Australia sues Facebook over Cambridge Analytica
techcrunch.com
techcrunch.com
1. https://techcrunch.com/2019/10/30/facebook-agrees-to-pay-uk-...
EDIT: If the goal of the fine is to just kill Facebook's presence in Australia, then yeah, I guess it works. But in this case, Facebook won't pay that fine. They'll just stop operating in Australia - in other words, they'll stop taking advertiser money from there. At worst, Australia's govt will block access to FB.
If FB needs to declare bankruptcy and shutter their doors then nothing of value will be lost.
If the fine structure's purpose is to prevent companies from doing extremely illegal things. Then it seems to work just fine. Facebook would be unable to repeat this mistake.
It's not like there are such things as corporate death sentences in much of the world. So there does need to be a mechanism to ensure that a company that repeatedly flagrantly violates the law is stopped from doing so eventually. Excessive fines are a way to do that, to make it so economically non-viable that it is avoided.
Now again, one can argue whether this violation is worthy of that. But on the face of it there is no reason why feasibility of payment is necessary for deciding the amount of a fine.
Capitalism has problems with pricing external costs to society. The more common example being things like pollution and climate change (something ironically that Australia is particularity bad at). The price for privacy violations here might be a bit high, but it is an externality worth pricing. The amount of money the government will need to spend fighting identity theft in response to this is just the first order effect. Economic damage from both the identity theft and loss of trust. Mental health damage done from the identity theft and leaked data being used. According to the article the government of Australia prices that at 1,700,000 per person. Which actually sounds like a reasonable amount once one considers paying police to track down thieves, prosecution, jail time, the potential for social services to have to help that person while their life is put back together, and so on.
It's the multiplication that screwed them here. That's the part that might not track quite correctly.
I'm not sure British English translates over the internet that well, but this was hyperbole.
Additionally, Australia would probably come down hard on any attempts for Facebook to market or solicit customers within their nation.
If a government of a country defines a website illegal, then that website simply will not be accessible from that country, end of story.
The US, despite leading the charge vis-a-vis the MPAA, has speech laws that make website blocking and censorship extremely difficult.
Facebook Ireland operates Facebook in Australia.
https://www.smh.com.au/business/companies/how-facebook-austr...
Well that would be a dreadful outcome for Australia, and I don't see anything indicating that is a potential outcome.
How anyone thinks that FB should be fined in any of this is ridiculous.
"We hate Facebook, they make too much money, therefore fine them!"
FB had APIs, that everyone in the entire world knew about. There maybe a little 'too open' for some, but nobody was screaming fraud. It seemed reasonable to most.
Then, a sneaky company inevitably came along and used the APIs to break the rules somewhat (arguably even then CA may not have).
As a result, FB did the prudent thing and nudged the APIs a little bit tighter. By the way - FB did the appropriate thing long before there was any scandal, any noise, any blowback.
FB investigated CA to make sure they deleted the data, in turn out CA lied and hid copies of the data.
There wasn't any material harm to anyone - even if CA was able to use the data to help target people (they weren't really), there are innumerable opportunities for companies to do that anyhow.
From the article: "Unless those individuals undertook a complex process of modifying their settings on Facebook, their personal information was disclosed by Facebook to the “This is Your Digital Life” App by default."
This is misrepresentative to the point of being a lie.
Facebook enables users to upload data and will only share such data with apps which the user has given authorization. In this case, users absolutely had to provide CA with the authority to access certain data, in the same way, they would have for any other app.
When Mark Zuckerberg visited Congress for his smackdown, it became clear very quickly that almost none of the Senators had a clue how FB even worked.
Of all the things I don't like Facebook for, there's nothing wrong with what they did here. They had a set of APIs unlike anyone had ever made before, the realized that they were probably a little to lose, so they tightened them up by their own volition.
But I don't agree Facebook isn't to blame.
Power comes with responsibility. At least that is what most countries believe.
So if you make money with a very powerful tool that could potentially bring down a government (this is what a judge has to decide) then you are to blame when your APIs where to lose.
It's like building a nuclear facility with mud.
B) The notion that the resulting action 'brought down governments' is just beyond false.
Anyone involved in digital marketing knows how absurd these claims are, moreover, there are numerous other, legal, and very common practices being used all the time that are considerably more impactful.
To boot:
C) The suing government's actions are vindictive and biased. A commenter above posted a link to refer to the UK government's damage claims. As part of the countersuit, FB demanded that UK office (ICO) demonstrate it's objectivity in the situation (the judge agreed). So guess what happened? The government made a quick perusal of their own communications and realized they would be destroyed in scandal and moved for a quick resolution with a very small settlement.
