Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

61–70 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#61
post #30

Earlier quoted context omitted.

I don't know how long you are allowed to store PII under GDPR (I'm not a lawyer) This article indicates that default settings are problematic: https://www.ctrl.blog/entry/gdpr-web-server-logs > All of these logs contains personal information by default under the new regulation. IP addresses are specifically defined as personal data per Article 4, Point 1; and Recital 49. The logs can also contain usernames if your we…

> Article 4, Point 1 Article 4 Point 1 is: > (1) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical,…

https://eugdprcompliant.com/personal-data/

> [...] The conclusion is, all IP addresses should be treated as personal data, in order to be GDPR compliant.

https://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip...

> What does the GDPR say?

> [...] Recital 30 clarifies that "online identifier" includes IP addresses.

http://www.privacy-regulation.eu/en/r30.htm

> (30) Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags.

Re: Google and Facebook accused of breaking GDPR laws

#62
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

The option to monetize your own data is an amazing idea: a startup that pays you to upload the data you can download from your google, apple, facebook, BIGNAME account, basically renting it daily until you revoke consent, then uses it to do all sort of shit you can with it. You’ll get hypeprofiled and harassed with all sorts of advertising, but you’re actually getting real money for that.

The problem with that model is... how much money is a single profile worth, really?

I'd love to be proven wrong and for a company to implement this. But as far as I know, it's not being done because the math doesn't work out. It's too cheap for regular people to be interested, and an incentive for spamtech to mass create fake profiles and get paid pennies for it.

In fact, the one variant I am aware of that works is survey sites, but that's because you get paid per result rather than for your data as a whole. If you're just renting your data daily, you'd get a lot less.

Re: Google and Facebook accused of breaking GDPR laws

#63
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

> If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything.

This could streamline processing of warrants, but beyond that, not much changes. If company's infrastructure was vulnerable to governments, it probably still will be. Maybe less so, given that GDPR also adds extra motivation for keeping users' data secure.

> If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out their data by the day for model training using the right to delete.

As it should be? They own it, so they can sell it.

> Account takeovers by hackers will lead to much more severe data breaches, since all data on that user in the system is easily accessible.

Not necessarily. GDPR isn't about storing all user data in one big table named PII. It's about knowing, via company procedures, what data you store and what the lifecycle of that data is. Also, with rights to delete data and revoke consents, there'll likely be less data available for an attacker to exfiltrate.

> The information apocalypse is made all that more easy because acount takeover + deep fakes + lyrebird plus all that easily accessible juicy data = impersonate anyone.

Not sure how this is relevant to GDPR. Could you elaborate?

> Data renting will create a way to monetize account takeover. The account takeover will include all possible information used to identify a person so how are the data brokers supposed to know it isn't you and how are you supposed to get your data back once it's out there getting monetized?

How was this different before GDPR? I don't see anything changing in that regard; what you wrote is already the case. Again, if anything, GDPR will reduce the amount of information an attacker can extract from a compromised account, because companies are incentivized to reduce the amount of data they store.

Re: Google and Facebook accused of breaking GDPR laws

#64
post #27

Earlier quoted context omitted.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

> IP addresses are PII, as defined in the law. No, that's far from fucking clear, but appears to have been repeated over and over and over again.

It’s in the faq, you can’t be upset with people repeating it.

https://www.eugdpr.org/gdpr-faqs.html

[edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Re: Google and Facebook accused of breaking GDPR laws

#65
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

On the positive side, it could also reduce product lock-in by increasing data portability. For example if I'm creating a social network startup, and users can export their data from Facebook in a parseable format, then it's trivial for me to offer an "import your data from Facebook" feature. The interesting question then becomes, could Facebook do anything about that? In the past they would be able to sue the startup…

The data belongs to the user. There's nothing Facebook can do to prevent exporting if it's via the data backup. They can just design it in a way that is easy to read by humans but very challenging for parsers.

Re: Google and Facebook accused of breaking GDPR laws

#66

My big problem with this is that the complaints are too quick (unless Google, Facebook, et al are stupid, which I don't think they are). First you have to make a request to see what they are using the data for. Then you can complain that it is being used for the wrong things. Unless the aforementioned companies are blatantly saying "We're sharing your data for targeted advertising without consent", then I think we ha…

Isn't the tracking a claim they make to advertisers, and can I opt out without declining the entire ToS?

Edit: Just to be clear. I'm not in the EU, so I can't check the ToS. If they are being stupid, then that's pretty stupid of them ;-)

The thing is, it is possible that as of today they have stopped tracking. I agree that it's very unlikely, but unless they actually tell you that they are tracking you, how would you know? You get ads, but they could be completely random. Who knows? As of today, maybe all EU residents are getting random ads? Until you make a request, I think you can't quite complain (again, unless they are stupid and actually telling that they are tracking you).

Re: Google and Facebook accused of breaking GDPR laws

#67

I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…

> and isn't given an option to decline consent to Googles ToS

You can turn off the phone and sell it on Ebay

Re: Google and Facebook accused of breaking GDPR laws

#68
post #55
post #46

Earlier quoted context omitted.

Companies have had two years to get their act sorted out on this.

I can still purchase a "new" 2 year old phone. I think that is a valid question.

Aren‘t the ToS pulled from the web when you set it up with a google account? I doubt you‘re agreeing to two year old ToS.

Re: Google and Facebook accused of breaking GDPR laws

#69
post #27

Earlier quoted context omitted.

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Define retention policies and explain you would keep IP addresses up to xxx months to ensure service operation/troubleshoot/etc.

Prune the logs.

There you have it.

Re: Google and Facebook accused of breaking GDPR laws

#70
post #30

Earlier quoted context omitted.

I don't know how long you are allowed to store PII under GDPR (I'm not a lawyer) This article indicates that default settings are problematic: https://www.ctrl.blog/entry/gdpr-web-server-logs > All of these logs contains personal information by default under the new regulation. IP addresses are specifically defined as personal data per Article 4, Point 1; and Recital 49. The logs can also contain usernames if your we…

> Article 4, Point 1 Article 4 Point 1 is: > (1) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical,…

> It is very far from clear that that covers IP addresses, which tend to be recycled

Enter stage left: Address van Six, carrying an EUI64 card in his right hand.

Post reply on HN