Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

261–270 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#261
post #139

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person.

This means that I can bankrupt small, careless companies that hold a few hundred users data?

Re: Facebook to change user terms, limiting effect of EU privacy law

#262

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

> If your startup is at odds with this, well then perhaps you're not the kind of company the EU wants to be doing business with.

The EU is not a single entity. It’s dozen of nations, more than 300M individuals.

Re: Facebook to change user terms, limiting effect of EU privacy law

#263

Earlier quoted context omitted.

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

IP addresses aren't PII. If you're capturing IP + real name, or similar (email + real name) then AIUI you'll need to tell people on request who you sell that info to and allow removal. Assuming it's a personal blog then just don't capture any PII. Don't sell it, be prepared to delete a user's comments on request. Don't capture PII without informed consent. Easy, no?

> be prepared to delete a user's comments on request.

Or, just block users from EU from commenting. I can see the win for the Internet here.

Re: Facebook to change user terms, limiting effect of EU privacy law

#264

Earlier quoted context omitted.

You missed the part about the blog comments. He would also need to implement a mechanism which allows users to delete their old comments.

The mechanism is they send you an email, you verify it as you wish (have them post a comment using their credentials), you overwrite all comments from that uid in the db with a simple query? If you're using a CMS then it's going to be type the username and hit "delete all comments"; maybe WordPress et al. do this already. With a small blog the administration of that is going to be facile, surely.

Sure it is facile. But it is a burden and a exposure to risk, which wont be worthwhile for the most non profit blogs.

And by the way, most blog comment systems don't require you to create an account before commenting. So this "have them post a comment using their credentials" wont work anyway.

Re: Facebook to change user terms, limiting effect of EU privacy law

#265

Earlier quoted context omitted.

The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. You actually have to keep their account active and make it work somehow. If you can't, then you are libel for a really huge penalty. I can't add enough smileys to that, so you will just have to imagine them.

Is that not only the case for consent as legal basis though? If you're signing up to a service, then surely they can use fulfilment of a contract (with some very expensive lawyers drafting some nice ToS language), or legitimate interests (i.e. argue that a social network relies on real names etc to function)? I see this turning into an in-app clicking contest though soon, a card comes up in the app with a little desc…

Yes there are two separate bases for processing of data, but the point is that consent cannot be bundled and made a precondition to another form of processing i.e. to provide a service.

Put another way, Facebook should not make the provision of a service (which technically should not require usage of data for other purposes i.e. marketing/advertising, ignoring any business model points) conditional upon providing consent for that other form of processing.

Bundling of consent means the consent is not freely given here because the user wants the service and so is less likely to refuse than if the consent decision was isolated from the provision of service.

Re: Facebook to change user terms, limiting effect of EU privacy law

#266

Earlier quoted context omitted.

The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. You actually have to keep their account active and make it work somehow. If you can't, then you are libel for a really huge penalty. I can't add enough smileys to that, so you will just have to imagine them.

> The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. That's actually pretty horrible. How about freedom of association and freedom to contract? These two are basic human rights. If one thinks their privacy rights are not respected they are free not to associate or contract and same thing for the entity on the other side of the con…

Freedom to contract isn't a basic human right, it also wouldn't affect companies acquiring my PII from third parties - as Facebook and the like did when harvesting address books.

In most (?) countries we deny the right to contract on many things, contracts that avoid taxation, contracts that involve selling human organs, contracts that make slaves.

It avoids power imbalances from causing desperate people to do things that dehumanise, disenfranchise, and devalue them.

Re: Facebook to change user terms, limiting effect of EU privacy law

#267

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

well if that is what they're doing it's not very useful, if I as a EU citizen do business with their US office they better follow the GDPR in relation to me or I'm going to mess with them.

Re: Facebook to change user terms, limiting effect of EU privacy law

#268

Earlier quoted context omitted.

We’re not talking about EU companies or entities but non-EU ones. In case of the EU you have your own local DPA other DPA local courts and high courts to appeal too and or work with. As a non-EU entity you get nothing.

You get the courts that the person you're servicing uses. Like when you sell to someone in a particular country and have to abide by their sales and tax laws.

That’s not true on both accounts EU courts have no jurisdiction over non-EU entities and there is no process on how to arbitrate a lawful retention requirement which trumps GDPR between EU and none EU entities.

As for the taxation part of your comment that is again an incorrect statement in fact it’s categoriclaly false.

If I as say a Brazillian company want to sell goods to an EU resident I do not perform any tax collection other than the local taxes in my country.

In fact it likely means that I can forgoe some local taxes like VAT or sales tax due to export.

You as the customer are obliged to pay all taxation related to this purchase which is usually paid when the item clears customs as the customs duty.

The only cases when one would collect tax on behalf of another country is when there is an explicit tax agreement to do so and process to support it. This is extremely rare and usually only happens within shared customs unions.

As a non-EU entity I legally can not collect VAT on behalf of EU customers because I have no way of paying that tax on their behalf.

Re: Facebook to change user terms, limiting effect of EU privacy law

#269

Earlier quoted context omitted.

"perhaps you're not the kind of company the EU wants to be doing business with" Europeans want Facebook and Google and the rest, the EU doesn't. The EU != the europeans. So international startups must now care more about what the EU wants than what european customers want. That's wrong. In the meantime, european governments take measures that jeopardise private life, like putting black boxes at ISPs in France to watc…

People living in the EU absolutely want control of the gathering of their PII. The only complaints I've seen about it are concerning people responsible for administrating data in companies. GDPR represents an ideology of not giving corporations free reign to make profits at any human/social cost, but to reign them in and give people chance to consent rather than be data-raped. Could you expand on how you think it's (…

> What's bad about informed consent wrt PII?

The cookie pop-up is an example of EU overeach. Doesn’t help privacy, doesn’t UI, and now everyone is just dismissing them.

Re: Facebook to change user terms, limiting effect of EU privacy law

#270

Earlier quoted context omitted.

"perhaps you're not the kind of company the EU wants to be doing business with" Europeans want Facebook and Google and the rest, the EU doesn't. The EU != the europeans. So international startups must now care more about what the EU wants than what european customers want. That's wrong. In the meantime, european governments take measures that jeopardise private life, like putting black boxes at ISPs in France to watc…

People living in the EU absolutely want control of the gathering of their PII. The only complaints I've seen about it are concerning people responsible for administrating data in companies. GDPR represents an ideology of not giving corporations free reign to make profits at any human/social cost, but to reign them in and give people chance to consent rather than be data-raped. Could you expand on how you think it's (…

> People living in the EU absolutely want control of the gathering of their PII.

I know everyone here wishes this to be true, but what data are you basing this claim on?

Post reply on HN