Facebook says it may quit Europe over ban on sharing data with US
theguardian.com
theguardian.com
Instagram and FB.. plenty of boards and forums, Mastodon.
For anyone who thinks that "there are no technology alternatives for XYZ" or that "tech cannot move so fast to close the XYZ gap".. see what happened in 2020 with COVID and how fast tech industry moved to cover the gaps that were newly created (or lately enhanced).
0: That that reason is "it's a pain in the ass to migrate to something else" rather than any actual merit of WhatsApp wouldn't make this tactic this any less effective.
This was huge tactical mistake that they have made. The same issue that they have is also common for google, microsoft, amazon (probably).
If EU would let them off the hook based on their "threats", everyone would start doing it the same. Now FB has put themself into unique position where they have forced EU to do exactly what they dont want.
Someone is very stupid in their chain of command.
I strongly believe this is the right path forward, not the Chinese/US model of banning services. If the US way of doing things prevails, you can bet that Facebook and the rest will be banned all over the world because it is actually a security risk and it is a proven fact that US intelligence agencies are indeed snooping Facebook and other US tech companies. How do we know that? Thanks to Snowden. The revealed program is PRISM[0], who knows what else is out there.
I really hope that the EU way becomes the norm, otherwise the internet will get patchy, we won't have global communities anymore. There might be solutions like companies incorporating in each country like Coca-Cola opening a plant in every country but it will not be the same and will make the barrier of entry so high that very few will make it. No more global startups form a dorm room.
[0]: https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
EU wants data privacy, and has regulations for it. European countries have always had strong consumer protection laws, it just so happens that the EU has unified them and it has teeth. To operate in a country, you have to follow that country's laws, period.
At Facebook's scale, I don't think this is beyond their technical capabilities, or too expensive. The reason they are worried is that they've built their business on data surveillance, and they are worried that the EU with all their privacy regulations will invalidate their business model.
As for Snowden, I remember the US president claiming that foreigners are not US citizens and thus we have no rights. Well, this is the EU protecting my rights, as an EU citizen. And US businesses will just have to comply if they want to do business here. Fine by me.
make that "will make their business model less profitable" and I agree. With that many users, I'm very skeptical you need ANY kind of micro-targeting of ads to make good money. But the targeting allows you to make crazy money so they're pretty attached to it.
Turns out, not always, though. One of the problems with GDPR is that enforcement is left with national DPAs, and it appears that the Irish DPA is really dragging their feet about it. Coincidentally, Ireland is where the European operations of many major technology conglomerates are established.
The legal framework is there, lawsuits are happening, and it scares companies built on data surveillance, and we know because some of them have moved out of EU already.
The big players are operating in a gray area that's harder to attack, but then again, they are bigger targets. Given past fines, and given GDPR's potential, I'm sure the EU wouldn't mind replenishing their budget in the future.
People pay for FB ads due to being able to target a demographic, eg women between 35-45 from California, interested in wellness. That's their whole value proposition.
They could turn around and start serving ads based on the content viewed, but content and viewing on FB is very superficial, and compared with Google's AdWords, they don't have searches that signal intent.
FB's ads convert pretty badly already. If those conversions drop further, might turn out to be a deal breaker.
So what are they gonna do? Serve ads for Coke-Cola?
I was talking in general anyway. Between GDPR, requirements for safeguarding, and Apple destroying the mobile in-app advertising ID, they probably don't feel so good.
Norwegian dating sites don't have permission to use age/location info, for ads, without explicit consent, and the ToS can't cover it, FYI.
Facebook could still make plenty of money without doing this.
From the Charta of Fundamental Right of the European Union:
Article 8 - Protection of personal data
1. Everyone has the right to the protection of personal data concerning him or her.
2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an independent authority.
It doesn't mean that the concept itself isn't possible to be disrespected, there is a lack of respect (and even considering the informal definition of disrespect to be an "insult") to data privacy in the US, there are no legal consequences to it though.
The EU-Facebook situation is built of laws passed by the EU, and court rulings over the span of over a decade with proven and known access of data by American spy agencies.
Facebook also has been given time and a clear path for resolution that they could follow to resolve this situation.
None of this is true in the Tik Tok situation.
The core of the issue is the same though. This one instance can go away but the core issue is there and it will keep coming in different forms. And If TikTok actually gets banned, I am afraid that anti-americanism and anti-globalism might get strong enough that the banning become the norm.
These things are not like controlling cheese imports, people will actually suffer from these things just like Chinese citizens suffer from the Chinese internet censor. The moment the USA give the example is the moment when suffering becomes acceptable for the greater good(the greater good will vary, some will say it is to protect local businesses other will say national security or simply rejoice that it is an opportunity to stick it to the yankees). This is not a future I am looking forward to.
