Facebook to move UK users to California terms, avoiding EU privacy rules
reuters.com
reuters.com
Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.
EU citizen works in the UK for 2 years then goes to Turkey for a vacation but likes the place so much, decides to stay for longer when still remote working for the same London company.Also connects through VPN because the Turks love banning websites.
Where this person residence is? Are the UK, USA, EU or Turkish rules apply? How FB would know about it?
That’s not an extreme scenario BTW, it happens all the time.
Tax residency is separate and the rules are a bit different and again vary by country.
Usually residency is self declared or based on where you have spent the majority of the year working in.
This is already handled, by lots of people, when they declare residency already, for where they currently live/work/are covered by taxes under.
This isn't a new thing.
Can you vote in Glasgow's local elections if you live in Manchester?
The electoral register knows I’ve left the U.K.; I had to tell HMRC separately because they don’t share info; likewise the Student Loans Company even though there is a close connection between income and repayments [0]; and when I tried to tell the DVLA, they told me they lacked the capacity to know about non-UK addresses.
[0] the repayment rules means that, for low- and mid-income people, it behaves more like a graduate tax on worldwide income than a loan — it’s a percentage of pay over a threshold, and only high earners can pay it off fully — and if you do a self-assessment tax return there is a box for student loan stuff.
In UK there's this concept called proof of address and it's usually bill or a document that is sent to your address, there's no central registry of residents.
Some countries require at least 6 months + 1 day to be considered a resident, others might have you have a resident even if you aren't there if "the country is the center of your family or economic interests".
What causes difficulties though is that the rules in different countries, even if clearly defined, can contradict each other on the question of tax residency. So you may well be liable to pay taxes in two (or more) countries at the same time.
You may even have to pay taxes in both countries on the same income or gains, unless there is a double taxation agreement that allows you to offset some of those taxes against each other [2]
[1] https://www.gov.uk/hmrc-internal-manuals/residence-domicile-...
Tax law favours a designated location for residency, for example.
The GDPR doesn't even operate on the level of residency (at least for data subjects). You're covered by the GDPR when you're physically in an EU member state[0] as regards your activity in that member state or if the data controller/processor is established in the EU. The UK GDPR will be the same, mutatis mutandis.
[0] Or somewhere where EU law applies by virtue of international law, like an embassy, an EU-flagged ship, an area of Antarctica claimed by an EU member state etc. etc.
If you're there on your 90day tourist visa, it's not your residence.
It also states that data from people in EU has to be processed and stored in the EU.
It's not a matter of citizenship nor residency. Facebook just geo-locate you IP endpoint (so endpoint of your VPN) and manage your data by doing so. So USA rules will apply.
BUT if you are browsing websites hosted in Europe, EU rules will apply to your data.
Now there's the practical question of how the EU enforces that protection against companies that have no presence in the EU, but those that do, the EU has made it quite clear they'll take enforcement action.
If the data controller/processor is in the EU, the GDPR applies.
If the data subject is physically located in the EU (even if not a citizen or resident) then the GDPR applies.
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15288746...
Article 3.
If the data subject is physically located in the EU (even if not a citizen or resident) and the data controller purposefully targets data subjects in the union, the GDPR applies.
As per [0]:
the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention
[0] https://gdpr.eu/Recital-23-Applicable-to-processors-not-esta...
"factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."
For example, almost anywhere in the world if you want to open a bank account they will explicitly ask you now if you’re an american citizen.
> 3.2 This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union,...
(Plus companies in the EU have to comply with GDPR for all subjects)
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15288746...
For example, it also applies to people which are traveling and are currently located in EU territory (provided that a service is intended to be used by EU residents).
An American tourist in Paris is protected by the GDPR.
Of course the EU will have trouble enforcing that protection against companies that don't operate in the EU. But the protection remains, even if it's practically unenforceable.
I don't know why people keep repeating this myth. Laws like these are old as dirt. It could as well have been about blood samples from Denmark used in research in the US: the samples are protected by Danish law and to use them in the US you have to agree to certain rules. Again an example of you saying you will follow certain rules to be allowed to transport and use the samples outside Denmark, not Denmark forcing their laws on anything in another country. You are free to not sign anything and not use or move the blood samples or PII anywhere.
I have never applied for an Irish passport but I am automatically an Irish citizen based on my ancestry. Does Facebook know this? Do I need to inform them to benefit from GDPR protections on an ongoing basis?
How the hell is any of this enforceable?
That depends on what you want to do. What GDPR protection are you trying to benefit from?
> How the hell is any of this enforceable?
You can try to reach out to the regulator if you believe your GDPR protections are being violated,
https://www.dataprotection.ie/
My experience with the ROI is that they are unlikely to jeopardise Facebook pulling out of Dublin.
