> individual “data rights” have led to unintended consequences; “privacy protection” seems to have undermined market competition;
That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies
Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (Amazon sending data to the wrong person, Spotify not asking for 2FA/email confirmation for the bulk download, companies deleting articles even when there would sufficient public interest, Ad vendors failing to ensure compliance and therefore seeing drops in demand, ...), that is, market failures - something this site would probably not call out but rather attribute it to the legislation.
Market competition is usually in the opposite to profits. Market competition usually works against the competing companies and in favour of their customers.
That is true in theory but it is not (solely) what is at stake here. Here, we are talking about the cost of regulations, and these do eat into the profits of companies. To some extent, these costs could also hurt competition (assuming the competitor had the same data-vacuuming business model). While we can not directly say whether the (possible) decrease in competition compensates for the compliance costs, looking at the overwhelming opposition by businesses small and large (incl FANG), it seems like the cost are higher.
Compliance costs money, what's supposed to be new or particularly bad about that?
Many in this thread seem to argue that launching an internet based business or entering a market as large as the EU was previously free and I honestly don't see where this illusion is coming from. Yes, GDPR compliance costs money, just like a whole bunch of other things.
> To some extent, these costs could also hurt competition (assuming the competitor had the same data-vacuuming business model).
Same question, if that data-vacuuming assumption is true, why should the general public care about preserving that? GDPR regulation and implementations are by no means perfect but it's not like transparency, forcing companies to think about their impact on their users privacy and other aspects don't present benefits as well. I realize that the question of regulation is a matter of philosophy just as much as it is political but painting GDPR as some kind of killer of good businesses seems, at least, very weird.
In general this might be agreeable. But in these cases these are not direct unintended consequences of the legislation but rather consequences of companies failing to do their due diligence when implementing GDPR. It would be like companies putting people in bomb disposal suits after sth like OSHA is implemented and complaining about the cost and lost productivity. Or to take the EU: Recently the CJEU ruled that all work time has to be tracked (not only overtime), and a German company (in Germany this wasn't mandated before) would force employees to install invasive phone apps that track location etc. and use to determine work time. Employees rightfully complaining should direct their anger at the company, not at a law that would work perfectly well with a standard punch card system
> But in these cases these are not direct unintended consequences of the legislation but rather consequences of companies failing to do their due diligence when implementing GDPR.
The complexity of additional law is part of its unintended consequences.
How is sending the recordings of one user to another a result of law complexity?
In any case, there's no increased complexity here; the Data Protection Directive (enacted in 1995) already mandated access to one's data (Article 12 - Right of access). The GDPR mostly gave some real teeth to that existing right.
> That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com"
I have not found the cultural climate on HN to be opposed to the GDPR at all. Both its goals and its implementation seem to be popular here overall, and most comments I see that are critical of it get enough downvotes to have their text significantly desaturated even if they're making a good argument.
It's my impression, though I have not worked in the field that people operating ad networks believe some kind of tracking is necessary to prevent click fraud, and do not want to sell ads free of any tracking even when they have customers asking for the option. I don't know how true this claim is or whether alternatives have been adequately explored.
What I do know is that some of the industries that use ads, such as newspapers are struggling to make enough money to continue operating. Nobody will miss a scummy adtech firm, but people might miss local news outlets. It's valid to talk about the impact on business not just in terms of profits, but also considering potential positive externalities of the continued operation of a given business.
I recall a discussion on the matter. Everyone that wasn't selling ads felt that if it was impossible to sell ads without tracking due to "click fraud", there was no obligation from society to prop up their failing business model by letting them ignore the privacy rights of the public just because it was expedient to do so.
The business model is fine, the EU and you are choosing to kill it. Not only are people arguing for no tracking they are arguing on forcing other people to live without tracking. So if someone in Europe wants a free service in exchange for their personal information they don't even have the choice. Additionally GDPR requires that businesses not restrict their products to only those that are funding it.
Well yeah, that's the meaning of laws/regulation, they apply to everyone. If someone in Europe wants a free service in exchange for [something illegal] well sorry but not allowed. That's not the hard part of this whole debate...
Except for the fact that in this case the "something illegal" is the user's own data, which they should get to decide what to do with. Isn't that the whole point of this discussion? That user's have the right to their own data? If they decide they want a free service in exchange for it, they're only 'hurting' themselves after all, and if they really have a right to their data (instead of a right to have their rulers tell them what to do with their data) then they should be able to make that choice! You can't act like everything that's "illegal" is equally bad, by grouping "personal data" with other "[something illegal]" items. That's a pretty severe case of equivocation.
