Earlier quoted context omitted.
IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.
Again, let's read the text. "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create…
Google and Facebook accused of breaking GDPR laws
231–240 of 384 posts
Re: Google and Facebook accused of breaking GDPR laws
#232Earlier quoted context omitted.
The data belongs to the user. There's nothing Facebook can do to prevent exporting if it's via the data backup. They can just design it in a way that is easy to read by humans but very challenging for parsers.
>They can just design it in a way that is easy to read by humans but very challenging for parsers. This is explicitly forbidden in article 20.1
Re: Google and Facebook accused of breaking GDPR laws
#233I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…
In that point of view, it seems a rather unfair complaint It is an unfair complaint. But to be fair to the regulators, these complaints were filed by users , and may well be dismissed once reviewed by regulators. This type of unfair complaint will be an interesting test to see just how abusive the GDPR enforcers may or may not be.
Google shouldn't be collecting data from users who agreed to share their data based on outdated ToS that are no longer legally valid.
They should ask for agreement to new GDPR-compliant terms just as they do for users who agreed to the old terms before GDPR was law.
Re: Google and Facebook accused of breaking GDPR laws
#234I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…
"you would need to agree to the ToS to get that update" If you have to agree to their ToS before you can use the device, it should be before you purchase. Google intentionally waited until they had your cash to say GOTCHA! We require an additional payment of your soul. Now its biting them in the ass, it is entirely fair.
If you buy from the Google store, you'd have to agree before buying (you can't buy without an account).
If you don't, then the seller had to notify you before your purchase. Google had little influence there.
And your argument doesn't work if you're taking about third party devices, which the parent was.
Android itself is open source. OEMs aren't forced to bundle the Google services with it. This can't be blamed on Google either.
They're probably still violating gdpr, and I'm looking forward to the first real cases. These are just silly
Re: Google and Facebook accused of breaking GDPR laws
#235I am trying to think what the secondary consequences of GDPR are going to be. If any user can see their data on any service than any government can quickly plug-in to access all user data on any service. This is like NSA Prism for everything. If a user can export their data easily from any service, they can easily resell their own data for money to services that seek to monetize that data. They could even rent out th…
What do you think changed for governments? If there is a search warrant, police could and still can access data. GDPR didn't change anything in this regard. My feeling is that in the EU there is a different view of government: it's not a third adversarial entity. Many other remarks you've made don't have anything to do with GDPR, for example fake accounts and takeovers.
We are not from another planet. EU likes to portray itself as trustworthy - it largely is - but that doesn't mean there are no problems. EU governments can vastly differ in quality , you just happen to hear from the most accountable ones.
Re: Google and Facebook accused of breaking GDPR laws
#236Earlier quoted context omitted.
Nope thats actually true. You cant force say tracking, if its not absolutely needed, for the product to work. And i think thats why a lot of the popups have dark patterns, to hide the fact, that you can no opt out to these things.
Hmm, seems you are right, I just found this PDF from the ICO: https://ico.org.uk/media/about-the-ico/consultations/2013551... "Avoid making consent a precondition of a service" "consent requests must be separate from other terms and conditions. Consent should not be a precondition of signing up to a service unless necessary for that service" I assume Facebook et al will simply find a way to make everything 'necessary…
The legal basis that is probably FAR more important but isn't being talked about is the contractual basis, and there are two. When I say people are overusing "consent", I mean that entering into a contract requires ~consent~ in loose everyday conversation, but is actually not "consent" for the purposes of the GDPR - its a contract.
Because of the difference between the loose meanings in everyday conversation and the (slightly) more precise definitions in the GDPR, you are seeing a LOT of articles push back on using the consent basis for compliance because what you are actually talking about, in GDPR terms, is a contractual basis, or a "legitimate use" basis attached to a contractual basis.
Most online businesses view their Terms of Service as establishing a contract. Therefore, no "consent" required because you using their website is a contract, even though in loose conversation you would say that you ~consented~ to enter that contract.
The document you posted is consistent in trying to hammer home the distinction. Read this excerpt:
> The ‘consent’ is a condition of service
If you require someone to agree to processing as a condition of service, consent is unlikely to be the most appropriate lawful basis for the processing. In some circumstances it won’t even count as valid consent.
Instead, if you believe the processing is necessary for the service, the better lawful basis for processing is more likely to be that the “processing is necessary for the performance of a contract” under Article 6(1)(b). You are only likely to need to rely on consent if required to do so under another provision, such as for electronic marketing.
It may be that the processing is a condition of service but is not actually necessary for that service. If so, consent is not just inappropriate as a lawful basis, but presumed to be invalid as it is not freely given. In these circumstances, you would usually need to consider ‘legitimate interests’ under Article 6(1)(f) as your lawful basis for processing instead.
Re: Google and Facebook accused of breaking GDPR laws
#237Earlier quoted context omitted.
Sounds like a legal headache for anybody who wants to set up a personal blog or blog for their company, with a penalty of up to 20 million euros if you get it wrong.
What? You can setup log rotation in 1 minute. In 3 minutes you can write a small paragraph that explains you only use IP addresses for security reasons and only store them for a few weeks. Also, the claim that you immediately get the maximum fine of 20 million euro for every small detail that you get wrong, is false: https://www.joyfulbikeshedding.com/blog/2018-04-17-should-no... (claim backed up by a book written by…
Judge's discretion on the fine, and he probably won't like me.
Re: Google and Facebook accused of breaking GDPR laws
#238Earlier quoted context omitted.
It’s in the faq, you can’t be upset with people repeating it. https://www.eugdpr.org/gdpr-faqs.html [edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/refo...
"IP address" does not appear in that text.
Re: Google and Facebook accused of breaking GDPR laws
#239Earlier quoted context omitted.
Sign me up! The sad truth though is that the users who are most likely to pay to get rid of ads, are also the users that are most valuable to advertisers, because that's a signal they have more money to spend than the rest.
You can disable Google's ad targeting at any time: https://adssettings.google.com/ You don't have to pay anything. What you get instead is untargeted ads, like ads for cars, potato chips, and shampoo, just like on TV. Personally I find those to be a lot more annoying. Facebook's ad targeting can be similarly disabled under https://www.facebook.com/ads/preferences/?entry_product=ad_s...
I'm genuinely curious: what's so much more annoying to you about untargeted ads? I've never found targeting to be effective at showing me ads that were genuinely better or less annoying.
I feel more comfortable with untargeted ads, since I can be much more confident nothing truly sneaky is going on, especially technology ever gets good enough to reliably manipulate me to buy more now.
Re: Google and Facebook accused of breaking GDPR laws
#240Earlier quoted context omitted.
It’s in the faq, you can’t be upset with people repeating it. https://www.eugdpr.org/gdpr-faqs.html [edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/refo...
> This website ... is NOT an official EU Commission website.