Live data from Hacker News

Facebook to ask everyone to accept being tracked so they can keep using it

independent.co.uk

71–80 of 162 posts

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#71

Earlier quoted context omitted.

response to: https://news.ycombinator.com/item?id=16870636 This thread is now too deep for me to respond to your comment. "The reach of GDPR is broad but is not unlimited. The mere fact that a U.S.-based website can be accessed in the EEA isn’t enough. If the company does not have a physical presence in the EEA, it must be determined whether that company engages in more than incidental contact with EEA residents." Th…

The experts that I talked to in this space in deciding to close my sites to EU IPs have all said that the GDPR probably doesn't apply to incidental traffic - especially if someone is actively trying to hide the fact that they are in a GDPR area. But nobody can guarantee a single thing, because it's so broadly written and is up for unique interpretations in each of dozens of foreign countries. It meets the very defini…

Ah, neat.

Experts say a lot of things on GDPR, one of the really interesting things about reading it myself is that I've found a lot of them seem to be wrong. I've heard a few people talking about a "social media exception" that doesn't seem to exist, for example.

It's possible that there have been preliminary rulings on GDPR that I'm not aware of, because I'm not a lawyer. So I'm not by any means declaring that your experts are definitely wrong, but I am nigh on certain that their source of information for making such statements is not the GDPR text itself.

I disagree that GDPR is an overly broad law by the way. The GDPR text is actually fairly specific. It encompasses a large domain, but it clearly defines that domain (Article 9 is an example of a large but specific definition, although it is only one of multiple such articles) and tells you clearly what you need to do within that domain to be compliant.

People just /think/ it's overly broad because it impacts a lot of tech companies and none of them have actually read the text. The human brain interprets this as "inspecific", whereas it's actually carefully targeted at a handful of specific things that lots of tech companies are doing (or not doing).

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#72
This action directly violates GDPR, the consent is not freely given and as such not valid. Trackwall is not acceptible, that's why "freely given" is written in Article 7.4.

Bottom line, even if you give them consent in such forced manner, they will pay the fine if they use the data. Not only that, I bet that in this moment there is a lawyer preparing class action against FB for forcing the consent (And they will win! After 25th of May, FB is breaking the EU law). Max Schrems gave FB hard time before and I bet he is just waiting for new chance, this is his site https://noyb.eu/ , check it and check how many donations he got. I am stockpiling myself with popcorns as this is going to be fun to watch. I really thought that FB is going to be smarter, probably Zuck got another of his tantrums and did another really stupid business mistake, that will cost him a lot.

But, as FB user, please consider something else: Facebook is trying to downplay your rights, which directly proves that don't care about you. Do you really want to continue using such service? Do you really value yourself so low that you are prepared to bend over?

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#73
post #64

Earlier quoted context omitted.

You have no idea what you're talking about. Per GDPR, it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis. In this case, since this isn't necessary for fb, the only available basis is consent. As for your havoc example, that shows nothing. If FB allows people to post image buttons on their site, it's FB's responsibility to ensure consent or del…

it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis You're correct. They are ensuring it by placing it in their terms for the use of their code/images on other sites. Nowhere in the GDPR does it say that every third party whose content may be placed on a site must themselves obtain consent. What exactly do you envision? That each page you load…

nope, try again.

FB doesn't get to use the data unless it's consented by the end user.

It is distinctly not GDPR compliant for FB to claim that their TOS requires consent so it's not their problem. Feel free to read the discussion about co-controllers (called as joint controllers) and particularly the A29WG guidance.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#74
post #73

Earlier quoted context omitted.

it's the controller's (in this case FB is def a controller) responsibility to ensure that their use of data has a legal basis You're correct. They are ensuring it by placing it in their terms for the use of their code/images on other sites. Nowhere in the GDPR does it say that every third party whose content may be placed on a site must themselves obtain consent. What exactly do you envision? That each page you load…

nope, try again. FB doesn't get to use the data unless it's consented by the end user. It is distinctly not GDPR compliant for FB to claim that their TOS requires consent so it's not their problem. Feel free to read the discussion about co-controllers (called as joint controllers) and particularly the A29WG guidance.

