|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:27 UTC (Tue) by pizza (subscriber, #46)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by paulj
Parent article: Bottomley: Solving the Looming Developer Liability Problem

> The next issue is that EU Directives are *not law*. They are /directives/ for member states to /implement/ a law that meets at least the requirements in the Directive.

That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities, it doesn't make much of a difference how much (or what type) of accelerant each member state chooses to use.

> We will, for quite a while, have all kinds of differences between member states in precisely what "markets" means in different member states. Some may be very trivial differences, some may be more significant.

In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:44 UTC (Tue) by paulj (subscriber, #341) [Link] (1 responses)

It is not at all unusual that member states implementations end up differing. Again, a Directive is a baseline - a member state may go further. Sometimes, member states implement something /looser/ than the Directive, for whatever reason. Sometimes this is deliberate, sometimes it is just because the Directive uses general words and different member states interpreted them differently.

It is not unusual to see a series of "first round" / "early adopter" implementations by a subset of member states, with differences, which then inform the interpretation, and lead to further implementations taking that into account (including some of the "early adopter" member states passing another law). I.e., there may be a legistlative convergence process that goes on, over 5+ years, across member states, where they all look at what each other are passing, with EU committees or industry bodies perhaps criticising some implementations for not meeting some intent.

Least, it is not unusual for the member state I live in to take a few goes at implementing a Directive. Also, it is not that unusual for there to be further Directives on the same matter, to deal with experience from implementations.

And even at the end of all that, there may still be differences, which may take another 5 to 10 years or more to sort out - e.g. cause a member state just disagrees, or didn't prioritise something, and it goes to the ECJ - and only then if there is enough of an issue for someone with standing (EU commission, a member state, or a member state's judicial system) to actually think it should sent to the ECJ.

So yes, it's going to take a good number of years for this to converge on settled and harmonised law across member states.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 21, 2023 16:55 UTC (Thu) by jepsis (subscriber, #130218) [Link]

Direct effect means that certain provisions of EU law, including directives, can be invoked and enforced by individuals or entities in national courts, even if the directive has not yet been implemented into the national legal system.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 21:04 UTC (Tue) by kleptog (subscriber, #1183) [Link]

> That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities

They wouldn't do it. No seriously. The EU Commission has no effective enforcement mechanism to ensure countries actually implement the directives faithfully. The whole point of the marathon trilogues and engagement of the Council and Parliament is to get a draft text the member states are actually willing to implement faithfully. If a member state at this point already feels that they'll get push back from their national parliament then they have to keep renegotiating until they get something that will work. (Note: it's up to the member state to organise this feedback loop properly.)

So every national parliament gets to give its own twist to this and no national government is going to "set fire to F/OSS activities" as you put it. This will lead to about a decade of discussion and negotiation while all the kinks get sorted out. The problem with this kind of pioneering legislation is that it's really hard to think of all the corner cases up front and you're better off just doing the best you can and keeping the enforcement light while all the kinks get worked out.

> In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.

Welcome to the EU. We don't want to be a federation, so we do everything the hard way. The alternative, where every state does their own thing without any coordination, would be much much worse.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds