Spicy. European courts and governments will love to see their laws and legal opinions being shrugged away in ironic quotes.
Spicy. European courts and governments will love to see their laws and legal opinions being shrugged away in ironic quotes.
But the EU willingly participates in this. Probably because they know there's no viable alternative for the big clouds.
This is coming now though since the US instantly.
Don't use them! They cost too much in dollar terms, they all try to EEE lock you in with "managed" (and subtly incompatible) versions of services you would otherwise run yourself. They are too big to give a shit about laws or customer whims.
I have plenty of experience with the big three clouds and given the choice I'll run locally, or on e.g. Hetzner, or not at all.
My company loves to penny-pinch things like lunch reimbursement and necessary tools, but we piss away latge sums on unused or under-used cloud capacity with glee, be ause that is magically billed elsewhere (from the point of view of a given manager).
It's a racket, and I'm by mo means the first to say so. The fact that this money-racket is also a dat-racket doesn't surprise me in the least. It's just good racketeering!
However that's not what most traditional companies do. What my employer does, is picking up the physical servers they had in our datacenters, dump them on an AWS compute box they run 24/7 without any kind of orchestration and call it "cloud". That's not what cloud is, that is really just someone else's computer. We spend a LOT more now but our CIO wanted to "go cloud" because everyone is so it was more a tickbox than a real improvement.
Microservices, object storage etc, that is cloud.
Parts of the European Commission "influenced" by lobbyists collude with the US.
Good job.
Sarbanes–Oxley would like a word.
The GDPR allows to retain data when require by law as long as needed. People that make regulations may make mistakes sometimes, but they are no that stupid as to not understand the law and what things it may require.
The data was correctly deleted on user demand. But it cannot be deleted where there is a Court order in place. The conclusion of "GDPR is in conflict with the law" looks like rage baiting.
If any non-eu country can circumvent GDPR by just making a law that it doesn't apply, the entire point of the regulation vanishes.
Do you mean that I, an EU citizen am being granted some special privilege from EU leadership to send my data to the US?
I say temporary because it keeps being shot down in court for lax privacy protections and the EU keeps refloating it under a different name for economic reasons. Before this name it was called safe harbor and after that it was privacy shield.
I mean, sometimes the government steps in when you willingly try to hand over something on your own will, such as very strict rules around organ donation, I can't simply decide to give my organs to some random person for arbitrary reasons even if I really want to. But I'm not sure if data should be the same category where the government steps in and says "no you can't upload your personal data to an American website"
It's all about jurisdiction. Do business in Country X? Then you need to follow Country X's laws.
Same as if you go on vacation to County Y. If you do something that is illegal in Country Y while you are there, even if it's legal in your home country, you still broke the law in Country Y and will have to face the consequences.
Where is the HQ of the company?
Where does the company operate?
What country is the individual user in?
What country do the servers and data reside in?
Ditto for service vendors who also deal with user data.
Even within the EU, this is a mess and companies would rather use a simple heuristic like put all servers and store all data for EU users in the most restrictive country (I’ve heard Germany).
If outside EU, then they need to accept EU jurisdiction and notify who is representative plenipotentiary (== can make decisions and take liability on behalf of the company).
> Where does the company operate?
Geography mostly doesn't matter as long as they interact with EU people. Because people are more important.
> What country is the individual user in?
Any EU (or EEA) country.
> What country do the servers and data reside in?
Again, doesn't matter, because people > servers.
It's almost like if bureaucrats who are writing regulations are experienced in writing regulations in such a way they can't be circumvented.
EDIT TO ADD:
From OpenAI privacy policy:
> 1. Data controller
> If you live in the European Economic Area (EEA) or Switzerland, OpenAI Ireland Limited, with its registered office at 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, is the controller and is responsible for the processing of your Personal Data as described in this Privacy Policy.
> If you live in the UK, OpenAI OpCo, LLC, with its registered office at 1960 Bryant Street, San Francisco, California 94110, United States, is the controller and is responsible for the processing of your Personal Data as described in this Privacy Policy.
If it was easier or more cost-effective for these companies not to have a foot in the EU they wouldn't bother, but they do.
Americans often seem to have the view that lawmakers are bumbling buffoons who just make up laws on the spot with no thought given to loop holes or consequences. That might be how they do it over there, but it's not really how it works here.
EU companies are required to act in compliance with the GDPR. This includes all sensitive data that is transfered to business partners.
They must make sure that all partners handle the (sensitive part of the) transfered data in a GDPR compliant way.
So: No law is overriden. But in order to do business with EU companies, US companies "must" offer to treat the data accordingly.
