Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

371–380 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#371

Earlier quoted context omitted.

What aspects of the law are disastrous for startups? What startups might see as a "massive regulatory burden", I see it as, at long last, a means of finally holding irresponsible companies to account. The spirit of the law is really quite simple; my personal data is an extension of me, and if you want to store or process it, you need a legal basis for doing so, and need to be able to demonstrate this legal basis to m…

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

Yet, you're still collecting it, and it doesn't seem like you're taking steps to protect it.

Re: Facebook to change user terms, limiting effect of EU privacy law

#372

Earlier quoted context omitted.

> Yes. Like I can’t retroactively ask you to remove what I said from your blog post. No. But I can ask you to remove my name and personal information from it.

That's precisely the problem and is a clear example of how Europeans value privacy differently. Personally, I think it is a fundamentally important right that I be able to post a blog about how "the_mitsuhiko wronged me" in some way and have that information publicly accessible. European courts think you should be able to suppress such information—even if it is true.

That's.. that's not at all true. If it's a news story, then the GDPR isn't applicable.

Re: Facebook to change user terms, limiting effect of EU privacy law

#373

Earlier quoted context omitted.

This law suggests a shift to assuming no consent for gathering of PII, only gathering data when you have informed consent and a justifiable business need. In the case of web servers I can't see a problem with not recording IP if you're also gathering PII; or asking for permission in the PII submission; or say dropping the last digits from a dotted-quad as a default.

You don't want to log access requests to your web servers based on IP? I disagree with you at pretty much the lowest, most fundamental level.

If you do, then ask the user.

Re: Facebook to change user terms, limiting effect of EU privacy law

#374

Earlier quoted context omitted.

The scope of personal data is disastrously large and the guidance is fuzzy at best. Take, for example, my old blog. It has commenting enabled and a standard Apache config (where logs include IP addresses). If I want to comply with GDPR, I have to do a bunch of work around log rotation/encryption, provide tools for old commenters to go back and remove their information, and this is even the simple case that I'm not us…

Yet, you're still collecting it, and it doesn't seem like you're taking steps to protect it.

Because I fundamentally don't think a random foreign entity should dictate how I manage logs on my personal blog. It's challenging enough to debug issues without having IP issues.

I don't even consider a random IP to be PII.

Re: Facebook to change user terms, limiting effect of EU privacy law

#375

Earlier quoted context omitted.

You don't want to log access requests to your web servers based on IP? I disagree with you at pretty much the lowest, most fundamental level.

If you do, then ask the user.

Explain how you ask the user whether you can get their IP address when any such request requires receiving their IP address.

This is draconian legislation which unnecessarily causes many more problems than it solves.

Re: Facebook to change user terms, limiting effect of EU privacy law

#376

Earlier quoted context omitted.

You might not, but your webserver did. Or did you change the logging configuration of your webserver to not store or obfuscate IPs in the past?

This law suggests a shift to assuming no consent for gathering of PII, only gathering data when you have informed consent and a justifiable business need. In the case of web servers I can't see a problem with not recording IP if you're also gathering PII; or asking for permission in the PII submission; or say dropping the last digits from a dotted-quad as a default.

Consent is only one possible justification for processing, you do not need it for everything. It's more a shift to "processing PII is forbidden unless for one of the following reasons", consent being one of them, and requiring assigning purposes to collected data. You can't just have webserver logs piling up somewhere without reason, but you probably can have a policy like "We keep IP addresses for 48 hours for security purposes", if you have an appropriate security process needing that data.

Re: Facebook to change user terms, limiting effect of EU privacy law

#377

Earlier quoted context omitted.

The GDPR applies to people located within the EU, irrespective of citizenship. So it would protect a US national in Berlin, but not a German national in New York.

So could I, as an American resident, invoke legal rights given by the GDPR while I'm on vacation in the EU?

Being on vacation doesn't entitle you to resident rights. This is typically known as a tourist visa.

Re: Facebook to change user terms, limiting effect of EU privacy law

#378

Earlier quoted context omitted.

> As a non-EU entity I legally can not collect VAT on behalf of EU customers because I have no way of paying that tax on their behalf. That’s not how this works. You are required to collect VAT and use the MOSS system to pay it quarterly.

That's not correct as a non-EU entity I'm under no obligations to register for MOSS or to collect VAT unless under TBES (which is nothing new since it's an extension of the old VOES scheme) which applies to a limited number of services only: https://ec.europa.eu/taxation_customs/business/vat/telecommu... Even if by some chance you are a small business that for an inexplicable reason does fall under this you can get o…

If you sellnon physical goods you are required to collect VAT when you cross a per country threshold.

Re: Facebook to change user terms, limiting effect of EU privacy law

#379

Earlier quoted context omitted.

That's precisely the problem and is a clear example of how Europeans value privacy differently. Personally, I think it is a fundamentally important right that I be able to post a blog about how "the_mitsuhiko wronged me" in some way and have that information publicly accessible. European courts think you should be able to suppress such information—even if it is true.

That's.. that's not at all true. If it's a news story, then the GDPR isn't applicable.

[deleted]

Re: Facebook to change user terms, limiting effect of EU privacy law

#380

Earlier quoted context omitted.

People living in the EU absolutely want control of the gathering of their PII. The only complaints I've seen about it are concerning people responsible for administrating data in companies. GDPR represents an ideology of not giving corporations free reign to make profits at any human/social cost, but to reign them in and give people chance to consent rather than be data-raped. Could you expand on how you think it's (…

> People living in the EU absolutely want control of the gathering of their PII. I know everyone here wishes this to be true, but what data are you basing this claim on?

Thank you. I for one don't care, I'm french and I live in Spain.

People SHARE their life on FB. They don't expect it to be private.

When journalists tell them Facebook is "selling" their data, they believe it because many want to believe they're victims of capitalism (that's even more true in Europe because the economy is mostly in a bad shape). Instead, they fall victim of politicians who want control (EU politicians now have POWER over american companies! how exciting), and of journalists who don't like competition (journalists work for TV stations or newspapers who sell... ads).

The only thing that has value on your Facebook page is the ad. Not your photos. Not your comments. Not your sexual or political preference. Only the ad.

We've all been fooled.

Post reply on HN