You Know GDPR Is Good Based on Who Hates It
You Know GDPR Is Good Based on Who Hates It
你可以通过谁讨厌 GDPR 来判断它是否是一项好政策
FDR has always been one of my favorite presidents, second maybe to Lincoln. Both were men the establishment assumed were one of them until, to their horror, they governed like they weren’t. Both could trash the opposition in one breath and take the moral high ground in the next. One of my favorite Roosevelt lines growing up came from Madison Square Garden, October 1936, standing before a crowd that included plenty of people who wanted him dead:
富兰克林·罗斯福(FDR)一直是我最喜欢的总统之一,地位仅次于林肯。他们两人都被建制派误认为是“自己人”,直到后来建制派惊恐地发现,他们的执政风格完全不是那么回事。两人都能在上一秒痛斥反对派,下一秒又占据道德制高点。我成长过程中最喜欢的罗斯福名言之一,出自 1936 年 10 月他在麦迪逊广场花园的演讲,当时他面对的人群中,有许多人巴不得他死:
“Never before in all our history have these forces been so united against one candidate as they stand today. They are unanimous in their hate for me—and I welcome their hatred.”
“在我们的历史上,这些势力从未像今天这样如此团结地反对一位候选人。他们对我的一致仇恨——我欢迎这种仇恨。”
What I love is that he doesn’t argue with the hate. He doesn’t say they’re wrong to hate him, or that the hate is unfair. He says the hate is evidence. The process is working. I’ve always treated it as a metric: if you’re doing something hard and nobody hates it, you probably aren’t doing it. If the right people hate it and those people happen to be some of the worst people alive, so much the better. By that standard, the GDPR (Europe’s General Data Protection Regulation) is doing beautifully.
我喜欢的是,他并没有与这种仇恨争辩。他没有说他们恨他是错的,也没有说这种仇恨是不公平的。他说,仇恨就是证据,说明进程正在发挥作用。我一直将其视为一种衡量标准:如果你正在做一件困难的事情,而没有人讨厌它,那你可能根本没在做事。如果那些“对的人”讨厌它,而这些人恰好又是世上最糟糕的一群人,那就再好不过了。按照这个标准,GDPR(欧洲《通用数据保护条例》)的表现非常出色。
The Cursed Banner
被诅咒的横幅
It is impossible to go anywhere in a technology space online without hitting a wave of commentary about how stupid GDPR is. It was written by bureaucrats who don’t understand the amazing potential of unrestricted technology. These US-based critiques almost always lean on the oldest trick in cyberlibertarianism: we don’t have time to regulate, we must simply adapt and ride the wave. Nobody has time for government.
在网络科技领域,你几乎随处可见关于 GDPR 有多愚蠢的评论。人们说它是由那些不懂不受限制技术之巨大潜力的官僚所编写的。这些来自美国的批评几乎总是依赖于网络自由意志主义中最古老的伎俩:我们没时间监管,我们只需要适应并顺应潮流。没人有时间理会政府。
Of all GDPR’s consequences, none gets more attention than the cookie banner, which critics present as the inevitable result of government meddling. Blaming GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the surveillance apparatus humming behind the “OK.” Ironically the banner designed to hide the machine has taught the public more about the machine than a thousand podcasts ever will. Even non-technical people stop at “your data is shared with 996 partners.” “For a sports score website?”
在 GDPR 的所有后果中,没有比 Cookie 横幅更受关注的了,批评者将其视为政府干预的必然结果。把 Cookie 横幅归咎于 GDPR,就像把蟑螂归咎于卫生检查员一样。这个横幅是蓄意的破坏行为,是一种精心设计的“黑暗模式”,旨在让你在了解“确定”按钮背后运行的监控机制之前就感到疲惫。讽刺的是,这个旨在隐藏机器运作的横幅,反而让公众对这台机器的了解比一千个播客还要多。即使是非技术人员,看到“您的数据已与 996 个合作伙伴共享”时也会停下来思考:“为了一个体育比分网站?”
So why is the tech commentary community so loud about this? Because they understand what’s at stake. If consent must be freely given and easy to refuse, the industry’s power shrinks exponentially. People might decide who has their data, how long it’s kept, and what it was collected for. You can only imagine how that thought keeps a Meta executive up at night when he’s not eating endangered animals, or ignoring calls from his children whose names he has forgotten while on a tacky yacht.
那么,为什么科技评论界对此反应如此强烈?因为他们明白利害关系。如果同意必须是自由给予且易于拒绝的,那么该行业的权力就会呈指数级萎缩。人们可能会决定谁拥有他们的数据、数据保存多久以及收集数据的目的。你可以想象一下,当 Meta 的高管不在吃濒危动物,或者不在那艘俗气的游艇上无视他早已忘记名字的孩子们的电话时,这个想法是如何让他彻夜难眠的。
Consider the following example. Did you know Google was doing this every single time you searched on Google? Did your dad? So even in the most maliciously compliant form the regulation does provide value and information. Remember the hatred is the metric. How did we get here, where US tech companies end up regulated by Brussels? Why isn’t the US government regulating US corporations anymore? If the rules are so terrible, why did nobody choose market exit? Has the EU become the world’s “privacy cop” or, in the inverse, the biggest player to protect a fundamental human right to privacy?