As a result, this means EU companies can not transfer sensitive data to US companies. (Since the president of the US has in principle the right to order any US company to turn over their data.)
But in practice, usually no one cares. Unless someone does and then you might be in trouble.
That is why international agreements and cooperation is so important.
Agreement with the United States on mutual legal assistance: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=legissum...
Regulatory entities are quite competent and make sure that most common situations are covered. When some new situation arises an update to the treaty will be created to solve it.
There's "legitimate interest", which makes the whole GDPR null and void. Every website nowdays has the "legitimate interest" toggled on for "track user across services", "measure ad performance" and "build user profile". And it's 100% legal, even though the official reason for GDPR to exist in the first place is to make these practices illegal.
It's a farce and just like the US constitution they'll just continuously argue about the meanings of words and erode then over time
Session cookies and profiles on logged in users is where I see most companies stretching for legitimate interest. But cross service data sharing and persistent advertising cookies without consent are clearly no bueno.
https://www.reddit.com/media?url=https%3A%2F%2Fpreview.redd....
none of these others are legitimate interest. Furthermore combining the data from legitimate interest (email address to keep track of your logged in user) with illegitimate goals such as tracking across services would be illegitimate.
- Direct Marketing
- Preventing Fraud
- Ensuring information security
It's weasel words all the way down. Having to take into account "reasonable" expectations of data subjects etc. Allowed where the subject is "in the service of the controller"
Very broad terms open to a lot of lengthy debate
> Very broad terms open to a lot of lengthy debate
Because otherwise no law would eve be written, because you would have to explicitly define every single possible human activity to allow or disallow.
direct marketing that I believe is legitimate - offers with rebate on heightened service level if you currently have lower service level.
direct marketing that is not legitimate, this guy has signed up for autistic service for our video service (silly example, don't know what this would be), therefore we will share his profile with various autistic service providers so they can market to him.
Fraud prevention is literally "collect enough cross-service info to identify a person in case we want to block them in the future". Weasel words for tracking.
> therefore we will share his profile with various autistic service providers so they can market to him.
This again falls under legitimate interest. The user, being profiled as x, may have legitimate interest in services targeting x. But we can't deliver this unless we are profiling users, so we cross-service profile users, all under the holy legitimate interest
You're literally not allowed to store that data for years, or to sell/use that data for marketing and actual tracking purposes.
Websites A and B buy fraud prevention service FPS, website A flags user x as fraudulent, how should FPS flag user x as high risk for website B if consent from user x was required?
Legitimate interest literally allows FPS to track users, build cross-service profiles, process and store their data in case FPS needs that data sometime in the future. Under legitimate interest response to query "What's the ratio of disputed transactions for this user?" is perfectly legal trigger to put all that data to use, even though it is for all intents and purposes indistinguishable from pre-GDPR tracking.
"Legitimate interests is now our legal basis for using your information to improve Meta Products"
Fun read https://www.facebook.com/privacy/policy?section_id=7-WhatIsO...
But don't worry, "None of these allow you to just willy-nilly send/sell info to third parties." !
Add to that the fact that the EU’s heavy influence on the courts is a well-documented, ongoing deal, and the GDPR comes off as a surveillance law dressed up to seem the total opposite.
Which courts are influenced by the EU? I don't think it's true of US courts, and courts in EU nations are supposed to be influenced by it, it's in the EU treaties.
While folks believe all sorts of things, I don’t think anyone is going to call international relations apolitical!
And that's a key institution in a democracy, given the frequency with which either the executive or legislative branches try to do illegal things (defined by constitutions and/or previously passed laws).
You're right though, in a perfect world courts would be apolitical.
Most other western democracies are a lot closer to a perfect world, it seems.
Or UK where you can get locked up for blasphemy[3] or where they lock up ~30 people a day for saying offensive things online because of their Online Safety Act?[4]
Or perhaps Romania where an election that didn't turn out the way the EU elites wanted is overturned based on nebulous (and later proven false) accusation that the election was somehow influenced by a TikTok campaign by the Russians that later turned out to have been funded by a Romanian opposition party.[5]
I could go on and on, but unfortunately most other western democracies are just as flawed, if not worse. Hopefully we can all strive for a better future and flush the authoritarians, from all the parties.
[1] https://www.youtube.com/watch?v=-bMzFDpfDwc
[2] https://www.euronews.com/2023/10/19/mass-arrests-following-p...
[3] https://news.sky.com/story/man-convicted-after-burning-koran...
[4] https://www.thetimes.com/uk/crime/article/police-make-30-arr...
[5] https://www.politico.eu/article/investigation-ties-romanian-...
