10 ms·
In my network of friends, which is within the EU and comprised entirely of EU citizens and spans multiple EU tech companies from dinky startups to Giant Unicorn
by mrmekon 8y ago
In my network of friends, which is within the EU and comprised entirely of EU citizens and spans multiple EU tech companies from dinky startups to Giant Unicorn, GDPR has been almost universally approved. We had to implement it, and generally feel better for having done so. The Giant Unicorn employees were dismayed by how little time they were given for such a giant task, but were in support of the law.
Everybody is completely and 100% against the copyright law.
There is a huge difference between the two from my point of view:
GDPR is not a law about "The Internet", it is a law about company records. It applies to Google, but it also applies to the Pakistani food stand on the corner. It affects Google a lot more, sure. I support the concept that a company does not have some inherent right to be a steward of my personal data without my explicit consent. GDPR is also easy enough for even tiny startups to comply with, and is significantly easier for small companies than large ones. It does not create a large barrier to entry for new startups or a rift between the existing small and large companies.
The copyright law, however, is a law about The Internet. It controls how businesses interact with the internet. It sets _technical_ restrictions on how they can do so. It sets technical restrictions that are probably not even feasible, at that. It absolutely does create a huge barrier to entry for small companies, and could possibly enshrine the existing tech giants into de-facto monopolies (I mean, if they aren't already...)
The copyright directive is horrible enough on its own. I don't see why everyone is in a rush to pull in mentions of GDPR to make it seem "worse". For a lot of us, it weakens the argument instead of strengthening it. Not everyone likes GDPR, obviously, but we can _all_ agree that the copyright law is garbage.
- throwaway122378 8y agoCan you elaborate on the specifics of the copyright law?
- mrmekon 8y agoIt's all still up in the air, and the wording is vague. GDPR's wording is also vague, as EU laws are. When we read between the lines, GDPR's vagueness sounds promising (hard to over-reach, easy to understand intentions), and the Copyright Directive's vagueness sounds terrifying (easy to over-reach, hard to understand intentions). https://en.wikipedia.org/wiki/Directive_on_Copyright_in_the_Digital_Single_Market https://en.wikipedia.org/wiki/Directive_on_Copyright_in_the_... A big difference is in the boundaries. GDPR is bounded by your customer records. One customer, one collection of personal data. There's a hard upper limit: about 7 billion. Companies tend to scale with customers, so generally bigger companies will have bigger customer bases and bigger employee bases to handle protecting the records. The Copyright Directive's bounds is user content. One customer, any number of potential infringements. A single person can run a company with 100 customers who upload 10,000 images each per year. Managing the customer base is pretty easy, managing the data storage is pretty easy, GDPR-protecting 100 people's data is pretty easy. But 1 million potential copyright infringements per year, each one of which could even be claimed by multiple rights holders. Your risk exposure grows with data, not with people. That one-man show probably can't handle tens of thousands of take-down requests, nor build an AI Machine Learning Cloud Native Copyright ID Blockchain System to automate it.
- walterbell 8y agoThanks for the concise scope analysis. This should be a mandatory subsection on the first page of future Internet regulations.
- tomp 8y agoIt's even worse. Copyright Directive is technically bound by copyrighted content, which can grow indefinitely even without the company doing anything! E.g. imagine a company like Snap, say that they have a constant number of users and users post a constant number of snaps per day. Therefore the amount of content posted/stored on the site doesn't grow, but you still need to be able to keep scaling the system, as the amount of copyrighted content that you should be able to potentially recognize continues growing!
- malvosenior 8y ago> I don't see why everyone is in a rush to pull in mentions of GDPR to make it seem "worse". For a lot of us, it weakens the argument instead of strengthening it. I have the opposite feeling. A lot of us rejected to GDPR on the basis that it's not the government's domain (any government) to impose its will on the internet. Even if the content of GDPR is well meaning it opened the door to further laws, such as the new copyright law. By saying "GDPR is a good idea, but the EU has no right to police the internet" it saves us from further legislative efforts. By saying "GDPR is a good law but the copyright law is bad" it means we have to have this debate over and over and the message to law makers is a tacit green light to keep going down this path.
- davidhyde 8y agoI 100% agree with this. GDPR is a shining beacon of success and it blows my mind that it came from the same clowns that made the cookie law. They covered my internet with cookie banner graffiti and now they want to mess with something as fundamental as a hyperlink.
- emilfihlman 8y agoGDPR is absolutely not the shining beacon of success. Let's review at some glaring, obvious and 100%-lets-make-this-law-shite points: 1. Application and enforcement: GDPR is 100% arbitrarily enforced, it is a "trust us, we could do no harm, trust us" law, that is extremely well suited to adding other such "trust us" laws. 2. Absolutely ridiculous overreach: on a technical level, GDPR is braindead. It applies ridiculous, stupid and unnecessary restrictions for no purpose. 3. You just added an obligatory "lol accept this or GTFO" thing to all sites.
- joshuakarjala 8y ago3. No, you cannot serve any EU customers if there is not option to "opt out" of any unnecessary processing
- Nursie 8y agoIn theory, very true. I've noticed quite a few US sites, particularly some large news orgs, have been going the "accept this or leave" route, and some are going the "accept this or click on the entrance to our insane maze of links that will confuse you until you give up" They are non-compliant, guess we'll see what happens.
