Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

181–190 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#181
post #145

Earlier quoted context omitted.

It depends on what part of the GDPR you're against. I'm generally in favor of a lot of the GDPR's goals, but the execution is pretty clumsy and a few of the provisions are at best useless and impose unnecessary costs.

I wonder which ones specifically? I am reading into it because I am onto implementing it in our small company. Everything is as in citation from GDPR: "Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes ... implement appropriate technical and organisational measures ..."

1. Most things fall into this category: Lack of clarity in the law (and a remaining lack of clarity from WP29 and the Commission) about dozens of issues. The Privacy Professional community has been proactive about trying to get info on a lot of these items, but there's just not much coming, and in a few cases what has come out has either departed from what seemed like more obvious meanings or in some cases has muddied the waters further.

2. The essential ban on offering services, downloads, etc. in exchange for consent to use data reduces consumer autonomy and will decrease the availability of free resources.

3. It will be extremely easy to use SARs maliciously, and the law includes NO check whatsoever on this. All it would take to cripple many SMBs is for some jerk to spin up a website that provides a nasty SAR template (that the users don't even realize is such a burden) that random people on the Internet can auto-send to every business they've ever used under some innocuous-sounding reason like "See what information businesses have on you!" 99% aren't using data against subjects' interests, so the net effect of this alone (in the way it is designed) is potentially-immense costs for small benefits.

As a recommendation, the $250 my company spent on buying me a membership to the IAPP has been one of the highest ROI decisions in recent memory. It has saved me a ton of time and effort (and the company quite a bit of money) from the member resources available, and the members listserv is essentially free light consulting from people who have already dug into everything.

Re: Facebook urged to make GDPR its “baseline standard” globally

#182
post #175
post #109

Earlier quoted context omitted.

You're right! All the stuff about right to be forgotten, right to view, right to make corrections, and so on should be very straightforward and easy for any company of any size interested in being honest. Especially for new players, who don't have ugly legacy systems to wrangle. Yet... I've read through GDPR. All ninety-nine articles are chock full of "reasonable measures" and similar verbiage. Unless you can afford…

I think "reasonable measures" is pretty typical language when talking about compliance. I don't know GDPR regulation very well but I know FDA regulation reasonably well and I imagine compliance will be similar, and much easier for the new GDPR. Most important is to document everything. Have a design history file that you can show in case you get audited. When you design your software, save your designs in the DHF. Wh…

Well said! Thank you for your comments.

With all that said, my point was that it's not obvious what is and isn't reasonable. Hiring a security specialist won't necessarily help you understand what bureaucrats will or won't deem reasonable, especially when there's no history to provide context.

Re: Facebook urged to make GDPR its “baseline standard” globally

#183

Earlier quoted context omitted.

What about deleting data in backups for an EU resident who submitted a request for data deletion? If a company is using mysqldump or equivalent it seems difficult to just drop certain records from those .sql files.

Have a reasonable retention policy on these backups. Backups are a "legitimate business interest" and you don't need to purge "right to be forgotten" requests from your backups if you stick to a reasonable and publicly-documented retention policy. This is advice that I've received from counsel. However, I am not a lawyer, and this in no way should be taken as legal advice.

If you ever had to restore from backup, I hope you kept track of what content now needs to be "re-forgotten"

Re: Facebook urged to make GDPR its “baseline standard” globally

#184

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

As someone who works in a startup in the healthcare space, I will point out that nobody lets health startups off the hook for HIPAA. You don’t get to be sloppy with people’s protected health information just because it makes your life easier.

I'm sorry but I don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger... it's not apples to apples

Re: Facebook urged to make GDPR its “baseline standard” globally

#185

Earlier quoted context omitted.

He means that both China and the EU (with the GDPR) infringe on freedom of speech.

How does the GDPR interfere with one’s right to lawful political speech?

First amendment is protecting all speeches except direct threats of violence. Right to be forgoten is by essence incompatible with the first.

Re: Facebook urged to make GDPR its “baseline standard” globally

#186
post #140

Earlier quoted context omitted.

I'll point out which question gives me nightmares, as the founder of a EU startup: - the requirement to have a DPO. Based on the requirements for the DPO, no one in the company can fill the role (conflict of interest), so we must hire an employee or consultant (expensive either way for a small startup) - one month to respond. That's a lot of informations to collect the first time, and I might have other fires to put…

thanks for this. so what's your advice for a social startup building a new platform in today's data-privacy concerned world?

