8 ms·
Just copy-paste GDPR, and enforce it.
by hadrien01 3y ago
Just copy-paste GDPR, and enforce it.
- taosx 3y agoGDPR doesn't work as described and companies have found many ways to make the process difficult. There is a clause (last case scenario) where the company can say that the data is critical to the system and can't delete it.
- anticristi 3y agoNo, they cannot https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ You probably refer to "legitimate interests". If you play that card, you are required to show a "Legitimate Interest Balancing Test", in which you show that your interests are arguably more important than the interest of the consumer: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ https://ico.org.uk/for-organisations/guide-to-data-protectio... Source: I love to watch Facebook becoming the first GDPR unicorn, i.e., a company with more than 1 billion € GDPR fine.
- JumpCrisscross 3y agoGDPR isn't a good fit for the American system. The principles that animate it [i.e. rights of access (Art. 15), erasure (17) and objection (21)] should be incorporated into law. But a combination of public and private enforcement, plus a strong civil regulator (but one who isn't obligated, by law or practice, to respond to complaints), is a better start. > watch Facebook becoming the first GDPR unicorn They're paying $725mm to users in America [1]. Difference being the damages go to users, not a regulator. [1] https://www.popsci.com/technology/meta-725-million-lawsuit-cambridge-analytica-settlement/ https://www.popsci.com/technology/meta-725-million-lawsuit-c...
- mindslight 3y agoThe problem is that no form of data personal protection is really a good fit for the American (political) system, because the US leans heavily into the fallacy that if it's legal for one individual to do some as private activity, then allowing to be scaled up to mass corporate behavior is inherently reasonable. So telling Surveillance Valley to stop building Stasi 2.0 is akin to telling your friends that they must forget your birthday. Furthermore, the American concept of "consent" mostly functions as a legal fiction whereby less powerful parties are coerced into signing a bunch of binding legal documents. Hence the desire to copy the GDPR verbatim - because if a privacy law used the American version of "consent", why even bother? One way to port the overall idea of the GDPR into the US legal system might be to define a non-transferable property right in personal information (information about yourself), which could only be licensed revocably. Those two key bits would be tough though, given widespread deference to the Coase fallacy that has blessed much corporate looting.
- JumpCrisscross 3y ago> no form of data personal protection is really a good fit for the American system Not true. We have the Privacy Act of '74, HIPAA, GLBA and COPPA, to say nothing of e.g. California's CCPA and Virginia's CDPA [1]. Or Illinois' biometric privacy protections [2]. > the US leans heavily into the fallacy that if it's legal for one individual to do some as private activity, then allowing to be scaled up to mass corporate behavior is inherently reasonable This is true for rights, which don't get diluted through assembly. Not rules or the law. Plenty of laws exempt small businesses and natural persons. > the American concept of "consent" mostly functions as a legal fiction whereby less powerful parties are coerced into signing a bunch of binding legal documents Not entirely true. See: EULA enforceability as it pertains to natural persons [3]. > to define a property right in personal information (information about yourself), making it non-transferable and revocable at any time One generally defines a property right to enable transferability. Revocable property isn't property, it's a license. Making information one's inalienable property that can only be revocably licensed sounds neat, but it doesn't add value over enumerating data rights. [1] https://www.comparitech.com/data-privacy-management/federal-state-data-privacy-laws/ https://www.comparitech.com/data-privacy-management/federal-... [2] https://www.jacksonlewis.com/sites/default/files/docs/IllinoisBIPAFAQs.pdf https://www.jacksonlewis.com/sites/default/files/docs/Illino... [3] https://en.wikipedia.org/wiki/End-user_license_agreement#Enforceability_of_EULAs_in_the_United_States https://en.wikipedia.org/wiki/End-user_license_agreement#Enf...
- Hamuko 3y ago>Difference being the damages go to users, not a regulator. Doesn't a class-action lawsuit just mean that like a third of it goes to private law firms?
- andygeorge 3y ago> GDPR doesn't work as described could you expand upon or clarify that? i work in systems infrastructure and have been a part of implementing GDPR-driven changes in both apps and infrastructure, so it certainly seems to be working in my line of work
- taosx 3y agoI'm not saying that systems are not in place, I'm just saying that it's too hard for the average consumer. - After you've requested deletion the company has 30 days to "respond" but they can extend that with two additional months. - They can go to extreme lengths to verify the identity of the user which they have the right to do so and if you don't respond to the confirmation they are not obligated to delete anything. I've encountered both practices in the past (and I've only made 3 requests, ever). The dream would have been an automated way to do it, something like a government service where each company would have to publish metadata about captured user data and once you request deletion through the service the company would receive an event, a webhook call...
- andygeorge 3y ago> it's too hard for the average consumer oh yeah, hard agree with this
- givemeethekeys 3y agoIf by GDPR you mean the cookie banner that appears on most websites? It's as if we ask for something and are punished for it. I'd like to see some proof that GDPR has achieved major changes in data privacy before a copy-paste.
- minsc_and_boo 3y agoNitpick: EPD is responsible for the cookie consents everywhere, not GDPR - https://gdpr.eu/cookies/ https://gdpr.eu/cookies/ GDPR primarily concerns the user with information and takedown requests, the latter which could be considered deletion.