Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

171–180 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#171

Earlier quoted context omitted.

> both are infringing 1st amendment The First Amendment protects you from the government. Facebook censoring you is not prohibited by the First Amendment. More broadly, I don’t see how GDPR interferes with one’s right to lawful political speech.

He means that both China and the EU (with the GDPR) infringe on freedom of speech.

How does the GDPR interfere with one’s right to lawful political speech?

Re: Facebook urged to make GDPR its “baseline standard” globally

#172

As an Indian citizen I would like to oppose this pseudo colonising attempt. EU is anyways a basket case bureaucracy and most member nations are considering leaving EU, Britain having left it already. I see not reason and logic to the fact that nations who have not opted in into this be subjected to laws that are essentially created by no-skin-in-the-game bureaucrats. Such attempts should be opposed at all costs. (I k…

1 out of 28 is not most, and that was on a knife edge vote.

26% of the country (many who have now died) voted to leave the EU

Re: Facebook urged to make GDPR its “baseline standard” globally

#173
post #108

There's been so many articles about Facebook and the recent privacy catastrophe that I'm finding it hard to keep up. Does anybody actually know what their response will be to the GDPR? Are the privacy benefits from the GDPR going to be exclusive to EU citizens? This seems problematic. Whatever happens, Facebook has irreparably damaged my trust in their handling of user data and I think many on here would agree. My wi…

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> not allowing that export at all would probably be met with legally-binding criticism

Yeah? Can you point me towards any law that says I have the right to export data I did not enter?

> The main use-case that was discussed then was to empower services like Riot, to encourage competition — something that, surprisingly, Facebook was very supportive of at the time.

You have any evidence for that encouraging competing social networds was the "main use-case" for this feature? This is a pretty strong claim to make with no support.

> It has since became clear that people were not reading the permissions that they were granting and more applications were abusing them than trying to build an alternative to Facebook

The vast majority of people whose data was stolen did not grant ANY access. You appear to be deliberately mis-representing events.

> Some services who needed the social graph for legitimate reasons well understood by the users (e.g. Tinder) have kept their now-not-publicly available access.

Access to the social graph, and full access to the activity of all your friends are not the same thing. Again you seem to be deliberately misleading people.

> Facebook not only has been very effective at showing me and letting me edit

So how can I monitor and delete the shadow profile they have build for me?

> Don’t be misinformed and attack Facebook for selling your data — they did not.

Nobody has said their sold the data. They gave it away for free

> The amount of blaming the nurse for your fever on those issues is getting really concerning.

I didn't have a fever before I reached Facebook, something Facebook did got me sick, so why shouldn't I blame them for the fever?

Re: Facebook urged to make GDPR its “baseline standard” globally

#174
Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

Re: Facebook urged to make GDPR its “baseline standard” globally

#175
post #109
post #62

Earlier quoted context omitted.

Read about what GDPR actually entails. Following it should be simple for a new player.

You're right! All the stuff about right to be forgotten, right to view, right to make corrections, and so on should be very straightforward and easy for any company of any size interested in being honest. Especially for new players, who don't have ugly legacy systems to wrangle. Yet... I've read through GDPR. All ninety-nine articles are chock full of "reasonable measures" and similar verbiage. Unless you can afford…

I think "reasonable measures" is pretty typical language when talking about compliance. I don't know GDPR regulation very well but I know FDA regulation reasonably well and I imagine compliance will be similar, and much easier for the new GDPR.

Most important is to document everything. Have a design history file that you can show in case you get audited. When you design your software, save your designs in the DHF. When you update or make changes to the design, put that in your DHF too.

For each GDPR article where it makes sense, have it written somewhere how you are compliant with what they ask for (you probably don't need to demonstrate compliance with Article 4 [1] but you should have it written somewhere how you are compliant with all the points in Article 5 [2]. When it says "Personal data shall be: (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes" You should be able to procure a document that lists the various kinds of personal data collected and how each is used; e.g. "Username: The username serves to associate a person's login id to their profile. [... other details] Profile Picture: The profile picture serves to display an image of the user. [... other details]."

When it tells you to have reasonable security measures, then document what your security measures are. "This data is encrypted" or "This data is saved on an external server disconnected from the internet and only accessible by someone with a dongle". If you're still worried that your user data could be insecure, then it might be worth hiring a security specialist to check it out.

[1] https://gdpr-info.eu/art-4-gdpr/ [2] https://gdpr-info.eu/art-5-gdpr/

Re: Facebook urged to make GDPR its “baseline standard” globally

#176

Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

Network effects, aka the chicken and egg problem

Re: Facebook urged to make GDPR its “baseline standard” globally

#177

Earlier quoted context omitted.

> can social media kill you though? Yeah, it can and it did. Not only did the Ashley Madison leak led to a few deaths, check out what happens in countries where homosexuality is punished by death when private information goes public...

The States killed those people not Ashley-Madison.

It can be both. Responsibility is not a conserved quantity. Entities who take on private data should be considering the effects of that data becoming released, including what others may use it for.

Re: Facebook urged to make GDPR its “baseline standard” globally

#178

Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

In fairness, what's stopping them from doing that and parsing the information out of a Facebook data dump?

Scale and trust mostly

Re: Facebook urged to make GDPR its “baseline standard” globally

#179

Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

Why would people trust another social network by uploading all of their data which they want to keep private I'm assuming if they took it off FB? I think this is the beginning of the death of social networks, and the rise of messaging apps as the primary method of keeping in touch with your friends.

Re: Facebook urged to make GDPR its “baseline standard” globally

#180

Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

People have been able to download their Facebook info since 2010: https://techcrunch.com/2010/10/06/facebook-now-allows-you-to...

Available here: https://www.facebook.com/help/131112897028467

Post reply on HN