Simply build a secure and private platform, don't be reckless with user data. Health startups already deal with this through HIPPA and it isn't really a big deal, just common sense practices for security and privacy

Re: Facebook urged to make GDPR its “baseline standard” globally

#187

Earlier quoted context omitted.

Blockchains storing social data is good example. It's infringing by nature GDPR. A decentralised facebook-like social network on the blockchain is not possible anymore. Each node can be sue. It had happened with TOR exit nodes.

IANAL, but crypto-shredding seems to be a viable way to meet GDPR deletion requirements, making it possible to implement compliant blockchains. Of course you'd have to make the nodes comply, but that has nothing to do with blockchains. But I still don't see the connection with the first amendment.

The first protects the nodes to store whatever social data they want. GDPR with particulary the right to be forgotten is a direct attack to this.

Re: Facebook urged to make GDPR its “baseline standard” globally

#188

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? There's nothing inherently wrong with a high bar to entry if that bar exists for a very good reason. If it were hard to break into this space due to regulation…

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter?

The answer is yes, it is onerous. And yes, it does matter.

Regulations always start as an idea that sounds good. The companies most impacted are then motivated to gain control of the regulations. Once they do, then they happily add on to regulations because that becomes a barrier to entry for new competitors, but do so in a way that ceases to be a problem for themselves. In the end the regulatory framework stops working and we have the very disaster that we were trying to block.

This is called regulatory capture. It is very, very common.

In the case of Facebook, here is the problem. The regulators are controlled by politicians who wish to remain in power. If Facebook breaks the rules in favor of those politicians, it becomes easier for the politicians to remain in power. The incentive is therefore for the politicians to become complicit in letting Facebook break the rules. However no new startup can provide the politicians with an incentive that matters - only Facebook, Google, and other similarly large players can bribe politicians in back room deals.

The payback for Facebook is that they get to solve their biggest existential crisis. The barrier to entry for a new social network just aren't as big as it seems. They can keep milking more from their users and buying up the Instagrams for only so long until something like Snapchat or Discord or someone not yet thought of succeeds. If Facebook is to avoid being replaced in the way that they replaced MySpace, and MySpace replaced Friendster, they need a new barrier to entry.

Regulation provides that for them. In public they will get chastised. You'll get speeches that you love. In private, they will happily become part of an effective surveillance state for those already in power in return for a blind eye being turned to their ongoing transgressions.

The result? The regulation that you are cheering won't accomplish the causes that you want. And if history is a guide, the very politicians whose speeches are the most to your taste will tend to be the ones who behind closed doors are selling you out. With their public speeches being nothing more than bargaining chips for private deals.

Re: Facebook urged to make GDPR its “baseline standard” globally

#189

Earlier quoted context omitted.

If you want to run a social media platform, GDPR is infringing your freemdom of speech. You can argue that it’s worth it, for the illusion of more privacy. I just don’t think it is.

You still haven't stated how exactly it's infringing on our right to freedom of speech.

If on your social network someone wants his posts to be removed, you have to comply under GDPR, or else. HN for example doesn’t allow to remove your comments after some time.

Re: Facebook urged to make GDPR its “baseline standard” globally

#190
post #149

Earlier quoted context omitted.

> the company acted with far more awareness than the law would Their response to the criticism, externally, was to deflect, and internally, was to ignore it [1]. Zuckerberg's response to the Android call and text scraping endeavor was more equivocation [2]. Then he decided to pipe up again about not applying GDPR globally [3]. One has to squint to see any sense of awareness in Facebook. > Don’t be misinformed and att…

My point was that in 2014 when Facebook understood that one of the dozen of thousands of partners could abuse the data that they were collected, they acted swiftly and asked their partners to justify their use case; they asked the accused parties (Kogan, GSR and SCL) to delete the data and obtained legally binding documents. I’m not sure how they could, legally force themselves into a business in a different jurisdic…

> I really don’t think you are making yourself actually smarter by judging Facebook in hindsight.

I've been blocking every Facebook domain I can find in my browser since 2010. Why? Because I knew they could connect up referer headers on Like buttons to my Facebook cookie, and create a complete profile of me and the kind of articles I read.

(I did the same thing with Google's Plus stuff, as best I could.)

Facebook didn't need to implement things that way. But they've been acting in a sinister way for years, their game plan has been clear as day. And I for one don't consent.

Post reply on HN