Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

71–80 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#71
post #6

> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent" This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product. The GDPR just changed this -- rightfully, in my opinion.

The GDPR ensures that only Facebook will be able to comply, and prospective competitors shouldn't even bother.

The regulation counts 58 000 words.

Re: Google and Facebook accused of breaking GDPR laws

#72
post #15
post #8

Earlier quoted context omitted.

Yeah, but the law of unintended consequences is sure to apply. The GDPR hits adtech companies fundamentally.

This is not "unintended consequences", it is explicitly anticipated by the law. Which is why people can and are suing. We'll see how it shakes out in the courts.

People are not "suing," they're filing complaints.

It's a small but important difference, since a lot of the uncertainty and doubt around the GDPR seems to revolve around being sued out of existence in courts of law, which is not a thing: you can't get sued randomly by disgruntled users.

Re: Google and Facebook accused of breaking GDPR laws

#73
post #56

> forcing people to accept wide-ranging data collection in exchange for using a service is prohibited under GDPR Erm... I don't think that's true. As long as you are open and transparent about what you are doing, and give users the right to request, update and delete the data you hold on them, then AFAIK this is allowed

Nope thats actually true. You cant force say tracking, if its not absolutely needed, for the product to work. And i think thats why a lot of the popups have dark patterns, to hide the fact, that you can no opt out to these things.

Re: Google and Facebook accused of breaking GDPR laws

#74
post #55
post #46

Earlier quoted context omitted.

Companies have had two years to get their act sorted out on this.

I can still purchase a "new" 2 year old phone. I think that is a valid question.

fwiw, the phone in the complaint is from 2018.

Re: Google and Facebook accused of breaking GDPR laws

#75
post #55
post #46

Earlier quoted context omitted.

Companies have had two years to get their act sorted out on this.

I can still purchase a "new" 2 year old phone. I think that is a valid question.

If a product that was in compliance goes out of compliance due to legal changes, it generally has to be pulled from the shelves. I'm saying this strictly from a legal perspective, not endorsing it per se, and I acknowledge the significant expense involved. But this sort of thing happens pretty frequently in a lot of other industries, and the result is pulled product and often a lot of destruction of unsold product.

In this case, fortunately, the hardware may not necessarily need to be destroyed, but it couldn't be sold until the software stack complies. Or, more likely economical, ship the phones somewhere where they are still legal and ship new stock into the EU with updated software. Or make sure there's an immediate update available for the phones and petition the EU for a variance on the grounds that as long as they update, they'll get compliant software. There's a number of options.

Re: Google and Facebook accused of breaking GDPR laws

#77
post #68
post #55

Earlier quoted context omitted.

I can still purchase a "new" 2 year old phone. I think that is a valid question.

Aren‘t the ToS pulled from the web when you set it up with a google account? I doubt you‘re agreeing to two year old ToS.

Possibly, but it still might not be possible for Google to provide a means to decline the ToS without issuing an update (which, as has been pointed out, wouldn't be possible to install anyway without accepting the ToS).

Re: Google and Facebook accused of breaking GDPR laws

#78
post #27

Earlier quoted context omitted.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

> IP addresses are PII, as defined in the law. No, that's far from fucking clear, but appears to have been repeated over and over and over again.

I would love for you to be right. A search for "gdpr are ip addresses personal data" only shows me articles that confirm what I said, including a ECJ ruling.

Re: Google and Facebook accused of breaking GDPR laws

#79
post #39

Earlier quoted context omitted.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

That's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.

Was there anything stopping people taking legal action against website operators before GDPR?

Re: Google and Facebook accused of breaking GDPR laws

#80
post #15
post #8

Earlier quoted context omitted.

Yeah, but the law of unintended consequences is sure to apply. The GDPR hits adtech companies fundamentally.

This is not "unintended consequences", it is explicitly anticipated by the law. Which is why people can and are suing. We'll see how it shakes out in the courts.

They're not being sued, and it's not a case for the courts.

They're being reported to the Data Protection Agencies in various EU countries.

Post reply on HN