Facebook now denying access unless EU users opt-in to tracking
twitter.com
twitter.com
I'm appalled that thousands of people still work for this company by choice.
While I am not a user and don't condone their practices, lots of people are happy and willing participants. Whether they need to be protected from themselves ala seat belts and cigarettes is a societal decision, but right now it's clear the citizenry has a favorable view of them even despite the onslaught from legislators and overarching media narratives.
Going on a tangent here...But I've been thinking about this. At some point it's going to come to a head between these two views of FB if the squeakiest wheels also influence laws. If you rock people's comfy boat too much, there will be backlash.
For another, the reason there's no mass exodus from Facebook is that Facebook users do not perceive the company as harming them. They perceive it as a useful service for staying in touch with friends and family. The utility it provides outweighs privacy concerns, because most people do not care about digital privacy. They care that no one is watching them go to the bathroom or have sex, but they do not care whether advertisers can target them based on aggregated information.
Just pointing out that this assertion is unjustifiably presented as fact.
If there were no absolute answer, then ethics as a field can't exist.
But that seems a bit tautological to me. Moral absolutism stood on more solid ground at a time when the world was smaller and more religious.
https://en.wikipedia.org/wiki/Good_and_evil
"... and that what is truly good or evil can be determined by examining what is commonly considered to be evil amongst all humans."
As Voltaire said about God, same goes for absolute morals.
They ought to exist because without absolutes society is liable to collapse.
That does not mean that absolute morals exist just that we sort of pretend they do.
Take any human behaviour and you will find pros and cons in the good/evil category.
Liqueur/weed laws, sexuality laws, voting laws, slavery laws, etc etc etc.
Extreme example. Bio-hackers release a virus which manages to kill the whole of humanity on Earth including themselves. Evil/bad absolutely?
Certainly bad for humanity if there are humans left on other planets. But otherwise the question is meaningless to humans.
All morals are localized to time/space.
Really? Nothing?
As an example, look into how Nazi Germany and the GDR used collected data. That is the reason why Germany has very strict privacy laws nowadays. But people like to forget about this by now...
Anti-Disclaimer: I do not work for Facebook nor have I ever have in the past.
I think the challenge on expanding on that is that you have not made a case for why it is objectively bad. Your posture is one of an assumption that everyone here understands and has the facts that you have. So it is hard to answer your question without knowing what you are thinking.
Additionally, I am wondering why the question is specifically about FB devs, as opposed to Google's? Or frankly, so many other companies who are likely making money in similar ways. Guessing that should include Yelp, LinkedIn, etc (not sure, though). Are we targeting FB merely because they're very effective?
For me, I have said it here and in person before: I do not see a problem so far in what Facebook is doing. I mean, I have quite a lot of personal issues with Facebook, which is why I have never had an account. Over 10 years ago when my friends in college asked why I did not have an account, my response was always "Why would I want a private company to know who my friends are? That is information that is precious." However, that's my personal issue, and my stance is and has always been that if a particular user is OK with Facebook having that information in exchange for their services, there is no ethical/moral dilemma. It is a transaction, and neither party is being coerced. So I have never been in favor of legislation that limits this relationship.
Now it should not be hard to understand that for me, if I've lived a fine life all this time without Facebook, any kind of argument that "not joining Facebook is not a realistic option" will not receive my sympathies.
The basic data collection is fairly transparent: Everything you provide to them (content, contacts, etc) is available to them. No user should be surprised that they utilize this information. It is the default assumption for any online service. If you use your Facebook account to log into other sites, it should be obvious that Facebook has that info. With regards to the more "shadowy" aspects (e.g. cookies tracking you across sites, etc), a point could be made, but honestly none of this is shadowy any more - it's been in the press repeatedly for years. Once again, if the users don't care, I don't see how it can be "objectively bad".
People tend to invoke the user's ignorance: Most users are not tech savvy and cannot be expected to know how all this works - so they cannot reasonably know they are making a bad bargain. I am not sympathetic to this. The reason is that in all the years Facebook has been in existence, I have talked to and educated many average folks about the potential downsides of giving a private company so much information about you. Everyone I spoke to was quite OK with the whole concept. Not one person felt it was problematic. So not only do I not have a reason to think FB is "objectively bad", I cannot even invoke social proof! Whatever bad people keep claiming is coming out of FB is something most of the population does not think is bad.
I have few sympathies for the (very few) people who are whining about it, because their behavior is similar to irresponsible adults who continually make bad decisions and have lives wrecked as a result, and then expect to get bailed out. Like not buying earthquake insurance in an earthquake zone and then demanding compensation when they lose their house.
Facebook did not become what they did by being clever against their users. They got there by working with them. Any discussion of issues about Facebook without implicating the users who happily helped them is biased.
Finally, and perhaps the most controversial part of my comment: Let's not kid ourselves. People are upset about this because it helped Trump more than any real concern about our privacy. Had a more likeable candidate (Obama, etc) used data from CA to help win an election, I would expect a fraction of the coverage this is getting right now. In fact, I think Obama did heavily utilize these services in 2008 and 2012 - just not as effectively as Trump's campaign did. If anything, Trump's campaign was merely more effective.
Privacy to the average person is like hell to the non-Christian.
1. I support opt-in by default organ donation because even though it's a "dark pattern", it creates the most public good.
2. I think developing AI will lead to lots of good things. Therefore I think the ends justify the means.
For various reasons, I would estimate Google and Microsoft have historically had the possibility of recruiting from about half the senior Engineers in my niche.. Facebook and Amazon are a bit lower, maybe as low as a quarter.
For companies bought by these companies there is a general readjustment as up to about half the engineers who would have refused a job offer from them leave while trying to take the most value in vesting schedules and line up something elsewhere.
