8 ms·
I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter r
by danishSuri1994 11mo ago
I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.
- jdasdf 11mo ago> clearer safe harbors for small actors Different rules for different people huh? Just because you like the group you're benefiting and dislike the group you're harming doesn't mean that is good policy.
- deleted 11mo ago[deleted]
- JumpCrisscross 11mo ago> Different rules for different people huh? Compliance has fixed costs. And smaller operations have a smaller blast radius when things go wrong. Reducing requirements for smaller operators makes sense.
- Swenrekcah 11mo agoNot different rules for different people. You would be subject to one rule for your small company and another rule as it grows. This is everywhere in society, from expectation difference between babies, kids, teenagers, adults and seniors and to tax bracket structures.
- rat9988 11mo agoThis is different for different people said differently. Why would small companies have access to things not allowed to big companies?
- kelseyfrog 11mo agoBecause quantity is a quality of its own.
- alwa 11mo agoYes, it is—gp’s point being we do that all the time and often agree that it makes sense. A baby doesn’t catch a sex pest charge for running around naked, but it also can’t get a gun license. A mom-n-pop doesn’t have to hire an auditor and file with the SEC, but it also can’t sell shares of itself to the public. Why? The bigger you are, the more responsibility you bear: the bigger the impact of your mistakes, the subtler the complexities of your operation, the greater your sophistication relative to individual customers/citizens—and the greater your relative capacity to self-regulate.
- Levitz 11mo agoBecause their conditions and abilities are different.
- rat9988 11mo agoBut the conditions aren't here to annoy big companies but because we want to shape society in a specific way. Why would I allow small companies to disrespct author rights and steal, or gather more private information about citizens?
- Swenrekcah 11mo agoCorporations are not people. This is not different rules for different people. In the traditionally implied sense of different rules for different social classes.
- andrepd 11mo agoIn literally no place in the world are the rules the same for running a multinational or running a lemonade stand. I feel this should be obvious.
- veltas 11mo agoIn almost every developed country the rules are exactly the same. No hairnet, no licence? Lemonade Stand Ltd can and will be shut down. The main difference is lenience in punishment which tends to tail off and disappear at the lemonade stand scale, and be stricter for large multinationals. I wish you were right though.
- hobs 11mo agoSeen house building regulations recently? Most countries will let the home owner do things they'd never let a contractor do without a permit. There's a lot of different laws for home or very small scale selling of various goods, brewing, canning, single person doing business as companies, etc.
- no-name-here 11mo ago> home owner But in this analogy, we aren’t talking about a person doing coding at home only for their own use, are we? Isn’t this about small companies - I.e. whether there should be different applicable laws if you hire a small construction company vs a large one to rewire your kitchen, etc?
- Spivak 11mo agoYep, a single person contractor business is no more able to work on a home without a license and permit than a giant corporation.
- vouwfietsman 11mo agoI'm not sure how you got to this conclusion. The answer is a simple google away: smaller companies face lower taxes, lower standards of documentation on health & safety, don't need work councils, less reporting on workspace/financials, etc etc etc.
- ivan_gammel 11mo ago>Different rules for different people huh? That’s how efficient market works. The bigger are the players, the higher are the chances they will distort the market. You need to apply the force proportional to size to return market back to equilibrium at maximum performance. We have anti-trust laws for this reason, so nothing new, nothing special.
- cess11 11mo agoI think most people agree that the state should be subject to harsher rules than you are, because it is large and powerful. But you would actually prefer to be subject to the same rules as the state? I.e. typically nothing which isn't explicitly allowed is forbidden for you to do, you are forced to hand out copies of documents you produce, and so on?
- kazinator 11mo agoThe problem is that an intellectually consistent position of being against "different rules for different people" means everywhere, in everything. For instance, poor people should not have any tax breaks: everyone should pay exactly the same percentage of their income, like 15% all across the board or whatever. Such ideas often have regressive effects. However, I get it. When it comes to handling personal information, you simply can't say that the "little guys" don't have to follow all the rules, and can cheerfully mishandle personal information in some way. Small operators have simpler structures and information systems; it should be easier for them to comply and show compliance, you would think (and maybe some of the requirements in the area can be simplified rather than rules waived.)
- veltas 11mo agoRegulation is a moat designed by and benefitting big corporations. Removing it for small businesses specifically would actually be fair.
- 47282847 11mo agoAlmost any corporate rule I am aware of has differences in how they apply depending on the size of the company. And as an entrepreneur and startup consultant I think that is a good principle. I don’t even see how society could function without it.
