Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But it's clear GDPR isn't working as intended. The compliance costs are absolutely enormous and EU member state national courts are leading to rule virtually every tech product being in noncompliance with it, as it so broad.

It's likely to lead to the quasi-ban of LLMs sooner rather than later in the EU. This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't.

While I lean remain; some people seem to have serious blind spots that a _lot_ of EU legislation is poorly thought out and given the slow pace of change extremely hard to revoke once it is in force (cf the ridiculous cookie banners; which were implemented in law in 2002 and _still_ haven't been changed, despite 10+ years of efforts to do so in the EU institutions). It's going to be even worse with the EU Digital Services Act, where being in compliance with GDPR and the DSA is a lawyers dream, as from what I understand it directly contradicts each other.



> The compliance costs are absolutely enormous and EU member state national courts are leading to rule virtually every tech product being in noncompliance with it, as it so broad.

Isn't that intended?


Not really. The ideal is to have companies that are delivering functionality while still respecting user's data rights. Apple's products are probably the closest to this ideal, given their incentives aren't about harvesting user data to sell ads. I'm sure there are some techno-alarmists that would like to either shut everything or significantly slow the pace of innovation - but the broader vision is one of delivering both value and safety without unreasonable overhead.


Lets face it, an above average number of people commenting here work in covertly monetizing our personal data, as there seems to be quite a few of them rubbed the wrong way by the GDPR I can only conclude it's working rather well.


That's a significant group of people for sure, but I'd add two more groups:

- A group that think GDPR = cookie law and there's nothing more written in it. Never any discussion about, say, forcing companies to report a data breach within 72h of detection. Or about being able to download your data, or forcing a company to remove your data, or...

- A group that think passing a new law = everyone is going to comply immediately and one random website that they know of that doesn't comply but wasn't sued yet into submission = GDPR was a mistake.


"There's no way to rule honest men..."


Right, it isn't working. Facebook/Meta was fined a billion today, but still will not respect user's privacy.


Sounds like it needs stronger teeth. Not to be neutered.


I feel like "it doesn't work as intended so it never will, do not try" - an argument very frequently said by cynics, is the antithesis of the indomitable human spirit and human achievement. It's very harmful to anyone trying to do anything challenging.

Imagine if this was one of the principal virtues in human civilizations. Where would humanity be? Would we know the Earth is round and not the centre of the universe? Would we have vaccines or antibiotics? Would we have most of our art and literature? Would simple technologies like irrigation even exist? We would probably not have any advancements past about middle ages.

I don't understand why so many cynics tell this to others these days. Do they genuinely have a mindset that nothing is worth trying if it failed the first time?


> Do they genuinely have a mindset that nothing is worth trying if it failed the first time?

No. But the way you first picked to do the thing is very likely impossible to make work. Don't decide on a mechanism, like cookies, and fixate on it without regard for practicality or effectiveness.

Preventing invisible tracking is probably a good goal that's worth iterating on but making sites pop up a list of good and bad tracking and being allowed to track the people who accidentally don't click "No!" seems like an entirely failed way to go about this.

If tracking is bad then stop it for everyone, not just people who clicked the correct thing. If some tracking is generally bad but allowable for certain functionality then mandate that tracking is only applied once the user had opted in, etc. Don't make users mark "Don't steal my organs while I sleep" on the hotel paperwork.


> No. But the way you first picked to do the thing is very likely impossible to make work. Don't decide on a mechanism, like cookies, and fixate on it without regard for practicality or effectiveness.

GDPR is not about cookies. Cookies are mentioned only once in the entire legal text as an example of a technology that can be used to associate users with personally identifiable data. If there is no risk for this association, GDPR does not care about cookies.

GDPR is about ethically acquiring and handling personal data.


I hoped it was clear that I was referencing the previous post, where compliance costs where said to be too high, by countering that fines are too low.

Yes, we need more effective GDPR, not less.


The GDPR allows for a bunch more escalations. Both in fines (that isn't 4% of global revenue yet) and in consequences (e.g. being all but expelled from the EU single market)


I’m in the EU this week and I had no idea that the cookie banners were so obnoxious, every site has a huge page blocking banner, and plenty of US news sites seem to block EU traffic entirely. I had to use a VPN to access some sites.


Funnily enough the ones that block are usually "State/City local news" website, which have a tiny, if not null EU audience already (meaning in practice nobody would care)

Now if the popups are obnoxious whose fault is it? (To answer that just notice how many other obnoxious popups/overlays/etc the same site has about other stuff)


All sites not run by shit-heads have a "reject all non-essential cookies and close button" clearly displayed.

They could just choose to honour "do not track", but I realise they want the money. Most large sites seem to have added the "reject all" button when it appeared that this was necessary for compliance. Those that did not don't care if they comply.

Obnoxious banners are a choice. If we didn't have them the choices of site -owner's wouldn't be less obnoxious, they would just be hidden.

It's like the warning your car makes 'put your seatbelt on'; sucks, but better than it not existing.


