If they are operating in the EU? they do actually. You can't just put whatever you want in your ToS/EULA and throw your hands up.
If they are operating in the EU? they do actually. You can't just put whatever you want in your ToS/EULA and throw your hands up.
If a shop says "no returns", what they actually mean is "changing your mind or deciding you don't like it isn't a valid reason". But you can still return something if it's faulty, isn't as described, or isn't fit for purpose - because they're your legal rights, phooey to the store's return policies.
It's my understanding (which could be wrong, is constantly evolving, and desperately needs test cases) that being able opt out of unnecessary PII collection or processing is a legal right, and phooey to the ToS that claims otherwise.
In practice, I think that's yet to be determined. GDPR is new. These rights are new. "If it's faulty" is easy for lawyers to determine. "Fit for purpose" ...isn't that hard, and the lawyers have had time to practice. "Unnecessary PII collection or processing" ... the lawyers are currently 23 wikipedia links deep^ trying to identify the aristotelian truth of the matter, presumably in order to make necessary amendments to the aforementioned contract.
Shops putting signs on walls is just not comparable to this, in practice. Normal people are signing dozens of pseudo-contracts they don't understand each day. That has been accelerating and gdpr has accelerated it further.
That’s actually a great point. Collecting PII is NOT illegal, as far as I can see. Nor can it be illegal. Same for personalized ads.
Consider a real estate agent. To show you the right kinds of houses to buy and finally make the contract, they have to have enough PII about you. If they know nothing about you, they’ll end up showing 1-bedroom studios for a family of five and a three bedroom suite for a bachelor living alone. Similar arguments can be made for all kinds of service providers.
Now onto the issue of FB, the only service they offer is “communication tools with built in personalized ads”. PII is necesary to provide that service.
Article 6 [0] is phrased negatively, making collecting PII illegal unless x or y. These points cover all the use cases the lawmakers deemed valid; a real-estate agent may collect PII because of 6.1b (taking steps to enter a contract at the request of the data subject). Should a new, possibly valid reason to collect PII come up it would first need to be checked and then added to the list.
Since most websites and online services do not aim to form a contract nor fit points c-f, they have to obtain consent by the data subject (6.1a) to make collecting PII legal.
Many common purposes for data processing might come under point f (legitimate interests) depending on the circumstances. Analytics, marketing, monitoring to check for fraud or other abuses are just a few examples.
I'm also curious where other points will land in reality. eg, if I ask Apple to remove all data they have about me, will that also remove me from your address book? If I ask Google to remove all data they have about me, will that also remove any emails you've received from me?
In this light, I'm happy to see the first complaints arrive against Google and Facebook, as they're exactly the examples we all have in mind, and we need to see how they'll play out in reality.
(Albeit, I also trust the European legal systems won't commonly wield the maximum possible fines, but rather seek compliance. The scary big numbers, the source of so much FUD, should be reserved for wilful disregard after this step. "Walk softly but carry a big stick" style.
Their case will be helped by the fact that they can simply have the user “consent” to stuff. And since none of those are “critical” services, they will find ways to prove that user consent was actually voluntary, and not coerced.
So I think you’re right that only the most egregious violations will have real trouble.
The judges might also want to demonstrate to everybody (including their own system) that the big stick can in fact be wielded to real effect. If people start beliving that the stick is really just a prop, no point carrying it, is there…
We'll see if this difference is legally superficial or material, as this all plays out.
There was a lot of MOP interest in gdpr and it's friends (like the US Congress' FB stuff). Politicians got attention for their rhetoric, as they legislated. Journalists delivered coverage and opinion, including a lot of moralising too. Social media was abuzz.^ They never told the average MOP that gdpr would be a bunch of contracts she'd be signing.
From the perspective of corporations.. the party complying & implementing gdpr... they've mostly interpreted it as "Rules About The Contract Our Customers Must Sign". Their lawyers assure them this is best.
I think this was a piece of legislation that our legislative systems are particularly ill-equipped to deal with.
^Relatively to the standard interest in laws.
It‘s just that we usually don‘t notice it because it‘s all concludent action, not a signature.
Yes, it‘s strange, but it is the holy cow of German contract law.
I think what the web needs right now is to figure out what the implied contract is, and save the modals for those out of the ordinary.
In the digital/information age, personal data is the new currency. You pay for online services with that currency. If your data (money) is more valuable to you than the value you’d derive from use of a certain service, then you don’t pay for it (and by rights, don’t get to use it). I think my money is too valuable for me to spend it on bottled water, so I drink tap water. I think my personal data is too valuable for what I’d get from using FB, so I dont use it (there’s 20+ very widely used apps to “stay in touch” and “communicate” with people).
Eventually (even a couple decades maybe), it will become a question of getting the most bang for your buck (data). If two companies offer the same sort of service, but no. 1 needs all personal info all the time (like FB today), and no. 2 only wants your location twice a day, no. 2 will be cheaper and win out. When no. 2’s executives get greedy and ask for your location 4 times a day, Reddit will squeal.
There's a reason Facebook has you agree to a 10,000 words ToS and related documents, and it's not because the contract here is blindingly obvious. It would be another thing if the type and extent of their data collection was clearly spelled out and delineated so you knew exactly what you're giving up; but Facebook explicitly wants the ability to collect anything and everything and use it for whatever. Under those conditions, what kind of information they collect about you and what other data it allows them to infer is completely opaque. ("It's just an indoor photo me and a friend, surely Googlebook can't tell where this was taken?" https://nakedsecurity.sophos.com/2016/02/29/google-knows-whe...)
Despite the whole media stink about Cambridge Analytica, usage figures aren’t significantly different. This leads me to believe the average user will simply agree to whatever is put in front of them so be able to use checkout pics and read newsfeeds or play farmville or whatever else it is that people do on FB.
What the EU could mandate is a max 1000 word ToS, that the more concerned user without legal training could actually grok. The GDPR just makes sure companies cover themselves legally - not that hard, if they can get away with a humongous ToS which almost no one will ever read.
I agree. Still, I think that there is a difference between implied contract/obligations and an actual piece of paper with your signature (or checkbox) on it.
Now, for the complainants complaints to be valid, there have to be things in the ToS that are against GDPR. As far as one can see, there isn’t. BigCos have been careful enough to not step on the toes of EU regulations. But what part of the GDPR gives the EU the right to force a company to offer its service to someone who doesn’t accept the “house-rules”?
Sorry if I seem argumentative, I’m not, I’m just trying to wrap my own head around this thing.