Live data from Hacker News

Facebook Locking Out GDPR Users Until They Consent

twitter.com

31–40 of 51 posts

Re: Facebook Locking Out GDPR Users Until They Consent

#31
Interesting that this coincides with his appearance to the EU parliament [0]?

What's most interesting to me, is that whilst many say this is flat out illegal under the GDPR. If after this appearance, i.e some form of lobbying to the EU. Whether it sets a new precedent?

If bigger companies can get away with this sort of action due to lobbying. Then smaller companies/startups will surely lose out as they are unable to match lobbying efforts and will result in not being able to be as competitive.

I'm very interested to see how things progress in the coming weeks. Whether there is an amendment (due to a backdown by Facebook) or this becomes the norm and other larger companies follow.

[0]: https://www.theguardian.com/technology/2018/may/22/european-...

Re: Facebook Locking Out GDPR Users Until They Consent

#32
post #24

If facebook is making >4% of its revenue from EU, then it's worth risking the fine.

As far as I know they can be fined multiple times until they comply with the law.

Not only that, the fines will get exponentially more severe for repeated non compliance.

Re: Facebook Locking Out GDPR Users Until They Consent

#33
post #32
post #24

Earlier quoted context omitted.

As far as I know they can be fined multiple times until they comply with the law.

Not only that, the fines will get exponentially more severe for repeated non compliance.

The maximum fine is 4% of revenue.

Re: Facebook Locking Out GDPR Users Until They Consent

#35

Since everything Facebook does requires consent under Article 6 (or, in some cases, Article 9) of the GDPR, what, exactly, should they do otherwise that would not violate clear proscriptions in the GDPR? This isn't a case where there is non-GDPR functionality that can be severed and provided in the absence of GDPR consent.

GDPR is quite unclear about..well...almost everything. But, for example, this guy wants to read his own messages, which is a rather popular use of Facebook. If they wanted to comply with GDPR, they could easily present him a dialog asking solely for permission to process the data necessary to show him his messages. Instead, they are asking for his consent to their entire new privacy policy. That policy includes permi…

To be the advocate of the devil: Facebook might claim that presenting targeted ads to users is their core business - if they stop doing that they will have no source of income.

From what I understand GDPR it allows data processing if this is needed to do the business, as it is in case of Facebook, so if someone refuses to agree for that, such person cannot use FB.

Re: Facebook Locking Out GDPR Users Until They Consent

#36
post #35

Earlier quoted context omitted.

GDPR is quite unclear about..well...almost everything. But, for example, this guy wants to read his own messages, which is a rather popular use of Facebook. If they wanted to comply with GDPR, they could easily present him a dialog asking solely for permission to process the data necessary to show him his messages. Instead, they are asking for his consent to their entire new privacy policy. That policy includes permi…

To be the advocate of the devil: Facebook might claim that presenting targeted ads to users is their core business - if they stop doing that they will have no source of income. From what I understand GDPR it allows data processing if this is needed to do the business, as it is in case of Facebook, so if someone refuses to agree for that, such person cannot use FB.

If they renamed themselves to Adbook and explicitly claimed their service is to offer targeted ads instead of being a social network, they might have a case, unfortunately their service is to offer a social network and they don't need to track me or offer ads in order to provide it. They need to do that in order to make money, which is a completely separate issue.

Re: Facebook Locking Out GDPR Users Until They Consent

#37
post #10

They're doing this with WhatsApp, too. WhatsApp is a dead-end at this point anyway, as they plan on removing end-to-end encryption. That's why both of WhatsApp's founders and many other employees have started leaving the company.

Citation needed.

I haven't seen this on WhatsApp.

Re: Facebook Locking Out GDPR Users Until They Consent

#38

Since everything Facebook does requires consent under Article 6 (or, in some cases, Article 9) of the GDPR, what, exactly, should they do otherwise that would not violate clear proscriptions in the GDPR? This isn't a case where there is non-GDPR functionality that can be severed and provided in the absence of GDPR consent.

GDPR is quite unclear about..well...almost everything. But, for example, this guy wants to read his own messages, which is a rather popular use of Facebook. If they wanted to comply with GDPR, they could easily present him a dialog asking solely for permission to process the data necessary to show him his messages. Instead, they are asking for his consent to their entire new privacy policy. That policy includes permi…

> But, for example, this guy wants to read his own messages, which is a rather popular use of Facebook. If they wanted to comply with GDPR, they could easily present him a dialog asking solely for permission to process the data necessary to show him his messages.

The normal operation of Facebook processes a lot of your information between login attempts, and not in direct response to yoour action; if they haven't gotten consent that satisfies the GDPR for that before May 25, they need to stop processing your information, which means they need to essentially completely disable and isolate your account, not just from you logging in, but from all visibility and interaction initiated by other parties.

While, in the abstract, a service they processes your information only in direct and immediate response to your UI interactions could adopt a granular permission model and seek consent for just what was necessary to handle each control interaction when you interacted with the relevant control (crappy UX, but it's possible), that's not the way Facebook works, nor is it something it seems Facebook could, with reasonable effort, be reengineered into. I'm not even sure pausing aall processing of your data until consent is received without deleting your account is something Facebook could reasonably be reengineered to do.

“Consent or delete your account” doesn't seem all that far from the choices Facebook practically has under the GDPR.

Re: Facebook Locking Out GDPR Users Until They Consent

#39

A ‘clever’ strategy would be if they required consent now, before the new rules kick in, and then later made it optional. Most users won’t go back and change the permissions anyway.

The rules have been active for over two years, it's just that they have not been enforceable. So that's not a clever strategy at all.

Re: Facebook Locking Out GDPR Users Until They Consent

#40

A ‘clever’ strategy would be if they required consent now, before the new rules kick in, and then later made it optional. Most users won’t go back and change the permissions anyway.

I don't think it works like this. If your argument for GDPR compliance is that you have your user's consent, it is required that the consent was freely given, when it was collected is orthogonal to that.
Post reply on HN