Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

331–340 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#331

Earlier quoted context omitted.

You seem to be responding to an entirely different GP post to the one I read, which seemed pretty clear that the GP's company isn't doing the kind of tracking and analytics that a lot of people might say were "NOT OK". It's easy to post bold privacy advocacy from the cheap seats, but I suspect you wouldn't like a world where these new rules really were enforced to the letter. Many of the organisations whose products…

GP's company isn't doing the kind of tracking and analytics that a lot of people might say were "NOT OK". GP's company isn't doing the tracking and analytics, but it is pulling data from companies that do. Therefore, regulations that affect GP's customers affect GP. This is right and proper, and I don't see what the problem is.

This is right and proper, and I don't see what the problem is.

The problem is that it will be almost impossible to comply with the letter of the law in this case without either imposing prohibitive levels of overhead or disregarding other good practices like logging diagnostics and keeping robust backups in case things go wrong.

There's a saying about babies and bathwater, but this is more like requiring the entire house to be rebuilt in order to throw out the bathwater. Sure, you can do it, but it's much easier to say that when it's someone else's manual labour being paid for by someone else's money that will make it happen.

Re: How the GDPR Will Disrupt Google and Facebook

#333

Earlier quoted context omitted.

Laws don't change in a matter of one or two days. So if they did this shutdown with the argument being that they otherwise can't offer their service in a legal way, it would have to be a permanent shutdown (or at least on a scale of several months, until the law is changed), because everything else would effectively result in openly admitting that they are knowingly running an illegal service. If that happens, how lo…

Laws don't change in a matter of one or two days. True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time. In most cases, I'd say that was extremely optimistic. However, in this case we're talking about a service used by probably a large majority of voters ac…

> True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time.

Interesting idea. I did not think about this, mostly probably because I would never do this if I was Facebook because there is a very real risk of it back-firing. Many people here (I'm living in Germany), especially among the politically active, are in a kind of love-hate relationship with Facebook, and a clear attempt of blackmailing an entire continents' population in order to force political action in favor of an absurdly rich, multinational corporation could very well kill off whatever positive attitude there is towards Facebook in particular.

As of competition having to comply with the privacy law: of course it would have to. But I also assume that this is not impossible at all, it is just inconvenient and costly, especially if you have a huge legacy system built under the assumption that you can do practically everything with the data of your users. If you design your system in compliance with the data protection law in the first place, this gets considerably easier. Money would not be a problem at all: there are more than enough investors in Europe who would love to throw money at an attempt to create a second multi-billion-dollar money-printing machine in a market that is currently assumed to have a very high barrier of entry (but exactly that would change if Facebook gave up on Europe).

I also assume that it will not be impossible at all for Facebook to comply with these regulations, just pretty inconvenient. Under this assumption, any refusal to comply must automatically be motivated by a desire to maximize profits and minimize political influence on the platform, not by a sheer struggle for survival. Facebook's PR department might try to spin this into a different story, however...

Re: How the GDPR Will Disrupt Google and Facebook

#334

While I see some of the concerns about the _technicality_ of the law as completely legitimate, it still bothers me that so many people reject the whole spirit of this law, and cannot put the negative of "tax on startups" against the much greater good of personal privacy. I've just started a business myself, and this regulation affects my company too. It makes development costlier; it'll take from the precious little…

Possibly because personal privacy as a "much greater good" is open to debate. People place wildly differing values on that property. Google's current ecosystem of data-sharing means that Assistant can make educated context guesses on what I mean when I talk to it based on my browser history and map navigation history. If the new privacy constraints damage that passive interconnection, that's not a net good for me.

> ... privacy as a "much greater good" is open to debate

I agree, but that's a different topic, really. The comments here aren't about the (un)/importance of privacy. The main debate seems to be either about the technicality of the law and its possible unintended consequences, which are legitimate concerns, or they're about how "this is gonna make my job much harder," which is not really a legitimate concern in this context, and those comments were the ones I was talking about.

> Google's current ecosystem of data-sharing means that Assistant can make educated context guesses on what I mean when I talk to it based on my browser history and map navigation history. If the new privacy constraints damage that passive interconnection, that's not a net good for me.