But is there any reason to believe that judged were pressured/compelled by political powers to make these decisions? Apart from, of course, the law created by these politicians, which is how the system is intended to work.
No, but I have every reason to believe that the judges who made these decisions were people selected by political powers so that they would make them.
>Apart from, of course, the law created by these politicians, which is how the system is intended to work.
But the system isn't working for the people, it is horribly broken. The people running the system are mostly corrupt and/or incompetent, which is why so many voters from a wide variety of countries, and across the political spectrum, are willing to vote for anyone (even people who are clearly less than ideal) that shits all over the system and promises to smash it. Because the system is currently working exactly how it's intended to work, most people hate it and nobody feels like they can do anything about it.
All systems can be bent, broken, or subverted. Still, we need to make systems which do the best within the bounds of reality.
As a lifelong independent, I can tell you that this sort of thinking is incredibly prevalent and also incredibly wrong. Even a casual look at recent history proves this. How do you define "democracy"? Most of us define it as "the will of the people". Just recently, however, when "the will of the people" has not been the will of the ruling class, the "will of the people" has been decried as dangerous populism (nothing new but something that has re-emerged recently in the so-called Western World). It is our "institutions" they argue, that are actually democracy, and not the will of the foolish people who are ignorant and easily swayed.
>All systems can be bent, broken, or subverted.
Very true, and the history of our nation is proof of that, from the founding right up to the present day.
>Still, we need to make systems which do the best within the bounds of reality.
It would be nice, but that is a long way from how things are, or have ever been (so far).
I think it's a misreading to say the government should do whatever the whim of the most vocal, gerrymandered jurisdictions are. Instead, it is a supposed to be a republic with educated, ethical professionals doing the lawmaking within a very rigid structure designed to limit power severely in order to protect individual liberty.
For me, the amount of outright lying, propaganda, blatant corruption, and voter abuse makes a claim like "democracy is the will of the most people who agree" seem misguided at best (and maybe actively deceitful).
Re reading your comment, the straw man about "democracy is actually the institutions" makes me think I may have fallen for a troll so I'm just going to stop here.
You haven't, so be assured.
>I think it's a misreading to say the government should do whatever the whim of the most vocal, gerrymandered jurisdictions are.
It shouldn't, and I didn't argue that. My argument is that the people in charge have completely disregarded the will of the people en mass for a long time, and that the people are so outraged and desperate that at this point they are willing to vote for anyone who will upend the elite consensus that refuses to change.
>Instead, it is a supposed to be a republic with educated, ethical professionals doing the lawmaking within a very rigid structure designed to limit power severely in order to protect individual liberty.
How is that working out for us? Snowden's revelations were in 2013. An infinite number of blatantly illegal and unconstitutional programs actively being carried out by various government agencies. Who was held to account? Nobody. What was changed? Nothing. Who was in power? The supposedly "good" team that respects democracy. Go watch the conformation hearing of Tulsi Gabbard from this year. Watch Democratic Senator after Democratic Senator denounce Snowden as a traitor and repeatedly demand that she denounce him as well, as a litmus test for whether or not she could be confirmed as DNI (this is not a comment on Gabbard one way or another). My original comment disputed the contention that one party was for democracy and the other party was against it. Go watch that video and tell me that the Democrats support liberty, freedom, democracy and a transparent government. I don't support either of the parties, and this is one of the many reasons why.
I can see that factoring in in a decision to penalise an US company when it breaks EU law, US court order or not.
GDPR is about personally identifiable humans. I'm not sure how critical that information really is to these models, though given the difficulty of deleting it from a trained model when found, yes I agree it poses a huge practical problem.
That's because they are obviously trained on copyrighted content but nobody wants to admit it openly because that opens them to even more legal trouble. Meanwhile China has no problem violating copyright or IP so they will gladly gobble up whatever they can.
I don't think you can really compete in this space with the EU mindset, US is playing it smart and leaving this to play out before regulating. This is why EU is not the place for these kinds of innovations, the bureaucrats and the people aren't willing to tolerate disruption.
a) highly qualified people, even European natives move to Silicon Valley. There is a famous photo of the OpenAI core team with 6 Polish engineers and only 5 American ones;
b) culture of calculated risk when it comes to investment. Here, bankruptcy is an albatross around your neck, both legally and culturally, and is considered a sign of you being fundamentally inept instead of maybe just a misalignment with the market or even bad luck. You'd better succeed on your first try, or your options for funding will evaporate.
On risk, we're hardly the Valley, but a failed startup isn't a black mark at all. It's a big plus in most tech circles.
