Live data from Hacker News

Facebook to change user terms, limiting effect of EU privacy law

reuters.com

401–409 of 409 posts

Re: Facebook to change user terms, limiting effect of EU privacy law

#401
post #388

Earlier quoted context omitted.

> What are you even trying to say here? If I don't live in the EU, have no legal presence in the EU I have no means through which I must comply with the GDPR. I was responding to your point that there were zero channels to help non-EU companies to comply. I’m really not sure on what resources you think are available to EU companies that are not available to non-EU companies? You would definitely not get GDPR advice a…

Local DPA, local courts, local MPs, industry unions, EU MPs, EU high courts. And please tell me how say I as a small merchant in any country outside of the EU can get in touch with them and get services from any of them. Better yet please tell me how a lawyer in Mexico or the Philippines would be able to advise me on GDPR unless they are part of a top tier international law firm which operates in the EU and has exper…

Ok, my apologies for not picking up on the fact you are in the EU. Is it the cost that is stopping you from making a subject access request today under existing laws?

Apologies also - I took Citizens' Advice in the narrow sense of the Citizens Advice Bureau (I used to work there so it's in my subconscious) who generally deal with benefits, employment and housing law queries. I took a look at the citizensinformation.ie and did a search for GDPR - I can't see much in the way of materials unfortunately. ACF makes materials available which can be read by anyone regardless of location. Sure, they might make advice available to local entities, but this would be a small benefit to EU orgs vs non-EU orgs.

However I still don't really follow your point how organisations will approach GDPR compliance in general and the idea that there is a massive gap between what is available to EU entities versus non EU entities.

For lots of organisations, GDPR will not be on their radar, and life will go on as normal post May 25th.

For organisations aware of GDPR, their route to compliance will be through reading the source materials and supporting materials available on the Art 29 Working Party website. That is the case regardless of whether the organisation is in or out the EU. They can consult materials from third parties like ACF but the core materials are as above.

I don't really think contacting your MP or actually contacting a regulator is something which many entities have actually done because actually the base regulation and the interpretation notes are sufficient to understand what an organisation has to do to comply (again available to anyone who cares to read). In terms of court access

In terms of access to legal advice, then I don't quite think it's as bad you paint out here! I've instructed local counsel in multiple countries direct and it's a straightforward process and those firms were not part of a top tier international law firm network. Often smaller local firms have firms of similar sizes in other countries that they can refer work to. If other peoples' implementations of GDPR are anything like my company's then the extent of legal advice sought will have been limited.

I think overall I take your point that resources on offer to non EU companies may be a more limited, but overall the core resources are the same. Lots of non-EU entities have been working very hard on looking to comply with GDPR using the above resources and taking local legal advice where relevant. I agree that for smaller organisations this is more problematic, but this is the case regardless of location to an extent.

I do take your point about the extra-judicial nature though. We will have to see how things work out. My instinct is that for lots of companies it will be business as usual and the local regulators will have bigger targets that they want to go after.

Re: Facebook to change user terms, limiting effect of EU privacy law

#402
post #175
post #10

Earlier quoted context omitted.

They'd also have to stop being based in Europe (they're officially headquartered in Ireland, because tax evasion), and (here's the kicker): stop doing business with all of Europe. Even if they had to say screw it and not do any targeting of their adds at all, it really wouldn't make any business sense for them to take their ball and go home.

FB's HQ isn't in Ireland. I think it's in the USA.

i think they mean "european HQ" in the sense that they serve the whole of EU from Ireland.

Re: Facebook to change user terms, limiting effect of EU privacy law

#403
post #13

Zuckerberg went to Congress and told them Facebook would support GDPR, as if the only thing GDPR is are just some controls you'd do at the user interface level (and as we learned today, that they're attempting to get around with dark pattern designs [1]). GDPR is much more comprehensive than that, but most importantly it gives data privacy regulators real teeth to enforce with (fines up to 4% of global revenue). The…

Actually he was asked if Facebook would roll out the GDPR requirements globally and he said they aren't and that America has different sensibilities

Re: Facebook to change user terms, limiting effect of EU privacy law

#404

Earlier quoted context omitted.

If the ICO (UK) issued a fine, you wouldn't appeal in Spain, would you? Because of course you respond to the DPA that issued the fine or complaint. Am I not understanding your question?

We’re not talking about EU companies or entities but non-EU ones. In case of the EU you have your own local DPA other DPA local courts and high courts to appeal too and or work with. As a non-EU entity you get nothing.

