Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

191–200 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#191
post #166

Earlier quoted context omitted.

> If FB moves all their operations out if the EU, how does the EU tax a company? If Facebook moved its servers and personnel out of the EU to avoid complying with EU law, I'd fully expect--and support--the EU to (a) punitively taxing EU businesses buying Facebook ads, (b) banning EU businesses from buying said ads, (c) extraditing Facebook executives to the EU and then (d) blocking Facebook in the EU. No jurisdiction…

So if some new chinese website becomes globally popular, the EU will try to prevent its business from paying money or buying ads from such company?

> if some new chinese website becomes globally popular, the EU will try to prevent its business from paying money or buying ads from such company?

This is a red herring. The hypothetical involved Facebook, a company serving European users and with equipment and people in Europe, reacting to European regulation by moving said equipment and people out of Europe while continuing to serve the same Europeans. That is skipping jurisdiction. Given such a blatant attempt to skip the law, while still doing what the law was designed to prevent, one expects enforcement.

A comparable hypothetical would be an American company reacting to an American law by moving its people and servers to Canada while keeping all its American users and then saying "we're no longer in America, you can't touch us."

Re: Facebook to change user terms, limiting effect of EU privacy law

#192
post #139

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

Not exactly correct. GDPR is closer to FATCA meaning — non US banks that deal with US citizens are subject to FATCA reporting IF they also have US assets. The penalty for a foreign bank not complying with FATCA is a penalty against US assets.

A bank with zero US financial system exposure can’t be penalized under FATCA because they have nothing to penalize. FATCA only works because banks have exposure to US assets.

The unintended consequence of FATCA is that it is dramatically harder for a US person to do any business with European banks — banks have closed accounts in order to reduce operational risk. So this “good law” (occurring to Democrats that passed it) actually made it much more difficult for Americans overseas and American companies who need overseas banking.

GDPR could be considered similar — it won’t have any jurisdiction if the company involved has no EU presence, but it could result in companies denying services to EU persons based on operational risk.

People should have thought this through much better.

Re: Facebook to change user terms, limiting effect of EU privacy law

#193
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this.

GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work.

Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like the GDPR within the context of local laws and regulations.

The DPA is responsible for the application of the GDPR within it's member state (and it's power is limited to that member state only but the GDPR does have a few venues for applying a local DPA directive across member state lines) it's also responsible for handling complaints in that state and it provides directives and advice to both law makers and the industry.

If I'm a UK company and need to deal with the GDPR (till Brexit do us part) I work with the ICO which is the UK Data Protection Agency. While other DPA might affect me the ICO is my primary source of both advice and enforcement and any issues that might originate in another DPA would still pass through the ICO.

Now I am a company in don't know where lets take Argentina I want to sell to EU customers which DPA do I answer too? which DPA to I ask for advice? How do I arbitrate complaints filed against me and to which DPA do I prove I handled data disclosure requests in a manner compliant with the GDPR? which DPA would know my local laws to ensure if my application with the GDPR was complaint with local data retention and lawful access laws? In fact other than going through my own state/trade department and organizations what venue do I have as a non-EU resident and a non-EU entity to any EU services and resources.

The question to all of this is none as a non-EU company there is fuck all you can do even if you want to comply with the GDPR.

Re: Facebook to change user terms, limiting effect of EU privacy law

#194
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

You suggest an exemption for startups? Wait until a Facebook decides to buy all their 'analytics' from a small startup they funded, basically circumventing the whole GDPR.

Re: Facebook to change user terms, limiting effect of EU privacy law

#195
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

If it is so typical, multiple examples please.

Re: Facebook to change user terms, limiting effect of EU privacy law

#196
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.

Re: Facebook to change user terms, limiting effect of EU privacy law

#197
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

Not exactly correct. GDPR is closer to FATCA meaning — non US banks that deal with US citizens are subject to FATCA reporting IF they also have US assets. The penalty for a foreign bank not complying with FATCA is a penalty against US assets. A bank with zero US financial system exposure can’t be penalized under FATCA because they have nothing to penalize. FATCA only works because banks have exposure to US assets. Th…

FATCA was designed to apply to non-US entities it provides clear definitions and channels on what to do and who do you work with, the GDPR has no functional models for non-EU entities.

Re: Facebook to change user terms, limiting effect of EU privacy law

#198
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account.

The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to me. If your startup is at odds with this, well then perhaps you're not the kind of company the EU wants to be doing business with.

Re: Facebook to change user terms, limiting effect of EU privacy law

#199
post #104

> But the fact that the button to reject the new Terms of Service isn’t even a button, it’s a tiny “see your options” hyperlink, shows how badly Facebook wants to avoid you closing your account. > When Facebook’s product designer for the GDPR flow was asked if she thought this hyperlink was the best way to present the alternative to the big “I Accept” button, she disingenuously said yes, eliciting scoffs from the roo…

It all comes in babysteps. A little here, a little there and when you look back you can't see where it all started going wrong.

Aka "Normalization of Deviance"[1]. Fix the minor problems now, or they become the new normal, eventually accumulating until a huge deviance from "normal" behavior isn't even noticed. The stories[2] about airline pilots completely ignoring checklists and unusual alarms while trying to take off with the gust lock still engaged are a shocking example of strong this effect can be.

For a very good explanation of how this happens, see Richard Cook's short talk "Resilience in Complex Adaptive Systems"[3].

[1] https://en.wikibooks.org/wiki/Professionalism/Diane_Vaughan_...

[2] http://www.rapp.org/archives/2015/12/normalization-of-devian...

[3] https://www.youtube.com/watch?v=PGLYEDpNu60

Re: Facebook to change user terms, limiting effect of EU privacy law

#200
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle.

Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe.

These are not burdens.

Post reply on HN