Earlier quoted context omitted.
People living in the EU absolutely want control of the gathering of their PII. The only complaints I've seen about it are concerning people responsible for administrating data in companies. GDPR represents an ideology of not giving corporations free reign to make profits at any human/social cost, but to reign them in and give people chance to consent rather than be data-raped. Could you expand on how you think it's (…
> What's bad about informed consent wrt PII? The cookie pop-up is an example of EU overeach. Doesn’t help privacy, doesn’t UI, and now everyone is just dismissing them.
Facebook to change user terms, limiting effect of EU privacy law
381–390 of 409 posts
Re: Facebook to change user terms, limiting effect of EU privacy law
#382Earlier quoted context omitted.
Well, he is not a company. So he doesn't need to do anything. If it's a personal website GDPR does not apply. If it is a company. Yes, it will require more work. That is the nature of regulation, but the demands placed on companies are not unreasonable in any way. I would place it on the same level as stores being required to provide receipts, or restaurants being required to clean the kitchen. It certainly was easie…
My personal blog is registered to my company. Restaurants being subject to local laws around hygiene makes sense. It would be far stranger for restaurants to be subject to health codes from across the world just because tourists occasionally visit. I had no say in GDPR but am forced to comply, despite the overheard it entails without any actual benefit to user privacy (in my case).
Also, you can keep logs (with IPs) if the purpose of the log is to prevent abuse. If you are only keeping the log on because it was the default, that is a bad reason to keep them, and is not in compliance with GDPR.
If you are keeping the log because you are selling the data to Facebook for data analysis, and are sad because you have to turn them off for EU citizens. I’m not sorry that you are forced to comply.
Re: Facebook to change user terms, limiting effect of EU privacy law
#383Earlier quoted context omitted.
"perhaps you're not the kind of company the EU wants to be doing business with" Europeans want Facebook and Google and the rest, the EU doesn't. The EU != the europeans. So international startups must now care more about what the EU wants than what european customers want. That's wrong. In the meantime, european governments take measures that jeopardise private life, like putting black boxes at ISPs in France to watc…
People living in the EU absolutely want control of the gathering of their PII. The only complaints I've seen about it are concerning people responsible for administrating data in companies. GDPR represents an ideology of not giving corporations free reign to make profits at any human/social cost, but to reign them in and give people chance to consent rather than be data-raped. Could you expand on how you think it's (…
"GDPR represents an ideology": one point we agree on.... "at any human/social cost": what cost? Can't I sue Facebook in a civil court if I suffer any prejudice just like I can sue any company?
Is there any "data-rape": if your data is processed only to choose which ad you will see, does it count as a "data-rape" for you? The ad you're seeing is the only thing of value on Facebook: your data has no value except to show you this ad.
Can you tell me where I can buy data from Facebook? I'd love to buy the friend-list of influencers who have set their privacy settings so that data doesn't leak. What? I can't? Doesn't FB sell people's data? ;-) What about famous artists private pictures then?
That's what people think of when they hear "Facebook is selling your data". They don't hear "Facebook is using your data to show you better ads which pay for the whole service".
Informed consent isn't bad. Have you read FB Terms&Conditions? Have you read the paragraph that says you're OK that FB has the right to use and reproduce the content you're posting on FB? You have already given your informed consent. Now you're trying to take it back.
Re: Facebook to change user terms, limiting effect of EU privacy law
#384Earlier quoted context omitted.
That's not correct as a non-EU entity I'm under no obligations to register for MOSS or to collect VAT unless under TBES (which is nothing new since it's an extension of the old VOES scheme) which applies to a limited number of services only: https://ec.europa.eu/taxation_customs/business/vat/telecommu... Even if by some chance you are a small business that for an inexplicable reason does fall under this you can get o…
If you sellnon physical goods you are required to collect VAT when you cross a per country threshold.
This means that most businesses it's not an issue since you can have a turn over of a few 100,000 EUR spread across the EU without being required for registration.
This is also solved via your payment processors and what would you know the EU also offers you the infrastructure to register where is the one stop shop for GDPR?
Re: Facebook to change user terms, limiting effect of EU privacy law
#385Earlier quoted context omitted.
My personal blog is registered to my company. Restaurants being subject to local laws around hygiene makes sense. It would be far stranger for restaurants to be subject to health codes from across the world just because tourists occasionally visit. I had no say in GDPR but am forced to comply, despite the overheard it entails without any actual benefit to user privacy (in my case).
So why is it registered to your company if it is your personal blog? To deduct taxes? If you are, you must derive business benefit from it. So it is in face not a personal blog. Also, you can keep logs (with IPs) if the purpose of the log is to prevent abuse. If you are only keeping the log on because it was the default, that is a bad reason to keep them, and is not in compliance with GDPR. If you are keeping the log…
It's not strictly personal, in the sense that I post technical content which sometimes leads to me being hired for consulting engagements.
> If you are keeping the log because you are selling the data to Facebook for data analysis, and are sad because you have to turn them off for EU citizens. I’m not sorry that you are forced to comply.
I honestly cannot tell if you are trolling or not.
Do you truly think Facebook has a program where I can sell them my Apache logs of a few daily visitors?
Re: Facebook to change user terms, limiting effect of EU privacy law
#386Earlier quoted context omitted.
You are assuming GDPR is good. I don’t think so. I don’t want GDRP in the US. The worst abuser of privacy - right now - is the government. I don’t think putting redtapes on startups will solve anything.
Just because we can't limit all players, we shouldn't even try to limit the vast majority of them? I'm not sure I agree with that logic... Yes, the federal government is as bad (in reality, worse) than you say, but that's no reason to not take action against the thousands of other players that are blatantly following in their footsteps in terms of data collection.
Government is pretending to save people’s privacy with one hand, while forcing private companies to store people’s personal information with the other.
Re: Facebook to change user terms, limiting effect of EU privacy law
#387Earlier quoted context omitted.
It would be a shame to take down your old blogs as I'm sure people get value from them. My approach is one very much based on risk - how likely am I to receive requests from data subjects requesting deletion of their data? How likely am I to be subject to a targeted attack where people try to remove information from my server? How likely am I to be the subject to enforcement action if my server is hacked and data is…
> My approach is one very much based on risk Mine too. The risk is massive fines, while I currently derive virtually no benefit from my online presence. > On one argument operating a blog is a purely personal activity and so out of scope of GDPR in any event. I also own a business and previously several of my clients have come through my blog postings.
In the UK for example the ICO who regulate data protection matters concluded 17,300 cases, in which only 16 of them resulted in fines.
I’m just intrigued as to how you have developed this perception of GDPR and data protection law looking to regulate small one man blogs out of existence?
/edit oh and my other point still remains - even if you’ve got some customers through a blog, you don’t appear to be within scope of GDPR on the assumption you’re not directly looking to do business with EU based customers (for example through offering payment options in European currencies).
Re: Facebook to change user terms, limiting effect of EU privacy law
#388Earlier quoted context omitted.
Laws are not always crystal clear in each case because to do so risks making them capable of being worked around (and of course in some cases they are just badly drafted - but I don't see this so much with GDPR). Laws are then subject to interpretation by the courts and by lawyers. If you're having issues with understanding laws, then you may need an expert to guide you, as in many areas of life. Recital 23 of GDPR w…
Yes laws are not crystal clear but you don't understand the problem because when laws are unclear in your country / union there is a clear channel to debate it which is the regulator and the courts this channels are not available to extra-territorial parties. Add to that the fact that you now have laws enforced on you that you have no control on how they were written or are enforced because you are not part of the el…
I was responding to your point that there were zero channels to help non-EU companies to comply.
I’m really not sure on what resources you think are available to EU companies that are not available to non-EU companies? You would definitely not get GDPR advice at the Citizens Advice as they have more important matters to deal with. To the extent a local regulator would provide guidance to an EU company, I am certain they would also provide to a non-EU company looking to comply. You present it as a clear distinction between EU vs non-EU companies but that simply is not the case!
We can agree to disagree on the pros and cons of an extra-territorial law but don’t misrepresent the position in terms of help available to EU vs non-EU companies.
Also your point about hairdressers is nonsense. A non-EU based hairdresser is very muh out of scope of GDPR!
Re: Facebook to change user terms, limiting effect of EU privacy law
#389Earlier quoted context omitted.
> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.
If it is so typical, multiple examples please.
Re: Facebook to change user terms, limiting effect of EU privacy law
#390Earlier quoted context omitted.
FATCA was designed to apply to non-US entities it provides clear definitions and channels on what to do and who do you work with, the GDPR has no functional models for non-EU entities.
Actually it kinda does... Article 27: "the controller or the processor shall designate in writing a representative in the Union"