A fine is a price, and there are basically no laws that put financial, let alone criminal liability for people behind the corporate veil or seizure/dissolution of a corporation that consistently breaks the law on the table
I'm extremely glad that the GDPR and NOYB.eu mean that car manufacturers can't pull that shit here. If I opt out, I'm opted out, or there will be big fines for them.
But it's a long piece of legislation and some of the requirements are time-consuming to implement even if you're not doing anything nefarious. "It is bad for innocent people to incur uncompensated costs" should be a primary principle in creating legislation.
> If I opt out, I'm opted out, or there will be big fines for them.
They're getting sued. If the plaintiffs win they'll have to pay. It's not obvious why this is worse or any less of a deterrent.
I'd say it may not be obvious why, but it's obvious that it is less of a deterrent, because this sort of data trading seems to be commonplace and semi-overt in the US, and much less common (and hush-hush in the rare cases where it does happen) in Europe.
I'd also hazard a guess why it's less of a deterrent: the risk, i.e. probability of successfully getting sued * cost of successfully getting sued, is likely much lower compared to the relatively high probability of a DPA going "WTF no" in Europe as soon as someone reports it.
But that's because the US doesn't even have the law requiring express and freely given consent, so they just stick the consent in some agreement nobody reads next to a box you have to check. You could have that rule without having the whole GDPR.
In this case they apparently collected the data even if you never checked the box, which is just egregious and now they're getting sued.
> the risk, i.e. probability of successfully getting sued * cost of successfully getting sued, is likely much lower
Certainly this is not because plaintiffs would be unwilling to file claims if they could.
This is the legal equivalent of "I can write Doom in one line, import doom; doom.start()".
These have established meanings in existing law. What are you proposing as a plausible ambiguous interpretation of "declared"?
> This is the legal equivalent of "I can write Doom in one line, import doom; doom.start()".
That's two lines.
Also, it's not equivalent, because the original is actually a composition and not just a tautology. It's like saying that this one liner to find word frequencies in a file:
fmt -1 <file> | sort | uniq -c | sort -rn
(from https://old.reddit.com/r/linuxadmin/comments/nq45r/what_are_...)...isn't a single line of bash because you haven't defined fmt or sort or uniq or '|'.
Is your argument that the GDPR can be one line because "data" already has an established meaning in existing law? The GDPR is large because all these things needed to be defined, and there are tons of edge cases, not because the lawmaker figured they'd add some extra fluff in there.
If you weren't doing anything harmful then your preexisting behavior shouldn't become unlawful.
The rest of the text is about specifying the terms of art processing, data, people, and consent.
> If you weren't doing anything harmful then your preexisting behavior shouldn't become unlawful.
Exactly. Except that you do not get to define harmful, the law does. If you weren't processing any PII, then your preexisting behaviour did not suddenly become unlawful.
Going by the EFF's latest published financials (2022), they took in $23 million vs $16.6 million in expenses. Vs literal billionaires and nation states. Some of the billionaires have more money than the nation states do. David, meet Goliath.
I care. I give them my money. They seem to do a better job at advancing these interests than anyone else. I'm more in awe of their attempts to take on issues of this magnitude given their meager resources than anything else.
The fact is, no company actually primarily exists to employ people, and people lose their jobs to this basic fact all the time, sometimes for no reason other than that some investor expects extremely marginal gains from signaling that they are serious about cutting costs
Also, the dissolution of a company and dispersal of its assets could include allocations for severance pay to cushion the blow if that's a concern, which is not always available to people who are hit by random layoffs
Currently the worst thing companies ever face is a little itty bitty fine and maybe a toothless regulator telling them “Pretty please would you mind not doing that again? If it’s not too inconvenient to shareholders that is…”
If their assets get sold and one entity buys all of them then they could just carry on operating the same company with them. The most likely buyer for something like that would be a competitor. That seems bad.
Maybe we could require the opposite. Their assets get sold, but can't all be sold to the same party. You split the company up, e.g. by delaminating vertically integrated components into separate companies. That way it's easier to enter the market and compete with any of them because you don't have to replicate the whole stack, only that one component.
You might not even need to have a vote, just some rules for when this happens automatically, like when a company has more than e.g. 35% market share, because that's too close to a monopoly and you wouldn't want a trust to form. We could call this anti-trust.
So if I want to start a small business, say a mom and pop restaurant, the public has to approve it first? You must be joking. Most businesses are small businesses. Hamstringing them is a recipe for disaster. Our regulatory system already disadvantages small businesses in countless ways. Indeed, that's part of the reason why large businesses can get away with so much.
The public already has a way to disapprove a business: don't buy from it. If nobody buys what the business is selling, it goes out of business.
The real oversight the public should be exercising, but isn't, is to vote out of office politicians that allow large businesses to buy their way out of trouble.
This “let the market decide” approach is clearly not working. It assumes that only the direct customers of a business are the stakeholders that matter, because they have the wallets to vote with. There are many, many companies that the general public do not buy things from yet suffer their harms. There are a lot of terrible businesses, large and small, that I don’t purchase from which I’d vote in a heartbeat to get rid of if I had the opportunity.
Examples, please? I find this claim extremely dubious.
> There are a lot of terrible businesses, large and small, that I don’t purchase from which I’d vote in a heartbeat to get rid of if I had the opportunity.
Of course, because you personally don't depend on those business for anything. (At least you appear to be assuming you don't--though you might indirectly. But let's assume you don't even indirectly.) What about the people who do?
> Examples, please? I find this claim extremely dubious.
Any company purchasing my data without my knowledge and selling it to advertisers.
Also, do you buy anything that the advertisers who buy your data are selling?
If con-gress was serious, theyd ban/restrict any social media that relied on tracking. Or better yet, they'd pass a bill restricting data brokers of any sort ala GDPR.
Nope. China bad. USA good!
Why would we reciprocate on a Communist plot against our children?
Would China allow an American social media company to capture 75% of their children?
If the point of fighting our enemies is to become our enemy, then why bother fighting?
How do you think countries like Iran, North Korea, etc justify censorship of western content? That exact line is used.