Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

361–370 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#361
post #287

Earlier quoted context omitted.

It would be a shame to take down your old blogs as I'm sure people get value from them. My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is…

> My approach is one very much based on risk Mine too. The risk is massive fines, while I currently derive virtually no benefit from my online presence. > On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. I also own a business and previously several of my clients have come through my blog postings.

Do you habitually post personally identifiable information of other people in your blog without their consent?

Re: Facebook to change user terms, limiting effect of EU privacy law

#362

Earlier quoted context omitted.

They have a lot of users and GDPR is really tricky to implement when dealing with any manual processes. Though they have a lot of users in the EU (population 700M), it seems that once they figure out how to do it for their 250M (?) EU users, expanding it to 2B users is not a huge stretch.

> population 700M You are probably counting 'Europe the continent' rather then the EU (where the GDPR will come in effect) which is rather lower at 525 million or thereabouts.

Yeah, I just Googled "EU population" and used the number Google gave, if I search "European Union population", then it gives 508M.

Re: Facebook to change user terms, limiting effect of EU privacy law

#363
post #147

Hmmmm. Does this mean that the Irish Dutch triple sandwich tax thing will break and facebroke is now paying US taxes?

The article mentions that they'll still try to claim revenue through Ireland for non-EU users, but that non-EU users technically have an agreement with the US company.

So no idea, basically.

Re: Facebook to change user terms, limiting effect of EU privacy law

#364

This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…

> I'm a huge proponent of GDPR

Why?

From what I can tell it does three things. Limits the secret data collection market to the government and bad actors, limits new companies by creating an additional artificial cost of entry through regulation, and sets up infrastructure to allow government to block any arbitrary site.

Edit: Another tool given to them is the potential to destroy any small business anywhere on the globe. Think about that.

Re: Facebook to change user terms, limiting effect of EU privacy law

#365

Earlier quoted context omitted.

> If you just say, "Oh I have consent" then the user can withdraw consent. If you actually needed that information (like the user's name!) then you are absolutely screwed. Well, only screwed if they want to keep their account? I can assume that resulting in Facebook closing down your account. All in all, I doubt millions of people will request data under the GDPR. But I guess the fines are significant enough to worry…

The really, really, really awesome thing about GDPR is that you can't deny service because someone wants to opt out of sharing their data. You actually have to keep their account active and make it work somehow. If you can't, then you are libel for a really huge penalty. I can't add enough smileys to that, so you will just have to imagine them.

> You actually have to keep their account active and make it work somehow. If you can't...

If you don't, not if can't. If you can demonstrate a reason that that piece of information is absolutely necessary for your service then you can deny service if the person doesn't want to provide the data. Otherwise you could submit a complaint about any delivery service for refusing delivery if you refuse to give them your address.

If you don't provide a reason why that data is necessary and still require the person to give it to you, then yes, you're in for some pain.

Re: Facebook to change user terms, limiting effect of EU privacy law

#366

Earlier quoted context omitted.

And that is just as "possible" under the current structure of GDPR.

Not really. For example, if Facebook Inc. establishes a "Totally not FB LLC" for the purpose of skirting GDPR, Facebook Inc. is still the data controller according to the law, as it is directing the data collection and purpose, even if "Totally not FB LLC" does all of the handling as a data processor. Except now the fine is levied on the total turnover of both companies, not just one.

Right, I meant it's just as "possible" in the sense of it not really being practically possible.

Re: Facebook to change user terms, limiting effect of EU privacy law

#367

Earlier quoted context omitted.

If I do business in, say, Australia, but Europeans fly to me to purchase my services, am I then bound by European law? The internet is basically the same deal, no?

Fun fact - Americans invented this concept. If you're doing anything fintech with a citizen of U.S., you have to uphold to certain regulations invented by the U.S.A. Even if you're doing it on European grounds.

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#368
post #358

Earlier quoted context omitted.

> The ICO (UK) has been fairly clear that the intention is not to fine businesses to the point where they cannot operate That's a problem, imho. We cannot rely on good intentions when it comes to the interpretation and enforcement of the law. Anyone who's gotten caught up in the quagmire of legal bureaucracy understands that. The law is the law, and will outlast the good intentions of the authors or people currently…

Almost all criminal law I know of has a clause "...up to x years/month". We are pretty fine with this since decades. Why should this be different?

That is reflective of the nature of the crime, and history of the criminality of the accused, not their intrinsic characteristics, such as being small businesses or large businesses.

Depending on the nature of the violation, it may also reflect the scope of the violation, such as fraud. This is a scenario where, again, the size of the business, or the risk of the business going under, is not taken into account.

If we really want two separate punishments for the same crime- one for small businesses and one for large businesses, because we don't intend on putting anyone out of business- then that should be a codified part of the punishment.

Re: Facebook to change user terms, limiting effect of EU privacy law

#369
post #297

Earlier quoted context omitted.

So companies that are careless with personal data and get hacked get out of business? That sounds like a benefit! Within small companies, it's now easier to push for proper data security, for not being careless. "Boss, I know it'll slow down our release, but if we don't do it, we could go bankrupt!"

If I don't have a server in your country, I shouldn't be in your jurisdiction. And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.

What makes you think progressive enforcement is not going to be the norm here?

Re: Facebook to change user terms, limiting effect of EU privacy law

#370
post #139

Earlier quoted context omitted.

Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…

> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.

This is why I don't think it is. For far, far, far too long, startups have treated user data, privacy, and security as an afterthought. Now, they are going to be required to give consideration to those things. This can be nothing but a good thing. The age of "move fast and don't care about user data" is coming to a close, and all should be happy.
Post reply on HN