Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

341–350 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#341
post #337
post #336

Earlier quoted context omitted.

Google's revenue is all about data collection. If they can't collect lots of data, the whole business model is a lot more questionable. In the face of that, 2.4bn once is a trivial fine; consider that that's something like what... 3% of their revenue in one year? Of course they'll try to avoid that in the future, but the fine is mild enough that it's not going to cause firms to err on the side of caution. They're goi…

Did you even read my post? It wasn't €2.4bn once, it was that PLUS €10m PER DAY of persistent non compliance. That would have come to €3.6bn per year. The lump sum was just for backdated non compliance.

I read that: the point is that 2.4bn just isn't all that much given what it does to the value of the company. It's probably a risk worth taking as long as you can get away with it. And yes; that means you'll need to eventually adapt - not because 10m a day is necessarily enough to actually enforce that, but also because this kind of stuff is gamable; complying with the ruling without much risk of competition at this point is pretty easy. And you'd need to make the calculation that even if 10m a day were acceptable for the gain, simply ignoring high-profile judgments against you may have worse ramifications down the line.

I'm not saying it's nothing: it's that it's a risk worth taking given the gains. If you're building a trillion dollar company (i.e. google), then eliminating competition or accepting some judicial friction as a way to establish dominance in your (data-mining) field is perhaps acceptable or even wise.

In that, these fines simply aren't punitive enough, especially since they come so late. And again - it's not black and white. The existence of such rules will alter behavior; it's just a question of whether the reaction will be legal mitigation tactics, a company-wide change in approach, or something in between.

Put it this way: if you can corner a market worth trillions, risking how much loss is acceptable to reduce or eliminate competition? I'd venture that these fines are at least one order of magnitude too small to be really frightening (which isn't to say that the behavior google was convicted for deserves that amount, simply that anything less than that means that law can't really be enforced)

Re: How the GDPR Will Disrupt Google and Facebook

#342
post #41

I see this as yet another tax on (European) startups who have to invest even more resources into regulatory compliance. This prohibition of freely using all available data will create great arbitrage opportunity for the shadow economy, and will have a net negative effect on innovation. I think prohibition has very bad side effects, and that MORE transparency is the way forward in politics, economy, and also society.…

As an EU citizen I don't really care about a definition of innovation that involves monetizing my data against my will or knowledge. That's not innovation it's exploitation. So I won't miss your business. There are all kinds of 'innovations' that don't involve collecting data about me, and the companies creating these kinds of products don't have to care one lick about the GDPR.

Considering the usage of Google in Europe I'd say you're in a small minority. Most people agree that what Google has done is innovation.

Re: How the GDPR Will Disrupt Google and Facebook

#343

> The critical question for both businesses is whether users will click “yes”, when asked to consent. Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's…

This is not even the fault of users. As a user, I want to get to the webpage I'm opening. I'll do whatever it takes to quickly reach there. I think "what's the worst they could have written". After all I haven't paid them anything. Expecting free users of Facebook to analyze a prompt on screen and legally consent to it is utter stupidity. Most people believe that clicking a checkbox isn't even legally binding.

In other words I know that clicking on a Facebook dialog box saying "you agree to give us 50% of your income" is meaningless and so I will click on it and use the website.

Re: How the GDPR Will Disrupt Google and Facebook

#344
post #166
post #18

Earlier quoted context omitted.

If you want to opt out of data collection, it's not that hard, just go to google.com/privacy

I don't login and regularly clear my cookies (pretty much whenever the first targeted ad gets past my adblocker). I wonder if there is a browser extension that will auto-opt-out of all 1,000,000 (or whatever) trackers on the internet each time you clear cookies.

You can use ghostery.

Re: How the GDPR Will Disrupt Google and Facebook

#345
post #180

My first instinct was to be pretty happy about these laws, which surprised me quite a bit. I generally identify on the libertarian/pro-capitalist side of things and "as a general rule" subscribe to the belief that government regulations are often more problematic than problem solving[0]. So I had to take a moment to analyse why I felt this way. Here's the problem as I see it: I know all of the things that are collect…

Just want to say that any emails I receive are my property. And I can grant consent to Google allowing them to mine these emails. Once you send an email, you are ceding control to the recipient.

