Smart rule making includes reducing the regulatory burden when it overreaches. The weight of regulation around tech in the EU is creating an environment such that the only companies that can operate in a space are the ones who can afford massive compliance overhead. That leaves you with the very same big tech firms that people are writing these rules to protect themselves from in the first place.
1. Without their consent,
2. Without their knowledge and,
3. Cannot be taken back or denied in a simple way.
There is a problem space here, in which there is zero solution. There is absolutely nothing, _NOTHING_, consumers can do if they want to protect their privacy. And before I hear 'well just don't use...' no - uh uh, that doesn't count. That's not a solution.
So, we need some kind of regulation. And, to be clear, it doesn't need to make violating privacy illegal. It doesn't, and the GPDR doesn't either. It just needs to make it possible for consumers to choose.
A free market is built on consumer choice, that is the core of a free market. It might seem counterintuitive, but regulation that protect consumer choice actually bolster the free market, not impede it.
The "reason" the EU is "struggling" isn't because only big dogs can compete. It's because US companies, which need not follow the rules, exist, and will slurp up the competition.
It's hard to compete with Google because they are cheaters. It's hard to compete with Meta because they are cheaters. They make literally hundreds of billions of dollars off of dark patterns, lies, stealing data, and privacy violations. If you even try to be honest, not even be good, just be honest, you will lose. Because they are not honest.
That's also true for tax laws, labor laws, environment laws, almost every safety code out there, building zoning...
I understand that there's nuance when dealing with all the edge cases to regulations. But it seems that the answer should not be extending the regulations to insane lengths to try to cover everything. That way lies insanity.
But uncertainty in compliance and time spent navigating compliance is nearly pure waste.
The folksy aphorism goes, The more wild cards and crazy rules, the greater the expert's advantage.
Complexity is clearly hired by lobbyists all the time, but uncertainty and ambiguity seem to me to be mostly caused by incompetence. It's not even clear if uncertainty benefits incumbents more; it can just as likely destroy a market or benefit new entrants, and you can't predict which will happen at the time you create it (otherwise it's not uncertain).
Legislative houses need technocratic QA. And that QA needs to be independent from the law-writing process.
Apple App Store review is a nightmare but still better than these regulations. They say yes or no clearly.
These EU regulations are more like: if you fuck up, you wouldn't know until the sentence might be really really high.
The reason is that in the EU fines are usually wrist slaps, compared to the size of the company, not threatening existence. We see this with big tech, who consider violating the law cost of business.
I understand why the rules are vague to an extent, simply because it is hard to impossible to cover every aspect of data collection.
But the GDPR is super vague on some very technical datapoints as well. Is an IP Address PII? Is there a difference between an IPv4 or an IPv6 address being PII? What constitutes as legitimate interest specifically? Can I use data for legitimate interests also for different first party purposes?
I‘ve spent more time than I care to admit navigating the compliance landscape of the GDPR and every time I consulted with compliance experts, I got different - partially conflicting - answers.
You say IP addresses are PII and this has long been determined.
Literally a week ago I read this reply on HN to someone mentioning IP addresses being PII:
> > logging an IP address.... > Untrue. IP is an category of PII but its not PII in itself unless you're a law enforcement. > Separately, if you log IP addresses you're doing it to prevent abuse and to provide security to your server, you're already permitted to do so. > More on that: https://missinfogeek.net/gdpr-consent/
So it seems like it’s not so determined, and this kind of uncertainty is exactly what makes compliance expensive.
Yeah and that is the challenge specifically. They are PII until they're not (or rather, they are not treated as PII until they are)
I obviously need them to provide my service. And I am fine if I store them for logging purposes and other legitimate interests for a reasonable amount of time. But what if I use a third party service for log aggregation? What if I am providing the service, but on the basis of an IaaS or PaaS service by one of the hyperscalers? What about the data I can derive from an IP address, such as an approximate location?
In Germany, we had lawyers sending out cease and desists just for Google Fonts being embedded on a website, nothing else.
Is there a difference between IP4 and IP6 addresses? Cause behind a cg NAT, I can barely identify anyone on the basis of an IPv4 address alone. With an IPv6 address on the other hand.
