Live data from Hacker News

Red flags in the Threads privacy policy

qz.com

161–170 of 263 posts

Re: Red flags in the Threads privacy policy

#161
post #142

Earlier quoted context omitted.

> Seriously though, GDPR compliance isn’t that hard Unless compiling data on your users and selling it is your entire business plan. One of the issue I see it that many companies have been lured into this impression that they need to track everything, in great detail, but it doesn't actually provide that much value. I blame the snake oil sales people in the advertising/remarketing/up-selling/cross-selling business.

This is correct. So many websites don’t actually need to collect any user data. It’s just a distraction, slows down and bloats their site and worsens UX. I recommend to simply get rid of any tracking. If you want user feedback, ask them or do tests. It’s cheaper and more effective.

So many websites don’t actually need to collect any user data.

Any commercial organisation is going to have customers and therefore customer details and payments data.

Any commercial site needs to record enough logs to investigate events like outages or security threats.

Any site that isn't purely informational and read-only probably works with user-provided data in some way.

People keep writing about GDPR and similar laws as if they only apply to data-harvesting analytics plugins on ad-ridden content farms but the same laws apply to everyone else as well. For many it will be reasonable and indeed necessary to process personal data in order to do whatever the site or app does.

Re: Red flags in the Threads privacy policy

#162

Earlier quoted context omitted.

People keep saying this and yet it’s never happened despite the GDPR being in place for 5 years now. As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant. Even when I worked for a company that did need to collect customer information, we pretty well understood what we could and couldn’t do under GDPR. This whole “GDPR is dangerous” meme needs to die because businesses a…

> As a tech manager for an EU company, I can honestly say that it isn’t that hard to be GDPR compliant It's pretty easy for a business to be GDPR compliant unless their business model or processes in some way involve collecting and processing or selling personal data of their users. Before GDPR a lot of businesses used this as a nice little second income stream, or just grew used to being able to freely analyze every…

That looks to me as though the system is working exactly as intended. When I do business with company 'A' I do not expect or consent to them passing that data on to company 'B'.

Re: Red flags in the Threads privacy policy

#164
post #62
post #53

Earlier quoted context omitted.

Right to be forgotten has some really nasty edge csaes.

If your app doesn't easily support redaction of personal data, you have a design flaw to fix.

How are you going to "fix" that "design flaw" when the personal data in question is the result of legally required customer age checks? Evidence needed to support your tax filings? Used to identify and block people who are repeatedly trying to defraud you or breach your security? Subject to a legal hold because it might provide relevant evidence in some legal action between other parties or it's been requested as evidence by some government committee?

Data protection laws like the GDPR might take the position that you should minimise the collection and use of personal data. Many of us might even agree with that position in principle. It can still be complicated to work out what "minimal" actually means if you did have good reasons to collect the personal data in the first place and you might still need to keep the data or some part of it for those purposes or to comply with other laws or regulations.

Re: Red flags in the Threads privacy policy

#165

Earlier quoted context omitted.

100% agree with this and the other post, the biggest red flag is "Meta". Whoever thought something good and user-first would come out of this wannabe Twitter killer is completely naive. I expect that federation won't last and there's 2 things that can happen, either Meta decides it's not worth it, or they will find a way to draw out most of federated users and then deal a killing blow to the fediverse. I was skeptica…

For me the biggest red flag is that they have apps in the EU but what they're doing with this one is so dodgy that they're not even risking entering the EU. Also, interesting to see a big international company actually back up their "we just won't do europe then"

> interesting to see a big international company actually back up their "we just won't do europe then"

that's the most interesting things to me. Whether:

1- Threads is dead in the water

2- They figure it out and makes the EU happy

3- EU is irrelevant enough to be ignored

2- still looks like the most likely 1- would be very embarrassing and 3- would be, indeed, an "interesting" development.

Re: Red flags in the Threads privacy policy

#166
post #92

Earlier quoted context omitted.

- Payments, particularly from P2P transactions. If I send you money, and then you request the deletion of your profile, there's plenty of complexity there. - Enforcement records from illegal content / violating content - Local data cache for offline mode in mobile apps I'm not saying all of these apply to "Threads". But there are tons of edge cases to consider that need code changes t o behave as expected.

> Payments There's really no complexity there. The right to be forgotten doesn't superseed other laws, and it is required by law in most countries, that transaction data be stored for 5 years plus running year, so in case you request to be forgotten, that can only happen once the mandatory data retainment has expired, which can easily be handled by a "transaction date", and simply run a batch job that matches each us…

There's a lot more to payments than raw transaction data. Payments are usually related to the exchange of goods or services. The delivery data of those could be essential for winning a chargeback dispute or a liability for a customer that asked to be forgotten.

Re: Red flags in the Threads privacy policy

#167
post #62

Earlier quoted context omitted.

If your app doesn't easily support redaction of personal data, you have a design flaw to fix.

How are you going to "fix" that "design flaw" when the personal data in question is the result of legally required customer age checks? Evidence needed to support your tax filings? Used to identify and block people who are repeatedly trying to defraud you or breach your security? Subject to a legal hold because it might provide relevant evidence in some legal action between other parties or it's been requested as evi…

I don't know where your actual problem is. The GDPR allows holding data for most of these purposes. You intermingled legal obligations with data legal departments would like to hold in the end there. Only one of those is required.

Also, some of these are pure theoretical in the EU. You're not even allowed to photocopy an ID in Germany; age verification is a checkmark someone sets upon verifying the ID is valid and then (metaphorically) handing it back, not a copy of a legal document that you probably don't want deduplicated to random S3 buckets held by all the companies you do business with. They're not exactly resistant to replay attacks, after all.

Re: Red flags in the Threads privacy policy

#168
post #103

Earlier quoted context omitted.

I think GDPR is pretty clear there. That companies like Facebook push fancy theories of what is and isn't legitimate interest is not the fault of the law. People will always try to push the limits to see what they can get away with, esp. when there is money to be made. That doesn't mean it will fly - like Facebook has just discovered (and others before them). Law cannot enumerate every single possible existing and fu…

There are ways to make this problem less bad though. You have your permissive case and then write a number of examples into the law that show what you do not consider allowed and invite future courts to consider them. Pre-emptive case law (which is a lot cheaper than actual case law), if you will.

It is interesting which special cases are explicitly noted in the GDPR (credit scoring for instance) and which classes of data are specially protected (political alignment, medical data) - and where the lobbying shines through by omission.

Re: Red flags in the Threads privacy policy

#169

Tbh if you are concerned about the privacy and ethics concerns here the biggest red flag is in the subtitle: Meta's Twitter rival launched in over 100 countries today—but not in the EU Anything more is simply detail - if a major launch of this sort of service omits the EU we immediately know exactly why.

Don't jump to conclusions. They're likely not launching in EU because EU requires user data be stored in EU, and their current launch stack is hosted elsewhere, look at this datacenter map of Meta: https://datacenters.atmeta.com/ They're mostly in the US, and most outside the EU. Given the record timeline from concept to launch for this app, it's normal they can't whip up a datacenter from nothing overnight.

GDPR require equivalent protections, not to store data in the EU.

Re: Red flags in the Threads privacy policy

#170

Earlier quoted context omitted.

any of us could've written something like that when young

you think zuck changed his mind on this?

On the contrary - this quote has stood the test of time. If you are trusting zuck in 2023 then you really are a DF
Post reply on HN