I'm not sure I see that, but I'd be willing to consider that possibility if there was any data to back that up instead of hysterical op-eds and articles. I see a lot of those, but not a lot in the way of convincing evidence.
Although, FB in general doesn't seem to help the political discourse, I don't think it's anyone's job to decide what ways of communication and discussion are right for a democracy, because if you control where people can speak and what they can say, it's a short step until you control how they vote.
Wait what? I cannot say illegal things are illegal? The only association I made is that things that break the law are illegal, which is a tautology and obviously true. I never said everything illegal is the same.
Personal data has many meanings and for some, this data might bring their literal death so of course it's a serious topic. Not common in the last ~30 years of western history, but that's just a tiny slice of time/location so of course it's sensible many of us want to keep personal data, well, personal.
I apologise, I might have misunderstood your point then. I assumed you were saying something more interesting then a simple tautology. Why say a tautology?
I thought what yout were saying is that we shouldn't want it to be legal because it's illegal and therefore bad.
> Except for the fact that in this case the "something illegal" is the user's own data, which they should get to decide what to do with.
And what websites have been open with their data collection before the GDPR forced them to? When I opened the data collection dialogs introduced by the GDPR for the first time I expected maybe two or three entries, and it was near consitently closer to 40! WTF. Calling it "user choice" when the site owner deliberately ommits that kind of information is dishonest at best.
Forcing companies to tell users what they're doing with their data so the users can have informed choice isn't really my issue here.
The issue I have is the rules in what can be done with that data. Because those rules make it so that the users don't get to decide what they're OK with being done with their data.
If I'm being really honest here, the GDPR seemed pretty well intentioned, IMHO it just went a little far.
Maybe I read a different text than you but I have yet to encounter a scenario in which a user would consent to processing that the law still would not allow. Assuming the consent was gathered according to the basic principles of GDPR, fair, transparent, specific etc.
Maybe I am missing something. Would you provide examples? I would be very glad to learn if there are edge cases I may be overlooking.
The GDPR does not restrict much what you can do with personal data in principle, it does require much more effort in explicitly informing the user (also for updates) and it does grand inalienable right to users on their own data.
Those "inalienable" rights are kind of the issue here: it's telling the businesses and users how they can sell that data and what they can use it for, so it's not a choice by the user on what they do with their data, and more a collective decision with the government.
As for explicitly informing the user about what they do with their data, that part I have no quarrel with.
My point would be that there are a lot of illegal business practices. You as a costumer cannot buy expired food.
> it's telling the businesses and users how they can sell that data and what they can use it for, so it's not a choice by the user on what they do with their data, and more a collective decision with the government.
That is true, and that should happen in cases where market incentives do not align with social or public interests.
I see where your coming from, and it makes sense. Your point of view, if I understand correctly, is that the government should protect consumers from accidentally making bad choices. And I get that. It seems like it would be nice. But I don't think that's a road we want to go down, because if the government gets to make choices for people in one area, why not others? And why are we assuming that the government always knows better than the people that are actually in situations?
I mean, if I'm being honest my views on government aren't very common, so it'll probably be expedient to agree to disagree. (:
I don't think tracking adtech is a fine business model, but I'm inclined to favor technical solutions over legislative ones. There are several reasons, including: technical solutions are available to everyone, not just specific regions; technical solutions evolve and respond quickly to a changing environment; technical solutions offer users more direct control over what they will accept; technical solutions are not coercive or backed by the threat of violence.
I love it how everyone is downvoting you for pointing out something super basic: GDPR is essentially the government deciding that everyone in Europe's data belongs to the government, to decide what they can use it for and what they can't. That's not personal data rights. That's other people deciding what's best for you.
To make a little jump, this is like saying that child labor regulations mean that your children are actually property of the government. (not to show it is wrong, but that there is some background context needed)
Also I can still give facebook all my personal data. Simply facebook need to get my consent to distribute and sell it and I will forever have some basic control on what data fecebook has on me. The government has little to do in this.
Also (beware the strawman), as far as I know people cannot sell their own organs in the EU, is this a sign that your body belong to the state or that business models build on harvesting poor people organs are unjust?
So for your examples, I would say yes, yes through its rules and actions the government has clearly shown that it thinks it owns those things. Including our bodies (drug war anyone?). And a business model that pays for organs is not "unjust" but maybe a bad idea for those that would participate, obviously. I mean, the way you phrase that makes it sound like they're going to be kidnapping poor people in the streets to steal their organs if there wasn't a law against selling organs, which doesn't make sense.
> Also I can still give facebook all my personal data. Simply facebook need to get my consent to distribute and sell it and I will forever have some basic control on what data fecebook has on me. The government has little to do in this.
