Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

151–160 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#151

Earlier quoted context omitted.

"our companies"? Facebook isn't only a US company. Facebook Ltd is a UK company and they have many more companies around the world. If you want to operate in UK and generate revenues there then Facebook Ltd must follow UK laws.

GDPR is more overeaching than that. You don’t need physical presence in EU to be subject to it. In theory, just having a webserver storing access logs (default of Apache and Nginx) makes you infringing it as EU IPs are now considered personal data.

> just having a webserver storing access logs (default of Apache and Nginx) makes you infringing it as EU IPs are now considered personal data.

That's not true. Read the 23rd point right at the top: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Here's the part of it that covers your webserver: "Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, [...]".

Re: Facebook urged to make GDPR its “baseline standard” globally

#152

There's been so many articles about Facebook and the recent privacy catastrophe that I'm finding it hard to keep up. Does anybody actually know what their response will be to the GDPR? Are the privacy benefits from the GDPR going to be exclusive to EU citizens? This seems problematic. Whatever happens, Facebook has irreparably damaged my trust in their handling of user data and I think many on here would agree. My wi…

EU residents, not citizens. It's an important distinction.

Woah, that would mean e-Residency in Estonia would be enough for GDPR protections, right?

https://e-resident.gov.ee

Note that becoming one involves going to your embassy in person.

Re: Facebook urged to make GDPR its “baseline standard” globally

#153
post #140

Earlier quoted context omitted.

Honestly, those questions should be pretty easy to answer especially if your company is small. If as a business you can’t answer these basic questions about the data you want to collect from me, I’m going to be hesitant to share it. People keep sharing that “nightmare letter” link but won’t point out which question gives them nightmares and why.

I'll point out which question gives me nightmares, as the founder of a EU startup: - the requirement to have a DPO. Based on the requirements for the DPO, no one in the company can fill the role (conflict of interest), so we must hire an employee or consultant (expensive either way for a small startup) - one month to respond. That's a lot of informations to collect the first time, and I might have other fires to put…

thanks for this. so what's your advice for a social startup building a new platform in today's data-privacy concerned world?

Re: Facebook urged to make GDPR its “baseline standard” globally

#154

Earlier quoted context omitted.

A lot of people don’t care about fire safety either (until their house is burning down) which is why we have regulations, building codes, mandatory sprinklers in offices, etc. I am starting to look at privacy like it should be treated as a public safety concern, since it’s invisible to people until it’s not.

can social media kill you though? I mean all this talk of regulating social networks is under the assumption that it's something you need to have. I would argue that safe shelter is a true human need, but posting cat gifs or pictures of drunken escapades or political musings does not seem equally comparable and thus I do not see how regulation does anything other than hamper competition.

> can social media kill you though?

Yeah, it can and it did. Not only did the Ashley Madison leak led to a few deaths, check out what happens in countries where homosexuality is punished by death when private information goes public...

Re: Facebook urged to make GDPR its “baseline standard” globally

#155

Earlier quoted context omitted.

No. Google should rank the "Suspect found NOT GUILTY of murder" as the top, most relevant page, because that is truly the most relevant. If Google refuses to rank this the top, it's out of sheer laziness, just like how they refused to fix the subversive content in Youtube Kids "because algorithms". If they did this in the first place, I think most people wouldn't care so much.

You say "should". Who guarantees that? News outlets are for profit organizations. If they judge "not guilty" as something that doesn't sell as well as "guilty" then they won't publish so much content about it, and because of Google's algorithm that latter won't be ranked very high. Even if it's ranked high, a lot of readers would still end up with this feeling that "yeah the latest news article say that but MAYBE tha…

I think we are in agreement. Google needs to change their AI/algorithms so that the more important, relevant aspect of every story increases in rank. Not the flashy click-baity articles.

Re: Facebook urged to make GDPR its “baseline standard” globally

#156
post #108

Earlier quoted context omitted.

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> The amount of blaming the nurse for your fever on those issues is getting really concerning. The nurse is being blamed because they've ignored clear, worsening symptoms for years.