If you're physically in an EU country then EU GDPR applies to you there; if you're physically in the UK then UK GDPR applies to you there.
That is not correct. Specifically, the counterexample is if you are a EU citizen living in an EU country and the actual bits are stored in a datacenter in Texas. GDPR still applies in this case, as long as the website owner accepts EU users. If the website specifically doesn't do business in the EU, things are different.
Since the data originates where you are, the data has crossed a border to get to Texas and is therefore subject to GDPR (extra-territorially), I agree.
If you were in Texas when that data was collected from you, and you returned to the EU, I doubt that GDPR would apply to that data.
The only reason the EU is able to get away with this to a degree is the american governments wish cooperation to a point and our treaties. However, I suspect america will only tolerate so much push from the EU.
If you do actual business in the EU they can block financial transactions, and if you don't do business in the EU, there isn't really any incentive to (ab)use the data GDPR covers?
I believe that is still covered by GDPR, but I'll openly admit that I specifically chose the counterexample in order to stay within my factual memory of the law.
Afaik GDPR covers EU citizens traveling abroad, as well as non-EU citizens in the EU.
Edit: It does not cover EU citizens traveling abroad, see thread below.
This is overall a good move by FB that puts a lot of pressure on EU/UK to come up with more sensible laws. Note that EU/UK has barely produced any major company operating in consumer web/app. It is for a good reason.
Future regulations with teeth, but don't exist yet, are things like:
- Data portability: I should be able to export my entire Facebook account in full in a standardized format and easily transfer it to any other social network of my choosing.
- Algorithmic control: I should be able to choose which recommendation algorithms are being used on me, or opt out of algorithms entirely.
- Algorithmic transparency: As a consumer, I should be able to see something similar to what Facebook's growth team sees. What specific changes caused people in my cohort to increase their watch time by 2%? Was it better button placement, which I'd be okay with, or was it an increase in conspiracy content, which might not be?
All of these things might be huge overhauls and difficult for the social media companies to deliver, but if you are pushing content in front of billions of people's faces for hours a day you should have an equivalent immense level of responsibility.
I still wonder what the 'legitimate interests' of ad companies are. I also wonder if rejecting the cookies actually works, it's not like I can check right?
The absolute vast majority of cookie banners are actually illegal under GDPR. One downside of GDPR isn't the banners, it's inaction by EU authorities which should've cracked down on these practices long ago.
1. Cookies essential for the functionality of your website (such as session cookies) don't need consent, and are explicitly allowed (you need to have an easily accessible clear-text explanation of what they do)
2. Pre-selected boxes do not constitute consent
3. You must provide a simple "opt out of all and proceed" button
4. You are not allowed to degrade functionality if user has opted out of non-essential cookies
5. You are not allowed to load any non-essential cookies before consent is given
You know, it used to be that ads were targeted by where they were shown, not by who was looking. That's a return to that model.
What matters is if it's Personal Data.
Personal Data is defined by the GDPR as:
"‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person".
I would say a tracking ID falls under "an identification number [or] online identifier"...
In essence, under EU law privacy is an unalienable right, it's not something that can be freely contractually sold away (alienated) by the users. If you have a contract where users agree to allow you to do whatever with their data because you give them $100 or show some content, then that does not fit the definition for consent according to GDPR, and this contract does not - can not - give you the right to process their data as you wish; that particular clause in the contract is effectively void, the users are "selling" something they can't legally sell.
If some data is required to fulfil your contractual obligations to the user (for example, processing their address to deliver pizza), then that is a legitimate use under GDPR 6.1.b which does not require consent, but if you'd want to use the same data for some other purpose (for example, using that same address for targeting advertising or giving it to a third party) then the contractual need clause 6.1.b wouldn't apply, you'd be stuck with 6.1.a (consent) and that is valid only if it's a genuine free choice without some benefit or service being conditional on providing "consent".
So you technically are allowed to block access to your site to people who don't click a checkbox "I agree to stuff", however, if you do so then clicking that checkbox does not constitute freely given consent, so it can't give you any rights to use the data for any of the people who checked that checkbox, for the purposes of GDPR that checkbox is simply meaningless if access to your site was conditional on it. So the users have the right to (and will) file complaints about illegitimate use of their data right after clicking the "I agree to stuff" checkbox.
No. That's illegal. Because:
- the functionality of your site does not depend on collecting user data for ads
- you can show ads without collecting user data
Also one that didn't just talk about cookies. What if I enable tracking code in my mobile app? That's not cookie-driven.
Additionally, as I only recently found out, it's common practice in European Law to have explanatory notes in the law itself. They are called recitals.