The "Exoduses" from incompatible buyouts don't really make headlines because 50% over ~3 years with replacement is hard to see from the outside and most tech mergers are catastrophes if both companies' lines were actually supposed to remain profitable.
As a modern analogy, imagine Erdogan's military and bodyguards. With all the global news on the matter, it's evident they are causing a lot of oppression to many people and basically contributing to a dictatorship, yet they still do as they are told from the top because their own benefit depends on it. Hell, he even got them to suppress a coup threatening his own power.
In order for FB to really change, it needs to change from the top. Otherwise, it's a massive effort to convince everyone at the bottom to push back against the top and threaten their own job security. The reality is Zuck, Andreessen, and the other board members at the top don't care to change, because changing for the benefit of their users also means less riches for themselves.
https://medium.com/@bozhobg/facebook-doesnt-plan-to-be-gdpr-...
Facebook has become a social justice issue (to steal a strong phrase).
Head in sand like this approach will remain unacceptable to EU.
I think we need to distinguish what data collection means...just because you have a Facebook cookie in your browser which causes the browser to fire a request everytime there is a call to facebooks domains and therefore send meta information about OS, Browser, IP, etc (which is hard to turn off without reinventing the web) doesn’t mean FB (just like any other website that uses cookies) does anything with that meta data or stores it at all.
I think we need to be careful about judging what they technically do and what they actually do!
Many people in this debate default to assuming the worst...which is never a useful position to take. I would suggest assuming the good intent on FBs behalf and then reverse engineer from there
I'd argue that, in general, assuming the worst is probably the best starting point. Trust is earned, not the default.
EDIT: removed wrong link.
What does that mean? Why did you link to your parent comment?
It means you can't deny service if the consent is not granted by the user.
> Why did you link to your parent comment?
Because in it I try to explain why donatj's theory that FB can simply deny service if people don't consent seems incorrect to me.
Well, here are the two where I try to explain my view:
Sounds a ton like the Windows Reduced Edition fiasco all over again but at a much more massive scale - forcing by law the development of a product almost no one wants.
So there's never a reason why the product must be worse for any particular subset of users.
When you need to ask consent is when you're trying to use personal data in ways that aren't directly related to providing features for that user. Like, for example, ads.
And you can't develop a bad version to "punish" users who don't consent to those unrelated uses of their personal data, because then the consent wouldn't be freely given.
My guess is that "we can silently change our ToS at any time" is no longer possible, and that's why you cannot login without agreeing first.
Given how deeply tracking is built into their business and technical model, I wouldn't be surprised if it really was too difficult to implement.
They are selling you to not just advertisers but selling your profile to companies that are able to use your profiled information to make their own decisions about things.
It's not just about advertisements. Imagine if you didn't serve a single advertisement and instead bought profiling information about people. You could use that profile information to make business or political decisions regardless of whether an advertisement was sold.
You could influence politics because you "know" your target audience.
Say, for example, the US presidential election or Brexit. Those are just the most high profile places for your profile to be used without ever having presenting advertisement to you.
Net neutrality is another one.
The big money is going to be selling your profile to everyone, including insurers - health, auto, home, etc. Good luck getting a good deal when they know how much you drink and the food you eat.
To the government - eventually that guaranteed Social Security and 401k will be means tested, and it appears you're spending on luxuries that disqualify you.the possibilities are endless.
And I know for a fact that there are more than a few HN readers who work for companies mediating this data.
That would go both ways, right? With the extra information, insurance companies would be _more_ keen on insuring those who behave in a way that makes insurance payouts less likely.
I wouldn't hold my breath, though. My car insurance was set at about $900/year by my insurer for 5 or 6 years. In that time, they never once lowered the price, even though I had one or two tickets expire, had a perfect driving record during that time, and my car lost about half its value due to aging.
Only when I finally decided to get a new quote from my credit union - about $400 for the year (less than half I'd been paying for years) - did my current insurer offer to reduce to the close to that price which is what I would have been paying had I been a new customer with my current record.
In other words, corporations will find a way to extract the maximum possible from everyone.
[1] https://www.slate.com/articles/technology/technology/2015/07...
Directly go to reddit or 4chan. Everything on facebook is 7 day old trash from reddit.
> Also, I don't even see adds with and Ad-blocker. What are they going to try to sell me, a meme page subscription?
You don't see it does not mean facebook does not track you and is not interested in selling stuff to you. It will just use your data to sell stuff to your family members.
I haven't signed in for years, but I have stuff on there going back to high school (back when you had to have an education email address to make an account, now that I think about it) which I'm sure would be fun to look through down the road.
And you can VPN within the EU..
Luckily, that’s not how it works
In many jurisdictions that's illegal. EU is saying FB's approach is also illegal unless they make some key changes.
Personally, I hope FB just quits Europe.
Button 1: Agree and proceed. Button 2: Set up credit card billing. Button 3: Close account.
For US & Canada this was $86.65 in the last 4 quarters.
For Europe this was $34.95.
Keep in mind they likely don't target ads using just one person's data: accuracy can be improved by looking at the data of similar people, and looking at the data of friends and family. It isn't as simple as offering a $10/month plan to keep your privacy, because they want everyone's data.
"Your data is worthless, everyone's data is priceless."
In other words, are 99% of European citizens going to just click through what ever annoying prompts they have to in order to get to their facebook (thats what I would do) or is there an actual widespread cultural difference in the EU that would stop large segments from agreeing to this.
It also coincides with FB's recent privacy breach news and overall general public dissatisfaction with FB's policies.
I know a lot of folks who simply don't use FB and are realizing that it's "really not free" in liability terms.
