UK’s GDPR replacement could wipe out oversight of live facial recognition
theregister.com
theregister.com
Workers rights, human rights… it’s all up for negotiation now. By people who aren’t listening to you.
What?
The single market.
Oh. Yeah, yeah. They did give us that. Uh, that's true. Yeah.
And the peace funds.
Oh, yeah, the peace funds, Reg. Remember what Northern Ireland used to be like?
Yeah. All right. I'll grant you the single market and the peace funds are two things that the EU have done.
And the Erasmus programme.
Well, yeah. Obviously the Erasmus programme. I mean, that goes without saying, doesn't it? But apart from the peace funds, the single market, and the Erasmus programme--
Food standards.
GDPR.
Huh? Heh? Huh...
Climate policies.
Ohh...
Yeah, yeah. All right. Fair enough.
And the chorizo.
Oh, yes. Yeah...
Yeah. Yeah, that's something we'd really miss, Reg, if we left the EU. Huh.
Cross-border healthcare.
And it's easier to travel to Spain now, Reg.
Yeah, they certainly know how to keep order. Let's face it. They're the only ones who could in a place like this.
All right, but apart from the single market, GDPR, climate policies, chorizo, order, food standards, Erasmus programme, a cross-border healthcare system, and peace funds, what has the EU ever done for us?
Prevented wars?
Oh shut up!
Cookies are the least offensive tracking technology. They're visible to users and the interactions with them can be seen. The EU should have mandated that all tracking has to be implemented as a cookie so that users could see it and block it themselves. Instead they added a lot of cruft and legal risk to every website and it doesn't make anyone "safer".
> you quickly see who works in bad faith
No, and that's the ultimate fail. You click the button and feel safe but you can't see the server-side logs so it's entirely a false sense of security.
If you want to stop tracking, make the law about tracking not about the current methods.
The acquisition needs to be through informed consent and the data retention needs to be for the reasons consented to and not extend for periods beyond that (unless you need to keep data to comply with other laws, eg tax).
It's likely to lead to the quasi-ban of LLMs sooner rather than later in the EU. This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't.
While I lean remain; some people seem to have serious blind spots that a _lot_ of EU legislation is poorly thought out and given the slow pace of change extremely hard to revoke once it is in force (cf the ridiculous cookie banners; which were implemented in law in 2002 and _still_ haven't been changed, despite 10+ years of efforts to do so in the EU institutions). It's going to be even worse with the EU Digital Services Act, where being in compliance with GDPR and the DSA is a lawyers dream, as from what I understand it directly contradicts each other.
Isn't that intended?
- A group that think GDPR = cookie law and there's nothing more written in it. Never any discussion about, say, forcing companies to report a data breach within 72h of detection. Or about being able to download your data, or forcing a company to remove your data, or...
- A group that think passing a new law = everyone is going to comply immediately and one random website that they know of that doesn't comply but wasn't sued yet into submission = GDPR was a mistake.
Oh, I'm not blind to it. My calculation is a simple one: looking at where we were and where are now, where would I prefer to be? For me it's not a difficult conclusion.
> This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't
Sure, but your argument completely disregards the privacy concerns which is the reason the EU has done what it's done. It's possible for Europe to decide that it's worth the cost in potential business to protect the privacy of its citizens. That's essentially what GDPR decided, after all.
(FWIW I've worked on GDPR implementations, I'm not so convinced it's a failure. It lead to a very meaningful drop in the amount of personal information the company was storing. The compliance costs were not particularly huge ongoing costs, just upfront implementation ones)
First there is the practical implementation. As we've seen the current stand-off between US government security laws and EU government privacy laws is still being decided in favour of transferring personal data for processing in the US. That might even be the preferable way to break the deadlock for the immediate future because the cost to the European economy and particularly the tech sector of suddenly cutting off all US-based services when the EU has no native competitors would be enormous and as things stand that appears to be the only safe way to guarantee legal compliance on both sides of the Atlantic.
There is also the hypocrisy angle. The GDPR allows for EU government access to personal data under their own security laws that is not so different to what the US laws allow the US government to have. There are definitely some double standards in the typical arguments about how the GDPR protects personal data from unwarranted government intrusion and overly broad security laws.
