Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

21–30 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#21
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

The option to monetize your own data is an amazing idea: a startup that pays you to upload the data you can download from your google, apple, facebook, BIGNAME account, basically renting it daily until you revoke consent, then uses it to do all sort of shit you can with it. You’ll get hypeprofiled and harassed with all sorts of advertising, but you’re actually getting real money for that.

Re: Google and Facebook accused of breaking GDPR laws

#22
My big problem with this is that the complaints are too quick (unless Google, Facebook, et al are stupid, which I don't think they are). First you have to make a request to see what they are using the data for. Then you can complain that it is being used for the wrong things. Unless the aforementioned companies are blatantly saying "We're sharing your data for targeted advertising without consent", then I think we have to wait a month for real complaints.

Re: Google and Facebook accused of breaking GDPR laws

#23
post #6

> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent" This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product. The GDPR just changed this -- rightfully, in my opinion.

yeah but now the product is not free.

Re: Google and Facebook accused of breaking GDPR laws

#25
post #20
post #15

Earlier quoted context omitted.

This is not "unintended consequences", it is explicitly anticipated by the law. Which is why people can and are suing. We'll see how it shakes out in the courts.

The law explicitly said "within hours of taking effect, these specific companies are to be sued due to not preparing sufficiently for GDPR"?

“Within hours”

You mean “within the 2 years probation period + a few hours”

Re: Google and Facebook accused of breaking GDPR laws

#26
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

The option to monetize your own data is an amazing idea: a startup that pays you to upload the data you can download from your google, apple, facebook, BIGNAME account, basically renting it daily until you revoke consent, then uses it to do all sort of shit you can with it. You’ll get hypeprofiled and harassed with all sorts of advertising, but you’re actually getting real money for that.

When “you are the product”, you can sell that product.

Re: Google and Facebook accused of breaking GDPR laws

#27
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Re: Google and Facebook accused of breaking GDPR laws

#28
post #6

> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent" This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product. The GDPR just changed this -- rightfully, in my opinion.

yeah but now the product is not free.

It'd be great if companies offered a "buy back your privacy" subscription model. For the services I really don't want to stop using (Twitter ...) I'd definitely be using that.

Re: Google and Facebook accused of breaking GDPR laws

#29
post #6

> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent" This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product. The GDPR just changed this -- rightfully, in my opinion.

yeah but now the product is not free.

Good now they have to make it worth paying for.

Re: Google and Facebook accused of breaking GDPR laws

#30
post #14

Earlier quoted context omitted.

or anyone who has a public httpd with default log settings

Default logging settings retain log files forever?

I don't know how long you are allowed to store PII under GDPR (I'm not a lawyer)

This article indicates that default settings are problematic: https://www.ctrl.blog/entry/gdpr-web-server-logs

> All of these logs contains personal information by default under the new regulation. IP addresses are specifically defined as personal data per Article 4, Point 1; and Recital 49. The logs can also contain usernames if your web service use them as part of their URL structure, and even the referral information that is logged by default can contain personal information (e.g. unintended collection of sensitive data; like being referred from a sensitive-subject website).

Post reply on HN