Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

351–360 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#351

Earlier quoted context omitted.

I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here. However, the wording I used before was actually taken directly from the GDPR itself[1]. Moreover, the interpretation that an otherwise unidentified image of someone may become personal data even if collected incidentally such as in a photo taken for other purposes or on CCTV is supported by amo…

> I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here. If you have a social network and you have a user A and a user B. Each of them uploads a picture in private showing both of the users on the image. If user A deletes his or her account the picture in user B's account is not to be deleted even though it contains a picture of user A.

But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it.

As I mentioned before, modern technologies raise complex issues about third parties that we have barely begun to explore. SOP at social networks is very much to get people to provide information about not only themselves but also other people they know, and that's a minefield if those other people aren't happy about it. Obviously you can't just say social networks can do what they want if someone else provided the personal data, because that undermines the entire principle of data protection and privacy. But equally, if you require explicit consent from everyone for everything, you create a huge burden that might make the whole idea unworkable or at least remove a lot of the value these services offer to their users when maybe a lot of people wouldn't have a problem with, say, a friend tagging them in a photo anyway.

As things stand, taking the GDPR at face value, I don't see how it would be legal for a social network to retain any photo in which someone is identifiable if that person doesn't consent, unless that social network also took rather dramatic steps like avoiding any sort of automated processing and analysis of photos that might identify people in them, as well as removing features like letting a user tag someone who isn't a member of the social network.

Re: How the GDPR Will Disrupt Google and Facebook

#352

Earlier quoted context omitted.

> I don't understand what you mean by "fundamentally scoped" in this context, so perhaps we're talking at cross-purposes here. If you have a social network and you have a user A and a user B. Each of them uploads a picture in private showing both of the users on the image. If user A deletes his or her account the picture in user B's account is not to be deleted even though it contains a picture of user A.

But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it. As I mentioned before, modern technologies raise complex issues about third parties that we have barely begun to explore. SOP at social networks is very much to get people to provide information about not on…

> But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it.

Except that is not included in this. You are in fact not even supposed to retain data to identify a user after their account has been used to match them on other data.

I don't know the law by heart right now but I had discussions even a year ago with people consulting on this about this very topic what to do for such cases.

This law was not drafted in a vacuum where nobody looked at real world situations.

Re: How the GDPR Will Disrupt Google and Facebook

#353

Earlier quoted context omitted.

But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it. As I mentioned before, modern technologies raise complex issues about third parties that we have barely begun to explore. SOP at social networks is very much to get people to provide information about not on…

> But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it. Except that is not included in this. You are in fact not even supposed to retain data to identify a user after their account has been used to match them on other data. I don't know the law by heart right n…

This law was not drafted in a vacuum where nobody looked at real world situations.

Sadly, given that we're talking about an EU law in a technical field, I suspect that what you just wrote is actually quite close to what did happen. That would be consistent with other recent EU rules affecting creative and technical businesses. In some cases, even senior EU and national government figures have admitted that those involved hadn't seen major unintended consequences coming at all, at least not until it was too late in the process to avoid them.

Essentially, the EU often exhibits good intentions and its laws might be made with laudable overall goals, but it frequently produces poor implementations that haven't been thought through in enough detail before legislating. So far the GDPR is shaping up to be another textbook example, with perhaps a side order of political football so the EU can beat up big US tech businesses because the EU's business environment hasn't resulted in creating equivalent services of its own.

This doesn't seem healthy for either our tech industry or our society as a whole to me. I'm actually a rather strong advocate of privacy online, but rules intended to protect it do need to be reasonably clear and practical or they're not going to be worth very much.

Re: How the GDPR Will Disrupt Google and Facebook

#354

Earlier quoted context omitted.

> But if user A withdraws their consent for the social network to process personal data about them, user B's photo is still personal data about user A if the social network knows or could know that user A is in it. Except that is not included in this. You are in fact not even supposed to retain data to identify a user after their account has been used to match them on other data. I don't know the law by heart right n…

This law was not drafted in a vacuum where nobody looked at real world situations. Sadly, given that we're talking about an EU law in a technical field, I suspect that what you just wrote is actually quite close to what did happen. That would be consistent with other recent EU rules affecting creative and technical businesses. In some cases, even senior EU and national government figures have admitted that those invo…

The track record of EU legislation is generally rather good and based on feedback I have seen that in particular American companies have on GDPR it's already succeeding in what it's there to do: raise awareness of data not being an asset but a liability.

We will see soon enough how this plays out. From where I'm standing I'm very welcoming of this development because it's the first time I see an actual attempt of companies doing something that is in the interest of the customer when it comes to data.

Re: How the GDPR Will Disrupt Google and Facebook

#355

Earlier quoted context omitted.