Re: How the GDPR Will Disrupt Google and Facebook

#346

Earlier quoted context omitted.

> It's every photo in Facebook's entire database that ever included a recognisable image of them, tagged or not. That is from my understanding wrong. In fact Facebook would not be permitted to establish the link. Just you appearing in the picture but it not being your picture does not qualify for personal data.

Any information that relates to an identified or identifiable natural person is personal data for these purposes. This remains essentially the same, except for a slightly broader specification of what constitutes identifiability, under the GDPR as under the current EU framework. In particular, under the GDPR, identifiers explicitly include factors specific to a person's physical or genetic identity. In short, if you'…

I'm sorry but you are wrong about that. The data is fundamentally scoped.

Re: How the GDPR Will Disrupt Google and Facebook

#347

Earlier quoted context omitted.

Economically, EU will be substantially smaller than the US after the UK leaves.

That's far from accurate. The U.K. currently represents around 15% of the EU GDP, which was around 15% higher than that of the US on its own (that includes Norway and Switzerland which are not member but allow me to pencil them in) If by substantially smaller you mean 'pretty much the same size' then yes you're right.

I think that if you're penciling in Norway and Switzerland, Canada should be penciled in for the US.

https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(PPP) is pretty clear:

2016 GDP (PPP) figures: US $18.6T, EU $19.7T (6% higher than US), UK $2.8T, EU - UK $16.9T (10% lower than US)

Re: How the GDPR Will Disrupt Google and Facebook

#348
post #165
post #161

Earlier quoted context omitted.

>Does that mean you avoid services like facebook or google? No. Can't. I can't do my job without Google and my social life wouldn't survive without Facebook (messenger, groups, events). Using these services is not voluntary at this point.

>Using these services is not voluntary at this point. Of course it is. You just don't want to because it's not convenient.

Eating food is not mandatory either, but it's very convenient.

Re: How the GDPR Will Disrupt Google and Facebook

#349

Earlier quoted context omitted.

Any information that relates to an identified or identifiable natural person is personal data for these purposes. This remains essentially the same, except for a slightly broader specification of what constitutes identifiability, under the GDPR as under the current EU framework. In particular, under the GDPR, identifiers explicitly include factors specific to a person's physical or genetic identity. In short, if you'…

I'm sorry but you are wrong about that. The data is fundamentally scoped.

I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here.

However, the wording I used before was actually taken directly from the GDPR itself[1].

Moreover, the interpretation that an otherwise unidentified image of someone may become personal data even if collected incidentally such as in a photo taken for other purposes or on CCTV is supported by among others the ICO (the UK's data protection regulator). There are a few specific examples in some of their published guidance [2,3,4].

Unless your argument is that Facebook isn't processing those photos in any way that would cause that interpretation to apply? In that case, I can maybe see how your argument works, but given what we know of Facebook processing uploaded photos just from the features they offer publicly, it's hard to imagine how their processing could possibly not be sufficient for all photos they hold to be treated as personal data.

[1] http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN..., Article 4, clause (1), where "personal data" is defined

[2] https://ico.org.uk/media/for-organisations/documents/1554/de...

[3] https://ico.org.uk/for-the-public/schools/photos

[4] https://ico.org.uk/for-the-public/cctv/

Re: How the GDPR Will Disrupt Google and Facebook

#350

Earlier quoted context omitted.

I'm sorry but you are wrong about that. The data is fundamentally scoped.

I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here. However, the wording I used before was actually taken directly from the GDPR itself[1]. Moreover, the interpretation that an otherwise unidentified image of someone may become personal data even if collected incidentally such as in a photo taken for other purposes or on CCTV is supported by amo…

> I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here.

If you have a social network and you have a user A and a user B. Each of them uploads a picture in private showing both of the users on the image. If user A deletes his or her account the picture in user B's account is not to be deleted even though it contains a picture of user A.

Post reply on HN