Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

341–350 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#341

Earlier quoted context omitted.

Yes. Like I can’t retroactively ask you to remove what I said from your blog post.

> Yes. Like I can’t retroactively ask you to remove what I said from your blog post. No. But I can ask you to remove my name and personal information from it.

That's precisely the problem and is a clear example of how Europeans value privacy differently.

Personally, I think it is a fundamentally important right that I be able to post a blog about how "the_mitsuhiko wronged me" in some way and have that information publicly accessible. European courts think you should be able to suppress such information—even if it is true.

Re: Facebook to change user terms, limiting effect of EU privacy law

#342

Earlier quoted context omitted.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...

And that is just as "possible" under the current structure of GDPR.

Re: Facebook to change user terms, limiting effect of EU privacy law

#343
post #287

Earlier quoted context omitted.

The law could have easily been tailored to target large social media companies. Instead it applies to everyone , including tiny businesses who accidentally have one European visitor. I'm strongly considering simply taking down all my old blogs/sites because it's far too much work to deal with GDPR for anything less than a medium-sized business.

It would be a shame to take down your old blogs as I'm sure people get value from them. My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is…

> My approach is one very much based on risk

Mine too. The risk is massive fines, while I currently derive virtually no benefit from my online presence.

> On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event.

I also own a business and previously several of my clients have come through my blog postings.

Re: Facebook to change user terms, limiting effect of EU privacy law

#344

Earlier quoted context omitted.

They have provided a real-world example elsewhere in the thread. It really seems to support their point: "Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simpl…

Well, he is not a company. So he doesn't need to do anything. If it's a personal website GDPR does not apply. If it is a company. Yes, it will require more work. That is the nature of regulation, but the demands placed on companies are not unreasonable in any way. I would place it on the same level as stores being required to provide receipts, or restaurants being required to clean the kitchen. It certainly was easie…

My personal blog is registered to my company.

Restaurants being subject to local laws around hygiene makes sense. It would be far stranger for restaurants to be subject to health codes from across the world just because tourists occasionally visit.

I had no say in GDPR but am forced to comply, despite the overheard it entails without any actual benefit to user privacy (in my case).

Re: Facebook to change user terms, limiting effect of EU privacy law

#345
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

My counter example to this is that nobody in the US does the super annoying cookie popup thing that's required in the EU already - why would they do GDPR which is orders of magnitude more complicated.

My counter example is that I live in the US and I see that cookie popup seemingly almost everywhere I go.

Re: Facebook to change user terms, limiting effect of EU privacy law

#346
post #239

Earlier quoted context omitted.

Not to stretch out this comment any more, but are we seriously arguing that adding a delete button is hard? I mean, most people on here would agree that its not something they would worry about. It sounds more like people are upset they are forced to do it, and have no say in it.

How want you add a delete button with out adding a complete login system? Or do you want to allow everybody to delete every comment? And of course this is also doable, but the question is, is it worth for a non profit (non tracking) blog? Probably not. Is it worth for Facebook and Google? Sure.

Exactly. I'm not arguing it's impossible, but that it imposes a meaningful additional burden on small operators without any real benefit to privacy.

Personally, I don't even think people should have the right to go back and delete a comment from years ago, which might have started a whole interesting discussion. But the EU requires that I think through such a system, including finding a way to identify them as the commenter and purge their PII from all logs/backups/caches as well.

Re: Facebook to change user terms, limiting effect of EU privacy law

#347

Earlier quoted context omitted.

You missed the part about the blog comments. He would also need to implement a mechanism which allows users to delete their old comments.

The mechanism is they send you an email, you verify it as you wish (have them post a comment using their credentials), you overwrite all comments from that uid in the db with a simple query? If you're using a CMS then it's going to be type the username and hit "delete all comments"; maybe WordPress et al. do this already. With a small blog the administration of that is going to be facile, surely.

I don't have a login system for my blog.

Re: Facebook to change user terms, limiting effect of EU privacy law

#348

Earlier quoted context omitted.

If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?

If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?

It is obviously not the same.

Re: Facebook to change user terms, limiting effect of EU privacy law

#349

> Facebook members outside the United States and Canada, whether they know it or not, are currently governed by terms of service agreed with the company’s international headquarters in Ireland. So would the GDPR have any protection for an Facebook-expatriate in the US who does not agree to the new terms, or would they still have no standing in European court as they are not citizen / residents?

The GDPR applies to people located within the EU, irrespective of citizenship. So it would protect a US national in Berlin, but not a German national in New York.

So could I, as an American resident, invoke legal rights given by the GDPR while I'm on vacation in the EU?

Re: Facebook to change user terms, limiting effect of EU privacy law

#350
post #261

Earlier quoted context omitted.

> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?

I think this kind of point has come up quite a few times in this thread, and I'm gonna use your comment to go over something which I don't think has been discussed much. The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such a…

> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate

That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that.

The law is the law, and will outlast the good intentions of the authors or people currently in charge. If the law, as written, was not intended to be as such, then it should be amended.

Post reply on HN