The goal of the regulation is to get the operators to comply, which they usually do after fines (EDIT: and litigations and whining, of course), because the costs of infractions are increased if they don't comply.
The issue is they usually comply with the specific law being broken, and then immediately stop complying with a different law
The goal should be to incentivise them to comply with the law as a whole, not to keep deliberately breaking different sections of the law to make profit above the level of fines
That's why people want the level of the fines to go up, to disincentivise the more broad lawbreaking
Imagine regular laws worked that way, where a prior conviction is only relevant if it was for the exact same crime, and you can go around committing dozens of crimes and be treated like a first offender every time because this time you chose robbery and last time it was theft.
You appear to be arguing with the assumption that "get the operators to comply" is false.
These companies do, in fact, change behaviour in response to such actions; they may hire lawyers to find and exploit as many loopholes as they can, but they do ultimately comply. Even X ultimately complied in response to Brazil, and the EU is a much more important market for Google than Brazil ever was for X.
(Why would you expect to get dollars from an EU settlement?)
It‘s nice to have such revenue to fund EU programs on digital sovereignty. European institutions give plenty of money to startups. You need an entry to the program, but when you are in, it can account for 50-70% or more in your early stage funding. And that‘s nice, because you keep more equity.
I find it more interesting that US Americans think letting their companies do whatever they want everywhere (as they currently do) is the better "strategy".
I don't think that's a sustainable model. Also most of those fines goes into filling the gaps in budgets related to recurring costs of maintaining the bureaucratic behemoth rather than funding research or innovation.
> I've never received a dollar from the EU as a victim.
There's this standard assumption that HN users are well educated.
Budgets don't work like that. It's not like the US federal government collects taxes and then deposits bags of gold coins on people's doorsteps.
Taxes, fines, etc are all collected and then they mostly go to a general, undifferentiated budget which is then divided by the various ministries (departments, whatever).
So yes, if you're a EU citizen you did get the back. As roads, hospitals, research funding.
Not really, next time they just make a calculated risk decision, if the revenue from non-compliance is quite significant than the fine they have to pay later (if they have to, because I can imagine so many other cases which went unnoticed or didn't result in a fine) there is no reason for them to comply next time. It's not like they will be prohibited from doing a business after n number of compliance violations or fines
Except they did comply for all the cases where they were fined. They're not fined for one-off behaviors, but for how their services are structured. That's GPs point.
If the cost of penalties doesn't exceed the cost of the offence then it's a winning move to offend.
The correct solution to this is to have fines scaled to the value of a company and an exponential doubling of fines for every re-offence that falls under the same category of crime with a cooling off period after a few years.
The fines do scale with noncompliance, if Google were to continue to offend they would get a daily fine that is retroactively applied to the full duration.
Because the goal isn’t to punish, it’s to get them to do what the law wants them to do. The fine is supposed to be a slap on the wrist - the actual desired behaviour is compliance
The maximum fine the EU can impose with the DMA is "10 % of its total worldwide turnover in the preceding financial year". I think this would hurt even Google. And I think a billion dollars is not nothing.
The same principle evoked in the rest of this thread, if the penalties match exactly or are under the profits you can generate by injuring (in the legal sense) EU citizens it's not really a penalty but rather a cost of business. Plus markets are very interconnected, especially the digital ones.
EU competition law is not framed around valuing Europeans more than others, it is framed around protecting competition and market functioning inside the EU.
No need to moralize it and pretend anyone is using this "value" European humans more than other humans.
Because they decided that way. Any other country in the world can decide the same thing but they don't have the same leverage as the EU. Google makes a lot of money in the EU.
Yep. If a train ticket costs 100 euro and the fine for freeloading is 5 euro, you'd be a fool to buy a ticket.
Don't blame Google for pushing boundaries. That's what people (and corpos) do in any competitive activity. Do blame our politicians for being incompetent and ill-meaning.
The lengthy legal battle against these fines is going to be extremely interesting, especially on the Shopping/Hotels/Flights side since it is an extremely competitive market. I wonder if the lower EU court will keep its overly proactive approach despite the CJEU's reversals.
