Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

371–380 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#371
post #368

Earlier quoted context omitted.

Shutting down or blocking all EU users is perfectly fine by me. At least I'd know which are the companies I should stay away from. But no, it won't happen, because the EU is the world's second biggest market. If China can afford to coerce companies into censorship and violating people's rights, the EU can afford to impose some privacy laws as well. And as I've been saying elsewhere, targeted ads are only needed at th…

> If China can afford to coerce companies into censorship and violating people's rights, the EU can afford to impose some privacy laws as well. Take this with a grain of salt since I am not from China and really only know about it from HN: The EU is not nearly as powerful as the Chinese government nor do I think the general Chinese population is aware of how much better G/FB/other sites are outside of china (admitted…

> * The EU is not nearly as powerful as the Chinese government*

Not sure what that's supposed to mean.

> If G/FB suddenly stopped supporting EU users

But they won't because they are not stupid. Instead they'll start respecting the privacy of EU citizens, which is going to be a win for us.

> I highly think most people want the free apps with targeted ads over a full block or paywalls.

Most people aren't aware of the threat to their privacy.

Also, do you work for a company that makes its living off targeted ads?

Not that I judge you or anything, I worked on a startup in the past building a platform for serving ads on bidding exchanges (what Criteo has been doing, except they succeeded). And now I'm working on anti-ad-blocking technologies. But I'm also privacy aware, as I've seen full well what targeting can do and I don't suffer from double standards.

The people that defend ads targeting are those that work in the ads industry.

Re: Google and Facebook accused of breaking GDPR laws

#372
post #316

Earlier quoted context omitted.

Is that relevant in any way? And Germans are more privacy aware than Americans, for obvious historical reasons.

There's nothing inherently wrong with storing user data or using targeted advertising as long as it's not abused. Instead of outlawing only cases of abuse like any sensible law would do, the EU just chooses to throw the baby out with the bathwater because it's not their baby.

No, data can be sold or leaked and abused at any point in time, it doesn't matter that it doesn't happen right now.

People that blame Cambridge Analytica are missing the point, which is that Facebook is a threat to everything we know just by existing.

Re: Google and Facebook accused of breaking GDPR laws

#373

Earlier quoted context omitted.

> So IP + timestamp of my ticket system logs is invalid What makes it "invalid"? If you can identify a person by their IP, then the IP becomes a part of their personal data. For most websites it's irrelevant, because people just visit and leave. But if someone signs in with their real name, you just need to update the ToS saying that apart from their other data you also store their IP. How complicated is that?

Ok, just update the ToS. No ability needed to provide opt out of that IP collection? No ability needed to go, upon request, and delete all these IP+timestamp logs that I could use to correlate with their name? Handwaving all of this stuff away as clear and easy is at the least ignorant to real people's concerns and at most willfully dishonest.

How can anyone "opt out of that IP collection"? It's not the way the Internet works: logging is an essential part of of its infrastructure (and in certain jurisdictions it's required by law). The only problem is if the IP is associated with personal data. If the user really wants to remove it, they can remove their personal data, and in this way the problem disappears.

On the other hand, if you plan to sell the IPs associated with some other data to a third party that can easily link it to people (Google and Facebook can), you may want to consult a lawyer.

Re: Google and Facebook accused of breaking GDPR laws

#374

Earlier quoted context omitted.

> So IP + timestamp of my ticket system logs is invalid What makes it "invalid"? If you can identify a person by their IP, then the IP becomes a part of their personal data. For most websites it's irrelevant, because people just visit and leave. But if someone signs in with their real name, you just need to update the ToS saying that apart from their other data you also store their IP. How complicated is that?

Ok, just update the ToS. No ability needed to provide opt out of that IP collection? No ability needed to go, upon request, and delete all these IP+timestamp logs that I could use to correlate with their name? Handwaving all of this stuff away as clear and easy is at the least ignorant to real people's concerns and at most willfully dishonest.

Can you point to the bit of the law that requires website owners to delete data upon request? Or the bit of the law that requires website owners to ask for consent to gather IP addresses?

Re: Google and Facebook accused of breaking GDPR laws

#375

Earlier quoted context omitted.

This is actually very interesting. It seems to me that many Americans really don't care how their personal data are (ab)used and will happily agree to absurd ToS-es without complaining. In Europe, we have quite different culture of doing things. And yes, the misnomed "right to be forgotten", i.e. the ability to remove my own personal data from a website, is an important right. Not being tracked is an important right.…

Americans for the most part hates being told what to do by the government. For me, I hate it because government intervention tends to cripple economic growth. I value economic growth > social welfare (used in the non derogatory way, in America "welfare" has an immediate negative connotation). I am also aware of this and can understand why other cultures would reverse that equation

That's correct: government intervention stifles economic growth, be it GDPR or the Paris Agreement. The point is, these laws are proposed where self-regulation fails, and the corporate greed lead us to the situation that is worse to the society as a whole than without it.

Re: Google and Facebook accused of breaking GDPR laws

#376

Earlier quoted context omitted.

