Earlier quoted context omitted.
I think this kind of point has come up quite a few times in this thread, and I'm gonna use your comment to go over something which I don't think has been discussed much. The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such a…
> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that. The law is the law, and will outlast the good intentions of the authors or people currently…
Facebook to change user terms, limiting effect of EU privacy law
351–360 of 409 posts
Re: Facebook to change user terms, limiting effect of EU privacy law
#352Earlier quoted context omitted.
You might not, but your webserver did. Or did you change the logging configuration of your webserver to not store or obfuscate IPs in the past?
This law suggests a shift to assuming no consent for gathering of PII, only gathering data when you have informed consent and a justifiable business need. In the case of web servers I can't see a problem with not recording IP if you're also gathering PII; or asking for permission in the PII submission; or say dropping the last digits from a dotted-quad as a default.
Re: Facebook to change user terms, limiting effect of EU privacy law
#353Earlier quoted context omitted.
If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?
If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?
Re: Facebook to change user terms, limiting effect of EU privacy law
#354This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…
Can someone explain this as my understanding is that only EU residents are covered by GDPR. So EU based companies do not have to comply with GDPR for non EU residents.
So this change to the user terms seems to me to have nothing to do with GDPR. The EU privacy law cannot be applied to non EU residents.
Re: Facebook to change user terms, limiting effect of EU privacy law
#355Earlier quoted context omitted.
IP by itself is not considered private. It's only when you attach it to other identifying data. Anonymous comments are not covered with GDPR.
> Anonymous comments Wordpress asks for your name and e-mail to post a comment, doesn't it? I guess the tuple (ip,name,email,comment_text) is PII?
Re: Facebook to change user terms, limiting effect of EU privacy law
#356This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…
> Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR Can someone explain this as my understanding is that only EU residents are covered by GDPR. So EU based companies do not have to comply with GDPR for non EU residents. So this change to the user terms seems to me to have nothing to do with GDPR. The EU privacy law cannot be ap…
Edit: Is further backed up by Recital 22 [2].
[1] https://www.gdpreu.org/the-regulation/who-must-comply/ [2] https://gdpr-info.eu/recitals/no-22/
Re: Facebook to change user terms, limiting effect of EU privacy law
#357Earlier quoted context omitted.
If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?
If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?
Re: Facebook to change user terms, limiting effect of EU privacy law
#358Earlier quoted context omitted.
I think this kind of point has come up quite a few times in this thread, and I'm gonna use your comment to go over something which I don't think has been discussed much. The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such a…
> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that. The law is the law, and will outlast the good intentions of the authors or people currently…
Re: Facebook to change user terms, limiting effect of EU privacy law
#359Earlier quoted context omitted.
My counter example to this is that nobody in the US does the super annoying cookie popup thing that's required in the EU already - why would they do GDPR which is orders of magnitude more complicated.
I live in the US and am constantly annoyed by the stupid cookie popup.
This will change anyways with the GDPR.
Re: Facebook to change user terms, limiting effect of EU privacy law
#360Earlier quoted context omitted.
And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...
And that is just as "possible" under the current structure of GDPR.