These fines go toward the EU's general budget as "other income" which reduces the amount that member states must contribute annually for the budget to balance. So the EU partially funds itself by leveraging fines like this on AliExpress, Google, Meta, Apple, etc. and the trickle-down savings to member states is then (presumably) used to fund public works and social services locally.
Interesting to see how Google solves this in their UI because this isn’t a new problem: In 2017, they were fined for a similar problem with Shopping and the auction house concept to compete for placement was heavily scrutinized.
I looked it up, and it seems that one issue is that Google, as a DMA gatekeeper, is supposed to provide anonymous data to other search services, but in practice, important parts of the actual data have been removed. The other issue is that competing AI services (not just Gemini) should also be allowed to run integrated app search.
And supposedly, "steering must be free". Or at least that's what they told Apple when fining €500M, I think today they both charge up to about 20% commission if apps use third party payments.
EU regulatory apparatus is maybe only part of the EU which is operates without obsequiousness to the US; on the one hand, this is necessary assertion of sovereignty, on the other you fear for the wider collateral damage which will inevitably ensue. Trump gonna respond to this with an escalation for sure
This is the fine after it got influenced by the political branch. It is a sign towards the companies that the law still bites and has to be adhered but reduced in this case to a level where it can be accepted by Google without major escalation in trade politics.
The current government has defied the supreme court many times. It can do this because the police force is controlled by the government, not by the supreme court, so it won't arrest the government.
This. There is one thing to have a lawful evil like Putin, who acts rationally. You know if you give him Crimea or whatever, he will stop bombing Kiev, or if you buy his gas, he will not suicide your politicians. With Trump, it's just like throwing a dice each time. It doesn't matter what you do, might as well do what's good for you.
Actually you know that giving Putin Crimea won't stop him bombing Kiev, seeing as they gave him Crimea, and then he bombed Kiev to get Donetsk. He also suicided politicians while we were buying his gas.
"Once you pay the Danegeld, you'll never get rid of the Dane."
That's one read. For me it feels like practically (ASML, ARM, SAP not withstanding) their only "contribution" to tech is fines and exporting regulation. Sometimes this works out well (usb-c on iPhone), but most of the time it feels like if they want software, hardware, or the web to operate the way they want, perhaps they should try to actually produce some of it instead of being wholly reliant on others while also trying to dictate the terms. I also don't really feel like Trump will do anything, mainly because neither he, nor anyone else before him has any track record of attempting to block or slow EU overreach into US tech interests. Or maybe I'm just cranky and pessimistic.
Google, Apple and co are free not to do business in the EU. There is no "overreach". It's a 450M pop market with a high median per-capita income. There are many reasons why the EU has a rather small tech industry of its own, high up among them that the EU does comparatively little to protect its market compared to China where most US tech companies don't even bother to enter anymore. In China, if a fine like this hits you, you are not allowed to do business anymore until it's either paid or revoked in court. So yeah, the EU is very lenient on all accounts.
Mistral and ElevenLabs seem to be doing pretty well.
Also, here in the U.S., we’ve managed to screw up so badly on data privacy and basic rights that the EU has been systematically replacing their entire tech stack with sovereign components.
On a huge decline and the people are dissatisfied which leads to populist parties becoming more popular and the current governments trying to hold their power by passing draconian laws.
Pretty well, to the point where the US administration complains that there's a trade imbalance. (which is true for manufactured goods, false when we count in services)
Doing just fine calling most of the american insanity for what it is. Beating apple and the likes into submission and making them produce actually somewhat good products.
EU just killed all hardware startups with Cyber Resilience Act. It killed all the SMEs <50 employees in hardware area too. The lost income from European companies will be replaced with fines for US companies. That’s a strategy! Visionaries at work.
So basically you need 3 persons writing compliance documentation and taking care of cybersecurity. Basically another 200000€ personal cost year in low cost area. 250000€ or more in bigger cities. You have a microprocessor in your product and it’s done deal.
No big deal for corporations though. Buddy’s workplace hired new compliance department for this topic with 30 persons. That’s competition european way.
It forces Europeans wanting to build hardware startups to go overseas, so there's even fewer new European hardware companies and Europe becomes even more dependent on the US and China.
Just like everyone left when the GDPR went into place? Having safety standards in place (and yes that also means documenting them) can even be a selling point. To have demonstrably secure hardware according to a standard can be highly desirable.
