Live data from Hacker News

German court rules Facebook use of personal data illegal

reuters.com

281–290 of 404 posts

Re: German court rules Facebook use of personal data illegal

#281
post #18

Wait until GDPR is in place in May and German and other EU courts will rule FB to death. IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.

I wonder. In my opinion more rules only means bigger hurdles for newcomers. The big companies might have a setback but will survive one way or another because they have the knowledge and money (lawyers, lobbyists) to adapt.

A good example is the VAT law of Europe. No problem for big companies, but small companies struggle to comply (its a returning subject on HN). Or the net neutrality law in the US: it will become harder for a startup to disrupt YouTube.

Re: German court rules Facebook use of personal data illegal

#282
post #279
post #213

Earlier quoted context omitted.

Suppose I put up a website hosted on a server I own in a non-EU country. A person from the EU visits the site, I gather their personal information, and I sell that information to a non-EU buyer blatantly in violation of EU privacy law. I have no offices, bank accounts, property, service providers, subsidiaries, suppliers, customers, etc., in the EU. > You do realize the EU can stop or confiscate the money that is tra…

You can probably get a lot less if you try to sell the data to non-EU entities compared to local ones though. Same for advertisement prices.

That raises some interesting questions. Let's say:

• I run website W. W does not obey EU privacy and data rules, but I, my company, my server, etc., are all outside the EU in places without treaties that would allow enforcement of EU rules against me.

• I sell data from EU citizens who visit W. I sell this data to ad network N that is also outside the EU. (I'm selling N all my visitor data, not just data from EU visitors).

• Company C that is in the EU or sells products in the EU or has a presence in the EU buys ads through N. N uses the data they bought from me to show C's ads to visitors from the EU who visit websites using N's ad network.

Questions:

1. Which of the various entities in this (me, N, C) are violating EU data and privacy laws, according to the EU?

2. Which of those entities could the EU actually enforce a fine against?

3. For those entities that are violating EU laws (according to the EU) but are out of the reach of EU fines, can the EU take alternate action such as ordering EU ISPs to block access to their websites?

Re: German court rules Facebook use of personal data illegal

#283
post #246

That article doesn't summarize the ruling very well. Here's a short tl;dr of the actual ruling[0]: Part A: Privacy settings - Facebook tried to claim that it is only subject to Irish law. Court disagrees since Facebook operates in Germany, so local law applies. [side note: this kind of confusion is exactly why the GDPR is needed] - Law states that the imprint must be "easily" accessible. Court found this not to be th…

Thanks for this succinct yet comprehensive summary.

Re: German court rules Facebook use of personal data illegal

#284
post #214

Earlier quoted context omitted.

No, the enforcement is through the national "supervisory authorities" such as the ICO. Most of the enforcement process is through national courts and the ECJ is only for the final layer of appeal. This very article says "German Court rules ..." > voided the UK's opt out of new human rights related legislation, despite a very clear paragraph in the treaties saying they did not apply to the UK. [citation needed]; did y…

See here: https://fullfact.org/europe/eu-and-human-rights/ In the section "Wasn’t the UK supposed to get an opt-out from EU human rights laws?" The summary is, when the Treaty of Lisbon awarded the EU new human rights powers the UK and Poland negotiated an opt out which was written in the treaty. It was a part of convincing the UK government to accept the new treaty without granting a referendum on it, as they had pr…

The reason d'être of the EU is to unite, so I expect eventually all opt-outs to end or to become meaningless. Countries joining the project should have that in mind, and I think they all have and had, even if they're not talking too much about it.

Re: German court rules Facebook use of personal data illegal

#285

I think if I was creating a new social media website today I'd probably not set up any presence in the EU. The sheer quantity of fines for vaguely specified "crimes" being handed out makes it a deeply unattractive business environment and it seems to be getting worse. I remember when Facebook was new, one of its big competitive advantages was its easy and comprehensive privacy controls. I didn't see other social netw…

Maybe there are social media business paradigms that don't revolve around exploitation of users' PII.

Re: German court rules Facebook use of personal data illegal

#286
post #239

Earlier quoted context omitted.

HIPAA and other mega-regulations like them have the same problems. And they do cause people to just give up rather than deal with the risk. I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at…

> I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at all, because of the vagueness, poor drafting and expansive reach of such things. As someone who worked extensively on HIPAA covered data a…

This. I am not a hipaa expert or anything, but if a company is not making an effort to protect the data, they dont deserve to make money off of products touching that data.

Re: German court rules Facebook use of personal data illegal

#287
post #218
post #210

Earlier quoted context omitted.

As mentioned in another reply, the actual laws will have to be implemented by the member states anyway. So the text for each country can vary and can be more specific. As for your strawman that I somehow argued to abandon all law: I won't deal with that.

No, they actually won't. The Data Protection Directive needed to be implemented by national legislators into national law, but the GDPR is a regulation which means it is directly binding law. Only a few technical, minor points need to be spelled out in national regulations or laws.

That's simply not true.

Each country (or state, in the case of Germany I believe) will have their own privacy commissioner with substantial leeway. Now technically these differences won't be implemented as laws, but there will be substantial differences between eg the French and the UK privacy regulators.

The GDPR also allows for individual states to strengthen its provisions, eg for genetic data.

Re: German court rules Facebook use of personal data illegal

#288
post #246

That article doesn't summarize the ruling very well. Here's a short tl;dr of the actual ruling[0]: Part A: Privacy settings - Facebook tried to claim that it is only subject to Irish law. Court disagrees since Facebook operates in Germany, so local law applies. [side note: this kind of confusion is exactly why the GDPR is needed] - Law states that the imprint must be "easily" accessible. Court found this not to be th…

Great summary!

> The court states that it is questionable whether a real name policy is at all legal, underlining the need for proper consent due to the significant consequences of volunteering one's real name.

That represents an amazing win for online privacy. And seems totally at odds with core Facebook policy.

Re: German court rules Facebook use of personal data illegal

#289

Earlier quoted context omitted.

The GDPR is beautiful and an example of the best outcomes democracy can produce. The winners are pretty much everyone. It's sad that the US can't implement public policy like this.

We'll have to wait a while before we know for sure, but one loser might be technology startups, especially European ones. As much talk as there has been about the effects of GDPR on huge companies, the fact is, they're not too concerned: they have enough lawyers to throw at the legal issues and enough engineers to throw at the technical issues. Smaller companies without these resources are going to see their lives ge…

Why do you equate technology startups with startups that finance themselves with private data (mis)use?

Instead of taking profit out of private data one has, it's possible to charge for the service. Alternatively, one can use the data to finance the business but also follow the rules and regulations. I don't see the big issue here.

Re: German court rules Facebook use of personal data illegal

#290
post #278

Earlier quoted context omitted.

The point is without a European corporate presence the EU loses its ability to enforce GDPR.

Can ads be sold internationally that easily?

No idea but GDPR gives folks a lot of reason to figure it out.
Post reply on HN