TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

99 pointsby taubekabout 1 month ago

18 comments

sega_saiabout 1 month ago
I think the title is clickbait'y. The EU proposes to simplify the law rather than abolish it, which makes sense to me.
评论 #43611209 未加载
评论 #43613309 未加载
评论 #43611067 未加载
terminalbraidabout 1 month ago
At the minimum I&#x27;d hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations.<p>Interesting timing with the digital sovereignty movement.
评论 #43611193 未加载
评论 #43611131 未加载
评论 #43611188 未加载
评论 #43610863 未加载
评论 #43611061 未加载
评论 #43611012 未加载
评论 #43611237 未加载
评论 #43611241 未加载
评论 #43610915 未加载
评论 #43610914 未加载
评论 #43610832 未加载
评论 #43615515 未加载
评论 #43630473 未加载
评论 #43610931 未加载
xeonmcabout 1 month ago
Quite apropos that this article was cookie-walled with a &quot;We value your privacy. Customize&#x2F;Agree&quot; modal screen
评论 #43611158 未加载
bcyeabout 1 month ago
GDPR is not complex because it is hard to comply with but because seemingly no one wants to.<p>EU-US data transfers have been declared illegal numerous times [1], but instead of supporting European cloud providers those decisions are barely enforced and quickly circumvented by a new data transfer act.<p>Cookie banners are not hard to implement if you don&#x27;t try to share user data with your &quot;864 most trusted partners&quot;, there are clear guidelines [2] now on how they need to be designed, but instead of criticising these not being properly enforced, the requirement for them itself is criticised.<p>How is it that Meta can regular break the law, with 7 of the 10 highest fines (or probably around a third of all fines) going against them [3] with seemingly no action taken to prevent this from continuing onwards.<p>noyb has managed to achieve more than a billion euro in fines with only 6 million euros in funding, we could be focusing on supporting NGOs doing incredible work for their budget and getting our DPAs to probably enforce the law.<p>The issue with GDPR is not the law but the seeming unwillingness to enforce it leading to unclarity what is expected and what not. [4]<p>[1]: <a href="https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;23-years-illegal-data-transfers-due-inactive-dpas-and-new-eu-us-deals" rel="nofollow">https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;23-years-illegal-data-transfers-due-inact...</a> [2]: <a href="https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;noybs-consent-banner-report-how-authorities-actually-decide" rel="nofollow">https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;noybs-consent-banner-report-how-authoriti...</a> [3]: <a href="https:&#x2F;&#x2F;www.enforcementtracker.com&#x2F;?insights" rel="nofollow">https:&#x2F;&#x2F;www.enforcementtracker.com&#x2F;?insights</a> [4]: <a href="https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;data-protection-day-only-13-cases-eu-dpas-result-fine" rel="nofollow">https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;data-protection-day-only-13-cases-eu-dpas...</a>
评论 #43611444 未加载
more_cornabout 1 month ago
Let’s roll back the stupid cookie notification. Replace it with “sites must respect the user setting in the browser” so we can set it once and be done with all that nonsense.
M95Dabout 1 month ago
&gt; &quot;the simplification plan will focus on reporting requirements for organizations with less than 500 people&quot;<p>I consider this extremely bad! It should be based on revenue, not people.<p>I can imagine extremely big data trading companies with less than 500 people. I can even imagine Meta&#x2F;Facebook doing various employee redistribution shenanigans and managing to fit inside that limit.
Woodiabout 1 month ago
So cookie banners go first? As an obsolote &quot;requirement&quot; when all that tracking will be finaly banned? Right ? Just like paper journals - they don&#x27;t do any identify-your-page-flipper...<p>And employer will be finally allowed to know his employee name and address?? Without additional paper trail? No, they won&#x27;t allow that, it will be to sane.
digganabout 1 month ago
&gt; The GDPR is seen as one of Europe&#x27;s most complex pieces of legislation by the technology sector<p>Really? Now I&#x27;m no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document (<a href="https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;PDF&#x2F;?uri=CELEX:32016R0679" rel="nofollow">https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;PDF&#x2F;?uri=CELE...</a>) is only 88 pages long, this cannot realistically be &quot;one of Europe&#x27;s most complex pieces of legislation&quot;. A lot of privacy-conscious SME basically had to do nothing to be compliant, telling me it seems to hit the mark of being not too complicated.<p>Most of the cases I&#x27;ve heard people complaining about GDPR being &quot;complicated&quot; or &quot;impossible to implement correctly&quot; have been from people&#x2F;organizations who are breaking GDPR, and have no way of reaching compliance without removing things they ultimately earn money from, which in my mind is the exact purpose of GDPR. Most orgs don&#x27;t seem to be introspective enough to understand why they are having such a hard time with GDPR though.<p>I hope that their proposed &quot;simplification package&quot; doesn&#x27;t actually remove what makes GDPR useful and good, but since they seem to be making a bunch of bad-faith arguments for this simplification, I&#x27;m not super optimistic.
