14 ms·
The more TOS I read through, the more it seems we need a "common law" solution. (I use the term "common law" loosely here) Something like a couple of pre-define
by deckeraa 3y ago
The more TOS I read through, the more it seems we need a "common law" solution.
(I use the term "common law" loosely here)
Something like a couple of pre-defined categories for software services (e.g. info provider, social network, real-world interface) with pre-set rules (e.g. the client cannot attempt to break the social network; the owner of the social network cannot re-sell data to a third party).
We have something like this for brick'n'mortar retail already -- each store can't just make up their own rules but rather has to operate within a societal framework.
The system we have right now leads to every corporation being incentivized to claim as much legal ground as possible in the TOS, leading to a de-facto corpo-state. It also undermines the rule of law in a cultural sense since many things in the TOS may be deemed unenforceable when actually challenged in court. The users will always be is a several disadvantageous bargaining position.
- ronsor 3y agoTerms of service and end-user license agreements essentially serve more as private legislation than an actually negotiated contract.
- squirrel6 3y agoWell stated. The only reason it’s not actually legislated is probably because this was just the path of least resistance.
- gen220 3y agoIt's difficult because digital ToS are so tightly tailored to your business, and digital businesses are so malleable and formless. If you went through the effort to standardize your ToS, it would only be "useful" to a tiny handful of businesses at specific points in their growth trajectory. Regulations like GDPR are a top-down approach to the privacy component of a Terms of Service (i.e. there are only so many variations to the privacy sections within a ToS that comply with GDPR), but there are so many more components than just customer data locality. That being said, as a privacy-respecting entrepreneur, coming up with a "user-respecting" (i.e. win/win, legible, minimally-demanding/withholding) ToS is a sizable challenge. It'd be nice to have templates. I basically resort to reading the ToS of companies I respect in similar verticals.
- space_fountain 3y agoIs that true? Often ToS seem to mostly consist of boilerplate that's copied from business to business
- nicd 3y agoImagine there were a set of a few common terms that businesses could select, each with an icon, a high-level explanation, and the detailed legal copy. I think there is a common set of those that would probably cover 80% of needs. The remaining 20% could be "extended", custom terms for this company. Such a system seems like it would make things much easier for consumers to understand, and also save legal fees for most companies. Maybe a good standard for a TOS-generator company to design and promote?
- paulmd 3y agoIn general the problem is not that the documents are not readable or comprehensible - I understand perfectly well that in legalese it says that the situation will favor the business in every possible legal fashion and if some of those are not legal the remaining document will favor the business in every remaining possible fashion. The problem is they are contracts of adhesion that consumers don’t have a real interest or consideration in, other than the performance being conditioned upon your agreement, and which they do not have any ability to debate or modify or generally any recourse except to go to another business with an equally odious contract as a condition of performance. They’re not incomprehensible, they’re unconscionable, and solutions tackling the former are missing the point. The problem is that the same “lobbying” that produced the regulatory environment permitting such contracts to be forced upon consumers also precludes any real attempt to tackle the latter. Businesses would scream here if you forced them to follow standard consumer protections, and our system is oriented to favor their interests over consumers in nearly every possible scenario as well. Another “continental” solution to this would simply be to outlaw contracts of adhesion or contracts in which the consumer does not receive a consideration (other than performance of the contract). If you don’t have a consideration it’s simply not a valid or consciencable contract, people don’t agree to give up money or rights voluntarily in return for nothing, therefore these contracts must facially be coercive.
- space_fountain 3y agoI like this idea, but I think it's not flexible enough. Instead my over complicated dream is to allow companies to propose new TOS in a similar way to new top level domains. They can put in a lot of money and add TOS language to the approved list, but then anyone can use that language. Ideally the pricing would be such that only 10 to 50 unique TOS would exist at any point in time
- rpmisms 3y agoSo instead of the richest companies setting the standard for what a TOS contains.... The richest companies would formally set the standard for what a TOS contains.
- space_fountain 3y agoI think the problem I was most interested in solving is maybe only somewhat related to this. I was frustrated that no one actually ever looks at TOS and so there is very little real informed choice happening. With a small fixed number it would be easier for audits and understanding to happen
- rpmisms 3y agoThe problem is that 99% of people will never read the TOS, period. South Park said it best in "Human Cent-iPad"
- bushbaba 3y agoThe easy answer should be TOS that are not non lawyer readable or not under N paragraphs are not binding. When you buy a house you don’t give 1 signature. You literally sign every friggen page including multiple places on the same page, TOS shouldn’t be different
- refactor_master 3y agoWe all know how cookie consents turned out though.
- account42 3y agoIt keeps exposing how little most businesses care about their users? Seems useful.
- Buttons840 3y agoRequire companies to make a reasonable effort to ensure users have read the license. Want to order some food from some new delivery website? Hold on, I just have to sit on this screen for 30 minutes pretending to read the EULA -- oh nevermind, I'll just go pick it up.
