6 ms·
Bluesky is breaking the rules in the EU
- ronsor 2y agoThese days I think everyone's breaking some rule in the EU
- mnau 2y agoHey, regulations are among our key export articles. Do not be so dismissive.
- nomdep 2y agoBy design, I suspect, so they can prosecute those who they don't like (but not their "friends")
- barbazoo 2y agoCan you elaborate? Have they in the past used this to "prosecute those who they don't like"?
- wrineha2 2y agoEU/EC officials aren't secret that they make as much as possible illegal to get companies to come in and talk with them before they launch products. I have heard this at least twice from the source and more than a couple times from other people I know.
- lxgr 2y agoDo you have any evidence to offer for that claim, other than a personal suspicion?
- nomdep 2y agoOf course not, it's just a feeling, and it's probably not the intention of some of the people writing those rules
- abeppu 2y agoI'm not saying this doesn't happen, but I also think it's genuinely difficult to write policies that apply to technical systems that don't exist at the time of writing and which are also clear enough that regulators, courts, and the relevant parties within tech companies all understand what they mean, what they imply about technical systems, etc. With respect to much older law, e.g. copyright, I think we still haven't fully interpreted what constitutes "copying" or "distributing" in a digital context. With respect to data privacy, though I was part of a team that was responsible for ensuring my company met GDPR obligations, it's still not clear to me what really constitutes deletion or erasure for these purposes. What if my DB doesn't delete stuff on disk immediately but marks some records with an in-memory tombstone, so normal DB queries will no longer return the record but files containing the record do still exist? Am I obliged to delete all DB backups when any individual exercises their deletion rights? If my datalake uses columnar files that record events (e.g. clickstream data) from many users, every time any user exercises their deletion rights, do I have to re-write all the files that included any event from them? To find all files containing a user efficiently, I'd probably need to start indexing by user, which if anything puts my team on the path to using user-specific data more intensively going forward. Or is it sufficient to mark their ID in a "forgotten" file and ensure that datalake results do not include information from their records, though the records are in principle still readable? If you didn't have a good systems/data engineer participating in the drafting of the policy, it's easy for a regulator to just write "delete" without thinking through what the actual definition should be, and what the implications are.
- amiga386 2y ago> Am I obliged to delete all DB backups when any individual exercises their deletion rights? No, just don't use that individual's data in any processing going forward, unless you have a lawful basis for doing so. If you restore from those backups, don't lose the fact this individual exercised their right to be forgotton. > What if my DB doesn't delete stuff on disk immediately but marks some records with an in-memory tombstone, so normal DB queries will no longer return the record but files containing the record do still exist? If you don't process those records any more, that's fine. Ideally purge your database tables from time to time, because you should also have retention limits, set to the minimum possible. "Forever" is not an acceptable limit for PII. > do I have to re-write all the files that included any event from them? No. Write a list of users whose events you mustn't process any more, and preferably stop collecting events for those users... assuming that specific data you're collecting is data which you don't have a legal basis to process without their continuing consent. If they withdraw consent, you have to stop. It's that simple. Design with that in mind. > the records are in principle still readable? It doesn't matter about "in principle", it matters if you continue to process the data of individuals who have exercised their right to be forgotton and withdrawn their consent, and you have no other lawful basis with which to continue processing their data. > which if anything puts my team on the path to using user-specific data more intensively going forward "The 'no beatings' law just makes we want to beat people even harder". You sound petty. Treat PII as if it were hazardous waste; minimise your collection of it and processing of it, dispose of it as soon as you can. > it's easy for a regulator to just write "delete" without thinking through what the actual definition should be, and what the implications are. They did think it through. Section 67 of the GDPR: "Methods by which to restrict the processing of personal data could include, inter alia, temporarily moving the selected data to another processing system, making the selected personal data unavailable to users, or temporarily removing published data from a website. In automated filing systems, the restriction of processing should in principle be ensured by technical means in such a manner that the personal data are not subject to further processing operations and cannot be changed. The fact that the processing of personal data is restricted should be clearly indicated in the system." Read the rest of the statute, it's not that difficult to understand: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... You just don't like having to do it, and would prefer if once a user gives consent (or even if they don't), you can keep that data and do anything you like with it for all time and there's nothing the user can do about it.
- deleted 2y ago[deleted]
- bradgessler 2y agoI wouldn’t be surprised if the EU is breaking some rule in the EU.