考虑以下例子。你知道你每次在谷歌搜索时,谷歌都在做这件事吗?你父亲知道吗?所以,即使是以最恶意合规的形式,该法规也确实提供了价值和信息。记住,仇恨就是衡量标准。我们是如何走到这一步的,以至于美国科技公司最终要由布鲁塞尔来监管?为什么美国政府不再监管美国公司了?如果规则如此糟糕,为什么没有人选择退出市场?欧盟是成为了世界的“隐私警察”,还是反过来,成为了保护隐私这一基本人权的最大参与者?
GDPR Day
GDPR 之日
Ah who doesn’t remember where they were on GDPR Day. Since we’re all socialists in the EU, we stood up from our government issued desks and gave the required three cheers for regulation, then resumed being on vacation for 6 weeks. Obviously after stopping by my free doctor on my way to the airport. On May 25th, 2018, GDPR took effect to the sound of American commentary, the way fireworks take effect to the sound of dogs.
啊,谁不记得 GDPR 生效那天自己在哪里呢?既然我们欧盟的人都是“社会主义者”,我们从政府发放的办公桌前站起来,为监管欢呼三声,然后继续休 6 周的假。当然,是在去机场的路上顺便看了看我的免费医生之后。2018 年 5 月 25 日,GDPR 在美国评论界的喧嚣声中生效,就像烟花在狗吠声中燃放一样。
You can tell American CEOs were aware of the regulation based on the speed by which they copied the language from it. Right before it took effect Brad Smith, the president of Microsoft, tweeted “We believe privacy is a human right.” Tim Cook was right behind, telling CNN that “privacy is a fundamental human right”. The framing of privacy as a human right is one of the key elements of the EU approach with GDPR. This is in stark contract with the US legal system which views information privacy as more of a market problem. You are all informed individuals in the wide marketplace of data exchanges and are left mostly to your own devices. In theory there should be regulations by the US of things like unfairness, deceptions and other market failures but in practice that doesn’t happen.
你可以从美国 CEO 们抄袭该法规措辞的速度看出他们对这项法规的了解。就在它生效前,微软总裁布拉德·史密斯(Brad Smith)发推文称:“我们认为隐私是一项人权。”蒂姆·库克(Tim Cook)紧随其后,告诉 CNN “隐私是一项基本人权”。将隐私定义为一项人权是欧盟 GDPR 方法的关键要素之一。这与美国法律体系形成了鲜明对比,后者更多地将信息隐私视为一个市场问题。在美国,你们都是数据交换大市场中的知情个体,基本上只能自求多福。理论上,美国应该对不公平、欺诈和其他市场失灵等问题进行监管,但实际上并没有发生。
Europe is no stranger to this fight. The German state of Hesse passed the world’s first data protection law in 1970, also known as the year the Beatles broke up, and set a standard we still fail to meet today:
欧洲对这场斗争并不陌生。德国黑森州在 1970 年(也就是披头士乐队解散的那一年)通过了世界上第一部数据保护法,并设定了一个我们今天仍未达到的标准:
“The records, data and results covered by data protection shall be obtained, transmitted and stored in such a way that they cannot be consulted, altered, extracted or destroyed by an unauthorized person. This shall be ensured by appropriate staff and technical arrangements.”
“受数据保护的记录、数据和结果的获取、传输和存储方式,应确保未经授权的人员无法查阅、更改、提取或销毁。这应通过适当的人员和技术安排来确保。”
At the launch of GDPR there were 126 countries with data privacy laws of some sort. What you see with this sea of legislation is an overwhelming consensus that what GDPR was attempting to do was correct. In fact you see a pretty high level of global convergence of standards. All 126 laws descend from the same commandments the OECD carved in 1980: collect only what you need, say what it’s for, keep it safe, let people see and correct it, and don’t be a creep about any of this. Fifty years later, the American internet industry is still stuck on commandment one.
在 GDPR 推出时,已有 126 个国家拥有某种形式的数据隐私法。从这片立法海洋中,你可以看到一个压倒性的共识:GDPR 试图做的事情是正确的。事实上,你可以看到全球标准的高度趋同。所有 126 部法律都源自经合组织(OECD)在 1980 年制定的相同准则:只收集你需要的数据,说明用途,确保安全,允许人们查看和更正,并且不要在这些事情上搞鬼。五十年过去了,美国互联网行业仍然卡在第一条准则上。
So first the often-repeated sentiment that this is a flight of EU fancy is straight up incorrect. Something you could describe as the “European standard” for data privacy quickly became a global standard. Why Did GDPR Spread so Quickly? Anu Bradford calls it the Brussels Effect: Europe regulates, the world complies, because despite American bluster, Europe is a market nobody can leave.
所以,首先,那种认为这只是欧盟异想天开的常见观点是完全错误的。你可以将其描述为数据隐私的“欧洲标准”,它很快成为了全球标准。为什么 GDPR 传播得如此之快?阿努·布拉德福德(Anu Bradford)称之为“布鲁塞尔效应”:欧洲监管,世界遵守,因为尽管美国虚张声势,但欧洲是一个没人能离开的市场。