Ireland to Order Facebook to Stop Sending User Data to U.S.
wsj.com
wsj.com
[0] https://www.politico.com/story/2019/04/24/ireland-data-priva...
Them finally doing something would be huge.
https://www.wsj.com/articles/russia-steps-up-new-law-to-cont...
An image in the same document ends up in (kinda, depends how you measure) 4 servers in 3 locations - also none of them in BC.
Is Google breaking the law here, or is there some exception?
I think that's the message being encouraged by laws like that of the EU
Facebook can have a pretty big team to engineer that kind of infrastructure, while the startup won't have that luxury. It's even worse when you need to go through a lawyer to make sure every single regulations are followed to the letter.
Lawyers will oversubscribe for everything it is up to you to familiarise yourself with the legal aspects and get your engineers to design within these constraints. You didn’t think engineering was just programming did you?
> If you’ve a hundred users in one country it’s worth your while having an instance just for them.
What? No. We are on the web, you forgot that what made Facebook a billion dollar industry was that they could get pennies out of billions of users every month?
If you can get hundred of paying users, sure, but then to me that has nothing to do with the web, that's simply selling a product. The web is more than selling, it's about allowing access, which sadly, is more than selling.
Startups aren't going to be targeted for regulatory action unless they are doing something particularly egregious. If you look at what other companies in the industry are doing and do something no worse than what the average company is doing, then you're going to be fine.
Facebook is a juicy enough target that they need to worry about regulations even if they are doing exactly what every other company in the industry is doing.
It is logistically impossible for them to go and proactively inspect other cases
2) Is US Facebook allowed to record a user-provided and recipient-approved statement of metadata association that references a “Person/Entity” that could potentially be in the EU?
3) Is US Facebook allowed to benefit from processing of metadata without receiving GDPR-compliant permission from the “person/entity” referenced?
I believe the answer will end up being Yes, Yes, No; Facebook EU/US can permit two world citizens to intentionally declare their friendship each other, and the cross-site link is user-specified and passes a “judgment call” opt-in test — but Facebook US cannot make use of that data record in any way that benefits Facebook (such as training models, tracking via social network data, or targeting advertising) other than to exclusively deliver minimum functionality. For example, not okay: “automatic face recognition tagging”; okay: “instant messaging”, “wall posting”.
Disclaimer: I am not your lawyer, I have not prepared citations for your review, please seek legal counsel if you’re considering actions based on my opinion, etc etc.
That say a lot....
1) IANYL is not widely-recognized, so I have to spell it out. The unusual phrasing, versus the typical IANAL, is because "I am not a lawyer" is inappropriate to use. If you are perceived as having given legal advice, it isn't necessarily relevant whether you're a lawyer, and if you are a lawyer you might not be allowed to 'practice law' in the jurisdiction of every reader, and find yourself subject to enforcement actions if you are found to have failed to highlight this distinction. Specifying clearly "I am not your lawyer" clearly indicates that you are not acting in any capacity as lawyer with respect to the reader, denying any opportunity for misinterpretation otherwise. It also clearly highlights that no duty to clarify, followup, or respond exists as a result of the comment, which is frequently misunderstood by Internet forum participants (see also following).
2) HN users frequently seek citations for opinions. Whatever their motivations, I have none to offer here. Clearly stating so helps them correctly perceive this as an opinion posted on an Internet forum, rather than misconstruing it as legal advice provided by a lawyer. They may choose to reject the opinion as it is insufficiently supported, which is of course their right. See also above.
3) Finally, "seek legal counsel" reminds the reader that a profession exists to make judgement calls about these things, and recommends consulting formally with such a professional rather than depending solely on an Internet forum comment. It also reiterates the "this is not legal advice" sentiment that the above try to convey, offering an additional layer of defense again people somehow misunderstanding the degree of legal advice that an Internet forum comment can provide and then suing for recompense when they don't like the outcomes of their actions.
If you can think of a shorter way to say it, I'm open to considering it, but IANAL certainly isn't enough.
That's what I always like about software development. It was simple, it was accessible... but now, you need a lawyer for each individual jurisdiction.
If a US-based user interacts with data posted by the European user, is that not considered “Sending data to the US?”
Sure it could be only accessed when you friend request it, but then it goes over a whole lot of performance issue and complex infrastructure, all that over something you voluntarily decided to publish... while not having any advantage. Facebook still has access to that data either way. You still have to believe their pinky sweare they won't do anything bad with it.
I would agree with anything sensitive, like banks information, medical information, etc... Things that make sense to pay for an actual regular audit, but for a social network like Facebook... that become completely absurd.
