Earlier quoted context omitted.
The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.
And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...
Facebook to change user terms, limiting effect of EU privacy law
281–290 of 409 posts
Re: Facebook to change user terms, limiting effect of EU privacy law
#282Earlier quoted context omitted.
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…
> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?
Re: Facebook to change user terms, limiting effect of EU privacy law
#283Earlier quoted context omitted.
They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…
> (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work If the blog is purely personal the GDPR does not apply. https://ico.org.uk/media/for-organisations/data-protection-r... > The GDPR does not apply to certain activities including processing covered by the Law Enforcement Directive, processing for national security purposes and processing carried out by individuals purely f…
IANAL but for me this doesn't sound like a blog, open to the public, maybe even with a public commenting system, would be freed from the burden of the GDPR.
IPs "can be", not "is" personal data
It doesn't help you that IPs are not always personal data, as soon as they can be, you have a problem if you store them.
Re: Facebook to change user terms, limiting effect of EU privacy law
#284Earlier quoted context omitted.
Doesn't apply. If you resign from your job, you stop being paid. If you try and resign from the Armed Forces, you're put in prison at best.
You absolutely can resign from the Armed Forces, otherwise how would there be veterans? The only difference is that you cannot resign mid-operation.
You can't resign from conscription, some countries have a system whereby conscripts could serve non-combat roles; but usually it's fight or death/imprisonment.
Apparently Germany had general conscription from 1935, but with lots of exceptions. By 1943 all men up to 60 were being conscripted. Follow orders or face a firing squad.
Re: Facebook to change user terms, limiting effect of EU privacy law
#285Earlier quoted context omitted.
Well the GDPR doesn’t define that it applies to anyone who touches PII belonging to EU residents. The logic dictates is that it won’t apply to companies that simply dont have any legal presence in the EU. But that is not defined because again there are no exceptions. However PayPal might enforce it on you in fear of the EU going after PayPal because it’s expected that all EU companies would require GDPR compliance fr…
Article 3 is clear about the scope of the regulation when an entity is outside the EU. It states that it will apply where that entity is offering goods/services or is monitoring data subjects in the EU. Enforcement is a separate matter but the underlying law is clear. Art 2 then contains general exceptions to the application of the regulation also.
The GDPR isn’t clear only anything it rewrittes agreeable concepts of localization which have much more severe applications than simply the GDPR.
It also provides zero channels and infrastructure for non-EU entities to comply to the GDPR in a manner which is offered to local EU companies.
If the GDPR would define its scope as if I can buy form you you must comply what stops the EU form mandating I must collect VAT on their behalf?
Re: Facebook to change user terms, limiting effect of EU privacy law
#286Earlier quoted context omitted.
By people located you mean residents? Just to be more specific.
No, just that's where they are. The law says a US citizen who happens to be in Berlin (maybe on vacation) is subject to German law. Fine says GDPR, I'm EU law, so I apply to that US citizen too.
Re: Facebook to change user terms, limiting effect of EU privacy law
#287Earlier quoted context omitted.
In light of recent revelations about the way social media companies treat their users’ data and privacy, strong regulation is not “overreach” but “overdue”.
The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.
My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is leaked?
On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. If you're outside the EU, GDPR will only apply if you are actually offering goods/services to those in the Union, or are monitoring them. I take the point about analytics in the second place, but in the absence of analytics, I don't see that making available a blog constitutes the offering of goods/services?
Re: Facebook to change user terms, limiting effect of EU privacy law
#288Earlier quoted context omitted.
> my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to me. In the U.S., freedom of speech usually trumps privacy rights. It will be very damageable if the supreme court ruled that any EU citizen can limit US speeches based on their laws.
I am not sure I follow you here: When I store your personal data, I should be allowed to do so under the 1st amendment that is about speech?
Re: Facebook to change user terms, limiting effect of EU privacy law
#289Earlier quoted context omitted.
I don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like…
So, given that there's no DPA in the US (as far as I'm aware, there are also none in China, India, Australia, etc), how would the GDPR be enforced against an entity with no physical presence in the EU?
PayPal could tell you you must comply to accept payments form the EU and likely in the same manner they handle everything which means no guidance, benchmarks or clear directions and it would be up to you to figure it out.
By PayPal I don’t mean just PayPal but any other payment processor or service provider which you are dependent on.
Re: Facebook to change user terms, limiting effect of EU privacy law
#290Earlier quoted context omitted.
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…
> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?