Earlier quoted context omitted.
The GDPR isn't actually as bad as people claim. The law is actually pretty reasonable. It is the result of years of discussion and deliberation. In fact, privacy watchdogs are complaining that it doesn't go far enough - it leaves plenty of holes. Most of the GDPR is about informed consent, having a valid reason for processing personal data and individual rights. Facebook will do just fine, they had years to prepare a…
How is the law reasonable? It's not even clear what is allowed under it and what isn't. The EU refuses to clarify anything, the only time any decision will be made is by courts, if there's an actual dispute in progress. The rules are so vague that any firm could be argued to be in violation. And the EU acts as judge, jury and executioner. It looks like a way to tax the SV tech firms without needing a treaty change. A…
German court rules Facebook use of personal data illegal
231–240 of 404 posts
Re: German court rules Facebook use of personal data illegal
#232Earlier quoted context omitted.
If you volunteer your data to Facebook I have a hard time considering you to have been “exploited.”
I don't have a strong position on the broader issue, but I feel like this argument ignores some context. It's one thing to sign up for your local car wash's loyal program and have them do some lightweight customer research on the data. It's quite another for to input your demographic info and interests into a social networking site and have it be analyzed by some of the most sophisticated data analytics in history. T…
Re: German court rules Facebook use of personal data illegal
#233Earlier quoted context omitted.
No. That's not how the EU works. That's how a national government would work but not the EU. The GDPR is not a directive so it does not have to be translated into national law. It is directly binding and applies immediately everywhere. Fines have to be paid up front, before appeals are exhausted. Appeals can of course take years. The EU courts have judges appointed by the same people who control the rest of the EU, a…
No, the enforcement is through the national "supervisory authorities" such as the ICO. Most of the enforcement process is through national courts and the ECJ is only for the final layer of appeal. This very article says "German Court rules ..." > voided the UK's opt out of new human rights related legislation, despite a very clear paragraph in the treaties saying they did not apply to the UK. [citation needed]; did y…
In the section "Wasn’t the UK supposed to get an opt-out from EU human rights laws?"
The summary is, when the Treaty of Lisbon awarded the EU new human rights powers the UK and Poland negotiated an opt out which was written in the treaty. It was a part of convincing the UK government to accept the new treaty without granting a referendum on it, as they had previously promised.
The opt out is very clear, really as clear as lawyers can make such things. It says:
The charter does not extend the ability of the CJEU, or any court or tribunal of… the United Kingdom, to find that the laws, regulations or administrative provisions, practices or action of… the United Kingdom are inconsistent with the fundamental rights, freedoms and principles that it reaffirms
and
In particular, and for the avoidance of doubt, nothing in Title IV of the Charter creates justiciable rights applicable to Poland or the United Kingdom except in so far as Poland or the United Kingdom has provided for such rights in its national law
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:C:2...
In other words, this part of the treaty does not allow the courts to overturn UK laws. Stated twice, for clarity.
A few years later the ECJ decided that the opt out was meaningless and voided it, under a new interpretation that they claimed meant they'd actually always had these powers, and therefore the treaty did not "extend" them, and so the opt out didn't "work" despite its apparently clear wording. They then began overturning UK laws.
It's unclear why the treaty had anything new in it at all if the courts had always had these powers of course, but this is how things go in the EU - no matter how plainly something seems to be written, no matter how clear the assurances seem to be at the time, the moment it becomes politically inconvenient to the project the rules are tossed out under bizarre and kafkaesque re-interpretations.
Same thing happened to Ireland with corporation tax. They were promised the EU wouldn't interfere with their tax policies. Then the EU decided low taxes were "state aid" and awarded itself the power to control Irish tax policy. Nobody had previously interpreted the state aid clauses that way.
Re: German court rules Facebook use of personal data illegal
#234Earlier quoted context omitted.
The GDPR isn't actually as bad as people claim. The law is actually pretty reasonable. It is the result of years of discussion and deliberation. In fact, privacy watchdogs are complaining that it doesn't go far enough - it leaves plenty of holes. Most of the GDPR is about informed consent, having a valid reason for processing personal data and individual rights. Facebook will do just fine, they had years to prepare a…
> Facebook will do just fine, they had years to prepare and an army of lawyers. They won't do fine. Don't want to go into details but their actual products/required architectures for their products just can't be GDPR compliant. And they didn't prepare anything. You confuse them with Google--they prepared GDPR but FB? Btw, one of GDPR's key motivation was to take FB down.
Re: German court rules Facebook use of personal data illegal
#235Earlier quoted context omitted.
Can you elaborate on which scheme you mean please?
https://www.theguardian.com/small-business-network/2014/nov/... and https://www.theguardian.com/small-business-network/2015/sep/... my solution was to stop selling into the EU, though amusingly once the UK leaves the EU I'll be able to start again (by just ignoring the EU's VAT rules)
> new VAT scheme
whereas this is from 2015. I was confused by language where you described it as a law to target Amazon. Now I see that was just an opinion.