So long as the government doesn't force companies to provide the basic control, that's how it seems like it should work! (:
> I mean, the way you phrase that makes it sound like they're going to be kidnapping poor people in the streets to steal their organs if there wasn't a law against selling organs, which doesn't make sense.
My understanding is that figuratively speaking that is almost what happened with subprime loans.
Corporations and market can have a lot of power in performing predatory tactics. If drugs were simply legal quite a few business would sustain themselves on other people addictions.
One of the main reason we need regulations is that any sensible and obvious law (like not kidnapping people to harvest their organs) has loopholes (like keeping people poor, ignorant and devoid of mobility (lack of education, criminal convictions etc.)) so that they will agree to sell their organs.
Organ harvesting is a deeply extreme subject and obviously will not happen with or without regulations, but modern free society need are built on the free enterprise (eventually in the public sphere) of individuals and consequently they need to handle when individuals gather too much power and can destabilize societies.
Every free society has this problem (including bitcoin with a 51% attack) and needs to find a solution to both promise rewards for personal enterprise and incentives not to abuse the system (for bitcoin (IIRC) they are respectively money and loss of hardware investment)
> So long as the government doesn't force companies to provide the basic control, that's how it seems like it should work! (:
(interpreting as government should not force companies)
My problem with that is that principles do not help us distinguish fair competition from predatory unethical behavior. In the contest of personal data and privacy that is relevant as we live a completely different universe from just a few years ago.
Gossip is not illegal, but if you were magically able to listen to every conversation in a 10 km radius that would be a problem. Legal and illegal are often linked to how hard it is to do something and the scale at which you can do it.
Which is a fine argument, but people often don't consider that this kills off all the businesses that rely on those adtech companies. I think part of the problem is that it's not immediately obvious that sites like Google and YouTube only run because of that adtech.
They only rely on ads because that's the path of least resistance. If the GDPR eventually means that there is no Google or no Youtube anymore – which is not very likely – that just means the cost of Google/Youtube doesn't justify its benefits, assuming markets work at all.
This is an astute observation about this site. I too have noticed, on many topics, that the comments here tend to acquire a different character when it's the middle of the night in California.
Many in adtech do support privacy and data protection, after all they're just people too and want a good experience online.
The problem is that GDPR is well intentioned but poorly implemented, a common occurrence in politics with examples in lots of sectors. These kinds of unintended consequences are what happens when politicians don't quite understand the nuances of an industry and focus more on regulation-in-principle and showboating rather than actually effective rules.
No, unintended consequences happen in every change one implements. Show me a law of any consequence, and I'll show you some unintended consequences it brought on.
I think you are confusing unintended with unforeseen, which is a different matter. But I don't think these were unforeseen; some are problems with the implementation, which will be corrected by the companies responsible, and others are just inevitable (if you give people access to something, by definition it makes it easier for a third-party to abuse that access).
These problems were not unforeseen. The politicians were warned over and over again and you can find articles about it going back years.
The implementation problems are with the law, not the companies. There are ways to enforce data protection and privacy without such complex and nebulous laws that aren't even effective against the worst offenders.
I've seen many critics of the GDPR say something to this effect; I've yet to see any make it concrete. Without wishing to put you on the spot, what leads you to that conclusion?
Purely anecdotal, but I've had many debates over the last year on HN with people who claim that GDPR is just protectionism - rather than being a sincere effort to improve human rights online, they argue that it's just a sour-grapes effort to cripple American tech companies.
Pretty funny argument given that the big US companies are benefiting the most from it according to the article.
“The consequence was that just hours after the law’s enforcement, numerous independent ad exchanges and other vendors watched their ad demand volumes drop between 20 and 40 percent. But with agencies free to still buy demand on Google’s marketplace, demand on AdX spiked. The fact that Google’s compliance strategy has ended up hurting its competitors and redirecting higher demand back to its own marketplace, where it can guarantee it has user consent, has unsettled publishers and ad tech vendors.” (Digiday)
Having the intention to harm US companies and while implementing it actually benefiting them is not mutually exclusive.
Political motivations will be complex for anything with as wide impact and as complex as GDPR.
The perception that the US tech companies should be affected the most was certainly factored in during the political process involving thousands of people. It's debatable how small or great impact this had, not whether there was any.
> Pretty funny argument given that the big US companies are benefiting the most from it according to the article.
That would be the "unintended" part.
Only the ginormous companies can spend thousands of human hours on compliance while their smaller competitors either leave the market or get steamrolled due to the compliance costs. All this has happened before, and all this will happen again...
> Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (... companies deleting articles even when there would sufficient public interest,...)