Here's a recital on what constitutes consent: https://gdpr.eu/recital-32-conditions-for-consent/
2) Data portability is already a requirement under GDPR Article 20. The problem is that it requires competing services to work together to create interoperable systems or formats. That's really unlikely to happen without addition regulatory action mandating that competitors cooperate.
People will always gloss over privacy policies, privacy tools, and privacy disclosures. The reality is that people are concerned about privacy, but not concerned enough to make any changes. People concerned about the environment still get on planes and fly all over the world.
A) Has offices in different locations in the world;
and
B) Sells, as a service, to other companies, the ability to "off-load" their users, user management, and user agreements -- to other countries and jurisdictions.
Yes, there are all kinds of problems with this idea(!), and yes, it would require tons and tons of Lawyers, both foreign and domestic, and that's if it could be done at all (is it moral/ethical/legal/legitimate/lawful at all levels?) -- but these issues temporarily excluded for the purposes of philosophical discussion, as someone who is interested in business and producing services for other businesses (AKA, value for business customers),
I have to wonder if there's a market there...
?
I of course, would lack the resources (much less the desire!) to attempt to capture that market, but nonetheless,
I have to wonder if there's a market there...
?
For advertising and behavioural tracking cookies, consent is required if it's tracking your personal data to the level of individually identifiable people, but frankly they shouldn't be doing that.
I've personally implemented websites in the EU with logging in, carts and analytical tracking that didn't require up-front consent popups because their behaviour was already reasonable and therefore compliant.
Some of us believe that the bigger sites deliberately use obnoxious consent forms in order to encourage USA residents to remain politically in favour of "implied consent" to individual behaviour tracking. In other words, obnoxious on purpose to give the impression the EU system is more onerous to each user than it really has to be.
After the UK leaves the EU I will do my browsing via a VPN through an EU country specifically because I want to be able to deny all such consents except to sites that I trust and support. (In practice I grant consent to about 10% of sites and deny the other 90%).
If I can find a browser extension to automate denying consent that would be great, but if I can't then I'll do it manually.
The thought of my consent to being tracked down to the level of individual, personal detailed behaviour being "implied consent" the USA way is horrible. I do not consent, full stop. It seems an affront to basic legal principles that the norm is for people to not be told about or therefore have the opportunity for informed consent to the detailed databases built up about their every action online, similar to credit files but much more detailed and secretive.
And one is not obliged to agree for using the service.
Of course, US FAANG companies try to create a kind of backlash, also things like when Amazon tries to force users to use credit card payments when other payment methods like bank transfer in advance work fine. But on the other hand, there is a noticeable increase in web shops in the EU which, for example, do not require any account creation at all - put something into the shopping cart, go to check-out, enter your address, enter your SEPA direct debit number, done. It is much faster and serves me as a customer better.
And no GDPR consent form needed, as all the processing is only for what is needed to do the payment and the delivery.
But anything automatic can have serious downsides, what happens if you start denying ‘good’ sites without realising it. Should all things that require consent be blocked?
This World Wide Web of permissions sounds like it’s going to be a bit of a nightmare.
If they're asking about cookies for GDPR then that's a mistake on the part of those sites. You can read about the details of PECR here https://ico.org.uk/for-organisations/guide-to-pecr/what-are-...
Of course under GDPR they may need to get permission for other forms of data processing (signing you up to a marketing mailing list, for example), but the rash of cookie permissions banners are because of PECR and similar legislation in other EU countries.
It’s getting more and more difficult to have a good experience browsing the web. That worries me.
[RANT] They should never have been implemented that way IMHO -- a different API or IETF-ish agreed HTML meta tag that would inform the browser of the scope, entities etc. would have allowed the browser to offer overall policy choices to the user.
Most would be "I don't care, do whatever you want to me" but those who do care could have been picky. That would also have allowed the browser to generate reports for the user regarding which sites currently have which permissions, etc. This would have put the onus on the browser implementation to get it right, and not e.g. fail to show the messages, but one could argue that any browser could get the random CSS used for these prompts wrong and not show the message.
I'm a GDPR fan and will likely use this jurisdiction transfer as a ceremonial point to close my FB account for good.
Some companies want to use the web to try to change users behaviour, and many users want those companies to change their behaviour. That’s not a solvable problem, it’s a circular reference bug.
So maybe better tools might actually make it worse, in a race to the bottom sort of situation.
My main concern is that the consent forms, however well meaning they might be, are creating a horrible environment. There are lots of perverse incentives for people to ruin the web experience. Some players stand to gain a lot from a horrible web environment. For example ones that have competing information products.
I’m increasingly thinking it would be better to just not have consent forms, and with better browser tools, people would hopefully go to websites that treated them well.
