Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a feature, not a bug.

I consider not being able to run an otherwise reasonable business at all a bug.

It means you don't get to use personal information for marketing purposes unless the customer really wants to to and says so.

It also means, for example, that you can't charge them using a US-based payment service, provide whatever product or service they are requesting if it involves interacting with a US supplier and providing their personal details for delivery or authorising access, or use US-based administrative services to help run your business more efficiently, without your customers' explicit consent, even if this is only to provide exactly what they've just asked you to provide.



> not being able to run an otherwise reasonable business at all a bug.

This is question begging. If your business model depends on openly breaking the law, it's not a reasonable business model.

If the end of slavery causes your cotton business to become unprofitable, it's not an attack on the cotton industry, it's still an attack on slavery.


If your business model depends on openly breaking the law, it's not a reasonable business model.

Alternative possibility: The law is broken.

What if your business model is otherwise perfectly reasonable and acceptable to all of your customers, and it doesn't rely on breaking the law at all, until the very governments who are entrusted with producing reasonable, consistent laws to support their populations are the ones who screw it up? Should we just close down all European companies doing business with US online services right now, today?

As far as I can see, that is technically what this ruling will lead to. Somehow, I don't think most people in either Europe or the US would consider the resulting collapse of both regions' economies to be desirable, and I doubt that was the desired outcome when the European lawmakers established the basic data protection principles at the heart of this. Those same lawmakers, after all, are the ones who saw fit to provide a Safe Harbor mechanism to facilitate reasonable international trade in the first place.

If the end of slavery causes your cotton business to become unprofitable, it's not an attack on the cotton industry, it's still an attack on slavery.

And what about providing exactly the service your customers were asking for, but using say a US-based payment service that is openly disclosed in your privacy policy? Maybe that is now illegal on a technicality, because you didn't get active consent for using that US service to charge their card. What if your Europe-based bank didn't have explicit permission from your customer to communicate with a US-based card scheme to authorise your customer's card, for that matter?

Will it really help to confront customers with yet more mandatory legalese at the online checkout that just describes what everyone expects to be happening anyway? Who is really going to benefit from that? I'm all for reasonable protection of personal data and proper safeguards for privacy, but when you go so far that you stop people transferring personal data in ways that are necessary to provide the exact product or service that a customer is deliberately requesting and would be reasonably expected by that customer, you've lost the plot and your system needs fixing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: