The key point is; it's not the CEO's company. He works for a pay check, the share holders invest for long term profits. Big difference.
Plus, they need the cooperation of governments. Their patents are just pieces of paper without governments enforcing them, for example, and their data centers need special power solutions. Governments don't trust companies that ignore government regulation.
And, even if they hope that the US government is more lax with their restrictions and will turn a blind eye, the US is very heavily dependent on the OECD working, and not helping the EU prosecute blatant criminals would be a big problem for American credibility.
This is not even getting into the fact that the EU is a much larger market than the American market is, too.
In practice, just pretending regulations doesn't exist (depending on the regulations in question, of course) can be stupidly expensive for the company in question. Share holders don't like stuff that's risky and expensive and would replace a CEO that mad.
If by substantially smaller you mean 'pretty much the same size' then yes you're right.
https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(PPP) is pretty clear:
2016 GDP (PPP) figures: US $18.6T, EU $19.7T (6% higher than US), UK $2.8T, EU - UK $16.9T (10% lower than US)
A very real possibility is that Google/Facebook will have these choices:
- Comply with GDPR.
- Shut down business in Europe entirely and eventually be forced to repatriate offshore assets and incur the relevant taxes.
- Continue business in Europe, ignore the GDPR and pay a fine of 4% worldwide revenue.
- Continue business in Europe, ignore the GDPR, don't pay the fine, have all European assets frozen.
That's ignoring the possibility that the EU may be able to reach their US assets as well.
They could shut down all their European operations, but that would cost them a lot more than 4% of revenue.
There's an interesting assumption in there, and I'm not entirely sure it's a correct one. Facebook and its subsidiaries play a large part in many people's everyday lives now, in particular forming the main way a lot of people stay in touch with their friends and family. It is not at all clear to me what would happen if Facebook decided to call the EU's bluff here and literally switched off its service to everyone in the EU for a day or two, replacing it with a single page explaining that until the law was changed they would not be able to provide their service to EU customers.
People stop using it as much.
That seems particularly bad for Facebook, given the network effects it relies on.
If everyone in Europe woke up one morning next year to find Facebook saying that as a result of new EU law they had been required to turn off their service and please would everyone write to their representatives (using the form conveniently provided below) to ask why they'd done this, what do you think would happen?
SOPA felt like a gift to Evil Media Corporations at the expense of The Internet People.
If Facebook goes dark as a protest against GDDR, people are far more likely to side with the EU, than with the Evil Corporation That Avoids Taxes.
Facebook would disappear from the EU
I bet customers would rally against the law rather than pay microtransactions.
Sadly, I think it's quite clear that most people are not that worried about it, even in Europe. Or at least, if they are, they're willing to put up with it for the convenience of the services they get in return.
The real problems, IMHO, are a lack of awareness particularly among non-technical people of what is really happening and its implications, and a lack of competition so that those who do value their privacy more highly can choose to protect it without giving up normal parts of modern life.
If that happens, how long do you think it will take a bunch of companies to spin up replacements for Facebook? It's not exactly rocket science to create a social network application; most of the value of Facebook also does not lie in the platforms' code, but in the network effects that it managed to create. Thus, there would be a timeframe in which a huge number of new social networks would try to win over a critical amount of users, with one of them eventually emerging as the dominant one. As soon as that happened, Facebook would have quite a big problem in case they ever wanted to re-enter the European market, as it would suddenly have to compete with a big network with serious network effects keeping their users from re-joining Facebook, even if that was suddenly possible again. They would probably decide to shill out the largest sum of money ever to simply buy up this competitor, because otherwise there would be a certain risk of the new competitor eventually winning the global race for the dominant network (I assume that due to network effects there will always be a clear gravitation towards a single global general-purpose social network, as long as access to this network is not purposely blocked), and no matter how low this risk is, Facebook would most likely try to eliminate it (remember the large sums they paid to buy up possible dangers in the past).
Other commenters already compared the situation with China; I think that is a pretty good comparison, just that the whole development/transition phase would happen much faster, now that it is pretty well known how the final product would have to look like to be accepted by the user.
True enough, but assuming they decided to pull the stunt before the new laws came into effect, which isn't until the middle of next year, the real question is whether public opinion could be shifted in so little time.