> While I lean remain; some people seem to have serious blind spots that a _lot_ of EU legislation is poorly thought

Oh, I'm not blind to it. My calculation is a simple one: looking at where we were and where are now, where would I prefer to be? For me it's not a difficult conclusion.

> This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't

Sure, but your argument completely disregards the privacy concerns which is the reason the EU has done what it's done. It's possible for Europe to decide that it's worth the cost in potential business to protect the privacy of its citizens. That's essentially what GDPR decided, after all.

(FWIW I've worked on GDPR implementations, I'm not so convinced it's a failure. It lead to a very meaningful drop in the amount of personal information the company was storing. The compliance costs were not particularly huge ongoing costs, just upfront implementation ones)


The EU isn't really protecting the privacy of its citizens with the GDPR as much as people think for at least two reasons.

First there is the practical implementation. As we've seen the current stand-off between US government security laws and EU government privacy laws is still being decided in favour of transferring personal data for processing in the US. That might even be the preferable way to break the deadlock for the immediate future because the cost to the European economy and particularly the tech sector of suddenly cutting off all US-based services when the EU has no native competitors would be enormous and as things stand that appears to be the only safe way to guarantee legal compliance on both sides of the Atlantic.

There is also the hypocrisy angle. The GDPR allows for EU government access to personal data under their own security laws that is not so different to what the US laws allow the US government to have. There are definitely some double standards in the typical arguments about how the GDPR protects personal data from unwarranted government intrusion and overly broad security laws.

I'm also firmly in the pro-privacy camp on principle but the rules do still need to be workable or everyone is just going to ignore them anyway. It's not clear to me that the way the GDPR is currently being used against big US tech companies is a good way to go.


> cutting off all US-based services when the EU has no native competitors would be enormous

I think you have it wrong way round - EU business was late, and 5he market was sevured by US corps. I dont think EU will ban US business, but if they did, that would create opportunity for homegrown co petition to emerge. By now, cloud services are not rocket science.


I dont think EU will ban US business, but if they did, that would create opportunity for homegrown co petition to emerge.

That's one theory. The problem is the several years of lag time between the opportunity being created and anyone actually exploiting it at scale. In the meantime countless SMEs that depend on modern online services for their day to day operations would probably have failed.

By now, cloud services are not rocket science.

And yet the US keeps producing them at a far higher rate than we do over here. Much of that has been due to the VCs almost casually giving away millions in funding in the hope of backing the next unicorn among all the failures, which is an investment culture you don't see so much in Europe. But there are also reasons investors tend to favour some countries over others and the regulatory environment is usually second on that list (after taxes/subsidies) if it's not first.

And in their regulatory environments the EU and US are almost polar opposites. The US is very lightly regulated (apart from the problems of regulatory capture, where the US seems to do much worse when it does happen) but that means tech firms engage in practices we might not like. The EU is very heavily regulated but that means added overheads even for well-behaved businesses that can eventually add up to being less competitive in a global market. Maybe there is a sweet spot in between but certainly neither the US nor the EU have found it yet.


What does "working as intended" means?

Some sibling comments challenge that it doesn't help reduce the amount of private data stored.

I would argue that GDPR is working as intended on the economic war front. The US weaponized their extraterritorial anti-corruption laws, China is also building similar legal weapons, GDPR is part of the european answer to that: a framework to catch up with other super powers who can pressure foreign companies whenever it pleases them.


I did quite a bit of work implementing GDPR compliance not long before it became enforceable and it was quite easy? Basically we had to make sure we knew where data was kept and how to delete/retrieve it. The biggest piece of work was making sure our logs didn't have personal info in them (sensible anyway imo) and adding proper log rotation.

Like every company will be different, but you really should know where your data is kept.


How _do_ you make an LLM trained on people's personal information comply with privacy law?


Depends on how you define privacy. If definitely accessing the data to train it was illegal/wrong, then you can't. But if that is ok, then the question is to what application will the LLM be applied? A generalized chat interface probably would be able to regurgitate private information. But things like reasoning engine, or recommendation system plugged into other downstream systems where the raw output isn't expose very much could work. There are a hundred new startups everyday it seems that are some kind of wrapper on top of an LLM applied to a niche use case. Many of these should be able to preserve privacy.


> It's likely to lead to the quasi-ban of LLMs sooner rather than later in the EU

It won't be GDPR but newer regs

> This is going to be an enormous challenge to the EUs tech industry if UK and US firms can use LLMs but EU companies can't

I'm sure they'll find a way

> a _lot_ of EU legislation is poorly thought out and given the slow pace of change extremely hard to revoke once it is in force

Kinda, but things don't change only by the original legislative process, but by subsequent regulations, agency reviews (like data protection organisms), judicial reviews, etc

> which were implemented in law in 2002 and _still_ haven't been changed, despite 10+ years of efforts to do so in the EU institutions

I'd love to know what kind of discussions went in regards to the cookie law and GDPR in legislative reviews. I'm sure it's all logged in a very verbose way in multiple websites and it would be some effort to get it all together

And the AI act worries me, but we know that actual enforcement and definitions and wiggle rooms exists (and as with GDPR, enforcement is kinda patchy)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: