Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

301–310 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#301
post #189

How does Facebook determine if a user resides in the EU? Based on the location that they give Facebook? Based on their IP address? Phone number?

Facebook has oodles of data on a massive percentage of their users. They have GPS data from the facebook app, from metadata in photos that are uploaded.

Re: Facebook to change user terms, limiting effect of EU privacy law

#302
post #234
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?

>> If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you?

By forcing EU ISPs to block your ip.

Re: Facebook to change user terms, limiting effect of EU privacy law

#303
post #293

Earlier quoted context omitted.

FATCA was designed to apply to non-US entities it provides clear definitions and channels on what to do and who do you work with, the GDPR has no functional models for non-EU entities.

Actually it kinda does... Article 27: "the controller or the processor shall designate in writing a representative in the Union"

No it's a joke article 27 says that you need to establish a presence in the union which isn't going to happen article 3 is also vague as hell.

Compare this to FATCA: https://www.irs.gov/businesses/corporations/foreign-account-...

And again FATCA and SOX applies to huge financial institutions that can afford all the lawyers in the world.

Say I make guitar picks and tuning forks in Zimbabwe I sell it online and I have costumers in the EU. I either need to comply with the GDPR which will be prohibitively expensive or will have to stop selling to EU customers.

The problem with the GDPR is that people don't understand both the inconsistency and the scope of it. Come 25th of May I'm sending a data access request letter to my dry cleaner which they will have to comply with within 30 days or face fines.

Re: Facebook to change user terms, limiting effect of EU privacy law

#304

Earlier quoted context omitted.

IP addresses aren't PII. If you're capturing IP + real name, or similar (email + real name) then AIUI you'll need to tell people on request who you sell that info to and allow removal. Assuming it's a personal blog then just don't capture any PII. Don't sell it, be prepared to delete a user's comments on request. Don't capture PII without informed consent. Easy, no?

> be prepared to delete a user's comments on request. Or, just block users from EU from commenting. I can see the win for the Internet here.

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#305

Earlier quoted context omitted.

I am not sure I follow you here: When I store your personal data, I should be allowed to do so under the 1st amendment that is about speech?

Yes. Like I can’t retroactively ask you to remove what I said from your blog post.

Isn't it like more that the state itself can't ask/force you to remove something, but i as a natural person can?

Re: Facebook to change user terms, limiting effect of EU privacy law

#306
post #296

Earlier quoted context omitted.

It’s not clear at all by this definition if I sell guitar picks on my personal store and I’m located in say Zimbabwe I’m either forbidden form selling it to the EU or will have to comply with the GDPR which can be prohibitive to me due to local laws. The GDPR isn’t clear only anything it rewrittes agreeable concepts of localization which have much more severe applications than simply the GDPR. It also provides zero c…

Laws are not always crystal clear in each case because to do so risks making them capable of being worked around (and of course in some cases they are just badly drafted - but I don't see this so much with GDPR). Laws are then subject to interpretation by the courts and by lawyers. If you're having issues with understanding laws, then you may need an expert to guide you, as in many areas of life. Recital 23 of GDPR w…

Yes laws are not crystal clear but you don't understand the problem because when laws are unclear in your country / union there is a clear channel to debate it which is the regulator and the courts this channels are not available to extra-territorial parties.

Add to that the fact that you now have laws enforced on you that you have no control on how they were written or are enforced because you are not part of the electorate that passed them.

International law is applied when 2 countries agree on a common set of rules in which case you have 2 representative electorates which are mediating an agreement.

The GDPR has no legal basis of application it's not part of any trade agreement or any other international agreement between the EU and other countries.

The claim that it somehow applicable is essentially tyrannical despite the intent of the law the means through which and the fact that people support it's universal application is terrifying.

What is even more terrifying is the likely means of enforcement which will be through the multinationals.

>The regulation is obviously available and there is a host of interpretative guidelines issued by the Article 29 Working Party which will enable anyone with enough time and desire to understand the implications of compliance. I'm not sure what kind of assistance you're looking for here? It's incumbent on the party who wants to operate in a country/provide services to users in that country to understand the relevant laws.

