Messenger API Updates for Europe
developers.facebook.com
developers.facebook.com
Not surprised, but there's no way to spin this in a way that doesn't make Facebook look shady and bad. So much for "working with regulators".
"We are currently working to restore these features and will continue to update this document and the changelog section with the details as they are available."
Doesn't this suggest that they aren't being shut-down?
Interesting that Facebook and everyone else has been knowing that these rules have been coming for years, they still haven't been ready. Certainly reads like they haven't been working with anyone, and their last resort is now to temporary shut down the features they were unable to fix, during these years.
There's being ready, but I think there's also some wariness that the penalties for non-compliance are so severe that it's not worth taking the risk.
When GDPR was first being proposed, I was at a startup in the messaging space, and we were in the midst of expanding into European markets. The level of effort to ensure compliance wasn't that high, but without established case law and a history of enforcement actions, it was deemed too much of a risk so we pulled back.
> Unfortunately, our website is currently unavailable in most European countries. We are engaged on the issue and committed to looking at options that support our full range of digital offerings to the EU market.
and have done so for years.
Facebook's "currently" may be worth as much as the "engaged" and "committed" of those sites.
"Unfortunately, our website is currently unavailable in most European countries. We are engaged on the issue and committed to looking at options that support our full range of digital offerings to the EU market. We continue to identify technical compliance solutions that will provide all readers with our award-winning journalism."
Ok, I'm sure it'll be any day now…
A similar example is sending garbage to China. At a certain point China stopped accepting it. Hopefully soon others will do the same and recycling will be tackled correctly.
By popular I mean "small businesses start advertising contacting them through WhatsApp"-popular.
It would be nice to have a breakdown of these numbers but we'll probably never get them from FB.
Here in Mexico, any mobile data package comes with free data for blessed services like Whatsapp and FB Messenger. Obviously trying to compete with each other on these perks.
Using a competitor like Telegram is a complete nonstarter when trading memes or video chat eats into your data. The cheapest plan from Telcel (pay-as-you-go + holding 20 pesos in your balance) lets you use Whatsapp infinitely.
GG to competition.
But if the EU decides to legislate against FB, for example, I doubt they'll be that silly, they'll probably shoot these clauses down.
It is probably illegal (on the paper we have net neutrality, the telcos just blatantly break the law) to do so in Sweden which why some telcos are in a legal battle with our regulatory authority.
While useful to people, most of whom want to just go to Netflix, that level of integration doesn't feel right.
I feel like all of these apps (with special emphasis on Telegram and Signal) have almost the exact same UX and features of WhatsApp... beyond adoption numbers.
Surely one of these can take its place?
[1] https://matrix.org/blog/2018/04/26/matrix-and-riot-confirmed...
Therefore, so far FB only collects contacts and improves its social network (in the technical sense) with WhatsApp.
Nothing that can replace WhatsApp? A simple messaging app like hundreds of others out there? If they shut down tomorrow I don't think anyone would be impacted. People would just switch to one of those. Nobody in 5-10 years would be like "I miss WhatsApp".
I know people, who only look for businesses on facebook, ask for support questions there, and dont't care if the business doesnt have a full webpage, if it has a facebook page (and even if it has, sendin an email is a lot "harder" than just clicking "chat" on a facebook page, to ask something (eg. if they're open now, due to pandemic,etc.).
These APIs that are being limited have very little to do with user privacy and mostly impact usability. For example it looks like handoffs between chat apps are no longer possible in Europe- a company could have an entry point chat bot that routes to a live human, or routes to an order-taking bot. That routing is no longer possible without the “handoff protocol”.
It looks like users can no longer send attachments to a business either. (Or rather they can still send the attachment, but the business can’t use the api to access it?). I don’t believe this is a win for users and just shows some unintended side effects of EU legislation.
(Also, listing the UK under EEA is .. complicated and subject to change in the next few weeks. https://en.wikipedia.org/wiki/Membership_of_the_United_Kingd... )
(Where is Facebook's data center anyway, is it Ireland?)
Less so for Switzerland? Because this does not seem to apply to Switzerland, which has signed the EEA agreement, but did not join.
I've the initial impression that this will be a good step for reducing the drift of user content into other websites and spaces where messages or user data may end up outside of the context for which it was generated.