So does this turn into a groundswell? Probably not, I agree with you. However, it does put some fences up that is probably causing FB to feel a bit more nervous. GDPR may be the first of many such efforts...
This is a school.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
In the case of a permission slip - the school already holds lots of info that the school collects under the 'Public Task or 'Legal Obligation' bases.
The slip then contains additional information that is only collect because the kid is going on a trip, but is necessary for the trip. This would be collected under the Contract basis 'If you want to go on this trip, the following info is necessary'.
If the school also wants to take photos of the child on the trip, for example, then the parent will be asked for consent.
So to answer your question, the parent (assuming the child is under 16) could ask for:
1. The photo consent to be removed - in which case the trip must continue
2. The info pertaining to the school trip to be removed (in which case the kid would no longer be going on the trip)
But they cannot request the core data that the school holds to be removed, unless they take their kid to another school.
I work at a telco/ISP and GDPR training (and graded tests) is mandatory for everyone, from customer support to CEO.
Amongst "ordinary" people, there is a growing sense of unease about data collection - reflected in the "Facebook must be listening to my phone because they overheard a conversation I was having and now I'm seeing ads for it".
I believe people are starting to understand the implications of data collection and are quite unhappy about it.
Because my guess would be that it would be cheaper to adhere to the rules rather than let a competitor grow big in Europe and eat their market elsewhere.
Unless, of course, their central business model is incompatible with GDPR-compliance in the first place...
Tracking is not the primary service Facebook provides to their users, so the GDPR will not allow them to bar access for users who do not opt-in to being tracked.
- accept ToS and use Facebook, or
- deny ToS, download user data and delete account (under 'More options').
Companies have always been able to deny users access if they don't accept a ToS, but clicking "I Accept" to the ToS shown in the screenshots is not a GDPR opt-in, and I cannot stress that enough. It is just a ToS update, which does not cover GDPR-compliant opt-in to tracking. The tracking questions following it are also not GDPR-compliant.
They will have to ask properly for opt-in when the 25th rolls around, or they will face fines for non-compliance.
FB is trying to muddy the waters with this ToS update, probably to fool people into thinking "well, I already accepted a bunch of stuff a couple of weeks ago, I'll just accept this GDPR thing as well". It seems that you've bought in to their misinformation campaign.
The GDPR stipulates that you cannot make access to your service contingent on opting in to tracking, unless you service cannot possibly function without tracking. Strava would be a good example, it cannot possibly work without tracking a user's GPS location.
But FB works just fine with no tracking at all. The only thing that would be compromised is be FB's business model, and that's just tough luck, they'll have to come up with something better, a model that doesn't infringing on people's privacy.
Source: I work for a telco/ISP and we are extremely aware of GDPR and the consequences, and we've been working diligently for ~2 years to make our entire business GDPR-compliant. Training courses and tests of our understanding of the rules are mandatory for everyone, from customer support to CEO.
They have a very easy choice actually. Either abide by the rules if they want to service EU citizens, or GTFO. If they want to give up a couple hundred million users and hand them over to the GDPR-compliant competition, that's their choice. It would be monumentally stupid, though. FB needs EU users a lot more than EU users need FB, but they're trying very hard to spin the press to make it appear the other way around.
It's like when McDonalds or a similar tax-dodging company threatens to leave a country if they face being forced to actually pay the taxes they owe. Leave millions and millions in profit right there on the table for their competitors to grab? Yeah right, ain't gonna happen.
If by "international technology" you mean "blatant disregard for privacy", then good riddance. We don't need that sort of "technology".
I am not sure the impact of closing their offices in Europe, though I am sure their the most interesting work is done in USA.
Good riddance, I say.
That would be great for diversity, not to mention provide a fertile playground for much-needed alternatives. Too bad it probably won't happen.
The real question isn't population, it's revenue per user. An typical American or a European will draw a lot more revenue to Facebook than a typical person from a 3rd world country accessing Facebook through "Free Basics."
My educated guess is that Europe is Facebook's #2 market behind the US, and there's enough revenue there for them to change their business model.
https://s21.q4cdn.com/399680738/files/doc_financials/2018/Q1...
From Slide 5:
Q12018: Europe was #2 with $3.036B in revenue
Q42017: Europe was #2 with $3.250B in revenue
And so on, it looks like every quarter on this slide has Europe in spot #2 behind US & Canada.
They have queues set up at the gate to rifle through your knickers in search of contraband dihydrogen monoxide, and will force you to dump any you have, and/or deny you boarding if you don't comply obsequiously enough.
Flying to Mexico (or anywhere else) and then the States? Or even Europe? You're fine. Even when you board the flight that will land in the States, your water is welcome. It's only direct flights to the US, and it's only (in my experience) enforced on outbound flights, from Lima. I've never encountered this anywhere else, and I've visited dozens of countries, and did a several months long RTW a few years ago.
Once you've spent 6-10 hours in a can at cruising altitude, with only the occasional thimbleful of water a few times, because of this kind of invasive idiocy, you might have a broader perspective on how much of aviation security is theater.
EDIT: That's just one example of the absurdity I've encountered in my travels. Another: being told that my carry-on sized backpack was somehow a material threat to the plane I was trying to board, and that it needed to be checked in the hold.
What am I supposed to do there? Logic my way out of my paid fare? Into one of $country's TSA-alike's interrogation rooms?
This nonsense is endemic to air travel, over the last decade particularly, and it's only getting worse.
The situation in A'dam : I guess it is impractical and unwanted to close the corridor from the one end to the other.
Fortunately, they left a relatively narrow outside corridor open. Still feels odd to have to check in and out again when you're coming from or to some of the main busses, or take a detour.
But even regional services include oodles of cameras, including on the trains. There's tracking of passengers and their destination. There are heavily armed guards/police/soldiers in many European train stations.
Are you talking about the Eurostar service from London (I remember the Waterloo station, though I hear it has moved to St. Pancras). That's the only one I can think of that fits your description.
The Thalys from Cologne to Paris via Belgium is/was also simple walk on walk off with normal train stations.
I don't doubt they keep those manifests, but I've found very little actual control.
Brussels does have troops going around, which is unsettling, but I never saw them inside the actual station, nor stopping people entering it, even after that poor devil immolated himself last year.
I 'm also in the EU and this makes perfect sense to me: if you can't accept seeing some ads then you can't use the free service. I highly doubt people are willing to pay $5 cash / quarter to use it, but i would like to see FB giving that option, just to see how miserably it fails.
Facebook would still work just fine without the tracking, as proven by the fact that you can switch off targeted ads and everything still works fine.
Does anyone know if Google has made any statements on this?
While I do trust Google more than I trust Facebook, I also actively avoid giving information to Google (through various practices).
Edit: they are doing this before the May 25th deadline.
Personal information that is deliberately and freely made public by the owner of that data (ie. you, the user) is free to use, both for the service on which you make it public, and for anyone who happens to read it on your publicly visible profile/wall.
The reasoning is that you made a deliberate choice to make this information public, meaning you have given consent to public viewing of said data.
What this Facebook issue is about, is the collection of personal data that you have not made publicly accessible, because it is private to you. FB is using this data to tailor ads and to modify your feed, giving you politics you agree with, suggesting pages for you to join, and so on. FB is also profiling you and inferring your private information, and using that to track you across the web (on every single web page with an FB "like" button, for instance). They have a disturbingly detailed profile on all of their users, including highly sensitive data such as political standing, sexual preferences, medical history, even possible infidelity.
FB is perfectly usable without giving them access to any other personal information than a fake date of birth and a throwaway email account. It is perfectly usable with "targeted ads" turned off. It is perfectly usable without the "optimized news feed", it can just default back to a chronological feed instead.
The violation of their users' privacy is not essential to the service FB provides to their users.
> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Facebook might declare otherwise, but since SMS and IRC both stand as counterexamples of successful text chat services that do not inherently depend on tracking, they would likely lose their case.
i.e. Without this tracking, the quality of Messenger is affected, and therefore, by definition, the service cannot be provided without it.
As such, trackers in 3rd-party advertising network code probably won't count as necessary; it's necessary for the ad network, but it is not necessary for the website displaying the advertisements, as proven by ad-blockers.
Likewise, the facebook like button and other "plugin" components aren't "necessary", they merely add value to the existing content / features, and must therefor be entirely opt-in.
At least, that's my understanding, which is entirely too facile to be taken as legal advice.
EDIT: As petercooper pointed out below, in addition to proving necessity, you must still also prove in court that you have balanced the necessity against users' rights and interests. As such, I no longer feel confident to say I even have a clue as to what is legal and what is not, for FB or for anyone else, until there's a big enough court case to set precedent.
when I was a child I stole a toy from Wal-Mart. Wal-Mart is still around. Therefore, Wal-Mart's entire existence as a store does not depend on any kind of anti-theft measures, and it should be illegal for them to film my entrance and exit.
1) Laws don't exist in isolation
2) Long standing law says theft is illegal and stores can take steps to limit it.
3) This new law (GDPR) says you can't take users details and use them unless necessary to provide your service.
With this new GDPR law it's the little guy, the user, that get protection from something of value being taken from them and exploited - their personal details.
So, extending the above counter-argument it is also true to say that like Walmart, the singular 'theft' of personal details might not be terminal for the user. But just like the law recognises the theft of material goods and it's potential harm (even in the case of a singal instance), it now recognises the 'taking' of personal data as harmful (also even a single instance).
Extending the argument further, the GDPR takes the stance that one entity has been taking something of value from another without true compensation for the value of that something.
When we realise that what has been taken from users has value and that users haven't been fairly compensated for that value, it becomes obvious that a set of entities have based a business model on profiting off another set without fair compensation.
The GDPR now limits that behaviour and business model to return balance to the 'contract' between the two parties. Users get to use a service by providing the minimum needed for that service to be provided.
Further, some stores put locks on items and displays that others do not. These are also required for the store to continue offering such services.
You, as an individual, may not have undermined the store. However, you, as an individual among many, may be the reason why certain stores are not able to function as other stores do.
EDIT: to clarify my point, I don't think the GDPR takes how revenue is obtained into account. The revenue model itself must still conform to user consent. The analogy of Walmart to ad-blockers is interesting, though slightly off when one behavior is illegal and the other is not.
This actually makes more sense finically for Facebook, if they did the first thing people would only have to buy data once, and worse they could resell the data to third parties decreasing Facebook’s control of the market. Instead by retaining control of the data Facebook can charge an advertiser for every ad they show, making more money. Ironically this also better protects peoples privacy because Facebook isn’t actually giving the data away.
It's certainly not a complete profile, and may have ranges of categorizations (i.e. 18-24 years old) BUT as an advertiser, I probably wouldn't need or want data more specific than that anyway.
You can of course though collect them if people actually click on them and come to your website! This is also the case for non targeted ads mind you as it’s simply how the web works
It would be interesting to see revenue as a necessity be tested in court, since there are open-source social networks that don't rely on user tracking or data sales to the extent that Facebook does it.
However, they need to pass two other tests, a "necessity" test that determines that the processing of information is necessary to serve the interest, and, most crucially, a "balancing" test which balances the commercial interest against the user's interests, rights, and freedoms. It's this latter part where more onerous advertising practices will falter.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Also, does Facebook's ad network really constitute "direct marketing"? I had imagined that to be more of an email blast about a new FB feature, rather than collect-your-usage-data-and-sell-marketing-slots-to-you.