And just by looking at Google, they are doing that in an increasingly aggressive way.
That would not have been used.
The whole reason why all the consent forms are constantly violating the GDPR is because companies want to make it as hard as possible to say no.
They'd only accept the browser API if the "No to all" button (which by law has to be default, has to be the option chosen if you click anything except yes, and has to be easier to use than "Yes to all") was hidden behind 3 layers of "are you sure", each of which having a 30 second timer before you could continue.
That's the whole reason this consent form disaster exists: because companies are trying to do everything they can go get around the laws.
Just look at the Do Not Track header: it's a legally meaningful statement that companies should follow. They don't.
The EU basically looked at that situation with a competitive browser market, extensions, the existence of the same feature in the past and said, "screw all that, the Commission knows best". Which is exactly the attitude that drove people to vote leave in the first place.
I suspect that this transfer is going to be consent-based to avoid non-compliance in the handful of cases cases where they have inaccurate data regarding location.
Also, agreement (which is only one of the principles which make data processing legal, but I think it is the only one which covers what Google does, using the data for advertising which is not related to the direct service) is voluntarily, that means one cannot be forced to agree by otherwise withholding the service.
Of course the latter point is not fully enforced for now but the EU is set to enforce it over time.
Can the company simply cut you off then?
You have no _right_ to the service, so if you choose not to agree, they can't force you to agree, but are they required to continue offering you the service?
FB surely has a physical office in London, why not make that office the new UK headquarter, and move UK users under, well... UK terms?
If there's no legal requirement for them to operate under UK terms - especially if those are worse than California - why would they?
They can't wait to do this because as soon as either the UK or EU changes their laws (may happen in a month, may not for years), the terms would no longer be valid for one set of users. Facebook would end up in a situation where its terms are invalid for millions of users potentially for months.
EU rules look great, until one of the nations decide to sh*t on it, see Hungary (I'm a Hungarian citizen, but not really proud of it any more) vs EU recently on budgeting, or Ireland being unwilling to actually enforce any EU regulations.
This could be more of a strategic move from Facebook, anticipating the UK government wanting a quick post-Brexit trade deal with the US and having limited practical room to manoeuvre in negotiating one. In particular, the UK government presumably doesn't want to commit political suicide, so it's very unlikely to compromise on issues like the NHS or food standards. That means it needs something else, and probably something big, that it can bring to the table. And that could well be favours for US tech firms that are already here, such as agreeing not to go after them for extra taxes and brushing anything resembling privacy protections under the carpet.
Whether that is a good bet for Facebook to make is a different question. If the Johnson administration doesn't manage to seal a deal very quickly -- and it does have a few other things on its plate right now, not to mention a known-hostile incoming Biden administration across the pond -- then there is a decent chance that any future US-UK trade deal will actually be concluded a few years later. By that time, our respective governments might well be led by Kamala Harris and Keir Starmer, for example, in which case Big Tech might have much bigger worries anyway.
But since no-one has a crystal ball, presumably those tech firms are going to try to insulate themselves from unnecessary risk in the fallout from Brexit, and this move by Facebook probably achieves that at a reasonable cost right now, regardless of what might happen some years later.
hahahahahahahaha.
The ICO has about as many teeth as a newborn baby.
They have actual knowledge of criminality by the adtech industry and they refuse to regulate. They say as much in their most recent annual report!
No, what the ICO does is issue press releases and notices of intent and then either does nothing or backs way the fuck down.
Just look at Marriot, BA, or AIQ for examples of the reality of the enforcement issues being nothing like their initial announcements of enforcement.
Denham is completely incompetent, and her office simply can't get its act together.
Given that the maximum penalty it can levy is £20m, it is completely toothless against any major corporation. BA got off with a slapped wrist after their fiasco. The GDPR looks good on paper but where exactly are these 4% of global turnover fines it was supposed to make happen?
In any case, it makes sense that those maximums would be used only in the most serious cases of wilful violations. I wonder whether internally at the ICO they might be waiting for a chance to make an example of one of the tech giants whose whole business model, unlike the organisations penalised so far, is based on exploiting personal data in questionable ways.
Now Facebook can still easily, with a somewhat straight face, say that this is purely necessitated by Brexit legalities while in reality they're just prepping for the repeal.
FB and Ireland are already fighting over privacy, and the US and UK are negotiating new terms. That may result in changes to UK privacy laws, which FB will be able to take advantage of.
To put it in context, just because EU users look at your site does not mean you need to follow EU laws any more than if China users look at your site or Iran users look at your site. You only need to follow your own jurisdiction's laws, and other countries can act to block your site if they don't like it.