In most cases, I'd say that was extremely optimistic. However, in this case we're talking about a service used by probably a large majority of voters across Europe, often for considerable time every day and for communications and arrangements that matter to them personally. "If they don't change this, you'll lose Facebook, Instagram and WhatsApp" is sure to get some people's attention, and all of those services going dark would probably make the front page of major news outlets. There would certainly be a lot of discussion; in fact, it might be a doubly effective move, because a lot of people would immediately then realise that without those services their main ways of telling their friends about something wasn't working.
If that happens, how long do you think it will take a bunch of companies to spin up replacements for Facebook? [...] Thus, there would be a timeframe in which a huge number of new social networks would try to win over a critical amount of users, with one of them eventually emerging as the dominant one.
I'm not sure that's how things would play out, if Facebook really did go offline permanently in Europe because of this. It would take vast resources to operate a social network on the scale of Facebook, but more importantly, before you could even start, the first thing you'd have to do is figure out how to comply with the same EU data protection rules and presumably then you'd also have to convince some serious investors that you could do it. If Facebook had already failed in that -- because obviously Facebook isn't just going to surrender the entire EU market and all its advertising revenue without a very good reason -- then why would we expect any new social network without all of Facebook's advantages to be able to comply if it was otherwise operating on the same basis, i.e., free to use but ad-supported?
Interesting idea. I did not think about this, mostly probably because I would never do this if I was Facebook because there is a very real risk of it back-firing. Many people here (I'm living in Germany), especially among the politically active, are in a kind of love-hate relationship with Facebook, and a clear attempt of blackmailing an entire continents' population in order to force political action in favor of an absurdly rich, multinational corporation could very well kill off whatever positive attitude there is towards Facebook in particular.
As of competition having to comply with the privacy law: of course it would have to. But I also assume that this is not impossible at all, it is just inconvenient and costly, especially if you have a huge legacy system built under the assumption that you can do practically everything with the data of your users. If you design your system in compliance with the data protection law in the first place, this gets considerably easier. Money would not be a problem at all: there are more than enough investors in Europe who would love to throw money at an attempt to create a second multi-billion-dollar money-printing machine in a market that is currently assumed to have a very high barrier of entry (but exactly that would change if Facebook gave up on Europe).
I also assume that it will not be impossible at all for Facebook to comply with these regulations, just pretty inconvenient. Under this assumption, any refusal to comply must automatically be motivated by a desire to maximize profits and minimize political influence on the platform, not by a sheer struggle for survival. Facebook's PR department might try to spin this into a different story, however...
This is a common assumption, and it might prove to be correct, but I'm unwilling to accept it as axiomatic.
Fundamentally, just looking at the right of a data subject to withdraw consent, it would mean Facebook needed to track every piece of data that could conceivably be tied back to an identifiable person throughout its entire organisation. That's not just their status updates or that time a friend tagged them in a photo. It's every photo in Facebook's entire database that ever included a recognisable image of them, tagged or not. It's every line in a log file that was saved by an engineer investigating a server glitch that relates to any activity that user took. It's everyone who uploads their contacts to find friends and has one of those data subjects in their contact list.
Now, I'm not saying I think Facebook should necessarily be able to do all of the above. In particular, I have often questioned their hoarding of data from things like contact details and photos that will inevitably include other people who may not have chosen to use Facebook or give their consent.
But I am questioning whether it is practically viable, even for an organisation with Facebook's scale and resources, to follow the letter of this law and still operate at all while continuing to provide similar services, if a few people decide to make a point and explicitly deny consent to hold any data about them, even if such data was supplied by other people. There are practical, ethical and legal issues here about third parties and automated systems that we have barely begun to explore, and we're talking about them at a scale where businesses like Facebook and Google have already had to invent new techniques and strategies for organising data just to cope with what they already do.
None of this has even touched yet on whether Facebook would still have a viable commercial model if users have a right to opt out of processing their data for purposes such as advertising but Facebook isn't allowed to deny them service in return, which is another interpretation I've seen talked about a lot (on the basis that an opt-out that stops you using something independent as well isn't a true opt-out and so wouldn't count). So far, I haven't studied the GDPR and informed reviews of it enough to reach any firm conclusions or opinions on that side of things, but again there are surely issues about the obligations of an organisation that offers a useful service but relies on advertising to fund it that go far deeper than just Facebook and the GDPR that haven't really been explored up to this point.