Some of those examples were deceptively reported. For example, the doctor who asked The Guardian to take down articles about her suspension: she had successfully appealed that case, and a judge overturned her suspension and ordered the record expunged: her name was dragged through the mud on bad information. This is exactly what right to be forgotten is meant for.
>> That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies.
What do you mean? I use news.ycombinator.com every day and I consider human rights, and consumer rights such as privacy, to be extremely important. In fact, I use news.ycombinator.com because there is a very strong current in support of such principles by the users here.
There is also a strong streak of free-market capitalism and technology-first, you-can't-stop-progress techno-optimism, but that is the point. This site offers opportunities for debate.
You're assuming too much if you're extrapolating from a few comments you disagreed with to the entire userbase of this site. HackerNews is not an echo chamber. Not yet, anyway.
Not really. The GDPR stipulates a right to be forgotten [1] with the following exceptions:
> 3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
> (a) for exercising the right of freedom of expression and information;
> (b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
> (c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
> (d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
> (e) for the establishment, exercise or defence of legal claims.
If the fundamental thesis is that "the market fails" or that "corporations are irresponsible", then at the very least it should be predictable that some of these regulations will have the real negative consequences (which I think we can agree some of these are) expressed in this article. The goal of this realization is not necessarily to disparage the GDPR, but hopefully to learn and perhaps put together a more precise or better iteration in place that avoids these pitfalls. For example:
> Spotify not asking for 2FA/email confirmation for the bulk download
I'm not extremely familiar with the letter of the law, but if it doesn't specify that you need 2FA/email, and there are clear fines/downsides to not complying, I do not see how this is not a predictable issue that would come up. The incentive is to comply, since you've already put in the work to make it possible, and there are onerous punishments for not doing so. In other words, a false negative (disallowing the download) can be potentially perceived as much worse than a false positive (allowing the download). This seems built-in: the goal of the law was to give it teeth to allow the user to get this data. If we just default to "its the companies fault for not applying an additional layer of thought to all this", then whether its true or not (and I agree it is!), it does not realistically solve the problem - establishing blame doesn't necessarily provide a path to making this less likely in the future as long as the equation is still heavily weighted towards disincentivizing false negatives. This is another way of saying: if we want to characterize corporations as lazy/malicious/what-have-you, then we can't then be Pikachu-surprised-face when they act that way under the letter of the law like some monkey's paw scenario: we should instead "aw shucks, fool me once" and try to come up with something better.
> companies deleting articles even when there would sufficient public interest
Similarly, we should try to predict that it is entirely plausible that the rights will be attempted to be abused, or leveraged, by those that it provides an obvious benefit for, even if it is malicious. Here again it is interesting that we begin with the thesis that "we need these laws because companies have proven not sufficiently responsible enough on their own" and yet then immediately make a law that is vague and thus defers major parts of the decision to these same companies. Many times this ultimately comes down to litigation where the boundaries of laws are worked out, and this is a very reasonable response: its only been a year, the courts will hopefully work out when these rules are mis-applied. However, it is on us to make sure we litigate "too much" right to forget (as in the cases here) and not just cases where companies refuse to forget. If not, the courts will send a clear message that it is perfectly fine to blindly abide by every request as the path of least resistance. Again: the premise is that they don't care, and we still haven't figured out how to legislate caring.
> I'm not extremely familiar with the letter of the law, but if it doesn't specify that you need 2FA/email
The Regulation doesn't mandate specific technical implementations anywhere; it leaves that to the industry, which is the expert in that regard. But on the subject of the Right of Access it does explicitly say:
"The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers"
It seems to me that not using 2FA/email means they haven't used all reasonable measures to verify the identity.
This ideological purity doesn't work well in the real world, and it's not about profits either.
People don't care about privacy as much as you imagine them to, especially if they have to give up everything they get for ads today. One look at what people willingly share to the world on social media shows that.
But powerful monopolies are a problem and market competition is the correct answer to that power. Regulation isn't a magic cure and should be used to place guardrails on the market, but in this case could've been written far better to provide data protection without entrenching the major players even further.
That opening paragraph already speaks to the over-elevation of the market over any other concerns. So it perfectly fits onto "news.ycombinator.com". Human rights, including privacy and data rights, are more important than the profits of some companies
Most examples in the text are, for instance, related to companies failing to properly implement the GDPR (Amazon sending data to the wrong person, Spotify not asking for 2FA/email confirmation for the bulk download, companies deleting articles even when there would sufficient public interest, Ad vendors failing to ensure compliance and therefore seeing drops in demand, ...), that is, market failures - something this site would probably not call out but rather attribute it to the legislation.