Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

281–290 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#281

Earlier quoted context omitted.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...

There are plenty of laws and legal instruments / concepts (controlling stake, anti-avoidance laws, etc) that stop large companies from doing this.

Re: Facebook to change user terms, limiting effect of EU privacy law

#282
post #261
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#283
post #240

Earlier quoted context omitted.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

> (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work If the blog is purely personal the GDPR does not apply. https://ico.org.uk/media/for-organisations/data-protection-r... > The GDPR does not apply to certain activities including processing covered by the Law Enforcement Directive, processing for national security purposes and processing carried out by individuals purely f…

"purely for personal/household activities."

IANAL but for me this doesn't sound like a blog, open to the public, maybe even with a public commenting system, would be freed from the burden of the GDPR.

IPs "can be", not "is" personal data

It doesn't help you that IPs are not always personal data, as soon as they can be, you have a problem if you store them.

Re: Facebook to change user terms, limiting effect of EU privacy law

#284

Earlier quoted context omitted.

Doesn't apply. If you resign from your job, you stop being paid. If you try and resign from the Armed Forces, you're put in prison at best.

You absolutely can resign from the Armed Forces, otherwise how would there be veterans? The only difference is that you cannot resign mid-operation.

Veterans may have retired (different to resigning), or been demobilised (like being made redundant).

You can't resign from conscription, some countries have a system whereby conscripts could serve non-combat roles; but usually it's fight or death/imprisonment.

Apparently Germany had general conscription from 1935, but with lots of exceptions. By 1943 all men up to 60 were being conscripted. Follow orders or face a firing squad.

Re: Facebook to change user terms, limiting effect of EU privacy law

#285
post #275

Earlier quoted context omitted.

Well the GDPR doesn’t define that it applies to anyone who touches PII belonging to EU residents. The logic dictates is that it won’t apply to companies that simply dont have any legal presence in the EU. But that is not defined because again there are no exceptions. However PayPal might enforce it on you in fear of the EU going after PayPal because it’s expected that all EU companies would require GDPR compliance fr…

Article 3 is clear about the scope of the regulation when an entity is outside the EU. It states that it will apply where that entity is offering goods/services or is monitoring data subjects in the EU. Enforcement is a separate matter but the underlying law is clear. Art 2 then contains general exceptions to the application of the regulation also.

It’s not clear at all by this definition if I sell guitar picks on my personal store and I’m located in say Zimbabwe I’m either forbidden form selling it to the EU or will have to comply with the GDPR which can be prohibitive to me due to local laws.

The GDPR isn’t clear only anything it rewrittes agreeable concepts of localization which have much more severe applications than simply the GDPR.

It also provides zero channels and infrastructure for non-EU entities to comply to the GDPR in a manner which is offered to local EU companies.

If the GDPR would define its scope as if I can buy form you you must comply what stops the EU form mandating I must collect VAT on their behalf?

Re: Facebook to change user terms, limiting effect of EU privacy law

#286
post #91

Earlier quoted context omitted.

By people located you mean residents? Just to be more specific.

No, just that's where they are. The law says a US citizen who happens to be in Berlin (maybe on vacation) is subject to German law. Fine says GDPR, I'm EU law, so I apply to that US citizen too.

The gdpr only applies to EU residents. People here on tourist visas are visitors not residents.

Re: Facebook to change user terms, limiting effect of EU privacy law

#287

Earlier quoted context omitted.

In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

It would be a shame to take down your old blogs as I'm sure people get value from them.

My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is leaked?

On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. If you're outside the EU, GDPR will only apply if you are actually offering goods/services to those in the Union, or are monitoring them. I take the point about analytics in the second place, but in the absence of analytics, I don't see that making available a blog constitutes the offering of goods/services?

Re: Facebook to change user terms, limiting effect of EU privacy law

#288

Earlier quoted context omitted.

> my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to me. In the U.S., freedom of speech usually trumps privacy rights. It will be very damageable if the supreme court ruled that any EU citizen can limit US speeches based on their laws.

I am not sure I follow you here: When I store your personal data, I should be allowed to do so under the 1st amendment that is about speech?

Yes. Like I can’t retroactively ask you to remove what I said from your blog post.

Re: Facebook to change user terms, limiting effect of EU privacy law

#289
post #253

Earlier quoted context omitted.

I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…

So, given that there's no DPA in the US (as far as I'm aware, there are also none in China, India, Australia, etc), how would the GDPR be enforced against an entity with no physical presence in the EU?

On paper it can’t. In practice since the EU expects EU entities to essentially mandate GDPR compliance form their non-EU partners in order to be complaint it’s is pretty simple at least for ecommerce.

PayPal could tell you you must comply to accept payments form the EU and likely in the same manner they handle everything which means no guidance, benchmarks or clear directions and it would be up to you to figure it out.

By PayPal I don’t mean just PayPal but any other payment processor or service provider which you are dependent on.

Re: Facebook to change user terms, limiting effect of EU privacy law

#290
post #261
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

Yes, because they hold user data and are careless.
Post reply on HN