Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

141–150 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#141
As an Indian citizen I would like to oppose this pseudo colonising attempt. EU is anyways a basket case bureaucracy and most member nations are considering leaving EU, Britain having left it already.

I see not reason and logic to the fact that nations who have not opted in into this be subjected to laws that are essentially created by no-skin-in-the-game bureaucrats.

Such attempts should be opposed at all costs.

(I know this "urging" is supposed to be "voluntary action" by facebook but nevertheless stinks of the same white man's burden colonizers talked about)

Re: Facebook urged to make GDPR its “baseline standard” globally

#142
post #52
post #23

Earlier quoted context omitted.

> EU residents, not citizens. It's an important distinction. Sorry if this is obvious. I haven't been following the details of this. Does that mean there is no protection for EU citizens while they are outside the EU?

Roughly: def GDPR_applies(company, person): if in_EU(person): return True if in_EU(company): return True return False There are various conditions, limitations, and exceptions that make the above not fully accurate, but its a good first approximation. You can read the actual text of the territorial scope rule here [1]. Edit: slightly less rough, but still quite rough: def GDPR_applies(company, person): if in_EU(compa…

Ok, what if a EU resident goes on a holiday in the US? Will all their data now be open to malicious treatment for the duration of the trip? Or only the data they enter/view during the trip?

Re: Facebook urged to make GDPR its “baseline standard” globally

#143
post #108

There's been so many articles about Facebook and the recent privacy catastrophe that I'm finding it hard to keep up. Does anybody actually know what their response will be to the GDPR? Are the privacy benefits from the GDPR going to be exclusive to EU citizens? This seems problematic. Whatever happens, Facebook has irreparably damaged my trust in their handling of user data and I think many on here would agree. My wi…

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> The amount of blaming the nurse for your fever on those issues is getting really concerning.

The nurse is being blamed because they've ignored clear, worsening symptoms for years.

Re: Facebook urged to make GDPR its “baseline standard” globally

#145
post #77

Earlier quoted context omitted.

The more I read people against GDPR the more I get the feeling they're the same kind of people behind mail based scams.

It depends on what part of the GDPR you're against. I'm generally in favor of a lot of the GDPR's goals, but the execution is pretty clumsy and a few of the provisions are at best useless and impose unnecessary costs.

I wonder which ones specifically? I am reading into it because I am onto implementing it in our small company.

Everything is as in citation from GDPR:

"Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes ... implement appropriate technical and organisational measures ..."

Re: Facebook urged to make GDPR its “baseline standard” globally

#146

Earlier quoted context omitted.

thanks, wow responding to a letter like your first link could significantly bog down resources for a young company... you can imagine if you launched and even received moderate user growth early on, but then started receiving such letters, your productivity could go down the tubes.

Honestly, those questions should be pretty easy to answer especially if your company is small. If as a business you can’t answer these basic questions about the data you want to collect from me, I’m going to be hesitant to share it. People keep sharing that “nightmare letter” link but won’t point out which question gives them nightmares and why.

> People keep sharing that “nightmare letter” link but won’t point out which question gives them nightmares and why.

There is a standard way in which "reasonable" regulations kill small companies. It works like this. You impose some small burden, something like an hour of labor a week. That won't destroy a small company, but that is not the only rule in the world. That rule takes an hour, another rule an hour and a half, a third rule a half hour. By the 60th rule, a two person company is past sunk. Even if every individual rule is nominally reasonable, the combination is hopelessly destructive.

The problem with tech companies is the rules don't just add together, they get multiplied by the user base, and it's entirely common for a very small company to have ten million users.

So you take a letter like that. The first time you get one it will take you a week to figure it out, but over time you get the response time down to an hour. Only with 10 million users, if 0.1% of the users make such a request per year, you're looking at 27 of those every day. That's more than three full time employees doing nothing but that. For this one "reasonable" regulation.

Re: Facebook urged to make GDPR its “baseline standard” globally

#147
post #58

Earlier quoted context omitted.

I think a few blogs have touched on this: * https://www.linkedin.com/pulse/nightmare-letter-subject-acce... * https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo... * https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ * https://pagefair.com/blog/2018/granular-gdpr-consent/

Based on the first link, that letter scares me a lot. I have a feeling that this level of regulation will destroy any social startup. You'd need a compliance department larger than engineering just to remain legal. This is clearly a win to Facebook.