FB has good and bad attributes we have to be smart about it, this kind of 'anti information angry mob' stuff should be beneath people.
B: They did not bring down any government. But the question is: is the tool named Facebook powerful enough to do so? And if true: did they do enough to prevent this?
C: Maybe they are biased. That's up to a judge to decide.
> Power comes with responsibility. At least that is what most countries believe.
But the question remains unanswered: what is Facebook to blame for? What responsibility did they shirk?
Cambridge Analytica lied about the purposes of their data and subsequently lied about deleting the data they collected. But Facebook remained true to their agreement to only share this data for academic purposes, and when they discovered that some university researchers were violating this agreement they terminated this data sharing program. With the benefit of hindsight we can say that Facebook should have been more doubtful of the integrity of academics - but without that hindsight I'm not sure what Facebook did wrong.
That's not true - they had deleted the data as requested. I worked there.
Funnily enough, the newspaper doesn't mention that Wylie didn't work at CA in 2016 - so he can't be considered a first hand witness or a whistleblower concerning the American presidential election or Brexit. He left in 2014 after obtaining the Facebook dataset to start his own political data consultancy, Eunoia Technologies. The company was based on the concept of micro-targeting(, which he falsely believed was a novel idea). He competed with CA for contracts unsuccessfully, and Eunoia was ultimately sued by CA for stealing clients. (This might explain why he was so willing to work with the Guardian to bring the company down.)
All of the information in the above paragraph can be found on Wikipedia, except for the parts in brackets.
You can read the report from QC Julian Malins or the ICO about the whole situation, they're found no evidence of CA retaining the data. But you can't prove a negative.
I felt that the entire story was as much about narrative than anything.
It's sad because these stories are important, The Guardian is mostly a credible entity, they really ruin their credibility with such shenanigans.
"In this case, users absolutely had to provide CA with the authority to access certain data, in the same way, they would have for any other app."
Unfortunately in this case the data also included your friend list and some items about your friends that may have been marked "friends only" .
This was the big mistake that Facebook is being crucified for, sadly. Like you said, they made changes to clamp things down long before any of the media knew of CA.
Let's flip this around then: Australia’s Privacy Act 1988 lays out clear rules and penalties. Facebook had a responsibility to learn and follow these rules if they wanted to do business in Australia.
> In this case, users absolutely had to provide CA with the authority to access certain data, in the same way, they would have for any other app.
That is not true, and this is clearly explained by the OIAC statement referenced in the article: 'Most of those individuals did not install the “This is Your Digital Life” App; their Facebook friends did. Unless those individuals undertook a complex process of modifying their settings on Facebook, their personal information was disclosed by Facebook to the “This is Your Digital Life” App by default.'
This is Australian privacy law we’re dealing with, not a Facebook EULA.
Sharing the data with Cambridge Analytica (for the purported use) wasn't the problem. Cambridge Analytica lying about what the data was uses for is the problem.
Never mind that this exceeds the company’s entire revenue by far.
Remember Cambridge Analytica's main founder, Aleksandr Kogan, was working at the psychology department of Cambridge University. Facebook had program to allow academic use of user data which it granted to Kogan. Kogan subsequently violated stipulations that this data not be used for commercial and political access, and upon learning of this Facebook terminated his access to this data and demanded that he delete the data that he already collected.
I'm not sure how one comes away from this thinking that Facebook is the culprit here. Sure, you can say that they were naive to believe in the integrity academics. But at no point did they willingly violate their user privacy policies, and when they discovered that a third party was abusing data they terminated access.
That would be considered economic warfare and the US wouldn't allow it.
Has there been excoriation over this? I've seen lots of hand-wringing over election interference and addiction. But the privacy complaints have yet to find footing in America.
Still, a precedent being set on this sort of scale would be a good thing, right?
A consumption tax is a pretty good way to tax foreign companies though imo, as long as your domestic market is desirable.
What happened with China?
I know FB isn't really operating in China. (At least no one I knew in Ningbo had it?) So did we sanction China for that or how did that all work? Because, and I don't know if we did or didn't, but if we didn't sanction China, why sanction Australia? Was that situation different somehow? (Other than just "China's richer").
So? It's about power, the US has it, Australia doesn't.
Australia can fine them a hefty sum, but nothing that looks like an existential threat to the company.
I am assuming this is some Class Action suite ? Or is this different as its from the privacy watchdog ?
This is really cool news though, it's about time that Facebook take some serious ownership of this mess.
Its a fine fit for a multi-billion dollar company. Unless they get it significantly reduced somehow...
Either way it's a good move on the part of governments to apply pressure to a known shady actor.