As its the EU and regulation, its time to trott out your hobby horse.
So let me trot out mine: regulation is good so long as it is backed up by even handed, robust, transparent, quick and effective sanctions.
the Online safety act is a good example of a bad law, which is enforced badly. The first big test (X producing industrial quantities of minors engaging in sexual activity) was failed. Had a small company produced a service that did they same thing, they would have been fined, servers ceased and owners thrown in jail. X got a letter saying they should stop.
An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves.
Old school methods like what McDonald's use, literally allow the customer to see in to the kitchen are very effective.
Not always ideal for every type establishment but I've seen high end Indian restaurants even do it by having the POS at the back where you can see the kitchen when paying which keeps the noise separate for the desired quiet atmosphere of a fine dining restaurant
I'm not sure how to translate this to the smartphone market though. Fairphone and LaJolla seem to do well in this regard though so back to brand reputation for a lot of this.
I don't recall any where it was every easy to see into the kitchen. Yes you could see some of the fryers where they made french fries, and sort of see into the kitchen but there was a lot of food-holding bins, drink dispensers, and other equipment etc. obscuring most of it.
> I'm not sure how to translate this to the smartphone market though. Fairphone and LaJolla seem to do well in this regard though so back to brand reputation for a lot of this.
I'm not here with a silver bullet or anything, but I'd say the EU's energy efficiency labeling works well and has a fairly low level of being gamed/falsified.
I don't think there's any big reason why the EU couldn't enforce labeling of a similar kind to IFixit's repair-ability scoring[0] for set devices.
On a separate note, the article mentions the lousy attempts some smart phone makers are guilty of with regards to repair instructions:
> Some records even refer customers to Temu or AliExpress for spare parts and repair instructions.
There are at least a lot less smart phone manufacturers than restaurants and cafes (comparing to scores on the doors) - if the EU really wanted to, it wouldn't be a huge resource to produce clear guidance on what expectations are for smart phone spare part provision, and issue fines whenever they're violated (you might think is a bad idea, and too much regulation, but my point is just that it's at least feasible)
SOrry, yes I should point out its not perfect. The scores on the doors website is also a partial remedy for this. But I should concede that no solution is perfect, and you still need to allow for the evolution of fraudsters.
> I'm not sure how to translate this to the smartphone market though
Me neither, The pre-existing ways are independent lab testing ( euro-ncap for cars, or ifixit) or the "you have to pay for testing" like for large white goods. None of those work if they are not enforced though....
I am unfamiliar with these matters and I am also unsure what specifically you are referring to.
But in general, if big companies get away with wrongdoings by receiving a gentle slap on their fingers, figuratively speaking, it will, in my opinion, lead to no change whatsoever.
Because if there are no material consequences for wrongdoings, they probably would not care. And there are very few kinds of actually material consequences for big companies. One of them being a really hefty fine.
> Because if there are no material consequences for wrongdoings, they probably would not care. And there are very few kinds of actually material consequences for big companies. One of them being a really hefty fine.
In mono/oligo-poly situations there's no really such a thing as "a really hefty fine". Either the cost will be happily trickled to the very public that are being wronged or the fine is effectively unsurvivably hefty, which noone would levy against a too-big-to-fail entity.
Look at the recent fine for Meta for example. Settling a case against one of the core monopolic drivers for a couple percentage points of early revenue is peanuts. I can't believe the exec suite[-s] are thinking anything else than "which anti-consumer behavior can we buy indulgence for?", they would be stupid not to at these discounted rates.
I'm half joking here, but at this point it feels like the only reasonable way to instill some fear against building Torment Nexus and cyberpunk dystopia would be personal criminal liability of the boards and exec suites that is impossible to settle.
Sadly that mess had a political component, any attempt to regulate US big tech results in howls from over the Atlantic.
Frankly, I'd prefer it if we just let them howl and said fuck it more but it's probably a good job I'm not making those decisions (and in honesty the picture is complex for companies that size/the politics).
Ironically the fact that the howls need to come from the other side of the Atlantic, rather than having any domestically, should tell anyone all they need to know about the situation.
Don't disagree but the results are impossible to know from the US side, politicians have to balance everything and decide whether it's worth the political capital.
Not like it's the only issue in US/UK relations these days either.
> Ironically the fact that the howls need to come from the other side of the Atlantic, rather than having any domestically, should tell anyone all they need to know about the situation.
Europeans by and large don't care about American companies these days. They use American software products because frequently there are no alternatives. And most of the news about them are negative.
They also totally don't care bout Chinese companies, they use those products because there are really no alternatives. Apple and Samsung (reluctantly) comply. I guess we know which other companies don't?
South Korea is a very dynamic, tech heavy country and it hasn't managed to push any software product as a market leader.
The EU is bigger, but it's fractured, so functionally it's basically 2-3x South Korea in terms of "software power". And that's not enough to compete with the much larger US juggernaut. Only China has managed to hold its own by simply banning US software all together.
I'm actually all in favor of the EU banning all American software. Fairly sure that after a huge initial tumble a healthy EU software market would thrive.
Edit: I need to brace myself, the Americans are waking up :-)))
Europe had the opportunity to create a silicon valley 30 years ago. They fumbled it so badly that most euro tech talent went to the US and worked or even founded their companies there. They still have not (and likely never will) implement the general reforms needed to create fertile grounds for tech to compete with the US.
If the current EU mindset existed 150 years ago, they would have banned steam engines because they are too loud and annoying. That's the level of shortsighted immediate gratification we are dealing with.
I don't know what SK has to do with this, they are basically still close to an emerging economy. Europe had a roaring economy when SK was still mostly farming.
From the article, it seems more about chinese brands, no?
> Some records even refer customers to Temu or AliExpress for spare parts and repair instructions.
> But even for products that are technically compliant, the listed weblink still rarely offers a direct path to parts prices. For major brands such as Apple and Samsung, it can take some clicking around before you find what you need, Right to Repair says.
There seems to be a very common idea why the EU is failing dramatically with these ideas that I didnt seem to understand. Knowing it has a US political context suddenly makes everything a little less weird.
> An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves.
> Another good example is NCAP ratings.
Worth noting that NCAP and Scores on the Doors are not regulators. NCAP is an industry body; SotDs is run by TripAdvisor.
Yes, Twitter frontpage should include a little counter with how much child exploitation it has facilitated today.
I don't think there's a single politician in Bruxelles that wouldn't love to come down hard on X. There is no love for Elon in those circles anymore. The problem is that he's attached himself to international politics through his daddy. Trump has threatened the EU with strict sanctions if they levy any sort of proportional fine to US tech companies.
The problem is no longer capitalist liberalism. The new challenge is American Fascism.
