Live data from Hacker News

Facebook to move UK users to California terms, avoiding EU privacy rules

reuters.com

461–470 of 506 posts

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#461

Earlier quoted context omitted.

> Also on the other side of things, does it harm me more if a foreign government holds information on me, random Joe, or if my own government holds the same info? Might be a good question for Kim Dotcom. Regardless of your views on his various business, it hard to explain how the US arresting a non-US citizen outside of the US isn’t a huge and worrying overstep by the US. Now I probably don’t need to worry about a Ki…

Let me understand you better. Would you say the following? - If FB is to operate under US law with US data centers you prefer to be geo-blocked by them based on IP and feel you need to be protected against your own will and you can't trust yourself to just not use the service - You are concerned about shadow profiles and the like, i.e. the unavoidability of FB even if you want to avoid it. But otherwise you'd be okay…

No, I’m saying if FB wish to operate their product in the U.K. they should follow U.K. law, and respect the rights that U.K. law provides to its citizens.

If FB don’t want to do that, then, yes, they should geo-block the U.K. to avoid the liability.

Being an American company doesn’t give them the right to just ignore local laws and customs of other countries, and it would be hypocritical to think otherwise. The US certainly doesn’t allow counterfeit products to enter from China, despite the fact those products would be mostly considered legal in China. So why the hell should American company’s have the right to ignore laws in other countries, just because somethings not illegal in the US?

Whether I trust myself to use a service is irrelevant. I should be able to use almost any service made readily available to me in the U.K. under the assumption they follow U.K. law. The onus should be on FB to operate legally and ethical, not on me audit every service I use for legal and ethical violations.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#462
post #406

Sort of related, does anyone know if all the consent form popups will stop once the UK leaves the EU?

I think they will go away over time. [RANT] They should never have been implemented that way IMHO -- a different API or IETF-ish agreed HTML meta tag that would inform the browser of the scope, entities etc. would have allowed the browser to offer overall policy choices to the user. Most would be "I don't care, do whatever you want to me" but those who do care could have been picky. That would also have allowed the b…

> [RANT] They should never have been implemented that way IMHO -- a different API or IETF-ish agreed HTML meta tag that would inform the browser of the scope, entities etc. would have allowed the browser to offer overall policy choices to the user.

That would not have been used.

The whole reason why all the consent forms are constantly violating the GDPR is because companies want to make it as hard as possible to say no.

They'd only accept the browser API if the "No to all" button (which by law has to be default, has to be the option chosen if you click anything except yes, and has to be easier to use than "Yes to all") was hidden behind 3 layers of "are you sure", each of which having a 30 second timer before you could continue.

That's the whole reason this consent form disaster exists: because companies are trying to do everything they can go get around the laws.

Just look at the Do Not Track header: it's a legally meaningful statement that companies should follow. They don't.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#463
post #441

Earlier quoted context omitted.

Consent is not required for "essential" cookies, because they are essential. Things like keeping track of your logged in state or shopping cart. (Even if consent were required for that, it should be asked at the point where you login or add the first item). For advertising and behavioural tracking cookies, consent is required if it's tracking your personal data to the level of individually identifiable people, but fr…

Having some way to auto deny consent seems like a good idea. But anything automatic can have serious downsides, what happens if you start denying ‘good’ sites without realising it. Should all things that require consent be blocked? This World Wide Web of permissions sounds like it’s going to be a bit of a nightmare.

The default should always be "block everything". When you try to do an action on a website that requires additional consent, you should be asked additionally.

Just like the iOS/new Android permissions Dialogs. No to all by default, only allowing specific permissions on demand.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#464
post #67

Earlier quoted context omitted.

This is called "Regulatory Capture" and is a form of corruption. It is not /why/ regulation exists any more than the murder of Mr Floyd is why police exist. Regulatory capture is utterly rampant right now and a huge threat to democracy. This is true regardless of one's personal politics or beliefs about big vs small government or political party of preference. It's a cancer and more dangerous than people think.

> Regulatory capture is utterly rampant right now and a huge threat to democracy. Rampant in the US. The EU has managed to avoid the worst of it so far.

The Leistungsschutzrecht is a disaster, though.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#465
post #64

Earlier quoted context omitted.

Citizenship matters not. Only residency. Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.