I think losing the companies that don't have security as a main priority isn't too bad. I assume that the EU will create import restrictions if there is a meaningful shift to avoid EU rules.
From what I gather, the cyber resilience act applies to all products placed on the EU market, regardless of whether the manufacturer is based inside or outside of the EU. So European hardware vendors will be competing on the same terms as American and Chinese ones when it comes to the CRA.
Google Search decision: https://ec.europa.eu/competition/digital_markets_act/cases/2...
Android decision: https://ec.europa.eu/competition/digital_markets_act/cases/2...
Look like feature request lists.
The goal of the regulation is to get the operators to comply, which they usually do after fines (EDIT: and litigations and whining, of course), because the costs of infractions are increased if they don't comply.
The goal should be to incentivise them to comply with the law as a whole, not to keep deliberately breaking different sections of the law to make profit above the level of fines
That's why people want the level of the fines to go up, to disincentivise the more broad lawbreaking
I've never received a dollar from the EU as a victim. If the fines are moderate and big co keeps paying that's steady revenue for the EU institutions.
These companies do, in fact, change behaviour in response to such actions; they may hire lawyers to find and exploit as many loopholes as they can, but they do ultimately comply. Even X ultimately complied in response to Brazil, and the EU is a much more important market for Google than Brazil ever was for X.
(Why would you expect to get dollars from an EU settlement?)
It is almost entirely unsurprising that the EU tech industry is such a disaster area when people say things like this as if they are a good thing.
There's this standard assumption that HN users are well educated.
Budgets don't work like that. It's not like the US federal government collects taxes and then deposits bags of gold coins on people's doorsteps.
Taxes, fines, etc are all collected and then they mostly go to a general, undifferentiated budget which is then divided by the various ministries (departments, whatever).
So yes, if you're a EU citizen you did get the back. As roads, hospitals, research funding.
This isn't a class action.
The correct solution to this is to have fines scaled to the value of a company and an exponential doubling of fines for every re-offence that falls under the same category of crime with a cooling off period after a few years.
The first fine should sting and the second should be damaging to a company and the third should be crippling.
The EU has been fining Google for years to no avail.
EU competition law is not framed around valuing Europeans more than others, it is framed around protecting competition and market functioning inside the EU.
No need to moralize it and pretend anyone is using this "value" European humans more than other humans.
The reasoning is very simple just "carry a big stick", multinational companies need to fear the fines to want compliance.
[0]: https://www.msn.com/en-us/news/crime/meta-says-it-s-staring-...
Corporations reliably break the law, the EU reliably enforces it.
I'm actually happy that this is the path the EU went, as there's a financial incentive to keep laws which benefit consumers.
https://www.irishexaminer.com/business/companies/arid-417489...
€4.536bn on €86.6bn, or about 5% (which is one third of the amount Ireland promised in an international treaty they would charge ...)
Don't blame Google for pushing boundaries. That's what people (and corpos) do in any competitive activity. Do blame our politicians for being incompetent and ill-meaning.
It’s all sort of intertwined now.
Reading about it, both points seem valid to me.
1 - restore interop with noscript/basic HTML browsers, stop favoring your 'whatwg cartel' web engine.
2 - gmail: restore interop with self-hosted SMTP servers without DNS (filtering on the IPv[46] literal from email address, this is stronger than SPF).
And there is probably more to add.
"Once you pay the Danegeld, you'll never get rid of the Dane."
There's no evidence of double tapping the school.
That requires live surveillance. Come back when you have video of that.
One of the groups took over a church where refugees were hiding and burnt them alive in the building.
Also, here in the U.S., we’ve managed to screw up so badly on data privacy and basic rights that the EU has been systematically replacing their entire tech stack with sovereign components.
There is Wikipedia article about this topic: https://en.wikipedia.org/wiki/Cyber_Resilience_Act
No big deal for corporations though. Buddy’s workplace hired new compliance department for this topic with 30 persons. That’s competition european way.
I think losing the companies that don't have security as a main priority isn't too bad. I assume that the EU will create import restrictions if there is a meaningful shift to avoid EU rules.
See also, the GDPR killing startups that attempt to invade our privacy and exploit personal data without permission.