- shadowgovt 11mo agoIt could, however, be good policy independent of personal preference. I like folks who have to work for a living and dislike billionaires relaxing on yachts bought on their generational wealth, but in addition sociology metrics of the United States in the past 100 years suggest that the highest levels of happiness correlated pretty heavily with marginal tax rates as high as 100% based on wealth.
- port11 11mo agoThis would require politicians and policy-makers that think long-term, know what they're regulating, and maybe have been in the field. I don't think Law school Eurocrats can do any of the 3 items above, at least not well enough. This is either a way to chop at the (poorly designed and already watered down) GDPR or true, unapologetic lack of care. I'm hoping to go for my 3rd startup and ‘compliance costs’ have never been stifling; it's just more expensive to run a business here and there's far, far less funding available. That's really it. Belgium's tax haven will make some people willing to give you 10k in post-seed. Wow. We hunted VCs for 1.5 years to negotiate one million-ish euros after showing market traction. We just aren't on the same level as the US, and that's kinda okay. Grants might work, but I mostly see grants for things that won't compete well in the current market. AI nonsense won't make us more competitive — but hey, we'll arrive late to the bubble. We need to be building the kind of core, dependable infrastructure that would honour privacy, make us more independent. Backing off on privacy protections won't yield a mobile OS, an independent browser, better cloud options, etc. It's just… lazy. “Slap AI on it”-level policy. Ugh.
- Retric 11mo agoPoliticians don’t need to know the details, they need to be advised by competent people with the best interests of the public in mind. Which may sound straightforward while being really difficult to get right.
- port11 11mo agoWell… I had friends working in research or drafting advice that ends up in the hands of policy-makers. And while these people are motivated and want to do their job well, I disagree that they're providing the best advice. Politicians don't need to know the details but should know understand the wider, larger brushstrokes of the painting. That would be worlds easier if tech people listened to Bruce Schneier and started getting into policy. Someone who's had a career in tech can probably tell good from bad advice when it comes to the best interests of the public in mind. And perhaps they'd be less corruptible by the best interests of the wealthy.
- pants2 11mo agoWhy did you use an LLM to write a comment?
- gruez 11mo agoWhat makes you think it's LLM generated?
- marknutter 11mo agoThe double quotes perhaps?
- stronglikedan 11mo agocolons and directional quotation marks scare folks who don't know how to use them properly
- pants2 11mo agoBrand new account with 4 rapid & likely LLM comments, directional quotation marks, and common ChatGPT-isms such as "that does X without doing Y"
- barrkel 11mo agoThe structure of what it wrote, and the banality of the point.
- eitland 11mo agoIn my case it is rarely that I use LLM to write comments but rather I frequently use an LLM on my finished comment to fix things I miss as a non native speaker. The content of the comment is my unique opinion and my unique writing and I mostly also make sure to remove stupid things like directional quotation marks. But yes, it is possible to be very much human but also trigger certain peoples AI detectors.
- marcosdumay 11mo agoYes, the solution is clearer rules. What drives compliance costs up is rarely the compliance itself, it's usually the uncertainty about your being in compliance or not. That's also true for tax laws, labor laws, environment laws, almost every safety code out there, building zoning...
- mlyle 11mo agoWell, compliance itself is costly, but the cost is stuff that society decided it wanted to spend money on. But uncertainty in compliance and time spent navigating compliance is nearly pure waste.
- a4isms 11mo agoTo continue a conversation from another thread on another post, uncertainty, complexity, ambiguity, and out-of-band context required are all costs that just happen to act as moats for entrenched incumbents. And no surprise, such incumbents often have so much influence over politics that they literally write the laws that regulate them. The folksy aphorism goes, The more wild cards and crazy rules, the greater the expert's advantage.
- mlyle 11mo agoYes-- I think most of us are familiar with regulatory capture. But the solution to regulatory capture isn't "no regulation."
- a4isms 11mo agoWild cards and crazy rules versus no regulation is a false dichotomy.
- marcosdumay 11mo agoI'm not sure. Complexity is clearly hired by lobbyists all the time, but uncertainty and ambiguity seem to me to be mostly caused by incompetence. It's not even clear if uncertainty benefits incumbents more; it can just as likely destroy a market or benefit new entrants, and you can't predict which will happen at the time you create it (otherwise it's not uncertain). Legislative houses need technocratic QA. And that QA needs to be independent from the law-writing process.