I'm getting sick of this hyperbole, if you want to see a real fascist regime you can look at Iran that killed several thousands of its own people over the course of a week shortly before the current hostilities, in contrast in almost a year of protests 3 people were killed in the US under circumstances that were at least debateable. Or maybe China that literally was rounding up ethnic minorities and sending them to rededucation camps while performing genocide. Or maybe Russia whose government is current grabbing their people giving them 2 weeks of training and then sending hundreds of thousands of young men to die on the front lines to seize their neighbors territory.
In contrast the US is, not following UK rules about taking down websites, is downsizing some government departments, and oh the horror removing people from the country who entered illegally?
I'm not saying things are great, I'm not saying I approve of what is going on right now, or that we are headed in the right direction, but this hysterical exaggeration helps no one and makes any semblance of progress less likely as it alienates more moderate people that would be willing to listen to your side. But it does give you a hit of righteous indignation on the Internet so score one for you, your only continuing to nip at the fraying social fabric of our society but you are getting updoots so good on that.
The image literally says "inspired by Starship Troopers". Which was inspired by fascism and Nazi uniforms in particular.
> if you want to see a real fascist regime
Is it not worth looking at how such regimes got there? Maybe as a preventative? Do we have to wait for it to go all the way to Holocausts before we go "uh oh, should've said something"?
An objectively good and very stylish film. It is like 30 years old and still grate to watch.
> Which was inspired by fascism and Nazi uniforms
And what exactly does it change? Are you afraid that particular type of pants will make people Nazi or what?
> it not worth looking at how such regimes got there? Maybe as a preventative?
The government get to many tools to influence every aspect of citizens' lives, and then uses those tools to get rid of all opposing voices. That is far more relevant to the Europe than to the US.
> An objectively good and very stylish film. It is like 30 years old and still grate to watch.
Yes, it's a great satire. You get problems when, as with The Boys' Homelander, people apparently can't figure out who the bad guys are.
> And what exactly does it change? Are you afraid that particular type of pants will make people Nazi or what?
I am afraid of people who are super into the Nazi aesthetic, yes, especially when they run the country I live in.
> The government get to many tools to influence every aspect of citizens' lives, and then uses those tools to get rid of all opposing voices. That is far more relevant to the Europe than to the US.
I don't care about any of your examples. I am explicitly not talking about Iran, China, Russia, Takedown requests by the UK, "downsizing" the government, or "remigration". I have opinions about all that, but it is not what I'm talking about here.
I am talking about weaponized trade relations, such as coupling embargoes or tariffs, to inner market fines. I am talking about explicitly threatening allies for enforcing their own legally sanctioned laws inside their sovereign territory. I am, in part, talking about threatening allies with invasion, if they don't do what you want.
Enforcement can be better, but I'm gonna give grace given how recently it was imposed. It's easy to point at extreme levels of enforcement being a key part of any regulation, but I have seen the breadth of the EU's scope and what needs to be balanced. Quite often I find that nonaction against compliance violations falls into the following:
- Lack of resources
- Lack of real consumer impact
- Awaiting legislation meant to clarify or strengthen impact of enforcement.
The article to me doesn't offer enough to justify any shout of doing anything different at the moment, rather it's just that they failed an audit. If they failed an audit and coupled this to swaths of consumer complaints, sure, but every EU member has a clear agency for consumer complaint, and I don't buy it that it is hard for consumers to report violations, it is far more likely in this case that they just don't care for the violations this particular group cares more about (like the links to Temu. I suspect a consumer doesn't care if it actually works still in practice, but we'd need surveys to confirm).
Consumer-replaceable batteries will be one area that WILL be a hot issue for consumers, so I would bet we will see much stronger reaction once that rule comes into effect.
> but every EU member has a clear agency for consumer complaint, and I don't buy it that it is hard for consumers to report violations,
The problem is the response is toothless. I reported Amazon for a violation to ICO in February 2019, received an automated email a month later asking for a swathe of information, replied to that, and 3 months later got an update that it would be assigned a Case Officer. That was the last time I heard from them on that matter.
Meanwhile, my local council will respond to pretty much _everything_ within 24-48 hours. I’ve reported all sorts of “small” things and when it comes up naturally friends are surprised that the council did anything. They’ve never actually tried reporting the issues, and assume it’s all fruitless.
What I expect from this is rather that at least a few producers get more repair friendly so I as consumer have the choice again. (Writing this on my first phone without easily changeable battery, I've tried for very long)
So I as my families tech guru can give the right signals to my family and in a few years we see the actual change happen. Slowly but steadily
Companies don't really care about rules per se. They care about their risk appetite, and whether the consequences of their actions create risk above that appetite level.
The simple calculus is: will it cost me more to comply, or more to ignore? If a company chooses the more costly option, they are betraying their shareholders and being managed poorly.
If you do not fine early and often, you are almost mandating that companies ignore the legislation. If this continues for several years, then you almost make it impossible to turn around later and fine, as businesses will want to know what's changed now. You will create an impression of uncertainty and instability, which is the last thing businesses want, and the last thing you want to do to encourage investment.
If you just set and enforce the rules from the start, then everyone can relax, do the right thing and be happy about it. It's funny how rarely this actually seems to happen.
> will it cost me more to comply, or more to ignore?
Is an (unfortunately) American view of things. The vast majority of European businesses I’ve worked with attempt to comply with the _spirit_ of the laws, while my experience with most American companies is they try to skirt the letter of the law to do whatever the hell they want.
I’m not saying one is better, or that all companies in both places are like that. But it rings true in my experience.
Don't get me wrong but it sounds like you are applying a foreign logic to the EU system without understanding how these things usually work here.
I personally happily followed GDPR rules, so did many others. Making it generally a better place. That wasn't because of fines but because we now had a framework to follow to make the world a safer place.
If it does not happen quickly, then the result might end up similar to data privacy topics.
If you can afford to keep fines in litigation/appeals/formal-defect limbo for a sufficient number of years, you can grow out of even once-threatening fines and delay compliance until the law that you finally bow down to is so old that its signs of old age will in the meantime become popular arguments for undermining or retracting it.
Contrary to popular belief, the EU is not very fast when it comes to enforcement on requirements like these. We already saw this with the ePrivacy Directive and GDPR: those scary hundreds-of-millions-of-euros fines are only handed out after ongoing and deliberate violation, where you've already received plenty of warnings and smaller fines.
18% compliance after one year with zero enforcement is not great, but it's already a massive increase over the near-zero repairable products we had only a few years ago. On top of that it is 18% of models, so there's a decent chance that a huge chunk of the noncompliant ones are obscure brands with near-zero sales: a handful of models by Apple and Samsung already add up to over 60% market share. And the report was literally written by iFixit, so there's a rather clear commercial incentive to underrepresent it and push for the strongest enforcement possible.
You can see the GDPR stats on https://www.enforcementtracker.com/statistics (scroll to “Enforcement over time” and click on “Total €”). 2018–2020 was effectively nothing compared to later.
