Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

211–220 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#211
post #200

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe. These are not burdens.

They have provided a real-world example elsewhere in the thread. It really seems to support their point:

"Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not using any 3rd-party analytics."

Re: Facebook to change user terms, limiting effect of EU privacy law

#212
post #85

> But the fact that the button to reject the new Terms of Service isn’t even a button, it’s a tiny “see your options” hyperlink, shows how badly Facebook wants to avoid you closing your account. > When Facebook’s product designer for the GDPR flow was asked if she thought this hyperlink was the best way to present the alternative to the big “I Accept” button, she disingenuously said yes, eliciting scoffs from the roo…

> I wonder if I could live with myself if this was my job. You are in the company, you have a job to do, everybody else is doing it. Other people share your concerns, but in the end, you have a feature to deliver and you don't want to fail your team. Some people is really concerned, they try to change things, they quit, they are tired of the pressure of going against the managers and making it more difficult for thei…

> but in the end, you have a feature to deliver

In the end we are all moral agents and responsible to refuse to do ethically questionable work.

You don't get fired on the spot in most companies for refusing to do something or asking to be assigned to another team.

And a skilled engineer has other options for employment with a comparable salary.

Re: Facebook to change user terms, limiting effect of EU privacy law

#213

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

You should use more punctuation, your writing is very hard to read and understand (as a non native speaker)

Yeah sorry writing on an iPhone is a makes it a bit hard.

Re: Facebook to change user terms, limiting effect of EU privacy law

#214

Earlier quoted context omitted.

The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. You actually have to keep their account active and make it work somehow. If you can't, then you are libel for a really huge penalty. I can't add enough smileys to that, so you will just have to imagine them.

> The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. That's actually pretty horrible. How about freedom of association and freedom to contract? These two are basic human rights. If one thinks their privacy rights are not respected they are free not to associate or contract and same thing for the entity on the other side of the con…

It's a bit different - you can deny service to people; however, if offering or denying service is conditional on consent, then this means that this consent isn't freely given and thus "doesn't count", doesn't give you any rights to handle that data.

It's done in the same manner as with other consumer contracts - there's a broad range of contractual terms that (in EU) automatically are unenforceable if they're put into a "take it or leave it" consumer contract; GDPR clarifies that permission to use private data is one of such terms; this permission cannot be transferred by some term in a nonnegotiable contract.

I.e. if customer A clicks "agree", customer B clicks "disagree", and you deny service to customer B because of that - then this means that the "agreement" of customer A (and everyone else) is worthless to you, it means that these clicks don't indicate freely given consent and thus do not give you permission to use their data, as customer A can reasonably claim that they did not really want you to use that data in this manner and they clicked "agree" only because you'd refuse them service otherwise.

The legal wording is such that you can't (and shouldn't be able to) gain GDPR-consent unless the users actually want you to do the thing you do with their data; GDPR requires that they know what exactly you'll do, and they without any coercion give an explicit opt-in indication that they want you to do it, and they can freely revoke that permission.

Re: Facebook to change user terms, limiting effect of EU privacy law

#215
post #203

Earlier quoted context omitted.

It's pretty crazy to me that people can feel this way after things like the Equifax breach. Equifax was sitting on all that data that people didn't even know they were included in, and probably didn't even WANT Equifax to possess. But that's just business as usual, businesses are allowed to do things we consider morally wrong because that's just how things work. And the second a law springs up that helps out the litt…

You're using a non sequitur. Equifax is of course a massive data processor which should be regulated. Choosing to instead regulate every single person who even accidentally has an IP address in their logs somewhere is the overreach. This helps massive corporations (who can afford to comply) and hurts small businesses which cannot.

I never really felt the need to store ips actually

Re: Facebook to change user terms, limiting effect of EU privacy law

#216
post #200

Earlier quoted context omitted.

> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe. These are not burdens.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

He can also just choose to not log ip addresses.

Re: Facebook to change user terms, limiting effect of EU privacy law

#217

Earlier quoted context omitted.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

He can also just choose to not log ip addresses.

Not logging IPs makes debugging and abuse detection much more challenging. Moreover, it is also the current default in most software which touches HTTP requests.

Re: Facebook to change user terms, limiting effect of EU privacy law

#218

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

I'm not a lawyer, but I would think your Argentina company can be in one of 2 states:

1. You have a subsidiary in EU, in which case that is who will get fined or will have to deal with the DPA where it is registered 2. You don't, in which case the EU can not fine you?

Re: Facebook to change user terms, limiting effect of EU privacy law

#219
post #88

Earlier quoted context omitted.

All major tech companies are going to make the GDPR tools available globally for fear of accidentally misidentifying someone as not covered by the GDPR. Facebook will not be an exception regardless of what they are saying now.

Yup, I work at a firm where we care about GDPR a lot , and IMO it's wayyyyy easier to implement globally then to cordon off some subset of our users into a different codepath/databasee/workflow. If FB actually leaves it like this, then they clearly believe that there's a lot more to be gained by not complying with GDPR

The depends on how much easier "wayyyyyyyy" represents. If it is harder to do but protects there use of data to make money enough that the extra effort is worth it, then they'll make the extra effort.

> then they clearly believe that there's a lot more to be gained by not complying with GDPR

This. Though more precisely it is the other way around: they have something to lose by complying globally rather than something to gain by not.

Extracting every last cent out of every bit of data they could possibly hoover up is their business model. I expect they'd be better of telling EU users to go elsewhere than applying GDPR style protections to non-EU users (which they won't do: even if they can extract less from EU users less is presumably better than none especially when network effects are taken into consideration).

> I work at a firm where we care about GDPR

Same here. Our clients use our systems to store a lot of information about their own users and their customers. But unlike facebook that information is not their primary business and source of income.

Re: Facebook to change user terms, limiting effect of EU privacy law

#220

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

I'm not a lawyer, but I would think your Argentina company can be in one of 2 states: 1. You have a subsidiary in EU, in which case that is who will get fined or will have to deal with the DPA where it is registered 2. You don't, in which case the EU can not fine you?

I don't think any of this is entirely clear, but from my understanding it seems like the EU wants to apply GDPR even if you don't have an EU presence.

In practice, I doubt that they'd get the US to enforce judgements. But it might mean that I can never risk going to Europe again lest I risk having a default judgement enforced against me for one of my businesses.

Post reply on HN