- graemep 11mo agoI always felt applying the same rules to everyone was a big problem with GDPR. Not just small business, but even non-profits that just keep a list of people involved with them are subject to the same rules, even if they only use the information internally and do not buy or sell any personal information. Its not just cookies and websites, its any personal information stored electronically.
- MangoToupe 11mo agoI just don't see the issue. The GDPR isn't exactly difficult to comply with, nor does it hamper any of the clear successes of the last 25 years outside of the ad industry. What's the benefit of backing out on it? Is this just an effort to make a homegrown surveillance network?
- graemep 11mo agoI am not saying privacy laws should be repealed (if you look at my other comments, quite the opposite). I am saying that the same regulations are both too easy for big business to evade (or ignore and treat fines as a cost of doing business) AND too burdensome on small organisations that do not trade information. Something as simple as a membership list can draw you in.
- pembrook 11mo agoUghhh here we go again. Every time GDPR is brought up on HN, the same "it's super simple to comply, just read it yourself!" religious incantation gets repeated ad-nauseam. I think it's because people love the idea of what they think GDPR actually represents (the fuzzy abstract idea of "privacy"), without ever diving into any of the implementation details. Almost nobody on this forum has ever talked to a lawyer about this, and even less people have followed the actual court rulings that have determined what GDPR actually means in practice. My favorite example, under GDPR over the last 5 years, regardless of whether you follow the spirit of GDPR to the letter...due to the various schrems rulings, back-and-forth on SCCs, data-transfers, and EU-US political spats...there's been multi-year periods where if you're using any service touching data in any part of your business even remotely connected to the US or any non-EU country (so, almost everything), it's been a violation that exposed you to massive fines should any EU resident have filed a complaint against you. This was recently resolved again, but will continue to go back and forth if GDPR remains as-is. And this is just one of many weird situations the law has created for anyone running a business more complex than "a personal blog."
- shadowgovt 11mo agoBrowser level consent primitives would be a significant improvement on the status quo.
- recursive 11mo agoDo Not Track was a spectacular failure. You can still turn cookies off in your user agent though.
- lenerdenator 11mo agoIt was a spectacular failure because the people who thought of it didn't stick to it.
- bigfatkitten 11mo agoIn no small part because the people who thought of it (the browser makers) had a powerful commercial incentive to ditch it, because they are funded by advertising.
- pseudalopex 11mo agoMicrosoft enabled Do Not Track by default. Advertisers said they would ignore it for this reason. Most of them never respected it. Apple removed it from Safari years later because it was used for tracking. Mozilla removed it from Firefox years after Safari. Chrome has it even now.
- shadowgovt 11mo ago> Advertisers said they would ignore it for this reason That was the missed opportunity. Had the EU stepped in and said "I'm sorry, the user expressed explicit intent to not be tracked and you're planning to ignore that? How about that's a fine?" it would have survived. But they weren't prepped to take action yet.
- 11mo ago
- clickety_clack 11mo agoSo “smart rules” only means “more rules”? Smart rule making includes reducing the regulatory burden when it overreaches. The weight of regulation around tech in the EU is creating an environment such that the only companies that can operate in a space are the ones who can afford massive compliance overhead. That leaves you with the very same big tech firms that people are writing these rules to protect themselves from in the first place.
- cael450 11mo agoWell, yeah, they were written to prevent at least some of the privacy abuse from those big tech companies, not to get rid of them. Sometimes the answer is more rules, such as rules protecting smaller businesses while continuing to place regulatory burdens on the tech giants, who are responsible for the most egregious invasions of privacy.
- array_key_first 11mo agoRight, but it's obviously not overreaching, because user's data is taken: 1. Without their consent, 2. Without their knowledge and, 3. Cannot be taken back or denied in a simple way. There is a problem space here, in which there is zero solution. There is absolutely nothing, _NOTHING_, consumers can do if they want to protect their privacy. And before I hear 'well just don't use...' no - uh uh, that doesn't count. That's not a solution. So, we need some kind of regulation. And, to be clear, it doesn't need to make violating privacy illegal. It doesn't, and the GPDR doesn't either. It just needs to make it possible for consumers to choose. A free market is built on consumer choice, that is the core of a free market. It might seem counterintuitive, but regulation that protect consumer choice actually bolster the free market, not impede it. The "reason" the EU is "struggling" isn't because only big dogs can compete. It's because US companies, which need not follow the rules, exist, and will slurp up the competition. It's hard to compete with Google because they are cheaters. It's hard to compete with Meta because they are cheaters. They make literally hundreds of billions of dollars off of dark patterns, lies, stealing data, and privacy violations. If you even try to be honest, not even be good, just be honest, you will lose. Because they are not honest.