There are many ways you can spin that question. Some are more, others are less reasonable questions to ask. But the point is, that even for something as fundamental as an IP address, there is a lot of compliance uncertainty around it.
Then you probably need Datenverarbeitungsauftraege with that third-party company, which define precise purpose of processing the data. Data collection and processing is purpose bound in Germany. The purpose needs to be stated and one is then bound to not use them for different purposes, unless one has consent by the people the data is about/from.
(not a lawyer, but this is my understanding)
> In Germany, we had lawyers sending out cease and desists just for Google Fonts being embedded on a website, nothing else.
This is good and as it should be. Google Fonts are not needed in almost all cases. They are merely a visual thing. The functionality of a website must not depend on loading Google fonts. To use them a website has to ask for consent from the user first. This can be done in a consent asking popup/dialog/whatever. If that is too cumbersome, then just don't use Google fonts. As a company host web fonts yourself, or don't use them.
> Is there a difference between IP4 and IP6 addresses? Cause behind a cg NAT, I can barely identify anyone on the basis of an IPv4 address alone. With an IPv6 address on the other hand.
That I cannot answer, or have not thought about in sufficient depth.
> There are many ways you can spin that question. Some are more, others are less reasonable questions to ask. But the point is, that even for something as fundamental as an IP address, there is a lot of compliance uncertainty around it.
Yes, there can be uncertainty, but in most cases the uncertainty is due to businesses doing things that require consent in the first place, while they don't actually have to do these things. There can of course be special cases, no question there, but then the special case is somehow integral to the business and then it should be worth it for the company to get a law person involved to clear up any uncertainties.
So it's not everyone, is it even most people? I'm not sure.
I do feel for you if you happen to live in the EU, but you get what you vote for. I don't live there, none of my businesses operate there, so I'm free to ignore it. The GDPR ends where the EU does, and cross-border enforcement of laws requires a bilateral agreement, that I would have to vote for.
I think there are many people who are fine with targeted advertising and also fine leading a private life in non-GDPR jurisdictions. I think that covers most people in the world.
Given the amount of ad-revenue services I get access to, it's a very good tradeoff for me, please don't kill it, and if you do kill it, stick to your own jurisdiction please.
There are workarounds like exemptions for small businesses, but this creates all kinds of new issues like a regulatory ceiling, which results in enormous new costs on some arbitrary day for a business once it crosses some kind of user or revenue threshold. Ramp-ups are difficult or impossible to legislate in this context. Further, two or multi-tiered regulatory systems are highly inefficient and arguably unfair. They're very difficult for everyone to navigate. Generally speaking, from countless examples around the world, rules should apply to everyone.
Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.
Yeah, forcing companies to write food ingredients on the package is bad for business. And I don't care about business more than about the well-being of society and myself. Same with tracking.
> Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.
Politicians, who usually aren’t experts in the field.
Industry leaders, who have every incentive to make the rules tougher for everyone.
Small businesses in particular do not have staff or the capacity to to deal with a large amount of compliance overhead. The biggest help for small businesses (and large businesses alike) would probably be if the GDPR would be less vague on the rules surrounding typically collected data
Ignoring that, the other problem is enforcement. Is it not unrealistic to have a law that says “if you have a data breach you are subject to a penalty?” And “if you fail to report that breach the penalty can go as far as corporate death or executive incarceration?”
Or even more simply - replace the wrist-slapping fines with criminal charges and imprisonment.
While everyone talks about souvereign data processing in the EU, both the commission as well as the governments of its member states completely failed in pampering a domestic cloud industry during the last 15 years. Mercy killing.
But it's really hard to tinker as a single hacker when a German legal troll firm can come for you for linking Google fonts on your web page (i.e. transferring IPs so breaching privacy)
But that's only a small part of a huge legal frame, and as I said I don't know much about these problematics.
You can still turn cookies off in your user agent though.
That was the missed opportunity. Had the EU stepped in and said "I'm sorry, the user expressed explicit intent to not be tracked and you're planning to ignore that? How about that's a fine?" it would have survived.
But they weren't prepped to take action yet.
The only reason why the advertisers were so unhappy about it is because what they do is neither good nor sensible by most people's standards.