Now that I type that out, I guess it does make more sense. However, I really am not a big fan of the common-law approach to the "balancing" test. Basically, whoever has the most money and faces the most lenient judge wins. Everyone else is left guessing what the hell is legal and what isn't, when a clear set of rules would be much easier to fairly apply to everyone.
Vote me down all you like, but it doesn't affect what is actual legal fact :-)
I'm pretty sure Facebook has the resources to have hired competent lawyers to advise them on that, and the money to afford preparation and execution of a strong court presentation of their viewpoint.
And Facebook probably had more information on what is necessary for the system Facebook provides to work than people trying to guess that from the outside.
It is, of course, possible, and, perhaps even likely, that a court will disagree with what they argue, and force a change—but it may be, from a PR perspective, worth the cost of non-compliance sanctions to have any decrease in utility resulting from changes they will be compelled to make to be very visibly forced on them by orders that they vigorously fought rather than self-initiated, so that European authorities and the GDPR get the blame for any reduced quality.
You could say that about any of the resource-rich people and companies that have subsequently had their arse handed to them in court.
No such thing as a free lunch.
What about someone who uploads a lot of pictures but doesn't have many friends? That person might be using more resources than the ad revenue they generated...
Are you saying they should be forced by law to block you?
> What about someone who uploads a lot of pictures but doesn't have many friends? That person might be using more resources than the ad revenue they generated...
That is a flat-fee/pricing issue, just like someone binge watching Netflix might be using more resources than they generate in revenue. It isn't relevant to the discussion.
Also illegal.
(b) isn't applicable because it only applies when it's directly necessary to provide for that particular user (like processing a CC number when paying for a product). That you business model generally needs it is not enough (see the ICO FAQ on the issue[1]).
(a) Consent is valid, but it must be freely given, that is, the provision on the service can't be conditional on the consent (article 7 (4)).
[1] https://ico.org.uk/for-organisations/guide-to-the-general-da...
> just that not every avenue of funding is allowed
Funding by targeted ads isn't illegal last time I checked.
"The processing must be necessary to deliver your side of the contract with this particular person. If the processing is only necessary to maintain your business model more generally, this lawful basis will not apply and you should consider another lawful basis, such as legitimate interests."
https://ico.org.uk/for-organisations/guide-to-the-general-da...
> Funding by targeted ads isn't illegal last time I checked.
It is if you don't get consent. And you can't make that consent required to provide a service, since then it won't be "freely given", as per Article 7.
If this is correct, this is a major blow for US industries.
I hope the US follows suit with Europe rather than attempting to start another trade war.
"Avoid making consent to processing a precondition of a service (...) If you make consent a precondition of a service, it is unlikely to be the most appropriate lawful basis."
https://ico.org.uk/for-organisations/guide-to-the-general-da...
> No such thing as a free lunch.
Please square that with the fact (which I already pointed out) that they already provide their free service without targeting, based on user settings.
They can't using tracking to "pay the costs of providing this free service" without ad targeting (unless they're selling the tracking data, which they publicly deny).
I'm making an educated guess that mere declarations of necessity tracking are not sufficient legal justification for it in the EU.
I'd love it if Facebook were nationalized (or destroyed), but none of the coverage of the GDPR made it sound like it was going in that direction. I thought it was just another stupid "click here to acknowledge our cookies" rule that was going to spam up the internet.
Since they are being selective on the users they accept based on being tracked, they are now on track for another EU fine.
Or do you foresee this being like drug prices, where the US subsidizes drug development for the world?
Is that typical, for the EU to get that involved in business decisions?
But yes, the EU does get involved in plenty of business decisions, just like governments everywhere. Usually when an industry is misbehaving and violating what is established (e.g. by the ECHR) as the rights of individuals.
Obviously. But that's not what I meant.
They did not say "tracking is illegal", they said "it's illegal if not necessary".
Are they then say: "It's not necessary because if you completely restructured your business you wouldn't need to track."
That's the part I meant - do they really go to that level of detail?
I think the key point is being clear about the trade. I think FORCING all websites to only be paid for by cash is bad; you should be able to trade your own data for access to a service.
Because "In the EU, personal information cannot be conceived as a mere economic asset: according to the case law of the European Court of Human Rights, the processing of personal data requires protection to ensure a person's enjoyment of the right to respect for private life and freedom of expression and association".
https://edps.europa.eu/sites/edp/files/publication/16-09-23_...
We can agree on intent and disagree on practice. I disagree with the GDPR in practice, but agree with its intent. I think there are many other ways to tackle these problems, and this is probably the worst one (especially to start with assuming this is the first really enforced one).
I don’t think it’s ironic that you like this law, I think it’s understandable that you would if you have privacy concerns and, given T. May’s choices over the years, you were unlikely to get it without membership to the EU.
Regardless of whether this is for the "greater good", this is deeply unsettling territory.
I guess I'd agree that if someone wrote a 5 page paper describing all the ways that Facebook harvests their data and what might be done with it afterwards then they should be allowed to do what they want? But I suspect most people would be like "uhhh, I think they, um, know what pages I liked? And maybe they use that for ads?"
"Clear consent", in my mind, would be something along the lines of "we use tracking cookies and tracking on widgets third-party websites embed, as well as the data you provide to us in terms of posts, comments, photos and other content to personalize the ads you see". If you accept those terms, well, then you certainly can't be surprised when Facebook — or whoever — does precisely that.
Based on my interpretation, the GDPR simply precludes that possibility.
The official goal of Facebook is not "buying your data" but "providing a social network". Thus, targeted ads are not strictly necessary for providing that service.
