Live data from Hacker News

EU data protection law after the Safe Harbour judgment

eulawanalysis.blogspot.com

61–70 of 80 posts

Re: EU data protection law after the Safe Harbour judgment

#61
post #12

Interesting tidbit: If you try to refer to this article with a link on Facebook, they will block you from posting it.

Very intresting. This is what I've got when trying to post it on facebook: You can't post this because it has a blocked link The content you're trying to share includes a link that our security systems detected to be unsafe: http://eulawanalysis.blogspot.com/2015/10/the-partys-over-eu... Please remove this link to continue. If you think you're seeing this by mistake, please let us know.

They also did that with links to a respected UK male suicide prevention charity - "The Campaign Against Living Miserably".

https://thecalmzone.net/2015/06/ask-facebook-to-remove-the-b...

That page says it's fixed, but it seems that FB is providing the wrong preview, linking to http://www.thecalmx/ instead of http://www.thecalmzone.net/

This spam filter carries a small risk of death, so it's pretty frustrating.

Re: EU data protection law after the Safe Harbour judgment

#62
post #59
post #52

Earlier quoted context omitted.

In general one is allowed to store data for a limited time for specific purposes. A delivery address, for instance, is vital to deliver a package to. You could probably even keep a names and addresses database so long as it was something you needed to keep in order to conduct business with the customer. Routine data mining, asking for irrelevant info, selling it on to third parties, not so much.

Maybe it's just me, but these rules are contradictory. The sentences seem explicitly designed to make that so. For instance, your email address and birthday, for, say, amazon.com, could easily be argued to "need to be kept in order to conduct business". After all, your email ... amazon spams it ... that's certainly part of the business they conduct (and frankly, they'd be more expensive if they didn't do that, so the…

>> that's certainly part of the business they conduct (and frankly, they'd be more expensive if they didn't do that, so there's easy arguments that it'd be harder to do business if they didn't). Your birthday ... same. They spam you harder on your birthday ... also part of their business.

Perhaps then I should have said to conduct transactions.

There is a substantive difference between holding information enough to allow people to buy stuff from you, and holding it to advertise, which usually requires extra permissions.

>> Laws like this won't protect anything.

This is too early to say. They may well protect lots of things, and they certainly can (for instance) be used as a place to start attacking ubiquitous tracking and tracing from.

>> The simple fact is you can't have easy to use sites like google, facebook, amazon and the many millions of easy webshops and have protection of private data, it just wouldn't work as well.

Then perhaps that's OK, because some things are actually more important than commerce. This stuff might have to be hard to get right.

Re: EU data protection law after the Safe Harbour judgment

#63
post #60
post #51

Earlier quoted context omitted.

This was a mistake due to this specific blog post sharing some design elements as some spammy blogspot posts and it was fixed. If we really wanted to censor this story wouldn't we block all criticism of Facebook and not a pretty straightforward and well-reasoned analysis of Safe Harbor? Wouldn't we block the "I declare that I am a wizard and Facebook can't use my content blah blah" memes?

"... due to sharing some design elements..." But someone downthread said the .co.uk version was not blocked (before you unblocked the .com). Are you implying the .co.uk version did not have the same "design elements"? As to your proposed argument, I think selectively blocking well-reasoned analysis by law professors and letting memes go unblocked makes the most sense for your company.

> Are you implying the .co.uk version did not have the same "design elements"?

Classifiers do weird things, and features you don't expect to be significant can suddenly have a much larger than intended effect. The domain name, as a feature, must've thrown it over the edge.

It's like that Google+ post where a picture of a couple of black people got tagged as "gorillas" by their auto-tagging ML system. No, Google isn't racist, their classifier just hates their PR department.

Ah, the joys of machine learning...

Re: EU data protection law after the Safe Harbour judgment

#64
post #60
post #51

Earlier quoted context omitted.

This was a mistake due to this specific blog post sharing some design elements as some spammy blogspot posts and it was fixed. If we really wanted to censor this story wouldn't we block all criticism of Facebook and not a pretty straightforward and well-reasoned analysis of Safe Harbor? Wouldn't we block the "I declare that I am a wizard and Facebook can't use my content blah blah" memes?

"... due to sharing some design elements..." But someone downthread said the .co.uk version was not blocked (before you unblocked the .com). Are you implying the .co.uk version did not have the same "design elements"? As to your proposed argument, I think selectively blocking well-reasoned analysis by law professors and letting memes go unblocked makes the most sense for your company.

Probably because this post was getting lots of links for a domain that is otherwise rarely seen on FB? You can read about the challenges of spam-fighting at scale (and people actually getting paid to write Haskell) here: http://www.wired.com/2015/09/facebooks-new-anti-spam-system-...

Re: EU data protection law after the Safe Harbour judgment

#65
post #33

Earlier quoted context omitted.

That's use of the data to which you've "consented" by their EULA. "Mass surveillance" specifically refers to warrantless bulk access to that data by security agencies. (Shadow profiles are plainly a violation of data protection law; do they exist for EU users?)

Yes they do.