I'm wondering whether it is now time for regulators to pressure mobile phone companies to install longer life batteries. There is not really an incentive to prolong device life for manufacturers and when I look at recent progress on the car industry and utility battery side there is imho. potential.
Are there battery chemistries available which would allow for significantly longer life without sacrificing cost, power capacity, size, or safety? Generally the best way to prolong battery life is for the consumer to never fully charge or discharge.
"back in the day" we had waterproof phones with user replacable batteries, you could just buy another battery and replace it yourself. I have no idea why we can't do this now.
Were they waterproof? I certainly don’t remember my Nokia 3210 being even splash resistant.
> I have no idea why we can’t do this now
For better worse I think the answer is quite simple - a combo of ease of manufacturing, a long term trend of slimmer devices that is broadly supported by customer behaviour, and an extra place to suggest a device upgrade instead of a repair. You’re more than able to get pretty much any smartphone battery replaced with a manufacturer similar spec these days, and people still choose not to do so.
Waterproof phones with replaceable batteries existed, but they used more rubber and other tricks to pull it off. This had the advantage of making it a lot easier to close the phone again and still keep the water resistant properties.
Having replaced the battery in my old phone, I sure understand why people don't "choose" to do so. The battery itself is worth maybe 20 bucks but the labour and tools required to replace it cost much, much more.
Compared to spending 30 bucks on a secondary battery back in the day, things sure have gone downhill since the days of user-replaceable batteries.
Power density and all of the problems that are fallout from high power density. A modern LiPoly battery contains a lot of energy. It's stored in a chemical that is highly reactive with oxygen, which you happen to be surrounded by at the moment.
Watch some videos on lithium battery fires. Not only do they have extremely hot flames but they spray out molten bits of battery and can't be extinguished with water.
To make a LiPoly battery that can be safely handled by normal people it needs a strong outer casing. A sealed battery in a phone uses the phone's case itself as the battery's protective casing. A user replaceable battery would need its own strong case. The phone then needs to be larger to accommodate the extra volume or have a smaller battery which stores less power than a sealed battery of equivalent volume.
The market has rewarded thinner phones with long lifetimes but also high performance. That triple point is challenging if not impossible to hit without sealed batteries.
> All you really need are easy to replace batteries.
They are easy _enough_ to replace already. Is it as easy as 20 years ago? Surely not. It also seems reasonable that something you're going to be realistically doing once per 3-4 years would require 1 or 2 hours.
Moreover, the regulation doesn't affect this process, apart from "no proprietary tools".
> That’s the only part that will wear out within a reasonable lifecycle.
Millions of broken screens and back glass/plastic panels beg to differ.
And the only part that an average user can hope to replace. I tried to replace a cracked sceen once, and ruined the phone. And I consider myself pretty handy, I do all my own car repairs, household plumbing, etc.
It's going to be cool to get user-replaceable batteries back in new phone releases.
Depending how it goes I can see myself keeping a spare instead of a powerbank
The whole discussion on what the EU is doing has devolved into this idea that everyone will be forced to offer a backplate that pops out and a battery you can remove with your fingers.
The directive is far more complicated, and you will not see that at all.
The regulation doesn't mean batteries have to be made swappable with just bare hands. Common tools and some simple, easily undoable gluing is still acceptable. It gets a battery replacement from a process that risks breaking glass parts, overheating components etc.. to something that can be done by a moderately skilled person with a moderately well stocked toolbox in an afternoon.
Isn’t that the case already for most devices? I can pay £80 and have a guy show up in a van and replace the battery in my iPhone in his van in 30 minutes or so.
Yes, and a lot of that happened in preparation for this specific EU directive.
This happens a lot, see Samsung and Apple announcing more years of security updates and feature updates, Apple announcing the switch to USB-C for the iPhone.
Once it's clear the EU will not budge, some big companies will just switch over in advance, other companies will lag.
I'll never forget the feeling when you get an old phone, replace the battery and it's like brand new again. People no longer need to replace their phone every year anymore so being able to just replace the screen and battery makes the device practically brand new.
I was expecting the bew folding screen to be really easy to replace, given that its basically floating behind a frame, but turns out no! its actually so built into the frame as to be a full body replacement with all the accompanying surgery
Sure, but so far I've replaced my phone screen once and the battery never, I suppose both would be equally easy though. Why is heating a big issue but removing screws not? Shouldn't we mandate user-replaceable screens too? Soon you'll end up regulating all phones to be modular.
I don't really see the value of regulation requiring a certain preference, given that there are tradeoffs. I owned a modular phone previously, and it was, as you say, not as thin and not waterproof, and not dustproof either. Given that it takes like 30 minutes to change the screen or battery on my current phone (which is not modular), I don't see why my preference should be disallowed by EU regulation?
Spare battery: remove empty battery, switch battery, you are back to 100%
Powerbank: mess with cables, keep phone plugged until it's charged and wait
If there is a market for spare batteries, there might be a market for external battery chargers as well > swap battery in the morning instead of charging, place empty battery on charger, repeat the next day
I purchased a Lenovo T580 ThinkPad in 2018, and I configured it with an extra battery. So it had one built-in and one that was removable. This added some extra weight and plenty of extra battery life.
Several times I thought about purchasing a spare battery, but I never did. I also thought about detaching the battery and using the machine without it, such as on AC line power, or when I didn't need the extra juice. But I realized that it was a bad idea to carry it around with a gaping hole on the bottom and exposed battery contacts. I would've felt comfortable if there was a dummy cap to snap on instead.
Spare batteries are a nightmare to handle. Far too easy to bend or have something short-circuit the pads, and you have to shut down and restart your phone.
However, what is needed desperately is the ability to quickly change a degraded battery.
Spare batteries that are designed as internal batteries not to be easily swappable, yes.
Look at DSLR cameras: take out in 1 second, put in in 1 second, physically robust.
We absolutely can have the best of both worlds. We just need to align the smartphone manufacturers to user serviceability and right to repair… even if they go kicking and screaming since they decided their bottom line is most important.
Ever had a GoPro? Or professional camera? Drone? It's really not so hard to imagine a market for replaceable batteries lol.
My ThinkPad t420 had a small built in battery so I could switch batteries without shutdown. Imagine the magic. Imagine taking 20+ hours of laptop battery with you 15 years ago.
Nah, when the old Samsung phones allowed user battery replacement it was completely safe and easy to handle. Restarting the phone took only a few seconds.
New definition of nightmare just dropped: changing a battery. Or is it simply handling a battery? I can't figure out what's supposed to be the nightmare.
Having spare batteries was so great with the old Samsung smartphones. I usually kept a spare on the charger and swapped it as I headed out the door. It took like 10 seconds, just pop the back cover off.
With the thru the roof cost of smartphones and many other computer hardware products because of the current memory crisis I believe the EU should concentrate on making sure customers get satisfaction when something goes wrong from the seller.
I’m not interested in fixing the device myself. I’m taking it back to the company Apple, Sony, Nvidia or Audio-Engine and have them fix it, a third-party chop shop or me involved trying to fix it myself is unacceptable.
Most of the items sold today-simply cost too much to try a tinker with it myself. That’s utterly ridiculous. I hope the EU or any country for that matter concentrate on making sure companies with strong laws, honor/standby and fix the problem with their product. I have little faith that they will.
I appreciate the intent to hold large corporations accountable, but I've lost faith in the EU being competent at doing so. Not as if I see anyone doing it better, but at least others aren't doing it so poorly.
I really don't get the big deal with GDRP. Consider what you are storing and why you are storing. Decide if those things align. If they do not, well don't implement that in first place. And I suppose LLMs are perfect for the boiler plate documentation so not big effort there either.
Somethings are big more challenging like getting the data for customer when asking or deleting it when reasonable. But as user I also like at least having that option. It is least any business can do.
GDPR is reasonable, maybe too weak regulation of big businesses with lots of data.
The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden. Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. They are pretty good and ethical anyway - the theatre recently impressed me when I found out that if you give them medical information in case of emergency they put it in a sealed envelope and no one opens it unless there is an actually emergency that requires it (i.e. you keel over there!).
> The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden.
Eh?
Collect only the personal data you need (with permission) and keep it secure. Such a basic responsibility to your members privacy and safety is hardly a burden.
> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance.
Yeah, and that is precisely where you want something like the GDPR to be as well!
Large corporations are one thing, they have compliance departments, but so, so many local organizations have gotten hacked or data exfiltrated because "why do software and hardware updates when everything is working" or due to incompetence ("cc all"). GDPR finally gave the younger crowd some leverage to get the old guard to do things at least somewhat decently.
Well, wait until you are at the receiving end. It can get nasty pretty quickly.
What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period?
How do you handle Data Subject Access Requests? Can you compile all the data related to that person in a reasonable time to send it to them?
How do you handle deletion requests? Can you name all the data storage that is affected if a deletion request comes in? Are your systems technically capable of deleting the data? What data is exempt (e.g. billing addresses can't just be deleted before the mandated archival period is over)? Do you maintain backups? Then how do you make sure that data covered by a deletion request is destroyed and stays gone even in the event of a backup recovery?
Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.
> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.
Indeed but it forces you to answer these questions and to think about them during the development process as well, maybe even enough to write decent unit and regression tests for anything authentication/authorization related before some security "researcher" siccs Claude Code or whatever on your API and pwns it.
You assume that the business is about developing software and will have a public facing API.
That's a very narrow perspective. The vast majority of businesses aren't this. Even a plumber who types up offers and invoices on a computer is subject to all of this mess.
> Even a plumber who types up offers and invoices on a computer is subject to all of this mess.
Yeah and that plumber has 1000s of customer names, addresses, phone numbers, mail addresses, in Europe maybe even SEPA Direct Debit data.
Not funny if that kind of stuff leaks, especially not if you're, say, a person with a public register block due to domestic violence or whatever (basically, one step before witness protection that gives you a whole new identity).
I think with many of the recent regulations, they could verify and find many of the egregious cases to be violating today.
The EU is just extremely worried about US tariffs and retracting support to Ukraine.
IMO they should just bite the bullet and do what they need to do. In a world of bullies those that are willing to show their teeth win. But instead we have a lot of politicians without a spine.
A huge part of that was fearmongering by people selling compliance consultancy services and people trying to find loopholes allowing them to keep abusing their users' data. For a lot of companies it really wasn't that big of a deal in practice.
Why would they? The worst thing that can realistically happen is a $1-$5 billion fine a few years from now, which they only need to pay a few years after that when they have exhausted their legal remedies.
That’s easy to calculate with, and almost certainly cheaper than compliance.
As its the EU and regulation, its time to trott out your hobby horse.
So let me trot out mine: regulation is good so long as it is backed up by even handed, robust, transparent, quick and effective sanctions.
the Online safety act is a good example of a bad law, which is enforced badly. The first big test (X producing industrial quantities of minors engaging in sexual activity) was failed. Had a small company produced a service that did they same thing, they would have been fined, servers ceased and owners thrown in jail. X got a letter saying they should stop.
An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves.
Another good example is NCAP ratings.
A lot of scores on the doors are often faked defeating their purpose. Helpful but not bullet proof.
https://www.youtube.com/watch?v=8SO8KcfhJmc
Old school methods like what McDonald's use, literally allow the customer to see in to the kitchen are very effective.
Not always ideal for every type establishment but I've seen high end Indian restaurants even do it by having the POS at the back where you can see the kitchen when paying which keeps the noise separate for the desired quiet atmosphere of a fine dining restaurant
I'm not sure how to translate this to the smartphone market though. Fairphone and LaJolla seem to do well in this regard though so back to brand reputation for a lot of this.
>Old school methods like what McDonald's use, literally allow the customer to see in to the kitchen are very effective.
Guess that's why the new refits have a giant wall to stop you seeing into the kitchen.
I don't recall any where it was every easy to see into the kitchen. Yes you could see some of the fryers where they made french fries, and sort of see into the kitchen but there was a lot of food-holding bins, drink dispensers, and other equipment etc. obscuring most of it.
> I'm not sure how to translate this to the smartphone market though. Fairphone and LaJolla seem to do well in this regard though so back to brand reputation for a lot of this.
I'm not here with a silver bullet or anything, but I'd say the EU's energy efficiency labeling works well and has a fairly low level of being gamed/falsified.
I don't think there's any big reason why the EU couldn't enforce labeling of a similar kind to IFixit's repair-ability scoring[0] for set devices.
On a separate note, the article mentions the lousy attempts some smart phone makers are guilty of with regards to repair instructions:
> Some records even refer customers to Temu or AliExpress for spare parts and repair instructions.
There are at least a lot less smart phone manufacturers than restaurants and cafes (comparing to scores on the doors) - if the EU really wanted to, it wouldn't be a huge resource to produce clear guidance on what expectations are for smart phone spare part provision, and issue fines whenever they're violated (you might think is a bad idea, and too much regulation, but my point is just that it's at least feasible)
[0] https://www.ifixit.com/repairability/smartphone-repairabilit...
SOrry, yes I should point out its not perfect. The scores on the doors website is also a partial remedy for this. But I should concede that no solution is perfect, and you still need to allow for the evolution of fraudsters.
> I'm not sure how to translate this to the smartphone market though
Me neither, The pre-existing ways are independent lab testing ( euro-ncap for cars, or ifixit) or the "you have to pay for testing" like for large white goods. None of those work if they are not enforced though....
> Another good example is NCAP ratings.
