Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

221–230 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#221

Earlier quoted context omitted.

As someone who works in a startup in the healthcare space, I will point out that nobody lets health startups off the hook for HIPAA. You don’t get to be sloppy with people’s protected health information just because it makes your life easier.

I'm sorry but I don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger... it's not apples to apples

  I don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger
There is, or at least there was a Facebook project for exactly that [1]

The thing is that none of those "anonymized" subjects would have ever been asked for consent if they really knew about the consequences.

Such behavior has really, really bad real world implications: When I got a knee operated one of the questions on the questionaire you need to fill is if you agree that your data can be shared in anonymous form for research. At that point (and given that this was a fairly benign condition) I didn't see a problem with consenting.

After that revelation about what Facebook was up to my answer in the future is a clear NO!

Facebook handling medical data. What could ever go wrong with that?

[1] https://www.cnbc.com/2018/04/05/facebook-building-8-explored...

Re: Facebook urged to make GDPR its “baseline standard” globally

#222

Earlier quoted context omitted.

I'm not the one who commented above, but I can see some problems with freedom of speech related to GDPR. The main problem is that EU legislation is complex and subject to interpretation for which we have no precedents. Such legislation is easily exploited by authorities to silence opposition. As Napolen never said, "A Constitution should be short and obscure." GDPR is long and obscure. That leaves even more power to…

> The main problem is that EU legislation is complex and subject to interpretation for which we have no precedents. Such legislation is easily exploited by authorities to silence opposition. As Napolen never said, "A Constitution should be short and obscure." GDPR is long and obscure. That leaves even more power to the executive. I'm not sure what this has to with free speech though. Many laws (in any country / feder…

I think it is a free speech issue if "we'll see authorities shutting down blogs and websites using GDPR as their tool" which is what I predict.

Re: Facebook urged to make GDPR its “baseline standard” globally

#223

Earlier quoted context omitted.

> The main problem is that EU legislation is complex and subject to interpretation for which we have no precedents. Such legislation is easily exploited by authorities to silence opposition. As Napolen never said, "A Constitution should be short and obscure." GDPR is long and obscure. That leaves even more power to the executive. I'm not sure what this has to with free speech though. Many laws (in any country / feder…

I think it is a free speech issue if "we'll see authorities shutting down blogs and websites using GDPR as their tool" which is what I predict.

> we'll see authorities shutting down blogs and websites using GDPR as their tool

If they're shutting down blogs, there's 2 possible reasons for it:

1. The blog is using a non-compliant commenting system. This may be hand-rolled or 3rd-party: in either case, disabling comments is a common-sense measure to stay up. No legal complexity of any document should obscure the simplicity of this solution.

2. The hosting company hosting the blogging platform is non-compliant and gets shut down completely. In this case, your argument re: the company being small and not understanding legalese hopefully shouldn't apply.

If they're shutting down websites, those websites are offering a user-oriented service of some kind, and should get their act together w.r.t. understanding the legal implications of doing this, no matter how small they are.

If you're not processing user data, you're not a target. Exercising free speech does not require processing user data.

Re: Facebook urged to make GDPR its “baseline standard” globally

#224

Earlier quoted context omitted.

I think it is a free speech issue if "we'll see authorities shutting down blogs and websites using GDPR as their tool" which is what I predict.

> we'll see authorities shutting down blogs and websites using GDPR as their tool If they're shutting down blogs, there's 2 possible reasons for it: 1. The blog is using a non-compliant commenting system. This may be hand-rolled or 3rd-party: in either case, disabling comments is a common-sense measure to stay up. No legal complexity of any document should obscure the simplicity of this solution. 2. The hosting compa…

> If they're shutting down blogs, there's 2 possible reasons for it:

There are other possible reasons. Like "we don't like it".

I live in the country where the corruption index (calculated by Transparency International) is lowest in the world. Still, we have a "black list" of web sites that the police distributes to Internet access providers to block users from accessing the sites. The legal basis of this is supposed to be stopping child pornography, but still, the mechanism is used for blocking sites that criticize the police, and have no pornography at all. And there is no legal mechanism to challenge the police and stop them from doing this.

GDPR gives many additional tools for authorities to perform censorship like this.

Re: Facebook urged to make GDPR its “baseline standard” globally

#225
post #217
post #108

Earlier quoted context omitted.

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

You must be a Facebook employee. GDPR also relates to the consent of having personal data. Facebook is well known for using fishnet trawler techniques to gather whatever personal data they can with little regard for consent. Wouldn't be surprised if everything is passed on to Palantir anyway. The fact that several aspects of their business model will have to change to accommodate GDPR should be telling.

I was; I clearly mention it when relevant. I left to work on Deliveroo; I’m now at Booking.

I also wrote a PhD on how to implement monopoly enforcement to the company and I’ve published my critical understanding of the company’s position for more than ten years prior to joining the company, at academic conference, on my blogs, on Quora, occasionally here. I was the first person to write scary things about Facebook, probably in 2005.

As I wrote repeatedly, the company has a ton of issues and is generally extremely open about it (that there are, less what they are specifically). The trawler approach to data gathering was one of them. Thank you for pointing that out: focusing on real problems is important. Facebook has been fixing aspects of that repeatedly, but it is hard: some data gathering or sharing is actually relevant and expected, so you can’t cut things without understanding what you would break -- a clear strategy change in the last three years.

Why not do more faster? Because the company is already trying to respond as fast as they can. Employees and ex-employees are indeed more tolerant of this because we know personally of the insane amount of work there is to do; prioritisation, i.e. the arbitrage between your most and second most important task, what you do now or later is insane. I left the company to work in a more balanced environment that happened to be the fastest growing start-up ever, where I got woken up ever night at 4am because scaled killed our database again, migrating to a more scalable technology every four months.

