Live data from Hacker News

German court rules Facebook use of personal data illegal

reuters.com

241–250 of 404 posts

Re: German court rules Facebook use of personal data illegal

#241

Earlier quoted context omitted.

The GDPR is beautiful and an example of the best outcomes democracy can produce. The winners are pretty much everyone. It's sad that the US can't implement public policy like this.

only real freedom is financial. Americans don't usually like to preemptively create rules and regulations that could hinder innovation or hurt businesses. What good is your privacy if you are poor.

> Americans don't usually like to preemptively create rules and regulations that could hinder innovation

What about software patents? Or gene patents for that matter.

Re: German court rules Facebook use of personal data illegal

#242
post #207

Earlier quoted context omitted.

> Point is that the UK government already has a tax regime. It has no incentive to fine Facebook so much there's a risk of it leaving. Do Facebook have a presence in the UK? I thought they were headquartered in Dublin? Do Facebook pay tax in the UK? News to me. > The ICO already said that it doesn't intend to use its big new fining powers under GDPR anyway, as there's no need. Citation very much needed. The ICO will…

> > The ICO already said that it doesn't intend to use its big new fining powers under GDPR anyway, as there's no need. > Citation very much needed. The ICO will follow the law. The ICO is using it's DPA powers already You can see how few people ICO impose fines on already, and that they have never imposed the maximum fine. UK regulators really do take a light touch approach, aiming to get companies to change behavio…

> You can see how few people ICO impose fines on already, and that they have never imposed the maximum fine

Why would they have to impose the maximum to be effective?

The maximum sentence for arson in the UK is life imprisonment, something you are unlikely to see imposed. That doesn't mean that everybody is going to start torching their houses for the insurance.

> UK regulators really do take a light touch approach, aiming to get companies to change behaviour.

Maybe the German ones did too, but Facebook chose to ignore them?

Here is a recent DPA case against a non US company btw[0].

[0]http://www.bbc.co.uk/news/business-42637820

Re: German court rules Facebook use of personal data illegal

#243

Earlier quoted context omitted.

>Facebook will do just fine, they had years to prepare and an army of lawyers. Microsoft had years to prepare and an army of lawyers too.

And they're doing just fine now... I don't get the point?

If somebody says "X has money and an army of lawyers" the implication is they are going to beat the case, Microsoft didn't, they were slapped with the largest fine ever at the time ($794 million USD). They are fine despite the inability of lawyers and prep time to deliver victory, not because of it. No guarantees FB will fare better (or worse).

Re: German court rules Facebook use of personal data illegal

#244

Earlier quoted context omitted.

> How is the law reasonable? It's not even clear what is allowed under it and what isn't. The EU refuses to clarify anything, the only time any decision will be made is by courts, if there's an actual dispute in progress. How is that different from a US law like HIPAA? The structures of the law seem largely the same, in that they give you guidelines to follow, but provide no clarity about what specifically is require…

HIPAA and other mega-regulations like them have the same problems. And they do cause people to just give up rather than deal with the risk. I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at…

Legislating from the bench is not a bad thing, to the extent it doesn't contradict a fully valid statute. Indeed, most law in the US is judicially created, and always has been, dating back to the English common law system from which we inherited ours.

American courts continue to create common law today. This happens less at the federal level only because the scope of federal common law is narrower.

I too have concerns over the breadth of the EU right to be forgotten, but not over the concept that a court could combine premises with a process of reasoning to arrive at such a conclusion.

The Supreme Court's focus on ensuring that the cases before it are actually legitimate is primarily for three reasons: keeping their workload manageable, deferring controversial decisions they don't actually need to make, and complying with the Case or Controversy Clause in the federal Constitution.

Notably, the Case or Controversy Clause does not bind the state courts. Whether they are willing to issue advisory opinions or perform other duties is a matter of state law.

Re: German court rules Facebook use of personal data illegal

#245
post #220

Earlier quoted context omitted.

Why do you think social networks have cross country network effects? Xing and VK seem to be doing just fine.

I’m completely unfamiliar with VK, but I’d love to believe that it’s a subtle nod to the Voight-Kampff test.

sorry, vkontakte / vk.com

Re: German court rules Facebook use of personal data illegal

#246
That article doesn't summarize the ruling very well. Here's a short tl;dr of the actual ruling[0]:

Part A: Privacy settings

- Facebook tried to claim that it is only subject to Irish law. Court disagrees since Facebook operates in Germany, so local law applies. [side note: this kind of confusion is exactly why the GDPR is needed]

- Law states that the imprint must be "easily" accessible. Court found this not to be the case (it took three clicks and was hidden behind a link called "explanation of your rights and duties").

- Law states that explicit, informed consent is necessary for the kind of data processing Facebook does. Facebook pointed users to the privacy settings page where all settings were enabled by default. Court found that this constitutes neither explicit nor informed consent - the settings would have to be opt-in, or the user needs to be explicitly informed about the full extent of how his data is used ("without any doubt").

Court explicitly states that presenting an opt-out after registration and login is not sufficient, especially if it is presented as an optional "privacy tour" that most users are going to ignore.

- Plaintiff stated that Facebook incorrectly claimed it was "free forever", when users were in fact incurring hidden costs by volunteering their personal data ["paying with their data"]. Court strongly disagrees - no money is changing hands, after all. They do recognize that there's a counterpart, but it's immaterial and as such does not constitute a "hidden cost". Court basically states that the meaning of "free" is not up to debate.

