Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

231–240 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#231

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

This is a nice summary, but it is a little fuzzy on one key point, as I understand it:

Facebook is still going to legally operate out of Ireland to dodge taxes.

Re: Facebook to change user terms, limiting effect of EU privacy law

#232

Earlier quoted context omitted.

In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...

Re: Facebook to change user terms, limiting effect of EU privacy law

#233

Earlier quoted context omitted.

> The worst abuser of privacy - right now - is the government Lol, that could not be further from the truth, you have no idea of the amount of data private companies gather, the government has nowhere near as much data as Facebook, that's why the NSA has programs to incorporate Facebook data, the reason being that it's much better than anything they have got by themselves.

If the government has facebook data plus any other single piece of data then they have more than facebook.

"Government can just steal Facebook's data" is definitely one more reason to limit what Facebook can gather and process.

Re: Facebook to change user terms, limiting effect of EU privacy law

#234
post #139

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?

Re: Facebook to change user terms, limiting effect of EU privacy law

#235

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

You use the legislation to guide your internal processes, systems and employee/user education. You ask your legal counsel for advise. Other than what you'd normally do anyway, you'd provide evidence of disclosure only to the DPA that asks. The DPA doesn't care about your local laws - seek local legal counsel instead. To a developer used to systems thinking this should not be rocket science. Most of it is just good pr…

DPA cares for local laws the GDPR does not trump local EU legislation.

What court do you use to appeal a complaint or a fine?

There are no processes at all for a non-EU entity to function within the GDPR and saying it’s not rocket science isn’t going to change that.

Re: Facebook to change user terms, limiting effect of EU privacy law

#236

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

I'm not a lawyer, but I would think your Argentina company can be in one of 2 states: 1. You have a subsidiary in EU, in which case that is who will get fined or will have to deal with the DPA where it is registered 2. You don't, in which case the EU can not fine you?

Well the GDPR doesn’t define that it applies to anyone who touches PII belonging to EU residents.

The logic dictates is that it won’t apply to companies that simply dont have any legal presence in the EU.

But that is not defined because again there are no exceptions.

However PayPal might enforce it on you in fear of the EU going after PayPal because it’s expected that all EU companies would require GDPR compliance from their business partners overseas that perform any data processing for them or are exposed to EU PII.

However how this compliance to be achieved, validated and arbitrated isn’t defined either.

Re: Facebook to change user terms, limiting effect of EU privacy law

#237
post #230

Earlier quoted context omitted.

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

IP by itself is not considered private. It's only when you attach it to other identifying data. Anonymous comments are not covered with GDPR.

However, is it not thought that because the ISP keeps a log of dynamic IP addresses, these could (in theory) be matched to the IP address of anonymous comments, thus de-anonymise them?

Re: Facebook to change user terms, limiting effect of EU privacy law

#238

Earlier quoted context omitted.

You use the legislation to guide your internal processes, systems and employee/user education. You ask your legal counsel for advise. Other than what you'd normally do anyway, you'd provide evidence of disclosure only to the DPA that asks. The DPA doesn't care about your local laws - seek local legal counsel instead. To a developer used to systems thinking this should not be rocket science. Most of it is just good pr…

DPA cares for local laws the GDPR does not trump local EU legislation. What court do you use to appeal a complaint or a fine? There are no processes at all for a non-EU entity to function within the GDPR and saying it’s not rocket science isn’t going to change that.

If the ICO (UK) issued a fine, you wouldn't appeal in Spain, would you? Because of course you respond to the DPA that issued the fine or complaint. Am I not understanding your question?

Re: Facebook to change user terms, limiting effect of EU privacy law

#239

Earlier quoted context omitted.

He can also just choose to not log ip addresses.

You missed the part about the blog comments. He would also need to implement a mechanism which allows users to delete their old comments.

Not to stretch out this comment any more, but are we seriously arguing that adding a delete button is hard? I mean, most people on here would agree that its not something they would worry about. It sounds more like people are upset they are forced to do it, and have no say in it.

Re: Facebook to change user terms, limiting effect of EU privacy law

#240
post #200

Earlier quoted context omitted.

> It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Where's the burden? Only collect the data you need; tell people what you're collecting and why; only keep it for as long as you need; keep it safe. These are not burdens.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

> (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work

If the blog is purely personal the GDPR does not apply.

https://ico.org.uk/media/for-organisations/data-protection-r...

> The GDPR does not apply to certain activities including processing covered by the Law Enforcement Directive, processing for national security purposes and processing carried out by individuals purely for personal/household activities.

And if GDPR does apply you only have to do the extra work if the IP addresses can be used to identify a natural person. Note here "can be", not "is".

> Like the DPA, the GDPR applies to ‘personal data’. However, the GDPR’s definition is more detailed and makes it clear that information such as an online identifier – eg an IP address – can be personal data. The more expansive definition provides for a wide range of personal identifiers to constitute personal data, reflecting changes in technology and the way organisations collect information about people.

http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...

> (26) The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.

And article 4

1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Post reply on HN