Live data from Hacker News

Zuckerberg didn’t make any friends in Europe today

techcrunch.com

41–50 of 326 posts

Re: Zuckerberg didn’t make any friends in Europe today

#41
post #22

If anything, this kind of regulation helps companies like Facebook keep their "monopoly", because it raises the monetary cost of starting a competitor. A number of smaller services and games have shut down due to increased cost of compliance, even for companies that don't have any privacy issues.

What alternative do you propose? The free market obviously fails to address privacy issues, I don't see how anything besides stricter regulation can help the affected people here.

Not that I am advocating this approach, but regulations that are more about liability and transparency (towards journalists and shareholders) might help.

Liability means that mistakes are (hopefully) punished more proportionally to their effects, which allows one to scale measures as the business grows. Meanwhile, the transparency means that any potential issues are easier to spot, making it possible for suits to be brought. Note that transparency towards users has been shown to be rather ineffective, similar to how no-one reads the eula.

Re: Zuckerberg didn’t make any friends in Europe today

#42

There's some irony in getting the Oath panel forcing me to consent to their tracking (in apparent violation of the GDPR) before showing me an article about Facebook's data handling problems. By the way, if you want to read the article without agreeing to their stuff, stop the page load after the article shows up. https://guce.oath.com/collectConsent?brandType=nonEu&.done=h...

This sums up EU laws in a nutshell.

Re: Zuckerberg didn’t make any friends in Europe today

#43
post #6

Earlier quoted context omitted.

Why would that violate GDPR?

Requiring consent as a pre-condition of a service is frowned upon under GDPR. If you have a legitimate requirement (which is fairly rigidly defined under GDPR) or legal obligations for that data then you don’t need user consent, but if you don’t then you need to offer the service regardless of the user consent or not.

Techcrunch isn't an European company though, and IIRC they have no obligation to serve European customers so a "wall" is probably allowed. Even if it was european, I don't think the GDPR makes websites obligated to be accessible for everyone.

Re: Zuckerberg didn’t make any friends in Europe today

#44
post #22

Earlier quoted context omitted.

What alternative do you propose? The free market obviously fails to address privacy issues, I don't see how anything besides stricter regulation can help the affected people here.

I'm not a policymaker, but GDPR seems overly-reactionary, over-reaching, and not well thought-out. I think the negative unintended consequences are likely much greater than however much it actually protects the privacy of individuals (which I don't think will be much at all).

I don't think GDPR is flawless, but at some point if we don't do anything, privacy violations are going to become so common place and so entrenched in the online economy that we can't fix it anymore.

At that point, the discussion would be all about all the "jobs we would destroy" and "businesses opportunities we would shut down!", and heavy lobbying would make sure it gets nowhere.

Re: Zuckerberg didn’t make any friends in Europe today

#45

Most press I’ve read so far in Europe is largely neutral or positive about Zuckerberg but very negative about the procedings, the parliament and conduct of the representatives. This is unusual but in my option justified. Here is one particularly devastating article (Google Translate): https://translate.googleusercontent.com/translate_c?depth=1&...

Looking at the Dutch media it's the complete opposite of what you say. It's mostly about Zuckerberg not saying much, to the frustration of the members of parliament.

Well, they also state how odd it was how the proceedings were conducted, what with Zuckerberg being able to pick which questions to answer.

Re: Zuckerberg didn’t make any friends in Europe today

#46

Most press I’ve read so far in Europe is largely neutral or positive about Zuckerberg but very negative about the procedings, the parliament and conduct of the representatives. This is unusual but in my option justified. Here is one particularly devastating article (Google Translate): https://translate.googleusercontent.com/translate_c?depth=1&...

https://www.zeit.de/digital/internet/2018-05/mark-zuckerberg...

https://www.lemonde.fr/pixels/article/2018/05/22/facebook-zu...

https://www.heise.de/newsticker/meldung/Kritik-an-Zuckerberg...

interesting cause i read it as 'zuckerberg didn't say much of any substance'

Re: Zuckerberg didn’t make any friends in Europe today

#47
post #18

Earlier quoted context omitted.

you're not allowed to say usage of an application/service is conditional on accepting data collection.