But in many continental countries, bankruptcy is a serious legal stigma. You will end up on public "insolvency lists" for years, which means that no bank will touch you with a 5 m pole and few people will even be willing to rent you or your new startup office space. You may even struggle to get banal contracts such as "five SIMs with data" from mobile phone operators.
There seems to be an underlying assumption that people who go bankrupt are either fatally inept or fraudsters, and need to be kept apart from the "healthy" economy in order not to endanger it.
> there is a legal obligation to keep that data;
https://commission.europa.eu/law/law-topic/data-protection/r...
This at best is force majeure that prohibits OpenAI with satisfying its contractual obligations that are there to comply with EU law. But contractual obligations are not the only control organizations have to ensure compliance with EU law, so this is not a defense.
> 1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay...
> 3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
> e. for the establishment, exercise or defence of legal claims.
https://gdpr-info.eu/art-17-gdpr/
The law makes no reference to the idea that the legal claims must be under a member state or EU law.
> Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
> ...
> for the establishment, exercise or defence of legal claims.
‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
We need many strong AI players. This would be a great way to ensure Europe can grow its own.
The reason this doesn't happen is because of Europe's internal issues, not because of foreign competition.
It's hard/pointless to motivate engineers to use other options and their significance doesn't grow since Engineers won't blog that much about them to show their expertise, etc. Certification and experience with a provider with 10%-80% market share is a future employment reason to put up with a lot of trash, and the amount of help to work around that trash that has made it into places like ChatGPT is mindboggling.
At least in sensitive contexts (healthcare etc.) I could imagine this resulting in further restrictions, assuming the order is upheld even for European user's data.
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
A US company can always stop serving EU customers if it doesn't want to comply with EU laws, but for most the market is too big to ignore.
There is no supreme law at that level; the two nations have to hash it out between them.
Making separate manufacturing lines for Europe vs US is too expensive, so in effect, Europe forced a US company to be less shitty globally.
The accurate comparison here isn’t between random low-budget USB-C implementations and Lightning on iPhones, but between USB-C and Lightning both on iPhones, and as far as I can tell, it’s holding up nicely.
I despise USB-C with all my heart. Amount of cable trash has tripled over the years.
I find it superior to both lightning and USB-C.
Given the sheer number of devices we interact with in a single day, USB-C as a standard is worth the trade off for an increase in our threat surface area.
1000 Attackers can carry around N extra charging wires anyway.
10^7 users having to keep say, 3 extra charging wires on average? That’s a huge increase in costs and resources.
(Numbers made up)
1) Surely the world conquering robo-army could get some adapters.
2) To the extend to which this makes anything more difficult, it is just that it makes everything a tiny bit less convenient. This includes the world-conquering robo-army, but also everything else we do. It is a general argument against capacity, which can’t be right, right?
That's not everyone wins. The people that actually bought these devices now have cables that don't work and need to replace with a lower quality product, and the people who were already using something else are continuing to not need cables for these devices. The majority breaks even, a significant minority loses.
Simply not choosing one cable to rule them all lets everyone win. There is no compelling reason for one size to fit all.
If some people like hip hop but more people like country, it's not a win for everybody to eliminate the hip hop radio stations so we can all listen to a single country station.
Further, rail gauge is not a consumer choice. If there were two rail gauges and your local rail station happened to have a different gauge than your destination, you'd be SOL. A different rail gauge may provide benefits for people with specific needs, but you don't get to take advantage of those benefits except by blind luck.
There is no such benefit from standardizing cable connectors. If someone charges their phone with the same style cable as you, you gain nothing. If someone uses a different cable, you lose nothing. There is no reason for anyone not to use their preferred cable which is optimal for their use case.
I'm sure there are more than a few people that would end up throwing out their perfectly functional accessories, only for the convenience of carrying less cables.
I don't want to ship another cable across the Pacific Ocean from China so I can have a cable that works on my devices.
I want to keep using them until they don't work and I can't repair them any more.
That is great you spent the money for this, but I'm not ready to throw away my perfectly fine devices.
On a specsheet basis it also charges faster and has a higher data transmission rate.
Lightning cables are not more robust. They are known to commonly short across the power pins, often turning the cable into an only-works-on-one-side defect. I replaced at least one cable every year due to this.
And... yeah, it turned out better than the standard. Their engineers have really good taste.
Instead Apple chose to make a good improvement on USB-C proprietary, and thus it will die like 8-track, betamax, and minidiscs.
Vendor lock-in is so big of a negative that everyone will pick whatever the least-bad open alternative is.
There's also an obvious compromise here – modify the US court ruling to exclude data of non-US users. Let's hope that cool heads prevail.