I'm also firmly in the pro-privacy camp on principle but the rules do still need to be workable or everyone is just going to ignore them anyway. It's not clear to me that the way the GDPR is currently being used against big US tech companies is a good way to go.
I think you have it wrong way round - EU business was late, and 5he market was sevured by US corps. I dont think EU will ban US business, but if they did, that would create opportunity for homegrown co petition to emerge. By now, cloud services are not rocket science.
That's one theory. The problem is the several years of lag time between the opportunity being created and anyone actually exploiting it at scale. In the meantime countless SMEs that depend on modern online services for their day to day operations would probably have failed.
By now, cloud services are not rocket science.
And yet the US keeps producing them at a far higher rate than we do over here. Much of that has been due to the VCs almost casually giving away millions in funding in the hope of backing the next unicorn among all the failures, which is an investment culture you don't see so much in Europe. But there are also reasons investors tend to favour some countries over others and the regulatory environment is usually second on that list (after taxes/subsidies) if it's not first.
And in their regulatory environments the EU and US are almost polar opposites. The US is very lightly regulated (apart from the problems of regulatory capture, where the US seems to do much worse when it does happen) but that means tech firms engage in practices we might not like. The EU is very heavily regulated but that means added overheads even for well-behaved businesses that can eventually add up to being less competitive in a global market. Maybe there is a sweet spot in between but certainly neither the US nor the EU have found it yet.
Imagine if this was one of the principal virtues in human civilizations. Where would humanity be? Would we know the Earth is round and not the centre of the universe? Would we have vaccines or antibiotics? Would we have most of our art and literature? Would simple technologies like irrigation even exist? We would probably not have any advancements past about middle ages.
I don't understand why so many cynics tell this to others these days. Do they genuinely have a mindset that nothing is worth trying if it failed the first time?
No. But the way you first picked to do the thing is very likely impossible to make work. Don't decide on a mechanism, like cookies, and fixate on it without regard for practicality or effectiveness.
Preventing invisible tracking is probably a good goal that's worth iterating on but making sites pop up a list of good and bad tracking and being allowed to track the people who accidentally don't click "No!" seems like an entirely failed way to go about this.
If tracking is bad then stop it for everyone, not just people who clicked the correct thing. If some tracking is generally bad but allowable for certain functionality then mandate that tracking is only applied once the user had opted in, etc. Don't make users mark "Don't steal my organs while I sleep" on the hotel paperwork.
GDPR is not about cookies. Cookies are mentioned only once in the entire legal text as an example of a technology that can be used to associate users with personally identifiable data. If there is no risk for this association, GDPR does not care about cookies.
GDPR is about ethically acquiring and handling personal data.
Yes, we need more effective GDPR, not less.
Some sibling comments challenge that it doesn't help reduce the amount of private data stored.
I would argue that GDPR is working as intended on the economic war front. The US weaponized their extraterritorial anti-corruption laws, China is also building similar legal weapons, GDPR is part of the european answer to that: a framework to catch up with other super powers who can pressure foreign companies whenever it pleases them.
It won't be GDPR but newer regs
> This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't
I'm sure they'll find a way
> a _lot_ of EU legislation is poorly thought out and given the slow pace of change extremely hard to revoke once it is in force
Kinda, but things don't change only by the original legislative process, but by subsequent regulations, agency reviews (like data protection organisms), judicial reviews, etc
> which were implemented in law in 2002 and _still_ haven't been changed, despite 10+ years of efforts to do so in the EU institutions
I'd love to know what kind of discussions went in regards to the cookie law and GDPR in legislative reviews. I'm sure it's all logged in a very verbose way in multiple websites and it would be some effort to get it all together
And the AI act worries me, but we know that actual enforcement and definitions and wiggle rooms exists (and as with GDPR, enforcement is kinda patchy)
Now if the popups are obnoxious whose fault is it? (To answer that just notice how many other obnoxious popups/overlays/etc the same site has about other stuff)
They could just choose to honour "do not track", but I realise they want the money. Most large sites seem to have added the "reject all" button when it appeared that this was necessary for compliance. Those that did not don't care if they comply.