GP's company isn't doing the kind of tracking and analytics that a lot of people might say were "NOT OK". GP's company isn't doing the tracking and analytics, but it is pulling data from companies that do. Therefore, regulations that affect GP's customers affect GP. This is right and proper, and I don't see what the problem is.

This is right and proper, and I don't see what the problem is. The problem is that it will be almost impossible to comply with the letter of the law in this case without either imposing prohibitive levels of overhead or disregarding other good practices like logging diagnostics and keeping robust backups in case things go wrong. There's a saying about babies and bathwater, but this is more like requiring the entire h…

The problem is that it will be almost impossible to comply with the letter of the law in this case without either imposing prohibitive levels of overhead

If the business requires this much overhead in order to internalize the data-externalities that it's generating, the business does not deserve to exist. Privacy violations are an externality, just like pollution, climate change, or deforestation. The way we deal with these externalities is through regulations and taxes that force businesses to internalize the costs they're imposing upon the rest of us. OP's business is like a chemical plant that gets its feedstock from polluting suppliers. If pollution regulations make the feedstock prohibitively expensive, then it's a signal that the existing process for making the product product wasn't providing a net economic benefit to society, and that the process needs to be either reengineered or shut down. By the same token, if privacy regulations make your product unprofitable, then your business model either needs to be reengineered, or you need to shut down.

There's no rule saying that cities have to be covered in smog. Likewise there is no rule saying that online media has to be funded through advertising. In the case of pollution, externalities that appeared to be inevitable turned out to be the result of choices resulting from economic incentives. When regulation changed the incentives, the externalities were massively reduced (as evidenced by the fact that Pittsburgh today has some of the best air quality in the US). I'm confident that the same is true of online media. The only reason that it's funded by privacy-violating advertising is because privacy-violating advertising is the cheapest and easiest business model. But if you take that off the table, businesses will be forced to innovate and come up with new payment structures that better align their interests with those of their customers.

Re: How the GDPR Will Disrupt Google and Facebook

#356
post #348
post #165

Earlier quoted context omitted.

>Using these services is not voluntary at this point. Of course it is. You just don't want to because it's not convenient.

Eating food is not mandatory either, but it's very convenient.

If you don't eat, your life ends

If you never get on Facebook again, what? You have to write snail-mail letters or use group MMS?

How has HN become an argument for why eating food is not in fact mandatory?

Re: How the GDPR Will Disrupt Google and Facebook

#357
post #118
post #91

Earlier quoted context omitted.

> Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) 20mil EUR even for zero revenue?!

Yes, but who exactly is processing personal data with zero revenue?

Hacker News itself? Every web forum? Every teenager who writes a webapp?

Re: How the GDPR Will Disrupt Google and Facebook

#358
post #292
post #128

Earlier quoted context omitted.

Startups?

In that case it's the EU's way of telling you that your startup idea isn't that great. Basing a startup idea on illegal techniques is not a good idea. Snapchat could've succeeded without that data so there's no reason why startups cannot adapt.

Illegal techniques like... forgetting to disable Apache access.log or ever collecting the results of an HTML form.

Re: How the GDPR Will Disrupt Google and Facebook

#359

Earlier quoted context omitted.

This is right and proper, and I don't see what the problem is. The problem is that it will be almost impossible to comply with the letter of the law in this case without either imposing prohibitive levels of overhead or disregarding other good practices like logging diagnostics and keeping robust backups in case things go wrong. There's a saying about babies and bathwater, but this is more like requiring the entire h…

The problem is that it will be almost impossible to comply with the letter of the law in this case without either imposing prohibitive levels of overhead If the business requires this much overhead in order to internalize the data-externalities that it's generating, the business does not deserve to exist. Privacy violations are an externality, just like pollution, climate change, or deforestation. The way we deal wit…

Did you just compare error logging and backups to toxic pollution?

Re: How the GDPR Will Disrupt Google and Facebook

#360
post #294

Earlier quoted context omitted.

Based on what they said, it sounds like they store personal info on behalf of their business clients, but don't look at it themselves. Their point is that this law still requires them to implement the granularity to delete individual records so their clients can be compliant. (I don't think it absolves them of any responsibility to implement privacy measures, but it does at least make sense.)

I don't understand how this is a surprising feature. Shouldn't every decent system be able to delete all data of one user without affecting other data? That companies haven't even thought of being able to delete user data makes the law even more important. It should be common business practice to delete data if a user asks, not something technically impossible.

No, because most systems facilitate interactions. Do you get to erase transactions from other people's accounts? Messages from other people's inboxes? Posts from other people's comment threads? None of these things are obvious.
Post reply on HN