Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

181–190 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#181
post #9

I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…

Nothing in the directive requires the access to personal data to be done "in band" through the normal login only. It's a valid interpretation of GDPR to only accept "give me all my data" requests by post, and require additional ID to confirm that you're giving it to the right person.

"The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means."

"Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject."

(article 12)

Re: Google and Facebook accused of breaking GDPR laws

#182
post #5

Considering that large sites with teams of lawyers are failing to follow the rules, how does a small site run by a few regular folks supposed to comply?

Because they're not failing due to misunderstanding the law, they're getting sued because their 'compliance' to the GDPR is against the spirit of it, and in most cases is actually in direct violation of multiple clauses. They're trying to follow the letter of the law and remain in the grey areas - if a 'small site run by a few regular folks' isn't doing anything shady, and isn't being basically negligent with their u…

I'm not sure about Facebook due to not using it, but Google's actually one of the less shady companies in this area. At least they do let you opt out of tracking-based advertising. Other sites don't. For instance, I just tried to view a Forbes article and it redirected to an interstitial which defaulted to letting them track me for advertising purposes, then when I changed the setting to only allow essential cookies it made me wait for several minutes with only a Cancel button, then finally redirected every page on the site to a message saying "You have arrived at this page because you have chosen not to consent to the use of cookies that help us provide a great experience (and great content) to you free of charge" and not allowing me to do anything but change my settings back.

Journalists are just a lot less willing to criticise the state of the free press than they are to attack companies like Google and Facebook that eat into their collective profits.

Re: Google and Facebook accused of breaking GDPR laws

#183

Earlier quoted context omitted.

The users that can afford and would buy this service are exactly the ones that advertisers want to reach. If you stop showing them ads or only share data for people not willing to pay, the data becomes useless.

Tough luck. There is no fundamental right allowing tracking or advertising. There is a fundamental right to privacy.

[deleted]

Re: Google and Facebook accused of breaking GDPR laws

#184
post #164

Earlier quoted context omitted.

How would anyone find out, and provide proof for this? Can we expect a EU government agency to validate companies on a regular basis? And if not, would they even cooperate with white-hat hackers to find offenders? Also, from what I read, data protection agencies have been understaffed and overworked for years now.

Tracking which doesn't result in any visible effect to the users is fairly harmless. The more concerning stuff involves handing the data to third parties like direct marketers and political campaigns. Those commercial relationships are a lot harder to hide and generate a paper trail. "Why did this company pay you $x million?" ".. stuff?"

When in doubt, make it a consulting fee

Re: Google and Facebook accused of breaking GDPR laws

#185
post #71
post #6

> "The GDPR explicitly allows any data processing that is strictly necessary for the service - but using the data additionally for advertisement or to sell it on needs the users' free opt-in consent" This is the key point. As the saying goes, on Facebook, you aren't the customer, you are the product. The GDPR just changed this -- rightfully, in my opinion.

The GDPR ensures that only Facebook will be able to comply, and prospective competitors shouldn't even bother. The regulation counts 58 000 words.

I love all these posts that assume because they've never been on a software that team that makes compliance part of their job, that it's completely outside the grasp of a small team.

Those of us in fields regulated prior to GDPR are laughing at you.

Re: Google and Facebook accused of breaking GDPR laws

#186
post #124
post #95

Earlier quoted context omitted.

What if they say it's $20 a month? And it's just facebook. Google also asks for $20, Reddit too, etc. It won't be cheap.

So you are stipulating an account worth is 240USD a year at facebook? Instead of 20, why won't you say 100, make it round. Seriously though, behemoths do fall and if facebook ceases to exist there will be no harm but good in my book.

The number that's been kicked around for he value of North American user is about $50/year. So $5/month will cover it.

Re: Google and Facebook accused of breaking GDPR laws

#187

I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…

"you would need to agree to the ToS to get that update"

If you have to agree to their ToS before you can use the device, it should be before you purchase.

Google intentionally waited until they had your cash to say GOTCHA! We require an additional payment of your soul. Now its biting them in the ass, it is entirely fair.

Re: Google and Facebook accused of breaking GDPR laws

#188

Earlier quoted context omitted.

The option to monetize your own data is an amazing idea: a startup that pays you to upload the data you can download from your google, apple, facebook, BIGNAME account, basically renting it daily until you revoke consent, then uses it to do all sort of shit you can with it. You’ll get hypeprofiled and harassed with all sorts of advertising, but you’re actually getting real money for that.

The problem with that model is... how much money is a single profile worth, really? I'd love to be proven wrong and for a company to implement this. But as far as I know, it's not being done because the math doesn't work out. It's too cheap for regular people to be interested, and an incentive for spamtech to mass create fake profiles and get paid pennies for it. In fact, the one variant I am aware of that works is s…

[deleted]

Re: Google and Facebook accused of breaking GDPR laws

#189
post #43

Earlier quoted context omitted.

Every website you visit can elect not to store IP addresses. In fact if you had German users their IPs were already protected, it's just that nobody cared to comply with individual EU member's privacy laws until they combined their weight into GDPR: https://blog.philippklaus.de/2011/05/modify-apache-logging-t...

Not necessarily. They may even be required to store access information, due to legal regulations in some countries. Also, providing service may become practically impossible if it is not possible to keep logs and similar data.

At which point it becomes "Legitimate Interests" (or whatever the correct term is).

Re: Google and Facebook accused of breaking GDPR laws

#190
post #174
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

If companies successfully argue that maximising revenue is a legitimate interest and thus, don't need users consent, then the GPDR will worth less the paper it was written on. I would be extremely surprised if the EU goes through all this tome, effort, and money just to let corporations continue with business as usual

> I would be extremely surprised if the EU goes through all this tome, effort, and money just to let corporations continue with business as usual

trust me, you didn't see what the eu already gone through, just to keep existing.

Post reply on HN