There's a ton of stuff you can't do, even with clear consent, because otherwise people who lack the means to understand the compromises or afford the safer choices will suffer.
But, hey. Why should I care, if I'm not getting charged those rates, right?
We’re getting pretty off-topic though, so if you’d like to talk more, go ahead and shoot me an email (r at ovao dot la).
Should ad companies be able to model someone's mental illness and show them ads for gambling sites, or whatever, when their brain is acutely more susceptible to them?
This is nothing more than a digital drug law: “You can’t choose what services you consume because we are determined to protect you from yourself, like it or not.”
I'm a big proponent of user control, and a similarly big proponent of businesses taking much greater responsibility for the data they collect (my data was part of the Equifax breach, so I certainly get it). I am, however, leery about laws that essentially bind a business's hands in terms of how they can and cannot monetize on users, even when as there's A) clarity and B) honest, plain and upfront disclosure about how they do that.
If a business tells me to agree to onerous terms to which I could never agree or to go pound sand, I'll gladly go pound sand. As a consumer, I lose no power there whatsoever.
I've told Facebook to pound sand for roughly their entire existence - never had an account even though I had the chance right after they expand beyond Harvard - and am considering whether life circumstances will increasingly force me (in practical rather than literal terms) to sign up.
A company in that semi-mandatory position deserves lots of binding rules to protect the rights of unwilling users, just as is true for electric companies since you rarely have much choice there.
Plus, I don't think Facebook's massive wall of several huge interlinked policies with soft-pedaled descriptions of what they do meets either of your A and B criteria, especially not when it's modally interrupting the user.
What? Yes it has.
"I am, however, leery about laws that essentially bind a business's hands in terms of how they can and cannot monetize on users, even when as there's A) clarity and B) honest, plain and upfront disclosure about how they do that."
I'm not, mainly because business has been shown that they absolutely cannot be trusted with that. They have abused the privilege, and so they had their toy taken away. If you want to be upset at someone for that, blame the businesses for not reigning in themselves, not the governments for doing what their populaces wanted.
Not to mention, A and B almost never, ever exist.
"If a business tells me to agree to onerous terms to which I could never agree or to go pound sand, I'll gladly go pound sand. As a consumer, I lose no power there whatsoever."
You've lost all power in that relationship, because you have no power to bargain. You have no power to negotiate. And while you'll gladly go pound sand, not everyone is in a position to do so.
Turn it around; why should Facebook be allowed to have "take it or leave it" terms? Why should we as a society allow that? And don't just say, "It's their business;" I don't find that to be a compelling reason. Why should users not have the control over their data that the GDPR brings?
I take issue with this specific stipulation that — even with clear and upfront user consent — a business simply cannot operate in ways that are A) not opposed to the safety or health of their users and B) potentially necessary to succeed in the markets in which they participate.
If you believe the only way they should be able to do that is to become a digital hermit, then you don't really believe that.
"When you say “no thanks”, that’s a user exercising control over their data, and is an action which necessarily involves no governmental body."
What about Facebook's shadow profiles?
"a business simply cannot operate in ways that are A) not opposed to the safety or health of their users"
There is nothing about the GDPR that opposes this. Not a one.
"B) potentially necessary to succeed in the markets in which they participate."
This most assuredly is not part of the GDPR. If the only reason your business has a chance of succeeding is by ignoring user privacy and ignoring the safety of user data, your business does not deserve to succeed.
I've been cordial to this point, but if cordiality isn't there on both sides, there's no point.
No we will not tell you what you did. You already know what you did.
Our automated systems found your policy violation and acted appropriately. They are beyond your comprehension or refutation.
You may not talk to a person regarding your dismissal. It is against policy to discuss active or closed issues.
You have no recourse other than social media or tech websites, and beg. And we still will likely not care.
--Care of US tech companies.
....So, you want to live with rules for companies that allow this kind of egregious and arbitrary actions? I sure as hell don't. Want to see what this stuff devolves to? Look no further than Comcast and ilk.
Where by "your" we mean "one's", i.e. effectively "our".
"Your" in that context was from the company to the user they wronged.
Car = Service
Seat belt = Tracking protection
At the end of the day this will need to be decided in courts.
I have no qualms with a competitor starting up to serve those denied by Facebook, but let's not muddy the water by equivocating a monopoly as a result of anti-competitive practices with one that forms simply because nobody wants to use anything else.
I don't think most of the people who find Facebook convenient for coordinating groups actually choose the tracking knowingly and willingly (at best begrudgingly), nor do they choose to exclude the people who object more proactively to those things even when that's the effect.
Society's legislative and regulatory choices have a valid role to fix negative externalities of what economic actors would otherwise naturally do. Natural monopolies/oligopolies like electric companies, highway operators, and Facebook are all worth regulating for roughly the same reasons - even according to Orthodox free-market undergraduate microeconomics 101.
I'm speaking more about "ought" than "is" here. I don't see any reason why Facebook should have to choose between serving everybody, regardless of the regulatory burden that it places on them, and taking a hike from the global market entirely. I'm not saying that they won't be forced to do so anyway.
> ...I don't think most of the people who find Facebook convenient for coordinating groups actually choose the tracking knowingly and willingly (at best begrudgingly)...
And yet, they've probably chosen it all the same. In the hypothetical scenario where somebody has a metaphorical (or literal) gun to somebody's head, forcing them to use Facebook, I don't see how Facebook themselves can be blamed for this, and simply chalking this sort of thing up as a "negative externality" and saddling Facebook with the burden seems to be weaselly way of making Facebook to the will of somebody who just can't bear to give it up.
You can't always get what you want. Some of us would do well to internalize this a bit.
