Remix.run Logo
maccard 14 hours ago

Well no, the cookie banner is a well intentioned but flawed and poorly designed law. Any law that is that technically specific but relies on people without an understanding of how it works is doomed to repeat the same fate. The eu should have seen prop 65 and not sleepwalked back into it.

nolok 14 hours ago | parent | next [-]

1. The EU works on intent of the law rather than specific wording and precedence.

2. The law is a very simple "if you want to do it, you have to make sure they know", intended to force information without creating excessive administrative / legal / tech burden, please inform me about what other way you would present it that would reach the goal without being subject to malicious compliance ?

maccard 13 hours ago | parent [-]

I understand. I'm generally a proponent of the spirit of the law rather than the wording of the law, and I've argued that is how the EU works here in the past. I think GDPR is a much, much better attempt at solving the problem, and has made meaningful change in tech industries. The ePrivacy directive just added pseudo-mandatory popups to every company without a technical lawyer.

spwa4 13 hours ago | parent [-]

Why? The whole point of the GPDR was to prevent medical information being used for insurance and all sorts of purposes.

Then come the lists of what exceptions are approved. Your medical info is used for divorces (anything involving court cases, anything involving criminal law), the police has access to it, your mayor has access to it, tax departments have access to it (think you can not pay tax and pay for your kid's cancer treatment instead? In Europe, think again). Insurance (if you get treatment for getting hurt in traffic your car insurance goes up). Unemployment (if you get treated for anything drug-related ...). Hospitals and doctors can use your medical information without your permission (for billing, for other treatments, for deciding if you should be interned, ...). And so on and so forth.

Oh and there are even silent exceptions. You see, YOU can't sue anyone under the GPDR. You can only ask a specific "supervisory authority" (you can't even choose which one)

They are under control of the executive, and so it is in most cases the currently elected party that decides if your GPDR complaint does anything, NOT the courts. Not the police. Not the public prosecutor. None of that. And it's even closed on the back end: you don't agree with these "supervisory authority"'s actions? Doesn't matter if you're complainant or defendant. You can't sue them either. You can't get a judge on your case, only appointed politicians.

There are even organizations that the GPDR supposedly applies to that have their own supervisory authority. Interpol violated your rights? No worries, file your complaint here in this building. You know, the building with "Interpol" on it in big letters.

So really, we do not even know the full list of exceptions.

More generally, the GPDR was supposed to prevent further encroachment of all sorts of organizations on privacy, with a big focus on medical data. It has achieved the opposite of that. FOR NOW (and not in every country) the only way to get a private medical file is to only use private medical care. For now that is still possible.

It's like the DMA (Digital Markets Act). Prevents organizations from using control of the OS to implement policy. There's a few exceptions though. Google gets an exception. Apple gets an exception. Through specific deals made with these organizations and the EU commissioner of

Nobody seems to have thought to scream into the commissions face: "THEN WHAT'S THE POINT?".

Well, who made those deals? Thierry Breton. He currently serves as a remunerated member of Bank of America’s Global Advisory Council (who have huge investments in Alphabet and Apple).

Yeah, I get why you want to focus on the intent only and not on what practically happened. Theory and practice are very, very different and the EU is incredibly pro-business and uses their power to literally grant billionaires exceptions to laws. That's how Goldman Sachs got it's first communist president (Barosso, who saved Goldman Sachs as president of the EU commission). That's reality, but of course the intent is thoroughly disguised, and you don't want to talk about the difference.

nolok 9 hours ago | parent [-]

Gdpr whole point was about insurance? Can you please diversify your news source and educate yourself? I didn't even bother to read your pamphlet of a comment after seeing such an obviously wrong first sentence

spwa4 8 hours ago | parent [-]

No it was about privacy. Specifically given as an example in the actual law, privacy of medical data FROM insurance companies. But of course privacy from everyone.

The goal was not even remotely achieved, and this was 100% on purpose.

tchalla 14 hours ago | parent | prev | next [-]

There a reason why we have courts. Laws aren’t algorithms despite what the tech world wet dream might want them to be.

watwut 14 hours ago | parent | prev [-]

Then again, the very same people complain about GDPR not being technically super specific.

At some point we have to accept the pattern. People with ideological objections against any limits at all will try to frame any regulation as stupid, regardless of what is in it.