9 ms·
> individual “data rights” have led to unintended consequences; “privacy protection” seems to have undermined market competition; That opening paragraph alread
by Quanttek 7y ago
> individual “data rights” have led to unintended consequences; “privacy protection” seems to have undermined market competition;
That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies
Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (Amazon sending data to the wrong person, Spotify not asking for 2FA/email confirmation for the bulk download, companies deleting articles even when there would sufficient public interest, Ad vendors failing to ensure compliance and therefore seeing drops in demand, ...), that is, market failures - something this site would probably not call out but rather attribute it to the legislation.
- Camas 7y ago> that is, market failures - something this site would probably not call out but rather attribute it to the legislation. Socially shaming companies does very little compared to legislation, so that's completely understandable.
- Quanttek 7y agoIn general this might be agreeable. But in these cases these are not direct unintended consequences of the legislation but rather consequences of companies failing to do their due diligence when implementing GDPR. It would be like companies putting people in bomb disposal suits after sth like OSHA is implemented and complaining about the cost and lost productivity. Or to take the EU: Recently the CJEU ruled that all work time has to be tracked (not only overtime), and a German company (in Germany this wasn't mandated before) would force employees to install invasive phone apps that track location etc. and use to determine work time. Employees rightfully complaining should direct their anger at the company, not at a law that would work perfectly well with a standard punch card system
- nordsieck 7y ago> But in these cases these are not direct unintended consequences of the legislation but rather consequences of companies failing to do their due diligence when implementing GDPR. The complexity of additional law is part of its unintended consequences.
- icebraining 7y agoHow is sending the recordings of one user to another a result of law complexity? In any case, there's no increased complexity here; the Data Protection Directive (enacted in 1995) already mandated access to one's data (Article 12 - Right of access). The GDPR mostly gave some real teeth to that existing right.
- Zak 7y ago> That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com" I have not found the cultural climate on HN to be opposed to the GDPR at all. Both its goals and its implementation seem to be popular here overall, and most comments I see that are critical of it get enough downvotes to have their text significantly desaturated even if they're making a good argument. It's my impression, though I have not worked in the field that people operating ad networks believe some kind of tracking is necessary to prevent click fraud, and do not want to sell ads free of any tracking even when they have customers asking for the option. I don't know how true this claim is or whether alternatives have been adequately explored. What I do know is that some of the industries that use ads, such as newspapers are struggling to make enough money to continue operating. Nobody will miss a scummy adtech firm, but people might miss local news outlets. It's valid to talk about the impact on business not just in terms of profits, but also considering potential positive externalities of the continued operation of a given business.
- jdietrich 7y agoPurely anecdotal, but I've had many debates over the last year on HN with people who claim that GDPR is just protectionism - rather than being a sincere effort to improve human rights online, they argue that it's just a sour-grapes effort to cripple American tech companies.
- jeremyjh 7y agoUndoubtedly it passed due to support from many people with each motive.
- lukevdp 7y agoPretty funny argument given that the big US companies are benefiting the most from it according to the article. “The consequence was that just hours after the law’s enforcement, numerous independent ad exchanges and other vendors watched their ad demand volumes drop between 20 and 40 percent. But with agencies free to still buy demand on Google’s marketplace, demand on AdX spiked. The fact that Google’s compliance strategy has ended up hurting its competitors and redirecting higher demand back to its own marketplace, where it can guarantee it has user consent, has unsettled publishers and ad tech vendors.” (Digiday)
- hannasanarion 7y ago> Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (... companies deleting articles even when there would sufficient public interest,...) Some of those examples were deceptively reported. For example, the doctor who asked The Guardian to take down articles about her suspension: she had successfully appealed that case, and a judge overturned her suspension and ordered the record expunged: her name was dragged through the mud on bad information. This is exactly what right to be forgotten is meant for.