If I (a complete stranger to you) walk up to you and kiss you on the lips, it doesn't make a difference whether you're wearing a t-shirt informing everyone you don't want strangers to kiss you on the lips or not - I don't have any basis on which I can presume to have obtained your consent so I'd still be violating your rights.
This is very much a "tech bros don't understand consent" case: if you do something without consent, you better have a damn good reason other than "but it's good for meeee" (or "good for my bottom line"). "My business model depends on it" also isn't a good justification - there are plenty of business models that depend on things that are unquestionably illegal, we just refer to them as "criminal enterprises" rather than "disruptive startups".
Actually it's worse, DNT headers are like posting a wall of text on facebook saying you do not consent to them using your images or posts for some purpose.
Track doesn't have a consistent definition across contexts, to regulate this you would have to fix it to something - what are your suggestions? DNT and the "deny optional" that foamed its way out of the GDPR aren't quite the same thing, and even if they are, it will take many court cases and years of time to figure that out.
If you have a better write on regulation lets hear it.
What most people miss about the GDPR is that most of it (as well as the ePrivacy Directive covering more technical aspects like cookies) really only exists because of the one big thing at its core most people are either not aware of or intentionally omitting:
The GDPR establishes a user's right to ownership and control of their personally identifiable information as an inalienable and irrevocable fundamental human right. This is what makes all the rest of it necessary: it's not about "cookie banners", it's about requiring others to obtain consent for what they want to do with that information; it's not about writing "privacy policies", it's about explaining what you do with that information and how you guarantee their rights are respected by you and disclosing who you're passing it on to and how you're ensuring they too respect those rights.
The alternative to consent dialogs (whether as "pop-ups" or via confirmations when prompting for relevant information) would be requiring every website to have a written contract with each user. Consent is only valid if it is demonstrably informed (and non-coerced but that's a different story) and it must be specific and revocable. You can't have users blanket opt-in to everything you'd like - they wouldn't even know what consent they'd need to withdraw later if they reconsider.
By the way, courts recently seem to have started ruling that the way many AIs work the companies training them are in violation of copyright laws by using intellectual property as training data without permission and in order for contracts to be legally binding, anything given by one party has to be given consideration by the other (i.e. anything of value given by one party has to be balanced out with something of value given by the other party) - so I wouldn't be too quick to ridicule the idea that using Facebook means Facebook can do with your data whatever its terms of service say they can do, even if posting on Facebook can probably not be considered an effective way of informing Meta about your disagreement.
The only thing required to make a signal like that legally binding is the power of law. It just wasn't there for DNT.
Or it will take one clear message from the regulators saying they're equivalent.
I've been through several startups after GDPR went into effect, it's really not a problem.
It's the same thing as any other regulation -- regulatory burden. Laws aren't code, they need interpretation. That means you need your own lawyer to tell you an interpretation that they feel they can defend in front of a judge.
There is a cost to that. In both time and money. I am the CEO of a startup who is subject to GDPR. The amount of time and money we've spent just making sure we are in compliance is quite high, and we barely operate in Europe and don't collect PII.
You can wing it and say "this looks easy, I can do this on my own!" and maybe you can. For a while. But no serious business is going to try to DIY any regulations.
So either you're lying or your lawyers are lying to you.
In 9 years you could've finally read and understood the rather small law yourself.
For the absolute vast majority of companies GDPR compliance is trivial.
For the absolute vast majority of remaining companies GDPR compliance is simple.
There are a few companies which may have to double-check their legal obligations and legitimate interests (e.g. by law banks must retain data for much longer than GDPR assumes).
I highly doubt that your startup which builds orchestration workflows requires 23 marketing cookies to "display relevant ads across sites" or "7 unclassified cookies" etc. especially since you claim you don't collect much information except the absolutely necessary: https://www.dbos.dev/privacy
No wonder you have "trouble complying with GDPR".
It's not a lawyer's job to answer that question because the answer is necessarily "yes" unless you intentionally did the illegal thing (i.e. intentionally did what the law explicitly tells you not to do) - and even then you might be able to defend it somehow.
The question is whether you have a good enough case for a ruling in your favor. And again, lawyers can't answer that because the question is always "it depends" - they're not in the business of fortune telling.
