Live data from Hacker News

Facebook to move UK users to California terms, avoiding EU privacy rules

reuters.com

431–440 of 506 posts

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#431
post #331

Earlier quoted context omitted.

They've been failing to even issue fines, let alone enforce them. Both for competence reasons (see also: the collapse of the AIQ enforcement, and the climb-downs in Mariot and BA cases) and for... I don't know why in the adtech case. The ICO has evidence of wide-scale criminal behaviour in the adtech industry. And yet they flat-out refuse to take enforcement action . They're even proud of the fact they're refusing to…

They did, however, appear to do a good job with the recent Experian and Equifax enforcement.

Are you talking about this case: https://ico.org.uk/about-the-ico/news-and-events/news-and-bl... ?

If so, we seem to have a major disagreement about the definition of a "good job". The ICO, by its own admission, found that:

> The investigation found how the three CRAs were trading, enriching and enhancing people’s personal data without their knowledge. This processing resulted in products which were used by commercial organisations, political parties or charities to find new customers, identify the people most likely to be able to afford goods and services, and build profiles about people.

> The ICO found that significant ‘invisible’ processing took place, likely affecting millions of adults in the UK. It is ‘invisible’ because the individual is not aware that the organisation is collecting and using their personal data. This is against data protection law.

The ICO was clearly aware that a large-scale GDPR breach was being committed for profit for several years by a large company who should know better (and has the resources to comply should they want to), and the best they could muster is an "enforcement notice" as opposed to a fine?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#432
post #64

Earlier quoted context omitted.

Citizenship matters not. Only residency. Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.

Okay, what does it mean “residency”? In the UK there’s no address registry where you declare your address. EU citizen works in the UK for 2 years then goes to Turkey for a vacation but likes the place so much, decides to stay for longer when still remote working for the same London company.Also connects through VPN because the Turks love banning websites. Where this person residence is? Are the UK, USA, EU or Turkish…

> In the UK there’s no address registry where you declare your address

Can you vote in Glasgow's local elections if you live in Manchester?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#433
post #429

Earlier quoted context omitted.

Hope so. In general I’m a fan of GDPR but I’d be glad to see this one go

For what it's worth those cookie popups are actually from the EU e-privacy directive (which is implemented as PECR in the UK), so they aren't because of GDPR.

I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR. When you browse from outside the UK, the sites don’t have the consent forms.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#434
post #406

Sort of related, does anyone know if all the consent form popups will stop once the UK leaves the EU?

If you mean cookie banners then no, they won't stop. UK data protections laws are going to be almost entirely unchanged come 1st Jan. Having said that this doesn't mean there will be no practical effects, as our status with regards to other EEA countries is changing so data transfer between EEA and the UK is affected. It also seems likely that UK data protection laws will start to diverge from EU data protection laws over time, though what this might look like in practice is anyones guess.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#435

This is the balkanization of the internet. We've lived through a brief period of free exchange among peoples, but it's soon over. I predict only one viable future for all technology companies, big and small: Pick a single national jurisdiction, keep your employees and servers inside it.

This should also a taster for people living in the UK (including me) on what will happen to our rights under a sovereign state after an apocalyptic Brexit. Not politicising this conversation, just seing what is to come outside of the EU and with the struggle that is coming head on. First they gave our FB data to the americans, next they went for our NHS! :) ps1: I don't use FB ps2: I got nothing against the americans…

This is just so true, and so depressing. We need to fight for standards internally now.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#436
post #433
post #429

Earlier quoted context omitted.

For what it's worth those cookie popups are actually from the EU e-privacy directive (which is implemented as PECR in the UK), so they aren't because of GDPR.

I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR. When you browse from outside the UK, the sites don’t have the consent forms.

> I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR.

If they're asking about cookies for GDPR then that's a mistake on the part of those sites. You can read about the details of PECR here https://ico.org.uk/for-organisations/guide-to-pecr/what-are-...

Of course under GDPR they may need to get permission for other forms of data processing (signing you up to a marketing mailing list, for example), but the rash of cookie permissions banners are because of PECR and similar legislation in other EU countries.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#437
post #436
post #433

Earlier quoted context omitted.