- notemaker 8y agoThe reality however, after GDPR was implemented, is 95% of the time GTFO or click accept.
- Jnr 8y agoWait till mid 2019 when EU countries will actually start enforcing it. Unofficially there is a change period so probably no one will really be touched by it in the first year.
- deltron3030 8y ago>GDPR is not a law about "The Internet", it is a law about company records. It applies to Google, but it also applies to the Pakistani food stand on the corner. It affects Google a lot more, sure. It's about full stack owners vs. people who depend on modules to operate, not size of the company. And controlling or maintaining consistentcy across all those modules might be difficult when it comes to GDPR. Just think about plugin pipelines that many small businesses build with Wordpress and similar, where every service that sits between your app and your database needs to be compliant if you want to comply with GDPR. The pakistani foodstand might be a full stack owner like Google, but in small, he controls his stack and can manually delete all records if neccessary. But if you use modules/services you can't really reach into the DB's of your module providers.
- charleslmunger 8y agoI am not a lawyer, but GDPR explicitly covers the plugin pipelines - they're "processors". The requirements for processors are basically that you can only use processors that are compliant with GDPR themselves. Any well designed regulation disallows skirting liability by subcontracting out functionality. Is that really unreasonable? It describes pretty clearly how to be a compliant processor, and it's basically saying that you have to have a contract with the "controller" that requires you to fulfill the same responsibilities that the controller would have under GDPR if they were doing the work in house. https://gdpr-info.eu/art-28-gdpr/ https://gdpr-info.eu/art-28-gdpr/
- deltron3030 8y ago> The requirements for processors are basically that you can only use processors that are compliant with GDPR themselves. How can you be sure that the compliance isn't just marketing? There is no official cert body or institution for GDPR afaik. Isn't it all trust based at this point? Actual certification would require a huge continous investment, where a outside body would constantly monitor and proof your code and its side effects. >Any well designed regulation disallows skirting liability by subcontracting out functionality. Is that really unreasonable? But what if this industry, especially the small business world is based on subcontracting out functionality? They're basically ignoring an existing ecosystem and methodologies that developed over a decade in that space. >It describes pretty clearly how to be a compliant processor, and it's basically saying that you have to have a contract with the "controller" that requires you to fulfill the same responsibilities that the controller would have under GDPR if they were doing the work in house. If its so clear, why isn't there an official cert body or institution? Afaik there is none. Compliance refers to the interpretations of the GDPR text, not real logical safety on an technology level, the laws aren't detailed enough for that. To cert or guarantee safety they'd have to monitor code repos and analyze side effects of the code on a constant basis. I think the correct way to handle data privacy is on an individual level, within the operating system and browser, making sure that your privacy settings are respected. A page that doesn't conform to your settings just wouldn't load, you get the internet you deserve. Everybody should also have the opportunity to learn the basics of using an internet connected device, similar to driver licenses. The individual level would be a much better fit, and potentially real solution and not just a castle in the sky. GDPR relies on trust, one little bug that results in a privacy issue and you can close up shop as business. It's a setting where those that employ cyber warfare to hack competitors and have those resources win. Politicians who brought you GDPR are the same ones that wage wars on drugs. Total morons.
- Tharkun 8y agoI disagree with the GDPR "success story" part of your comment. So far it's backfired entirely. The goal was to provide users with more control, and (from the standpoint of such a user) to reduce relentless personal data harvesting. That hasn't happened. What's happened is more annoying "we use cookies and track you"-banners all over the internet. As a user who doesn't use cookies, these damned things won't even go away and keep coming back. It hasn't given me more control. At all. If anything, it's made me more trackable on the internet (because now I'll have to use cookies to tell people I don't want their god damned cookies). Online newspapers are the worst. "Here's a front page you can read, and maybe the start of an article, if you want more, you have to give us permission to track you -- or you can just fuck off". What exactly has GDPR solved here? Nothing. Before this nonsense, I could simply tell my browser not to accept cookies from these sites, and I could tell my plugins to ignore their tracking stuff. But at least I could read the newspaper without any hassle. Now all I get is more annoying popups and less contents. Thanks, GDPR. Yes, I'm being snarky. Yes, I know the idea of the law is pretty solid. But no, I'm not at all happy with the outcome.
- pbhjpbhj 8y agoAIUI the "allow being tracked to gain access" is unlawful.
- Tharkun 8y agoApparently "allow being tracked to gain more access" somehow isn't. As far as I can tell that's what every major newspaper in Belgium is doing. I suspect they've got folks in their employ who speak legalese. But then newspapers in Belgium are pretty horrible in general. They're exempt from paying VAT, even for content they sell online. Online-only news sites don't get this exemption and have to charge 21% VAT, so the entrenched newspapers have something of an unfair advantage there. But anyway, that's a different rant entirely. Just an illustration of their general scumminess.
- Dormeno 8y agoThis paper says it is lawful. https://www.iabeurope.eu/wp-content/uploads/2017/11/20171128-Working_Paper03_Consent.pdf https://www.iabeurope.eu/wp-content/uploads/2017/11/20171128...
- Pica_soO 8y agoThe GDPR could have been even better- if it specified a standard for how much data - and rights a user would be able to offer to a website- thus allowing for automation- and even trade-offs per protection-level.