If you ask a lawyer for legal advice, it's their job to give you sufficiently good and accurate enough advice that if you tried to sue them over giving you bad or inaccurate advice they'd have a good enough chance of winning that lawsuit. How much they're willing to speculate about things like what's good enough for you and how high they'll set the bar depends on a variety of factors again.
There's literally no guarantee you can successfully defend something in front of a judge. The law is the law and the facts are the facts. If you end up in court, it helps if you have solid paperwork and a solid papertrail you can use to demonstrate you did everything correctly and in good faith - this is about creating facts that can be used to your advantage.
But the amount of expense required to do literally everything perfectly to the letter of the law and reliably document that you did so would make running a profitable operation impossible regardless of what laws we're talking about, so you necessarily have to strike a balance. And where you strike that balance is a business decision because it's about managing the risk of doing business. And that's not something your lawyer can decide for you - that's something you have to decide for yourself if you run the business. Because at the end of the day it's about your personal liability - whether through financial risk if your business is held liable or direct liability if you get personally held liable for your actions.
But this is not legal advice, I'm not a lawyer. I just know enough about (EU privacy and general German) law to be dangerous and accidentally trick actual lawyers into thinking I have a law degree.
By the way, that's also where that line comes from: it's saying "you can't hold me liable for decisions you make based on what I told you" - even when what a lawyer says is perfectly reasonable and sound to them they'll likely tell you it's "not legal advice" unless you are willing to pay the price tag of being able to hold them liable for what they said.
Yes, it forced these small businesses to think about how they're handling personal data, but that should be the fucking point, I don't care if a company is Facebook or if it's a 2 person startup, neither should be collecting and redistributing personal data and tracking people.
I'm hoping to go for my 3rd startup and ‘compliance costs’ have never been stifling; it's just more expensive to run a business here and there's far, far less funding available. That's really it.
Belgium's tax haven will make some people willing to give you 10k in post-seed. Wow. We hunted VCs for 1.5 years to negotiate one million-ish euros after showing market traction. We just aren't on the same level as the US, and that's kinda okay. Grants might work, but I mostly see grants for things that won't compete well in the current market.
AI nonsense won't make us more competitive — but hey, we'll arrive late to the bubble. We need to be building the kind of core, dependable infrastructure that would honour privacy, make us more independent. Backing off on privacy protections won't yield a mobile OS, an independent browser, better cloud options, etc.
It's just… lazy. “Slap AI on it”-level policy. Ugh.
Politicians don't need to know the details but should know understand the wider, larger brushstrokes of the painting. That would be worlds easier if tech people listened to Bruce Schneier and started getting into policy.
Someone who's had a career in tech can probably tell good from bad advice when it comes to the best interests of the public in mind. And perhaps they'd be less corruptible by the best interests of the wealthy.
Compliance costs almost nothing. If you collect data, explain why and what for. If people ask you to delete it, do that. If you want to share data with others, ask first (or just, you know, don't).
Not just small business, but even non-profits that just keep a list of people involved with them are subject to the same rules, even if they only use the information internally and do not buy or sell any personal information.
Its not just cookies and websites, its any personal information stored electronically.
I am saying that the same regulations are both too easy for big business to evade (or ignore and treat fines as a cost of doing business) AND too burdensome on small organisations that do not trade information. Something as simple as a membership list can draw you in.
Every time GDPR is brought up on HN, the same "it's super simple to comply, just read it yourself!" religious incantation gets repeated ad-nauseam.
I think it's because people love the idea of what they think GDPR actually represents (the fuzzy abstract idea of "privacy"), without ever diving into any of the implementation details.
Almost nobody on this forum has ever talked to a lawyer about this, and even less people have followed the actual court rulings that have determined what GDPR actually means in practice.
My favorite example, under GDPR over the last 5 years, regardless of whether you follow the spirit of GDPR to the letter...due to the various schrems rulings, back-and-forth on SCCs, data-transfers, and EU-US political spats...there's been multi-year periods where if you're using any service touching data in any part of your business even remotely connected to the US or any non-EU country (so, almost everything), it's been a violation that exposed you to massive fines should any EU resident have filed a complaint against you. This was recently resolved again, but will continue to go back and forth if GDPR remains as-is.
And this is just one of many weird situations the law has created for anyone running a business more complex than "a personal blog."
There are a lot of good ideas in the GDPR, but once you start looking into implementation it gets a lot more complex.