Obnoxious banners are a choice. If we didn't have them the choices of site -owner's wouldn't be less obnoxious, they would just be hidden.
It's like the warning your car makes 'put your seatbelt on'; sucks, but better than it not existing.
Like every company will be different, but you really should know where your data is kept.
Even when it's legally dubious we'll do our damnedest to look like we're surveilling the ** out of you.
That said, I didn’t think London was nearly as bad a Singapore for number of cameras. And their aren’t closed, I have no doubt that’s all to a central store, facial, and AI all rolling now.
In the US, I worry that some anonymous fellow citizen packing heat is going to snap and decide to execute a lifestyle change on me I didn't ask for and then melt away, unaccountable. The US unsolved murder rate is at a record high. Between the lack of firearm rights and the ubiquitous surveillance, I never had that fear in the UK.
They say a fish isn't really aware of the water they're swimming in. Visiting Europe was like having a weight lifted off me, a tension released, that I'd been carrying my whole life and didn't know was there. Americans just live with the spectre of death due to random gun violence perched on their shoulder these days.
As soon as anything impedes special interests even slightly, be sure it will be legislated out of existence if possible.
One argument brexiteers trot out commonly is that EU regulations make it hard to be competitive. But human rights should impede "competition" otherwise it's a race to the bottom.
This contrasted with the weak response from the government after the sordid London bridge attacks, with the mayor even stating that "Terror attacks are 'part and parcel of living in a big city'". Is this what people in the UK want?
"Part and parcel of living in a great global city is you have to be prepared for these things. You have to be vigilant."
The context was talking about working with other big cities, specifically New York as it was just before a meeting with Bill de Blasio to talk about cross-training and information exchange.
Johnson was asked directly about workers rights prior to Brexit and said that we would improve them and that it was so totally wrong of Remainers to assume any rights would be eroded... and no-one paying attention is surprised to find that was a lie. But it probably worked for a small margin of voters in the referendum.
The reality is that the EU legislation was toxic and loopholed at the behest of the UK and its special interests. The UK was not a moderating influence, but the UK was the one calling for no encryption and spying of the population.
If given a chance to improve or remove legislation the UK government will remove it NOT because its an assault on freedom and liberty, but because they dont think it goes far enough in curtailing freedom and liberty.
As a UK national, I have to prefer being beaten with relish by genuine sadists (the UK government), rather than by sadists who pretend to have some heart left over.
Most EU countries have an ultra-right wing, nationalist and euroskeptic party in their parliament (I just don't want to say "fascist"). At least three (Italy, Hungary and Poland) have one in government. In France, Mme Le Pen has consistently got to the second round of presidential elections for the last ... three? Four? elections?
Things aren't going well.
You mean might be a new union? I can agree with that. A fragmented Europe is not stable, if the EU dissolves in the next 10 years, it's almost certain there will be some sort of union in the next 2 generations. Whether there'll be another war in Western Europe between now and then is another question altogether.
Leaving was their 'controversy of the day', there are other ones they can use to pent up dissent.
But the kind of people who want the policy that Brexit is - i.e. xenophobic nationalists - are not the kind of people you'd want to take such an opportunity.
Membership of the EU was a great opportunity. Brexit is an opportunity for fascists.
I'd be curious to hear how exiting the European Union relates to the doctrines of Benito Mussolini.
Phew, that was a close one!
I need propositions, not further slander.
Personally, I would take a guaranteed "90% right" system (aka the EU) over a random number generator (aka Brexit)...
This is the part everyone wants to say but isn't right. They are usually listening to people, just not people who agree with you :)
One of the grand follies is to assume politicians are not doing what their constituents support.
They almost always are, and often enjoy incredibly high local support/satisfaction ratings, even when the national ones are in the toilet.
They spend significant amounts of time polling and understanding how their constituents will react to issues and votes.
Now, you may want to argue those constituents are ignorant, or don't know what the vote really means, or whatever, but it's a sideshow.