It is a lot easier to find people like me who never had FB accounts and who can testify that not having one has not impacted my life.
The same can be said about google's search service. The search still works, but adsense and adwords won't work without your private info. And google can claim it doesn't sell search, they sell ads.
None of the tracking they do is essential to the service they ostensibly provide to their users, namely as a microblogging/discussion/sharing platform.
I bet that nobody would! Ranking is what makes these products work...and it requires data to do the ranking.
Sure, rank search results based on how many users a given group has, and put the most popular ones at the top. That doesn't require violating anyone's privacy.
The reason ranking is used left and right these days is because it makes products dramatically better.
E.g. allow them to either sign up to the tracking or pay 100$/month for access
Tracking would not be mandatory to access the service, as the alternative way (to pay for the service) is available
What you're looking for already exists; install WeChat.
Quite frequently, yes to both questions. Choice is key and many often feel more empowered to individually choose their company than their government.
When there isn't meaningful competition in a market, it's specious to point to the abstract possibility of competition as an argument for sucking it up and cozying up to the monopolist, who has structured your arrangement with them to limit your freedom and recourse as much as practicable.
A profit motive doesn't magically make the human foibles that the "Gubmint is baaad" crowd insists will lead to the end of human freedom — and puppies, too — more manageable, or less dangerous to the rest of us.
Oversight. If you want meaningful competition and don't have it due to harmful monopolization, that's the government's problem to solve. Nobody's asking for self-regulating companies here. It's very important to understand which forces can or cannot actually eliminate competition and choice. If there is a path towards choice, I'll take it. Often that path is unclear of course.
How's that working out for us?
Maybe my premises and categories blind me to that risk in some way; I'll certainly cede that possibility. I'd be curious to see people who think the way you're describing do the same, vis à vis theirs.
That's the trouble with articles of faith, though: for the people who hold them, they're axioms; for the rest of us, they're implicit, unsupported premises to someone else's argument.
Facebook doesn't have a right to track people in the EU without gaining their consent to it in a way that complies with EU law.
EU citizens have a legal right to expect that Facebook will comply with European consumer protection laws.
If Facebook doesn't want to properly comply with EU regulations, they're free to totally withdraw from the EU market. Otherwise, it can expect penalties for its willful noncompliance.
The only problem is: Facebooks terms of service isn't really reasonable, and most people won't understand the implications. As I understand the GDPR one of the goals is to give users a set of rights, in regards to their data. These right cannot, under any circumstances, be violated, just as you can't bond yourself into slavery or sign away your right to free speech.
Facebook and others are currently trying to find loophole, like with the cookie-law, except this time the EU did it's homework and companies won't get of with such simple solutions. Really if Facebook believe they can't do business in the EU after the 25th of May, due to the GDPR, then they shouldn't. Just close of all EU activities. Of cause I understand why they won't, the company would lose a good chunk of it's value, but it will anyway if it can't find a way to legally operate under the GDPR.
Next up: the US targets Germany's auto industry - a backbone to their economy - with tariffs or other import restrictions, seeking to damage BMW, Mercedes, and Volkswagen in any and all ways possible. Easy cover: Germany having the world's largest current account surplus, at 8% of GDP. Recourse after that: more restrictions, regulations, targeting of US tech giants in the EU, and tariffs on various US products.
France says: Germany and its trade policies are a problem, seeks to reduce German dominance while trying to remain more neutral with the US:
https://www.politico.eu/article/emmanuel-macron-says-german-...
It's going to be a very interesting year or two.
a) Tracking non-facebook users via Facebook icons on web pages, and
b) Storing the information of non-users such as photos other people take, phone books other people upload, etc?
Same as the cookie situation Europe has, but more so.
Consent must also be given explicitly, you cannot have a pre-checked "yes" checkbox or an "accept and continue" button.
Consent can also be given in a legally binding contract. A website ToS is very much not able to override the GDPR.
You are of course perfectly in your right to block all EU IP ranges, if you think that's a better solution, although cutting off 500 million potential customers is a bit harsh.
In short, EU citizens have absolutely no obligation to support your flawed business model.
I know my reasons for wanting to ditch FB personally (I'm about 50/50 on that), but I'm curious as to your reasons for wanting others to dump it.
Here is what remained: https://web.archive.org/web/20151011192709/http://observer.c...
Basically, anyone using it, encourages more people to use it, thus causing further damage.
(I don't have a FB account)
Is "consent" gained by a screen with only an "I agree" button even kosher by it?
> This appears to breach several important principles of the #GDPR, including the principle of purpose limitation, freely given, non-conditional consent, and of transparency. In other words, if Facebook attempts to collect consent in this manner, that consent will be unlawful.
Nobody is forcing them to serve the EU market.
In the specific case of Facebook, near-zero of the users actually understand either what they are giving or the full extent of what they are getting or not (especially since the latter changes constantly as FB alters their policies and algorithms etc). So, it's more like "give us stuff you don't understand with ramifications you haven't thought about, and you get a complex, somewhat unpredictable, changing service." This is nothing like the theoretical trade between two participants with equal power and complete information.
I have purchased a house, and used a mortgage to do so. In getting that mortgage, I was presented with reams and reams of paper that I had to agree to and sign. The basic facts of the loan, however, were mandated by the government that they be disclosed to me in as simple and straightforward terms as possible. That mandate for disclosure should be sufficient for a person to decide to do business with a service, regardless of the nature of what is being transacted. If what I read here is accurate, it's akin to me saying "No, I won't sign any of this. Now give me my keys."
The bank is not required to give you a mortgage. The regulation says that if they want to offer one, they can't include "No camera, no keys" as a condition.
Strava is a good example, it does not work without GPS position, otherwise it cannot track your bike routes.
