I don't want an incompetent patronizing government. I want competent leadership in politics and business that is able to set up a culture of innovation.
I don't want an incompetent patronizing government. I want competent leadership in politics and business that is able to set up a culture of innovation.
This isn't an EU level decision. Countries in the EU have a lot of control over their own affairs, as they should.
Conflating EU and Domestic policies is a bad thing (this was done a lot in the UK)
In this certain case, I see already other nation's leaders and eventually the EU commission feeling inspired by this "bold" way Italy deals with ChatGPT. And #chatcontrol is an issue that directly comes from the EU commission (again the German "home secretary" is pointing at Brussels while officially hilariously stating "no we won't install client-side scanning everywhere").
I wonder where Belgians point to. Schuman?
[1] From the FT but here's a non-paywalled link https://archive.is/p4H9X
Here's a classic for you, one of the early incidents which lead to this kind of regulation: https://en.wikipedia.org/wiki/1858_Bradford_sweets_poisoning
Here's some more contemporary links:
https://food.ec.europa.eu/safety/food-improvement-agents/add...
https://food.ec.europa.eu/safety/food-improvement-agents/fla...
Which includes an answer to your question: "The procedure for authorisation of a flavouring substance is common to the one established for food additives and enzymes under Regulation (EC) No 1331/2008."
>Are you seriously confused why governments regulate what can be put in food and sold to the public?
Are these the same regulators that allowed Olestra to be used? sidebar--just to check the spelling of Olestra, I used the Mac's force click dictionary access: "Origin 1980s: from (p)ol(y)est(e)r + the suffix -a." WTF? Seriously? We dropped some letters from polyester and called it food ingredient?
Yeah, sounds like some "regulations will save us" doesn't work as expected.
I don't see how said regulation would have helped in this case, the shop owner simply mistook fake sugar for arsenic, it's not like he decided to sell arsenic-flavored candies.
(He didn't mix up the sugar with arsenic. He mixed up the gypsum.)
Then you're free to do so if you aren't putting artificial sweeteners in them.
https://en.wikipedia.org/wiki/Commission_Directive_91/71/EEC
So Italy's concerns might also apply to us, and every EU nation with EU GDPR.
BUT let's not kid ourselves there is huge pressure to stop OpenAI from techphobes to pearl-clutching techphiles and of course ruthless rivals who want a breather to catchup.
This was the bit i wondered about, there’s at least an incentive for this kind of jiggery pokery lobbying but little transparency.
It's a decision by a domestic DPA based on the GDPR. In practice, it will have an impact across the EU, because any company intending to operate uniformly across the EU has to, in practice, comply with the most onerous GDPR interpretation taken by any domestic DPA.
This ratcheting effect is a practical reality given how the GDPR operates. It's also why orgs like Schrems' NOYB celebrate individual victories with the most activist DPAs. They ultimately do have an impact across the EU.
edit: minor additions/corrections
I don't really want my government 'innovating' much at all. I want them to provide for defense of the people and freedoms.
How many competent government leaders have you seen?
Hear, hear.
How many "accept all cookies" button did you have to press today?
Not, however, on Hacker News, because Hacker News isn't using data for more than actual functionality, and you don't need to ask permission in that case.
As additional homework, you can also lookup malicious compliance etc. Or even the sibling discussion on how Facebook wants you to apply for a permission to opt out of their tracking: https://news.ycombinator.com/item?id=35383925
Privacy should have been promoted through technological means, e.g the EU could have funded development of fingerprintless browser technologies, zero-knowledge proof based identity verification, etc, instead of through bureaucratic regimentation of private interaction.
But boy was I wrong. The people criticizing GDPR were right: Tech giants were able to cope better with the regulations while smaller domestic companies were put under an additional burden of excessive bureaucracy. And from what I perceive, there's now cookie banners everywhere while my personal data is still going into opaque silos.
Those cookie banners are either non-compliant with the regulations or meaningless. Why people add them is anyones guess.
It's true that a cookie banner (notification only) does not equal "the site can now do whatever it wants and is GDPR compliant thanks to the banner".
However, cookie notification banners are nothing to do with GDPR! They are to comply with an earlier (but still active after GDPR) bit of legislation, the 2002 'ePrivacy Directive' (sometimes known as the "cookies law").
If you don't go near personal data, but still want to use cookies for website functionality, then GDPR doesn't apply but you need to notify users of your use of cookies. If you are doing stuff that's covered under GDPR, then you obviously need to do more than just a cookie notification, and in most cases doing that 'more' will cover the non-personal cookies too so no need for a separate cookie notification on top.
https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
edit to be more specific: section (25) includes "Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using." and "Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose." (meaning that unlike with GDPR, it's easier to say "these cookies are necessary, accept them or don't use this website")
Full text of that 2002 directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
And usual disclaimer, this is not legal advice, if you're doing anything affected by either the ePrivacy Directive or GDPR you'd do well to do one or both of getting specific advice from a lawyer with specific expertise in this area, and that if it's a personal site (or a company without the money for legal advice), better safe than sorry and better to give users more power (in terms of requiring their consent to use even cookies that might not need explicit opt-in to be legal, etc) than required rather than less. Both better in terms of liability, and in terms of ethics!
The cookie banners people are now complaining about are literally companies skirting or otherwise breaking GDPR. Because they now have to ask for your consent before the siphon your data and sell it wholesale to the highest bidder.
There are certainly plenty of examples of poorly implemented banners attempting to comply with GDPR while not actually being compliant, where consent is required, but I wouldn't call those 'cookie banners' since they generally talk about privacy and personal data, not just about cookies/local storage.
My point was that there are plenty of websites that don't need to comply with GDPR (because nothing they do falls under its scope), but they still need to comply with the ePrivacy Directive and therefore there are plenty of cookie banners used for that purposes that are a perfectly acceptable way of complying with that law - though because people are more familiar with GDPR than with the ePrivacy Directive, they see those banners and think it's a non-compliant attempt at dealing with GDPR.
---
I think, but don't quote me in that, that with ePrivacy you don't really need a banner, but an explanation that you use cookies. But that is a minor issue
Hearsay and rumors, so don't take this seriously
But it's from 2017... https://eur-lex.europa.eu/legal-content/EN/TXT/?darkschemeov...
(If the twitter discussion was interesting, any suggested accounts to follow for this sort of topic?)
I guess you'd want follow
- Felix Reda https://twitter.com/Senficon (former European MP for the Purate Party)
- NOYB EU https://twitter.com/NOYBeu (fighting the GDPR fight)
- Max Schrems https://twitter.com/maxschrems (https://en.wikipedia.org/wiki/Max_Schrems)
These are more or less the usual suspects you'd follow :)
There was already one large crackdown on non-compliant cookie banners, and even large entities had to stop fooling around and implement them properly.
The leftovers need to be picked up one by one, but that necessarily takes time.
My point is: Did it help fighting privacy issues? I don't think so. Did it harm? I do think so. Will it ever be somehow measured for its effectiveness and be taken back/changed to be more effective? I don't think so. So better get rid of it.
I don't think it has made of jot of difference for privacy, but it sure has degraded the user experience of using the web.
The problem is that not enough fines have been meted out. Had they been, we'd see less of the unuseful, annoying, unnecessary banners. Because they are this way on purpose: to make you "consent" to wholesale collection and trading of your data.