I often see people say "well 70% of people in the country support X so politicians aren't listening". But when you break it down, they are usually voting in alignment with constituent support, and it's just a variant of Simpson's paradox in action (overall population vs subgroups).
They do nothing but listen, have dedicated staffers and help that do nothing but analyze constituent opinion/views/etc.
You will rarely find them doing anything that is going to go against that. The exception is the small number of places where they are forced to deal with multiple constituencies for real.
I knew EU regulators would be freaking out about AI. I didn't anticipate that this freaking out would take the form of unbelievably stupid draft regulations, though in retrospect it's obvious. Regulators gonna regulate.
At this point if I were a European founder planning to do an AI startup, I might just pre-emptively move elsewhere. The chance that the EU will botch regulation is just too high. Even if they noticed and corrected the error (datum: cookie warnings), it would take years.
Now that I think about it, this could be a huge opportunity for the UK. If the UK avoided making the same mistakes, they could be a haven from EU AI regulations that was just a short flight away.
It would be fascinating if the most important thing about Brexit, historically, turned out to be its interaction with the AI revolution. But history often surprises you like that.
I mean, everytime I go to a new site, what cookies am I going to accept...? What ridiculous yet boring puzzle is going to try to trick me into giving this or that info over? Thanks EU!
The nice thing about being part of the EU was that we had a second level of sanity involved in our jurisdiction .. especially important when we have inept dangerous parties in control.
We're so democratic we lock up people who look like they might be going to protest against us having rulers selected by accident of birth, rulers we are forced to spend £10s of £Millions 'celebrating' despite them being some of the richest people in the World. You can't get more democratic than that! Good job everyone here has more than enough, so it's not at all immoral. /s
I believe we need to strengthen laws against it. As well as start practicing a broader set of personal security & privacy techniques.
For example, a few of the easy ones I apply by default: I try hard to never use someone else's WiFi: and pay cash everywhere I can; and when say a fast food place asks for my name, unnecessarily, I give them a throwaway alias name (like Joe or Bob), so at worst thats the name they enter in their system. Hundreds more techniques exist obviously, some much stronger, and I recommend folks tailor theirs to taste.
Trade-offs always, and no silver bullet. But wise to take SOME action to fight back and protect yourself. Don't be paranoid, but don't be a fool.
----
---
Edit: I presume drive-by downvoters supported the conviction of Wayne Couzens?
So I'm not surprised that they think invasive surveillance capitalism is also a good thing.
I’m curious of what British politics like in general. Like, I’m absolutely against invasive surveillance, but I associate it more with communist China and its authoritarian bullshit.
https://en.wikipedia.org/wiki/Operation_Demetrius
We also routinely convicted people on flimsy charges, this being the most notorious case:
https://en.m.wikipedia.org/wiki/Birmingham_Six
A notoriously brutal policing operation split along ethnic lines:
https://en.m.wikipedia.org/wiki/Royal_Ulster_Constabulary
Infiltration of various groups by police with the sole purpose of surveilling and disrupting their activities:
https://www.theguardian.com/uk-news/2018/oct/15/undercover-p...
Mass surveillance by GCHQ as documented by Snowden:
https://en.wikipedia.org/wiki/Global_surveillance_disclosure...
Rendition without trial (aka kidnapping) and torture:
https://www.theguardian.com/world/2013/may/22/uk-support-cia...
https://en.wikipedia.org/wiki/Abu_Ghraib_torture_and_prisone...
London is the most surveiled city outside China:
https://www.verdict.co.uk/most-surveilled-city/
And last but not least, the Metropolitan Police is full of creeps, rapists and murderers:
https://www.bbc.co.uk/news/uk-england-london-58747614
https://www.theguardian.com/uk-news/2022/jun/28/met-police-p...
https://www.theguardian.com/uk-news/2021/apr/22/fourth-offic...
...
OK, one more, I give you.. indefinite prison sentences:
https://www.theguardian.com/society/2022/sep/28/call-to-rese...