Facebook had to reconsider offering services like targeting based on what Experian knows about their users, who I believe are almost exclusively American resident. I don’t think that has to do with GDPR because it’s not on the same continent but I’m not privy to details. EU citizen living in the US or Americans who moved to the EU are both large enough demographics to warrant caution.

They were not hiding the feature because there was an expectation from Americans that their credit card companies sold economic data; Facebook just made that integration easier -- I’m assuming as a reaction to how common a source of Custom Audience that was. If you didn’t like it before, you could hide it on https://www.facebook.com/ads/preferences/ with a click.

After the CA scandal, American became more sensitive to those approach and Facebook responded, almost instantly -- so fast advertisers are a little confused. That balance, pro-users, is also something that anyone familiar with the company, investors, board members but also employees can confirm: there is a strict hierarchy when one of the four “orgs” objectives disagree. Security is always right; User Engagement takes over Advertising.

Every business in Europe has to accommodate to GDPR, mainly processes but all advertising-based company massively so; one would in denial if they think that’s not the case -- the text is still widely open to interpretations. The fact that Facebook had the least amount to change is indeed telling. What you notice is the scale of the company, the prejudice and the attention. What you are missing is in front of you: Facebook is very willing to admit its wrongs and fix them.

Re: Facebook urged to make GDPR its “baseline standard” globally

#226
post #215

Earlier quoted context omitted.

> The amount of blaming the nurse for your fever on those issues is getting really concerning. The nurse is being blamed because they've ignored clear, worsening symptoms for years.

I’m sorry: what problem do you think Facebook is ignoring? I have heard interesting arguments elsewhere — but not on the company ignoring anything. All I’ve heard in this thread is people judging the company in hindsight, and based on a rather convoluted speculation (that happen to be false: Cambridge Analytica used credit card data and voter records, not Facebook data, to assess psychological profile). Facebook has…

> I’m sorry: what problem do you think Facebook is ignoring? I have heard interesting arguments elsewhere — but not on the company ignoring anything.

I think they've been willfully ignoring the likelihood that this sort of data exfiltration has been happening on a very widespread level for years. Many of those 800,000 "quiz" apps are likely designed for this purpose, and their proliferation should've set off warning bells inside Facebook - it did outside.

Zuckerberg's being out there acting like this was all an unforeseeable, shocking, limited-scope issue is disturbing to me.

Re: Facebook urged to make GDPR its “baseline standard” globally

#227

Earlier quoted context omitted.

IANAL, but crypto-shredding seems to be a viable way to meet GDPR deletion requirements, making it possible to implement compliant blockchains. Of course you'd have to make the nodes comply, but that has nothing to do with blockchains. But I still don't see the connection with the first amendment.

The first protects the nodes to store whatever social data they want. GDPR with particulary the right to be forgotten is a direct attack to this.

Yes, protects, it doesn't require them to. Facebook and its likes volunteering to destroy personal data on request really doesn't have anything to do with the first amendment at all.

Edit: come to think of it I'm not even sure it protects them, but again, it certainly doesn't require them to store or transmit anything.

Re: Facebook urged to make GDPR its “baseline standard” globally

#228
post #104

Earlier quoted context omitted.

The GDPR makes some things easier for start ups. Users now have a right to their personal data in a "commonly used" digital file. Now the start up can have a "Import your Facebook data" feature. Currently a provacy conscious start up is competing with those who aren't, making it harder. But with this law, you won't have as many shady companies like Facebook. Storing less private data makes you less liable to get hack…

You've been able to download your Facebook contents in a zip file for nearly six years. It made absolutely no difference in competition.

Yes, and that was due to existing EU data protection law, which gives you the right to access your personal data.

The GDPR states that it must be accessible in a common digital format which is new.

Re: Facebook urged to make GDPR its “baseline standard” globally

#229

Earlier quoted context omitted.

How does the GDPR interfere with one’s right to lawful political speech?

First amendment is protecting all speeches except direct threats of violence. Right to be forgoten is by essence incompatible with the first.

It says nothing in the text of the first amendment that direct threats of violence are not covered. If that restriction is compatible with the first amendment I don't see why a future right to be forgotten can't be.

Re: Facebook urged to make GDPR its “baseline standard” globally

#230
post #188

Earlier quoted context omitted.

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? The answer is yes, it is onerous. And yes, it does matter. Regulations always start as an idea that sounds good. The companies most impacted are then motivated to gain control of the regulations. Once they do, then they happily add on to regulations because that becomes a barrier to entry for new competitors,…

You must be American. This is not the first regulation in EU and they are created to serve it's citizens. The issue you are talking about is rampant in USA. The problem is not regulations but your politicians and your filthy rich businessmen.

See https://en.irefeurope.org/Publications/Online-Articles/Regul... for lots of examples showing that regulatory capture is a real issue in Europe. The fact that you turn a blind eye towards it shows that jingoism isn't a purely American trait.

And for the record, I grew up in Canada. I am not opposed to the idea of regulation in principle. However every approach has failure modes. And regulation works a lot better in practice when you exercise skepticism about the actual aim as opposed to the stated one.

If you wish to build your skills at skepticism, I highly recommend watching the series Yes, Minister. It is from the UK in the 1980s. However the lessons about how bureaucrats manage to get their way while pretending to listen to politicians are timeless. It also came out much later that it is less fiction than it first appears - most episodes were based on actual incidents. And some were downright prophetic - compare https://www.youtube.com/watch?v=37iHSwA1SwE with actual British policy towards the EU since.

I have no reason to believe that the picture painted then of the bureaucracy in Whitehall is significantly better than the bureaucracy that has sprung up in the EU.

Post reply on HN