- artninja1988 2y agoThat'll be 5 trillion dollars per cookie, please
- rahkiin 2y agoTl:dr; they are missing a EU-user counter and a reference to an EU office
- Suppafly 2y ago>But since Bluesky isn’t yet big enough to be considered a “very large online platform” under the DSA, the regulator says it can’t regulate Bluesky the way it does X or Threads. So it sounds like they are 'breaking' rules that don't even yet apply to them?
- JosephRedfern 2y agoYeah, this feels like a non-story.
- yen223 2y agoBut this gives us an excuse to moan about cookie banners, so up to the front page it goes
- doctorpangloss 2y agoThis stats link Verge found is nice: https://bsky.jazco.dev/stats https://bsky.jazco.dev/stats Do EU based bots count?
- d357r0y3r 2y agoEU regulation has been a disaster for the web.
- nicce 2y agoNot the companies that cause the regulation?
- BadHumans 2y agoIt can go both ways. Just because a company has done something that deserves to be regulated does not mean the regulation itself is a good way of accomplishing that. For what it is worth, I think the EU for the most part is doing alright in some places with some severe missteps as far as encryption and privacy goes.
- afavour 2y agoNot really. The methods companies use to skirt around the EU regulation has been the actual disaster. Case in point: The EU never mandated the cookie popups that proliferate the web. They simply passed common sense regulation about user tracking. But there's too much money to be made tracking your every move on the internet, so along came the popups that convince you to allow yourself to be tracked. Every time I see one I'm reminded of how relentlessly exploitative the modern web is, not how mistaken the EU are.
- nox101 2y agoI'd say those are unintended consequences and should have been taken into account. The effective result of the regulation appears to be just to have added annoying popups and close to zero change in company behavior.
- Jensson 2y ago> and close to zero change in company behavior. You have third party data brokers in the US which has everyone's data and sells it to anyone, you don't have that in the EU. I'd say that is a pretty big change.
- georg-stone 2y agoThey just have to fine every tech company lol
- BadHumans 2y ago> But since Bluesky isn’t yet big enough to be considered a “very large online platform” under the DSA, the regulator says it can’t regulate Bluesky the way it does X or Threads. So are they breaking the law or aren't they? Sounds like they aren't but the EU wants to be on their back anyway.
- afavour 2y agoI thought the article was pretty clear: they are breaking rules (not laws, FWIW) but are not yet big enough for the EU to do anything about it. At their current growth trajectory they will soon. The EU statement seems to just be an anticipation of the inevitable.
- dathinab 2y ago> Sounds like they aren't but the EU wants to be on their back anyway. > The regulator hasn’t reached out to Bluesky directly, yet, The Financial Times writes. I think no on is on anyones back, they just follow standard procedure more or less. There is a new "growing" platforms which might be affected by such regulations and they just want to make sure what their state is and under which legal aspects they operate (e.g. if they have any EU offices onto which they should base official communication). The things pointed out by the article are also non issues: - a missing statistic about EU users which you need once you have a certain size but practically kinda should have before _to show you have not quite yet that size_. But that is somewhat of a nothing burger, you add it when needed and as long as there is no reason to believe you acted with malicious intend it's unlikely to involve any penalties. - regulation related to moderation, non issue as Bsky enforces their AGB and that already fulfills more or less all moderation requirements (maybe not some increased reporting requirements for larger companies, but like said they don't count as such yet) So IMHO a nothing burger. My guess is various news paper made "official" information/press requests to some EU institutes asking if Bsky complies with this or that and stuff like that and then created a issue from atm. more or less nothing. Wonder if it was with malicious intend.
- whalesalad 2y agoif I were starting a startup, especially a social one, EU rules are literally the last thing on the earth that I would be caring about. Come to think of it, I have never and hope to never consider the EU rules ever in my lifetime.
- wayvey 2y agoCan you elaborate on why you'd have that stance? Genuinely curious
- gr__or 2y agoIt's par for the course with HN libertarian virtue signaling
- S0y 2y agoIt's a variation on "Premature Optimization Is the Root of All Evil". Focus on what actually matters for your startup. If for some reason some EU regulator actually comes knocking, you're most likely big enough to mean you've created a successful startup. Then you just say "Sorry!" and you implement what they want. This is probably different if your company is in the EU, but this is my North American point of view.
- Symbiote 2y agoThe principle of the EU's rules is treating people's private data with the respect it deserves. What other expectations of society would your startup ignore?
