. It just send the local housing market further down the drain.
If there is any remaining problem it is that the rules are not enforced strictly enough on tech giants.
An indie dev in New York does not care about the GDPR. The just build cool shit and put it online. Look at all the Show HNs here.
In the EU, the situation is very different. Indie devs are super afraid and work hard to make their stuff less useful to please the GDPR.
Now about larger players:
EU companies agonize their worldwide users with cookie banners. Because that is what the GDPR tells them to do.
Non EU companies dont do that. Because why should they? Will a lone Italian traveller in the USA sue them for using Google fonts? Probably not. And if they do - they can handle it. So they only agonize their EU users with cookie banners.
If your business model depends on creating undesirable externalities for your "users" then you don't have my sympathy. The only shame is that we still need to enforce GDPR properly on large players, but that's a political and social thing, not per se a problem with the law itself.
And the oh so horrible cookie banners: the solution would be to not track people. If you aren't fully acting in the users interest, the cookie banner is easy to implement, or maybe not even required. So whenever you are annoyed by a cookie banner, it should be directed at the company, not the law.
If your app is literally about self quantification and the user pays you to collect that data and keep it private? You might not even need to state it anywhere, although the safe thing is of course to list all the ways you do or do not collect data.
If your app is about self quantification and you monetize by selling user data or its aggregates... GDPR. If you use a third party data provider instead of hosting the data yourself: GDPR etc. Because user data might not be important to you, but it is to your users, so you probably shouldn't be allowed to YOLO handling it
Exactly. If a company doesn't care enough about its users to even tell them what they are doing with their data (or in some cases even know what they are doing with it) then the user can't expect that company to secure it or to provide a valuable service with it.
That is it - as a startup, GDPR is not a massive prohlem. You know what is a real problem? The fact that you can raise 10x more investment in the US with the same slide deck.
It's funny you think deregulating housing would solve the housing crisis. If you think rent limits are a disincentive to build more affordable housing, how about we just subsidize loans for non-commercial home ownership instead of expecting investors who want a ROI to either make their luxury apartments more affordable for no good reason or adhere to health and safety standards in their barely profitable social housing projects? After all, if tenants can cough up the money to regularly pay ever-increasing rents they can surely pay back loans with similar rates.