|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:17 UTC (Tue) by bluca (subscriber, #118303)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem

Exactly, and it clearly uses the verb "market", which most definitely does not include J. Random doing a git clone out of the first repository it finds on the internet.


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 16:34 UTC (Tue) by paulj (subscriber, #341) [Link] (8 responses)

The next issue is that EU Directives are *not law*. They are /directives/ for member states to /implement/ a law that meets at least the requirements in the Directive. Nothing stops a member state implementing a directive plus more. The member state law will be - in the first instance - interpreted according to the member state's own jurisprudence for any cases arising within the member state. The /intent/ of the EU legislators has /little/ to do with this.

We will, for quite a while, have all kinds of differences between member states in precisely what "markets" means in different member states. Some may be very trivial differences, some may be more significant. There may be member states whose legislature and/or judiciary creates a law where "markets" has a meaning much wider than any of us here would like. Further, it may take a long time before a case ever gets to the European Court of Justice to decide whether or not that difference is worth addressing/fixing. Indeed, one member state's interpretation of the Directive, as expressed in its implementation may influence others and lead to there being no difference for the ECJ to have to rule on.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:27 UTC (Tue) by pizza (subscriber, #46) [Link] (3 responses)

> The next issue is that EU Directives are *not law*. They are /directives/ for member states to /implement/ a law that meets at least the requirements in the Directive.

That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities, it doesn't make much of a difference how much (or what type) of accelerant each member state chooses to use.

> We will, for quite a while, have all kinds of differences between member states in precisely what "markets" means in different member states. Some may be very trivial differences, some may be more significant.

In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:44 UTC (Tue) by paulj (subscriber, #341) [Link] (1 responses)

It is not at all unusual that member states implementations end up differing. Again, a Directive is a baseline - a member state may go further. Sometimes, member states implement something /looser/ than the Directive, for whatever reason. Sometimes this is deliberate, sometimes it is just because the Directive uses general words and different member states interpreted them differently.

It is not unusual to see a series of "first round" / "early adopter" implementations by a subset of member states, with differences, which then inform the interpretation, and lead to further implementations taking that into account (including some of the "early adopter" member states passing another law). I.e., there may be a legistlative convergence process that goes on, over 5+ years, across member states, where they all look at what each other are passing, with EU committees or industry bodies perhaps criticising some implementations for not meeting some intent.

Least, it is not unusual for the member state I live in to take a few goes at implementing a Directive. Also, it is not that unusual for there to be further Directives on the same matter, to deal with experience from implementations.

And even at the end of all that, there may still be differences, which may take another 5 to 10 years or more to sort out - e.g. cause a member state just disagrees, or didn't prioritise something, and it goes to the ECJ - and only then if there is enough of an issue for someone with standing (EU commission, a member state, or a member state's judicial system) to actually think it should sent to the ECJ.

So yes, it's going to take a good number of years for this to converge on settled and harmonised law across member states.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 21, 2023 16:55 UTC (Thu) by jepsis (subscriber, #130218) [Link]

Direct effect means that certain provisions of EU law, including directives, can be invoked and enforced by individuals or entities in national courts, even if the directive has not yet been implemented into the national legal system.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 21:04 UTC (Tue) by kleptog (subscriber, #1183) [Link]

> That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities

They wouldn't do it. No seriously. The EU Commission has no effective enforcement mechanism to ensure countries actually implement the directives faithfully. The whole point of the marathon trilogues and engagement of the Council and Parliament is to get a draft text the member states are actually willing to implement faithfully. If a member state at this point already feels that they'll get push back from their national parliament then they have to keep renegotiating until they get something that will work. (Note: it's up to the member state to organise this feedback loop properly.)

So every national parliament gets to give its own twist to this and no national government is going to "set fire to F/OSS activities" as you put it. This will lead to about a decade of discussion and negotiation while all the kinks get sorted out. The problem with this kind of pioneering legislation is that it's really hard to think of all the corner cases up front and you're better off just doing the best you can and keeping the enforcement light while all the kinks get worked out.

> In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.

Welcome to the EU. We don't want to be a federation, so we do everything the hard way. The alternative, where every state does their own thing without any coordination, would be much much worse.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 21:14 UTC (Tue) by bluca (subscriber, #118303) [Link] (3 responses)

No, the CRA is a regulation, not a directive: https://european-union.europa.eu/institutions-law-budget/law/types-legislation_en
It has immediate and direct effect.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:41 UTC (Wed) by paulj (subscriber, #341) [Link] (2 responses)

I had missed it was a regulation. Thanks for pointing that out. Huge difference. I'm surprised something as sweeping as this can be done by regulation.

Reading the CRA, they appear to be exercising authority to regulate primarily based on Articles 173, and 322(2) (for budgetary things?) of the Treaty on the Functioning of the European Union:

https://www.legislation.gov.uk/eut/teec/article/173 (Industry Competitiveness)
https://www.legislation.gov.uk/eut/teec/article/322 (Common Provisions)

Article 173 is worth reading carefully. Does the CRA follow the objectives of paragraph 1? Does it distort competition? Does it favour or disfavour small and medium-sized businesses?

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:45 UTC (Wed) by paulj (subscriber, #341) [Link]

Note that in the first instance it will still be member state agencies and judicial systems that interpret this Regulation and apply it practically. And differences can arise - between what we here think the legislators intent was, and also between member states. And such differences ultimately must go to the ECJ, to be harmonised - which may take time, if ever.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 16:26 UTC (Wed) by kleptog (subscriber, #1183) [Link]

Just one last comment (just saw corbet's note).

The Act includes a section about why it is a regulation, every act has to specify why it is a directive or regulation and the legal basis for it. While in principle a regulation is effective everywhere at once, the actual enforcement is to be done by entities which don't exist yet and will need to be created by the member states. The entities will be underfunded (they always are) and will not have time to go after anything but the biggest companies.

Also note the fines are actually the sideshow. The primary goal is that the terms get included in B2B contracts and that businesses start holding each other to account. That's the only way to influence suppliers outside the EU.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 28, 2023 10:35 UTC (Thu) by gfernandes (subscriber, #119910) [Link] (1 responses)

As used in the text, it would imply "market" is a noun - not a verb ("...made available *in the market*). Therefore would imply the regulation reads indirectly on developers contributing directly or indirectly to what eventually is assembled into a product that is shipped either for a price or made available free of cost.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 28, 2023 12:01 UTC (Thu) by Wol (subscriber, #4433) [Link]

> Therefore would imply the regulation reads indirectly on developers

Spot on. I like the use of the word *INDIRECTLY*. Which means the legislation does *not* apply to developers.

Sure they have to take it into account - inasmuch as they have a *contractual* relationship with the people to whom the regulation *does* apply.

NO CONTRACT? NO LIABILITY!

As the Europeans here keep saying !!!

I know in America anybody can sue anybody else for any thing. And in America, it can be a business tactic for bankrupting the competition.

But in the UK, the Court's very first question is going to be "Where is the agreement between you? I want to read it". And if that agreement says "here's a freebie, if it breaks you can keep both pieces", the Court is going to be EXTREMELY upset with the plaintiff.

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds