Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

201–210 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#201
post #89
post #13

Zuckerberg went to Congress and told them Facebook would support GDPR, as if the only thing GDPR is are just some controls you'd do at the user interface level (and as we learned today, that they're attempting to get around with dark pattern designs [1]). GDPR is much more comprehensive than that, but most importantly it gives data privacy regulators real teeth to enforce with (fines up to 4% of global revenue). The…

Facebook just needs to be gone forever now.

In the long run it would not change a thing. Personal data is a huge business, Facebook demise would just put some smoke and mirrors in the media, then their customers would be sucked in by Google and others, at the same conditions.

Limiting corporations power would be one thing but I don't expect any politician to move in that direction when either they're lobbied/bribed by the same entities they should limit, or face the risk of having their career destroyed (search for "mccarthysm").

Re: Facebook to change user terms, limiting effect of EU privacy law

#202

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone, including tiny businesses who accidentally have one European visitor.

I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

Re: Facebook to change user terms, limiting effect of EU privacy law

#203
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

It's pretty crazy to me that people can feel this way after things like the Equifax breach. Equifax was sitting on all that data that people didn't even know they were included in, and probably didn't even WANT Equifax to possess.

But that's just business as usual, businesses are allowed to do things we consider morally wrong because that's just how things work.

And the second a law springs up that helps out the little guy, it's a massive governmental overreach. How dare government actually try to help people, think of all the businesses they are hurting!

Re: Facebook to change user terms, limiting effect of EU privacy law

#204
post #203

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

It's pretty crazy to me that people can feel this way after things like the Equifax breach. Equifax was sitting on all that data that people didn't even know they were included in, and probably didn't even WANT Equifax to possess. But that's just business as usual, businesses are allowed to do things we consider morally wrong because that's just how things work. And the second a law springs up that helps out the litt…

You're using a non sequitur. Equifax is of course a massive data processor which should be regulated. Choosing to instead regulate every single person who even accidentally has an IP address in their logs somewhere is the overreach.

This helps massive corporations (who can afford to comply) and hurts small businesses which cannot.

Re: Facebook to change user terms, limiting effect of EU privacy law

#205

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

You suggest an exemption for startups? Wait until a Facebook decides to buy all their 'analytics' from a small startup they funded, basically circumventing the whole GDPR.

Laws are not code. You could have the exemption be based on the number of individuals whose data is processed, for example: Facebook can use as many shells as they want, but they'd still need to comply if they want to look at their massive user base, but my small business with a few dozen customers wouldn't need to worry.

Re: Facebook to change user terms, limiting effect of EU privacy law

#206

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

Yup. It's crazy to me that this law is going into effect without even such basic questions being answered.

Re: Facebook to change user terms, limiting effect of EU privacy law

#207

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

You should use more punctuation, your writing is very hard to read and understand (as a non native speaker)

Re: Facebook to change user terms, limiting effect of EU privacy law

#208

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

The scope of personal data is disastrously large and the guidance is fuzzy at best.

Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not using any 3rd-party analytics.

No part of my "business model" is attempting to profit from personal data yet I have to jump through a bunch of new hoops.

My likely solution for projects is to simply block EU traffic going forward.

Re: Facebook to change user terms, limiting effect of EU privacy law

#209
post #88
post #13

Zuckerberg went to Congress and told them Facebook would support GDPR, as if the only thing GDPR is are just some controls you'd do at the user interface level (and as we learned today, that they're attempting to get around with dark pattern designs [1]). GDPR is much more comprehensive than that, but most importantly it gives data privacy regulators real teeth to enforce with (fines up to 4% of global revenue). The…

All major tech companies are going to make the GDPR tools available globally for fear of accidentally misidentifying someone as not covered by the GDPR. Facebook will not be an exception regardless of what they are saying now.

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#210

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

> UK company and need to deal with the GDPR (till Brexit do us part)

Brexit will make little or no difference unless you refuse to deal with EU citizens in any way the involves you having access to their PII or storing any information about them (including traces of their activity in your product/app/site.

GDPR will be carried over post-brexit, and even if it is later revoked by act of parliament and not replaced by something equivalent you'll still need to deal with it if you want to trade with EU citizens. If the UK refused to play ball and somehow blocked us from the punishments for non-compliance we will face inconvenient sanction by other means.

GDPR isn't perfect (is any regulation?) and their are certainly significant questions to be answered from the PoV of people operating outside the EU, and even some issues that may still require more clarity for those entirely operating here, but I wholeheartedly welcome it (UK citizen here, FWIW) despite being a data specialist and therefore having a bad nervous-twitch reaction to any idea of a non-soft delete operation!

Post reply on HN