Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

201–210 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#201

Earlier quoted context omitted.

If on your social network someone wants his posts to be removed, you have to comply under GDPR, or else. HN for example doesn’t allow to remove your comments after some time.

And how is me deleting my content your service violating your right to free speech exactly?

If it's a part of conversation - like most of social media posts -, I would assume it's fair use to keep it. Like if I interview you, and I publish the video, you can't retract what you said. Why social medias should be different?

Re: Facebook urged to make GDPR its “baseline standard” globally

#202
post #117

Earlier quoted context omitted.

You are making the wrong assumptions. I am a EU citizen, but live in the US. I will vote in an heartbeat for a 1st amendment like in an Europe law. You just don’t see how Europe speech is reatricted, and how laws like GDPR contributes to it.

I'm an EU citizen and I disagree, so I guess that's just, like, your opinion, man.

You won't vote to protect free speech?

Re: Facebook urged to make GDPR its “baseline standard” globally

#203

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

A big part of the problem is we have a brand new set of very vaguely written rules with no case law. Given time, I expect we should see case law and software change to be more GDPR friendly.

I am very curious to see what happens to EU ad revenue after GDPR. If it doesn't drop (outside of Google & Facebook's internal platforms), I'm guessing there isn't much GDPR compliance going on.

Re: Facebook urged to make GDPR its “baseline standard” globally

#204
post #182
post #175

Earlier quoted context omitted.

I think "reasonable measures" is pretty typical language when talking about compliance. I don't know GDPR regulation very well but I know FDA regulation reasonably well and I imagine compliance will be similar, and much easier for the new GDPR. Most important is to document everything. Have a design history file that you can show in case you get audited. When you design your software, save your designs in the DHF. Wh…

Well said! Thank you for your comments. With all that said, my point was that it's not obvious what is and isn't reasonable. Hiring a security specialist won't necessarily help you understand what bureaucrats will or won't deem reasonable, especially when there's no history to provide context.

You're right about that. I guess for a rule of thumb, imagine what the reaction on HN will be if your system gets hacked, and assume bureaucrats will say the same thing. Will they be criticizing "Everyones' credit card information was saved in plain text" or will it be "Even though this disgruntled employee uploaded everyone's usernames to [untrustworthysite], most of that information is still encrypted and the company made a public announcement about it hours later".

It's your best guess what is and isn't reasonable. As long as you've documented what you did and why you did it, then you've satisfied that requirement. If an auditor finds what you've done to be insufficient, you'll probably get a warning but you'll still be considered compliant for having done something.

I know it's not a satisfying answer and I'm sorry that I don't have a better one, but complying with regulation is not as definite a "yes/no" as programming.

My knowledge is with the FDA so I'll give an example I'm familiar with. I worked with CT scanners and we needed to do verification/validation. The FDA requirement was to the effect of "must define reasonable requirements for the device" and "must set up testing procedures that reasonably demonstrate that a device can meet its requirements" and so the team I worked with set requirements like "radiation dose: CT is an old industry so there was a bit more to it than that, but we were still following requirements that we had written, and testing them in with procedures we had made. The point is the requirements even in the health industry can be vague, so you really just have to do your best to come up with something reasonable.

And because it's vague, that's also why it's so important to document everything.

Re: Facebook urged to make GDPR its “baseline standard” globally

#205

Earlier quoted context omitted.

> just having a webserver storing access logs (default of Apache and Nginx) makes you infringing it as EU IPs are now considered personal data. That's not true. Read the 23rd point right at the top: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Here's the part of it that covers your webserver: "Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union,…

From the french version, same (23): > envisage d'offrir des services à des personnes concernées dans un ou plusieurs États membres de l'Union They just have to prove you are considering EU in your app. It can be anything. Like Having EU timezones, or a country input with EU countries is enough to prove intent to server EU residents. If you collect IPs via your web sever, you are infringing.

> is enough to prove intent to server EU residents

Given that it's still April, there's literally no way for you to know that. Also, the sentence you're quoting starts with "may make it apparent" not "does make it apparent".

