Live data from Hacker News

Facebook to ask everyone to accept being tracked so they can keep using it

independent.co.uk

61–70 of 162 posts

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#61
post #59

Earlier quoted context omitted.

this is fundamentally insufficient, though. if there's a hosted image from a facebook domain (e.g. a like button), unless that image is loaded after consent is given, facebook can already associate that users' IP address with having visited that web site by nature of sending the image over. in other words, facebook is tracking pre-consent (unless those images are loaded post-hoc, which is just not happening in today'…

It doesn't matter if you load an image off fb. per GDPR, without consent, fb cannot legally use that data (for EU residents). And you don't need to trust that; fb knows they're going to be spending some quality time in front of their privacy regulator.

You're actually wrong. It is the responsibility of the website to notify the user. Facebook has placed in its policies a rule that says that you cannot use its code/buttons/images on your site without obtaining consent by the user for FB to place cookies there. They have a reasonable expectation that you have complied with this, or the image/whatever would not have been caused to load by your site.

Otherwise, think of the havoc. You decide that you want to get Facebook in trouble. So you place a Facebook button on your site and don't notify users or ask consent. Then you go call regulators. In this case, you'd find yourself in trouble, not Facebook.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#62
post #6

Earlier quoted context omitted.

Won't ublock [1] solve that by blocking that kind of scripts from loading? [1] https://www.ublock.org/

I recommend Privacy Badger, sponsored by the EFF, which is supposed to block trackers. I prefer it over Ghostery, which is backed by some company. uBlock Origin is great for blocking Ads though. If you really need to block scripts, there's NoScript. I recommend using at least the adblocker and the tracker blocker, even if only to reduce memory usage of the browser and take back a couple of CPU cycles from your comput…

Not to mention that ghostery used to sell your data to advertisers. I think they stopped, but how ironic can it get!?

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#63

Earlier quoted context omitted.

In that case, you won't have any reason to believe that they are an EU citizen unless and until they indicate otherwise, and there are provisions within the GDPR for it not to apply in those cases where you are not intentionally obtaining data from EU citizens. On my sites that don't get alot of EU traffic anyway, I'm simply blocking EU IPs, and on all registration forms, I've removed EU countries from the country se…

>there are provisions within the GDPR for it not to apply in those cases where you are not intentionally obtaining data from EU citizens. I read the entire document a few weeks back and recall no such provisions. Could you cite one for me? I'm trying to be as informed on this as possible. Article 3, "Territorial scope", lays out where GDPR applies, and it contains no derogations for "but I didn't know they were europ…

It's a massive document so I'm not going to go through and find it, but here's an interpretation of what I'm talking about [1]:

"The reach of GDPR is broad but is not unlimited. The mere fact that a U.S.-based website can be accessed in the EEA isn’t enough. If the company does not have a physical presence in the EEA, it must be determined whether that company engages in more than incidental contact with EEA residents."

So if someone is going out of their way to mask the fact that they are from the EU, and you aren't otherwise seeking out EU users, you're not going to get in trouble for that. One issue I have with it though is that translation may trigger GDPR exposure, and since Spain is part of the EU, many sites aimed at Spanish speakers (but not aimed at the EU) may have this beast of a law apply to them. I operate a few sites that have Spanish content, so that is deeply troubling.

[1] https://www.gtlaw.com/en/insights/2018/2/the-gdpr-deadline-l...

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#64
post #59

Earlier quoted context omitted.

It doesn't matter if you load an image off fb. per GDPR, without consent, fb cannot legally use that data (for EU residents). And you don't need to trust that; fb knows they're going to be spending some quality time in front of their privacy regulator.

You're actually wrong. It is the responsibility of the website to notify the user. Facebook has placed in its policies a rule that says that you cannot use its code/buttons/images on your site without obtaining consent by the user for FB to place cookies there. They have a reasonable expectation that you have complied with this, or the image/whatever would not have been caused to load by your site. Otherwise, think o…

You have no idea what you're talking about. Per GDPR, it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis. In this case, since this isn't necessary for fb, the only available basis is consent.

As for your havoc example, that shows nothing. If FB allows people to post image buttons on their site, it's FB's responsibility to ensure consent or delete the data on ingress.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#65
post #64

Earlier quoted context omitted.

You're actually wrong. It is the responsibility of the website to notify the user. Facebook has placed in its policies a rule that says that you cannot use its code/buttons/images on your site without obtaining consent by the user for FB to place cookies there. They have a reasonable expectation that you have complied with this, or the image/whatever would not have been caused to load by your site. Otherwise, think o…

You have no idea what you're talking about. Per GDPR, it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis. In this case, since this isn't necessary for fb, the only available basis is consent. As for your havoc example, that shows nothing. If FB allows people to post image buttons on their site, it's FB's responsibility to ensure consent or del…

it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis

You're correct. They are ensuring it by placing it in their terms for the use of their code/images on other sites. Nowhere in the GDPR does it say that every third party whose content may be placed on a site must themselves obtain consent. What exactly do you envision? That each page you load have 40 different consent dialogs show up?

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#66

Earlier quoted context omitted.

