Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

31–40 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#31
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

What do you think changed for governments?

If there is a search warrant, police could and still can access data. GDPR didn't change anything in this regard.

My feeling is that in the EU there is a different view of government: it's not a third adversarial entity.

Many other remarks you've made don't have anything to do with GDPR, for example fake accounts and takeovers.

Re: Google and Facebook accused of breaking GDPR laws

#32
post #28

Earlier quoted context omitted.

yeah but now the product is not free.

It'd be great if companies offered a "buy back your privacy" subscription model. For the services I really don't want to stop using (Twitter ...) I'd definitely be using that.

They would take your money and track you anyway, and everyone knows it

Re: Google and Facebook accused of breaking GDPR laws

#34

The 'loophole' here would be the definition of 'legitimate intrests', where businesses can defend not giving users a choice in many of these matters due to the activity being critical for the service to work or the business to survive. I.e. Facebook _could_ argue that users would have to have their data collected and analysed, as this would enable them to sell ads which in turn is their core interest. Another example…

Somebody on Reddit posted a list of Tumblr's "partners" that they share data with by default: https://i.imgur.com/YCNvEMa.png

I'm finding it difficult to believe that they can come up with a "legitimate interest" for all of those that would also actually hold up in court.

Re: Google and Facebook accused of breaking GDPR laws

#35
post #27

Earlier quoted context omitted.

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

Re: Google and Facebook accused of breaking GDPR laws

#36
post #32
post #28

Earlier quoted context omitted.

It'd be great if companies offered a "buy back your privacy" subscription model. For the services I really don't want to stop using (Twitter ...) I'd definitely be using that.

They would take your money and track you anyway, and everyone knows it

And be fined into oblivion.

Re: Google and Facebook accused of breaking GDPR laws

#37
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

On the positive side, it could also reduce product lock-in by increasing data portability. For example if I'm creating a social network startup, and users can export their data from Facebook in a parseable format, then it's trivial for me to offer an "import your data from Facebook" feature. The interesting question then becomes, could Facebook do anything about that? In the past they would be able to sue the startup for appropriating data that Facebook was granted an exclusive license to via TOS. Now it's not so clear. Where are the limits of my control of my own data?

Re: Google and Facebook accused of breaking GDPR laws

#38
I am reading through the complaints,

The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android...

The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS.

Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an update waiting to resolve GDPR related issues, you would need to agree to the ToS to get that update, to enable opt-out?

In that point of view, it seems a rather unfair complaint. I havn't checked the other's yet, but I start to feel that perhaps these have been filed too early, without enough thought and examination, just to get headlines?

Re: Google and Facebook accused of breaking GDPR laws

#39
post #27

Earlier quoted context omitted.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

That's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging.

Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.

Re: Google and Facebook accused of breaking GDPR laws

#40
post #25
post #20

Earlier quoted context omitted.

The law explicitly said "within hours of taking effect, these specific companies are to be sued due to not preparing sufficiently for GDPR"?

“Within hours” You mean “within the 2 years probation period + a few hours”

GDPR has been law for two years, since 25 May 2016, a point your downvoters seem to be missing.
Post reply on HN