Live data from Hacker News

Facebook’s tracking of non-users ruled illegal again in Europe

techcrunch.com

61–70 of 395 posts

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#61
post #13
post #2

>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA If it is "industry standard", does that make it ethical?

I think the implication is more, "why are you only paying attention to us ? If you think this is a bad practice, then you should be going after our competitors , too." Corporations tend not to mind if you take away a business strategy of theirs, as long as you take it away from everybody else at the same time. If you only take it away from one corporation, that corporation will be temporarily outcompeted by the corpo…

Yeah. How many times this line saved you?

"Officer, The guy in front of me was driving fast too, so why not him?"

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#62
post #13
post #2

>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA If it is "industry standard", does that make it ethical?

I think the implication is more, "why are you only paying attention to us ? If you think this is a bad practice, then you should be going after our competitors , too." Corporations tend not to mind if you take away a business strategy of theirs, as long as you take it away from everybody else at the same time. If you only take it away from one corporation, that corporation will be temporarily outcompeted by the corpo…

This business strategy is only viable if your market penetration is huge. No wonder the biggest infringer is tackled first. Also, this probably is a precedent-setting decision with more to follow.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#63
post #51

Earlier quoted context omitted.

>Funny. If your site drops dramatically on Google's search results, or if YouTube/Facebook bans your account for reasons, tough luck. They are a corporation and can do whatever they want without resorting to any sort of internal consistency. That's not really relevant to the parent's observation that Facebook is likely arguing that they're being singled out in an environment where their practices are so rampant as to…

This law has to be enforced somewhere first. Either it is enforced against Facebook first, and Facebook complains "Why don't all of the the small fries have to do it yet" and if it is enforced against the small fries, they will say, "Why doesn't Facebook have to do it yet"? And the answer is, the justice department will probably enforce the law in the way that the expect to have the best effect for themselves. It is…

That’s not typically how things usually work.

When a government agency (think IRS or FAA) decides on a specific interpretation of a law, rule or regulation, they don’t go after a random guy to prosecute. They publish an opinion, a guideline, or interpretation and a compliance deadline. The industry is given a choice to comply or present an alternative interpretation (through courts, lobbyists or legislative representatives).

It’s one thing if one company out of a hundred doesn’t comply, and somewhat different when the standard industry practice goes against new interpretation.

Selective encorcement is more typical of countries with weak judicial systems and endemic corruption, where “friends” of the current government get compassionate understanding, but everybody else is subject to the strict rule of the law.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#64
post #48

Earlier quoted context omitted.

But Facebook and Google are the biggest and most flagrant offenders. It wouldn't make sense to go after anyone else first, and you want to have a precedent so you can go after other companies (or other companies will stop committing crimes of their own volition because being litigated against is expensive). As for your belief that American companies are being unfairly targeted, this also doesn't make much sense to me…

>European companies wouldn't break the laws in the first place, Asian companies don't really compete in the European "web services" market, so the only major source of rights violations is going to be American companies. European companies are just as capable of violating the law as American companies. Part of the argument being made by critics is that there's been little sign that comparable effort has been made by…

> European companies are just as capable of violating the law as American companies.

I never said they aren't capable, I said that they would generally choose not to (not to mention that "hosted in Europe" is actually now becoming a bit of a selling point because of the pro-privacy regulations there).

> Part of the argument being made by critics is that there's been little sign that comparable effort has been made by European governance to investigate its domestic companies as rigorously as it's been investigating America's.

European regulators are very strict with European companies in a variety of ways. Just because it doesn't make international news every week is not proof that it doesn't happen (I work for SUSE remotely and my impression is that the German government is very meticulous about verifying that companies aren't breaking the law.)

> The counterpoint would be that the companies are only breaking the law because the EU decided that its laws can be applied globally.

Facebook and Google do business with people in Europe (provide a service and use them as ad-fodder). This is similar to exporting goods to Europe -- you need to obey the laws of the country if you want to do business there. They actually have an even better deal than than that, because there are no tariffs for online communication! Not to mention that Facebook and Google have physical hardware in European countries.

They aren't enforcing their rules globally, they're saying "if you want to engage with our citizens you have to play by our rules." Facebook and Google can always choose to block those countries (like they do Iran).

> Because it's difficult to believe that there's only enough resources to prosecute a handful of companies at a time.

This case was by a privacy watchdog, a private organisation. I find it very believable that they don't have enough resources to sue the likely several thousand American companies that are potentially violating EU laws. I also would be surprised if the Belgian government had enough cash lying around to do that too.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#65
post #37
post #4

Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry: * Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service * Opt-in/out separately for every activity (no more "research purposes") * Data dele…

Note: the following questions are not because I'm trying to figure out how to work around GDPR. They are to help figure out just what the meaning of it is. Imagining hypotheticals that try to work around a law is a common method in legal circles for clarifying the law. My employer does not keep any data that would be problematic, and compliance looks like it will be pretty easy for us [1]. > Explicit consent for non-…

>1. Suppose that the data is used to pay for keeping the site afloat? Does that make it essential?