The only entities that can enforce GDPR are the DPAs in various EU countries. So if some action is taken against a non-EU company, it's anyway done by one of the DPAs - e.g. if there's a complaint against some USA company by a German citizen, it would be the German DPA handling that.

Any decisions of German DPA can be contested just as any other administrative decisions in German courts, the German DPA is fully under their authority. Yes, you won't have your local courts, but it doesn't mean that you can't appeal - you simply have to file this appeal where the contested decision was made.

Re: Facebook to change user terms, limiting effect of EU privacy law

#405
post #401

Earlier quoted context omitted.

Local DPA, local courts, local MPs, industry unions, EU MPs, EU high courts. And please tell me how say I as a small merchant in any country outside of the EU can get in touch with them and get services from any of them. Better yet please tell me how a lawyer in Mexico or the Philippines would be able to advise me on GDPR unless they are part of a top tier international law firm which operates in the EU and has exper…

Ok, my apologies for not picking up on the fact you are in the EU. Is it the cost that is stopping you from making a subject access request today under existing laws? Apologies also - I took Citizens' Advice in the narrow sense of the Citizens Advice Bureau (I used to work there so it's in my subconscious) who generally deal with benefits, employment and housing law queries. I took a look at the citizensinformation.i…

The company I work for has been working on GDPR compliance for the better part of 3 years.

We also maintain compliance in the financial sector and we have both very good in house and external counsel which works with both the ICO and political institutions to ensure we meet our compliance.

The fact is that as an EU citizen you have a say about how the GDPR is applied and you have a say in how it will be enforced and interpreted.

As a non-EU entity you have no voice.

You also cannot ask for assistance from any EU or member state body.

You also don’t have access to DPA run events for example: https://ico.org.uk/about-the-ico/news-and-events/speaking-en...

Now if you want a good comparison as you have worked for a legal aid organization before you can likely estimate the hourly billable of a lawyer in the UK to provide you counsel on UK or EU law vs say FATCA or SOX.

My bet is that it would likely be at least 3 zeros in difference.

The fear isn’t that a DPA would go after you, but rather that they’ll force service providers to compell you to comply.

Under the GDPR for PayPal to remain compliant it needs to ensure that all merchants that use it to receive payments from EU residents are also compliant because you share your Personal Information with PayPal who then shares it with the merchant (name, email, address, phone number etc.).

This is going to be the likely channel of enforcement not them dragging you to court.

Re: Facebook to change user terms, limiting effect of EU privacy law

#406
post #41

User's generally won't care about privacy, but they will care about money. What this essentially boils down to is Facebook is charging users by taking their data, which is worth some amount of money.

Website terms and conditions could ask for a pint of blood from their firstborn and people would still click okay. No one reads these things. The GDPR is just going to end up being a more annoying version of the cookie law.

Yes, but my point is that it's all about money. No one cares about privacy, but they do care if they are told how much money Facebook is making off of them, and that they can extort Facebook for that money and keep some of it for themselves.

Re: Facebook to change user terms, limiting effect of EU privacy law

#407
post #31
post #22

Earlier quoted context omitted.

Not since the new tax code went into effect, but what does that has to do with anything?

More bollox. Just stop fucking lying, you're just showing yourself to be an ignorant ass.

Personal attacks will get you banned here, so please don't post like this.

You've unfortunately posted other uncivil comments in the past, too; could you please (re-)read the site rules at https://news.ycombinator.com/newsguidelines.html and use HN as intended from now on?

Re: Facebook to change user terms, limiting effect of EU privacy law

#408
post #189

How does Facebook determine if a user resides in the EU? Based on the location that they give Facebook? Based on their IP address? Phone number?

99% of people give FB their location. Perhaps as just if (EU IP | EU LANGUAGE | EU PHONE NUMBER | EU LOCATION SET) == EU. Just to be safe for a massive 4% of global REVENUE fine.

Yeah my question is not does facebook know your location (they do), but what criteria are used to determine if you are under the legal regime of the GDPR. If it's just the location you set, I would advise my non-EU friends to set their location to somewhere in the EU.

Re: Facebook to change user terms, limiting effect of EU privacy law

#409
post #33
post #25

Earlier quoted context omitted.

I have to disagree. As someone who is grappling with the impact of these laws on US business I'm acutely aware of the non-existent privacy we all have and how our information is abused and resold. The GDPR, while a pain, are a response to decades of an industry that should have known better.

I think you're understating how much of this law is about EU resentment of US tech companies' mindshare and marketshare.

That is your opinion. Just because you think so doesn't make it true.
Post reply on HN