Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

261–270 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#261
post #65

Earlier quoted context omitted.

The data belongs to the user. There's nothing Facebook can do to prevent exporting if it's via the data backup. They can just design it in a way that is easy to read by humans but very challenging for parsers.

I don't understand how a facebook post made by me 'belongs' to me. It was addressed to specific audience that facebook made available to me, it wouldn't have existed in the first place if facebook didn't exist. How does it completely belong to me.

If you make a song on a Gibson guitar, should the song belong to Gibson?

Re: Google and Facebook accused of breaking GDPR laws

#262

Earlier quoted context omitted.

You were probably downvoted for your the absoluteness of your statement. For instance, you do not have more rights as a European business owner. Even as just a user, you have fewer rights to enter agreements now with these tech companies free from government involvement. What you may call rights, others call restrictions and limitations of rights.

Agreed. As an American, reading the term rights associated with increased government control is nonsensical. I understand the European viewpoint, its just much different in America

This is actually very interesting. It seems to me that many Americans really don't care how their personal data are (ab)used and will happily agree to absurd ToS-es without complaining. In Europe, we have quite different culture of doing things. And yes, the misnomed "right to be forgotten", i.e. the ability to remove my own personal data from a website, is an important right. Not being tracked is an important right. Not being profiled - ditto. It's really shocking to me that the narrative in the USA is that GDPR is evil, whereas many people in Europe consider it a very positive development, in spite of additional work that needs to be done.

Re: Google and Facebook accused of breaking GDPR laws

#263
post #186
post #124

Earlier quoted context omitted.

So you are stipulating an account worth is 240USD a year at facebook? Instead of 20, why won't you say 100, make it round. Seriously though, behemoths do fall and if facebook ceases to exist there will be no harm but good in my book.

The number that's been kicked around for he value of North American user is about $50/year. So $5/month will cover it.

That's not the number that is being kicked around.

Facebook will yield more than $100 per active user in the US and Canada for fiscal 2018. That's going to $200 from here over the next six or seven years (it doubled from 2015 to 2017). No meaningful number of users are paying $15 per month out of pocket for Facebook.

Google search is similarly worth a lot per user in the US. People would be irate if they had to pay $10 or $20 per month to use search engines after commonly enjoying the free utility of that for the last two decades.

Re: Google and Facebook accused of breaking GDPR laws

#264

Earlier quoted context omitted.

So IP + timestamp of my ticket system logs is invalid because I also have a timestamp of ticket updates by a user. Actually, just IP because I have a timestamp on the log file. So the latest line has an IP, so I can take the file timestamp and see the latest ticket comment and now I've linked it to an individual. You're right, this is easy. Even easier now that I can't think of a way of storing an IP without the abil…

> So IP + timestamp of my ticket system logs is invalid What makes it "invalid"? If you can identify a person by their IP, then the IP becomes a part of their personal data. For most websites it's irrelevant, because people just visit and leave. But if someone signs in with their real name, you just need to update the ToS saying that apart from their other data you also store their IP. How complicated is that?

Ok, just update the ToS. No ability needed to provide opt out of that IP collection? No ability needed to go, upon request, and delete all these IP+timestamp logs that I could use to correlate with their name? Handwaving all of this stuff away as clear and easy is at the least ignorant to real people's concerns and at most willfully dishonest.

Re: Google and Facebook accused of breaking GDPR laws

#265

Earlier quoted context omitted.

In that point of view, it seems a rather unfair complaint It is an unfair complaint. But to be fair to the regulators, these complaints were filed by users , and may well be dismissed once reviewed by regulators. This type of unfair complaint will be an interesting test to see just how abusive the GDPR enforcers may or may not be.

The real test is how Google behaves. Google shouldn't be collecting data from users who agreed to share their data based on outdated ToS that are no longer legally valid. They should ask for agreement to new GDPR-compliant terms just as they do for users who agreed to the old terms before GDPR was law.

Why do you think that previous ToS was outdated and no longer legally valid? Why do you think consent given x years earlyer would not be valid?

Re: Google and Facebook accused of breaking GDPR laws

#267

Earlier quoted context omitted.

Agreed. As an American, reading the term rights associated with increased government control is nonsensical. I understand the European viewpoint, its just much different in America

This is actually very interesting. It seems to me that many Americans really don't care how their personal data are (ab)used and will happily agree to absurd ToS-es without complaining. In Europe, we have quite different culture of doing things. And yes, the misnomed "right to be forgotten", i.e. the ability to remove my own personal data from a website, is an important right. Not being tracked is an important right.…

Americans for the most part hates being told what to do by the government. For me, I hate it because government intervention tends to cripple economic growth. I value economic growth > social welfare (used in the non derogatory way, in America "welfare" has an immediate negative connotation). I am also aware of this and can understand why other cultures would reverse that equation

Re: Google and Facebook accused of breaking GDPR laws

#268

Earlier quoted context omitted.

Agreed. As an American, reading the term rights associated with increased government control is nonsensical. I understand the European viewpoint, its just much different in America

This is actually very interesting. It seems to me that many Americans really don't care how their personal data are (ab)used and will happily agree to absurd ToS-es without complaining. In Europe, we have quite different culture of doing things. And yes, the misnomed "right to be forgotten", i.e. the ability to remove my own personal data from a website, is an important right. Not being tracked is an important right.…

Put simply: Americans prefer corporate overreach to government overreach. The latter is seen as only needed in extreme circumstances because there is often no going back. It's why you see hate for things like the cloud act and GDPR... it doesn't matter where they are enacted, some people don't want the government involved on these things at this point.

Re: Google and Facebook accused of breaking GDPR laws

#269

I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…

Google and the manufacturer had 2 years to ensure this wouldn't be an issue.

Re: Google and Facebook accused of breaking GDPR laws

#270
post #205

Earlier quoted context omitted.

Again, let's read the text. "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create…

So truncating logs is an overreaction? There is no need to do that for GDPR? I see many people saying the opposite.

It's not strictly necessary but it's a good idea anyway, even outside of GDPR. The key question is, what kind of processing are you doing on the logs? If you're using it to build user profiles that needs careful consideration. You should also think about whether the URL in a web log contains personal data that affects that: if you know that 192.168.100.blah has accessed "/logged-in-user/joe-bloggs", then that IP address may now be personal data.
Post reply on HN