Its not just business. A community organisation (like my local amateur theatre, or a sports club, or a parish church etc.) is subject to pretty complex rules. Often things run by volunteers that keep very little data. Here is the guidance for UK GDPR (which is still pretty much identical to the EU version) compliance for small organisations:
https://ico.org.uk/for-organisations/advice-for-small-organi...
Read it all, and tell me its simple for an organisation with a limited budget, or for someone without either a technical or legal background to understand.
I've implemented it like a half-dozen times. Why do you think I'm so confident? It's truly not very difficult, particularly if you don't have to retrofit some hell-app that uses a billion cookies. For the most part, collecting PII is already a liability and you don't want to do this anyway outside of critical information (e.g., email).
So - in order for you to build that train - you'd need to wait for industries to set up to build every single component up to local standards. And if nobody sets these industries up to manufacture the components you need, you'll have to build it yourself, somehow.
You'd rightfully call this out as protectionism. And the worst part is not even the protectionism - the worst part is that you'll likely get no trains, because in practice nobody except a huge incumbent company can build all the components they need themselves, and huge incumbent companies often have no incentive or no agility to do so.
Yes, it should remain as is and enforced. Yes, storing your users' data in the US is extremely problematic because the US really couldn't give two shits about privacy, or user data.
Given how much Russian political influence tanked after the economic ties were forcibly severed (or at least had to become more discreet and indirect as in the case of Russian gas imports - though those will allegedly further decrease in the near future) it seems reasonable to assume that a lot of these weirdly pro-US anti-EU stances held by European politicians are linked to the economic ties to the US. But of course I'd never dare to accuse any EU politicians of taking bribes - us Westerners have far more sophisticated methods of giving politicians money to do what benefits us than the profane bribery of Russian cops being handed money to look the other way.
However, this generation is beginning to learn the lesson every generation learns: one has to deal with the world as it is, not as one wishes it were. Scarcity exists.
Unfortunately, in globalized economic reality, you will have to transfer data to other countries to conduct business.
Unfortunately, in fossil fuel driven reality, you can't just go off fossil fuels by switching to paper straws, you have to actually build viable alternatives first.
Unfortunately, in non-world-peace reality, you can't just stop having a military and become pacifist. Turns out you still need missiles and tanks.
Unfortunately, in low-birth and low-economic-growth reality, you cannot let people retire at 62 and draw inflation-pegged pensions until death.
Unfortunately, in non-0 interest rate reality, governments can't keep deficit spending to prop up a broken socialist economic model.
Etc. Etc.
"This generation" lol. I'm 45.
What I'm learning that this generation will find way to justify any and all activity by any and all industries using any number of logical leaps and non-sequiturs, and will fight any way to make the world even a slightly better place because "low-birth and non-0 interest rate" or something. Or that 15000 invasive trackers have to keep my precise geolocation data for 12 years because "scarcity".
> Unfortunately, in non-0 interest rate reality, governments can't keep deficit spending to prop up a broken socialist economic model.
Governments have deficit spending because we subsidize private inefficiency at a social level and refuse to run them efficiently. It's insisting on letting private entities run things that is clearly not working.
What services are you talking about? AWS? Microsoft? Some small startup? Gmail? What data? etc.
The fundamental issue is the EU doesn't like that US intelligence agencies have the ability to subpoena any server associated with US firms or companies that use US firms. However, the vast majority of the entire tech industry touches the US in some way.
Here's a good primer: https://trustarc.com/resource/schrems-ii-decision-changed-pr...
Last year the EU and the Biden administration came to an agreement (the second of these after the last was shot down). The current one may not stand either.
If it doesn't, and you're an EU company who has an employee using something as trivial as Notion, you're already in violation (even if Notion is otherwise GDPR compliant, the US gov can subpoena them and look at their data, meaning they can be declared defacto non-compliant).
This is further complicated by the fact that, as it turns out, having access to US intelligence isn't so bad in the context of Russia-Ukraine.
But sorry, saying "literally everything" is a gross exaggeration. Debugging a program with the help of ChatGPT is not using user data. Editing a logo is not using user data. Storing code on a web platform is not using user data. And others...
And even then, for some of the services (like mail, communication, erp, etc.) there are alternatives companies in Europe that work just fine.