I think we're overestimating a technical difficulty here, and downplaying a moral principle.

Providing a personalised service without storing large amounts of personal information in a central location is not impossible. It's just technically harder to do.

And even if it was impossible, then still, we need to sort out the moral consequences first. Not by banning technological progress of course, but perhaps by bringing more oversight to corporations. Or by making sure that people of lower socioeconomic background aren't hit harder than the wealthy.

Re: How the GDPR Will Disrupt Google and Facebook

#335
post #53

Earlier quoted context omitted.

It's a percent from revenue not from profit. So 5% from google revenue is a lot

It is. On the other hand, companies like Google/Facebook/MS/Apple have such huge profit margins that a conviction will be but a speed bump, and given that their business model is based on the data regulated by GDPR to such a great extent, one may expect them to challenge the new regulations as much as they can. They also (probably) have the most competent legal divisions, which will help them exploit any gray areas.…

Yeah, but 4%/20m is only the third strike. If as a small company you're unwilling or unable to fix those issues in a reasonable time frame after the first two strikes, you might not deserve to survive as a business in the first place.

Re: How the GDPR Will Disrupt Google and Facebook

#336
post #329
post #305

Earlier quoted context omitted.

I'm not so sure. And it's not just ad-targetting - all kinds of personalized stuff and simply general purpose data mining suffer too. And don't forget that they wouldn't get the full 4% immediately; and would likely be fined much less than once per year based on current trends anyhow. So that 4% is going to be further diluted.

That's not what has happened so far. The search Engine Results fine of €2.4bn was based on the length and severity of past infringement and they were threatened with a $10m per day fine, equivalent to 5% of global revenue, on an ongoing basis if they didn't comply within 90 days. So they absolutely have been hit with a heavy lump sum fine from day one. There's no need to theorise about how the EU might enforce such l…

Google's revenue is all about data collection. If they can't collect lots of data, the whole business model is a lot more questionable. In the face of that, 2.4bn once is a trivial fine; consider that that's something like what... 3% of their revenue in one year?

Of course they'll try to avoid that in the future, but the fine is mild enough that it's not going to cause firms to err on the side of caution. They're going to look for the absolute edge of the law.

Frankly, if google had not leveraged their search "monopoly" (not quite a monopoly), I suspect their market cap would have been more than 2.4bn lower; so this was a pure win - especially since conviction and detection aren't a slam dunk.

Re: How the GDPR Will Disrupt Google and Facebook

#337
post #336
post #329

Earlier quoted context omitted.

That's not what has happened so far. The search Engine Results fine of €2.4bn was based on the length and severity of past infringement and they were threatened with a $10m per day fine, equivalent to 5% of global revenue, on an ongoing basis if they didn't comply within 90 days. So they absolutely have been hit with a heavy lump sum fine from day one. There's no need to theorise about how the EU might enforce such l…

Google's revenue is all about data collection. If they can't collect lots of data, the whole business model is a lot more questionable. In the face of that, 2.4bn once is a trivial fine; consider that that's something like what... 3% of their revenue in one year? Of course they'll try to avoid that in the future, but the fine is mild enough that it's not going to cause firms to err on the side of caution. They're goi…

Did you even read my post? It wasn't €2.4bn once, it was that PLUS €10m PER DAY of persistent non compliance. That would have come to €3.6bn per year.

The lump sum was just for backdated non compliance.

Re: How the GDPR Will Disrupt Google and Facebook

#338

Earlier quoted context omitted.

Laws don't change in a matter of one or two days. True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time. In most cases, I'd say that was extremely optimistic. However, in this case we're talking about a service used by probably a large majority of voters ac…

> True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time. Interesting idea. I did not think about this, mostly probably because I would never do this if I was Facebook because there is a very real risk of it back-firing. Many people here (I'm living in Germa…

I also assume that it will not be impossible at all for Facebook to comply with these regulations, just pretty inconvenient.

This is a common assumption, and it might prove to be correct, but I'm unwilling to accept it as axiomatic.

