Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

1–10 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#3
This is the crux of the problems with how companies are interpreting the GDPR. Every service I've seen with a privacy policy pop up within the last 24 hours has basically justified all of their current data collecting practices as being necessary for their business. The spirit of the GDPR is to improve privacy, not just make Terms of Service pages longer.

Re: Google and Facebook accused of breaking GDPR laws

#6
> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent"

This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product.

The GDPR just changed this -- rightfully, in my opinion.

Re: Google and Facebook accused of breaking GDPR laws

#7
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

"large sites with business models developed around shady stuff GDPR is supposed to protect from" - there, FIFY.

Re: Google and Facebook accused of breaking GDPR laws

#8

This is the crux of the problems with how companies are interpreting the GDPR. Every service I've seen with a privacy policy pop up within the last 24 hours has basically justified all of their current data collecting practices as being necessary for their business. The spirit of the GDPR is to improve privacy, not just make Terms of Service pages longer.

Yeah, but the law of unintended consequences is sure to apply. The GDPR hits adtech companies fundamentally.

Re: Google and Facebook accused of breaking GDPR laws

#9
I am trying to think what the secondary consequences of GDPR are going to be.

If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything.

If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out their data by the day for model training using the right to delete.

Account takeovers by hackers will lead to much more severe data breaches, since all data on that user in the system is easily accessible.

The information apocalypse is made all that more easy because acount takeover + deep fakes + lyrebird plus all that easily accessible juicy data = impersonate anyone.

Data renting will create a way to monetize account takeover. The account takeover will include all possible information used to identify a person so how are the data brokers supposed to know it isn't you and how are you supposed to get your data back once it's out there getting monetized?

Post reply on HN