- 11mo ago
- MangoToupe 11mo agoInnovation isn't worth it for innovation's sake, though. Europe could easily profit watching others innovate and taking what makes sense for europe. I don't see anything about GDPR that would harm innovation or long-term success for europe.
- jedberg 11mo ago> I don't see anything about GDPR that would harm innovation or long-term success for europe. It's the same thing as any other regulation -- regulatory burden. Laws aren't code, they need interpretation. That means you need your own lawyer to tell you an interpretation that they feel they can defend in front of a judge. There is a cost to that. In both time and money. I am the CEO of a startup who is subject to GDPR. The amount of time and money we've spent just making sure we are in compliance is quite high, and we barely operate in Europe and don't collect PII. You can wing it and say "this looks easy, I can do this on my own!" and maybe you can. For a while. But no serious business is going to try to DIY any regulations.
- troupo 11mo ago> The amount of time and money we've spent just making sure we are in compliance is quite high, and we barely operate in Europe and don't collect PII. So either you're lying or your lawyers are lying to you. In 9 years you could've finally read and understood the rather small law yourself.
- jedberg 11mo agoI have read and believe I understand it. That does not matter. What matters is can your decisions be defended in front of a judge. I am not qualified to figure that out, and unless you're a lawyer, neither are you.
- troupo 11mo agoBefore you get to a judge you will get plenty of warnings and anple time to fix whatever it is you're doing wrong. For the absolute vast majority of companies GDPR compliance is trivial. For the absolute vast majority of remaining companies GDPR compliance is simple. There are a few companies which may have to double-check their legal obligations and legitimate interests (e.g. by law banks must retain data for much longer than GDPR assumes). I highly doubt that your startup which builds orchestration workflows requires 23 marketing cookies to "display relevant ads across sites" or "7 unclassified cookies" etc. especially since you claim you don't collect much information except the absolutely necessary: https://www.dbos.dev/privacy https://www.dbos.dev/privacy No wonder you have "trouble complying with GDPR".
- ljm 11mo agoPutting conditional logic in legislation still benefits big companies, if it still requires legal expertise to unpack all of the complexity added to the law. GDPR is a mess exactly because of this, and so is the UK’s ridiculous OSA. It’s loopholes and malicious compliance all the way down. Ignoring that, the other problem is enforcement. Is it not unrealistic to have a law that says “if you have a data breach you are subject to a penalty?” And “if you fail to report that breach the penalty can go as far as corporate death or executive incarceration?” Or even more simply - replace the wrist-slapping fines with criminal charges and imprisonment.
- YetAnotherNick 11mo agoSmarter rules and clear rules are kind of contradictory. GDPR is smart but not clear(as it operates on intent). Tax laws are clear, but not smart(as the interpretation is literate and there are multiple loopholes).
- btreesOfSpring 11mo agoA shorter and consistent iteration cycle by meaningful working groups on the legislation until a long term workable legal framework is enacted from the lessons gathered. Something like, every four months, X working group will present updates to legal recommendations and they will be voted on at that time. Allow for public input throughout the process. Mistakes will be made but can be short lived with the correction cycle. They are trying to tightrope walk complex legislation for tech. Might as well take on a tech release cycle to get out of beta and into release version 1.0 of these laws.
- deleted 11mo ago[deleted]
- seanmcdirmid 11mo agoAI should also be seen as an opportunity for small actors to actually understand and follow numerous complex rules. You don't need a huge legal and compliance team anymore, you just need to feed chatgpt the right amount of legal and ruling documentation, and then consult it on how you can actually comply.
- noitpmeder 11mo agoHAHAHAHA good joke. Oh wait. You're serious. Oh god please no.
- closeparen 11mo agoYou could simply ban targeted advertising, since that's what everyone is actually upset about, and not create insane collateral damage for non-adtech operators who happen to have network services and databases.
