Live data from Hacker News

German court rules Facebook use of personal data illegal

reuters.com

291–300 of 404 posts

Re: German court rules Facebook use of personal data illegal

#291

Earlier quoted context omitted.

> Interesting business decision. Was the cost of compliance that high, or was your revenue that trivial? the cost of having to pay VAT on all of my UK REVENUES (digital services, remember!) would vastly dominate the PROFIT (not revenue) made from my EU sales compliance wise, I'd rather not have to fill in VAT returns if it is optional (this is a side business, not my main employment) > Well I was having a conversatio…

I'm not sure you have that right. I don't professionally engage with MOSS so I will not give advice, but I professionally do work with VAT and handle some millions in VAT a year, so I am pretty familiar with the dreaded VAT guide. All quotes are from the aforementioned resource > the cost of having to pay VAT Presumably you mean the higher price from charging VAT > on all of my UK REVENUES "your UK sales will not be…

> I think it is rather more than a crystal ball when you are the UK VAT lead for a big 4. This means you get consulted on it by the government

given the cabinet doesn't seem to know what their objective is, this seems like a fantastical claim

> When did you ever pay VAT to the EU?

not directly, but that's why it exists and where (a chunk of) the money goes -- read about the history of the VAT, it used to form the 40% of the EU's budget (down to about 14% these days)

> Not at all, the UK government will enforce on its behalf, as we will expect them to enforce on our behalf.

doesn't work like that in practice, once we're out HMRC isn't going to spend money chasing people for taxes due in Bulgaria, in the same way it doesn't chase people for taxes owed in Russia today

> The UK is in the process of bringing all EU law into UK law (where it isn't already) with the strangely titled Great Repeal Bill.

yes

> so EU law will apply to you.

no, at that point it will be UK law

> Also the government have committed to an open border in Northern Ireland as mandated by the Good-Friday agreement.

depends on what they mean by "open" -- regardless of that: there's nothing that prevents a customs border in the good-friday agreement (have a read, it's only about 10 pages long: [1])

> (various points based on the assumption that the government will commit absolutely to one policy voters don't care about and completely abandon all others)

the government has also committed to leaving the EU customs union and the single market

I agree that it's hard to see how both are possible, but politics is the art of the fudge

> I wonder against that backdrop how you think you are going to be outside of EU law?

I don't accept the premise or the conclusion -- b) doesn't violate the GFA[1] or the confidence and supply agreement[2] (not a coalition)

to be blunt: it seems like you're making things up

> You seem to have a downer on the EU, if you don't mind me saying?

why should I like it? if you're running a medium sized or big business it's fantastic (unless you're a large foreign business like Facebook, Amazon or Microsoft), but I'm trying to run a small business, and it seems like they're doing their best to kill me

hell, if in 5 years we're still subject to the ever increasing mountains of poorly thought out legislation written by morons, I suppose emigration is always an option

[1]: https://www.gov.uk/government/publications/the-belfast-agree...

[2]: https://www.gov.uk/government/publications/conservative-and-...

Re: German court rules Facebook use of personal data illegal

#292
post #59
post #18

Wait until GDPR is in place in May and German and other EU courts will rule FB to death. IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.

The GDPR isn't actually as bad as people claim. The law is actually pretty reasonable. It is the result of years of discussion and deliberation. In fact, privacy watchdogs are complaining that it doesn't go far enough - it leaves plenty of holes. Most of the GDPR is about informed consent, having a valid reason for processing personal data and individual rights. Facebook will do just fine, they had years to prepare a…

The problem with the GDPR isn't that it is too far-reaching. The problem is that it isn't clear what companies have to do to comply with the new regulation.

Large companies will simply pay their lawyers to deal with this. Small companies basically will have to do their best and hope they don't get sued.

Re: German court rules Facebook use of personal data illegal

#293
post #109

Earlier quoted context omitted.

If I could be given a bit of latitude to generalize for a second, I've noticed that America has a very "self-focused" culture wherein the individual is often seen as being solely responsible for everything relating to their self. That makes a lot of sense but I've seen this often taken to extremes such that the perspective is used to absolve various levels of government, corporations, and organizations from responsib…

That simply reflects technical reality. Once you give them information, you no longer can restrict what they can do with it technically. legally, sure, you can write whatever law you like, but the best way to protect your privacy continues to be technical measures.

Law trumps technical means.

The privacy regulators have the authority to enter your business and server locations and look directly at the data you have and what you do with it.

Also, laws do have an impact even if there is no technical mean to enforce it. Working without paying taxes is forbidden but has no technical means of ensuring it. Yet, most pay taxes.

What is so difficult about deleting, not collecting and not using data?

Re: German court rules Facebook use of personal data illegal

#294
post #79

Earlier quoted context omitted.

Here is a list of countries with the most Facebook users: https://www.statista.com/statistics/268136/top-15-countries-... The first EU country is #10, and it won't even be an EU country in a few years. I think Facebook would survive leaving the EU market just fine. I'm sure they really, really don't want to, but they could. Edit: updated link

Wrong link :-)

Oops!

Re: German court rules Facebook use of personal data illegal

#295
post #18

Wait until GDPR is in place in May and German and other EU courts will rule FB to death. IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.