Hmm. It seems that a process is ongoing about this, since 2011: http://europe-v-facebook.org/EN/Complaints/complaints.html

(Irish Data Protection Commissioner is clearly running this at the slowest speed they can get away with)

Re: EU data protection law after the Safe Harbour judgment

#66
post #30
post #19

I think there's a bit of a rush to panic about data balkanisation here; remember, this is not a ruling that applies directly to Facebook, but to the information commissioner of Ireland. There's no new policy and no court orders to do particular things. What's likely to happen is an extensive legal limbo. We may even end up with a special Snowden version of the cookie warning: "Data stored on this system is subject to…

> We may even end up with a special Snowden version of the cookie warning Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent. Update : Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128

It looks like the DPC of Ireland has been "considering" this question since 2011, and still not got anywhere: http://europe-v-facebook.org/EN/Complaints/complaints.html

Re: EU data protection law after the Safe Harbour judgment

#67
post #31
post #24

Earlier quoted context omitted.

Well, viable strategy now for many startups (also EU ones) using US infrastructure is to block all EU customers. How is that good?

It'll do wonders for EU start ups using EU infastructure.

using EU infastructure

...which in many cases doesn't exist yet. In particular, Europe lags significantly in "on-line" services.

Obviously it would solve some problems if this were not the case. However, given that for now it is the case, the price of enforcing a total ban on exporting personal data outside Europe would be closing down vast numbers of on-line European small businesses that aren't intentionally doing anything unreasonable or customer-hostile. Clearly this isn't going to be accepted readily by anyone involved.

A more realistic result when the dust has settled might be yet another disclosure that businesses are required to make prominently when someone buys or signs up for something, in order to be deemed to have explicit consent from the data subject to export the data. This appears at first sight to be a reasonable way to handle the ruling, and in principle I think it's hard to argue with requiring a business to disclose fairly what they're really doing with personal data. Indeed, I've noticed that in recent years organisations like my insurers have started adding terms that explicitly say they're going to export personal data and foreign governments might get access to it, and that if you want to deal with them at all then you have to accept that. (I'm not sure how I feel about such conditions when having the insurance is mandatory by law, as for example with motor insurance for drivers, and based on my experience so far it looks like literally everyone offering such insurance is now imposing similar conditions.)

Then again, for on-line businesses at least, isn't that what privacy policies have evolved to deal with? Separate to this case, under the new consumer protection rules, it seems likely that such policies would now be considered to fall under the same general rules about fairness and transparency as the main terms of a consumer contract. Assuming that is true, I'm not sure there is a huge advantage in cluttering up on-line order/sign-up forms with explicit wording about routine things, while there is certainly a disadvantage in making such forms any more complicated than they need to be. The question then becomes one of reasonable expectations about what a normal customer would consider routine.

I suppose that brings us back to approximately where we came in, other than the fact that it's now a matter of public record that the US government itself was violating those reasonable expectations and opened Pandora's box. Somehow I suspect that if some sort of basic disclosure/consent on sign-up doesn't deal with this issue, it will be addressed by adjusting the relevant European-level legislation so that disclosure to allied governments in the interests of national security is a blanket exemption, and enough people won't know or care about the implications that this will pass even though privacy advocates would surely oppose it.

Re: EU data protection law after the Safe Harbour judgment

#68
post #37

Earlier quoted context omitted.

Then treat personal data as radioactive. Don't store it. Don't collect it if you don't need it. If you have it, try to get rid of it, and delete it ASAP.

That's not practical. "I haven't received my package!" "Well, we sent it 2 weeks ago" "What address did you send it to?" "Don't know" EDIT: Also, "Why does this shopping website require me to re-input the shipping address every time I want to buy something? Why can't it remember it like every website used to?"

Actually its fine if you make the user explicitly give you permission to store it for them. If they 'opt in' then its all good, and if they don't well they will have to re-enter it every time they order but they will be ok with that.

It would be interesting to put some teeth in the "no sharing" rules about collected private information.

Re: EU data protection law after the Safe Harbour judgment

#69
post #30
post #19

I think there's a bit of a rush to panic about data balkanisation here; remember, this is not a ruling that applies directly to Facebook, but to the information commissioner of Ireland. There's no new policy and no court orders to do particular things. What's likely to happen is an extensive legal limbo. We may even end up with a special Snowden version of the cookie warning: "Data stored on this system is subject to…

> We may even end up with a special Snowden version of the cookie warning Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent. Update : Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128

I don't believe such a ruling will be allowed to stand for long, if it really is effectively a blanket ban that can't be overridden by reasonable consent. Enforcing something like that really would have the potential to block international trade on an economy-damaging scale.

Re: EU data protection law after the Safe Harbour judgment

#70
post #31

Earlier quoted context omitted.

It'll do wonders for EU start ups using EU infastructure.

using EU infastructure ...which in many cases doesn't exist yet. In particular, Europe lags significantly in "on-line" services. Obviously it would solve some problems if this were not the case. However, given that for now it is the case, the price of enforcing a total ban on exporting personal data outside Europe would be closing down vast numbers of on-line European small businesses that aren't intentionally doing…

Those startups could rapid prototype using Cloud provide---oh.
Post reply on HN