- tolmasky 7y agoIf the fundamental thesis is that "the market fails" or that "corporations are irresponsible", then at the very least it should be predictable that some of these regulations will have the real negative consequences (which I think we can agree some of these are) expressed in this article. The goal of this realization is not necessarily to disparage the GDPR, but hopefully to learn and perhaps put together a more precise or better iteration in place that avoids these pitfalls. For example: > Spotify not asking for 2FA/email confirmation for the bulk download I'm not extremely familiar with the letter of the law, but if it doesn't specify that you need 2FA/email, and there are clear fines/downsides to not complying, I do not see how this is not a predictable issue that would come up. The incentive is to comply, since you've already put in the work to make it possible, and there are onerous punishments for not doing so. In other words, a false negative (disallowing the download) can be potentially perceived as much worse than a false positive (allowing the download). This seems built-in: the goal of the law was to give it teeth to allow the user to get this data. If we just default to "its the companies fault for not applying an additional layer of thought to all this", then whether its true or not (and I agree it is!), it does not realistically solve the problem - establishing blame doesn't necessarily provide a path to making this less likely in the future as long as the equation is still heavily weighted towards disincentivizing false negatives. This is another way of saying: if we want to characterize corporations as lazy/malicious/what-have-you, then we can't then be Pikachu-surprised-face when they act that way under the letter of the law like some monkey's paw scenario: we should instead "aw shucks, fool me once" and try to come up with something better. > companies deleting articles even when there would sufficient public interest Similarly, we should try to predict that it is entirely plausible that the rights will be attempted to be abused, or leveraged, by those that it provides an obvious benefit for, even if it is malicious. Here again it is interesting that we begin with the thesis that "we need these laws because companies have proven not sufficiently responsible enough on their own" and yet then immediately make a law that is vague and thus defers major parts of the decision to these same companies. Many times this ultimately comes down to litigation where the boundaries of laws are worked out, and this is a very reasonable response: its only been a year, the courts will hopefully work out when these rules are mis-applied. However, it is on us to make sure we litigate "too much" right to forget (as in the cases here) and not just cases where companies refuse to forget. If not, the courts will send a clear message that it is perfectly fine to blindly abide by every request as the path of least resistance. Again: the premise is that they don't care, and we still haven't figured out how to legislate caring.
- blfr 7y agoMarket competition is usually in the opposite to profits. Market competition usually works against the competing companies and in favour of their customers.
- dev_dull 7y agoShhh, that kind of talk goes against the “market bad regulation good” thinking in vogue right now.
- Quanttek 7y agoThat is true in theory but it is not (solely) what is at stake here. Here, we are talking about the cost of regulations, and these do eat into the profits of companies. To some extent, these costs could also hurt competition (assuming the competitor had the same data-vacuuming business model). While we can not directly say whether the (possible) decrease in competition compensates for the compliance costs, looking at the overwhelming opposition by businesses small and large (incl FANG), it seems like the cost are higher.
- tastroder 7y agoCompliance costs money, what's supposed to be new or particularly bad about that? Many in this thread seem to argue that launching an internet based business or entering a market as large as the EU was previously free and I honestly don't see where this illusion is coming from. Yes, GDPR compliance costs money, just like a whole bunch of other things. > To some extent, these costs could also hurt competition (assuming the competitor had the same data-vacuuming business model). Same question, if that data-vacuuming assumption is true, why should the general public care about preserving that? GDPR regulation and implementations are by no means perfect but it's not like transparency, forcing companies to think about their impact on their users privacy and other aspects don't present benefits as well. I realize that the question of regulation is a matter of philosophy just as much as it is political but painting GDPR as some kind of killer of good businesses seems, at least, very weird.
- Quanttek 7y ago
- manigandham 7y agoThis ideological purity doesn't work well in the real world, and it's not about profits either. People don't care about privacy as much as you imagine them to, especially if they have to give up everything they get for ads today. One look at what people willingly share to the world on social media shows that. But powerful monopolies are a problem and market competition is the correct answer to that power. Regulation isn't a magic cure and should be used to place guardrails on the market, but in this case could've been written far better to provide data protection without entrenching the major players even further.
- icebraining 7y ago> in this case could've been written far better to provide data protection without entrenching the major players even further. Could it? How?
- YeGoblynQueenne 7y ago>> That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies. What do you mean? I use news.ycombinator.com every day and I consider human rights, and consumer rights such as privacy, to be extremely important. In fact, I use news.ycombinator.com because there is a very strong current in support of such principles by the users here. There is also a strong streak of free-market capitalism and technology-first, you-can't-stop-progress techno-optimism, but that is the point. This site offers opportunities for debate. You're assuming too much if you're extrapolating from a few comments you disagreed with to the entire userbase of this site. HackerNews is not an echo chamber. Not yet, anyway.
- soulofmischief 7y agoI'd say the consequences were intended. > companies deleting articles even when there would sufficient public interest Is that really part of GDPR? That just seems authoritative.
- Quanttek 7y agoNot really. The GDPR stipulates a right to be forgotten [1] with the following exceptions: > 3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: > (a) for exercising the right of freedom of expression and information; > (b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; > (c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3); > (d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or > (e) for the establishment, exercise or defence of legal claims. [1] https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/