Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

11–20 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#12
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

Re: Google and Facebook accused of breaking GDPR laws

#14
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

or anyone who has a public httpd with default log settings

Re: Google and Facebook accused of breaking GDPR laws

#15
post #8

This is the crux of the problems with how companies are interpreting the GDPR. Every service I've seen with a privacy policy pop up within the last 24 hours has basically justified all of their current data collecting practices as being necessary for their business. The spirit of the GDPR is to improve privacy, not just make Terms of Service pages longer.

Yeah, but the law of unintended consequences is sure to apply. The GDPR hits adtech companies fundamentally.

This is not "unintended consequences", it is explicitly anticipated by the law. Which is why people can and are suing. We'll see how it shakes out in the courts.

Re: Google and Facebook accused of breaking GDPR laws

#16
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

Because they're not failing due to misunderstanding the law, they're getting sued because their 'compliance' to the GDPR is against the spirit of it, and in most cases is actually in direct violation of multiple clauses. They're trying to follow the letter of the law and remain in the grey areas - if a 'small site run by a few regular folks' isn't doing anything shady, and isn't being basically negligent with their users data, they will be fine.

Re: Google and Facebook accused of breaking GDPR laws

#18
post #14

Earlier quoted context omitted.

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

or anyone who has a public httpd with default log settings

Default logging settings retain log files forever?

Re: Google and Facebook accused of breaking GDPR laws

#19
The 'loophole' here would be the definition of 'legitimate intrests', where businesses can defend not giving users a choice in many of these matters due to the activity being critical for the service to work or the business to survive.

I.e. Facebook _could_ argue that users would have to have their data collected and analysed, as this would enable them to sell ads which in turn is their core interest.

Another example could be automatic enrollment into newsletters or data collection/analyzation with the option to opt-out by going to settings. You don't _have_ to give users the explicit consent checkbox during signup if you can defend the activity by it being in your legitimate interests.

This article goes into more detail: https://medium.com/mydata/five-loopholes-in-the-gdpr-367443c...

Re: Google and Facebook accused of breaking GDPR laws

#20
post #15
post #8

Earlier quoted context omitted.

Yeah, but the law of unintended consequences is sure to apply. The GDPR hits adtech companies fundamentally.

This is not "unintended consequences", it is explicitly anticipated by the law. Which is why people can and are suing. We'll see how it shakes out in the courts.

The law explicitly said "within hours of taking effect, these specific companies are to be sued due to not preparing sufficiently for GDPR"?
Post reply on HN