There's a draft for "ePrivacy Regulation"[1][2] introduced in 2017 that looks to replace ePrivacy Directive, but it's still in a draft and discussions stage. There's no guarantee it'll become a law.
[0] - https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32...
[1] - https://www.mckinsey.com/business-functions/risk/our-insight...
Source - worked on ePD compliance.
But I don't understand how ePD with no changes from 2009 can suddenly include Facebook and others? Unless there have been other regulations passed?
I can't find anything about ePD changes that forces Facebook to do this, all I can find is the upcoming ePR (ePrivacy Regulation) that will affect Facebook and others, but it hasn't been passed yet.
I haven't heard of any privacy/GDPR/ePD changes recently other than the EU-US Privacy Shield invalidation.
Is there anything I can read on the changes you're talking about?
Sorry but this is not how EU works and it doesn't make any sense at all.
You can't "speak with the EU", in the same way you can't "speak with the United States of America".
You can speak with a data regulator in a specific country if you wish so. But each one of them is also part of the European Data Protection Board, which ensures the consistent application of data protection rules throughout the EU.
I can understand lawyers speaking with one of the regulators, and been told about the ePR "ePrivacy Regulation" proposal that looks to repeal the ePD "ePrivacy Directive".
But we live in a sane world (at least here in the EU) where impactful regulations and directives don't change overnight without any notice and implementation period. The ePR "ePrivacy Regulation" draft suggests a 24-month transition period, similar what happened with GDPR which was agreed in 2016 and went live in 2018. So the earliest ePR will take effect as of today is 2023.
Having some "lawyers speak with the EU" about some unannounced "internal material" that "need to happen right away" doesn't make sense.
So no, I don't see how your or Facebook changes were influenced by ePD "ePrivacy Directive" from 2002/2009.
I was using short hand when I said “spoke with the EU”. You chose to misinterpret that.
All I know is that Facebook needs to comply with this by December 21st. This was something we became aware of a few months ago.
If you think that’s impossible, fine by me.
On December 21st, a 2018 European Electronic Communications Code (EECC) directive goes live on 21st of December 2020.
It's a directive to consolidate and reform the framework for the regulation of electronic communications services and networks in the EEA.
> Under the EECC, the scope of electronic communication services will be expanded to include over-the-top/online communication services. Therefore, providers of VoIP services and other online communication apps (video, chat, messaging) will be subject to telecoms regulation and by extension the ePrivacy Directive.
> For the foreseeable future, those caught by the provisions of the ePD will continue to need to comply, taking into account the interplay with the ever-evolving guidance and case law on the GDPR (e.g. on consent, notice, etc.), which will often apply in the context of the application of the ePD. The ePD rules have not been kept up to date with the latest technological developments and are also not well aligned to the enhanced protections of the GDPR.
I was wrong, the changes are influenced by ePD, but indirectly because of the broadening definition of electronic communication services. Finally we're there. I'm surprised no one else commented about this earlier and it took so much time to understand why this is happening.
This means that data sharing between the US and EU is a lot more complicated, as the EU ruling basically says that US data protection regulations are not sufficient to comply with the requirements set out in the GDPR.
The recommended work around to to just send the link which now makes it explicit to the user that they are connecting to the third party.
But seriously, if anyone had doubts what GDPR will achieve, I think this person is pretty naive. GDPR is not a progression, but a regression, and it will seriously hit (already does) online businesses in the long run.
Same thing with cookie warnings. No normal person will read tons of legal text on every website they visit. And even if the normal person will read it, they won't be able to decline the cookies, because the site will not work. But let's say you're a technically savvy person that is actually interested in cookie privacy; I'm really surprised you're not using "cookie autodelete"-style plugins already.
Creating laws only to have laws will never work. It only creates cost for everyone in order to be compliant. And people always go where the cost is lower.
I feel this is like saying "we don't need safety legislations at work because businesses take a hit trying to stay compliant, if you don't want to be hurt at work, I'm surprised you're not wearing a helmet already."
Thing is, I wouldn't need "cookie autodelete" style plugins in the first place if companies cared about data privacy.
The problem with law is that only good guys abide the law. And you don't need to defend yourself from the good guys, only from the bad guys. And bad guys will violate the law anyway.