Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

291–300 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#291
post #261
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

The EU will retain its current ability to impose lower fines than the maximum, which I imagine they'll do in most cases where the fine would bankrupt a company unless the behavior is amazingly egregious (e.g. "We refuse to do the barest attempts to comply even after several warnings despite dealing very heavily with Europe and collecting lots of data").

That said, the existing legal precedents won't prevent the imposition of much larger fines when warranted after May 25, given the new law's higher maximums.

Re: Facebook to change user terms, limiting effect of EU privacy law

#292
post #234
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?

It might be worth specifying your co. is for US users only in your TOS until you are more attractive to European customers.

Re: Facebook to change user terms, limiting effect of EU privacy law

#293

Earlier quoted context omitted.

Not exactly correct. GDPR is closer to FATCA meaning — non US banks that deal with US citizens are subject to FATCA reporting IF they also have US assets. The penalty for a foreign bank not complying with FATCA is a penalty against US assets. A bank with zero US financial system exposure can’t be penalized under FATCA because they have nothing to penalize. FATCA only works because banks have exposure to US assets. Th…

FATCA was designed to apply to non-US entities it provides clear definitions and channels on what to do and who do you work with, the GDPR has no functional models for non-EU entities.

Actually it kinda does... Article 27: "the controller or the processor shall designate in writing a representative in the Union"

Re: Facebook to change user terms, limiting effect of EU privacy law

#294
post #178

Earlier quoted context omitted.

> freedom to contract I think you'll find this libertarian "right to enter into any contract for anything" doesn't exist in EU law. The Charter of Fundamental Rights doesn't list it. It does list the right to protection of personal data.

Pretty sure Freedom of association is at least part of French constitution https://fr.wikipedia.org/wiki/D%C3%A9cision_Libert%C3%A9_d%2...

Article 12 of the Charter of Fundamental Rights of the EU has a freedom of association:

> 1. Everyone has the right to freedom of peaceful assembly and to freedom of association at all levels, in particular in political, trade union and civic matters, which implies the right of everyone to form and to join trade unions for the protection of his or her interests.

But I don't think the person I'm replying to above was thinking of labour unions. ;)

Re: Facebook to change user terms, limiting effect of EU privacy law

#295
post #157

Earlier quoted context omitted.

I predict Max Schrems will continue his legal cases against Facebook. He has co-founded an NGO (NOYB) which has raised €330k in donations & membership fees to use the GDPR to protect privacy. https://noyb.eu/

What does noyb mean? I can't see it anywhere and it's really frustrating me.

"None Of Your Business"

> What does "noyb" stand for? > > We use “noyb” as a brand name. The name was suggested by a twitter user, and is the abbreviation of “none of your business”, which fits quite well with the goals of “noyb”, because your privacy is none of a company´s business.

https://noyb.eu/faqs

Re: Facebook to change user terms, limiting effect of EU privacy law

#296
post #275

Earlier quoted context omitted.

Article 3 is clear about the scope of the regulation when an entity is outside the EU. It states that it will apply where that entity is offering goods/services or is monitoring data subjects in the EU. Enforcement is a separate matter but the underlying law is clear. Art 2 then contains general exceptions to the application of the regulation also.

It’s not clear at all by this definition if I sell guitar picks on my personal store and I’m located in say Zimbabwe I’m either forbidden form selling it to the EU or will have to comply with the GDPR which can be prohibitive to me due to local laws. The GDPR isn’t clear only anything it rewrittes agreeable concepts of localization which have much more severe applications than simply the GDPR. It also provides zero c…

Laws are not always crystal clear in each case because to do so risks making them capable of being worked around (and of course in some cases they are just badly drafted - but I don't see this so much with GDPR). Laws are then subject to interpretation by the courts and by lawyers. If you're having issues with understanding laws, then you may need an expert to guide you, as in many areas of life.

Recital 23 of GDPR will give you insight into how your Zimbabwean guitar pick seller would be treated. If they are consciously offering picks to data subjects in the EU, either through specifically referencing EU data subjects, or through offering picks in EU currencies or tailoring the site for different European languages, then they are likely in scope.

Conflict of laws provisions are a separate point, however in various areas, the GDPR expressly states that legal obligations override GDPR obligations in various areas.

Whenever any company considers that a law may apply to them (whether as a result of operating in the country or because of the extra-territorial implications of certain laws, like GDPR) they generally take advice from local lawyers as to the implications or do independent research.

The regulation is obviously available and there is a host of interpretative guidelines issued by the Article 29 Working Party which will enable anyone with enough time and desire to understand the implications of compliance. I'm not sure what kind of assistance you're looking for here? It's incumbent on the party who wants to operate in a country/provide services to users in that country to understand the relevant laws.

If you disagree with the extra-territorial application of the GDPR then that's a separate issue. Bringing international tax treatment into the discussion is also not of relevance.

Re: Facebook to change user terms, limiting effect of EU privacy law

#297
post #261
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

So companies that are careless with personal data and get hacked get out of business? That sounds like a benefit!

Within small companies, it's now easier to push for proper data security, for not being careless. "Boss, I know it'll slow down our release, but if we don't do it, we could go bankrupt!"

Re: Facebook to change user terms, limiting effect of EU privacy law

#298
post #234
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?

I don't know if they can.

But if you're a VC funded business aiming to "change the world" and grow big, then it might be a problem for you later.

Re: Facebook to change user terms, limiting effect of EU privacy law

#299

Earlier quoted context omitted.

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

> What aspects of the law are disastrous for startups?

Any law that gives power to users instead of companies harms companies.

To me, it's an acceptable trade off

Re: Facebook to change user terms, limiting effect of EU privacy law

#300

Earlier quoted context omitted.

I am not sure I follow you here: When I store your personal data, I should be allowed to do so under the 1st amendment that is about speech?

Yes. Like I can’t retroactively ask you to remove what I said from your blog post.

> Yes. Like I can’t retroactively ask you to remove what I said from your blog post.

No. But I can ask you to remove my name and personal information from it.

Post reply on HN