Ironically it's a very bad example: EuroNCAP is an independent organization and has nothing to do with the EU and legislation/regulations as such.
> X got a letter saying they should stop.
I am unfamiliar with these matters and I am also unsure what specifically you are referring to.
But in general, if big companies get away with wrongdoings by receiving a gentle slap on their fingers, figuratively speaking, it will, in my opinion, lead to no change whatsoever.
Because if there are no material consequences for wrongdoings, they probably would not care. And there are very few kinds of actually material consequences for big companies. One of them being a really hefty fine.
> Because if there are no material consequences for wrongdoings, they probably would not care. And there are very few kinds of actually material consequences for big companies. One of them being a really hefty fine.
In mono/oligo-poly situations there's no really such a thing as "a really hefty fine". Either the cost will be happily trickled to the very public that are being wronged or the fine is effectively unsurvivably hefty, which noone would levy against a too-big-to-fail entity.
Look at the recent fine for Meta for example. Settling a case against one of the core monopolic drivers for a couple percentage points of early revenue is peanuts. I can't believe the exec suite[-s] are thinking anything else than "which anti-consumer behavior can we buy indulgence for?", they would be stupid not to at these discounted rates.
I'm half joking here, but at this point it feels like the only reasonable way to instill some fear against building Torment Nexus and cyberpunk dystopia would be personal criminal liability of the boards and exec suites that is impossible to settle.
I don't consider meta too big to fail. If they go out of business the world can move on with minor disruption and inconvenience.
Sadly that mess had a political component, any attempt to regulate US big tech results in howls from over the Atlantic.
Frankly, I'd prefer it if we just let them howl and said fuck it more but it's probably a good job I'm not making those decisions (and in honesty the picture is complex for companies that size/the politics).
Ironically the fact that the howls need to come from the other side of the Atlantic, rather than having any domestically, should tell anyone all they need to know about the situation.
this is the first time ive heard the europeans indicted over not wanting ai child porn, and that the US is better than Europe for trying to tackle it
privacy rights, standardization of cables, and monopoly busting are also pretty good things.
the real question is why americans havent pushed back against their new feudal lords to carve out the same rights they did against the old ones
Might as well ban computers then, no?
Don't disagree but the results are impossible to know from the US side, politicians have to balance everything and decide whether it's worth the political capital.
Not like it's the only issue in US/UK relations these days either.
That's the situation whether we like it or not.
> Ironically the fact that the howls need to come from the other side of the Atlantic, rather than having any domestically, should tell anyone all they need to know about the situation.
Europeans by and large don't care about American companies these days. They use American software products because frequently there are no alternatives. And most of the news about them are negative.
They also totally don't care bout Chinese companies, they use those products because there are really no alternatives. Apple and Samsung (reluctantly) comply. I guess we know which other companies don't?
>They use American software products because frequently there are no alternatives
Hint hint
Hint hint to what?
South Korea is a very dynamic, tech heavy country and it hasn't managed to push any software product as a market leader.
The EU is bigger, but it's fractured, so functionally it's basically 2-3x South Korea in terms of "software power". And that's not enough to compete with the much larger US juggernaut. Only China has managed to hold its own by simply banning US software all together.
I'm actually all in favor of the EU banning all American software. Fairly sure that after a huge initial tumble a healthy EU software market would thrive.
Edit: I need to brace myself, the Americans are waking up :-)))
Europe had the opportunity to create a silicon valley 30 years ago. They fumbled it so badly that most euro tech talent went to the US and worked or even founded their companies there. They still have not (and likely never will) implement the general reforms needed to create fertile grounds for tech to compete with the US.
If the current EU mindset existed 150 years ago, they would have banned steam engines because they are too loud and annoying. That's the level of shortsighted immediate gratification we are dealing with.
I don't know what SK has to do with this, they are basically still close to an emerging economy. Europe had a roaring economy when SK was still mostly farming.
You will actually find European HN users who will unironically say that we should have never started using fossil fuel engines at all.
Let's assess that opinion in a hundred years. Maybe they're just Michael Burrys.
Both of you, have fun fighting non existant 0.001% strawmen.
We shouldn't really want a silicon valley. See how much trouble the US has trying to get meta to stop abusive practices to minors.
Not having a silicon valley is a good thing.
> Europe had the opportunity to create a silicon valley 30 years ago.
I really like history but nothing like this come to mind, I'd be happy to read about it, what exactly did they do/not do?
From the article, it seems more about chinese brands, no?
> Some records even refer customers to Temu or AliExpress for spare parts and repair instructions.
> But even for products that are technically compliant, the listed weblink still rarely offers a direct path to parts prices. For major brands such as Apple and Samsung, it can take some clicking around before you find what you need, Right to Repair says.
There seems to be a very common idea why the EU is failing dramatically with these ideas that I didnt seem to understand. Knowing it has a US political context suddenly makes everything a little less weird.
> An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves.
> Another good example is NCAP ratings.
Worth noting that NCAP and Scores on the Doors are not regulators. NCAP is an industry body; SotDs is run by TripAdvisor.
I think the food hygiene ratings are a regulatory thing - https://ratings.food.gov.uk - places are required to show their stickers by law.
I'm not sure how the Scores on the Doors website, which is at least related to TripAdvisor, fits into all of this...
It shows the ratings that are provided by food standards inspectors.
Yes, Twitter frontpage should include a little counter with how much child exploitation it has facilitated today.
I don't think there's a single politician in Bruxelles that wouldn't love to come down hard on X. There is no love for Elon in those circles anymore. The problem is that he's attached himself to international politics through his daddy. Trump has threatened the EU with strict sanctions if they levy any sort of proportional fine to US tech companies.
The problem is no longer capitalist liberalism. The new challenge is American Fascism.
> American Fascism
I'm getting sick of this hyperbole, if you want to see a real fascist regime you can look at Iran that killed several thousands of its own people over the course of a week shortly before the current hostilities, in contrast in almost a year of protests 3 people were killed in the US under circumstances that were at least debateable. Or maybe China that literally was rounding up ethnic minorities and sending them to rededucation camps while performing genocide. Or maybe Russia whose government is current grabbing their people giving them 2 weeks of training and then sending hundreds of thousands of young men to die on the front lines to seize their neighbors territory.
In contrast the US is, not following UK rules about taking down websites, is downsizing some government departments, and oh the horror removing people from the country who entered illegally?
I'm not saying things are great, I'm not saying I approve of what is going on right now, or that we are headed in the right direction, but this hysterical exaggeration helps no one and makes any semblance of progress less likely as it alienates more moderate people that would be willing to listen to your side. But it does give you a hit of righteous indignation on the Internet so score one for you, your only continuing to nip at the fraying social fabric of our society but you are getting updoots so good on that.
The President of the United States is openly posting fascist shit regularly. Yesterday:
https://www.independent.co.uk/news/world/americas/us-politic...