评论 #43610900 未加载
评论 #43610858 未加载
评论 #43610898 未加载
评论 #43611199 未加载
评论 #43611184 未加载
评论 #43614167 未加载
xinayderabout 1 month ago
I see lots of comments supporting it but I can see they are mostly from the business side. What does &quot;simplification&quot; mean for users? I&#x27;m expecting companies to be given way more room for exploiting user consent for shady data collection practices.
JCWasmx86about 1 month ago
If the GDPR is simplified, the fines should be drastically raised. (At least for companies) E.g. to minimum 20% of the global last years revenue, for bigger companies (FAANG-Scale) to minimum 70% of the revenue. The GDPR must make companies afraid of breaking the law.
评论 #43613889 未加载
m00dyabout 1 month ago
Cookie consent banners might be one of the most frustrating aspects of modern web browsing. A better solution could have been a thoughtful extension or fork of HTTP, specifically for EU implementations, something that handles consent through HTTP headers instead. That would allow users to easily opt in or out, either globally or per tab, without the clutter. Ideally, technical regulations like these should be designed by people with a strong understanding of technology, to ensure practical and user-friendly solutions.
评论 #43611107 未加载
评论 #43611571 未加载
_petroniusabout 1 month ago
As a big GDPR fanboy, one thing I would be happy for them to remove is the portability between providers requirement: it was essentially dead on arrival, is not implemented, and could be done away with.<p>The other EU-level regulation that needs to be either removed or completely rethought (since it will clearly not be enforced in a way that makes sense) is the cookie regulation. It was well-intentioned, badly implemented, and the GDPR addresses more of the core problems, it is time to do away with it.<p>But as a whole, I push back against the idea that deregulation is the primary way in which the EU can or should become competitive with the US on technology. Lack of public investment, worse ability for companies to offer equity incentives, and timid private investment are all much bigger problems than consumer protection regulations.
评论 #43615956 未加载
borutoabout 1 month ago
I don&#x27;t live in Europe. I still believe GDPR is god send. I just send a chat-gpt generated e-mail to the company to forget me citing GDPR and voila it just works.<p>just have to lie as bit that i am a resident of EU though.
perch56about 1 month ago
Before tossing GDPR onto the bonfire, perhaps the EU should first look at DORA.
jdiez17about 1 month ago
Uh oh. I&#x27;m all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you&#x27;re not doing nasty stuff with people&#x27;s data, 2) actually needed.<p>Any opposing views?
评论 #43611636 未加载
评论 #43611183 未加载
评论 #43611002 未加载
评论 #43611293 未加载
juntoabout 1 month ago
Whilst I don’t like cookie banner, I personally appreciate the EU GDPR simple style of cookie banners which are simply three options:<p>- accept all - necessary only - reject all<p>So many websites outside the EU have a mass of dark patterns for which I increasingly reject all or leave the website.<p>GDPR is really simple.<p>Only store data that you really need to service the customer’s needs, always permit the customer to correct incorrect data and allow them to delete it unless you have a legal reason to keep it. Report GDPR failures within 72 hours where customer data has been compromised and treat PII carefully.<p>In the US - fuck the customer.<p>I know which I prefer.
cbmaskabout 1 month ago
The politicians cite competitiveness as the motivator for relaxing the GDPR. The real reason for the EU lagging behind the US in &quot;big tech&quot; is of course the lack of venture capital and the red tape in registering corporations.<p>The GDPR does not prevent US big tech from operating in the EU.<p>As it stands, this is just another attack on EU citizens&#x27; rights. It is also the least of the EU&#x27;s current problems. De-industrialization due to high energy prices is, but of course von der Leyen will not mention <i>that</i>.
评论 #43613886 未加载
评论 #43614865 未加载
评论 #43610975 未加载
评论 #43615267 未加载
djha-skinabout 1 month ago
I think simplifying the law for companies smaller than the 500 person cutt-off makes sense. The Brussels effect is strong. I was just in a company of approximately ~150 people in America and a significant portion of our time went to GDPR&#x2F;California law takedown requests. User data was everywhere, it was a nightmare. No one thinks of this stuff when everyone is still in sink or swim mode. We got it done though.<p>Maybe it&#x27;s an argument for the other side though as well. The architecture of the system was designed to track people as much as possible so we could do A&#x2F;B, app design, and marketing more effectively. It felt like it was the company&#x27;s life blood.<p>I would say the law should at least make people get their architecture right when small so that when they&#x27;re big it&#x27;s not <i>impossible</i> to comply later.<p>One last thought: our company was small in head count but is getting much bigger right now in revenue. I&#x27;ve heard of small head count, billion dollar companies. What of them?
评论 #43613542 未加载