I think GDPR is not perfect, but I do welcome measures to prevent over-collection of data by whomever.
There are only two possible interpretations of this sentence:
1. You have just confessed to a crime. Do your engineers store user data in Notion?
2. You have just confessed to not having even a single clue about GDPR and what it entails. Your engineers using Notion will not make your company liable for GDPR unless bullet point 1.
> This is further complicated by the fact that, as it turns out, having access to US intelligence isn't so bad in the context of Russia-Ukraine.
Ah yes. Your shitty company selling user data left and right to "our privacy-preserving partners" is the same as "access to US intelligence in the context of Russia-Ukraine"
No, I am not selling user data, nor is the vast vast majority of companies affected by GDPR. Please do not assume bad faith as it ends useful discussion (and is against HN guidelines).
So you believe GDPR and the ePrivacy directive (which people here unknowingly conflate) are the most perfect words ever put on paper and there is nothing that could be improved?
You think yourself more important than you really are. I've replied to many comments in this discussion, and three of them, I think, happened to be yours. Two of them happened in the same thread. This one.
> No, I am not selling user data, nor is the vast vast majority of companies affected by GDPR. Please do not assume bad faith as it ends useful discussion
Ah yes. Where good faith is "GDPR is bad because wellfare state and US intelligence"?
> So you believe GDPR and the ePrivacy directive (which people here unknowingly conflate) are the most perfect words ever put on paper and there is nothing that could be improved?
So, good faith and non-circular arguments are assigning words to opponents and trying to make them argue something they never said, apparently.
Imagine if anti-GDPR crowd actually argued in good faith. I can't. Because of behaviour like this.
How the hell do you expect everyone else to?
Different rules for different people huh?
Just because you like the group you're benefiting and dislike the group you're harming doesn't mean that is good policy.
You would be subject to one rule for your small company and another rule as it grows.
This is everywhere in society, from expectation difference between babies, kids, teenagers, adults and seniors and to tax bracket structures.
A baby doesn’t catch a sex pest charge for running around naked, but it also can’t get a gun license. A mom-n-pop doesn’t have to hire an auditor and file with the SEC, but it also can’t sell shares of itself to the public.
Why? The bigger you are, the more responsibility you bear: the bigger the impact of your mistakes, the subtler the complexities of your operation, the greater your sophistication relative to individual customers/citizens—and the greater your relative capacity to self-regulate.
In the traditionally implied sense of different rules for different social classes.
For instance, poor people should not have any tax breaks: everyone should pay exactly the same percentage of their income, like 15% all across the board or whatever.
Such ideas often have regressive effects.
However, I get it. When it comes to handling personal information, you simply can't say that the "little guys" don't have to follow all the rules, and can cheerfully mishandle personal information in some way.
Small operators have simpler structures and information systems; it should be easier for them to comply and show compliance, you would think (and maybe some of the requirements in the area can be simplified rather than rules waived.)
I wish you were right though.
But in this analogy, we aren’t talking about a person doing coding at home only for their own use, are we? Isn’t this about small companies - I.e. whether there should be different applicable laws if you hire a small construction company vs a large one to rewire your kitchen, etc?
https://www.independent.co.uk/news/world/americas/asa-baker-...
But you would actually prefer to be subject to the same rules as the state? I.e. typically nothing which isn't explicitly allowed is forbidden for you to do, you are forced to hand out copies of documents you produce, and so on?
That’s how efficient market works. The bigger are the players, the higher are the chances they will distort the market. You need to apply the force proportional to size to return market back to equilibrium at maximum performance. We have anti-trust laws for this reason, so nothing new, nothing special.
I like folks who have to work for a living and dislike billionaires relaxing on yachts bought on their generational wealth, but in addition sociology metrics of the United States in the past 100 years suggest that the highest levels of happiness correlated pretty heavily with marginal tax rates as high as 100% based on wealth.
Compliance has fixed costs. And smaller operations have a smaller blast radius when things go wrong. Reducing requirements for smaller operators makes sense.
The content of the comment is my unique opinion and my unique writing and I mostly also make sure to remove stupid things like directional quotation marks.
But yes, it is possible to be very much human but also trigger certain peoples AI detectors.