Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

201–210 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#201

Targeted advertising has become such a big deal, and implemented at such high cost, that I wonder if the trade off is even worth it now. I could imagine Apple or Samsung simply "sponsoring" Facebook for a week or month at a time with banners and messaging - tastefully done of course! - and how much less hassle that would all be, rather than aggregating millions upon millions of cookies and chasing people around the i…

Targeted advertising has always seemed pretty dumb, to me most advertising is done by Coke and their target is every where.

> Targeted advertising has always seemed pretty dumb, to me most advertising is done by Coke and their target is every where.

Doc Searls made a good point: targeted advertising isn't advertising, it's really direct marketing (like spam and junk mail).

Coke is doing advertising, but the adtech "targeted" advertisers are just spamming you using new technology.

https://blogs.harvard.edu/doc/2018/05/12/gdpr/comment-page-1...

Re: Google and Facebook accused of breaking GDPR laws

#202
post #174
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

If companies successfully argue that maximising revenue is a legitimate interest and thus, don't need users consent, then the GPDR will worth less the paper it was written on. I would be extremely surprised if the EU goes through all this tome, effort, and money just to let corporations continue with business as usual

Eu cookie law is one prior example of this. That worked out to “business as usual” in the end, didn’t it?

Re: Google and Facebook accused of breaking GDPR laws

#203

Earlier quoted context omitted.

> IP addresses are PII, as defined in the law. No, that's far from fucking clear, but appears to have been repeated over and over and over again.

It’s in the faq, you can’t be upset with people repeating it. https://www.eugdpr.org/gdpr-faqs.html [edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/refo...

> This website ... is NOT an official EU Commission website.

Re: Google and Facebook accused of breaking GDPR laws

#204
post #110

Earlier quoted context omitted.

You need somebody that knows the regulations and developers that are capable of auditing the whole system. That's added fixed costs, which is an advantage for incumbents.

But these regulations are not that complicated! Heck, in the EU we've been observing most of them in the last years already. Most things are really straightforward. Things get complicated when your core business is making users' data available to third parties. But it's not different from any other business: if you want to make money in catering for example, you need to read and adhere to relevant laws, too.

Is an IP address PII or not? I have read multiple different interpretations today.

Is a hash of an IP address PII?

Re: Google and Facebook accused of breaking GDPR laws

#205
post #27

Earlier quoted context omitted.

The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.

IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.

Again, let's read the text.

"Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

An IP address is an "identifier". However, an IP address does not identify a natural person; you know that, I know that, and even the GDPR knows that.

However, if you start building a map of IP addresses to user real names, or some other form of profile construction, then the IP addresses become personal information.

Re: Google and Facebook accused of breaking GDPR laws

#206
post #123

Earlier quoted context omitted.

>They can just design it in a way that is easy to read by humans but very challenging for parsers. This is explicitly forbidden in article 20.1

Machine readable only means no images. You can still structure it in a way that it's a pain to import. Or use changing structures. Definitely violates the spirit of the law but don't think Facebook cares about that.

I'd argue that the GDPR is entirely about spirit.

Re: Google and Facebook accused of breaking GDPR laws

#207
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

"Legitimate interest" works for regular data (Article 8).

You cannot claim "legitimate interest" for sensitive data (Article 9), such as political and religious views, or sexual orientation.

Re: Google and Facebook accused of breaking GDPR laws

#208
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

> So Facebook's lawyers can say, "It's in our legitimate interest to maximise advertising revenue". They can say it is their interest to have enough revenue to operate the site and some (how much?) profit above that. Maximizing revenue is an other angle. Though if we accept that we live in capitalist society then maximizing profits is one of the core tenets of that.

Well, in case of "need enough revenue to operate" they could just add reasonable "no tracking" monthly fee.

Re: Google and Facebook accused of breaking GDPR laws

#209
post #170

I think Facebook's lawyers have determined that they can use the 'legitimate interest' basis for showing targeted ads to their users [0]. This basis does not require consent from users except as part of the take-it-or-leave-it initial terms of service. Here are the parts of the 'legitimate interest' basis which are most useful to Facebook: The GDPR does not define what factors to take into account when deciding if yo…

You could probably take it a step further and say that it is in the user’s best interest to see targeted rather than generic advertising, because you can show fewer ads and make the same revenue. I don’t know if regulators will buy it though.

I for one am very interested to see how this continental experiment changes the experience of internet users in Europe. And I’m sure glad (at least in this dimension) that I’m not there. (Overall I think I’d be better off living in Europe despite the occasional law I disagree with, but that’s another story.)

Post reply on HN