Unless caught red handed, we generally trust companies to comply, but sometimes verify.
The technical argument, that it is too inconvenient to comply with the regulation. has little merit in this case.
You lost me there. You shared it with Facebook users, which are worldwide. Are you from Canada? Well look at you reading my comment I voluntarily pushed over HN, a website accessible worldwide while I'm Canadian. Isn't it absurd that because I'm in Canada I wouldn't expect you to be able to read it? You and everyone else that are on HN? This is not something I send specifically to YOU, this is not something
> Unless caught red handed, we generally trust companies to comply, but sometimes verify.
Isn't it what we complains about here though? We do not expect Facebook US to handle the data correctly. Yet they do expect them to do it in Europe? I can see your point, Europe can't verify what Facebook do in the US. It's a good point, but I would have been less against their idea if that was the solution, requiring them to allow Europe to verify or else they wouldn't let them hold that data.
can you cite where the european laws and/or relevant rulings make this distinction?
Wiki - https://en.wikipedia.org/wiki/EU-US_Privacy_Shield
News- https://duckduckgo.com/?t=ffab&q=privacy+shield+&iar=news&ia...
The Irish DPC didn't want to make this decision (for reasons), kicking the can to the CJEU, which eventually resolved Schrems II and remanded the decision on FB's SCC's back to the DPC.
It is hard to imagine a SCC that could provide "essentially equivalent" protection if the other end is an American company, given the authority the US government can exert over it.
States coming to a variety of conclusions and making a variety of decisions about how to treat a private US company holding an unimaginably large amount of social data and metadata... was an eminently knowable and completely obvious set of risks going in, so I have little sympathy for Facebook "failing" to plan a mitigation for those risks. It's hard to see it as anything but a deliberate choice.
Unfortunately, given their past history I suspect the hope was that the company would be able to have its cake and eat it too, by playing on legislators' and citizens' lack of technological literacy and adhering to a "better to ask forgiveness than permission" policy. Throwing up engineering hurdles to compliance just benefits Facebook in this case, because they're banking on states' inability to simply ban Facebook. Facebook can force them to the table, with the deck stacked against them.
"Won't your citizens be angry if you make Facebook inaccessible to them?"
"Everyone uses it! That could be seen as censorship!"
"Let's work together to find a solution that benefits everyone."
It's the same story as with Uber and AirBnB.
Problem solved
The EU still allows transfering data to other third countries if suitable protections can be effectively put in place, whether through some governmentally agreed program like what Privacy Shield tried to do or through Standard Contractual Clauses. They simply view the laws in the US as too hostile to most of their residents' data privacy rights. ("Most" instead of "all" because US citizens have more protections under US law even when living in Europe.)
So, while sure it is a kind of border, it's a "privacy-protected vs privacy-dangerous" border rather than a blanket "us vs them" border. Or, phrased another way, it's not a border as a goal, but rather preventing the nature of the internet from overriding their separate privacy goal. I am fine with that attitude.
Let's take Facebook. We could have Facebook.US, Facebook.EU, Facebook.UK, Facebook.CN, etc.
In a borderless internet, you'd still be allowed to use the one that you wanted, but each would be subject to the laws of its "country". (I realize that the EU isn't a country.)
Plus it's not in $country is in $region, if all countries made an effort to adopt GDPR data could be stored anywhere.
EU is looking for their citizens data, since no one else seems to care that much (other than China but for completely different reasons).
Unless you think that the protocol of tech giants to poor data protection is fine, when they are saying:
"Ups, we're sorry :(... it won't happen again!"
Yeah that’s part of the original vision of the Internet.
Rules, Letters to enforce those rules, Strongly worded letters to enforce those rules.
Announced and unannounced audits to ensure compliance.
In the extreme case and only if needed, fines, warrants and searches or revocation of access to customers (EU companies wanting to advertise) and resources (FB users in Europe).
FB knows that and they also know this particular case is very public so they will either comply (probably hesitantly and last minute) or withdraw from the EU market if the bean counters say it's not worth the effort.
I've never heard a clear answer about how GDPR applies in dual-citizenship or non-EU-residence situations.
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Now search for users in your “add friend” dialog. Are you now querying a database per country?
I publish a message on my Facebook wall, can it then be kept on Facebook US database? It just like an e-mail, any recipient should be able to keep it, isn't it?
Okay now I send my age, can they keep it? Why not? I send you my birth date by email, you can keep it, can't you?
What's the limit, and how does it works? When I send an email, it's clear who's my recipient, so is that the limit? Recipients has to be clear? Then can a corporation be the recipient too?
Storing user data should be difficult, otherwise there's no incentive to really think about how you store it and how securely.