Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.

    Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect

  • except the package law as it stands is going to force many small businesses to close because they can't afford the cost.
  • > She had to go to Berlin data authority periodically and report status.

    That seems more of a German bureaucracy thing rather than GDPR specifically.

    The UK, which does still implement GDPR from its time as a member state, does not require this level of officiousness.

  • That's not true. The Data Protection Officer doesn't need to be a dedicated person, an employee can simply be given that role in addition to their regular roles. There are rules to prevent a conflict of interest. But I don't think many small corporations have a dedicated DPO.
  • "The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the surveillance apparatus humming behind the "OK.""

    Create a problem, the "dark pattern", and then offer a "solution"

    The source for the "solution" is also the source of the original problem

    This is one of the various tactics in the SillyCon Valley playbook

    Use the "solution" or else suffer the problem

    Consent immediately or suffer the cookie banner

    Lowbrow, mafia-style persuasion but with cowardly annoyance in place of direct confrontation

    I never see any cookie banners when there is no Javascript interpreter. No cookies get through the local forward proxy anyway. But that's not SillyCon Valley's "solution" to the annoyance, it's mine

  • I don't quite understand GDPR though as it theoretically let's me remove my personal data from benign websites, but doesn't let me remove my data where I would really want it removed, e.g. (my personal nemesis) SCHUFA, CRIF, Boniversum - which are all private companies.

    SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.

  • While you might hate them, you don’t want your data to be removed from their systems. If you’re having a hard time accessing credit with them, imagine what happens when you try to access credit as a ghost.
  • Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...

    > If the rules are so terrible, why did nobody choose market exit?

    Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.

    The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.

    EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.

  • >The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started

    essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.

  • I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.

    That said I am generally happy with GDPR.

  • It might have sounded clever but if you aren't concluding GDPR is good/bad based on what it is you are not reasonable.
  • Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
  • Everyone understands this, it doesn't matter.
  • I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.

    The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.

  • The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
  • Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?

    https://european-union.europa.eu/

  • Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.

    The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.

    Shame on the people making stuff like this.

  • As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.

    Was it a PITA? Sometimes, yes.

    Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.

    But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.

  • Well, it's the cost of collecting data. A lot of businesses don't really need to collect data. It's only the cost of doing business if you are in the personal data business.

    For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.

  • there is a whole campaign online about hating on the EU & its regulations.
  • Maybe it’s all a misinformation campaign… or maybe even people who live in, recognise and benefit from the good sides of the European experience, can also legitimately criticise bad aspects? It’s not binary - there are shades of grey.
    by mft_
  • I mean this isn't some hidden agenda. The Heritage Foundation has an active plan to dismantle the EU from within.
  • There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
  • Are you sure about it?

    In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.

    https://www.facebook.com/ads/library/report/?source=onboardi...

    Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious

  • I made a physical product and upon learning European regulations, I quickly decided I was going to spend 0 time designing it for Europe.

    If I made millions, sure, pay someone to figure it out.

    But I was not going to waste design time early on.

    I can't imagine how much this affects small business in Europe.

  • I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself.

    I very much support their ideals and their people-centered mindset.

    But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.

  • Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
  • People are hating it untill goes abroad to the countries where no such regulations exists.

    Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship.

    Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned.

    Or mandatory USB-C charge socket. God bless EU regulations!

  • Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
  • Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.