Fundamentally, just looking at the right of a data subject to withdraw consent, it would mean Facebook needed to track every piece of data that could conceivably be tied back to an identifiable person throughout its entire organisation. That's not just their status updates or that time a friend tagged them in a photo. It's every photo in Facebook's entire database that ever included a recognisable image of them, tagged or not. It's every line in a log file that was saved by an engineer investigating a server glitch that relates to any activity that user took. It's everyone who uploads their contacts to find friends and has one of those data subjects in their contact list.

Now, I'm not saying I think Facebook should necessarily be able to do all of the above. In particular, I have often questioned their hoarding of data from things like contact details and photos that will inevitably include other people who may not have chosen to use Facebook or give their consent.

But I am questioning whether it is practically viable, even for an organisation with Facebook's scale and resources, to follow the letter of this law and still operate at all while continuing to provide similar services, if a few people decide to make a point and explicitly deny consent to hold any data about them, even if such data was supplied by other people. There are practical, ethical and legal issues here about third parties and automated systems that we have barely begun to explore, and we're talking about them at a scale where businesses like Facebook and Google have already had to invent new techniques and strategies for organising data just to cope with what they already do.

None of this has even touched yet on whether Facebook would still have a viable commercial model if users have a right to opt out of processing their data for purposes such as advertising but Facebook isn't allowed to deny them service in return, which is another interpretation I've seen talked about a lot (on the basis that an opt-out that stops you using something independent as well isn't a true opt-out and so wouldn't count). So far, I haven't studied the GDPR and informed reviews of it enough to reach any firm conclusions or opinions on that side of things, but again there are surely issues about the obligations of an organisation that offers a useful service but relies on advertising to fund it that go far deeper than just Facebook and the GDPR that haven't really been explored up to this point.

As surprising as it may seem given my comments in this discussion, I'm actually a pretty firm believer in stronger privacy rights and a confirmed sceptic when it comes to the big data hoarders like Facebook and Google. But I'm also someone who runs businesses and has first-hand experience of what happens when the EU's non-technical legislators meddle in technical issues they don't fully understand, often missing even the blindingly obvious consequences, never mind the more subtle and/or long-term implications. So I don't think we should dive into changes like this without considerable thought, and contrary to what various officials from the EU and the national data protection authorities like to say, I don't believe for a moment that this sort of change is a small, incremental development of the existing privacy frameworks we already operate under.

Re: How the GDPR Will Disrupt Google and Facebook

#339

Earlier quoted context omitted.

> True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time. Interesting idea. I did not think about this, mostly probably because I would never do this if I was Facebook because there is a very real risk of it back-firing. Many people here (I'm living in Germa…

I also assume that it will not be impossible at all for Facebook to comply with these regulations, just pretty inconvenient. This is a common assumption, and it might prove to be correct, but I'm unwilling to accept it as axiomatic. Fundamentally, just looking at the right of a data subject to withdraw consent, it would mean Facebook needed to track every piece of data that could conceivably be tied back to an identi…

> It's every photo in Facebook's entire database that ever included a recognisable image of them, tagged or not.

That is from my understanding wrong. In fact Facebook would not be permitted to establish the link. Just you appearing in the picture but it not being your picture does not qualify for personal data.

Re: How the GDPR Will Disrupt Google and Facebook

#340

Earlier quoted context omitted.

I also assume that it will not be impossible at all for Facebook to comply with these regulations, just pretty inconvenient. This is a common assumption, and it might prove to be correct, but I'm unwilling to accept it as axiomatic. Fundamentally, just looking at the right of a data subject to withdraw consent, it would mean Facebook needed to track every piece of data that could conceivably be tied back to an identi…

> It's every photo in Facebook's entire database that ever included a recognisable image of them, tagged or not. That is from my understanding wrong. In fact Facebook would not be permitted to establish the link. Just you appearing in the picture but it not being your picture does not qualify for personal data.

Any information that relates to an identified or identifiable natural person is personal data for these purposes. This remains essentially the same, except for a slightly broader specification of what constitutes identifiability, under the GDPR as under the current EU framework. In particular, under the GDPR, identifiers explicitly include factors specific to a person's physical or genetic identity.

In short, if you're in a photo and it's recognisably you, it's personal data.

Post reply on HN