4 ms·
Asking for it and not enable it by default is the only way to abide by European and South American Data Protection laws..
by Alcatros552 2y ago
Asking for it and not enable it by default is the only way to abide by European and South American Data Protection laws..
- hx8 2y agoManjaro doesn't have region specific isos, so it sounds like this will end up being the global policy. However international compliance isn't something every developer is aware of so it may take time before the project is releases a compliant version.
- jeroenhd 2y agoIMO asking for consent (or not collecting data at all) is always the right move, regardless of legal obligations. Might as well just ask everyone for consent.
- protonbob 2y agoThis is the morally correct thing to do but it does result in selection bias for any statistics gathered. It's hard to figure out a way to get good data but users rights must be respected.
- dmitrygr 2y agoSomehow, before the wide availability of constantly connected Internet, software got made. Perhaps constantly collecting data on your users is not required after all.
- hx8 2y agoIf your competition is collecting user data and you aren't then they have a competitive advantage in understanding where to make investments for future development investments. It's really best to just kill the arms race and restrict data collection.
- dmitrygr 2y agoYou can fight back by exposing how much data the competition collects. I buy devices that collect less data as a choice. Many others do too.
- eloisant 2y agoYou don't get any meaningful stats from opt-in. Might as well not collect any data at all.
- _heimdall 2y agoDoes that only hold if the data collection contains PII and isn't considered necessary for the product? Either way I expect Manjaro's collection would be an issue if its opt-out, just curious how those edges of that law are defined.
- jeroenhd 2y agoI don't know how American data protection laws work in this sense, I've only read up on the GDPR. I don't think American data protection laws are any more strict than their European counterparts though. You don't need to share this information for Manjaro's software to do its work so it's not necessary for the product. If it's strictly necessary, they may need to inform EU users, but don't need consent. The edges of the law are pretty sharp. There are a few reasons for which data may be collected without consent, and "I want to see what kind of computers visit my website" isn't one of them. Most of the time, you'll need explicit consent (can't hide consent in the EULA or T&C). This goes for anything containing PII. And, for the record, an IP address is considered PII in many cases. Pseudonyms also don't protect you. Even with consent, collecting PII like this also adds a ton of extra overhead (suddenly you need to encrypt your database, serve information/correction/deletion requests from the people you've collected data about, not being allowed to host such data in the US, etc.) to the point I wouldn't even bother collecting this info from EU users. Foreign companies break the GDPR all the time and very few of them ever get fined, but when it comes to communities trying to do the right thing, the GDPR rightfully succeeds in making data collection expensive.
- jeroenhd 2y agoI agree. And as was said in a comment by the author in the thread: > True, that. I wasn’t even thinking about the GDPR when I wrote that. :man_facepalming:
- sealeck 2y agoMy understanding (and I am not a lawyer) is that under European data protection law the important thing is to obtain user consent for this; I think there's a very reasonable argument that informing the user that you collect telemetry and that if they wish to avoid this they should just build their own copy of the software (which provides a very easy to access opt out which should satisfy everyone). Although EU privacy and technology regulation is generally pretty ok, this seems to be one of those cases where their lack of technical skill or knowledge really shines through (other examples include the endless cookie banners and https://www.euronews.com/next/2024/07/22/microsoft-says-eu-to-blame-for-the-worlds-worst-it-outage https://www.euronews.com/next/2024/07/22/microsoft-says-eu-t...)
- failbuffer 2y agoI don't know the law, but "build it yourself lol" is hardly easy, especially for software that needs to be constantly updated for security.
- bombela 2y agoWhy did MS comply to the EU request on installations outside of the EU? MS Windows with crowdstrike BSOD'd for American airlines on the American soil afterall.
- sealeck 2y ago> Why did MS comply to the EU request on installations outside of the EU? Because it's really expensive to maintain two versions of the same kernel?
- Nullabillity 2y agoConsent needs to be freely given; you can't nudge users into it and you can't hold access ransom over it. There's no way what you're suggesting would fly.
- ranger_danger 2y agoI'm not an expert and not on either side, but couldn't a notice like "by agreeing to these terms you allow us to turn on telemetry by default, and you are free to simply not use this software instead" be allowed?