That said, I'm pro-privacy and think there should be better regulation about that in the US.
I think this is possibly a bit naive. Regulations also exist to protect powerful people's businesses, to push personal agendas, and to further political aims even if those are not actually in the interests of any consumers. Also sometimes people think they're making a regulation to protect consumers, but actually it makes things worse.
Case in point: Uber suggesting minimum wage for their workers, some time ago. Think about this, the company refuses to recognize them as their work force but are fine to suggest a minimum wage. As it happens, the minimum wage would put their competition out of business at that time so it must have been seen as favorable for Uber. The competition was not so well funded and so this would be an attrition war at a point in time when Uber was potentially able to win it and wipe all competition out.
This shows that you don't even need corrupt bureaucrats to have regulation steered this or that way by private business.
It's a dumb rule regardless, but please don't blow the costs out of proportion.
Regulatory capture is utterly rampant right now and a huge threat to democracy. This is true regardless of one's personal politics or beliefs about big vs small government or political party of preference. It's a cancer and more dangerous than people think.
Rampant in the US. The EU has managed to avoid the worst of it so far.
They’re easy to spot as news/entertainment all mocks them for being “mean”
There is also the plainspeak people. Law written so that average people can understand them. Lawyers less needed.
Often after a dictator takes power they do a crackdown on ‘corruption’ which has popular support. What their actually doing is consolidating power, but if you call it a corruption crackdown then it sounds like a great thing.
What you want is someone that says something specific not platitudes which can mean anything, and are impossible to hold people accountable. Remove a single regulation and they can call it a win. But fail to go to the moon, build a wall, reduce spending etc, and they just failed.
Simplified tax goals.
Fairtax was a great attempt at this. One tax rate. Everyone got a check so that poor people didn’t suffer.
Millions of tax attorneys and government would need to find something else to do.
But those are the people who are usually focused on removing consumer protections more so than removing regulations based in corruption.
Without laws, the people/groups you mention would just use the law of the jungle - might makes right - to get what they want. At least with laws they have to somewhat accommodate this process to get what they want, frequently compromising along the way.
I'm not saying that all laws are perfect, but let's not get overwhelming cynicism get the best of us.
Might doesn't make right but might writes. (regulations)
The problem isn't the laws or regulations, but the fact that we leave corrupt politicians to write them.
Of course, fixing that is much easier than done, because even if you have a functioning democracy, corrupt politicians are still propped up by propaganda. Corporate's wishing to write the laws contribute much to support those politicians with lobbying and propaganda (Murdoch news empire)
To solve this you need a well-educated, politically conscious population, which is easier said than done.
The less skeptical we are, the more self-serving regulation we'll get.
Apparently he knew all the right senators to get a regulation passed making it so all health companies would be forced to license our software.
Wasn’t technically feasible at the time. Might be now.
Freaked me out as to how evil it was.
We're talking here about the right to get a copy of your own data, the right to be forgotten when you want to leave, the right to be informed about data breaches, and a right to agree to types of data processing.
Your analogy is "you enter a shop and cannot leave again, may be abused, and lose control."
Neither is google
That doesn’t necessarily mean that there aren’t other justifications for any given regulation. But ain’t no small business owner or entrepreneur in history ever said “Boy! All these regulations sure are making my life easy”
Smaller companies have less capital to expend on compliance
It's our work, as a society, to be watchful and try that the game is one that everybody have a chance to enjoy.
You can't do that without rules, in fact you can't have a game without rules. Even private property is just a rule.
2. Of course they further political aims. Anything that has to do with law is political, by definition. This statement makes regulations sound scary and sinister, but actually imparts no information to the discussion.
A world without regulations won't be some libertarian paradise. It'll be an authoritarian dystopia, where the powerful can do what they please, and you will have zero proactive recourse against them, and very limited reactive recourse.
PS. Consider that a rule, or even aversion against regulation is itself a regulation. Which absolutely has side effects[1] that protect powerful businesses, and is pursued for personal and political aims.
[1] Very obvious ones, actually.
I listed two other example purposes in my comment alone! So obviously I don't think this.
> Of course they further political aims.
Did you miss the rest of the sentence? I said specifically ...even if those are not actually in the interests of any consumers.
(Not that any of this matters much these days - companies like Uber demonstrate that you can absolutely run an illegal operation in western countries, and end up with a double-digit billion dollars IPO.)
Elon Musk's emotions certainly dictate a lot of his companies' behavior.
Companies aren't emotionless if they are essentially an extension of an individual.
This is what people want to believe.
But I think you'll find that regulations exist for a large number of reasons, some of which seem noble and others much less so. Frequently, they exist to provide disproportionate protections and perks to the connected.
