Earlier quoted context omitted.
So companies that are careless with personal data and get hacked get out of business? That sounds like a benefit! Within small companies, it's now easier to push for proper data security, for not being careless. "Boss, I know it'll slow down our release, but if we don't do it, we could go bankrupt!"
If I don't have a server in your country, I shouldn't be in your jurisdiction. And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.
Facebook to change user terms, limiting effect of EU privacy law
331–340 of 409 posts
Re: Facebook to change user terms, limiting effect of EU privacy law
#332Earlier quoted context omitted.
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…
> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?
The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such as Microsoft and Facebook. If you are a small organisation and you can show that you have and will continue to take meaningful steps towards protecting the data you hold and providing your users with transparency as to your processing, then the ICO and other regulatory authorities are not going to hit you with a 20M Euro fine [1].
I certainly feel as though the law is being perhaps misrepresented as some sort of anti-business regulatory overreach. I highly doubt the European Union wants to a) Drive businesses away from Europe and all that yummy tax money that they bring with them, or b) Piss off European consumers by restricting their access to all the fun things being provided by non-EU companies. It's not in the EUs interest to do either of those things, but there has to be a balance, right? The fact that organisations can collect huge amounts of personal data and when/if something happens just shrug it off (exaggeration, I'll admit). The current legislation doesn't give supervisory authorities (such as the ICO) enough of a bite to encourage compliance from larger companies. £500k (current fine limit) is nothing to an organisation that turns over billions a year globally. I'm sure in many of these circumstances the cost of compliance would far outweigh any fines handed out.
The debate here is very interesting though, as there are plenty of people viewing this from different angles. I wonder if some residents of non-EU countries here feel as though the EU (to them an unelected body) is effectively overruling their domestic legislation, and that this is not right. I can certainly understand the argument that whilst (in my opinion) this law could be overwhelmingly good for consumers, especially given the current climate, it could be viewed as setting a dangerous precedent for extraterritorial reach.
[1] https://iconewsblog.org.uk/2017/08/09/gdpr-sorting-the-fact-...
Re: Facebook to change user terms, limiting effect of EU privacy law
#333Earlier quoted context omitted.
If I don't have a server in your country, I shouldn't be in your jurisdiction. And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.
If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?
Re: Facebook to change user terms, limiting effect of EU privacy law
#334Earlier quoted context omitted.
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…
My counter example to this is that nobody in the US does the super annoying cookie popup thing that's required in the EU already - why would they do GDPR which is orders of magnitude more complicated.
Re: Facebook to change user terms, limiting effect of EU privacy law
#335Earlier quoted context omitted.
If I don't have a server in your country, I shouldn't be in your jurisdiction. And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.
Facebook almost certainly has servers, and subsidiaries, and staff in the EU
Facebook moves 1.5bn users out of reach of new European privacy law https://www.theguardian.com/technology/2018/apr/19/facebook-...
Re: Facebook to change user terms, limiting effect of EU privacy law
#336Earlier quoted context omitted.
> The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. That's actually pretty horrible. How about freedom of association and freedom to contract? These two are basic human rights. If one thinks their privacy rights are not respected they are free not to associate or contract and same thing for the entity on the other side of the con…
> If one thinks their privacy rights are not respected they are free not to associate or contract We tried that. It didn't work. > The basis of a free society is the freedom to contract You cannot write any contract as you want. They are limited, and for very good reasons. One example is indentured servitude. It's basically a contract you voluntarily sign that binds you to work for a party for a duration of time. Doe…
> We tried that. It didn't work.
It did and still does work. People freely give away their information, giving up their rights to privacy, in exchange for services they want. I really don't see what the big deal is, and GDPR is a massive overregulation.
Re: Facebook to change user terms, limiting effect of EU privacy law
#337Earlier quoted context omitted.
That’s not true on both accounts EU courts have no jurisdiction over non-EU entities and there is no process on how to arbitrate a lawful retention requirement which trumps GDPR between EU and none EU entities. As for the taxation part of your comment that is again an incorrect statement in fact it’s categoriclaly false. If I as say a Brazillian company want to sell goods to an EU resident I do not perform any tax co…
> As a non-EU entity I legally can not collect VAT on behalf of EU customers because I have no way of paying that tax on their behalf. That’s not how this works. You are required to collect VAT and use the MOSS system to pay it quarterly.
Even if by some chance you are a small business that for an inexplicable reason does fall under this you can get out of this scheme fairly easily (VAT exemption rules apply) and more importantly VAT can be handled by a proxy e.g. a payment processor.
For businesses there is no VAT collection at all and all businesses must pay reverse VAT when purchasing (or providing) services from (and to) outside of the EU regardless if they fall under TBES or not.
Re: Facebook to change user terms, limiting effect of EU privacy law
#338Earlier quoted context omitted.
The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…
IP addresses aren't PII. If you're capturing IP + real name, or similar (email + real name) then AIUI you'll need to tell people on request who you sell that info to and allow removal. Assuming it's a personal blog then just don't capture any PII. Don't sell it, be prepared to delete a user's comments on request. Don't capture PII without informed consent. Easy, no?
I personally think so, but everything I've read about GDPR says they usually now are considered in scope.
Deleting comments is non-trivial. How do I verify that the person requesting deletion is the original commenter? How do I then wipe out every mention of their IP address from all my logs?
These are easily solvable questions for large companies, but overheard for small startups and personal projects.
Re: Facebook to change user terms, limiting effect of EU privacy law
#339Earlier quoted context omitted.
The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…
IP by itself is not considered private. It's only when you attach it to other identifying data. Anonymous comments are not covered with GDPR.
There is no guarantee that comments stay anonymous. Commenters can, and do, enter their real name as their display name.
Re: Facebook to change user terms, limiting effect of EU privacy law
#340Earlier quoted context omitted.
That is a somewhat valid concern, but here in Denmark (EU) GDPR har actually been helpful to highlight some of the data collection by the state, and some of it, has been set on standby or at least been postponed because of concerns (student mental health/well beeing, was so to be registered, and stored on a SSN level “for research”)
Got any articles on that? I wonder what local agencies I could fuck with in my country thanks to GDPR :)