The image literally says "inspired by Starship Troopers". Which was inspired by fascism and Nazi uniforms in particular.
> if you want to see a real fascist regime
Is it not worth looking at how such regimes got there? Maybe as a preventative? Do we have to wait for it to go all the way to Holocausts before we go "uh oh, should've said something"?
We had our https://en.wikipedia.org/wiki/Beer_Hall_Putsch a few years back, even.
> literally says "inspired by Starship Troopers"
An objectively good and very stylish film. It is like 30 years old and still grate to watch.
> Which was inspired by fascism and Nazi uniforms
And what exactly does it change? Are you afraid that particular type of pants will make people Nazi or what?
> it not worth looking at how such regimes got there? Maybe as a preventative?
The government get to many tools to influence every aspect of citizens' lives, and then uses those tools to get rid of all opposing voices. That is far more relevant to the Europe than to the US.
> An objectively good and very stylish film. It is like 30 years old and still grate to watch.
Yes, it's a great satire. You get problems when, as with The Boys' Homelander, people apparently can't figure out who the bad guys are.
> And what exactly does it change? Are you afraid that particular type of pants will make people Nazi or what?
I am afraid of people who are super into the Nazi aesthetic, yes, especially when they run the country I live in.
> The government get to many tools to influence every aspect of citizens' lives, and then uses those tools to get rid of all opposing voices. That is far more relevant to the Europe than to the US.
Have you been in a coma the last few years?
I don't care about any of your examples. I am explicitly not talking about Iran, China, Russia, Takedown requests by the UK, "downsizing" the government, or "remigration". I have opinions about all that, but it is not what I'm talking about here.
I am talking about weaponized trade relations, such as coupling embargoes or tariffs, to inner market fines. I am talking about explicitly threatening allies for enforcing their own legally sanctioned laws inside their sovereign territory. I am, in part, talking about threatening allies with invasion, if they don't do what you want.
How about just delegitimizing free & fair elections? The foundation of representational democracy requires confidence in voting.
President Trump has spent over 7 years trying, without any proof, that US state and federal elections are rigged when he or his allies do not win.
Enforcement can be better, but I'm gonna give grace given how recently it was imposed. It's easy to point at extreme levels of enforcement being a key part of any regulation, but I have seen the breadth of the EU's scope and what needs to be balanced. Quite often I find that nonaction against compliance violations falls into the following:
- Lack of resources
- Lack of real consumer impact
- Awaiting legislation meant to clarify or strengthen impact of enforcement.
The article to me doesn't offer enough to justify any shout of doing anything different at the moment, rather it's just that they failed an audit. If they failed an audit and coupled this to swaths of consumer complaints, sure, but every EU member has a clear agency for consumer complaint, and I don't buy it that it is hard for consumers to report violations, it is far more likely in this case that they just don't care for the violations this particular group cares more about (like the links to Temu. I suspect a consumer doesn't care if it actually works still in practice, but we'd need surveys to confirm).
Consumer-replaceable batteries will be one area that WILL be a hot issue for consumers, so I would bet we will see much stronger reaction once that rule comes into effect.
> but every EU member has a clear agency for consumer complaint, and I don't buy it that it is hard for consumers to report violations,
The problem is the response is toothless. I reported Amazon for a violation to ICO in February 2019, received an automated email a month later asking for a swathe of information, replied to that, and 3 months later got an update that it would be assigned a Case Officer. That was the last time I heard from them on that matter.
Meanwhile, my local council will respond to pretty much _everything_ within 24-48 hours. I’ve reported all sorts of “small” things and when it comes up naturally friends are surprised that the council did anything. They’ve never actually tried reporting the issues, and assume it’s all fruitless.
If the severity of punishment for violations was high enough, we would only need very few example cases, before it stops.
Does it really matter this early?
What I expect from this is rather that at least a few producers get more repair friendly so I as consumer have the choice again. (Writing this on my first phone without easily changeable battery, I've tried for very long)
So I as my families tech guru can give the right signals to my family and in a few years we see the actual change happen. Slowly but steadily
Companies don't really care about rules per se. They care about their risk appetite, and whether the consequences of their actions create risk above that appetite level.
The simple calculus is: will it cost me more to comply, or more to ignore? If a company chooses the more costly option, they are betraying their shareholders and being managed poorly.
If you do not fine early and often, you are almost mandating that companies ignore the legislation. If this continues for several years, then you almost make it impossible to turn around later and fine, as businesses will want to know what's changed now. You will create an impression of uncertainty and instability, which is the last thing businesses want, and the last thing you want to do to encourage investment.
If you just set and enforce the rules from the start, then everyone can relax, do the right thing and be happy about it. It's funny how rarely this actually seems to happen.
I will say;
> will it cost me more to comply, or more to ignore?
Is an (unfortunately) American view of things. The vast majority of European businesses I’ve worked with attempt to comply with the _spirit_ of the laws, while my experience with most American companies is they try to skirt the letter of the law to do whatever the hell they want.
I’m not saying one is better, or that all companies in both places are like that. But it rings true in my experience.
Don't get me wrong but it sounds like you are applying a foreign logic to the EU system without understanding how these things usually work here.
I personally happily followed GDPR rules, so did many others. Making it generally a better place. That wasn't because of fines but because we now had a framework to follow to make the world a safer place.
It does matter, yes. Because it won’t lead to the outcome you want until someone actually gets a painful fine.
They will get fined, but it doesn't happen within just a few weeks.
If it does not happen quickly, then the result might end up similar to data privacy topics.
If you can afford to keep fines in litigation/appeals/formal-defect limbo for a sufficient number of years, you can grow out of even once-threatening fines and delay compliance until the law that you finally bow down to is so old that its signs of old age will in the meantime become popular arguments for undermining or retracting it.
I think it matters especially this early, to demonstrate that the legislation is a serious matter, not to be taken lightly and ignored.
Contrary to popular belief, the EU is not very fast when it comes to enforcement on requirements like these. We already saw this with the ePrivacy Directive and GDPR: those scary hundreds-of-millions-of-euros fines are only handed out after ongoing and deliberate violation, where you've already received plenty of warnings and smaller fines.
18% compliance after one year with zero enforcement is not great, but it's already a massive increase over the near-zero repairable products we had only a few years ago. On top of that it is 18% of models, so there's a decent chance that a huge chunk of the noncompliant ones are obscure brands with near-zero sales: a handful of models by Apple and Samsung already add up to over 60% market share. And the report was literally written by iFixit, so there's a rather clear commercial incentive to underrepresent it and push for the strongest enforcement possible.
You can see the GDPR stats on https://www.enforcementtracker.com/statistics (scroll to “Enforcement over time” and click on “Total €”). 2018–2020 was effectively nothing compared to later.
