Earlier quoted context omitted.
Do you think that the GDPR has really changed anything for either Facebook or its users? Do you think that anything changed in the way data is being handled? All i see is a bunch of highly paid law firms writing up 200 additional pages in terms and conditions to shield the company, but nothing really changed as far as daily business is concerned.
Considering that GDPR is only in full effect after May 25th 2018, there is nothing to talk about in regards to its effect right now.
Zuckerberg didn’t make any friends in Europe today
311–320 of 326 posts
Re: Zuckerberg didn’t make any friends in Europe today
#312Earlier quoted context omitted.
I'm not a policymaker, but GDPR seems overly-reactionary, over-reaching, and not well thought-out. I think the negative unintended consequences are likely much greater than however much it actually protects the privacy of individuals (which I don't think will be much at all).
GDPR is mostly a regulation that was a directive (DPD) before. If you handled data responsible before and didn't do shady stuff with it, there is little extra to do to be GDPR compliant.
Re: Zuckerberg didn’t make any friends in Europe today
#313Earlier quoted context omitted.
Or having more competitors would push them to ask for data portability and thus transparency.
Data portability (and careless, incentivised users) is what started the Cambridge Analytica scandal.
Re: Zuckerberg didn’t make any friends in Europe today
#314Earlier quoted context omitted.
This is a uniquely American point of view on a European law though.
Businesses that make money off advertising are found all over the world, which is a bigger place than just America and the EU.
Re: Zuckerberg didn’t make any friends in Europe today
#315Earlier quoted context omitted.
Consent must be freely given, granular and revocable. Consent is only one of the six grounds for lawful data processing. Consent is not always necessary, nor is it always sufficient. https://gdpr-info.eu/art-6-gdpr/
> Consent must be freely given, granular and revocable “Granular” appears nowhere in the article you cite nor the related recitals (and even if the exact phrase did, the specific degree of granularity required would still be an open question.) > Consent is only one of the six grounds for lawful data processing. I’d argue it's two of the six, as voluntary entry into a contract which requires certain processing is a fo…
Recital 43 states:
"Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance."
Recital 42 states in part:
"Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment."
This is quite plainly worded - if you don't allow users to freely choose which data they give you and what you do with it, then you don't have valid consent. I think that "granular" is a reasonable description. There's certainly a degree of grey area, but the spirit is clear. Putting that into practice requires careful thought. Would a reasonable person understand the implications of your consent agreement? Would they be surprised or annoyed at the scope of your data collection or the use you make of that data? Could you reasonably anticipate a user being unable to properly exercise their rights to choose due to the choices you offer them?
>I’d argue it's two of the six, as voluntary entry into a contract which requires certain processing is a form of consent, even if the word doesn't “consent” isn't used in that provision.
The distinction between consent and contractual necessity is significant. If you're relying on the grounds of contractual necessity, then you can only collect and use the minimum of data for the minimum duration and process it to the minimum extent necessary to fulfil that contract (Art. 5 & recital 39). You can't keep customer data indefinitely or tack on a bunch of clauses to your T&Cs that allow you to sell that data to third parties. If you want to go beyond the absolute necessities, then you'll need to ask for consent. On the other hand, if you're relying on contractual necessity, then the conditions for consent (Art. 7) do not apply.
Re: Zuckerberg didn’t make any friends in Europe today
#316Earlier quoted context omitted.
It's a huge competitive advantage for privacy-oriented companies that were actually following the old Data Protection Directive. I've spoken to people who are in a blind panic about GDPR day, but I've also spoken to people who were completely unconcerned because they already had their ship in order. If your business relies on re-selling user data or aggressively targeting ads through data mining, coming into complian…
> If your business just sells a useful service at a reasonable price while respecting user privacy, you've got very little to worry about. What about games/apps people would never pay for but they would be ok with getting targeted ads within? Is the EU ok with losing these services because they would not be profitable businesses if their only option were to ask users to pay?
Evidently, yes. If your business can't survive without infringing on the rights of users, then the EU doesn't want your business.
Re: Zuckerberg didn’t make any friends in Europe today
#317Earlier quoted context omitted.
> If your business just sells a useful service at a reasonable price while respecting user privacy, you've got very little to worry about. What about games/apps people would never pay for but they would be ok with getting targeted ads within? Is the EU ok with losing these services because they would not be profitable businesses if their only option were to ask users to pay?
>Is the EU ok with losing these services because they would not be profitable businesses if their only option were to ask users to pay? Evidently, yes. If your business can't survive without infringing on the rights of users, then the EU doesn't want your business.
Re: Zuckerberg didn’t make any friends in Europe today
#318Earlier quoted context omitted.
>Is the EU ok with losing these services because they would not be profitable businesses if their only option were to ask users to pay? Evidently, yes. If your business can't survive without infringing on the rights of users, then the EU doesn't want your business.
But what if those apps could survive if they were allowed to ask for your private data or a payment? That wouldn't infringe on anyone's rights as far as I can tell.
Re: Zuckerberg didn’t make any friends in Europe today
#319Earlier quoted context omitted.
So you like your free travel and ability to work anywhere in the EU??? But beyond that what does the EU offer other than a lot of regulations that seem to be hurting a lot of smaller countries?
"...beyond that"... that is funny. The "ability to work anywhere in the EU" is a huge win for all countries involved, and it alone would be worth having the EU. And what kind of "regulations that seem to be hurting a lot of smaller countries" do you mean? I can't think of any.
Re: Zuckerberg didn’t make any friends in Europe today
#320Earlier quoted context omitted.
* Unfortunately, younger generations have lost sight of this, some of them erroneously believe that wars could not start again in Europe without the EU. That's very short-sighted, historically, Europe has been torn by wars almost all the time. * We live in different times today. 2018 is not 1918. I would be worried if younger generations could imagine to waste their lives and their wealth for war. The problem is that…
Nobody expected the war in 1918 either. US, and to a lesser extent European countries, have had little difficulty finding bodies to send to war in the last 50 years.