Okay, what does it mean “residency”? In the UK there’s no address registry where you declare your address. EU citizen works in the UK for 2 years then goes to Turkey for a vacation but likes the place so much, decides to stay for longer when still remote working for the same London company.Also connects through VPN because the Turks love banning websites. Where this person residence is? Are the UK, USA, EU or Turkish…

Countries generally have rules around residency that boil down to "if you spend most of a year within the country you are resident in that country".

Tax residency is separate and the rules are a bit different and again vary by country.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#466
> Facebook Inc will shift all its users in the United Kingdom into user agreements with the corporate headquarters in California

FB surely has a physical office in London, why not make that office the new UK headquarter, and move UK users under, well... UK terms?

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#467

Earlier quoted context omitted.

Incorrect. With GDPR the EU extended their power to protect all EU citizens regardless of residency in, or out, of the EU. Of course the EU will have trouble enforcing that protection against companies that don't operate in the EU. But the protection remains, even if it's practically unenforceable.

I'm British and have a British passport and I permanently reside in the UK but I'm also technically an Irish citizen because my Irish father was born in Ireland. I have never applied for an Irish passport but I am automatically an Irish citizen based on my ancestry. Does Facebook know this? Do I need to inform them to benefit from GDPR protections on an ongoing basis? How the hell is any of this enforceable?

> Do I need to inform [facebook] to benefit from GDPR protections on an ongoing basis?

That depends on what you want to do. What GDPR protection are you trying to benefit from?

> How the hell is any of this enforceable?

You can try to reach out to the regulator if you believe your GDPR protections are being violated,

https://www.dataprotection.ie/

My experience with the ROI is that they are unlikely to jeopardise Facebook pulling out of Dublin.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#468

Earlier quoted context omitted.

Centralization of supply chains, economic monoculture, increased spread of disease, increased carbon emissions, massively increased pollution. That’s a lot of risks which are mostly unquantifiable; it’s dubious to claim we know which is worse, especially in the long run. We lived without globalism for many thousands of years, it’s incredibly new and unproven.

We had a much less global world in the early 1900s. Didn’t stop the Spanish flu and multiple world wars from happening.

[deleted]

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#469
post #441

Earlier quoted context omitted.

Having some way to auto deny consent seems like a good idea. But anything automatic can have serious downsides, what happens if you start denying ‘good’ sites without realising it. Should all things that require consent be blocked? This World Wide Web of permissions sounds like it’s going to be a bit of a nightmare.

The default should always be "block everything". When you try to do an action on a website that requires additional consent, you should be asked additionally. Just like the iOS/new Android permissions Dialogs. No to all by default, only allowing specific permissions on demand.

It’s so opaque though. Most of the time I have no idea what I’m really consenting to. Every website has a different way of asking, a different way of describing what it’s asking consent for. It often feels like the list of permissions being asked for is way more than what is necessary.

Compare that to reading a magazine:

- Step 1 - open

- Step 2 - read

It’s night and day. Eventually it will be too difficult to use the web. I’m think people who make a living from building for the web have not grasped the severity of the problem.

If you worked in the movie business and someone said that eventually it would be too difficult to watch a movie, because you would have to give permission left right and centre, you would be worried because that’s bad for business. Your viewers will eventuakly go do something else.

Well that’s what’s happening on the web.

Re: Facebook to move UK users to California terms, avoiding EU privacy rules

#470
post #3

Tech companies, or any company for that matter, will do what is best for themselves. Regulations exist to protect consumers and other companies from accusative behaviors. Remove the regulation and the 'we care for your privacy' message disappears with it. Because they never cared for your privacy, they will just doing what was mandatory.

> Regulations exist to protect consumers and other companies from accusative behaviors. I think this is possibly a bit naive. Regulations also exist to protect powerful people's businesses, to push personal agendas, and to further political aims even if those are not actually in the interests of any consumers. Also sometimes people think they're making a regulation to protect consumers, but actually it makes things w…

Sure. Businesses will try to protect themselves with regulation to whatever extent possible - it's what the market does (which is why I find it silly to discuss private markets and governance as if they were two separate and independent things). But "no regulations" isn't a solution to regulatory capture. It'll only make competition more cut throat (possibly involving real throats being cut), and companies more anticonsumer.

(Not that any of this matters much these days - companies like Uber demonstrate that you can absolutely run an illegal operation in western countries, and end up with a double-digit billion dollars IPO.)

Post reply on HN