Live data from Hacker News

German court rules Facebook use of personal data illegal

reuters.com

391–400 of 404 posts

Re: German court rules Facebook use of personal data illegal

#391
post #386

Earlier quoted context omitted.

I think since the UK left, it's actually all of them?

Nope, Ireland also has common law. I don't think that there are any others though.

Oh, you're right! I remembered common law is basically English-speaking countries only, and I forgot about Ireland, oops :)

Re: German court rules Facebook use of personal data illegal

#392

Earlier quoted context omitted.

No matter what infrastructure you're using? You won't believe how many payment systems out there are not very MOSS friendly. If you are a developer and cannot use VAT MOSS logic as e.g. plugin you basically have to get IP country code, add country VAT tax and adjust the payment plan. Yeah... all really really trivial if the payment system is not used to dynamic pricing on different country of customers! I hope you se…

Do you have to actually change the retail price? The way we do it is to keep the price constant for the customer. If their country has a lower VAT rate, they have to pay more. I'm not sure most even know/care how much VAT they pay, but they do care about the total price - and this doesn't change no matter if you change IP/user VPN etc. It also removes any incentives to cheat.

Good comment. Actually this is what I'm doing... move the logic to the book keeping side and deal with less income e.g. on Hungary with 27% VAT. Nevertheless why do I have to do all this hassle when somebody who sells e.g. a hardcover (vs. ebook) does not need to do this when selling cross border and they need to start thinking in this direction once they cross over 50 - 100,000 € on one country. Because I'm selling digital goods is much harder on my side.

Re: German court rules Facebook use of personal data illegal

#393
post #335

Earlier quoted context omitted.

Teenagers can agree to contracts, but only in very limited terms. For example, they can buy food in a supermarket. Buying stuff in a store constitutes a contract.

Is that German law? Because in the Netherlands this is called a "sale", and comes with very different rights and duties for both parties.

When I said ’contract’ without qualifier then I meant any form of legally binding agreement including sale contracts. A contract does not need to be written down.

Re: German court rules Facebook use of personal data illegal

#394
post #8

Earlier quoted context omitted.

One way of thinking of legislation is to encourage/discourage behavior indirectly. Think how putting a ridiculous tax on cigarettes makes people less likely to want to use them. In this sense, the German government (and greater EU) may be completely fine in implementing these laws to discourage the presence of these types of companies operating in their jurisdiction. After all, it is hard to argue that social media a…

> Think how putting a ridiculous tax on cigarettes makes people less likely to want to use them. It also makes them more likely to buy them illegally.

Well yes, and laws against killing people make people want to murder (i.e. kill illegally with premeditation). It's incredible that people think "someone will break the law" is a justification for not having the law.

Re: German court rules Facebook use of personal data illegal

#395

Earlier quoted context omitted.

I find it surprising that people have gotten so used to Facebook's abuse of data that they cannot even imagine things being different. You uploading data to Facebook to share with your friends does not mean that you give consent to have it stored, analyzed, and sold for profit. If I upload data to Dropbox, my bank, or my health insurance, I don't expect them to be sold to advertisers either. So what if there was a so…

It does seem inconceivable to me. How would it make money? Subscriptions? People can't even be bothered to pay for YouTube despite complaining endlessly about ads.

If a business can't make a profit in a socially conscious way, does the society benefit from its existences? If the only way you can make a social network is by selling members' lives to the highest bidder, maybe it's a product we should give a miss.

Re: German court rules Facebook use of personal data illegal

#396
post #328

Earlier quoted context omitted.

Please explain how. It would certainly help privacy respecting competitors,it seems.

It’s the same with the Banking sector...all those banking regulations are in place for a good reason, yet in sum they make it impossible to start a new bank and stifle competition/innovation.

Legal rights and protection for the public surely trumps the privilege to run a business and create a profit.

Re: German court rules Facebook use of personal data illegal

#397
post #325

Earlier quoted context omitted.

