Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

141–150 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#141

Earlier quoted context omitted.

I've never understood what would happen if Google or Facebook just ignored EU regulations, claimed that they were not under the EU's jurisdiction, and ignored any judgement. Would the EU erect a great firewall at that point?

Couldn't they just take the money owed the usual way, by freezing accounts, confiscating assets, etc.? None of these corporations can feasibly avoid that without exiting EU markets altogether.

> None of these corporations can feasibly avoid that without exiting EU markets altogether.

Ultimately if the fines or compliance costs get too high that's exactly what happens. A company that does no business in the EU is not subject to EU rules. But because it is such a large and wealthy market the threshold is very high. If Kazakstan passed a similar law it'd be a very different story.

Re: How the GDPR Will Disrupt Google and Facebook

#142

Earlier quoted context omitted.

The legislation itself refers to this in article 7.4: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. " I don't think it is forbidden, but you'd have a hard time explaining wh…

A couple of specific scenarios: Visit turbotax.com to file a tax return, it asks for your bank account before you fill out the tax information. But it's not required, unless you're reporting interest earnings on that account. On turbotax.com, after you fill out the tax form you have a refund of overpaid taxes. The site asks for your bank account in order to arrange for the refund to be deposited, or instead they can…

I misworded these hypothetical scenarios, making them seem like they would actually happen today. I don't recall that it asks you for bank account numbers before you even begin. It probably doesn't. I have used turbotax for years and had pretty much the same bank accounts during that time. It does ask for the numbers at reasonable times. If you don't give them you can still use Turbotax to take care of business.

Re: How the GDPR Will Disrupt Google and Facebook

#143
post #140
post #137

Earlier quoted context omitted.

Leaking PII isn't the main issue. Processing of PII is. And Facebook et. al. do a lot of that.

Yeah but they have the resources to deal with these regulations. The parent comment complains about smaller companies having to deal with these regulations.

These regulations aren't all that onerous, to be honest.

Take a look at this link, for example: https://iconewsblog.org.uk/2017/08/25/gdpr-is-an-evolution-i...

Re: How the GDPR Will Disrupt Google and Facebook

#144
post #99

Earlier quoted context omitted.

>We as European businessmen were and still are unable to generate the same kind of innovation as the US I don't want US innovation. Thanks for the offer.

Does that mean you avoid services like facebook or google? Many of those innovations are based on data collection and using that to make customer segments to sell targeted ads. Without that model you may be asked to pay a few dollars or see additional ads that are more likely to be less interesting.

Does that mean you avoid services like facebook or google?

Plenty of us do.

Re: How the GDPR Will Disrupt Google and Facebook

#145
post #109

I encourage a little more thought before cheering this on as a win. While GDPR isn't as ridiculous as the Cookie Law, it still shows that the EU/EC don't understand the technology they are trying to regulate, and it comes at a huge cost to tech companies. Take the right to be forgotten . First of all, it should be common sense that no one has the right to force legitimate news articles to disappear because they don't…

You need to research the right to be forgotten as it applies to news articles, it doesn't work in the way you describe. And as far as this stuff being difficult to do, sure, but isn't it worth doing? Why shouldn't a customer have a say which cloud provider hosts their data? Why shouldn't we be able to make sure no data is kept about us after we stop using a service? Like with anything novel in software it only seems…

> You need to research the right to be forgotten as it applies to news articles, it doesn't work in the way you describe.

I was referring to Google vs. Costeja, which I realize isn't GDPR, but an EU court did rule that way.

> You don't need a compliance officer, but you do need a security officer

I strongly believe that compliance and security are two very different things, that are only slightly related. They come at it from a very different perspectives. A security engineer should be doing threat modeling and protecting against threat vectors. A compliance officer may consult a security engineer, but ultimately their job is to check boxes to make sure regulations are followed. I think compliance staff are more appropriately part of a legal team than an engineering team.

That isn't to say compliance officers aren't useful. Having a strong compliance voice can be great. I've seen companies without a compliance officer reduce security because an auditor told them regulations required something. A good compliance officer would have been able to push back against the auditors, pointing out what regulations actually require, and working with the security engineers to come up with a solution that meets regulations and actually improves security.

Re: How the GDPR Will Disrupt Google and Facebook

#146
post #44

Earlier quoted context omitted.

I wish more penalties were like this. This sounds great. Now these companies will finally have real incentive to comply. Hell, the percentages should be higher. That's the only way to enforce regulations. Otherwise, they'll just pay a puny fine, American style, and not do shit.

I've never understood what would happen if Google or Facebook just ignored EU regulations, claimed that they were not under the EU's jurisdiction, and ignored any judgement. Would the EU erect a great firewall at that point?

Things like this: https://www.wsj.com/articles/facebook-executive-arrested-in-...

The advantage of having armies and police forces is that you can lock people up who don't adhere to your rules. Good luck having any employees in Europe if you decide to ignore their regulations!

Re: How the GDPR Will Disrupt Google and Facebook

#147
post #143
post #140

Earlier quoted context omitted.

Yeah but they have the resources to deal with these regulations. The parent comment complains about smaller companies having to deal with these regulations.

These regulations aren't all that onerous, to be honest. Take a look at this link, for example: https://iconewsblog.org.uk/2017/08/25/gdpr-is-an-evolution-i...

I completely agree. This is only hurting companies which business is to track their users. Which is why I personally have very little sympathy for people complaining that we're moving their cheese.

Re: How the GDPR Will Disrupt Google and Facebook

#148

> The critical question for both businesses is whether users will click “yes”, when asked to consent. Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's…

Yes, users will click yes on basically anything.

No, they won't. When the EU imposed new consumer protection rules not so long ago, it resulted in having to put some scary-looking legalese directly on your sales funnel pages if you were supplying digital content, even if said legalese was of no practical value to anyone including your customer. That alone was enough to hurt conversions, even if you didn't require something like a token checkbox to be ticked before continuing. The GDPR compliance requirements are potentially on an entirely different scale.

Re: How the GDPR Will Disrupt Google and Facebook

#150
post #138

Earlier quoted context omitted.

This is not new and if your backup system does not comply with regulations, it's probably more of a design problem. Perhaps, but it's a design problem that approximately 100% of otherwise reasonable backup systems will have, and working around it comprehensively will be extraordinarily expensive. Do we really want to impose rules that incentivize businesses storing personal data on behalf of their customers not to ba…

It feels like the reaction of a VW engineer complaining that CO2 emissions regulations are making his job complicated. Yeah, if you want the data, you need to be able to handle the data in a compliant way. The other solution is to not collect the data. Keep in mind that this is targeted at user tracking. Don't expect me to be sympathetic to the troubles of backing up all of that tracking data.

Yeah, if you want the data, you need to be able to handle the data in a compliant way. The other solution is to not collect the data.

But since that data will include things like routine server logs, back-ups of customer records necessary for statutory financial record-keeping purposes, and so on, it's never that easy. With such a broadly written law, you could spend a small fortune on legal advice just to find out what your real, practical obligations are to make a good faith attempt to comply.

Keep in mind that this is targeted at user tracking.

The intent might have been to go after user tracking, but unfortunately, that's not what the law they made actually says.

Post reply on HN