Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

221–230 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#221

Earlier quoted context omitted.

My point is that I don't think they have it figured out ;-) (and they have just over a month left!) I agree that once they get it sorted (which they will have to do), they will almost certainly roll out the majority of it world wide just because it is easier.

Very few companies (care to) understand GDPR and the full extent or its reach/scope. Most think that it's all about "adding the privacy policy to our website" and that's it. When the flood of letters starts, THEN they will feel the true pain/essence/extent of GDPR. E.g. when my bank will get MY letter asking them who they share my data to, and asking them to STOP sharing my data with friggin FB (WTF???) on their app.…

Here's some help to make your bank cry a little: The GDPR Nightmare Letter -- https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

Re: Facebook to change user terms, limiting effect of EU privacy law

#222

Earlier quoted context omitted.

You're using a non sequitur. Equifax is of course a massive data processor which should be regulated. Choosing to instead regulate every single person who even accidentally has an IP address in their logs somewhere is the overreach. This helps massive corporations (who can afford to comply) and hurts small businesses which cannot.

I never really felt the need to store ips actually

You might not, but your webserver did. Or did you change the logging configuration of your webserver to not store or obfuscate IPs in the past?

Re: Facebook to change user terms, limiting effect of EU privacy law

#223

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

"perhaps you're not the kind of company the EU wants to be doing business with"

Europeans want Facebook and Google and the rest, the EU doesn't. The EU != the europeans.

So international startups must now care more about what the EU wants than what european customers want. That's wrong.

In the meantime, european governments take measures that jeopardise private life, like putting black boxes at ISPs in France to watch everyone (aka. fight terror...).

GDPR is ideology. Not private life protection.

Re: Facebook to change user terms, limiting effect of EU privacy law

#224
post #9

Earlier quoted context omitted.

I don't think the servers matter, it's not really about the servers, it's about the business side of it, they operate a low tax business within the EU. I don't think they can move out of the EU without all of a sudden not having to pay a lot more for doing business with EU companies. So they still want to operate as a company within the EU to get the tax advantages, but then also are subject to the laws.

If FB moves all their operations out if the EU, how does the EU tax a company? Presumably EU companies can do business with non-EU companies without the other company having an EU presence? Genuinely curious. Not sure how this works as I'm not a bizguy.

I'm no expert, and I'm not 100% sure what the EU can do, but its not about the EU taxing them, it's all about minimizing paying tax in any country, but say if it was purely US based, it wouldn't have the benefits of its Irish tax avoidance system that everyone seems to use. It would be all exposed to being taxed in the US which I believe would cost a lot more.

Re: Facebook to change user terms, limiting effect of EU privacy law

#225

Earlier quoted context omitted.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

He can also just choose to not log ip addresses.

You missed the part about the blog comments. He would also need to implement a mechanism which allows users to delete their old comments.

Re: Facebook to change user terms, limiting effect of EU privacy law

#226

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

> UK company and need to deal with the GDPR (till Brexit do us part) Brexit will make little or no difference unless you refuse to deal with EU citizens in any way the involves you having access to their PII or storing any information about them (including traces of their activity in your product/app/site. GDPR will be carried over post-brexit, and even if it is later revoked by act of parliament and not replaced by…

That was a joke, the ICO will continue post Brexit I have no problems from the UK.

The GDPR isn't perfect it's just none workable for companies that are not in the EU.

Re: Facebook to change user terms, limiting effect of EU privacy law

#227

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

You use the legislation to guide your internal processes, systems and employee/user education. You ask your legal counsel for advise. Other than what you'd normally do anyway, you'd provide evidence of disclosure only to the DPA that asks. The DPA doesn't care about your local laws - seek local legal counsel instead.

To a developer used to systems thinking this should not be rocket science. Most of it is just good practice. Kim Cameron came up with the laws of identity many years ago, which the GDPR is surprisingly similar to.

Re: Facebook to change user terms, limiting effect of EU privacy law

#228

Earlier quoted context omitted.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

For Apache can't you just change LogFormat to exclude IPs and delete the old logs?

Re: Facebook to change user terms, limiting effect of EU privacy law

#229
post #200

Earlier quoted context omitted.

> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe. These are not burdens.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

Well, he is not a company. So he doesn't need to do anything. If it's a personal website GDPR does not apply.

If it is a company. Yes, it will require more work. That is the nature of regulation, but the demands placed on companies are not unreasonable in any way. I would place it on the same level as stores being required to provide receipts, or restaurants being required to clean the kitchen. It certainly was easier when they didn't need to do that, but don't we agree it's an reasonable burden to place on businesses to guarantee an acceptable level of service?

Re: Facebook to change user terms, limiting effect of EU privacy law

#230

Earlier quoted context omitted.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

IP by itself is not considered private. It's only when you attach it to other identifying data. Anonymous comments are not covered with GDPR.
Post reply on HN