GDPR is reasonable. How Facebook handles user data is not. I'm sure, they'll mostly ignore the law at first, and if they get sued, they'll claim having a legitimate interest [1], but that will be their strategy, because actually complying with the law voluntarily would likely cost them more. And yes, especially Germany already had a very similar law in place, but Facebook did not actually need to keep to it most of t…

Ignoring the court order of which they were duly informed and which contains time to comply is a felony. Including a huge fine in this case, which will likely be calculated per German user. Think something closer to 30 M€.

With "ignore the law", I meant not (fully) implementing the requirements that the GDPR imposes. If a judge actually rules that they did not properly implement the GDPR requirements, then yeah, they will correct that.

But until someone sues them and that court case concludes, there's going to be a lot of time, in which they can probably make enough money by not properly implementing the GDPR requirements to easily recover however high that fine is in the end.

Re: German court rules Facebook use of personal data illegal

#398

Earlier quoted context omitted.

What are those good reasons?

Accountability for starters

That is the authorities business.

When someone in the street is speaking aloud, then you can't go to them and demand them to reveal their name, even if what is spoken is against the law. You can call the police and they can determine the name of the speaker. The internet is not a lawless place.

Re: German court rules Facebook use of personal data illegal

#399
post #361
post #359

Earlier quoted context omitted.

Why do you equate startups with startups that finance themselves with private data? Every piece of regulation is another headache for a business. Take for example the combination of GDPR + backups. If you have enough technical manpower, you can change the backups. If you have enough legal manpower, you can argue that changing those backups counts as 'unreasonable'. If you have neither you have a headache. Don't forge…

I see zero chance for the argument that it be unreasonable to adjust backups. Either they are adjusted, or they violate the law, period. Software projects like apache2, nginx, or your favourite website framework should adapt to the GDPR to make it easier for those who use them. How things will turn out is not settled yet. If you are a small company not focused on handling private data, and documentedly continuously w…

> If you are a small company not focused on handling private data

I'll repeat myself a little bit: IP addresses and user names are also private data.

Please provide me with an example of an IT business that doesn't deal with private data. No real names, no user names, no IP addresses.

I haven't looked in to this example, but I suspect even the name of a client on a bill would be subject to the GDPR.

> continuously work on compliance

That's the big part of the headache. Even if you're a one man shop, you have to spend time and effort to get informed and deal with it. Multiplied by all regulations that might effect your business.

Re: German court rules Facebook use of personal data illegal

#400
post #399
post #361

Earlier quoted context omitted.

I see zero chance for the argument that it be unreasonable to adjust backups. Either they are adjusted, or they violate the law, period. Software projects like apache2, nginx, or your favourite website framework should adapt to the GDPR to make it easier for those who use them. How things will turn out is not settled yet. If you are a small company not focused on handling private data, and documentedly continuously w…

> If you are a small company not focused on handling private data I'll repeat myself a little bit: IP addresses and user names are also private data. Please provide me with an example of an IT business that doesn't deal with private data. No real names, no user names, no IP addresses. I haven't looked in to this example, but I suspect even the name of a client on a bill would be subject to the GDPR. > continuously wo…

> No real names, no user names, no IP addresses.

Well, don't record IP addresses in the first place? Or if you need ip addresses for protection against technical attacks like DDOS-attacks, then delete them as soon as possible.

What is so difficult about deleting a real name and a user name stored by you if the owner of that account asks you to?

> I haven't looked in to this example, but I suspect even the name of a client on a bill would be subject to the GDPR.

Common sense gives that data on documents you are legally required to store like for example invoices are exempted from deletion during the legal storage duration. After that, why not anonimize them or delete completely?

Things become pretty easy if the default becomes not storing any data, and only make exemptions from it after careful consideration if it's really needed, what private data it contains and how it has to be handled based on that.

Data is not just a resource, it is also a liability.

Post reply on HN