Too bad EU anti-AI laws had real quick enforcement, cementing EU as colonies of US and China for all eternity
> EU anti-AI laws
God I wish.
I'm wondering whether it is now time for regulators to pressure mobile phone companies to install longer life batteries. There is not really an incentive to prolong device life for manufacturers and when I look at recent progress on the car industry and utility battery side there is imho. potential.
Are there battery chemistries available which would allow for significantly longer life without sacrificing cost, power capacity, size, or safety? Generally the best way to prolong battery life is for the consumer to never fully charge or discharge.
This regulation seems to relax the rules a bit for batteries that last longer.
I wonder if it will just lead to using same size batteries more gently.
Batteries always have a limited lifetime.
"back in the day" we had waterproof phones with user replacable batteries, you could just buy another battery and replace it yourself. I have no idea why we can't do this now.
Were they waterproof? I certainly don’t remember my Nokia 3210 being even splash resistant.
> I have no idea why we can’t do this now
For better worse I think the answer is quite simple - a combo of ease of manufacturing, a long term trend of slimmer devices that is broadly supported by customer behaviour, and an extra place to suggest a device upgrade instead of a repair. You’re more than able to get pretty much any smartphone battery replaced with a manufacturer similar spec these days, and people still choose not to do so.
Waterproof phones with replaceable batteries existed, but they used more rubber and other tricks to pull it off. This had the advantage of making it a lot easier to close the phone again and still keep the water resistant properties.
Having replaced the battery in my old phone, I sure understand why people don't "choose" to do so. The battery itself is worth maybe 20 bucks but the labour and tools required to replace it cost much, much more.
Compared to spending 30 bucks on a secondary battery back in the day, things sure have gone downhill since the days of user-replaceable batteries.
Plain old, madagascar vanilla artificial obsolescence.
Ohhh Elon is from South Africa and made electric cars because he’s mad at gas cars
Ok byeeee
> I have no idea why we can't do this now.
Power density and all of the problems that are fallout from high power density. A modern LiPoly battery contains a lot of energy. It's stored in a chemical that is highly reactive with oxygen, which you happen to be surrounded by at the moment.
Watch some videos on lithium battery fires. Not only do they have extremely hot flames but they spray out molten bits of battery and can't be extinguished with water.
To make a LiPoly battery that can be safely handled by normal people it needs a strong outer casing. A sealed battery in a phone uses the phone's case itself as the battery's protective casing. A user replaceable battery would need its own strong case. The phone then needs to be larger to accommodate the extra volume or have a smaller battery which stores less power than a sealed battery of equivalent volume.
The market has rewarded thinner phones with long lifetimes but also high performance. That triple point is challenging if not impossible to hit without sealed batteries.
All you really need are easy to replace batteries. That’s the only part that will wear out within a reasonable lifecycle.
Aside from FairPhone no one offers that
> All you really need are easy to replace batteries.
They are easy _enough_ to replace already. Is it as easy as 20 years ago? Surely not. It also seems reasonable that something you're going to be realistically doing once per 3-4 years would require 1 or 2 hours.
Moreover, the regulation doesn't affect this process, apart from "no proprietary tools".
> That’s the only part that will wear out within a reasonable lifecycle.
Millions of broken screens and back glass/plastic panels beg to differ.
And the only part that an average user can hope to replace. I tried to replace a cracked sceen once, and ruined the phone. And I consider myself pretty handy, I do all my own car repairs, household plumbing, etc.
> All you really need are easy to replace batteries. That’s the only part that will wear out within a reasonable lifecycle.
This is far from true. Power connectors.
Screens too
It's going to be cool to get user-replaceable batteries back in new phone releases. Depending how it goes I can see myself keeping a spare instead of a powerbank
The whole discussion on what the EU is doing has devolved into this idea that everyone will be forced to offer a backplate that pops out and a battery you can remove with your fingers.
The directive is far more complicated, and you will not see that at all.
The regulation doesn't mean batteries have to be made swappable with just bare hands. Common tools and some simple, easily undoable gluing is still acceptable. It gets a battery replacement from a process that risks breaking glass parts, overheating components etc.. to something that can be done by a moderately skilled person with a moderately well stocked toolbox in an afternoon.
Isn’t that the case already for most devices? I can pay £80 and have a guy show up in a van and replace the battery in my iPhone in his van in 30 minutes or so.
Yes, and a lot of that happened in preparation for this specific EU directive.
This happens a lot, see Samsung and Apple announcing more years of security updates and feature updates, Apple announcing the switch to USB-C for the iPhone.
Once it's clear the EU will not budge, some big companies will just switch over in advance, other companies will lag.
Powerbank: Works with all phones, Doesn't require you to shut down and take your phone apart, Can be charged with a regular phone charger.
Spare battery: ???
I don't need to be able to swap a spare battery like we did 15 years ago.
However when your battery is old, and drains fast, it's really nice to be able to order a new one and easily change it by removing 4 screws.
Not having to perform surgery on your phone, heating it to remove glue, etc.
I'll never forget the feeling when you get an old phone, replace the battery and it's like brand new again. People no longer need to replace their phone every year anymore so being able to just replace the screen and battery makes the device practically brand new.
I was expecting the bew folding screen to be really easy to replace, given that its basically floating behind a frame, but turns out no! its actually so built into the frame as to be a full body replacement with all the accompanying surgery
Sure, but so far I've replaced my phone screen once and the battery never, I suppose both would be equally easy though. Why is heating a big issue but removing screws not? Shouldn't we mandate user-replaceable screens too? Soon you'll end up regulating all phones to be modular.
> Soon you'll end up regulating all phones to be modular.
That would be great, obviously there would be tradeoffs (not as thin, potentially less waterproof) but that seems like the right direction to go in.
I don't really see the value of regulation requiring a certain preference, given that there are tradeoffs. I owned a modular phone previously, and it was, as you say, not as thin and not waterproof, and not dustproof either. Given that it takes like 30 minutes to change the screen or battery on my current phone (which is not modular), I don't see why my preference should be disallowed by EU regulation?
I wouldn't want to design the phone around an event that happens every 3 years at minimum.
Spare battery: remove empty battery, switch battery, you are back to 100% Powerbank: mess with cables, keep phone plugged until it's charged and wait
If there is a market for spare batteries, there might be a market for external battery chargers as well > swap battery in the morning instead of charging, place empty battery on charger, repeat the next day
I purchased a Lenovo T580 ThinkPad in 2018, and I configured it with an extra battery. So it had one built-in and one that was removable. This added some extra weight and plenty of extra battery life.
Several times I thought about purchasing a spare battery, but I never did. I also thought about detaching the battery and using the machine without it, such as on AC line power, or when I didn't need the extra juice. But I realized that it was a bad idea to carry it around with a gaping hole on the bottom and exposed battery contacts. I would've felt comfortable if there was a dummy cap to snap on instead.