Or you just build your permissions and opt-in platform as a base for the social app.

We wouldn't let a self driving startup ignore traffic laws because it's "too hard". Likewise we shouldn't let a social startup ignore privacy laws and auditing.

Re: Facebook urged to make GDPR its “baseline standard” globally

#148
post #58

Earlier quoted context omitted.

I think a few blogs have touched on this: * https://www.linkedin.com/pulse/nightmare-letter-subject-acce... * https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo... * https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ * https://pagefair.com/blog/2018/granular-gdpr-consent/

I kind of feel like every question in the first link is entirely reasonable and people _should_ be able to get those answers, though. Nothing in there is onerous if you're following good practices anyway. I really feel like the answers to all of those questions are going to be basically identical between people, and all you really need to do is be able to export whatever data you have on somebody quickly in order to…

> respond to that email in under quarter of an hour.

Let's take an app like Instagram as an example. Instagram had over 1 million users within two months and 10 million within a year, and no profits. You're running on a shoestring trying to keep servers online without any serious budget to speak of. It's probably you and a few friends/associates working closely together.

All of a sudden with GDPR, you have to pay a lawyer to help you understand what you need to do to comply with the regulations. You also have to spend engineering time developing solutions to enable the queries in that letter, enable purging records from long-term backups, etc. And people have to spend the 15 minutes responding to each request.

Now, let's say each request does only take 15 minutes like you suggest (which I find highly unlikely). If a small fraction like 0.5% of your customer base sends such a letter, then that's 50,000 letters. At 15 minutes each, that's 12,500 hours which is over 6 full-time employees. Many small business don't even have 6 employees to conduct the entirety of their business right now!

Re: Facebook urged to make GDPR its “baseline standard” globally

#149
post #108

Earlier quoted context omitted.

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> the company acted with far more awareness than the law would Their response to the criticism, externally, was to deflect, and internally, was to ignore it [1]. Zuckerberg's response to the Android call and text scraping endeavor was more equivocation [2]. Then he decided to pipe up again about not applying GDPR globally [3]. One has to squint to see any sense of awareness in Facebook. > Don’t be misinformed and att…

My point was that in 2014 when Facebook understood that one of the dozen of thousands of partners could abuse the data that they were collected, they acted swiftly and asked their partners to justify their use case; they asked the accused parties (Kogan, GSR and SCL) to delete the data and obtained legally binding documents. I’m not sure how they could, legally force themselves into a business in a different jurisdiction when that business had not broken the law — only a Platform user agreement.

Facebook did that four years before the law, namely GDPR, came into action. That’s not even accounting for the fact that outside of Europe, US and elsewhere, what CA did appears legal. Who the US Congress should be judging is probably whomever is in charge of writing laws.

Unless Facebook had a way to let, four years later (an eternity by Facebook standard) the programmatic ad platform know that those three entities (Kogan, GSR and SCL) that the compliance team interacted with four years earlier were related to CA; or even that CA, working for the official Romney campaign was related to the Pro-Trump SuperPACs buying ads (which would be coordination and illegal) blocking them without the revelations of Alex Wylie would be prescient.

I really don’t think you are making yourself actually smarter by judging Facebook in hindsight.

As Facebook done shady stuff? Absolutely: the Android Contact thing is certainly representative of the “gather first, ask questions later” early attitude which explains why Messenger is so bloated. Anyone familiar will confirm this is laziness over mischief. I worked there: you don’t need to make things up to find issues with Facebook.

On the particular problem in point, GSR, Facebook was outwitted and made misinformed decisions but they would absolutely not have been helped by either the public opinion of developers (we wanted more sharing) or the law (inapplicable) at the time.

The company learned to be more careful; its critics should too, because we absolutely will need those critics to be smart.

Re: Facebook urged to make GDPR its “baseline standard” globally

#150

Earlier quoted context omitted.

Yes, both are infringing 1st amendment. It’s not because GDPR seems more acceptable than it’s not built on bad premises.

If you want to run a social media platform, GDPR is infringing your freemdom of speech. You can argue that it’s worth it, for the illusion of more privacy. I just don’t think it is.

You still haven't stated how exactly it's infringing on our right to freedom of speech.
Post reply on HN