In the UK we do have very well established "Consumer Law" which is there explicitly to protect the consumer and recognises that they are often not otherwise in a powerful position.
The most relevant stuff for Facebook is the data protection stuff, but another example, relevant to other online transactions, is the Distance Selling Regulations ( https://www.gov.uk/online-and-distance-selling-for-businesse... ). This gives the customer the right to cancel, without a reason, for up to 14 days after the goods are delivered. If the business doesn't explicitly tell you this then your right to cancel is extended to 12 months.
So, when regulations do not work for your advantage as a normal citizen, maybe the problem is not the existence of regulation but the lack of democratic representation and integrity in your government and the bodies it creates and controls.
The best innovations around privacy have come from the desire to prove to users that the company respects your privacy. Regulation has mostly given us fake cookie related banners that have become a spam in themselves.
Don't let Facebook make 7 bucks a month on every user.
I don't think so. The actions behind the words will disappear for sure, but not the message itself
Regulations exist because the government created them. Everything else is secondary.
In effect it's harder and harder to find cases where the 4th amendment protections apply to US citizens, either.
Like do you believe in them or not?
The entire US constitution only applied to the US Federal Government, until the 14th amendment expanded it to state governments and all publicly chartered entities and all entities that accept direct material support from publicly chartered entities which is only noticeable when they interact with the people.
So that would have been over 100 years ago so you might think the point is moot. The reality is that the point is not resolved, never will be completely resolved, and has had less time to be resolved than people may notice.
Protecting those rights for the entire world is a bit out-of-scope.
But what I instead mean is that if the US government interacts with non-citizens outside of its own borders (as it often does), shouldn't it respect the the 'inalienable' rights 'all men' have? That would preclude them from engaging in torture, detention of non-combatants without trial, mass surveillance of foreigners, etc.
What I mean is that it shouldn't matter if a person is a US citizen or not; if the US government is interacting with people, it should respect the rights it believes all people to intrinsically have. Again, that is different than proactively 'bringing' people those freedoms.
Not sure I would go this far, but I do agree with this
> The ICO can fine, but almost certainly won't
But only because one the U.K. leaves the EU, the ICO will struggle to actually enforce its fines when all of the companies involved are notional operating in the EU with little direct presence in the U.K.
Both for competence reasons (see also: the collapse of the AIQ enforcement, and the climb-downs in Mariot and BA cases) and for... I don't know why in the adtech case.
The ICO has evidence of wide-scale criminal behaviour in the adtech industry.
And yet they flat-out refuse to take enforcement action.
They're even proud of the fact they're refusing to do their job - they put it in their annual report!
And even in their non-data protection duties, they've all but given up enforcing the Freedom of Information Act. Statutory timelines are apparently now utterly meaningless. The ICO has even stopped publishing data on compliance levels.
It looks like Denham wants to spend her time as Information Commissioner issuing tough-sounding press releases and threatening (but ultimately flawed) pre-enforcement notices and then using the publicity from those to become a Thought Leader in AI ethics.
So, the UK governments solution is that all these laws will be re-written by the government in one big package and the UK parliament gives more or less an advance approval to that. I am probably not the only one who sees this as a significant weakening of parliamentary democracy in the UK.
GDPR is not an EU directive. Directives are the ones that member states will need to adopt to their own laws. One example would be consumer rights directive. It gives a list of goals, but member states can decide how to archive them.
Regulations, like GDPR, come in effect automatically on the whole EU. One example of these, in addition to GDPR, would be various economic sanctions.
If someone leaves EU, they would still keep all those laws they implemented before but are free to change if they wish by following their own law making procedures. However, they would no longer need to care about any of the regulations (they may need to follow some if they wish to trade with EU). They are free to still adhere to them if they wish. They may need to adopt some laws for them if their national regulation bodies don't have necessary rights to enforce such regulation (as earlier EU regulation would have triumphed national law).
A naïve answer would be: as long as there's a positive ROI. But I guess all the headaches must be taken into account.
Please do.
British users are no longer subject to EU protection come January 1st and we can now be thrown to the wolves, courtesy the wisdom of our Brexiteer chums.
GDPR is fully incorporated into British law so can you clarify what you mean by this? Do you mean that the EU regulator has more teeth than its UK equivalent? Both seem to be equally useless in fact.
I don't buy the equivalence in toothlessness either - the EU seems to have a willingness to take on big tech overreach in a way UK Gov has neither the capability or willpower going by past performance.
Well, you will see what happens to these laws.
The whole Brexit enterprise is mainly an attempt to do maximum de-regulation. The discussions about food safety standards and health care service and its financiation are pretty good indicators what will follow in other areas.
