Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

191–200 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#191
post #104

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

The GDPR makes some things easier for start ups. Users now have a right to their personal data in a "commonly used" digital file. Now the start up can have a "Import your Facebook data" feature. Currently a provacy conscious start up is competing with those who aren't, making it harder. But with this law, you won't have as many shady companies like Facebook. Storing less private data makes you less liable to get hack…

You've been able to download your Facebook contents in a zip file for nearly six years. It made absolutely no difference in competition.

Re: Facebook urged to make GDPR its “baseline standard” globally

#192

Earlier quoted context omitted.

EU residents, not citizens. It's an important distinction.

Woah, that would mean e-Residency in Estonia would be enough for GDPR protections, right? https://e-resident.gov.ee Note that becoming one involves going to your embassy in person.

No. It only covers residents ("data subjects") who are inside the EU or dealing with companies in the EU. People who aren't in the EU (including EU citizens currently in foreign countries) and are dealing with companies outside the EU aren't covered.

Re: Facebook urged to make GDPR its “baseline standard” globally

#193
post #167

Earlier quoted context omitted.

Ok, what if a EU resident goes on a holiday in the US? Will all their data now be open to malicious treatment for the duration of the trip? Or only the data they enter/view during the trip?

You're still a resident of your home country while you're on vacation, so failing to cover any of that data would appear to be a breach of GDPR.

Dealing with companies outside the EU is only covered while you are currently inside the EU, regardless of where you reside.

Re: Facebook urged to make GDPR its “baseline standard” globally

#194

Earlier quoted context omitted.

You still haven't stated how exactly it's infringing on our right to freedom of speech.

If on your social network someone wants his posts to be removed, you have to comply under GDPR, or else. HN for example doesn’t allow to remove your comments after some time.

And how is me deleting my content your service violating your right to free speech exactly?

Re: Facebook urged to make GDPR its “baseline standard” globally

#195
post #58

Earlier quoted context omitted.

I think a few blogs have touched on this: * https://www.linkedin.com/pulse/nightmare-letter-subject-acce... * https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo... * https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ * https://pagefair.com/blog/2018/granular-gdpr-consent/

Based on the first link, that letter scares me a lot. I have a feeling that this level of regulation will destroy any social startup. You'd need a compliance department larger than engineering just to remain legal. This is clearly a win to Facebook.

At least on the surface it doesn't seem that bad. You just have an opt-in data collection with (type-of-data, purpose-of-data) tuples and let users actually delete data on request.

Allow Socially to collect the following information for the purposes of providing you service:

- Minimal Account Information: email address and password

To prevent spam if you don't provide additional profile information you will be required to verify your account with a valid government ID. Only the expiration date will be stored.

- Information posted to your timeline.

Without this you will be unable to post updates.

- Messages sent to others.

Without this you will be unable to send messages.

- Profile Information: Name, Address ...

Allow Socially to collect the following information for the purposes of protecting your account:

- Network Addresses used to access the service.

- Login location

- Login times

After a short time using the service if we see a login that doesn't match the information on record we will notify the primary email for approval.

- Links to other sites you click.

We will check links you click against our list of known phishing sites and scams and warn you before redirecting you.

Allow Socially to collect the following information for running internal studies and improving our service.

- Features you use.

- Posts you read.

- Links to other sites you click.

Allow Socially to collect the following information to help make ads more relevant to you:

...

Re: Facebook urged to make GDPR its “baseline standard” globally

#196
post #108

There's been so many articles about Facebook and the recent privacy catastrophe that I'm finding it hard to keep up. Does anybody actually know what their response will be to the GDPR? Are the privacy benefits from the GDPR going to be exclusive to EU citizens? This seems problematic. Whatever happens, Facebook has irreparably damaged my trust in their handling of user data and I think many on here would agree. My wi…

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> The amount of blaming the nurse for your fever on those issues is getting really concerning.

"Study Suggests Medical Errors Now Third Leading Cause of Death in the U.S." (https://www.hopkinsmedicine.org/news/media/releases/study_su...)

Re: Facebook urged to make GDPR its “baseline standard” globally

#197

Earlier quoted context omitted.

You forgot the key Silicon Valley ethos: "Move fast and break things", where things include ethics and users' privacy expectations

Well the world has changed clearly. When facebook/myspace started out, would they have been able to achieve success if they were bogged down with data privacy compliance?

[deleted]

Re: Facebook urged to make GDPR its “baseline standard” globally

#198

“Urging” Facebook to do anything not in its commercial interest isn’t worth squat. Best case: another vague promise to be broken as soon as we forget. Facebook needs to be broken up and an American GDPR codified into law. If you care about this, pick up the phone and call your Congressperson and Senators.

Broken up into what? It's not Facebook's monopoly over social media that's the issue being discussed.

Re: Facebook urged to make GDPR its “baseline standard” globally

#199

Earlier quoted context omitted.

GDPR is more overeaching than that. You don’t need physical presence in EU to be subject to it. In theory, just having a webserver storing access logs (default of Apache and Nginx) makes you infringing it as EU IPs are now considered personal data.

> just having a webserver storing access logs (default of Apache and Nginx) makes you infringing it as EU IPs are now considered personal data. That's not true. Read the 23rd point right at the top: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Here's the part of it that covers your webserver: "Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union,…

From the french version, same (23):

> envisage d'offrir des services à des personnes concernées dans un ou plusieurs États membres de l'Union

They just have to prove you are considering EU in your app. It can be anything. Like Having EU timezones, or a country input with EU countries is enough to prove intent to server EU residents. If you collect IPs via your web sever, you are infringing.

Re: Facebook urged to make GDPR its “baseline standard” globally

#200
post #100

Earlier quoted context omitted.

Check out Article 3 of GDPR, "Territorial Scope", for some guidance on that: https://gdpr-info.eu/art-3-gdpr/

I read it and I am still confused. Does "in the Union" mean within the geographic borders of EU states? Does "established" mean having a physical presence? Having been incorporated? Registered with a regulatory body? Having remote employees who live there?

You have to physically live in the EEA, or the company doing the data collecting has to be located in an EEA member country.

If any of those two, or both, covered. If neither, not covered.

Post reply on HN