In that case, you won't have any reason to believe that they are an EU citizen unless and until they indicate otherwise, and there are provisions within the GDPR for it not to apply in those cases where you are not intentionally obtaining data from EU citizens. On my sites that don't get alot of EU traffic anyway, I'm simply blocking EU IPs, and on all registration forms, I've removed EU countries from the country se…

>there are provisions within the GDPR for it not to apply in those cases where you are not intentionally obtaining data from EU citizens. I read the entire document a few weeks back and recall no such provisions. Could you cite one for me? I'm trying to be as informed on this as possible. Article 3, "Territorial scope", lays out where GDPR applies, and it contains no derogations for "but I didn't know they were europ…

response to: https://news.ycombinator.com/item?id=16870636

This thread is now too deep for me to respond to your comment.

"The reach of GDPR is broad but is not unlimited. The mere fact that a U.S.-based website can be accessed in the EEA isn’t enough. If the company does not have a physical presence in the EEA, it must be determined whether that company engages in more than incidental contact with EEA residents."

This statement seems to have misinterpreted article 27, which states that if your processing is merely occasional, or if you are occasionally a processor for an EU controller, you need not specify a designated representative to the EU.

Read more here: https://gdpr-info.eu/?s=occasional

But the exception you think exists pretty much doesn't. It's got a small exception for occasional sharing of data without consent when it relates to active legal proceedings.

Naturally the EU has no jurisdiction over you if you don't live in the EU and you aren't based in the EU. They may be able to apply pressure on your partners though, be that advertising companies or others. This may flow through to you, in time. We're already seeing Facebook come under pressure to provide US citizens with the same protections that the GDPR provides EU residents.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#67

Earlier quoted context omitted.

but, at the risk of rabbit-holing, your suggestion would be a pretty fundamental change to how the web works. in effect, you'd be moving toward a splintered web, where content is basically region locked. I think you're spot on, but that was the danger of implementing heavy-handed legislation like GDPR all along. I believe that EU citizens are going to find themselves locked out of a whole world of content. But that's…

Hmm. I'm not sure about that. If Apple and Google won't pull out of China even though China makes them do all sorts of business stuff they disagree with, I highly doubt they (web companies) would pull out of the entire EU. It would be absolutely incredible if Facebook et al "took their ball and went home" throwing away 500 million customers .

Google did effectively pull out of China in 2010 [1].

But in the case of the GDPR, it probably helps Google and Facebook more than it hurts them -- they can afford to jump through all of its hoops while smaller competitors might have trouble. It's essentially a barrier to entry.

[1] https://en.wikipedia.org/wiki/Google_China

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#68

Earlier quoted context omitted.

>there are provisions within the GDPR for it not to apply in those cases where you are not intentionally obtaining data from EU citizens. I read the entire document a few weeks back and recall no such provisions. Could you cite one for me? I'm trying to be as informed on this as possible. Article 3, "Territorial scope", lays out where GDPR applies, and it contains no derogations for "but I didn't know they were europ…

response to: https://news.ycombinator.com/item?id=16870636 This thread is now too deep for me to respond to your comment. "The reach of GDPR is broad but is not unlimited. The mere fact that a U.S.-based website can be accessed in the EEA isn’t enough. If the company does not have a physical presence in the EEA, it must be determined whether that company engages in more than incidental contact with EEA residents." Th…

The experts that I talked to in this space in deciding to close my sites to EU IPs have all said that the GDPR probably doesn't apply to incidental traffic - especially if someone is actively trying to hide the fact that they are in a GDPR area. But nobody can guarantee a single thing, because it's so broadly written and is up for unique interpretations in each of dozens of foreign countries. It meets the very definition of a bad law - too broad and will cause decreased economic opportunity for those that are subjected to it.

FYI you can reply to other posts when the thread is this deep by clicking on the "X minutes ago" thing on the comment your want to reply to.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#69

Earlier quoted context omitted.

I'm curious what about that notification is "hidden away in legal wording" or doesn't "require active consent". You have to agree with it to make that go away.

At least the way my multi-national employer is interpreting it, under GDPR you can't get away with "click here if you agree with our privacy policy". You have to explicitly say everything that is tracked, everything that is stored, how long, and why it is required for use. If it's not required for use, you can't ask for it and you can't store it unless the person explicitly says yes. If they say no, you have to let t…

I'd be fascinated to see what that looks like.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#70

Earlier quoted context omitted.

I've always dealt with the cookie notifications by using ublock to simply block that element, I never click "ok". I've never had a website actually stop me from using it when I do this until google changed their search page a few weeks ago. I imagine that you simply won't be able to use websites anymore if you are from the EU and don't give consent. You'll just be told to go away.

It's trickier than that for the website owner. EU citizens accessing websites through VPN's are still protected by GDPR.

As are non-EU citizens while in the EU, in some cases, and possibly even non-EU citizens not in the EU while using a service centered on providing them with e.g. travel arrangements in the EU. As a lawyer specializing in GDPR recently told me. Even investigative data journalists are going to have a lot of fun with the consequences of GDPR if she's right.
Post reply on HN