Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

131–140 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#131

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

They have a lot of users and GDPR is really tricky to implement when dealing with any manual processes. Though they have a lot of users in the EU (population 700M), it seems that once they figure out how to do it for their 250M (?) EU users, expanding it to 2B users is not a huge stretch.

My point is that I don't think they have it figured out ;-) (and they have just over a month left!) I agree that once they get it sorted (which they will have to do), they will almost certainly roll out the majority of it world wide just because it is easier.

Re: Facebook to change user terms, limiting effect of EU privacy law

#132

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

They have a lot of users and GDPR is really tricky to implement when dealing with any manual processes. Though they have a lot of users in the EU (population 700M), it seems that once they figure out how to do it for their 250M (?) EU users, expanding it to 2B users is not a huge stretch.

It's not hard to do, but it limits a lot of stuff that their business is built on. So implementing it world-wide could have a negative business impact and will definitely impact the stock price in the short term.

Re: Facebook to change user terms, limiting effect of EU privacy law

#133
post #85

> But the fact that the button to reject the new Terms of Service isn’t even a button, it’s a tiny “see your options” hyperlink, shows how badly Facebook wants to avoid you closing your account. > When Facebook’s product designer for the GDPR flow was asked if she thought this hyperlink was the best way to present the alternative to the big “I Accept” button, she disingenuously said yes, eliciting scoffs from the roo…

> I wonder if I could live with myself if this was my job. You are in the company, you have a job to do, everybody else is doing it. Other people share your concerns, but in the end, you have a feature to deliver and you don't want to fail your team. Some people is really concerned, they try to change things, they quit, they are tired of the pressure of going against the managers and making it more difficult for thei…

Perhaps the thought of the next job interview could help them grow a moral spine?

Re: Facebook to change user terms, limiting effect of EU privacy law

#134
post #85

Earlier quoted context omitted.

> I wonder if I could live with myself if this was my job. You are in the company, you have a job to do, everybody else is doing it. Other people share your concerns, but in the end, you have a feature to deliver and you don't want to fail your team. Some people is really concerned, they try to change things, they quit, they are tired of the pressure of going against the managers and making it more difficult for thei…

Perhaps the thought of the next job interview could help them grow a moral spine?

Have your interviews focused on personal morality, or on getting the job done?

Re: Facebook to change user terms, limiting effect of EU privacy law

#135
post #41

Earlier quoted context omitted.

Website terms and conditions could ask for a pint of blood from their firstborn and people would still click okay. No one reads these things. The GDPR is just going to end up being a more annoying version of the cookie law.

I'd be interested if you could ask your users if they are _not_ a EU resident. Only if they click yes go ahead, otherwise show that you will not serve them. Probably 90% would learn to click the "Not from EU" button. Who should hold you accountable for false user input in that case?

In the case of Facebook, people people upload photos with gps data, attend events that have an address... No judge would accept the 'but they said they weren't a EU resident' argument.

Re: Facebook to change user terms, limiting effect of EU privacy law

#136
post #109

Earlier quoted context omitted.

Data collection for security and intelligence purposes by governments is exempt from GDPR rules, I think.

No it's bloody not.

Article 2d "This Regulation does not apply to the processing of personal data: [...] by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security." exempts data collection by gov't for security purposes.

Article 6.1c "Processing shall be lawful only if and to the extent that at least one of the following applies: [...] c) processing is necessary for compliance with a legal obligation to which the controller is subject;" exempts data collection by private parties if ordered by gov't, e.g. if they require communications operators to track subscriber identities or something else, then GDPR consent requirements don't apply.

So I'd say that it's materially true that "Data collection for security and intelligence purposes by governments is exempt from GDPR rules", as long as governments are doing this data collection according to whatever other laws they have passed and not in violation of them (which sometimes has been the case, though, with executive branch doing what legislative branch has forbidden them).

Re: Facebook to change user terms, limiting effect of EU privacy law

#137
post #85

Earlier quoted context omitted.

> I wonder if I could live with myself if this was my job. You are in the company, you have a job to do, everybody else is doing it. Other people share your concerns, but in the end, you have a feature to deliver and you don't want to fail your team. Some people is really concerned, they try to change things, they quit, they are tired of the pressure of going against the managers and making it more difficult for thei…

I guess they're "just following orders"...

Doesn't apply. If you resign from your job, you stop being paid. If you try and resign from the Armed Forces, you're put in prison at best.

Re: Facebook to change user terms, limiting effect of EU privacy law

#138

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

> I just can't imagine they are prepared

It sure seems that way and I find it amazing. It has been known for a long time that the GDPR will come into effect in May. Maybe they thought they could lobby it away?

Re: Facebook to change user terms, limiting effect of EU privacy law

#139

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR.

The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater. Again, this applies to US companies even if it's a single record of EU personal data.

Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person.

As to the question of EU law applying in the US, just look to financial regulation like Sarbanes–Oxley to see it going the other way.

Re: Facebook to change user terms, limiting effect of EU privacy law

#140

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

> If you just say, "Oh I have consent" then the user can withdraw consent. If you actually needed that information (like the user's name!) then you are absolutely screwed.

Well, only screwed if they want to keep their account? I can assume that resulting in Facebook closing down your account.

All in all, I doubt millions of people will request data under the GDPR. But I guess the fines are significant enough to worry about it.

Post reply on HN