Staying with this analogy: The nurse also has a near monopoly on providing targeted care and it sure appears that (s)he knowingly or negligently assisted the spread of the fever causing pathogen. Then, leveraging her unique familiarity of the illness, (s)he made ~$500B selling a targeted care plan.

Re: Facebook urged to make GDPR its “baseline standard” globally

#157
post #100

"[any big US tech companies] Urged to Adopt GDPR Globally as a Standard" As an European living abroad, I still have no idea if I will be protected by the GDPR. I read at least 2 opposite answers on HN on the last days: "yes because you are a EU citizen", "no because it's where you are when the data are collected that matters".

Check out Article 3 of GDPR, "Territorial Scope", for some guidance on that: https://gdpr-info.eu/art-3-gdpr/

I read it and I am still confused.

Does "in the Union" mean within the geographic borders of EU states?

Does "established" mean having a physical presence? Having been incorporated? Registered with a regulatory body? Having remote employees who live there?

Re: Facebook urged to make GDPR its “baseline standard” globally

#158
post #134

Earlier quoted context omitted.

I disagree. Here's an outline of what a response to the letter in that first link should look like for a small, well-meaning* startup: The letter is nicely formatted into 9 bullets. All are optional for small companies, and all can be automated - the answer should be the same for all users. 1. This is a "yes" or "no" question. If the answer is "no", you can ignore the rest of the letter. If yes, the answer is the sam…

> 3. You can avoid doing if you want. If you are doing this, you're signing up to take on this additional burden of informing your users. Consider this when making this decision. This is the only bullet in the list that is in any way burdensome as you will need to update this text in your automated response whenever you take on 3rd-parties (if at all). Pretty much everyone is going to. Google Analytics, Zendesk, Sale…

> Pretty much everyone is going to [...] even AWS qualifies...

I worded this badly. This is optional on a case by case basis, i.e. there's a cost-benefit to using each 3rd-party, and this burden is worth considering for each. It's still not a massively onerous burden tbh if you do use a lot of 3rd parties.

> And "detail all your security measures". Which, for a small company that doesn't have an InfoSec group, probably means next to nothing. An admission that feels a lot like liability...

I'm sorry but if you're really defending companies with no competent security measures in place, regardless of size, I think you're in the wrong forum here. If you are a commercial entity of any size there should be moral hazard in ignoring security of your users' personal data.

> It's the sort of thing an angry consumer might do, and most startup founders subject to GDPR are not deeply knowledgeable about it.

Exactly. And unlikely to be more knowledgeable if they're reading misleading scaremongering articles like this on LinkedIn!

Re: Facebook urged to make GDPR its “baseline standard” globally

#159

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

As someone who works in a startup in the healthcare space, I will point out that nobody lets health startups off the hook for HIPAA. You don’t get to be sloppy with people’s protected health information just because it makes your life easier.

Re: Facebook urged to make GDPR its “baseline standard” globally

#160

Is anyone talking about the harmful effects on startup companies that may want to create new social platforms to compete against the incumbent players? All the talk about regulating facebook, twitter, etc are actually great for those companies because they can afford compliance. But it raises the bar of entry so high that new companies wouldn't be able to compete since with limited resources they wouldn't be able to…

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? There's nothing inherently wrong with a high bar to entry if that bar exists for a very good reason. If it were hard to break into this space due to regulation…

> We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different?

Safety critical code and health care technology are life and death situations.

It's also important to understand that the regulations in those sectors have destroyed (or deterred) an incredibly large number of startups, and the net lives saved as a result is quite likely negative because the value of life-saving technological advances generally exceeds the cost of mistakes in developing them.

People have severe emotional reactions to this. A doctor's experiment may kill fifty already-terminal patients but uncover a cure that goes on to save five million. But the families of the fifty dead patients can blame a specific person for their deaths while the five million aren't even aware what they lost, so the regulations are biased against progress.

This is obviously not a good template for making decisions in other industries where emotions don't run so high.

Post reply on HN