Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

101–110 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#101
post #69
post #27

Earlier quoted context omitted.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Define retention policies and explain you would keep IP addresses up to xxx months to ensure service operation/troubleshoot/etc. Prune the logs. There you have it.

Sounds like a legal headache for anybody who wants to set up a personal blog or blog for their company, with a penalty of up to 20 million euros if you get it wrong.

Re: Google and Facebook accused of breaking GDPR laws

#102
post #39

Earlier quoted context omitted.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

That's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.

If that's the case, you'll need to switch your provider.

I am pretty sure that any of the big providers who want to make business in the EU offers the possibility to prevent logging. If not, there is hope that they will soon.

Re: Google and Facebook accused of breaking GDPR laws

#103
post #36
post #32

Earlier quoted context omitted.

They would take your money and track you anyway, and everyone knows it

And be fined into oblivion.

How would anyone find out, and provide proof for this?

Can we expect a EU government agency to validate companies on a regular basis? And if not, would they even cooperate with white-hat hackers to find offenders?

Also, from what I read, data protection agencies have been understaffed and overworked for years now.

Re: Google and Facebook accused of breaking GDPR laws

#104
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

The smaller the site (and the newer) the easier it is to comply. Don’t amass mountains of ad data and you’re fine.

Re: Google and Facebook accused of breaking GDPR laws

#105
post #79
post #39

Earlier quoted context omitted.

That's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.

Was there anything stopping people taking legal action against website operators before GDPR?

No, but with the GDPR, they'd have more of a case, and it's easier to file a complaint. Whether that's a good or bad thing is a matter of perspective.

Re: Google and Facebook accused of breaking GDPR laws

#106
post #43
post #27

Earlier quoted context omitted.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Every website you visit can elect not to store IP addresses. In fact if you had German users their IPs were already protected, it's just that nobody cared to comply with individual EU member's privacy laws until they combined their weight into GDPR: https://blog.philippklaus.de/2011/05/modify-apache-logging-t...

Not necessarily. They may even be required to store access information, due to legal regulations in some countries. Also, providing service may become practically impossible if it is not possible to keep logs and similar data.

Re: Google and Facebook accused of breaking GDPR laws

#107
post #34

The 'loophole' here would be the definition of 'legitimate intrests', where businesses can defend not giving users a choice in many of these matters due to the activity being critical for the service to work or the business to survive. I.e. Facebook _could_ argue that users would have to have their data collected and analysed, as this would enable them to sell ads which in turn is their core interest. Another example…

Somebody on Reddit posted a list of Tumblr's "partners" that they share data with by default: https://i.imgur.com/YCNvEMa.png I'm finding it difficult to believe that they can come up with a "legitimate interest" for all of those that would also actually hold up in court.

I think those are just the members of the new IAB consent framework. This is how programmatic ads work, you "partner" with a bunch of ad networks and serve an ad from whichever is paying the most at that moment.

Re: Google and Facebook accused of breaking GDPR laws

#108
post #95

Earlier quoted context omitted.

Sign me up! The sad truth though is that the users who are most likely to pay to get rid of ads, are also the users that are most valuable to advertisers, because that's a signal they have more money to spend than the rest.

What if they say it's $20 a month? And it's just facebook. Google also asks for $20, Reddit too, etc. It won't be cheap.

We already donate to reddit.

Re: Google and Facebook accused of breaking GDPR laws

#109
post #75

Earlier quoted context omitted.

If a product that was in compliance goes out of compliance due to legal changes, it generally has to be pulled from the shelves. I'm saying this strictly from a legal perspective, not endorsing it per se, and I acknowledge the significant expense involved. But this sort of thing happens pretty frequently in a lot of other industries, and the result is pulled product and often a lot of destruction of unsold product. I…

If google had made software updates available, which gave the correct options and are GDPR compliant. But the OEM, Network don't approve / supply those updates, is Google at fault? (In this case its a non-Google phone running Android)

It's Google's terms, and Google is the one who determined the mandatory flow of that setup as per agreement with the hardware vendor. The EU could absolutely hold them responsible for not having this sorted out with their partners, it isn't like the OEM put the terms on a device and sold it without Google's permission.

Re: Google and Facebook accused of breaking GDPR laws

#110
post #71

Earlier quoted context omitted.

The GDPR ensures that only Facebook will be able to comply, and prospective competitors shouldn't even bother. The regulation counts 58 000 words.

I see so many people parroting this but I just don't get it. Surely it won't be a problem at all for a new startup handling data correctly from day 1? Facebook has a mountain of historical data that was collected using non-GDRP-compliant methods that now falls foul of EU law.

You need somebody that knows the regulations and developers that are capable of auditing the whole system. That's added fixed costs, which is an advantage for incumbents.
Post reply on HN