If you use the data for bank transactions or paypal subscriptions it's essential.

If you sell the data for profit, it might be essential but it falls under "opt-in only" of the GDPR. So in this part; not essential in the above sense.

>2. Suppose my site is presented as a site that has basic and premium content. The premium content is behind a subscription paywall.

Subscription paywall is fine. What isn't fine is degrading the service if the user opts out of having trackers included in the website when they visit.

>3. In #2, does it matter if that's how my site works for people that I can identify as being the EU, but works different for people elsewhere (e.g., for people in the US it collects data on everyone and does not offer the option to pay)?

GDPR only applies when you target people currently in the EU (citizen or not) and EU citizens outside the EU.

>4. Suppose I just say "the hell with this...I don't want to deal with GDPR", and have my site ask first time visitors if they are in the EU or EU citizens.

If they say no, I would say that is okay to believe considering the GDPR also requires a "Are you 16" question. Ask a lawyer.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#66
post #11
post #4

Looking forward to May (when GDPR officially comes into force). Provided that it doesn't end up like the cookie law (and there are explicit provisions in GDPR and ePrivacy to avoid that) this might shake up the ad industry: * Explicit consent for non-essential data use, you always need to provide opt-out without degrading the service * Opt-in/out separately for every activity (no more "research purposes") * Data dele…

Can you elaborate on what you mean by "doesn't end up like the cookie law"? I'm an American and don't have much awareness of this other than I've noticed that sites in the EU like the Guardian tend to have annoying banners saying they use cookies at the bottom of their splash screens.

TL;DR: sites were obliged to provide information and ask for consent when using marketing cookies. That is, cookies required for the site to work (e.g. session) were fine, but tracking/analytics were not. Everyone started to show banners saying "we use cookies [OK] [what cookies?]", users just got used to clicking OK on them, and almost nobody has any clue what this was all about.

You could see the cookie law as a gentle request for Internet businesses to self-regulate and limit unnecessary tracking. It didn't work (I don't know of any case when businesses decided to self-regulate themselves out of potential extra profit), so now GDPR is meant to force companies to stop their user-hostile data abuse.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#67
post #2

>“The cookies and pixels we use are industry standard technologies and enable hundreds of thousands of businesses to grow their businesses and reach customers across the EU,” said Facebook’s VP of public policy for EMEA If it is "industry standard", does that make it ethical?

>enable hundreds of thousands of businesses to grow their businesses

Seems innocuous enough until you really think about what they're saying. "But, tracking these people without their consent allows companies, including us, to make money off of them".

That's actually a pretty brazen thing to say; as if the fact that people can be monetized should trump their right to privacy.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#68
post #50

One of the good things about HN is that the engineers working and building these features are likely reading these posts too, I'm curious how one implements these things. Are engineers (some of the brightest ones) not realizing that some of their actions are ethically questionable, or is the big picture not visible to the average engineer in a large company like FB? I assume that many have the exact same reaction and…

Afaik software will be sane untill Lawyers and Finance execs are involved. Once they are into your company no more great software.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#69
post #22
post #21

Earlier quoted context omitted.

Perhaps there should be a central clearinghouse for people who don't want to be tracked by certain sites. How can you tell facebook to not track you without a facebook account? The best you can do is block various known IPs or other patterns which are bound to change over time.

>How can you tell facebook to not track you without a facebook account? That's the wrong question to ask. You shouldn't have to tell it not to track you. That shouldn't be able to do it, unless you explicitly tell them "hey you can track me."

If only. That battle seems to have been lost long ago, at least in the U.S.

Google, Criteo and other have long had a default opt-in policy for their retargeting products, etc.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#70
post #51

Earlier quoted context omitted.

This law has to be enforced somewhere first. Either it is enforced against Facebook first, and Facebook complains "Why don't all of the the small fries have to do it yet" and if it is enforced against the small fries, they will say, "Why doesn't Facebook have to do it yet"? And the answer is, the justice department will probably enforce the law in the way that the expect to have the best effect for themselves. It is…

That’s not typically how things usually work. When a government agency (think IRS or FAA) decides on a specific interpretation of a law, rule or regulation, they don’t go after a random guy to prosecute. They publish an opinion, a guideline, or interpretation and a compliance deadline. The industry is given a choice to comply or present an alternative interpretation (through courts, lobbyists or legislative represent…

Well, it's not that they haven't been talking publicly for years that they are going to do something.

And I guess Facebook and others have been trying to lobby it away for years already.

Post reply on HN