Hacker News new | ask | show | jobs
by pton_xd 20 days ago
I don't understand the EU's position on privacy. On the one hand, they enacted GDPR to give you control over access to your personal data.

On the other, they need access to all of your data.

11 comments

The EU's position on privacy seems pretty consistent to me - they're against your data being monetized by private entities but not against building governmental tools to monitor private entities.

In good faith this could be summarized as "Personal data should be used for public safety but not for profit" - but that philosophy is definitely a strong contrast with the basic American philosophy towards civil liberties.

> basic American philosophy towards civil liberties.

Errrr, america does not look like country that cares about that. It does care about liberties of rich companies tho.

Exactly, that is the American philosophy being referenced.
The unquestioned view in certain circles - including here - is that when the EU/UK does something that chips away at people's online privacy, there's un ulterior motive.

It's entirely possible that politicians just want to do something about CSAM and young people having their mind twisted by social media. The electorate do seem to be keen on some sort of action.

This is being heavily pushed by certain actors so it's not just politicians wanting to do something about CSAM: https://balkaninsight.com/2023/09/25/who-benefits-inside-the...

Many abuse survivors and youth advocates strongly oppose Chat Control; here is one voice detailing why: https://www.linkedin.com/pulse/why-i-dont-support-privacy-in...

Other governments across the Channel also want to protect children online, while at the same time dismissing thousands of reports of grooming, for fear of being labelled "racist".
>It's entirely possible that politicians just want to do something about CSAM

except that honest-to-God child rapists get extremely lenient sentences in Western Europe and rarely (if ever) get deported afterwards.

> except that honest-to-God child rapists get extremely lenient sentences in Western Europe and rarely (if ever) get deported afterwards.

Where would you imagine western European rapists could be deported to? Presumably Fred West, Jimmy Savile, Ted Heath, Gary Glitter, Richard Huckle, Ian Watkins, Stewart Hall and Fred Talbot need to be sent back to Pakistan or similar where they learnt their wicked ways. You daft get

Ban social media then, don't scan everyone's info. We know it's going to end up in the US. They can't claim to be working for the European project if the implement legislation that entrenches US majors and goes against the interest of their citizens.
I don't doubt it sort of by why then go through these bizarre loops and secrecy, etc.
I think the position can best be approximated as "companies should not be able to do this, but you should trust your government to do this to you". (That's a bad position that needs to be defeated every time it arises, but it's a consistent position.)
Given the choice of trust between, lets say Amazon/Meta/Google and the EU (or some European government), 9 times out of 10, the EU is the lesser evil.
You don't have to use Amazon/Meta/Google. You have to use the government.

Let's not forget that these are the people and laws that are supposed to represent and help you, not the other way around. While private companies have no such obligation.

I've moved countries 5 times in my life. I still haven't been able to fully degoogle.
Amazon/Meta/Google is sometimes required, nobody in the real world can get away from that.

> supposed to represent and help you, not the other way around. While private companies have no such obligation.

Exactly my point.

For now none of Amazon, Meta, or Google can jail you or legally do violence on you, separate you from your family, etc. Your sense of threat is extremely miscalibrated.
Not really. I know what you are playing at. The probability of the government being vindictive towards a single family, whilst not truly zero, is for almost all practical purposes zero.

The probability of a (my or your) child enduring harmful content, perpetuated and enabled by Meta/Google (in particular) is almost a certainty.

We are not required to pick amongst evils. We could, in fact, say private chats are private and end to end encryption is sacrosanct.
If you are purist and you don't live in the real world with real evils. I don't want pedophiles to have privacy.
>I don't want pedophiles to have privacy.

that is why police already have access to mechanisms to remove privacy from people suspected of being a pedophile.

The existing mechanisms are inadequate or not fit for 2026. Hence this discussion.

You are agreeing with me :)

After Epstein, Hollywood and decades earlier Dutroux, you'd think people like you would have wizened.

For fuck's sake, my country's entire media/intellectual class protected an avowed and even boasting pedophile during his entire life! https://en.wikipedia.org/wiki/Gabriel_Matzneff

what a crazy turning of the tides to see this comment in the gray.

i suppose the times have changed from when most people on the internet were cypherphunk. now it's common to see people say "i have nothing to hide, please scan all of my communications", unironically invoking "please think of the children".

Maybe big tech weren't good a lobbying bureaucrats against GDPR but got better at lobbying in the EU for this. There's also been a slight shift towards authoritarianism in the last decade, which naturally love the possibilities of stricter communication control.

Children protection and russian propaganda are the tried and tested covers at enforcing age verification, message scanning, and probably any future pan-european surveillance network.

Very clear position: they want absolute control over both companies and citizens
Not "access to ALL of your data". Also, as confusing as it might be, it is in the nature of EU (at least IMHO) to not have a clear position over multiple legislatures.
This is a wedge.
There's no position on privacy. They make whatever laws the corporate laws and elites like, and that furthers their own bureucratic reach. GDPR is a good way to create a "compliance moat" against smaller players, and to give the EU bureucrats more power.
It is simple. GDPR is aimed at private entities misusing your data. Keyword private.
Not even that. The government outsources a lot of their functions, so a LOT of organizations have access to extremely private data, where necessary.

For example, Palantir gets access to "large and diverse (government) databases with Dutch citizens’ data for analysis" (including mental health treatment data) under the GPDR to help police in the Netherlands do terror investigations (from 2012 to 2019). I'm sure you can appreciate the wisdom and privacy-enhancement in that just as much as me!

There are large lists of private organizations that get access to government data about citizens ... every country has multiple (public and secret ones).

Oh, they also "failed to mention" this to parliament, and this was only discovered after a journalist got a tipoff and requested financial data about the deal ... for about 5 years. Of course, there was never even the slightest investigation into this.

https://nltimes.nl/2025/08/22/dutch-police-also-use-controve...

(paywalled) https://www.volkskrant.nl/tech/ook-nederlandse-politie-gebru...

It seems fairly consistent, doesn't it? CC 2.0 is that the government must be able to access things, and GDPR has a legal basis exemption that is defacto used every time by government entities. The general idea is that private parties cannot consent to things to each other but that residents of a place consent to being governed by the government. e.g. you can't consent to having someone jail you; but you also can't opt out of jail by the government.

Personally, the politics of Europe is really not for me, but I can see why others might find it attractive. In the end, history will show us which path is adaptive.

The thing is that according to the Universal Declaration of Human Rights privacy and the right to private communication is a basic human right. And GDPR was literally enacted to enforce this human right.

Now one basic principle of democracy is that supreme courts are superior to the people in power. Someone needs to watch the lawmakers so to say. Because it could actually be that the European commission enacts laws that are illegal. And Chat Control 2.0 could actually be illegal because it violates the Universal Declaration of Human Rights. However, somebody has to take them to The Court of Justice of the European Union to test it.

The one that passed doesn't give them access to anything. It is different from the scary one.