Live data from Hacker News

Facebook to move UK users to California terms, avoiding EU privacy rules

reuters.com

191–200 of 506 posts

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#192

Earlier quoted context omitted.

The closest thing to this currently is Mastodon. https://www.theverge.com/2019/7/12/20691957/mastodon-decentr... There are a lot of open hard technology and business problems to make decentralized systems act as good as centralized systems. In short, The web architecture (HTTP, HTML, URI, MIME) inherently is decentralized for consumption but encourages centralized updates. Many years ago I wrote about these technical…

Mastodon, does not operate above the ability of a nation state to block Mastodon. At the info tech department of a large flagship university recently, (and for reasons that are a bit salacious), there was a need to block mastodon servers on campus and some coming from off campus. It was almost as easy as the flip of a switch to turn it off. If a university can do it on their network, it's a virtual certainty that a n…

Did this university ban the use of Tor?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#193
post #177

Earlier quoted context omitted.

gpdr on the other hand is tough to enforce on companies who wholly are in the US. from a sovereign perspective the EU can pound sand when telling Americans how to treat people in their own land. The only reason the EU is able to get away with this to a degree is the american governments wish cooperation to a point and our treaties. However, I suspect america will only tolerate so much push from the EU.

> gpdr on the other hand is tough to enforce on companies who wholly are in the US. If you do actual business in the EU they can block financial transactions, and if you don't do business in the EU, there isn't really any incentive to (ab)use the data GDPR covers?

Yup that's the idea, the EU is a big market and GDPR is the cost of doing business there.

As a startup though, it's absolutely part of your calculus. If you are worried about GDPR compliance, you can choose to just not launch in the EU (actually that might not be enough, I believe you may need to actively refuse EU users) until after you've proven the concept. Although with California's CCPA, depending on the specifics of your situation, you may as well just carve out some time to deal with compliance.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#194

Earlier quoted context omitted.

That’s the political pitch. It’s really just the EU trying to challenge the economic dominance of US tech companies. Tariffs and trade barriers are unpopular, and people who implement them are supposedly very bad. But privacy regulation and huge fines for big tech are very popular, and the people who implement them are supposedly very good. When people see the fines given out I think they presume the regulations are…

Requirements that data must be handled in a certain way is akin to requirements that electronics have no lead in them and that cars emit only a certain amount of toxic fumes and that cattle aren't addled with too much HGH. If you see no value in the regulations then you might see it as you have. But in reality the regulations are valuable and that is why you see the different reactions.

This comment is based on an assumption that the regulation actually achieved beneficial privacy outcomes. It’s arguable been most successful in Access to Data area, and to some extend Data Erasure. But the Consent and Documentation provisions are a complete joke. Most EU data subjects have no idea who’s holding their data, or how/why they have access to it.

The only area it’s been truly successful in has been levying fines against foreign companies and restricting access to the EU market. It’s a very successful piece of tariff legislation. Because the compliance strategy from most organizations was either stop trading in the EU, or accept the fines as a cost of business. (edit: there's also a 3rd common compliance strategy, which is just to pretend that since you're not specifically targeting EU data subjects, that you don't have to comply. I believe this is part of the reason that HN ignores the GDPR for instance)

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#195

Earlier quoted context omitted.

Yes, that's also my understanding, but EU GDPR refers to data being inside and outside the territory of the EU. So, transferring your data between the EU and UK will mean you are (now) crossing a data border. That's a change. I understand that GDPR will immediately split into EU GDPR, and UK GDPR.

Yeah, but have UK privacy laws been updated to reflect fact the UK is no longer part of the EU? Something I've seen in lots of UK law derived from EU directives is that it applies limits to behaviour specifically happening in the EU. So UK privacy law might provide a whole load of protections to EU citizens, but not specifically to UK citizens, because EU citizens would be a superset including UK citizen. Except, as…

They must have had some work done on figuring out which legislation needs updates like this?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#196

This is the balkanization of the internet. We've lived through a brief period of free exchange among peoples, but it's soon over. I predict only one viable future for all technology companies, big and small: Pick a single national jurisdiction, keep your employees and servers inside it.

It’s more like de-globalization, which could very well be a good thing given the multitudes of problems that have arisen out of globalization.

Living in a country where a global total war and several occupations of the most evil totalitarian regimes in history is still within living memory, and having been under an isolationist totalitarian power, comments like these make me shudder.

Globalization has some problems. The benefits so far have massively outweighed them, especially if you take the long view. How about we try to fix those faults, instead of retreating and isolating?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#197

Earlier quoted context omitted.

GDPR is generally based on where the data is located That is not correct. Specifically, the counterexample is if you are a EU citizen living in an EU country and the actual bits are stored in a datacenter in Texas. GDPR still applies in this case, as long as the website owner accepts EU users. If the website specifically doesn't do business in the EU, things are different.

Ah, apologies, you're right to pick that up, it's not quite what I meant. Maybe "where the data originates" is better? Since the data originates where you are, the data has crossed a border to get to Texas and is therefore subject to GDPR (extra-territorially), I agree. If you were in Texas when that data was collected from you, and you returned to the EU, I doubt that GDPR would apply to that data.

If you were in Texas when that data was collected from you, and you returned to the EU, I doubt that GDPR would apply to that data.

I believe that is still covered by GDPR, but I'll openly admit that I specifically chose the counterexample in order to stay within my factual memory of the law.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#198
post #46
post #25

How these rules apply for people with multiple citizenships and residence? That’s the case with a lot of people in Europe. How to find out to which jurisdiction my FB data is bound to?

It’s not about citizenship but where you live. In place A the rules of place A apply. If place A is part of the EU, EU laws apply.

Incorrect. With GDPR the EU extended their power to protect all EU citizens regardless of residency in, or out, of the EU.

Of course the EU will have trouble enforcing that protection against companies that don't operate in the EU. But the protection remains, even if it's practically unenforceable.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#200
post #78

Earlier quoted context omitted.

Citizenship matters not. Only residency. Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.

The US tax authorities disagree.

[deleted]
Post reply on HN