Live data from Hacker News

Facebook urged to make GDPR its “baseline standard” globally

techcrunch.com

211–220 of 236 posts

Re: Facebook urged to make GDPR its “baseline standard” globally

#211

Earlier quoted context omitted.

As someone who works in a startup in the healthcare space, I will point out that nobody lets health startups off the hook for HIPAA. You don’t get to be sloppy with people’s protected health information just because it makes your life easier.

I'm sorry but I don't see a comparison between what people *willingly post online to public forums compared to their personal health ledger... it's not apples to apples

The content of the data is not the issue. The point is that society has decided to pass a law stating that certain data needs to be treated a certain way or there are serious penalties because of past abuses. We in the US take for granted that this law exists, but there was much complaining in the medical establishment about how burdensome it is to them conducting their work because of all the extra protections it required. This was especially true in biomedical research where patient data was pretty carelessly treated in many cases. Not because the people involved were bad people, but because society as a whole had not thought through the consequences of walking around with an unencrypted list of cancer patients on a floppy disk.

Re: Facebook urged to make GDPR its “baseline standard” globally

#212
post #169

Earlier quoted context omitted.

> We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? Safety critical code and health care technology are life and death situations. It's also important to understand that the regulations in those sectors have destroyed (or deterred) an incredibly large number of startups, and the net lives saved as a result is quite lik…

People's personal info can be a matter of life or death too. If yours isn't, you can count yourself fortunate.

> People's personal info can be a matter of life or death too.

That's the point. If we pass regulations that result in continued and increased centralization because only large organizations can afford compliance, that is not advantage to the people whose lives are at risk.

If you're a homosexual in Russia or a democracy activist in China or an advocate for womens' education in parts of the middle east or a Jew in WWII Germany, "privacy laws" can't save you. A company's fear of the state can't protect anyone from a corrupt state. But structural and technological privacy protections might. Which are the things hamfisted regulations inhibit.

Debian is better at this than AT&T.

Re: Facebook urged to make GDPR its “baseline standard” globally

#213
post #117

Earlier quoted context omitted.

I'm an EU citizen and I disagree, so I guess that's just, like, your opinion, man.

You won't vote to protect free speech?

free speech*

*Terms and conditions may apply.

Re: Facebook urged to make GDPR its “baseline standard” globally

#214
post #173
post #108

Earlier quoted context omitted.

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> not allowing that export at all would probably be met with legally-binding criticism Yeah? Can you point me towards any law that says I have the right to export data I did not enter? > The main use-case that was discussed then was to empower services like Riot, to encourage competition — something that, surprisingly, Facebook was very supportive of at the time. You have any evidence for that encouraging competing s…

> Yeah? Can you point me towards any law that says I have the right to export data I did not enter?

In the case in point, you did approve, i.e. enter, all the relation on your graph so I’m not sure how your question is related. To your question: GDPR allows you to access any information associated to identifiable information, there are explicitly no limits on whether you entered it, it was scraped, logged or if it was inferred.

>> main use-case that was discussed

I have the notes from my PhD, yeah. Statistics on blogs posts mainly. They are on another computer, but if you really think this is important. The main use case was obviously to have your friends as a feature in social games, music sharing but that was not really discussed — unless, like for Apple Music, the intention appeared to be to build a competing graph.

I probably should have phrased it better, “the most discussed case”.

> The vast majority of people whose data was stolen did not grant ANY access.

Every one of them granted access to their likes and social graph to their friends. Their friends then overlooked how the platform granted them the ability to share that further. That’s the thing about a social graph that hardly anyone seems to notice now: it’s shared personal data. That’s why calling it “ownership” makes it confusing: information isn’t an excludable good.

> So how can I monitor and delete the shadow profile they have build for me?

I don’t think you have a shadow profile. Your friends shared information about you with Facebook, namely that they know socially the person controlling your email address. What you are asking is for you to be able to tell Facebook that the company should not accept, or store, the information that your friends want to connect with whomever ends up connecting using a certain address. But, if you change your mind, Facebook needs to be able to change that too. Storing your intention, or controlling the ability for you to change it, that would be a profile, missing most feature — a ghost or shadow profile, if you wish.

If you want to prevent your friends from sharing your personal information with programatic agents, I’d love to get your take on how to do that. I use Facebook for most of my social life because I know that, because as a central control the tool, they enable me to prevent my friends from abusing my trust (like email would) and they monitor other programatic agents.

> Nobody has said their sold the data.

This is alas a commonly repeated story (like the shadow profile). If you go through the paragraph, it should be fairly clear that I was actually trying less trying to debunk that and more trying to contrast Facebook and data brokers.

> something Facebook did got me sick

If you don’t have a Facebook account, I’m not sure how Facebook or Cambridge Analytica would have been able to hurt you personally.

Re: Facebook urged to make GDPR its “baseline standard” globally

#215
post #108

Earlier quoted context omitted.

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

> The amount of blaming the nurse for your fever on those issues is getting really concerning. The nurse is being blamed because they've ignored clear, worsening symptoms for years.

I’m sorry: what problem do you think Facebook is ignoring? I have heard interesting arguments elsewhere — but not on the company ignoring anything.