> Facebook’s UK users will remain subject to UK privacy law, which for now tracks the European Union’s General Data Protection Regulation (GDPR)
My understanding is similar to this, which is that all the privacy laws are the same, so is this a Brexit thing because the UK is outside of the EU so it's a legal liability to hold information within the EU (Facebook Ireland as it says)?
So while this might "avoid" EU privacy rules in some stretched interpretation of "avoid", in fact it will be avoiding them by applying an identical set of rules. That is, unless the UK government changes its data protection legislation at some point, which is another kettle of fish.
They've given a vague statement to defend this being necessary — "Like other companies, Facebook has had to make changes to respond to Brexit" — even though Reuters point out Twitter as an example of a company _not_ making a change like this.
Also, Facebook haven't explicitly said that they won't treat data differently to EU citizens, but that "There will be no change to the privacy controls or the services Facebook offers to people in the UK", which is subtly different.
To give one example, the European Data Protection Board (EDPB) has no authority to bind the ICO.
The recent fin of Twitter by the Irish DPO was subject to that mechanism (Ireland tried to fine Twitter, the EDPB said the fine was too low and it was increased).
So, transferring your data between the EU and UK will mean you are (now) crossing a data border. That's a change.
I understand that GDPR will immediately split into EU GDPR, and UK GDPR.
Something I've seen in lots of UK law derived from EU directives is that it applies limits to behaviour specifically happening in the EU. So UK privacy law might provide a whole load of protections to EU citizens, but not specifically to UK citizens, because EU citizens would be a superset including UK citizen. Except, as of 1st Jan 2021, that won't be true any more.
Even without that, it doesn't make sense for Facebook companies to store the UK data in the EU/Ireland, where it would presumably then have to comply with both EU GDPR and UK GDPR.
> There will be no change to the privacy controls or the services Facebook offers to people in the UK
> Facebook’s UK users will remain subject to UK privacy law, which for now tracks the European Union’s General Data Protection Regulation (GDPR).
Presumably this move in preparation for when that stops being the case.
The UK's position is strange because of Brexit, but it seems the practical position of all recent governments has been that existing EU laws should be transposed into UK national laws where necessary and with the required changes to make sense, until such time as our national authorities might decide to deviate from them. Primary legislation has already been made to that effect. The big question is what "that effect" actually is, given the huge volume of legislation affected and the potential ambiguity in what changes are required for any given law of EU origin to continue to make sense in a post-Brexit UK.
Naturally there's a cost to all things: developers need to eat; they need a work/life balance.
Unless there's financial backing for a concept or project it will have a hard time getting off the ground.
And unless there's some corporate interest in what's being worked on it simply won't be written.
The best hope is open-source outreach not as benevolence, but as part of a large company's recruitment policy.
One thing I'd like to see is Microsoft licensing Firefox's backend, and allowing the user to chose which engine to use.
Chromium might have some major advantages, but user privacy (and ultimately experience) will never be a part of it - we need to stop relying on corporations that have intentions that are ultimately adversarial to the end user.
Will that ever happen? Fuck no - Microsoft already bundles adware into their $300 operating system.
At the moment there aren't really any significant contradictory laws/regulations I am aware of. Facebook could just choose to treat everyone as if they were protected by EU laws, but they choose not to. They didn't have to change how they relate to UK users, but they legally could and they chose to.
Facebook/Twitter will be turned into a protocol within 10 years that anyone can use. Permissionless systems like the internet always win over centralized systems over time. Big tech will eventually be remembered the same way as we remember AOL.
The future is bright and I'm fairly optimistic. I will enjoy living in a post-nation state driven world where humanity works together as a whole towards our common goals.
And in fact on an EU level, rules are unified instead of balkanized. The digital single market project brought things like the GDPR or the abolishment of EU roaming charges, allowing you to travel around the EU without having to pay extra to your phone provider.
First they gave our FB data to the americans, next they went for our NHS! :)
ps1: I don't use FB ps2: I got nothing against the americans (apart from their eating habits and love for guns) ps3: there is a post-Brexit feast coming, and it won't be the People enjoying the main course(s).
That's better than a race to the bottom, e.g.
> Pick the jurisdiction(s) are most biased towards your selfish interest for your shareholders, tell the rest of the world to quit whining and deal with it. They either they can play ball or opt of of modern society.
The move is because the UK is leaving the EU so the EU rules no longer apply to UK users.
I don't see any reason they cannot do that. It will hurt their bottom line for sure, but it's completely reasonable imo.
Nothing really changes for the rest of the web. You're allowed to stand up your own webserver if you want.
How does that help when you have countries like the US that enforce extra-territorial laws?