As surprising as it may seem given my comments in this discussion, I'm actually a pretty firm believer in stronger privacy rights and a confirmed sceptic when it comes to the big data hoarders like Facebook and Google. But I'm also someone who runs businesses and has first-hand experience of what happens when the EU's non-technical legislators meddle in technical issues they don't fully understand, often missing even the blindingly obvious consequences, never mind the more subtle and/or long-term implications. So I don't think we should dive into changes like this without considerable thought, and contrary to what various officials from the EU and the national data protection authorities like to say, I don't believe for a moment that this sort of change is a small, incremental development of the existing privacy frameworks we already operate under.
That is from my understanding wrong. In fact Facebook would not be permitted to establish the link. Just you appearing in the picture but it not being your picture does not qualify for personal data.
In short, if you're in a photo and it's recognisably you, it's personal data.
However, the wording I used before was actually taken directly from the GDPR itself[1].
Moreover, the interpretation that an otherwise unidentified image of someone may become personal data even if collected incidentally such as in a photo taken for other purposes or on CCTV is supported by among others the ICO (the UK's data protection regulator). There are a few specific examples in some of their published guidance [2,3,4].
Unless your argument is that Facebook isn't processing those photos in any way that would cause that interpretation to apply? In that case, I can maybe see how your argument works, but given what we know of Facebook processing uploaded photos just from the features they offer publicly, it's hard to imagine how their processing could possibly not be sufficient for all photos they hold to be treated as personal data.
[1] http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN..., Article 4, clause (1), where "personal data" is defined
[2] https://ico.org.uk/media/for-organisations/documents/1554/de...
If you have a social network and you have a user A and a user B. Each of them uploads a picture in private showing both of the users on the image. If user A deletes his or her account the picture in user B's account is not to be deleted even though it contains a picture of user A.
As I mentioned before, modern technologies raise complex issues about third parties that we have barely begun to explore. SOP at social networks is very much to get people to provide information about not only themselves but also other people they know, and that's a minefield if those other people aren't happy about it. Obviously you can't just say social networks can do what they want if someone else provided the personal data, because that undermines the entire principle of data protection and privacy. But equally, if you require explicit consent from everyone for everything, you create a huge burden that might make the whole idea unworkable or at least remove a lot of the value these services offer to their users when maybe a lot of people wouldn't have a problem with, say, a friend tagging them in a photo anyway.
As things stand, taking the GDPR at face value, I don't see how it would be legal for a social network to retain any photo in which someone is identifiable if that person doesn't consent, unless that social network also took rather dramatic steps like avoiding any sort of automated processing and analysis of photos that might identify people in them, as well as removing features like letting a user tag someone who isn't a member of the social network.
Except that is not included in this. You are in fact not even supposed to retain data to identify a user after their account has been used to match them on other data.
I don't know the law by heart right now but I had discussions even a year ago with people consulting on this about this very topic what to do for such cases.
This law was not drafted in a vacuum where nobody looked at real world situations.
Sadly, given that we're talking about an EU law in a technical field, I suspect that what you just wrote is actually quite close to what did happen. That would be consistent with other recent EU rules affecting creative and technical businesses. In some cases, even senior EU and national government figures have admitted that those involved hadn't seen major unintended consequences coming at all, at least not until it was too late in the process to avoid them.
Essentially, the EU often exhibits good intentions and its laws might be made with laudable overall goals, but it frequently produces poor implementations that haven't been thought through in enough detail before legislating. So far the GDPR is shaping up to be another textbook example, with perhaps a side order of political football so the EU can beat up big US tech businesses because the EU's business environment hasn't resulted in creating equivalent services of its own.
This doesn't seem healthy for either our tech industry or our society as a whole to me. I'm actually a rather strong advocate of privacy online, but rules intended to protect it do need to be reasonably clear and practical or they're not going to be worth very much.
We will see soon enough how this plays out. From where I'm standing I'm very welcoming of this development because it's the first time I see an actual attempt of companies doing something that is in the interest of the customer when it comes to data.
The advantage of having armies and police forces is that you can lock people up who don't adhere to your rules. Good luck having any employees in Europe if you decide to ignore their regulations!
Ireland and the Netherlands subcompanies are essential part of US Corporate tax evasion. (Double Irish with a Dutch sandwich).
Whenever you sell to an european company, you must be compliant, as otherwise the european company is liable
Ultimately if the fines or compliance costs get too high that's exactly what happens. A company that does no business in the EU is not subject to EU rules. But because it is such a large and wealthy market the threshold is very high. If Kazakstan passed a similar law it'd be a very different story.
The following outages would impact their US customers, who would sue under US jurisdiction.