Live data from Hacker News

Facebook points finger at Google and Twitter for data collection

techcrunch.com

51–60 of 70 posts

Re: Facebook points finger at Google and Twitter for data collection

#51
post #35

Earlier quoted context omitted.

I really hope nothing remotely similar to gdpr is written into legislation in the US. I do not even know how I would get started writing a website that would adhere to GDPR requirements

So, on the one hand, I really would like a GDPR equivalent law in the US. OTOH, anyone who says they clearly understand the implications of GDPR for their site has either spent a lot of money on lawyers or is lying. Let alone someone who has implemented it. Privacy by design requires deletion of data after legitimate interests and/or consent have expired, probably (!!!) in 3rd party systems. How, precisely, do you im…

There are plain english guidelines available for the GDPR, in the UK they are published by the ICO which is the government agency tasked with enforcing the law. I'm sure there are edge cases which aren't fully documented but as long as you're not pushing the edges of the law and are trying to stay within the spirit you will be fine. Probably.

0. You require the third party you passed the data on to delete data when you tell them. The third parties should tell the person that they now have their data, where they got it from, how they will process it and how to get in touch with their data protection officer. 1. You can but you must also allow someone to delete in full (assuming none of the many reasons to reject removal requests apply or you don't wish to exercise them). 2. This is murky, but probably not. There's a right of freedom of expression and information. 3. No, you have to be a resident not a visitor. You'd have to see how Eire define residency.

Re: Facebook points finger at Google and Twitter for data collection

#52

Earlier quoted context omitted.

Thank you for showing me the supposedly trivial guide to understanding GDPR. The only thing that website has shown me is that no globally competitive tech company will ever grow out of the EU for the next hundred years or so.

So? Perhaps one of the facets of the GDPR is the EU’s willingness to accept that fostering “globally competitive tech companies” may not be in the best interests of itself or its citizens.

If that's the case, then they are absolute morons.

Re: Facebook points finger at Google and Twitter for data collection

#53

Earlier quoted context omitted.

Thank you for showing me the supposedly trivial guide to understanding GDPR. The only thing that website has shown me is that no globally competitive tech company will ever grow out of the EU for the next hundred years or so.

So? Perhaps one of the facets of the GDPR is the EU’s willingness to accept that fostering “globally competitive tech companies” may not be in the best interests of itself or its citizens.

Yes building tech companies that people love to use and provide high paying jobs does not benefit the citizens of a country

Re: Facebook points finger at Google and Twitter for data collection

#54

I personally don't really care about what information they collect. I do hugely care who they give that information to & what they do with it. Haven't heard anything about Google wholesale handing all my data over to anybody who clicks a couple buttons to sign up to their developer program though. I'm guessing Facebook has the technical expertise to allow 3rd parties to run aggregate (non identifying) queries on the…

Google keeps their data private because they've already secured their advertising/search territory. Disclosing profiles would only undermine their competitive advantage. It seems like Facebook gave away that information in hopes of developing a more engaging walled garden with 3rd party help, and perhaps some naivety. > I'm guessing Facebook has the technical expertise to allow 3rd parties to run aggregate (non ident…

> Google keeps their data private because they've already secured their advertising/search territory.

That is one possible self-interested reason for them to keep the data private. They could also just care deeply about guarding user data they collect. This could be for either selfish or unselfish reasons -- it's both good business and moral. It's very hard to tell from the outside, because their actions would look largely the same either way.

Personally I think it's pretty naive to believe any company does any thing for a single reason. There are a constellation of reasons, some more important than others.

Re: Facebook points finger at Google and Twitter for data collection

#55
post #35

Earlier quoted context omitted.

I really hope nothing remotely similar to gdpr is written into legislation in the US. I do not even know how I would get started writing a website that would adhere to GDPR requirements

So, on the one hand, I really would like a GDPR equivalent law in the US. OTOH, anyone who says they clearly understand the implications of GDPR for their site has either spent a lot of money on lawyers or is lying. Let alone someone who has implemented it. Privacy by design requires deletion of data after legitimate interests and/or consent have expired, probably (!!!) in 3rd party systems. How, precisely, do you im…

> OTOH, anyone who says they clearly understand the implications of GDPR for their site has either spent a lot of money on lawyers or is lying. Let alone someone who has implemented it.

http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...

It's long but the language is far easier than American legalese. The implications depend on your site/service behaviors. An RSS reader is pretty trivial, interactive social media... less so.

> Privacy by design requires deletion of data after legitimate interests and/or consent have expired, probably (!!!) in 3rd party systems. How, precisely, do you implement that?

Privacy by design is a design philosophy, it might be a pain to refactor into an existing system but the design constraints aren't onerous.