But Facebook does not require tracking to work. It does not require you to give them any personal details at all in order to work. It would work just fine even if everyone gave them fake emails, phone numbers, birth dates and even fake names. Thus they cannot make giving up privacy a requirement for using their service.
Besides that, this ToS update thing is absolutely not GDPR compliant. It does not list the things personal data will be used for. It hides the opt-out (to the face tracking) behind a dark pattern small "options" text and makes the default action opt-in. The list goes on.
This is simply an effort from FB to muddy the waters and sow doubt about opt-in and GDPR consequences.
They will have to provide proper GDPR opt-in screens come the 25th, or they will be fined for non-compliance.
To connect to other users on a service, I don't need to know any personal details about them, only their chosen username, which can be completely random and have no relation to their identity.
The whole point of FB is for people to exchange data about themselves with their friends and family! If people don’t share any data or just fake data FB doesn’t work.
For them to offer their service they also have to make money, so they run ads to do that. And to make the ads useful to people they need data for targeting!
And now they allow users to either agree to this deal or download their data, delete Facebook and do whatever they want.
Simple as that
I can sign up with a fake date of birth and a throwaway email account, under a generic name (remove any identifying unique spelling or middle names, for instance) or a completely fake name. And I could still connect with friends and family, provided I know the names they've chosen to use on FB.
According to the GDPR, anything you share publicly is basically fair game. So if you post something in a public post on your public wall, anyone can view and use that data for whatever they want.
The issue is all of the secret data FB collects. They have disturbingly extensive profiles of every one of their users, including political standpoint, which phase of life they're in (eg. "stable established adult" or somesuch), their sexual preferences, sports teams, club memberships, medical history, the list goes on and on. They get this from your non-public account information and from tracking you across websites you visit.
That is the issue here, the tracking and storage of personal information that people want to keep private. FB's tracking and privacy violations are not vital to the service they provide. Their business model may depend on (targeted) ads and privacy violations, but that is not an excuse. You cannot base your business model on breaking laws and hoping to get away with it.
FB isn't "allowing" users to either agree to the ToS or go pound sand, they're basically saying "fuck you, we'll exploit your private information as much as we want, and you don't have a choice". They're doing this to muddy the waters and make people think "oh I already agreed to this, make it go away", when the actual GDPR consent form pops up after the 25th.
But users do have a choice. The GDPR very specifically says that you cannot make access to your service contingent on opting in to private data collection and tracking, because consent has to be given freely, ie. not under threat of access denial.
You can only do this if your service cannot possibly work without the collection of personal data. Something like Strava (which tracks bike rides via GPS) cannot function without collecting GPS locations. So they have a good argument that they cannot provide their service, if users do not opt in to location tracking. But they have to very clearly state what they will use this collected data for, and they cannot change it later without collecting new freely given consent from their users.
I also don't find any of the data that FB or Google have of me "disturbingly extensive" or that they have been "breaking laws" to get it.
I give them data so they can provide value to my life...it's as simple as that! If that deal doesn't work for you then you simply shouldn't use their products..nothing wrong with that.
I also personally prefer targeted ads over un-targeted ones btw. And I like using these services without having to pay for it...its a good deal!
I also want to add that, while you repeat popular believes, I have yet to see evidence for many/all of them and I would prefer you would either stay with the known facts or be more explicit about whats a personal opinion/internet myth. thanks
Have you downloaded FB's data dump of you? That is only the bare surface of what they collect. They do not give you access to the underlying profiling and the social graph they have built on your information. All you are getting is chat logs, uploaded photos/videos, a list of contacts/friends and some simple keywords. That's not even scratching the surface of the data model FB has on every single user.
The data you think you're giving them and the data they actually have are orders of magnitude apart.
The "well you can just choose not to use them" argument falls completely flat when you realize that many businesses and organizations have no internet presence outside of Facebook. They've set up a Facebook page because "everyone has Facebook, right?". If you cannot see the problem with that, then I'm not sure what to say.
Frankly I would argue that the ML models they create from usage data are theirs! Regardless of how useful they would be to me as a individual to download or not.
Now about the FB tracking pixels and the data they collect, I consented to those when I used the third parties websites they were in and accepted their TOS...and I have a choice to not use those sites or if I choose to block the pixel from firing via technical methods.
FB tracking pixels are on less then .1% of all websites...so I also don’t buy that arguments that Facebook follows anyone around, because it’s simply not true!
Update: so I was curious to see how this actually works and looked up the documentation: https://developers.facebook.com/docs/facebook-pixel/events-a...
So there is two ways to do it for third parties: get user consent before starting to use the website or use their advanced API and delay firing of the pixels until users have consentent later in the process...like for example on the checkout page!
There are hints of it though. I noticed in my most recent data dump there was a list of "contacts." Some of those were people who I was never Facebook friends with and included contact information (e.g. alternate emails) that I never had.
It seems like this data was built off of people's phone contact lists. It definitely seems like my contact list was the root of mine.
Isn't that "you pay with your data"?
Or do you mean it would allow things like "$5/month, or free if you consent"?
https://thinkgdpr.org/wp-content/uploads/2017/05/DIRECTIVE-E...
E.g. I spent 3 years at Yahoo (more than a decade ago now) wrangling with US product managers that found it incredibly hard to accept that the "workarounds" they kept proposing for EU requirements for payments systems were highly illegal in the European countries we operated in, as a means to cut effort. My team existed pretty much only to form a protective layer between the US payments team and the European business because the European business didn't trust them to not pull a fast one to save time, because they didn't understand the seriousness of the requirements.
But in many European countries, the courts takes a very dim view on that kind of attitude.
You cannot grandfather in user consent, especially not with a blatantly non-compliant procedure like this one.