Edit: The pattern I'd identify throughout 200 years of our history is that we regularly "clamp down" on groups that are no threat (eg, Catholics, Irish people, and today Muslims) and radicals of any kind who wanted stuff like the vote, or socialised healthcare, or a decent environment. The pattern may well span longer, but I can definitely pick it up during that time.
I don't think it is even a matter of national character, either: it is a function of how our politics works. We have two viable parties of government, and they don't contest certain things, including authoritarian policymaking.
The newspapers are suggesting the new migrant stats to be published soon by Home Office for past 12 months will show extremely high numbers from both Hong Kong and Ukraine. To be honest I'm surprised people from Hong Kong didn't pick Australia instead of UK given it's better weather and bigger homes/roads compared to cramped England.
The policy is not without flaws though, the youngest BNO holders are now 26, immigration policy that focus on older generation is much harder to work. The 12-18 year olds are having a hard time as well, a 6 year stay is required before you could go to university with home fee, and no home fee basically means no university for many families.
My understanding is that the UK has the pretty generous BNO visa with immediate working rights and a path to citizenship, while Australia has an enhanced post-graduation pathway.
THe first is much easier and more flexible.
https://twitter.com/RishiSunak/status/1660560546465193984
Look how clean and groomed our dear leaders are while they are surveilling the population and ruin the economy. Whatever it takes!
"Authoritarian" concerns were expressed last time Labour was in government [1], and they're "seriously considering" resurrecting their policy of mandatory id cards if they get in power again [2].
And, before I get smeared as a "Tory"/"Brexiteer", I am not - I'm someone who remembers what happened last time Labour was in power and see neither party offers an alternative to increasing surveillance in the UK.
[1] https://www.theguardian.com/commentisfree/2006/apr/24/commen...
[2] https://labourlist.org/2022/11/mandatory-id-card-policy-shou...
Why would anyone who wanted mandatory "ID please" checkpoints advocate for them before introducing ID cards when:
a) it makes no sense to advocate for them prior, there’s a natural sequence of dependencies.
b) it would hinder the introduction of ID cards and hence, mandatory "ID please" checkpoints.
We had that back when the government made it mandatory to have ID to be employed or have a bank account or rent a house. Not having an ID scheme didn't prevent it being made a requirement.
The sad thing is that the UK has inflicted all the negative aspects of ID requirements on people without the consolation prize of a universal free ID.
If you have a job, rent a house, or have a bank account in the UK, you must have a government ID at the moment. Because people wanted that requirement barrier built so it could be used against immigrants.
You might as well say we should not have police because if they're required to beat you up if they saw you commit a crime then that would be bad. It would, but they're not, and it's the people who would intend that who you should oppose.
In several European countries, you absolutely do.
Criticising the current PM doesn't automatically make it a partisan issue IMHO.
Personally I don't actually care what party they're in. I care how {badly} the {party who are currently in power} are running the country.
> neither party offers an alternative to increasing surveillance in the UK
I agree. They're all worthy of criticsm at the moment. And particularly the ones currently in power.
In hindsight I was wrong to say that; it was a bad choice of words. I agree with you. Thanks.
That said I do think the Tories have taken it to the n-th degree recently, though. It's unlikely that Labour would introduce new bills that are quite as heavy handed as the Police, Crime, Sentencing and Courts Act 2022 but I imagine they're unlikely to unwind what is currently there now.
> GPT-4, make a generic 90-second UK political ad script about a G7 meeting in Japan. We don't have much footage, so slow it down and fill it with B-roll. Focus on nonspecific virtues, like freedom and peace. Include quotes from the main politician, and even though it's a video about G7, do a section on Zelensky and Ukrainian conflict.
It keeps writing much better scripts though.
For all the things I can think of to complain about our current government, this is not one of them.
The end result is you'll just have sweatshops of people watching CCTV streams clicking matching face images because it's illegal to get a computer to do it automatically.
Good luck explaining how that isn't "data processing".
Automating mass surveillance is dangerous; it makes _possible_ levels of societal control which simply weren’t possible for even the most aggressively dedicated police states of the past. It’s a bit of a Pandora’s box, and probably best left closed.