Part B: Terms of Use

- Terms of use state that the user "acknowledges" to have "read" the privacy policy during registration. This is invalid in two different ways - a mere "acknowledgment" is insufficient, since it puts the burden on proof on the user, and since parts of the privacy policy are invalid, the user can't legally agree to it its entirety anyway.

Court explains that "read and understood" clauses like this one are invalid. Clearly, the user didn't actually read and understood the whole thing - but the language in the terms forces him to admit he did, which would disadvantage him by implying informed consent about everything in it when he didn't explicitly consent to anything.

- There's a clause in the ToU stating that the user "agrees to use his real name". This does not constitute informed consent since the user isn't properly informed - Facebook does not state why his real name is required and how it will be used.

The court states that it is questionable whether a real name policy is at all legal, underlining the need for proper consent due to the significant consequences of volunteering one's real name.

- Same for "agreeing that personal data is transferred to the US" - no explanation why data is transferred, what it will be used for or even what data is transferred. In addition to that, there's no indication which data protection standards are applied.

- Similar case for "agreeing that the profile picture is used [...] commercially": no informed consent since the user is not informed about the consequences.

... and a few more clauses where the court finds that no informed consent is given by the user due to very broad clauses with little explanation.

- It's OK to have the user agree that he's 13 years or older. Facebook cannot possibly check whether it's true, and the age doesn't matter anyway since the contract would be valid even if it weren't the case.

- Plaintiff complained about a few informational clauses in the privacy policy. Court rejected this since they weren't part of the terms of use due to their purely informational character (user isn't agreeing to anything).

This was a very interesting read. It is very clear that the courts take the requirement of "informed consent" very seriously, as they should. Is is not enough to present the user with a 100+ page privacy policy and have him agree to it, they actually need to present it such that the user realizes what they're agreeing to.

[0]: https://www.vzbv.de/sites/default/files/downloads/2018/02/12... (interesting part is page 22 onwards)

Re: German court rules Facebook use of personal data illegal

#247
post #18

Wait until GDPR is in place in May and German and other EU courts will rule FB to death. IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.

> IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.

By limiting their use of personal data, according to the law? And by requesting informed consent from users, instead of silently opting them into all their anti-privacy features? And by not hiding this two thirds of the way through a 100 page TOS?

It's not like it's impossible to make a good faith attempt at all those things. Facebook isn't even trying.

When they make a good faith attempt, and get sued out of existance, you may have a point. They haven't, though.

Re: German court rules Facebook use of personal data illegal

#248

Earlier quoted context omitted.

It is good that they are protecting their citizens from exploitation by US companies but this is not uncommon that it is easier to regulate a large company that is not your constituent. The EU has not done so well on regulating diesel autos for instance but the US is knocking that one of the park.

Your comparison is not correct. The practices of FB are not universally considered bad, many people are OK with them. The diesel scandal was a deliberate scheme to cheat everybody - you can't find anyone who considers what they did as good. And the Germans finally started arresting people, too - although the USA gave a good example.

The Germans are treating VW just like the US was treating the bankers responsible for the 2007 subprime mortgage crisis: with a pat on the back.

Re: German court rules Facebook use of personal data illegal

#249

Earlier quoted context omitted.

https://www.theguardian.com/small-business-network/2014/nov/... and https://www.theguardian.com/small-business-network/2015/sep/... my solution was to stop selling into the EU, though amusingly once the UK leaves the EU I'll be able to start again (by just ignoring the EU's VAT rules)

I knew about that but I was thrown by this > new VAT scheme whereas this is from 2015. I was confused by language where you described it as a law to target Amazon. Now I see that was just an opinion. > my solution was to stop selling into the EU Interesting business decision. Was the cost of compliance that high, or was your revenue that trivial? > though amusingly once the UK leaves the EU I'll be able to start agai…

> Interesting business decision. Was the cost of compliance that high, or was your revenue that trivial?

the cost of having to pay VAT on all of my UK REVENUES (digital services, remember!) would vastly dominate the PROFIT (not revenue) made from my EU sales

compliance wise, I'd rather not have to fill in VAT returns if it is optional (this is a side business, not my main employment)

> Well I was having a conversation with one of the UK's foremost VAT specialists on Friday, from one of the UK big 4 accountancy firms. He was very clear that the general opinion is that the UK will align with the EU for VAT.

well I'm glad his crystal ball is operating well... saying that I'm sure we will have a similar VAT after leaving (payable to our exchequer instead of the EU), but unless something radically changes the EU's laws won't be directly enforceable in the UK post brexit, and it's unlikely the UK will go out of its way to collect EU specific taxes for the EU's benefit

regardless, all of my "is EU VAT optional outside the EU?" discussion in this post and above is only an interesting thought experiment, it's not worth the possible consequences in practice (especially if your main worry is the lack of UK VAT free allowance like me... maybe if you're a large US based SaaS provider it's different)

Re: German court rules Facebook use of personal data illegal

#250

Earlier quoted context omitted.

Well, it's not that - before that law was introduced, you could simply ignore the country, since it's about digital downloads. If all you cared for was getting a payment, it was not unusual to have the transaction list in the forms of e-mails. Now you need much more information.

A customer is entitled to an invoice and a full invoice requires an address. Most businesses that offer digital goods and services should have had that even before. All the people I know that were affected by the VAT changes certainly had all customer adresses. This is not a cash sale in a local book store.

This is wrong. You are not forced to give your whole address always to buy something, especially on digital goods. In fact e.g. giving only your payment information like your debit/visa card is actually enough for buying stuff legally online as a normal customer in EU (b2c).
Post reply on HN