Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

351–360 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#351

Earlier quoted context omitted.

I think this kind of point has come up quite a few times in this thread, and I'm gonna use your comment to go over something which I don't think has been discussed much. The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such a…

> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that. The law is the law, and will outlast the good intentions of the authors or people currently…

I agree with you, I think your point is in a similar vein to my comment about the extraterritorial nature of the law. It's great whilst we have people in charge who we might agree with, but where are the protections if you do not agree or if the circumstances change. I can envisage the legislation, being interpreted in the strictest fashion, being used against organisations for political or other motives. Do we have adequate protections against this in the legislation?

Re: Facebook to change user terms, limiting effect of EU privacy law

#352

Earlier quoted context omitted.

You might not, but your webserver did. Or did you change the logging configuration of your webserver to not store or obfuscate IPs in the past?

This law suggests a shift to assuming no consent for gathering of PII, only gathering data when you have informed consent and a justifiable business need. In the case of web servers I can't see a problem with not recording IP if you're also gathering PII; or asking for permission in the PII submission; or say dropping the last digits from a dotted-quad as a default.

You don't want to log access requests to your web servers based on IP? I disagree with you at pretty much the lowest, most fundamental level.

Re: Facebook to change user terms, limiting effect of EU privacy law

#353

Earlier quoted context omitted.

If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?

If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?

Fun fact - Americans invented this concept. If you're doing anything fintech with a citizen of U.S., you have to uphold to certain regulations invented by the U.S.A. Even if you're doing it on European grounds.

Re: Facebook to change user terms, limiting effect of EU privacy law

#354

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

> Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR

Can someone explain this as my understanding is that only EU residents are covered by GDPR. So EU based companies do not have to comply with GDPR for non EU residents.

So this change to the user terms seems to me to have nothing to do with GDPR. The EU privacy law cannot be applied to non EU residents.

Re: Facebook to change user terms, limiting effect of EU privacy law

#355
post #230

Earlier quoted context omitted.

IP by itself is not considered private. It's only when you attach it to other identifying data. Anonymous comments are not covered with GDPR.

> Anonymous comments Wordpress asks for your name and e-mail to post a comment, doesn't it? I guess the tuple (ip,name,email,comment_text) is PII?

Name is, email is, IP combined with either (or both) is.

Re: Facebook to change user terms, limiting effect of EU privacy law

#356

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

> Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR Can someone explain this as my understanding is that only EU residents are covered by GDPR. So EU based companies do not have to comply with GDPR for non EU residents. So this change to the user terms seems to me to have nothing to do with GDPR. The EU privacy law cannot be ap…

You must abide by GDPR if your organisation is based in the EEA [1].

Edit: Is further backed up by Recital 22 [2].

[1] https://www.gdpreu.org/the-regulation/who-must-comply/ [2] https://gdpr-info.eu/recitals/no-22/

Re: Facebook to change user terms, limiting effect of EU privacy law

#357

Earlier quoted context omitted.

If you don't want to be in their jurisdiction, don't do business in their jurisdiction. If you do business in their country, why would you not be subject to their laws?

If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?

No.

Re: Facebook to change user terms, limiting effect of EU privacy law

#358

Earlier quoted context omitted.

I think this kind of point has come up quite a few times in this thread, and I'm gonna use your comment to go over something which I don't think has been discussed much. The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate. It also seems fairly clear to me that they do not expect smaller organisations to jump through the same hoops as large ones such a…

> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that. The law is the law, and will outlast the good intentions of the authors or people currently…

Almost all criminal law I know of has a clause "...up to x years/month". We are pretty fine with this since decades. Why should this be different?

Re: Facebook to change user terms, limiting effect of EU privacy law

#359

Earlier quoted context omitted.

My counter example to this is that nobody in the US does the super annoying cookie popup thing that's required in the EU already - why would they do GDPR which is orders of magnitude more complicated.

I live in the US and am constantly annoyed by the stupid cookie popup.

You are annoyed by stupid people who think they need a bunch of third party trackers on their site. Nobody, even not the EU, has problems with first party cookies.

This will change anyways with the GDPR.

Re: Facebook to change user terms, limiting effect of EU privacy law

#360

Earlier quoted context omitted.

And then huge media company just creates small subsidiary (tiny business) to "accidentally" collect personal information. Got caught? No problem, close that one, open another...

And that is just as "possible" under the current structure of GDPR.

Not really. For example, if Facebook Inc. establishes a "Totally not FB LLC" for the purpose of skirting GDPR, Facebook Inc. is still the data controller according to the law, as it is directing the data collection and purpose, even if "Totally not FB LLC" does all of the handling as a data processor. Except now the fine is levied on the total turnover of both companies, not just one.
Post reply on HN