If your "3rd party system" is something like AWS, just delete the data. If you're sending it off to some other service, they do need to be GDPR complaint (the law covers this situation).

re: legitimate interests, we partitioned our data. Access logs, for example: one stream gets anonymized for simple analytics, another gets dumped into in-depth weekly analytics jobs, and the final log stream outputs encrypted auto-expiring S3 files with strong access control for infosec purposes. When a user withdraws consent, we just stop logging new information. Truly anonymized data is OK, our in-depth analytics data is purged within 14 days, and InfoSec is a justifiable legitimate interest.

> Can you shadow-delete accounts for some period of time to allow users to change their minds?

Yes. GDPR does not require instant response. You should be transparent about what will be kept and how long, a clearly communicated 24h shadow-delete is completely reasonable.

> Do people have GDPR privacy rights over eg comments on YC that may mention them by nym?

This is a good question, I'm also curious about quotes. The recent Google case suggests both fall under GDPR.

> Given the GDPR covers EU residents (not just citizens), as an American can I buy a plane ticket to Dublin and start requesting full data dumps? What rules are those provided to me under, and how do you make software that can do that?

Assume everyone is covered by GDPR.

Re: Facebook points finger at Google and Twitter for data collection

#56
post #6
post #2

I feel like whoever wrote this article missed the point completely. For the internet to function, websites need your information. If you want to log into a website using Facebook login, Facebook needs to know what website you are logging into. When you watch a Youtube video on someone else's website, in order for that data to be sent to you they need to know what your IP address is and they need to know what website…

Perhaps the internet must know, but must it remember?

Yes. If it can't remember, there won't be progress on anything.

Re: Facebook points finger at Google and Twitter for data collection

#57
post #50

Contrary to most comments here, it is significant that other companies do. Facebook competes in the free market. If they scale back on data collection, that will hurt their offering to advertisers and cost them money that will go to Google and others. That lost revenue will harm their ability to retain talent and build new products, and ultimately cost them their user base. “We don’t track you” is not as compelling a…

> Scaling back all US companies will give a leg up to competitors in more lenient jurisdictions

Laws can be written to only apply to American users. That would leave American companies free to compete on level terms in other countries.

Re: Facebook points finger at Google and Twitter for data collection

#58
post #7
post #6

Earlier quoted context omitted.

Perhaps the internet must know, but must it remember?

Yes absolutely, how do you think you prevent people from ddosing and how do you think we prevent spam if not with logs? Also I'm surprised how nobody has mentioned how important this data is for AB testing.

Perhaps "using customers as guinea pigs" is not the hill you want to die upon? A/B testing is not a good justification for data collection. It may, actually, be a good reason for condemning it.

Re: Facebook points finger at Google and Twitter for data collection

#59

I personally don't really care about what information they collect. I do hugely care who they give that information to & what they do with it. Haven't heard anything about Google wholesale handing all my data over to anybody who clicks a couple buttons to sign up to their developer program though. I'm guessing Facebook has the technical expertise to allow 3rd parties to run aggregate (non identifying) queries on the…

Google keeps their data private because they've already secured their advertising/search territory. Disclosing profiles would only undermine their competitive advantage. It seems like Facebook gave away that information in hopes of developing a more engaging walled garden with 3rd party help, and perhaps some naivety. > I'm guessing Facebook has the technical expertise to allow 3rd parties to run aggregate (non ident…

> multiple "non-identifying" queries can actually identify individuals.

Zero challenges from me on this. I 100% agree. However, it is doable. It just takes effort.

Re: Facebook points finger at Google and Twitter for data collection

#60

I personally don't really care about what information they collect. I do hugely care who they give that information to & what they do with it. Haven't heard anything about Google wholesale handing all my data over to anybody who clicks a couple buttons to sign up to their developer program though. I'm guessing Facebook has the technical expertise to allow 3rd parties to run aggregate (non identifying) queries on the…

> I personally don't really care about what information they collect If the government said "let's make a database of every Jew in America," people would get rightfully riled up. Yet we've allowed a single entity to assemble a database orders of magnitudes more detailed.

My opinions are influenced by (if memory serves) some Microsoft researcher who years back said something along the lines of how having all the data points is how computers can truly benefit an individual.

You can see the early fruition of this by looking at how useful Google Now/map planning etc are.

Computers could be our all knowing assistants.

That's on a very surface superficial level.

Imagine the kinds of benefits when this all knowing entity is applied to medical issues. Real substantive progress could be made.

However, today's mismanagement of data could scare people off all knowing entities for good & end up severely limiting real progress.

As with everything else, all that data is rife for abuse if the necessary legislation & technical limiting/auditing regarding access/use are not first put in to play.

Post reply on HN