A degree of being difficult or impossible for a country that isn't hosting the servers or business operations of an internet service to enforce laws and regulations on it used to be seen as a feature. We already have a situation where reading most US local news from Europe requires the use of a VPN. Is an expansion of that situation desirable? When most of the population starts doing it, will banning VPNs be the norm outside of countries the West largely regards as totalitarian?
I don't like the path this has to go down for enforcement to be effective.
We can easily have global communities if social media is based on open standards and transparent data sharing, rather than corporate offerings with jealously guarded, covertly collected, personal data silos.
I'm personally really happy to see these challenges to corporate social media, whether it's TikTok in the US, or Facebook in the EU.
A lack of safe, secure and legal international data transfers would damage the economy and hamper the growth of data-driven businesses in the EU, just as we seek a recovery from Covid-19.
Clean up your act, or leave the EU data in the EU; we all know you're not going anywhere.
If the EU says that all data related to EU residents has to stay in the EU, what happens if I as an American leave a comment on a post by a friend of mine in Europe? If my interactions with Europeans have to be stored in the EU, will all of my requests have to be served by Facebook servers in the EU? Definitely won't be fun for latency. I don't think that would be an insurmountable problem, but it makes things complicated.
Let's make things even more complicated: what if another jurisdiction passes similar rules? Lets say all data pertaining to residents of New Zealand and Australia has to stay in Oceania. How will people in the EU and Oceania be able to interact without running afoul of at least one jurisdiction's rules?
Talking about edge cases is a distraction from the fact that FB is refusing to implement things that are very much not edge cases and do not have fundamental implementation challenges associated with them.
If the US passed a mirroring law in order to protect Americans' data from being spied on by GHCQ, then you have two mutually exclusive privacy regulations. The data can't exist outside of the EU, but the data also can't exist outside of the US. Considering the competing goals (in this hypothetical situation where the US doesn't want Americans being spied on by the EU, and the EU doesn't want Europeans being spied on by the US), I have 0 faith in the governments being able to resolve this balkanization.
I mean, I know the lobby is powerful but that does strike me as a bit improbable.
Hope I’m right.
And I'm sure you could work out some kind of subsidy scheme for truly impoverished people who legitimately can't afford that.
The problem is network effects and getting people to switch. But if you regulate any company not adopting this model out of existence, it could work.
That said, I do acknowledge that the nature of social networks strongly leads to a natural monopoly situation more akin to a utility. It's not an easy problem. But I think paying for it isn't the hard part.
edit: I see you added a statement saying that Facebook is a natural monopoly, and I really don't understand how that can be true. From the late 90s until now we have had many people running multiple IM clients, and we currently have many people running multiple social networks simultaneously.
I think two critical differences between the manner IM was used historically and social networks are used now is the (mainly) 1-to-1 nature of chat content (as opposed to mainly 1-to-N nature of social network content) and the usage of persistent state.
Without any actual data, my intuition is that the main use case of chat for most people is ephemeral, mostly-synchronous 1-to-1 communication. I only rarely went back through chat history, usually to find some obscure link or something. And because most people's main use of chat is 1-on-1 communication, there is no need to curate persisted content for external viewing.
A key component of Facebook is curated and formatted personal content that their connections can asynchronously view. Most people do not want to maintain duplicate photo albums on several platforms, post the same thoughts or essays or rants on multiple platforms, etc.
I agree that Facebook could theoretically be a natural monopoly, but in practice there appear to be many social networks operating in parallel. This may be an unstable equilibrium, but I view LinkedIn, Instagram (before the takeover), and to a lesser extent TikTok, SnapChat, Reddit, Youtube, and Twitter as Facebook competitors. It seems like there are many people who use more these networks in parallel, which means that there is no natural monopoly.
On the other hand, I do believe that Facebook has a so-called 'moat', though it may not be as strong as some others believe.
Push come to shove you can just shut the company down when you get sued.
The only thing you can do is be a smart consumer. Know who owns your data, and be mindful of what your actually buying.
I really want a VR headset, not a Facebook Advertisement delivery device .
> In a court filing in Dublin, Facebook’s associate general counsel wrote that enforcing the ban would leave the company unable to operate.
Wait, does that mean that snooping by US intelligence agencies on people in EU is required for Facebook operation?
It's a weird ban though, as if interpreted as described, it would lead to two Facebooks where EU/US users would not be able to interact.