All I’ve heard in this thread is people judging the company in hindsight, and based on a rather convoluted speculation (that happen to be false: Cambridge Analytica used credit card data and voter records, not Facebook data, to assess psychological profile).

Facebook has made difficult decisions with partial information that ended up proving to be suboptimal — but I don’t see when they have ignored either symptoms or criticism.

Re: Facebook urged to make GDPR its “baseline standard” globally

#216
post #136

Having worked on GDPR, it is unnecessarily harsh and in no way, shape or form would I support this standard going global. There are plenty of ways to make users data completely private without being ridiculously overreaching the way GDPR is. And having the sword of infinite lawsuits hanging over your head has and never will work, look at how ambulance chasers in the US have taken the most mundane laws and turned them…

If the industry didn't want what they're trying to spin as an "overreaching" standard like GDPR, maybe they shouldn't have spent so much time and effort seeing how far they could push their abuse of users' privacy.

Maybe governments should remove the plank from their own eyes before attaching the voluntary association eye splinters in the market.

Re: Facebook urged to make GDPR its “baseline standard” globally

#217
post #108

There's been so many articles about Facebook and the recent privacy catastrophe that I'm finding it hard to keep up. Does anybody actually know what their response will be to the GDPR? Are the privacy benefits from the GDPR going to be exclusive to EU citizens? This seems problematic. Whatever happens, Facebook has irreparably damaged my trust in their handling of user data and I think many on here would agree. My wi…

GDPR requires you to handle personally identifiable information in a way that makes sense to the users and that is auditable. Facebook overall does that far better than anyone. The situation with Cambridge Analytica was that they let users export the information about their friends, information that users had access to; not allowing that export at all would probably be met with legally-binding criticism. What the API…

You must be a Facebook employee.

GDPR also relates to the consent of having personal data. Facebook is well known for using fishnet trawler techniques to gather whatever personal data they can with little regard for consent. Wouldn't be surprised if everything is passed on to Palantir anyway.

The fact that several aspects of their business model will have to change to accommodate GDPR should be telling.

Re: Facebook urged to make GDPR its “baseline standard” globally

#218
post #140

Earlier quoted context omitted.

I'll point out which question gives me nightmares, as the founder of a EU startup: - the requirement to have a DPO. Based on the requirements for the DPO, no one in the company can fill the role (conflict of interest), so we must hire an employee or consultant (expensive either way for a small startup) - one month to respond. That's a lot of informations to collect the first time, and I might have other fires to put…

thanks for this. so what's your advice for a social startup building a new platform in today's data-privacy concerned world?

I'm going to be honest: I have no clue about social. I operate in socio-medical domain, we don't share by default.

We are mostly fine with the spirit of the GDPR, it's the work we have to do to follow it to the letter which is a problem (and the lack of process internally).

Re: Facebook urged to make GDPR its “baseline standard” globally

#219
post #188

Earlier quoted context omitted.

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? We don't give special provisions to start ups writing safety critical code or developing new health care technology, why would this be any different? There's nothing inherently wrong with a high bar to entry if that bar exists for a very good reason. If it were hard to break into this space due to regulation…

I don't think GDPR compliance is as onerous as you seem to think it is, but even if it were, would it matter? The answer is yes, it is onerous. And yes, it does matter. Regulations always start as an idea that sounds good. The companies most impacted are then motivated to gain control of the regulations. Once they do, then they happily add on to regulations because that becomes a barrier to entry for new competitors,…

You must be American. This is not the first regulation in EU and they are created to serve it's citizens.

The issue you are talking about is rampant in USA. The problem is not regulations but your politicians and your filthy rich businessmen.

Re: Facebook urged to make GDPR its “baseline standard” globally

#220
post #117

Earlier quoted context omitted.

I'm an EU citizen and I disagree, so I guess that's just, like, your opinion, man.

You won't vote to protect free speech?

You're moving the goalposts. Your statement suggested you want a US-style "1st amendment" in Europe. I don't. That has nothing to do with "free speech" as a concept.

Under the US interpretation of free speech political donations are protected as "speech" and politicians can go on TV and say they want someone to be murdered and not face any consequences.

I'm German so you can imagine why I fundamentally disagree with that notion, even if our laws are sometimes a bit too strict (though that often has more to do with post-WW2 denazification than free speech in particular -- e.g. not being allowed to put nazi symbology in video games, not even as enemies).

UK libel laws and their advertising code are another example of European laws being a bit too strict. But even that is something I'd prefer over the "law of the strongest" in the US.

EDIT: Free speech is obviously a great idea and an important right, but the problem with freedoms and rights is that they can't be absolutes when you live in a society with other people you want to share those rights and freedoms ("your liberty to swing your fist ends where my nose begins"). Additionally some of those freedoms and rights are mutually exclusive so you need to define an order of precedence. Even free speech absolutists generally draw the line somewhere (e.g. generally violence isn't considered speech even if it is a form of expression and few people would defend the right to shout "fire" in a crowded building and not facing the consequences of the resulting mayhem).

In other words "being willing to defend free speech" is a meaningless platitude unless you first define what you consider the acceptable limits of that freedom.

Post reply on HN