Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

191–200 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#191

Earlier quoted context omitted.

> IP addresses are PII, as defined in the law. No, that's far from fucking clear, but appears to have been repeated over and over and over again.

It’s in the faq, you can’t be upset with people repeating it. https://www.eugdpr.org/gdpr-faqs.html [edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/refo...

"IP address" does not appear in that text.

Re: Google and Facebook accused of breaking GDPR laws

#192
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

Lawyers can say such things and I'm sure that Facebook will try to fight it, but I don't think they'll be able to do so successfully, because the GDPR is very specific about what a "legitimate interest" is.

See here for an explanation: https://www.gdpreu.org/the-regulation/key-concepts/legitimat...

PS: the EU can't wait to give fat fines to companies like Facebook and Google, due to their tax evasion schemes. It's the whole reason for why these companies haven't been able to stop GDPR, with all of their lobbying prowess. And I don't care about such motives, as an EU citizen I'm glad that GDPR exists.

Re: Google and Facebook accused of breaking GDPR laws

#193

The 'loophole' here would be the definition of 'legitimate intrests', where businesses can defend not giving users a choice in many of these matters due to the activity being critical for the service to work or the business to survive. I.e. Facebook _could_ argue that users would have to have their data collected and analysed, as this would enable them to sell ads which in turn is their core interest. Another example…

Yes and I think because of that 'legitimate interest' clause companies like Facebook will be allowed to work as ususal.

I am not big Facebook fun, but I understand that they business model relays on selling targeted ads, so they have 'legitimate interest' to track their users, because otherwise they would have to go out of business - I don't think it should be possible to force someone to radically change business model because of GDPR.

The interesting part is that GDPR is something that will be enforced an the countries level, so each country might have different interpretation of that clause and I see that there will be competition among countries who will offer 'better' interpretation from business perspective.

Re: Google and Facebook accused of breaking GDPR laws

#194

Earlier quoted context omitted.

The option to monetize your own data is an amazing idea: a startup that pays you to upload the data you can download from your google, apple, facebook, BIGNAME account, basically renting it daily until you revoke consent, then uses it to do all sort of shit you can with it. You’ll get hypeprofiled and harassed with all sorts of advertising, but you’re actually getting real money for that.

When “you are the product”, you can sell that product.

you would have to find a market for them first. realistically private data is useless outside of a marketing platform like google or facebook. Maybe you can fill up some forms or polls for a few cents, that's it.

Re: Google and Facebook accused of breaking GDPR laws

#195

Earlier quoted context omitted.

> unable to understand What if he is not very smart? Or even better, what if he is very dumb? At which level should those be written then?

The literal text of the GDPR is as follows: >the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

Yes, and before that it says ` If the data subject's consent is given in the context of a written declaration which also concerns other matters,` which means i can use legalese but only if it does not concern other matters in the same document? :)

Re: Google and Facebook accused of breaking GDPR laws

#196
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

> So Facebook's lawyers can say, "It's in our legitimate interest to maximise advertising revenue".

They can say it is their interest to have enough revenue to operate the site and some (how much?) profit above that. Maximizing revenue is an other angle.

Though if we accept that we live in capitalist society then maximizing profits is one of the core tenets of that.

Re: Google and Facebook accused of breaking GDPR laws

#197
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

The assumption you're making with most of your points is that, currently, data is only safe from governments/hackers because its not readily available to users, and for some reason it being not easily accessible by users means its safer (correct me if I'm reading what you're saying wrong). I don't think making the data more available to users means it's now inherently less safe - actually, it could be argued that hav…

You have expanded the surface area for hackers for sure esp. if you have an automated system. If your system is manual, like a phone number, that's not immune to phishing/stolen identity attacks.

Re: Google and Facebook accused of breaking GDPR laws

#198
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

On the positive side, it could also reduce product lock-in by increasing data portability. For example if I'm creating a social network startup, and users can export their data from Facebook in a parseable format, then it's trivial for me to offer an "import your data from Facebook" feature. The interesting question then becomes, could Facebook do anything about that? In the past they would be able to sue the startup…

Facebook has been offering their data for free for a very long time. in fact that's what they re accused of. They also have export tools since long ago, like twitter IIRC.

I think their terms specifically say that your data belongs to you.

Re: Google and Facebook accused of breaking GDPR laws

#199

Earlier quoted context omitted.

> and isn't given an option to decline consent to Googles ToS You can turn off the phone and sell it on Ebay

If you live in the USA. However, as an European you have more rights, and in the next years we will witness a lot of battles between EU users and American corporations desperately trying to maintain the old status quo.

To downvoters: I'm curious to hear your counter-arguments. Yes, as a European I have more rights related to personal data than Americans. American companies can continue playing the same old tricks on American citizens with no consequences. It's not possible to do the same to Europeans anymore.

Re: Google and Facebook accused of breaking GDPR laws

#200
post #138

Earlier quoted context omitted.

I'm pretty sure that's incorrect at least today, it's possible to skip through the initial setup on a stock Android device without adding a Google account or accepting a ToS.

If there is, they don't make it obvious. Whenever I've tried setting up a stock Android phone, I've looked for a way to do so without adding a Google account, but found no such option. Perhaps it's possible to do so by pressing or holding some obscure sequence of buttons, but in that case it is reasonable to argue that a 'hidden' option isn't really an option at all. After all, you can't hide microscopic text on a pa…

"Add a google account, enter your email"

On the bottom of that page in grey is a skip button. You do that and you've skipped over it.

Post reply on HN