- abigail95 11mo agoEveryone is upset about that except the people clicking on it, which seems to be a lot of people given the amount of revenue and how much people will bid for placement. So it's not everyone, is it even most people? I'm not sure. I do feel for you if you happen to live in the EU, but you get what you vote for. I don't live there, none of my businesses operate there, so I'm free to ignore it. The GDPR ends where the EU does, and cross-border enforcement of laws requires a bilateral agreement, that I would have to vote for. I think there are many people who are fine with targeted advertising and also fine leading a private life in non-GDPR jurisdictions. I think that covers most people in the world. Given the amount of ad-revenue services I get access to, it's a very good tradeoff for me, please don't kill it, and if you do kill it, stick to your own jurisdiction please.
- SamDc73 11mo agoThe real issue with regulation isn’t the rules themselves; it’s who ends up writing them. And it’s almost always one of two groups: Politicians, who usually aren’t experts in the field. Industry leaders, who have every incentive to make the rules tougher for everyone.
- zenmac 11mo agoSmall company and business should be treated differently than big corp. And the fine and punishment should be adjusted accordingly.
- moooo99 11mo agoWhile I generally agree, just differentiating the fines is not sufficient. Small businesses in particular do not have staff or the capacity to to deal with a large amount of compliance overhead. The biggest help for small businesses (and large businesses alike) would probably be if the GDPR would be less vague on the rules surrounding typically collected data
- Gareth321 11mo agoI agree in theory but in practise, this just results in even more regulations. There are very few or no real world examples of stricter regulations being written in clearer terms. The reasons are numerous, but a big one is that people often have a financial incentive to circumvent these regulations. They attack the edge cases and the ambiguity between each word. If the regulations are not written sufficiently prescriptively, courts are swamped with cases and eventually a precedent is set which nullifies much or most of the intended purpose of the regulations. So regulators go to painstaking lengths to write clear and verbose regulations, but ensuring compliance with tens of thousands of pages of regulations are expensive, and this results in an economies of scale barrier for small businesses. There are workarounds like exemptions for small businesses, but this creates all kinds of new issues like a regulatory ceiling, which results in enormous new costs on some arbitrary day for a business once it crosses some kind of user or revenue threshold. Ramp-ups are difficult or impossible to legislate in this context. Further, two or multi-tiered regulatory systems are highly inefficient and arguably unfair. They're very difficult for everyone to navigate. Generally speaking, from countless examples around the world, rules should apply to everyone. Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.
- fsflover 11mo ago> Ultimately this means fewer regulations generally are good for startups - and larger businesses. Yeah, forcing companies to write food ingredients on the package is bad for business. And I don't care about business more than about the well-being of society and myself. Same with tracking.
- Gareth321 11mo agoI think that when I wrote that fewer regulations help small businesses, but that there are costs for this, you read, "all regulations are bad and I think they should all be removed." Since you didn't read my whole comment, I'm going to paste the important sentence again now: > Ultimately this means fewer regulations generally are good for startups - and larger businesses. But there are also social and consumer costs for this. There is no perfect balance to be found. Just competing ideological beliefs and positions.
- sensanaty 11mo agoI keep hearing this argument that it stifles small businesses, but how is that exactly? I've worked for a variety of small startups in NL and GDPR has never, not once, been a real issue or blocker. Yes, it forced these small businesses to think about how they're handling personal data, but that should be the fucking point, I don't care if a company is Facebook or if it's a 2 person startup, neither should be collecting and redistributing personal data and tracking people.
- edarchis 11mo agoThere is no certification to pass or anything. You just have to keep it in mind when creating your business. It's too easy to just abuse data and then claim that it's too late to fix. I've been through several startups after GDPR went into effect, it's really not a problem.
- slow_typist 11mo agoEuropean startups will not profit if this deregulation goes through. US and Chinese corporations will. While everyone talks about souvereign data processing in the EU, both the commission as well as the governments of its member states completely failed in pampering a domestic cloud industry during the last 15 years. Mercy killing.
- franga2000 11mo agoWhat actual innovation is stifled by data protection laws? What small business is unable to operate because of the GDPR? Compliance costs almost nothing. If you collect data, explain why and what for. If people ask you to delete it, do that. If you want to share data with others, ask first (or just, you know, don't).
- ernst_klim 11mo agoAt this point I think it's utopic. Meta has an army of lawyers, they will optimize and adapt. But it's really hard to tinker as a single hacker when a German legal troll firm can come for you for linking Google fonts on your web page (i.e. transferring IPs so breaching privacy)
- OWaz 11mo agoI've worked for startups and established industry giants and being compliant with GDPR did not stifle us in any way at all. It's really not that hard unless the business model depends on profiting off of user data. No good will come from this for the EU.