- closewith 3y ago> Want to order some food from some new delivery website? Hold on, I just have to sit on this screen for 30 minutes pretending to read the EULA -- oh nevermind, I'll just go pick it up. Well, that would be ideal, because in order to actually get users, the company would have to have very simple and reasonable terms. After all, that's the case for the cast majority of in-person businesses.
- kelnos 3y agoTo be fair, I expect many people don't actually read every page of the stuff you have to sign when you buy a house, either.
- 3y ago
- bruce511 3y agoWhile I understand that looseness of your "common law" phrase, it's precisely the newness of the field that leads us to the lack of historical precedence (ie "common law"). So I would argue that we don't need "common law", we need "actual law". The problem is that "law" is a subject that is very, very specific. Don't want them yo sell "your data" - well then first you need to define what data is "yours" and what is "theirs". That might be harder than you think. (Do you own your docile security number? Or find the govt lend it to you? Are public records considered to be public data?) Privacy is just one corner. What about finances - can a service cut you off? What if you never oaid for it? Can you delete posts? Can quotes from deleted posts still exist? Can advertisers target specific demographics? The problem being that writing actual law gor this stuff is hard. Writing law that will satisfy even a majority of people is near impossible. So I hear your call, but I suspect you won't be happy with the law when they make it.
- bangoimby 3y agoI'm not sure, IANAL but I would say that much of what a EULA or ToS covers is not that novel, companies skate by on technicalities, and a nontrivial portion of a typical agreement may even already be invalid but lacks case law. If companies weren't worried this might be true they wouldn't need the severability clauses. For example, disassembling or repairing items you paid for or duplicating legally owned copyrighted works for personal use (not distribution) were rights that were well established, but sprinkle in the right technology (even if it has no purpose other than to interfere with these rights) and suddenly it gets a pass. It's not a novel situation, it's a loophole to opt out of established law. You are right that we won't be happy with the new laws, as so far and with the examples I gave new laws have mostly removed consumer rights, not asserted them.
- anileated 3y ago> duplicating legally owned copyrighted works for personal use (not distribution) were rights that were well established, but sprinkle in the right technology and suddenly it gets a pass True in more than one way; owning copyright to your works and being able to refuse/get paid for commercial distribution was a right well established, but a sprinkle of right technology and suddenly they can charge people to copy your work on demand with minor modifications for your own commercial use (while you get nothing).
- 1vuio0pswjnm7 3y ago"... the owner of the social network cannot resell data to a third party)." Not sure I understand. Social media operators do not sell data. They provide access to computer users, acting like a Trojan Horse. ("Our app is installed on millions of phones. Millions people use some individual's website to communicate with each other." Zuckerberg, Musk, etc.) Perhaps "resell" refers to when social media companies buy data. What prohibits them from (re)selling it. Maybe the seller's terms would prohibit transfer to any third party.
- m463 3y agothey don't sell it, they share it. for example, I don't believe using google analytics or using a facebook badge is selling data, but it is sharing it.
- 1vuio0pswjnm7 3y agoWhat is a Facebook badge.
- 1vuio0pswjnm7 3y agoThey buy data. Sometimes it comes as part of an acquisition. https://www.propublica.org/article/facebook-doesnt-tell-users-everything-it-really-knows-about-them https://www.propublica.org/article/facebook-doesnt-tell-user... Sometimes it comes as part of an acquisition. https://www.cnet.com/news/facebooks-latest-mobile-acquisition-its-all-about-your-data/ https://www.cnet.com/news/facebooks-latest-mobile-acquisitio... https://www.titlemax.com/discovery-center/lifestyle/everything-facebook-owns-mergers-and-acquisitions-from-the-past-15-years/ https://www.titlemax.com/discovery-center/lifestyle/everythi... As everyone knows, they also give data away. https://www.fastcompany.com/40554491/zuckerberg-keeps-insisting-facebook-doesnt-sell-our-data-what-it-does-is-even-worse https://www.fastcompany.com/40554491/zuckerberg-keeps-insist... https://www.cnet.com/news/politics/zuckerberg-facebook-data-was-sold-to-cambridge-analytica-too/ https://www.cnet.com/news/politics/zuckerberg-facebook-data-... https://www.cnbc.com/2019/04/16/facebooks-zuckerberg-mulled-developer-deals-to-decide-value-of-data.html https://www.cnbc.com/2019/04/16/facebooks-zuckerberg-mulled-... https://www.nytimes.com/2018/03/19/technology/facebook-data-sharing.html https://www.nytimes.com/2018/03/19/technology/facebook-data-... https://www.cnbc.com/2018/06/04/facebook-reportedly-gave-personal-data-to-60-companies-including-apple-amazon-and-samsung.html https://www.cnbc.com/2018/06/04/facebook-reportedly-gave-per... https://www.theverge.com/2018/6/8/17435764/facebook-data-sharing-huawei-cybersecurity https://www.theverge.com/2018/6/8/17435764/facebook-data-sha... Using to term "sell" to describe these data transfers to other parties is ineffective. Prohibiting the "sale" of data will not stop social media companies from transferring data to others.
