Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

221–230 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#222
post #204

Earlier quoted context omitted.

But these regulations are not that complicated! Heck, in the EU we've been observing most of them in the last years already. Most things are really straightforward. Things get complicated when your core business is making users' data available to third parties. But it's not different from any other business: if you want to make money in catering for example, you need to read and adhere to relevant laws, too.

Is an IP address PII or not? I have read multiple different interpretations today. Is a hash of an IP address PII?

Is this really that complex? If it can be linked to the individual, then it is. https://www.whitecase.com/publications/alert/court-confirms-...

Re: Google and Facebook accused of breaking GDPR laws

#223

Earlier quoted context omitted.

If you live in the USA. However, as an European you have more rights, and in the next years we will witness a lot of battles between EU users and American corporations desperately trying to maintain the old status quo.

To downvoters: I'm curious to hear your counter-arguments. Yes, as a European I have more rights related to personal data than Americans. American companies can continue playing the same old tricks on American citizens with no consequences. It's not possible to do the same to Europeans anymore.

You were probably downvoted for your the absoluteness of your statement. For instance, you do not have more rights as a European business owner. Even as just a user, you have fewer rights to enter agreements now with these tech companies free from government involvement. What you may call rights, others call restrictions and limitations of rights.

Re: Google and Facebook accused of breaking GDPR laws

#224
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

You could probably take it a step further and say that it is in the user’s best interest to see targeted rather than generic advertising, because you can show fewer ads and make the same revenue. I don’t know if regulators will buy it though. I for one am very interested to see how this continental experiment changes the experience of internet users in Europe. And I’m sure glad (at least in this dimension) that I’m n…

> You could probably take it a step further and say that it is in the user’s best interest to see targeted rather than generic advertising, because you can show fewer ads and make the same revenue. I don’t know if regulators will buy it though.

It would be hard to argue that when none of these companies are in fact showing "fewer ads" as a result of targeting.

Re: Google and Facebook accused of breaking GDPR laws

#225
post #88

Earlier quoted context omitted.

Nope thats actually true. You cant force say tracking, if its not absolutely needed, for the product to work. And i think thats why a lot of the popups have dark patterns, to hide the fact, that you can no opt out to these things.

Hmm, seems you are right, I just found this PDF from the ICO: https://ico.org.uk/media/about-the-ico/consultations/2013551... "Avoid making consent a precondition of a service" "consent requests must be separate from other terms and conditions. Consent should not be a precondition of signing up to a service unless necessary for that service" I assume Facebook et al will simply find a way to make everything 'necessary…

They have, and thats why they are going to be sued.. they made tracking a precondition for using the service.

Re: Google and Facebook accused of breaking GDPR laws

#226
post #174

Earlier quoted context omitted.

If companies successfully argue that maximising revenue is a legitimate interest and thus, don't need users consent, then the GPDR will worth less the paper it was written on. I would be extremely surprised if the EU goes through all this tome, effort, and money just to let corporations continue with business as usual

> I would be extremely surprised if the EU goes through all this tome, effort, and money just to let corporations continue with business as usual I wouldn't. EU is all about bureaucracy and hordes of civil servants doing meaningless jobs. If GDPR becomes fruitless like Cookie Law, then they'll say tough luck, hire more civil servants and start working on another useless law.

There was a lot of lobbying done to water down the GDPR.

But on the other hand, corporations are all about unscrupulous behaviour and doing the minimum possible (if that) to claim they respect the law. If the GDPR works, they'll just hire more lobbyists.

Re: Google and Facebook accused of breaking GDPR laws

#227

This is the crux of the problems with how companies are interpreting the GDPR. Every service I've seen with a privacy policy pop up within the last 24 hours has basically justified all of their current data collecting practices as being necessary for their business. The spirit of the GDPR is to improve privacy, not just make Terms of Service pages longer.

Actually the spirit of GDPR is also to make Terms of Service shorter by being clear and understandable. If you as a user is unable to understand what you are agreeing to then it is a violation of GDPR.

Our policies got much longer with GDPR. We only collect information for legitimate reasons (i.e we need it for the service they are using), we ask for it, and we never target it / sell the data. It helps that our customers are paying customers and not using a free service.

So our TOS used to be quite simple in plain english that all the data we request is only for the purpose of providing the service.

Now we had to outline all the information we collection (even though they are the ones who provide it, so they know what we collect) and outline all our services we use where that data we collect ends up (AWS, Sentry, Loggly, etc... the services we need to run our system and support them). Most of our clients have no idea what any of the information we added is because its all technical details about how we are providing the service to them.

GDPR required us to do a lot of work that ended up costing us time and money and literally nothing changed because we were already making sure we protected our users privacy.

Hopefully some bad actors get hit but for now GDPR has left a bad impression on me.

Re: Google and Facebook accused of breaking GDPR laws

#228

Earlier quoted context omitted.

It's Google's terms, and Google is the one who determined the mandatory flow of that setup as per agreement with the hardware vendor. The EU could absolutely hold them responsible for not having this sorted out with their partners, it isn't like the OEM put the terms on a device and sold it without Google's permission.

But the OEM is responsible for software support for their devices (this is the entire Android model and why Google has been working so hard on the Treble project the past year+). Since the current version of Android doesn't have this problem, I don't see how this is Google's problem.

It's Google's terms for an agreement with Google. How could any reasonable person make the claim it is not Google's problem? Especially considering they had two years to prepare, and 2018 phones still have this problem.

Presumably, if moderately recent phones were compliant, Google could ensure that outdated/invalid consent forms were only tentatively accepted until Play Services updated within the first day or so of activation, and then presented a remedial consent form which was GDPR compliant. The EU would very likely accept this solution as a technical best effort method to ensure older devices were respecting people's rights.

But it sounds like they never really put in the effort. What version of Android is GDPR compliant? 8.1?

Re: Google and Facebook accused of breaking GDPR laws

#229
post #88

Earlier quoted context omitted.

Nope thats actually true. You cant force say tracking, if its not absolutely needed, for the product to work. And i think thats why a lot of the popups have dark patterns, to hide the fact, that you can no opt out to these things.

Hmm, seems you are right, I just found this PDF from the ICO: https://ico.org.uk/media/about-the-ico/consultations/2013551... "Avoid making consent a precondition of a service" "consent requests must be separate from other terms and conditions. Consent should not be a precondition of signing up to a service unless necessary for that service" I assume Facebook et al will simply find a way to make everything 'necessary…

For consent this is true, but there are other legal ways for you to collect the data. One is legitimate interest, this one is more abstract but requires a bit more work from you.

I think a lot of the future court cases will be around trying what one can use legitimate interest for.

https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: Google and Facebook accused of breaking GDPR laws

#230
post #204

Earlier quoted context omitted.

Is an IP address PII or not? I have read multiple different interpretations today. Is a hash of an IP address PII?

Is this really that complex? If it can be linked to the individual, then it is. https://www.whitecase.com/publications/alert/court-confirms-...

So IP + timestamp of my ticket system logs is invalid because I also have a timestamp of ticket updates by a user. Actually, just IP because I have a timestamp on the log file. So the latest line has an IP, so I can take the file timestamp and see the latest ticket comment and now I've linked it to an individual. You're right, this is easy. Even easier now that I can't think of a way of storing an IP without the ability to at least correlate the latest one.
Post reply on HN