Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

151–160 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#151
post #69

Earlier quoted context omitted.

Define retention policies and explain you would keep IP addresses up to xxx months to ensure service operation/troubleshoot/etc. Prune the logs. There you have it.

Sounds like a legal headache for anybody who wants to set up a personal blog or blog for their company, with a penalty of up to 20 million euros if you get it wrong.

> with a penalty of up to 20 million euros if you get it wrong

Much like if you set up your billing software wrong, you could go to jail for years for fraud. Or you could violate a safety regulation and get shut down for months.

Staring at the worst possible punishment is hopelessly hyperbolic.

Re: Google and Facebook accused of breaking GDPR laws

#152
post #75

Earlier quoted context omitted.

If a product that was in compliance goes out of compliance due to legal changes, it generally has to be pulled from the shelves. I'm saying this strictly from a legal perspective, not endorsing it per se, and I acknowledge the significant expense involved. But this sort of thing happens pretty frequently in a lot of other industries, and the result is pulled product and often a lot of destruction of unsold product. I…

If google had made software updates available, which gave the correct options and are GDPR compliant. But the OEM, Network don't approve / supply those updates, is Google at fault? (In this case its a non-Google phone running Android)

Interesting line of argument; if it was a CE compliance issue it would clearly be the vendor/importer. But the GDPR doesn't talk about devices, it talks about data controllers.

Information commissioners can't require data controllers to do things which cannot reasonably be done. So I think this ends up with "the existing phones are fine for technically necessary data processing, but buying an Android phone cannot be direct marketing consent in and of itself".

Re: Google and Facebook accused of breaking GDPR laws

#153
post #95

Earlier quoted context omitted.

Sign me up! The sad truth though is that the users who are most likely to pay to get rid of ads, are also the users that are most valuable to advertisers, because that's a signal they have more money to spend than the rest.

What if they say it's $20 a month? And it's just facebook. Google also asks for $20, Reddit too, etc. It won't be cheap.

I would actually pay a small amount to have a read-only account for facebook that doesn't track me at all. I don't want to post anything, but I would like to view stuff more easily on the platform. Especially since so many events are organized through fb.

Re: Google and Facebook accused of breaking GDPR laws

#154
post #43

Earlier quoted context omitted.

Every website you visit can elect not to store IP addresses. In fact if you had German users their IPs were already protected, it's just that nobody cared to comply with individual EU member's privacy laws until they combined their weight into GDPR: https://blog.philippklaus.de/2011/05/modify-apache-logging-t...

Not necessarily. They may even be required to store access information, due to legal regulations in some countries. Also, providing service may become practically impossible if it is not possible to keep logs and similar data.

Other legal requirements trump the GDPR data minimization. In that case you only need to provide that data when the user wants a data export.

Re: Google and Facebook accused of breaking GDPR laws

#155
post #110

Earlier quoted context omitted.

I see so many people parroting this but I just don't get it. Surely it won't be a problem at all for a new startup handling data correctly from day 1? Facebook has a mountain of historical data that was collected using non-GDRP-compliant methods that now falls foul of EU law.

You need somebody that knows the regulations and developers that are capable of auditing the whole system. That's added fixed costs, which is an advantage for incumbents.

But these regulations are not that complicated! Heck, in the EU we've been observing most of them in the last years already. Most things are really straightforward. Things get complicated when your core business is making users' data available to third parties. But it's not different from any other business: if you want to make money in catering for example, you need to read and adhere to relevant laws, too.

Re: Google and Facebook accused of breaking GDPR laws

#156
post #95

Earlier quoted context omitted.

Sign me up! The sad truth though is that the users who are most likely to pay to get rid of ads, are also the users that are most valuable to advertisers, because that's a signal they have more money to spend than the rest.

What if they say it's $20 a month? And it's just facebook. Google also asks for $20, Reddit too, etc. It won't be cheap.

Are you saying the free market doesn't apply to pricing for these services?

Re: Google and Facebook accused of breaking GDPR laws

#157
post #39

Earlier quoted context omitted.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

That's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.

> but that won't stop people taking legal action against the website's operator.

The GDPR doesn't allow individuals to take legal action against non-compliant companies. It allows individuals to report companies to their local data protection agency.

Re: Google and Facebook accused of breaking GDPR laws

#158
post #28

Earlier quoted context omitted.

It'd be great if companies offered a "buy back your privacy" subscription model. For the services I really don't want to stop using (Twitter ...) I'd definitely be using that.

The users that can afford and would buy this service are exactly the ones that advertisers want to reach. If you stop showing them ads or only share data for people not willing to pay, the data becomes useless.

Tough luck.

There is no fundamental right allowing tracking or advertising.

There is a fundamental right to privacy.

Re: Google and Facebook accused of breaking GDPR laws

#159
post #43

Earlier quoted context omitted.

Every website you visit can elect not to store IP addresses. In fact if you had German users their IPs were already protected, it's just that nobody cared to comply with individual EU member's privacy laws until they combined their weight into GDPR: https://blog.philippklaus.de/2011/05/modify-apache-logging-t...

Not necessarily. They may even be required to store access information, due to legal regulations in some countries. Also, providing service may become practically impossible if it is not possible to keep logs and similar data.

Yea, they cover that:

https://ico.org.uk/for-organisations/guide-to-the-general-da...

Re: Google and Facebook accused of breaking GDPR laws

#160
post #51

Earlier quoted context omitted.

Reconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.

Don't forget to scrub the headers! Your software stack might store something as well.

You are legally responsible for whatever your computer systems do, and you've always been.
Post reply on HN