Spare batteries are a nightmare to handle. Far too easy to bend or have something short-circuit the pads, and you have to shut down and restart your phone.
However, what is needed desperately is the ability to quickly change a degraded battery.
Spare batteries that are designed as internal batteries not to be easily swappable, yes.
Look at DSLR cameras: take out in 1 second, put in in 1 second, physically robust.
We absolutely can have the best of both worlds. We just need to align the smartphone manufacturers to user serviceability and right to repair… even if they go kicking and screaming since they decided their bottom line is most important.
Ever had a GoPro? Or professional camera? Drone? It's really not so hard to imagine a market for replaceable batteries lol.
My ThinkPad t420 had a small built in battery so I could switch batteries without shutdown. Imagine the magic. Imagine taking 20+ hours of laptop battery with you 15 years ago.
Nah, when the old Samsung phones allowed user battery replacement it was completely safe and easy to handle. Restarting the phone took only a few seconds.
> Spare batteries are a nightmare to handle.
New definition of nightmare just dropped: changing a battery. Or is it simply handling a battery? I can't figure out what's supposed to be the nightmare.
Maybe it's the turning off of a telephone.
Having spare batteries was so great with the old Samsung smartphones. I usually kept a spare on the charger and swapped it as I headed out the door. It took like 10 seconds, just pop the back cover off.
I really, really don’t want to carry a second clunky device around with me.
And extra batteries aren't?
I would be more optimistic but I ordered some pretty solid power banks from Anker, which should be a top notch power bank manufacturer.
Both types of products from them were recalled after about a month for being fire hazards.
I imagine it's not universal but it really made me question the product category.
With the thru the roof cost of smartphones and many other computer hardware products because of the current memory crisis I believe the EU should concentrate on making sure customers get satisfaction when something goes wrong from the seller.
I’m not interested in fixing the device myself. I’m taking it back to the company Apple, Sony, Nvidia or Audio-Engine and have them fix it, a third-party chop shop or me involved trying to fix it myself is unacceptable.
Most of the items sold today-simply cost too much to try a tinker with it myself. That’s utterly ridiculous. I hope the EU or any country for that matter concentrate on making sure companies with strong laws, honor/standby and fix the problem with their product. I have little faith that they will.
I appreciate the intent to hold large corporations accountable, but I've lost faith in the EU being competent at doing so. Not as if I see anyone doing it better, but at least others aren't doing it so poorly.
I don't want to get down-voted but I like this regulation, good job EU!
Do you like the intent, or the implementation and enforcement?
Politicians have a tendency to think that passing legislation fixes problems, where is its only the start of the process.
Being in favor of right-to-repair is generally popular on HN, for obvious reasons.
Whereas, given a large part of the HN demographic works in the AdTech industry.....
Being in favour of the GDPR will bring out downvotes and FUD from the people whose very salaries are dependent on invading your privacy.
I really don't get the big deal with GDRP. Consider what you are storing and why you are storing. Decide if those things align. If they do not, well don't implement that in first place. And I suppose LLMs are perfect for the boiler plate documentation so not big effort there either.
Somethings are big more challenging like getting the data for customer when asking or deleting it when reasonable. But as user I also like at least having that option. It is least any business can do.
GDPR is reasonable, maybe too weak regulation of big businesses with lots of data.
The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden. Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. They are pretty good and ethical anyway - the theatre recently impressed me when I found out that if you give them medical information in case of emergency they put it in a sealed envelope and no one opens it unless there is an actually emergency that requires it (i.e. you keel over there!).
> The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden.
Eh?
Collect only the personal data you need (with permission) and keep it secure. Such a basic responsibility to your members privacy and safety is hardly a burden.
> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance.
Yeah, and that is precisely where you want something like the GDPR to be as well!
Large corporations are one thing, they have compliance departments, but so, so many local organizations have gotten hacked or data exfiltrated because "why do software and hardware updates when everything is working" or due to incompetence ("cc all"). GDPR finally gave the younger crowd some leverage to get the old guard to do things at least somewhat decently.
Well, wait until you are at the receiving end. It can get nasty pretty quickly.
What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period?
How do you handle Data Subject Access Requests? Can you compile all the data related to that person in a reasonable time to send it to them?
How do you handle deletion requests? Can you name all the data storage that is affected if a deletion request comes in? Are your systems technically capable of deleting the data? What data is exempt (e.g. billing addresses can't just be deleted before the mandated archival period is over)? Do you maintain backups? Then how do you make sure that data covered by a deletion request is destroyed and stays gone even in the event of a backup recovery?
Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.
> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink
I doubt anybody wants to deal with fire safety inspections either.
Though I'm quite sure you will change your mind when your personal data gets hacked or your office burns down.
Some of my personal data has leaked. Some of it has to be public because of some laws.
Fire safety is less onerous and less complex.
> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink.
Indeed but it forces you to answer these questions and to think about them during the development process as well, maybe even enough to write decent unit and regression tests for anything authentication/authorization related before some security "researcher" siccs Claude Code or whatever on your API and pwns it.
You assume that the business is about developing software and will have a public facing API.
That's a very narrow perspective. The vast majority of businesses aren't this. Even a plumber who types up offers and invoices on a computer is subject to all of this mess.
> Even a plumber who types up offers and invoices on a computer is subject to all of this mess.
Yeah and that plumber has 1000s of customer names, addresses, phone numbers, mail addresses, in Europe maybe even SEPA Direct Debit data.
Not funny if that kind of stuff leaks, especially not if you're, say, a person with a public register block due to domestic violence or whatever (basically, one step before witness protection that gives you a whole new identity).
Thousands of customers? Your numbers are out of touch with reality.
They need to start fining.
chill out it has not been a month.
I suspect it’s something similar to the GDPR where the EU passes a law but has very few resources on how to check if you’re actually compliant.
I think with many of the recent regulations, they could verify and find many of the egregious cases to be violating today.
The EU is just extremely worried about US tariffs and retracting support to Ukraine.
IMO they should just bite the bullet and do what they need to do. In a world of bullies those that are willing to show their teeth win. But instead we have a lot of politicians without a spine.
A huge part of that was fearmongering by people selling compliance consultancy services and people trying to find loopholes allowing them to keep abusing their users' data. For a lot of companies it really wasn't that big of a deal in practice.
Why would they? The worst thing that can realistically happen is a $1-$5 billion fine a few years from now, which they only need to pay a few years after that when they have exhausted their legal remedies.
That’s easy to calculate with, and almost certainly cheaper than compliance.
Fines like this always come with a legal obligation to adhere to the requirements, it's never just a cost of doing business.
Cheat until caught then lie.
There seems to be a strong sentiment in a specific direction, with everyone saying more or less the same weird arguments.
Maybe non EU people shouldn't judge this much? Its generally Very welcomed around here