Live data from Hacker News

Facebook to move UK users to California terms, avoiding EU privacy rules

reuters.com

411–420 of 506 posts

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#411

I don’t understand this, but maybe I missed it in the article. How can FB avoid GDPR simply by moving offices? The rules apply to any business anywhere so long as they serve EU users. What am I not getting here?

Brexit. British users are no longer subject to EU protection come January 1st and we can now be thrown to the wolves, courtesy the wisdom of our Brexiteer chums.

British users are no longer subject to EU protection

GDPR is fully incorporated into British law so can you clarify what you mean by this? Do you mean that the EU regulator has more teeth than its UK equivalent? Both seem to be equally useless in fact.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#412

Earlier quoted context omitted.

> Regulatory capture is utterly rampant right now and a huge threat to democracy. Rampant in the US. The EU has managed to avoid the worst of it so far.

I call BS on that. US remains extremely competitive, what tech company has EU produced in last 20 years remind me ? EU is a regulatory black hole.

Intercom, Zalando, Spotify, Revolut, Transferwise, Skyscanner, ASOS, Raspberry PI, Betfair, Mojang.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#413
post #406

Sort of related, does anyone know if all the consent form popups will stop once the UK leaves the EU?

I'm no expert, but the UK implemented the EU's General Data Protection Regulation by passing the Data Protection Act 2018 [1] which will still be in place come 1 January 2021. There could be revised/new legislation in future though.

[1] https://www.legislation.gov.uk/ukpga/2018/12/enacted

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#414
post #406

Sort of related, does anyone know if all the consent form popups will stop once the UK leaves the EU?

I think they will go away over time.

[RANT] They should never have been implemented that way IMHO -- a different API or IETF-ish agreed HTML meta tag that would inform the browser of the scope, entities etc. would have allowed the browser to offer overall policy choices to the user.

Most would be "I don't care, do whatever you want to me" but those who do care could have been picky. That would also have allowed the browser to generate reports for the user regarding which sites currently have which permissions, etc. This would have put the onus on the browser implementation to get it right, and not e.g. fail to show the messages, but one could argue that any browser could get the random CSS used for these prompts wrong and not show the message.

I'm a GDPR fan and will likely use this jurisdiction transfer as a ceremonial point to close my FB account for good.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#415

Earlier quoted context omitted.

This is a pertinent question. I set my account up in the UK but now reside in Croatia. Facebook has not been explicitly given my nationality, so I would assume they have to err on the side of caution and keep me under EU terms?

Don’t they do it based not on where you live (arguable they have no business knowing that) but on the location from which you access their services?

So if you travel a lot you never know which policy applies? Like between U.K. and the Continent

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#416

Earlier quoted context omitted.

Brexit. British users are no longer subject to EU protection come January 1st and we can now be thrown to the wolves, courtesy the wisdom of our Brexiteer chums.

British users are no longer subject to EU protection GDPR is fully incorporated into British law so can you clarify what you mean by this? Do you mean that the EU regulator has more teeth than its UK equivalent? Both seem to be equally useless in fact.

I mean that - whatever the legal details - Facebook clearly feels that it is now more useful to manage British data under a jurisdiction that was not an option before, an option that was held up as offering significantly less protection than under the EU.

I don't buy the equivalence in toothlessness either - the EU seems to have a willingness to take on big tech overreach in a way UK Gov has neither the capability or willpower going by past performance.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#417
post #64

Earlier quoted context omitted.

Citizenship matters not. Only residency. Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.

Okay, what does it mean “residency”? In the UK there’s no address registry where you declare your address. EU citizen works in the UK for 2 years then goes to Turkey for a vacation but likes the place so much, decides to stay for longer when still remote working for the same London company.Also connects through VPN because the Turks love banning websites. Where this person residence is? Are the UK, USA, EU or Turkish…

> How FB would know about it? In a matter of fact GDPR applies to people in EU, and data processed in EU.

It also states that data from people in EU has to be processed and stored in the EU.

It's not a matter of citizenship nor residency. Facebook just geo-locate you IP endpoint (so endpoint of your VPN) and manage your data by doing so. So USA rules will apply.

BUT if you are browsing websites hosted in Europe, EU rules will apply to your data.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#418

Earlier quoted context omitted.

Requirements that data must be handled in a certain way is akin to requirements that electronics have no lead in them and that cars emit only a certain amount of toxic fumes and that cattle aren't addled with too much HGH. If you see no value in the regulations then you might see it as you have. But in reality the regulations are valuable and that is why you see the different reactions.

This comment is based on an assumption that the regulation actually achieved beneficial privacy outcomes. It’s arguable been most successful in Access to Data area, and to some extend Data Erasure. But the Consent and Documentation provisions are a complete joke. Most EU data subjects have no idea who’s holding their data, or how/why they have access to it. The only area it’s been truly successful in has been levying…

> This comment is based on an assumption that the regulation actually achieved beneficial privacy outcomes.

followed by

> [list of benefits to privacy and one that maybe needs more work]

stay salty.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#419

Earlier quoted context omitted.

Citizenship matters not. Only residency. Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.

In case of GDPR (EU) and securities laws (US), citizenship matters, not location. For example, almost anywhere in the world if you want to open a bank account they will explicitly ask you now if you’re an american citizen.

My understanding is that GDPR primarily cares about location, not citizenship or residence. There are some subtleties around which location is the relevant one, for example when the delivery address is in a different country from the country the subject is in when they send the order.

> 3.2 This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union,...

(Plus companies in the EU have to comply with GDPR for all subjects)

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#420
post #405

How can they do this without repermissioning current UK users?

Google did something similar with a targeted terms of service update – I believe it was agree or close your account. I suspect that this transfer is going to be consent-based to avoid non-compliance in the handful of cases cases where they have inaccurate data regarding location.

I never agreed. Google just stopped asking after a while. I think I could refer Google to the data protection office, but the chances that they'll actually do anything about it are slim to zero.
Post reply on HN