I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR. When you browse from outside the UK, the sites don’t have the consent forms.

> I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR. If they're asking about cookies for GDPR then that's a mistake on the part of those sites. You can read about the details of PECR here https://ico.org.uk/for-organisations/guide-to-pecr/what-are-... Of course under GDPR they may need to get permission for other forms of data processing (sig…

So the only way to not have consent forms is to browse from outside the UK & EU?

It’s getting more and more difficult to have a good experience browsing the web. That worries me.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#438

Earlier quoted context omitted.

It would be odd to see the Information Commissioner (the UK's data protection regulator) as toothless, given it has so far been among the most severe in penalising large businesses under the much greater powers it acquired under the GDPR. This could be more of a strategic move from Facebook, anticipating the UK government wanting a quick post-Brexit trade deal with the US and having limited practical room to manoeuvr…

It would be odd to see the Information Commissioner (the UK's data protection regulator) as toothless Given that the maximum penalty it can levy is £20m, it is completely toothless against any major corporation. BA got off with a slapped wrist after their fiasco. The GDPR looks good on paper but where exactly are these 4% of global turnover fines it was supposed to make happen?

I think you have misunderstood how the maximum penalties work under the GDPR.

In any case, it makes sense that those maximums would be used only in the most serious cases of wilful violations. I wonder whether internally at the ICO they might be waiting for a chance to make an example of one of the tech giants whose whole business model, unlike the organisations penalised so far, is based on exploiting personal data in questionable ways.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#439
post #433
post #429

Earlier quoted context omitted.

For what it's worth those cookie popups are actually from the EU e-privacy directive (which is implemented as PECR in the UK), so they aren't because of GDPR.

I don’t know, seems to me that most of the sites I see them in are US sites that say they have to get consent because of GDPR. When you browse from outside the UK, the sites don’t have the consent forms.

Consent is not required for "essential" cookies, because they are essential. Things like keeping track of your logged in state or shopping cart. (Even if consent were required for that, it should be asked at the point where you login or add the first item).

For advertising and behavioural tracking cookies, consent is required if it's tracking your personal data to the level of individually identifiable people, but frankly they shouldn't be doing that.

I've personally implemented websites in the EU with logging in, carts and analytical tracking that didn't require up-front consent popups because their behaviour was already reasonable and therefore compliant.

Some of us believe that the bigger sites deliberately use obnoxious consent forms in order to encourage USA residents to remain politically in favour of "implied consent" to individual behaviour tracking. In other words, obnoxious on purpose to give the impression the EU system is more onerous to each user than it really has to be.

After the UK leaves the EU I will do my browsing via a VPN through an EU country specifically because I want to be able to deny all such consents except to sites that I trust and support. (In practice I grant consent to about 10% of sites and deny the other 90%).

If I can find a browser extension to automate denying consent that would be great, but if I can't then I'll do it manually.

The thought of my consent to being tracked down to the level of individual, personal detailed behaviour being "implied consent" the USA way is horrible. I do not consent, full stop. It seems an affront to basic legal principles that the norm is for people to not be told about or therefore have the opportunity for informed consent to the detailed databases built up about their every action online, similar to credit files but much more detailed and secretive.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#440
post #295

Earlier quoted context omitted.

For most law sure. But for GDPR the EU explicitly extended it's protection to all EU citizen regardless of residency, and non EU citizen with residency in the EU. Now there's the practical question of how the EU enforces that protection against companies that have no presence in the EU, but those that do, the EU has made it quite clear they'll take enforcement action.

Citizenship and residency (of data subjects) doesn't come in to the GDPR at all. If the data controller/processor is in the EU, the GDPR applies. If the data subject is physically located in the EU (even if not a citizen or resident) then the GDPR applies.

One minor correction:

If the data subject is physically located in the EU (even if not a citizen or resident) and the data controller purposefully targets data subjects in the union, the GDPR applies.

As per [0]:

the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention

[0] https://gdpr.eu/Recital-23-Applicable-to-processors-not-esta...

Post reply on HN