GDPR really isn't that much more than the previous DPA which was in place 20 years without problem. Businesses and startups were still formed. To stick to the general. Who pays for education and promotion of alternatives against industries spending billions? Either it's coming out of tax or a regulation is required to force educational messages and disclaimers. If neither it just seems a way to assert the status quo…

I think anti social media PSAs are as reasonable as any other PSAs. It's ok to encourage people to go outside instead of play video games or encourage people to not talk on the phone while driving. The video game and phone industries are big too. It's ok to give grants to projects that already have other players in the industry. It's ok to suggest people use ad block. There's no need to be so defeatist assuming nothi…

It's OK but ineffectual when up against industries spending orders of magnitude more. It can never be a level playing field.

You give using a phone while driving as an example. UK tried PSAs for years before ultimately outlawing it. Enough were seen ignoring that law that they doubled the penalty some years later. From the occasional piece I've seen on US sites that mention the issue I get the impression that distraction from phones is a disappointing but accepted facet of modern driving.

The older I get the more agreeable I feel to more regulation and adequate enforcement. Without it companies large and small, and individuals, are too inclined to be abusive - of pollution, of privacy, of financial misselling and so on. All to make that sale or commission. Caveat emptor works when it's a consumer against the local greengrocer, or taking a survey before house purchase. Not so much when it's a consumer against multi-nationals employing psychologists and so forth which is why most UK consumer regulation has been steadily moving away from that model for years.

As a European I can look as the US, who prefer minimal regulation, and see it as providing much confirmation that I don't want to do it that way. I'm a little disappointed that UK governments frequently do wish to adopt a US-lite approach.

Re: Google and Facebook accused of breaking GDPR laws

#377
Where do I sign up? I was forced today to accept Facebook's new settings and I was presented with an option to either allow facebook to process my data for face recognition or not. Choosing not does not allow you to move forward in the settings, and it is deeply confusing - there is an "accept and continue" button, but there is some rather small text that states choosing accept and continue will enable face recognition. Closing the browser and reopening it at this point shows the same text, and only the option to accept and continue. Doing so and then checking settings will show face recognition to be disabled, but I am no longer sure what I accepted and continued with.

The whole scheme is scammy as anything. The text presented is something along the lines of "disabling this feature will allow other people to impersonate you" which at best is nasty fear mongering.

Fuck those assholes.

Re: Google and Facebook accused of breaking GDPR laws

#378
post #75

Earlier quoted context omitted.

If a product that was in compliance goes out of compliance due to legal changes, it generally has to be pulled from the shelves. I'm saying this strictly from a legal perspective, not endorsing it per se, and I acknowledge the significant expense involved. But this sort of thing happens pretty frequently in a lot of other industries, and the result is pulled product and often a lot of destruction of unsold product. I…

If google had made software updates available, which gave the correct options and are GDPR compliant. But the OEM, Network don't approve / supply those updates, is Google at fault? (In this case its a non-Google phone running Android)

> But the OEM, Network don't approve / supply those updates, is Google at fault? (In this case its a non-Google phone running Android)

Great question. I have no idea, and with the GDPR having been looming on the horizon for two years now, is something that would be beneficial (and cost-effective) to spend money on getting quality legal advice.

To anyone who has seen the complaints about startups having to spend $20k on a lawyer to explain the GDPR to them, a small startup won't be facing complicated legal questions like these (and those who insist on doing so, have been given ample warning).

A friend of mine has an online business that involves offering/reselling/managing a client's domain registrations (as part of a package of specialised hosting services). Meaning he can't really get around sharing his clients' information with third parties (registrar, other domain shop, I'm not sure). 25th of May approaching. He reads up on the GDPR, makes some adjustments how or what data he stores (because earlier, you know, it was considered good practice to "store all the things" just-in-case), writes a 3-page license agreement (I suppose he took a boilerplate example and adjusted it to his needs), sends it to his clients to agree, and done. Less than a week's work.

Re: Google and Facebook accused of breaking GDPR laws

#379
post #324

Earlier quoted context omitted.

You have those backward. Natural rights, at least, are considered to exist before and outside of government. Enumerated rights may derive from government, as do privileges. The "lege" in privilege literally means "law". Enumerated rights are the rights the GP was talking about. These are defined in law, though may derive from natural rights.

Yeah, good luck enforcing that natural rights w/o any entity to protect you from those who are stronger than you and keen on violating your "rights" for their own good. If I have a gun and you don't, and nobody can enforce your right to life, the chances are that I can kill you and your right to life with a single movement of a finger any time I want. And because not everybody can become warlords, w/o any organisatio…

I'm just clearing up some confusion about definitions here, not making any comment on enforcing rights.

Re: Google and Facebook accused of breaking GDPR laws

#380

I am reading through the complaints, The first one: https://noyb.eu/wp-content/uploads/2018/05/complaint-android... The User sets up a "new" (non Google) phone, and isn't given an option to decline consent to Googles ToS. Now how does this work with a physical product? It needs to be compliant on the 25th of May 2018, but the version of Android may be old and not updated (given its Android). Even if there was an upda…

Android has the ability to push updates to phones that haven't been set up yet; when you first turn on a new phone the first thing it does is ask for wifi so it can check for updates. Google has the ability to update the phone before literally any other part of setup occurs. You do not need to consent to the ToS first; the setup steps on Android are really carefully thought through from a legal perspective. (I know t…

Google cannot update a phone that uses an OS built by another OEM. Since the OEM cited in this complaint is a low end Huawei phone they're responsible for pushing the update.
Post reply on HN