- m463 3y agoby law in california you can opt-out of binding arbitration in any contract for a short time after signing it. (30? 60? days? i am not a lawyer)
- throwaway2037 3y agoThis is interesting. Can anyone provide more details?
- anon373839 3y agoIndividual states don’t have the power to restrict arbitration agreements in this way. California has tried repeatedly, but the laws keep getting invalidated because they’re preempted by the Federal Arbitration Act, which requires that contracts containing binding arbitration clauses be enforced and treated the same as all other contracts. State laws that selectively disfavor or restrict arbitration agreements will violate this. If this regrettable state of affairs is to be improved, it will require an act of Congress, unfortunately.
- MisterBastahrd 3y agoPersonally, I'd like for it to be illegal to force people into TOSes which add binding arbitration to access their accounts and data once they've already time and money into the system otherwise. I shouldn't be negatively impacted regarding my rights to data or damages just because you were careless with my data. Likewise, any explicit agreement to legal remedy should really be in its own independent section for users to approve.
- account42 3y agoPersonally I'd like for binding arbitration to be unenforceable period. It's a hack to work around the laws of the country by preventing people from availing themselves of this and should be treated as such.
- _v7gu 3y agoHow about a "continental law" solution? Usually you can't give up rights you do not have yet, so you can't sign a binding arbitrage clause if you haven't been wronged yet. This is in addition to TOS'es being restricted heavily by laws that define the limits of general terms and conditions (generally contracts that are offered to a large amount of people) and the existence of consumer arbitration committees that make it really simple for consumers to go after firms.
- denton-scratch 3y ago> so you can't sign a binding arbitrage clause if you haven't been wronged yet. This doesn't make sense to me. Firstly, I take it that by "arbitrage" you mean "arbitration"; arbitrage is a kind of market trading, and "binding arbitrage clause" isn't a thing. If we're talking about arbitration, many contracts contain binding arbitration clauses which are enforcible by either party from the outset; neither party has been wronged yet.
- crote 3y agoUntil your country actually implements laws like these and Hacker News starts complaining that it is "business hostile" and "stifling innovation". There are plenty of European countries which already have some laws like these. When I buy something on the internet, I have 14 days to return it if I don't like it. I am guaranteed to have a reasonable warranty. Companies cannot abuse my personal data without explicit consent. And indeed, forced binding arbitrage is also not allowed. There is no need to mandate a template ToS, you just need basic consumer protection laws.
- that_guy_iain 3y ago> There are plenty of European countries which already have some laws like these. When I buy something on the internet, I have 14 days to return it if I don't like it. I am guaranteed to have a reasonable warranty. Companies cannot abuse my personal data without explicit consent. And indeed, forced binding arbitrage is also not allowed. This is because of EU laws. A lot of the best laws we have in European countries are because of EU laws. I also suspect that this clause isn't valid in most of Europe.
- concerned_user 3y agoYou are correct, I can not find where arbitration is forbidden in the directive also it is quite the opposite. I think in this particular case we are talking about Directive 2011/83/EU of the European Parliament and of the Council on consumer rights. Article 6(1) (t) where applicable, the possibility of having recourse to an out-of-court complaint and redress mechanism, to which the trader is subject, and the methods for having access to it.
- gpderetta 3y agoADR is not forbidden. But it is regulated by 2013/11/EU [1]. In particular: " (43) An agreement between a consumer and a trader to submit complaints to an ADR entity should not be binding on the consumer if it was concluded before the dispute has materialised and if it has the effect of depriving the consumer of his right to bring an action before the courts for the settlement of the dispute. Furthermore, in ADR procedures which aim at resolving the dispute by imposing a solution, the solution imposed should be binding on the parties only if they were informed of its binding nature in advance and specifically accepted this. Specific acceptance by the trader should not be required if national rules provide that such solutions are binding on traders." [1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32013L0011 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...
- osullip 3y agoI'm a little lost here. If you don't want a company to have your DNA, don't give it to them. It seems like a business was built around people wanting to be told they had 20% more fun in their bloodline, for a fee. Those people didn't consider the implications of giving this kind of data to a private company. Now the company is saying, "we got the DNA you gave us, for a fee and we don't want to go to court to fight you about how we use it". Just don't give them your DNA. It's not that hard.
- orbisvicis 3y agoIt's not like we don't have cultural admonishments against this type of behavior - take Rapunzel for example. * Walled garden of the sorceress equivalent to corporate walled garden. * Rapunzel (the leafy green) representing either a life-saving service or unquenchable greed of the consumer. By holding the genetic health of future children hostage, The 23andMe connection is particularly apropos - the sorceress holds Rapunzel hostage. * The husband agrees to a ToS in exchange for rapunzel (the leafy green). As the story unfolds the consequences reveal themselves...