Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

271–280 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#271
post #244

Earlier quoted context omitted.

However, is it not thought that because the ISP keeps a log of dynamic IP addresses, these could (in theory) be matched to the IP address of anonymous comments, thus de-anonymise them?

No, because you need to take into account the effort needed to de-anonymise the IP address. > > (26) The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable na…

This article makes a compelling argument that it could be: http://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip-...

IANAL, but I'd be wary of saying that you'll be fine storing dynamic IP addresses. You'll probably need to have a rationale as to why you don't consider it.

Re: Facebook to change user terms, limiting effect of EU privacy law

#272

Earlier quoted context omitted.

He can also just choose to not log ip addresses.

Not logging IPs makes debugging and abuse detection much more challenging. Moreover, it is also the current default in most software which touches HTTP requests.

We could make it easier for states to find and prosecute criminals by not requiring warrants and making encryption illegal, but we don't (and we shouldn't) because the peoples' rights are inalienable, whereas the rights of states, corporations and other entities to interfere with that privacy are not.

Yes, it would be more challenging, and inconvenient, and probably a massive pain in the ass not to log IPs by default, but if the end result is a weakening of the power of modern social media companies (and political and law enforcement agencies) to exploit people's data for nefarious ends without consequence, then society as a whole, and the web, benefit.

Mind you, I don't necessarily believe GDPR is the solution, or that logging IPs is unreasonable, but I do welcome the conversation people seem to be having about who owns their identity.

Re: Facebook to change user terms, limiting effect of EU privacy law

#273
post #157

Earlier quoted context omitted.

I predict Max Schrems will continue his legal cases against Facebook. He has co-founded an NGO (NOYB) which has raised €330k in donations & membership fees to use the GDPR to protect privacy. https://noyb.eu/

What does noyb mean? I can't see it anywhere and it's really frustrating me.

I'm afraid that's none of your business, Mr Fastball.

Re: Facebook to change user terms, limiting effect of EU privacy law

#274

Earlier quoted context omitted.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

> my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to me. In the U.S., freedom of speech usually trumps privacy rights. It will be very damageable if the supreme court ruled that any EU citizen can limit US speeches based on their laws.

I am not sure I follow you here:

When I store your personal data, I should be allowed to do so under the 1st amendment that is about speech?

Re: Facebook to change user terms, limiting effect of EU privacy law

#275

Earlier quoted context omitted.

I'm not a lawyer, but I would think your Argentina company can be in one of 2 states: 1. You have a subsidiary in EU, in which case that is who will get fined or will have to deal with the DPA where it is registered 2. You don't, in which case the EU can not fine you?

Well the GDPR doesn’t define that it applies to anyone who touches PII belonging to EU residents. The logic dictates is that it won’t apply to companies that simply dont have any legal presence in the EU. But that is not defined because again there are no exceptions. However PayPal might enforce it on you in fear of the EU going after PayPal because it’s expected that all EU companies would require GDPR compliance fr…

Article 3 is clear about the scope of the regulation when an entity is outside the EU. It states that it will apply where that entity is offering goods/services or is monitoring data subjects in the EU. Enforcement is a separate matter but the underlying law is clear. Art 2 then contains general exceptions to the application of the regulation also.

Re: Facebook to change user terms, limiting effect of EU privacy law

#276
post #8

I don't use Facebook, but could one build a service that automatically sets Facebook's privacy settings to sensible options? A large part of the problem is that changing these through the web site is painful in the extreme. I suppose I'm asking if their API provides read/write access to privacy settings. If so, there's a big opportunity here. More generally, I'd like to see governments mandate that all FB user's priv…

Do you consider your privacy settings your personal information? Do you believe companies should just be exposing that kind of information to random other companies through an api?

I'd expect that kind of answer from Facebook, in some sunny fake-sincere wording. I mean - they shadow-profile you for security reasons!

Re: Facebook to change user terms, limiting effect of EU privacy law

#277

Earlier quoted context omitted.

I don't think any of this is entirely clear, but from my understanding it seems like the EU wants to apply GDPR even if you don't have an EU presence. In practice, I doubt that they'd get the US to enforce judgements. But it might mean that I can never risk going to Europe again lest I risk having a default judgement enforced against me for one of my businesses.

If your store front is accessible to EU based citizens then you have an EU presence.

No if you aren’t a legal entity in the EU you have no presence in the EU.

If you would push for this the only thing that would happen is that companies would stop accepting orders from the EU.

If this is going to be the definition expect a lot of store fronts to be closed to EU residents following May 25th or more likely the first time this precedence will be set in court.

Re: Facebook to change user terms, limiting effect of EU privacy law

#278
post #239

Earlier quoted context omitted.

You missed the part about the blog comments. He would also need to implement a mechanism which allows users to delete their old comments.

Not to stretch out this comment any more, but are we seriously arguing that adding a delete button is hard? I mean, most people on here would agree that its not something they would worry about. It sounds more like people are upset they are forced to do it, and have no say in it.

We argue why putting people in jail for not implementing a delete button is regulatory overeach.

Re: Facebook to change user terms, limiting effect of EU privacy law

#279
post #93

Earlier quoted context omitted.

Do you consider your privacy settings your personal information? Do you believe companies should just be exposing that kind of information to random other companies through an api?

You could use the OAuth authentication API and let the user consciously giving user settings access to the service. As long as the service doesn't do anything with that data the agreement with the user doesn't permit, and the data is deleted upon the user's request, the service is GDPR compliant.

Impossible for technical reasons, like data sharing between WhatsApp and Facebook proper. /s

Re: Facebook to change user terms, limiting effect of EU privacy law

#280

Earlier quoted context omitted.

I don't think any of this is entirely clear, but from my understanding it seems like the EU wants to apply GDPR even if you don't have an EU presence. In practice, I doubt that they'd get the US to enforce judgements. But it might mean that I can never risk going to Europe again lest I risk having a default judgement enforced against me for one of my businesses.

If your store front is accessible to EU based citizens then you have an EU presence.

The threshold for determining establishment is a low threshold however there will still be various factors taken into account in determining whether that establishment is there (for Art 3(1), and indeed whether goods and services are being offered to data subjects in the EU (for Art 3(2)).

The mere availability of a website is not sufficient however to satisfy the above. Recital 23 below gives more details about those factors:

  *Whereas the mere accessibility of the controller's, 
  processor's or an intermediary's website in the Union, of 
  an email address or of other contact details, or the use 
  of a language generally used in the third country where 
  the controller is established, is insufficient to 
  ascertain such intention, factors such as the use of a 
  language or a currency generally used in one or more 
  Member States with the possibility of ordering goods and 
  services in that other language, or the mentioning of 
  customers or users who are in the Union, may make it 
  apparent that the controller envisages offering goods or 
  services to data subjects in the Union.*
Post reply on HN