I still don't see why not. Maybe it's what GDPR says, but it's wrong and I can't see this being enforced. If data collection is the "payment" for using the "service", you have two choices: you don't pay and don't use the service, or you pay up. This is like saying a business can't make usage of a service conditional to payment.

I think they're intentionally putting severe restrictions on business models that are built around paying for a consumer service by analyzing and sharing consumers' personal data instead of taking money. You're viewing this as a bug in the law; Europe views this as a feature.

There are certainly cases where one can make access to the service conditional on consent: for example, if the service is to analyze your resume/CV and give you feedback on improving it, or even job leads based on it, of course you'll need to consent to them collecting and processing the personal information on your resume. But you probably don't have to consent to them selling that data or using it to target you with ads going forward. They don't want that business model to be easily and broadly viable in Europe.

Re: Zuckerberg didn’t make any friends in Europe today

#48
post #6

Earlier quoted context omitted.

Why would that violate GDPR?

Requiring consent as a pre-condition of a service is frowned upon under GDPR. If you have a legitimate requirement (which is fairly rigidly defined under GDPR) or legal obligations for that data then you don’t need user consent, but if you don’t then you need to offer the service regardless of the user consent or not.

> Requiring consent as a pre-condition of a service is frowned upon under GDPR.

No, it's not. Requiring extraneous consent as a precondition of service, that is, requiring consent for some processing as a precondition of provision of a service that does not depend on that processing is an indication that consent is coerced rather than freely given, and hence not effective consent, under the GDPR. But what that means on concrete terms with complex interdependent services (and whether it is a de facto ban on such services, because instead extremely granular services and granular consent is required) remains to be clarified, probably through practical enforcement. If one views, for instance, what Facebook was offering pre-GDPR as a service, then “consent for what the service entails or no service” is not extraneous consent. If you view it as a cluster of distinct services, that becomes different. Whether the monetisation model of “free” services is essential or not is another question, and it's quite possible that GDPR will result in a lot fewer free-of-charge services available in the EU.

Re: Zuckerberg didn’t make any friends in Europe today

#49
post #17

Earlier quoted context omitted.

Requiring consent as a pre-condition of a service is frowned upon under GDPR. If you have a legitimate requirement (which is fairly rigidly defined under GDPR) or legal obligations for that data then you don’t need user consent, but if you don’t then you need to offer the service regardless of the user consent or not.

I think that's where the wiggle room (or court battleground?) of GDPR will be. Lots of companies do that: Quora, Pinterest,...

I think quora and co is more about having an account and not about any sort of data consent per say.

Re: Zuckerberg didn’t make any friends in Europe today

#50
post #18

Earlier quoted context omitted.

you're not allowed to say usage of an application/service is conditional on accepting data collection.

I still don't see why not. Maybe it's what GDPR says, but it's wrong and I can't see this being enforced. If data collection is the "payment" for using the "service", you have two choices: you don't pay and don't use the service, or you pay up. This is like saying a business can't make usage of a service conditional to payment.

I believe you can still store non-personally identifying information, that is to say if you cannot store that User X is a male of 40 years of age and that user x read the article, you can still store that a male of 40 years of age read the article. Probably you don't know User X gender and age under those conditions though.

But assume you have to store some personal information about User X and you do know gender as part of it. Or have code to derive gender at data saving time (This part is tricky by my reading, you have to be able to sort of sandbox the ways that you can get personally identifying info out so that you can show regulatory agencies that you're not pulling it out to do stuff you shouldn't. If you're pulling it out to enrich data before saving, but that data is still not personally identifying the user I think it is probably ok (I'm on shaky ground on this part)

User X as a user of service with login has to allow you to keep their login information or service cannot function. User X says you cannot save my reading history, meaning it cannot be associated with them. But at the time of reading it you save reading activity (this example is of course contrived and silly) - userType: 'requestAnonymous', haslogin: true, age: deriveLikelyAge(User), gender: returnLikelyGender(User), articleId: current.articleId

and so on and so forth. You still have quite a lot of valuable analytics, and you do have some other analytics about the user that has to be saved anyway - which is they have opted out of data collection schemes 1, and 3, but not 2,4,5.

Post reply on HN