> my solution was to stop selling into the EU
Interesting business decision. Was the cost of compliance that high, or was your revenue that trivial?
> though amusingly once the UK leaves the EU I'll be able to start again (by just ignoring the EU's VAT rules)
Well I was having a conversation with one of the UK's foremost VAT specialists on Friday, from one of the UK big 4 accountancy firms. He was very clear that the general opinion is that the UK will align with the EU for VAT. This was a response to my question about the catastrophic cashflow impact that losing the VAT rules on imports would have to UK businesses. He told me not to worry, as VAT alignment was simply a necessity.
Re: German court rules Facebook use of personal data illegal
#236Earlier quoted context omitted.
> Btw, one of GDPR's key motivation was to take FB down. this all seems very similar to the new VAT scheme, in that it was designed to target a foreign giant (Amazon), which was barely affected as a result, and instead ended up hurting the competitiveness of the EU's own small businesses the EU Commission's response to small business concerns about that new VAT scheme? "we'll allocate some time to talk about that in…
That's not entirely true - MOSS actually works quite well, and preparing a sales report grouped by country should be trivial no matter what infrastructure you're using.
Re: German court rules Facebook use of personal data illegal
#237Earlier quoted context omitted.
Well, it's not that - before that law was introduced, you could simply ignore the country, since it's about digital downloads. If all you cared for was getting a payment, it was not unusual to have the transaction list in the forms of e-mails. Now you need much more information.
A customer is entitled to an invoice and a full invoice requires an address. Most businesses that offer digital goods and services should have had that even before. All the people I know that were affected by the VAT changes certainly had all customer adresses. This is not a cash sale in a local book store.
the significant problem is now the fact that I have to register for VAT domestically if I want to to sell to people in other EU countries
before if my turnover was below ~£70,000 I paid no VAT at all due to the exemption (giving me a competitive edge vs. big companies with better economies of scale)
after the new regulations if I make any EU sales I have to either fill in VAT returns for EU member state I've sold to (not feasible, that would be hundreds of VAT returns/year in many languages), or register for domestic VAT which will handle that for me, but kills my business model
the EU Commission doesn't see this as a significant problem, likely as it is a beneficiary of VAT (the VAT being an EU mandated tax)
Re: German court rules Facebook use of personal data illegal
#2382 don't sell your soul to marketing parasites
Seems like common sense really but it has (US) companies scrambling. Good. We are GDPR!
Re: German court rules Facebook use of personal data illegal
#239Earlier quoted context omitted.
> How is the law reasonable? It's not even clear what is allowed under it and what isn't. The EU refuses to clarify anything, the only time any decision will be made is by courts, if there's an actual dispute in progress. How is that different from a US law like HIPAA? The structures of the law seem largely the same, in that they give you guidelines to follow, but provide no clarity about what specifically is require…
HIPAA and other mega-regulations like them have the same problems. And they do cause people to just give up rather than deal with the risk. I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at…
As someone who worked extensively on HIPAA covered data and systems, there are only three options here.
Option 1) Mandate no data protection. This is how you end up with hidden security dumpster fires like Equifax, when public companies are involved (cost of security vs profit).
Option 2) Strictly mandate how companies must behave to be compliant. Example: DoD (I believe?). Legal requirements always lag technical best practices.
Option 3) Generally mandate what compliance results in. Example: HIPAA. Results in lack of clarity and legal challenges.
Of these options, I'll take (3) every time.
If a startup isn't willing to make a best effort to comply (which is specifically worded into HIPAA and substantially reduces penalties), then I'd rather they not be able to touch my health data anyway...
Re: German court rules Facebook use of personal data illegal
#240Earlier quoted context omitted.
That's not entirely true - MOSS actually works quite well, and preparing a sales report grouped by country should be trivial no matter what infrastructure you're using.
If you cannot provide a list of sales by country, you maybe should not be running a business.
There are two hard parts to what the EU did, for businesses.
The first is you have to charge variable VAT rates and remit the collected tax. However VAT rates do vary not only by country but in some cases within countries too, and they do change, so you have to make sure you have a really up to date list of tax rates and geographies where they apply. Including varying rates down to the city levels.
But the real kicker is that you can't trust the user's claim about where they are. Users are financially incentivised to lie about their location because these are digital downloads. So if they claim to live in a low VAT region they pay less, but download the same files. Simple as that.
As a consequence the VAT regulations have a LOT of complicated edge cases and "guidance" in them about how to figure out where the user really is, not where they say they are. This is hard of course, the user may be using VPNs and so on. There is specific guidance on how to handle users who are on ships sailing between VAT regions, or planes that are in the air when a purchase is made. So you've got a really complex pile of logic to start with, and then you're also in an adversarial situation where the users are all trying to screw you over by forging their location. And if they succeed, you can suffer big fines.
Oh and finally of course, you can't use any technical tricks to figure out where the user actually is, because then you'd violate EU privacy laws ... have fun with all of this! In practice it has to all be outsourced, it is too much work to implement in house for all but the largest of firms.