What are you even trying to say here? If I don't live in the EU, have no legal presence in the EU I have no means through which I must comply with the GDPR.

Mandating that I would create a local legal entity to serve as a proxy in a member state is a violation of existing trade agreements and WTO rules.

Enforcement of extra-territorial laws must be done through a process which is agreeable and understood by all parties.

>If you disagree with the extra-territorial application of the GDPR then that's a separate issue. Bringing international tax treatment into the discussion is also not of relevance.

This entire debate is about the extra-territorial application of the GDPR, bringing international tax treatment is super relevant because it's an established framework and it already establish things like localization which are critical for extra-territorial application that the GDPR must follow.

People really need to wake up and understand that the GDPR isn't about Facebook or eBay, Amazon or the likes it applies to them equally as it applies to your local dry cleaner or hair dresses which collect and process Personal Information as defined under the GDPR and are subject to the full extent of it's regulatory requirements.

What is more frighting is that through commerce of either tangible goods or services this regulation can be applied to non-EU entities in not only a extra-territorial fashion but in also extra-judicial one.

The reality is that either many small businesses or businesses regardless to which the volume of trade they have with the EU is less than the cost of compliance would likely be forced to stop offering services to EU consumers or switch to a proxy like well eBay or Amazon.

The scope of regulation like FATCA or SOX which were mentioned here as examples applies to institutions that can afford it and can handle it.

The GDPR applies to everyone equally, actually that isn't true if it applies to non-EU entities it doesn't apply equally it's much more costlier to them. If nothing else is then just by your ridiculous example "consult a lawyer" then a GDPR lawyer in Belgium or the UK would be fairly cheap since it's an established local law, to get the same level of advice and to get arbitration with a DPA in say Bolivia you can't go to an ambulance chaser you'll be limited to an international law firm. Not to mention that getting legal advice for such services can be achieved for free in the EU through the local DPA and or various organizations like Citizen Advice which provide legal assistance.

Re: Facebook to change user terms, limiting effect of EU privacy law

#307
post #280

Earlier quoted context omitted.

If your store front is accessible to EU based citizens then you have an EU presence.

The threshold for determining establishment is a low threshold however there will still be various factors taken into account in determining whether that establishment is there (for Art 3(1), and indeed whether goods and services are being offered to data subjects in the EU (for Art 3(2)). The mere availability of a website is not sufficient however to satisfy the above. Recital 23 below gives more details about thos…

Yes, I should have better specified "accessible". If you ship to those customers, and make that publicly known, that appears to satisfy the intent to provide service to that country?

Add on language and currency, basics of accessibility, and you're meeting the definition AFAICT.

Re: Facebook to change user terms, limiting effect of EU privacy law

#308
post #234
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?

It's an unlikely scenario - but block your domain, block bank transfers (not for small offenses, though). "Ask" any EU based payment providers (pretty much all have offices in the EU) to stop servicing you. You can use crypto currencies and the like but the inconvenience is there.

Then probably (or your employees) would not like to visit the countries there, etc.

Technically you should not be selling electronic services in the EU w/o EU VAT, so that already is sort of a breach... but no one chases so small fish.

Re: Facebook to change user terms, limiting effect of EU privacy law

#309

Earlier quoted context omitted.

The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. You actually have to keep their account active and make it work somehow. If you can't, then you are libel for a really huge penalty. I can't add enough smileys to that, so you will just have to imagine them.

> The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. That's actually pretty horrible. How about freedom of association and freedom to contract? These two are basic human rights. If one thinks their privacy rights are not respected they are free not to associate or contract and same thing for the entity on the other side of the con…

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#310
post #297
post #261

Earlier quoted context omitted.

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

So companies that are careless with personal data and get hacked get out of business? That sounds like a benefit! Within small companies, it's now easier to push for proper data security, for not being careless. "Boss, I know it'll slow down our release, but if we don't do it, we could go bankrupt!"

If I don't have a server in your country, I shouldn't be in your jurisdiction.

And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.

Post reply on HN