- sroussey 2y agoYeah, the idea that companies bend over backwards to protect credit card information but not data on the user is mind boggling. Except when you think of incentives.
- Eduard 2y agoSo when it comes to data protection, your startups will be user-hostile? Noted.
- sg47 2y agoEU's greatest contribution to technology has been that annoying pop-up on every website.
- dewey 2y agoOften repeated, always wrong.
- hn_version_0023 2y agoIn your estimation what is the EU’s greatest contribution?
- dewey 2y agoLongest period of peace in Europe seems like a pretty big achievement, even if many of us don't even know what it's like to live through wars in Europe. On a smaller scale, having a single currency, no roaming fees, traveling and working everywhere without worrying about tourist or a working Viswa is pretty big too. Easy to forget about many of these things as we just take these as a given baseline. https://european-union.europa.eu/achievements_en https://european-union.europa.eu/achievements_en
- hn_version_0023 2y agoIt was implied through GP that the topic was “greatest contribution to technology”
- jborean93 2y agoYep it’s been great to see the sites that try and track me vs them just doing it without me knowing.
- _Microft 2y agoNo permission is required for cookies that are needed to make a website work. Cookie dialogs are solely the contribution of those who want to keep tracking you but aren't allowed to do so without your consent.
- S0y 2y agoWonder how you define "Bluesky" users in the context of ATProto. is it users of the relay? users of bsky provided PDS? users of the bluesky frontend?
- dathinab 2y agonumber of active registered users you have a login with bluesky, you register with a email thats more or less what matters here at the moment
- DataDaemon 2y agoThe question who is not breaking EU rules? The funny thing, when there is penalty let's say $100M, all these funds going to the government to spend more for another regulations. Never ending loop. User doesn't receive anything.
- beardyw 2y agoI suspect this fulfills three objectives: 1. It puts Bluesky on notice that they need to watch their numbers 2. It preempts accusations of unfair application of the rules 3. It reminds Blusky that if they trade internationally they need to "do as Romans do".
- dathinab 2y ago> 1. It puts Bluesky on notice that they need to watch their numbers can't be as they haven't reached out to Bluesky, can't put someone on notice without communicating with them this articles seems to be based on newpapers doing "press requests" not any EU institution initiating actions, some parts can outright be read as "what is Bsky, we should find out if it is relevant if we get press requests about it, where is their office again?" > 2. It preempts accusations of unfair application of the rules I'm not sure where such accusations should come from. I don't thing any related EU regulatory organizations care about what people in the US thing about supposedly unfair treatment of X compared to Bsky. > 3. It reminds Blusky that if they trade internationally they need to "do as Romans do". which only makes sense if they communicate with them but the only communication flow seem to have been the Financial Times asking some regulators. So I don't think so.
- Symbiote 2y agohttps://www.reuters.com/technology/eu-says-bluesky-is-violating-information-disclosure-rules-2024-11-25/ https://www.reuters.com/technology/eu-says-bluesky-is-violat... This is the original article (linked from The Verge one) and is much clearer: > Bluesky, the rapidly growing social media platform, is violating EU regulations by failing to disclose important details, a European Commission spokesperson told reporters during a daily briefing on Monday. > “All platforms in the EU even the smallest ones which are below the threshold, which is the case for Bluesky, have to have a dedicated page on their website where it says how many user numbers they have in the EU and where they are legally established. This is not the case for Bluesky as of today,” the spokesperson said.
- deleted 2y ago[deleted]
- nephy 2y ago[flagged]
- mnau 2y agoI get the "Our content is not available in EU" more and more often. 16%-14% of world's GDP and sinking fast.
- AlienRobot 2y ago>Regnier reportedly went on to say that the commission has asked the EU’s 27 national governments to look for “any trace of Bluesky” like EU-based offices. The regulator hasn’t reached out to Bluesky directly, yet, The Financial Times writes. Really?
- slooonz 2y agoSo… EU regulations are about "protecting users privacy"… but requires you to know how many of your users are EU-based, and publicly report it ? I don’t know about you, but "country of residence" is the kind of private information but I’d rather not be collected unless good reasons. Requiring to collect it seems rather antithetical to "protecting user privacy".
- lxgr 2y agoIf you don't collect anything, you don't need to collect the country of residence either. On the other hand, if you do, you'd better know what local data privacy laws you have to comply with for a given user!
- b59831 2y ago[dead]
- incomingpain 2y agoThis wont be allowed to remain here. Bluesky is the promise land. Mastodon can be ignored or made fun of now.