Having said that, if you're building a service that let's people select EU timezones, countries, currencies and so on you're probably going to have a hard time proving that you're not providing goods or services to Europeans (because you probably are). If you're providing goods or services to Europeans GDPR applies.

Re: Facebook urged to make GDPR its “baseline standard” globally

#206

Earlier quoted context omitted.

What about deleting data in backups for an EU resident who submitted a request for data deletion? If a company is using mysqldump or equivalent it seems difficult to just drop certain records from those .sql files.

Difficult yes, impossible not.

Of course. For us, it came down to cost. EU customers make up <1% of our revenue. Implementing this non trivial feature didn’t make sense for us financially. So, we decided to drop all EU customers entirely.

Re: Facebook urged to make GDPR its “baseline standard” globally

#207

Earlier quoted context omitted.

Have a reasonable retention policy on these backups. Backups are a "legitimate business interest" and you don't need to purge "right to be forgotten" requests from your backups if you stick to a reasonable and publicly-documented retention policy. This is advice that I've received from counsel. However, I am not a lawyer, and this in no way should be taken as legal advice.

If you ever had to restore from backup, I hope you kept track of what content now needs to be "re-forgotten"

We received similar advice from our legal counsel, but got stuck on this implementation detail.

Re: Facebook urged to make GDPR its “baseline standard” globally

#208

Earlier quoted context omitted.

I kind of feel like every question in the first link is entirely reasonable and people _should_ be able to get those answers, though. Nothing in there is onerous if you're following good practices anyway. I really feel like the answers to all of those questions are going to be basically identical between people, and all you really need to do is be able to export whatever data you have on somebody quickly in order to…

> respond to that email in under quarter of an hour. Let's take an app like Instagram as an example. Instagram had over 1 million users within two months and 10 million within a year, and no profits. You're running on a shoestring trying to keep servers online without any serious budget to speak of. It's probably you and a few friends/associates working closely together. All of a sudden with GDPR, you have to pay a l…

If the concern is that business owners can no longer cut costs by being lax with people's data... isn't that the whole point of the GDPR? That we've collectively decided that letting people cut those costs is having too many negative concequences too often and that we need to stop?

Re: Facebook urged to make GDPR its “baseline standard” globally

#209

Could GDPR be the end of Facebook? GDPR mandates that the user data be portable. Users can now download their data and upload it to a new social network. What is stopping a new startup to come and create a social network where users upload their facebook data.

> What is stopping a new startup to come and create a social network [...]

Nothing. But Google Plus already had your name and a lot of information on you, yet still failed. Ello had a ton of hype around it and people signed up, yet no-one really stuck around.

Re: Facebook urged to make GDPR its “baseline standard” globally

#210
post #58

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

I think a few blogs have touched on this: * https://www.linkedin.com/pulse/nightmare-letter-subject-acce... * https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo... * https://wtfuh.com/2018-04-09/gdpr-has-a-few-problems/ * https://pagefair.com/blog/2018/granular-gdpr-consent/

I would strongly recommend reading what Pagefair has been putting. They have been one of the few sources I've found that is take GDPR literally. It isn't even clear what level Google's compliance will be - https://pagefair.com/blog/2018/googles-nonpersonal-ads/

There are a lot of extremely serious questions that arise regarding network security, anti-fraud, and anti-abuse measures. Just looking at basic bot detection measures, all of the sophisticated methods are now illegal. It certainly requires a major re-think of how websites serve content as well as the sustainability of advertising as a revenue channel. I can't even wrap my head around how someone would run a GDPR-compliant dating website/app.

If you think Pagefair's interpretations of the GDPR are correct then Google and others are calling the EU's bluff. They are implementing part of the GDPR strictly but the parts which invalidate their business models are being interpreted more liberally or ignored altogether.

I'm not saying that the GDPR is a good idea, bad idea, morally right or wrong. Rather, a lot of things we have come to view as a given -- such as how we detects bots, fraud, and abuse -- are no longer valid. Infrastructure, both technical and business, will need to be re-designed either to comply with the GDPR or evade it.

Post reply on HN