Again, under your (incorrect) interpretation of the GDPR, what exactly do you envision? That each page you load have 40 different consent dialogs show up - one for each tracker and external image that is on the page? Some have hundreds.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#75
post #11

Earlier quoted context omitted.

Heh, funny. Unfortunately also nonsense. A CFO also exists and not because a company doesn't handle finances responsibly. Or a CEO implies no engineering?

I think you misread. The implication was that Facebook would not exist with real privacy in the product, not the role of CPO within Facebook.

Yes, this is correct. Thanks for clarifying.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#76

Earlier quoted context omitted.

I'm curious what about that notification is "hidden away in legal wording" or doesn't "require active consent". You have to agree with it to make that go away.

At least the way my multi-national employer is interpreting it, under GDPR you can't get away with "click here if you agree with our privacy policy". You have to explicitly say everything that is tracked, everything that is stored, how long, and why it is required for use. If it's not required for use, you can't ask for it and you can't store it unless the person explicitly says yes. If they say no, you have to let t…

> If they say no, you have to let them use it anyway, without the tracking and without the storing.

This is the part I'm most excited about. (Or would be if I lived in the EU.) I'll be very interested to see how that works out. I'd love to see something like that in the US.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#77
post #27

My adblocker detects approximately 44 trackers on that page, including one from connect.facebook.net.

The article isn't "Independent to ask everyone to accept being tracked".

No, but how can you trust a source if they are doing the exact same thing? They are a bit hypocritical.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#78
post #3

I just added the "Facebook Container" extension to my Firefox browser. I am hoping it will prevent most of Facebook's tracking, but I do know that it probably won't block all the tracking.

yup likewise. I noticed their 'opt out for interest based ads' was through a cookie set by some consortium of creeps companies. at the time I remember thinking its like 'if I dont want you to track and follow me all over the internet then I need to allow you to track me and follow me all over the place so you know who I am.. Riiight'. plus that setting resets if you delete the cookie. so I dont know how will that wor…

> given that FB is after my healthcare data

What? Can you provide a link to that? I hadn't heard this before, and find that really disturbing. I'd like to learn more.

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#79

Earlier quoted context omitted.

yup likewise. I noticed their 'opt out for interest based ads' was through a cookie set by some consortium of creeps companies. at the time I remember thinking its like 'if I dont want you to track and follow me all over the internet then I need to allow you to track me and follow me all over the place so you know who I am.. Riiight'. plus that setting resets if you delete the cookie. so I dont know how will that wor…

> given that FB is after my healthcare data What? Can you provide a link to that? I hadn't heard this before, and find that really disturbing. I'd like to learn more.

they might be referring to this: https://www.theverge.com/2018/4/5/17203262/facebook-medical-...

Re: Facebook to ask everyone to accept being tracked so they can keep using it

#80

Earlier quoted context omitted.

At least the way my multi-national employer is interpreting it, under GDPR you can't get away with "click here if you agree with our privacy policy". You have to explicitly say everything that is tracked, everything that is stored, how long, and why it is required for use. If it's not required for use, you can't ask for it and you can't store it unless the person explicitly says yes. If they say no, you have to let t…

> If they say no, you have to let them use it anyway, without the tracking and without the storing. This is the part I'm most excited about. (Or would be if I lived in the EU.) I'll be very interested to see how that works out. I'd love to see something like that in the US.

> If they say no, you have to let them use it anyway, without the tracking and without the storing.

That part of what he said is incorrect. The EU may be able to do alot of things, but they can't make me give you access to private documents on my server that is not based in the EU if I don't want to. You can simply tell them to go away if they disagree with your terms, or you can block all EU users from the beginning.

Post reply on HN