Here is a list of countries with the most Facebook users: https://www.statista.com/statistics/268136/top-15-countries-... The first EU country is #10, and it won't even be an EU country in a few years. I think Facebook would survive leaving the EU market just fine. I'm sure they really, really don't want to, but they could. Edit: updated link

Heh, wrong link. It should be https://www.statista.com/statistics/268136/top-15-countries-...

Re: German court rules Facebook use of personal data illegal

#296

Earlier quoted context omitted.

> the GDPR seems fine, as well as quite defensible. So, that's the thing. Either, it's fine and defensible, and the Facebooks of the world will just comply, and so won't be a trade barrier, or it's not. It can't be both. And also, don't wish for a "trade barrier" for this purpose, import substitution has been demonstrated over and over again to be really just awful policy.

I was hypothesising Facebook being unreasonable. And their business model could very well be incompatible with GDPR. They're an ad company that feeds on personal data. I'm not sure they can get the informed consent of most of their users for this. Simply put, GDPR could be reasonable and sue Facebook to death (at least within its borders).

Facebook can be compliant with the GDPR and be profitable. They must change, however.

Re: German court rules Facebook use of personal data illegal

#297

Earlier quoted context omitted.

“And the EU acts as judge, jury and executioner.” That’s true only if you regard he EU as a single entity. Laws made via the EU will be turned into national law, and independent judges will judge all cases, up to the EU high court. By the same right you could call the US judge, jury and executioner on all laws and rules made and enforced by the US government (FACTA anyone?)

No. That's not how the EU works. That's how a national government would work but not the EU. The GDPR is not a directive so it does not have to be translated into national law. It is directly binding and applies immediately everywhere. Fines have to be paid up front, before appeals are exhausted. Appeals can of course take years. The EU courts have judges appointed by the same people who control the rest of the EU, a…

>consider the case where they simply voided the UK's opt out of new human rights related legislation

Erm...you are aware that this case has nothing to do with the ECJ, but with the ECHR, which isn't even an institution of the EU, but of the Council of Europe* , which is an entity completely separate from (and older than) the EU.

* not to be confused with the European Council or the Council of the European Union. Yeah, it's a bit silly.

Re: German court rules Facebook use of personal data illegal

#298

Earlier quoted context omitted.

> How is the law reasonable? It's not even clear what is allowed under it and what isn't. The EU refuses to clarify anything, the only time any decision will be made is by courts, if there's an actual dispute in progress. How is that different from a US law like HIPAA? The structures of the law seem largely the same, in that they give you guidelines to follow, but provide no clarity about what specifically is require…

HIPAA and other mega-regulations like them have the same problems. And they do cause people to just give up rather than deal with the risk. I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at…

I've worked in the healthcare space. HIPAA doesn't scare enough people/companies away. Not by a long shot.

Sensitive personal medical info was routinely sent, by major companies, over insecure FTP or even plaintext email, on a regular basis.

Anyone who has ever had medical benefits at any point in their lives most likely has their benefit information, along with socials and more, sitting unencrypted in databases of a plethora of small companies/medical/insurance providers whose only concern for security is a mandatory HIPAA CYA compliance lecture for their every couple of years. The rest of the time they go about sending socials and pmi through plain text email or just leave shit on their desks for anyone to pick up.

Re: German court rules Facebook use of personal data illegal

#299
post #239

Earlier quoted context omitted.

HIPAA and other mega-regulations like them have the same problems. And they do cause people to just give up rather than deal with the risk. I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at…

> I've listened in on various conversations around health products over the years. HIPAA is a common reason given for not getting into the healthcare space and focusing elsewhere. A lot of smart people and smart products that could have been focused on health just never turn up at all, because of the vagueness, poor drafting and expansive reach of such things. As someone who worked extensively on HIPAA covered data a…

HIPAA (and PCI compliance) has done little to prevent 1) in practice, especially when balanced against the huge costs it has on industry and the 'hidden' cost of crippled innovation.

You can't measure the true cost of hundreds of thousands of projects and startups that were never realized because HIPAA scared them away...and this is stuff that would have saved billions in healthcare costs, improved the public's health, and supported research/processes that could save lives.

Saying it's only a dynamic between "profit vs security" completely downplays the utility of technical progress in health care. This isn't just about quarterly profits of large mega-corporations.

As someone who started off working in the health space I can assure you I personally gave up on multiple potential projects because of HIPAA. And know of countless others who have to in spaces that seem "crazy" no one has yet built software for.

And I say this as a complete paranoid hawk on information security and privacy rights...

Re: German court rules Facebook use of personal data illegal

#300
post #246

That article doesn't summarize the ruling very well. Here's a short tl;dr of the actual ruling[0]: Part A: Privacy settings - Facebook tried to claim that it is only subject to Irish law. Court disagrees since Facebook operates in Germany, so local law applies. [side note: this kind of confusion is exactly why the GDPR is needed] - Law states that the imprint must be "easily" accessible. Court found this not to be th…

It’s interesting...implementing these changes won’t hurt Facebook...but they will kill any competition from other (smaller) players.

This ruling will in the end contribute to Facebooks long term success and will cement its market position.

Post reply on HN