(the ruling wasnt a total ban on sending data, rather that there must be restrictions over what private data can be transferred)
Any US-based company is required to submit to warrants/subpoenas (assuming they're legal/proper) from intelligence agencies. It may certainly be the case that courts would hold Facebook in contempt if they refused - even if they refused in order to comply with EU law.
This is both a problem for individual civil liberties and for non-US businesses, as the US intelligence system does conduct commercial espionage.
My understanding was that intelligence agencies were required to get a so-called "FISA warrant" to compel the production of information. [1] Am I missing something?
[1] https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
Yeah: Stellar Wind, muscular, prism and skynet
Basically the national surveillance agency wants APIs with all communication networks, so they can request anything, arguing their automated big data mining will only request data they are allowed to request, by law or warrant. The data providing business should not look into the details what they request, because that would endanger national security.
The FISA courts have a history of signing very broad warrants like "all data related to who talks to whom necessary for national security"
And the agency has argued in the past that they can copy anything anyway because only if a human officially looks at the data in an investigation, a warrant is needed. As long as it is only fully automated machines running big data analysis on it, and no one is looking, such rules do not apply.
And the FISA court pretty much signs any "look into it" order if the machine says "i found something, someone should look into this".
The worst of the worst is that skynet thing: it creates lists of people that are to be targeted by automated flying killer robots. I know this sounds ridiculous. That is the reason why they picked that name.
I remember reading a Wired article probably 10 years ago that an early large investor was the NSA/or similar, so yes, snooping may be a feature.
You really didn't look that hard did you?
So the new age internet needs bureaucratic regulation tags to comply with all laws.
Think of something like $0.25 per BGP query. Even that would be enough to grind the web into halt.
the safe harbor / privacy shield agreement was dq'd because US intelligence can reach into the data, thereby not meeting the requirements of GDPR. facebook can't operate because it now lacks safe harbor, and is unable to meet the alternate requirements for data protection.
it's a very interesting ruling, because SCC was upheld, and US intelligence can just as easily look into data transferred under SCC agreements. in my brief reading, users have to explicitly agree to allow export of their data under SCC though.
I really hope all nations start to implement serious controls here. In my opinion you should need a license store user location data and they should be revoked immediately if you're found not protecting it, or retaining it longer than you need to.
For example a rideshare service should only store your location for the duration of your ride and then should delete it within 10 days or so. I love ridesharing, but I don't like the idea of someone being able to know everywhere I've been for the last 2 years.
The "we" in the above quote is both touching and sincere.
Another example is Xing which is a surprisingly popular LinkedIn clone that copies many of the dark patters of the original.
You can accuse Xing of many things but not that they are behind LinkedIn. I mean regarding the technology, UX and overall experience I have no complaints and I find the community there much more pleasant than LinkedIn. That's one reason I'm still on Xing, but quit LinkedIn some time ago.
What I criticize though is their use of dark patterns and tricking their users into accepting things they most probably don't really want. In that regard they are more akin to Facebook and maybe even worse than the recent LinkedIn.
> "Facebook, and many other businesses, organisations and services, rely on data transfers between the EU and the US in order to operate their services."
There are still corporations that exist that offer other types of services though.
Like if you architected it so that every user has a home country and enforced data locality then FB needs a datacenter in every country they operate in and a US user viewing a UK profile needs to (in my view arbitrarily) go across the Atlantic ocean just so that you can play jurisdictional games with no actual security boundary. It's still all Facebook, and it's the same cross-pollination there was before, every country will need to access every other country's data and a malicious US could still force FB to produce the data of UK users but it feels better?
Good riddance Facebook.
"Facebook has warned that it may pull out of Europe if the Irish data protection commissioner enforces a ban on sharing data with the US..." haha, "warned" who? You're not wanted!
It would be impractical to have European data only physically stored in Europe and be able to have North Americans interact with Europeans. US vs. Canada doesn't have the same problem.
The only reason they're not lumped together more is that Americans forget they're there.
Quebec shares a legal heritage with Louisiana, though that sets both apart from the rest of the US and Canada.
In short: yes, the US/Canadian judiciary may decide not to enforce rulings of European courts, but there’s still ways to make things painful for Facebook if they choose to continue operating in Europe while not being compliant.
Instagram too. That’s widely used by youth.
Take WhatsApp and Instagram offline in Europe while you're at it :-)
It's interesting that it qualified the statement with, “Facebook is not threatening to withdraw from Europe,”. It sounds like what they are really saying is that we have a lot of work to do to figure out how to operate under these conditions. That's a fair statements, but I have full faith that capitalism will motivate them to figure out how to make it all work.