Nothing new in that. Different jurisdictions have always had different legislation, both online and offline. For a while, when the internet corporations were small, and most business and life interests were still offline, internet companies flew under the radar. The last 10-15 years, though, larger jurisdictions have very much asserted their influence online.
Whereas some Brits don't care about privacy protection, many do. The British likely already have or will get their own privacy laws after Brexit, but it remains to be seen whether large corporations like facebook will respect those.
When Britain was inside the EU, facebook risked billion euro fines. Outside of the EU, the risk of ignoring the rules is smaller.
The latest move from facebook shows that they believe British users are now fair game. They can prey on them the same way they prey on Californian users.
It's not soon over. It has been over for many years now.
I'd explain more but this content is not available in your country.
All this is is the reining in of a few greedy corporations that offer information-sharing platforms in exchange for exploitation. New communities will pop up, and old ones resurface.
Got a popular page on Facebook? pay for it to be seen. Got a great unique website? Pay to be seen via Adwords.
Website owners don't link so liberally as they once did because the link graph has been obliterated by "what people think will please Google" rather than linking to things they think other people might like to see.
When I used FB I lost count of the number of times I had to re-jig my setting for displaying content from "most popular" (according to them) versus most recent.
I still find that when I'm browsing Facebook. I see an article with XXXX number of comments and try to see what's newly been said, it's almost impossible- it's like I'm fighting against what new information is available vs their preferred method of displaying things due to the technical limitations of how they store information.
Here's something I've always wondered: I don't really get this obsession with maximizing the number of people who go to one's web page. If you're just a regular person who's not profiting from ads or something, it shouldn't matter.
If I post something to the internet, I maybe send it to a few people who might want to see it and that's it. I don't care about collecting pageviews, or likes, or follows, or upvotes, or any of these vanity metrics. It doesn't really matter to me if something I wrote was viewed by 10 people, 1000 people, or 100,000 people. Who cares? What difference does it make? My life is not richer because thousands of random people read some blog post or forum comment.
The only reason I can see to promote some creative work is if you're making a profit off of it. In that case, it's an investment. Spend $X on discovery and make $Y in revenue from ads or conversions or whatever. But just to put up some web site about your stamp collection? Who cares how many people visit?
Comments.
Comments are the final frontier. Why do you think I never bother getting a personal blog website off the ground? Because the traffic it gets pales in comparison to the audience I get from writing comments. This comment for instance might be seen by several hundred people, all within my target demographic. How many people might see my longform blog content? Maybe dozens if I'm lucky. I've never really written a meaningful blog post, but I've probably written a novel's worth of comments.
And because comments aren't really written for monetary gains, they are one of purest forms of writing left on the internet today. People still write comments liberally and openly, speaking their mind and even voicing unpopular opinions, because they don't give a shit about what Google thinks. Google doesn't read comments. Say the quiet parts loudly.
Maybe someday there will be an age where you can be certain almost every comment you read is already bought and paid for by some corporate interest or a guerrilla advertiser, but fortunately we are still not there yet.
And if you stop paying Facebook will severely limit any organic traffic to your page. That should be illegal, unfortunately it is not being viewed as something serious, meanwhile Facebook gets showered with billions extracted out of small businesses.
Has nothing to do with technical limitations and everything with engagement metrics. Facebook does not want to show you what you want to see, they want to show you what will hook you and keep you in the platform. If anything, it takes more resources to show their view than just a time posted order.
I don’t believe that is what the platform is doing. It is displaying content the user will most likely interact with, resulting in the user staying on the platform longer. It seems quite dangerous to me, as it could cause users to assign some sort of weight to the content, particularly if the content is well liked by others it could lead to the belief that ‘this is the correct information’.
On the other hand it can be too easy for too many people to be seen: spam.
Which makes you wish for more curated and controlled platforms.
And that’s why we have moderators and upvotes and downvotes.
Do you think it was easier in the age before the internet to be gain an audience?
This has always been my own reaction to pronouncements that the Internet as we knew it is dead, or over.
I'm usually quite optimistic about our ability to freely (and usually without monetary cost) create and share, globally.
However, the closure of Nekochan (an old fashioned web forum dedicated to SGI hardware and the IRIX OS) has changed my mind a little bit. The owner of that site became convinced that it was literally impossible to run a forum website and maintain GDPR compliance. He believed that it introduced infinite liability and would require constant purging of data based on requests that could come at any time into the infinite future.
I'm paraphrasing, of course, and I was not actively using the site when it shut down, but it was one of my favorite spots online and a source of priceless information and richness.
And now it's gone ...
I would quite like my data to stay in the UK, where national governments I don't elect or pay taxes to, can't touch it.
I believe strongly that the social media and internet ad business models are at best amoral but responsible for the second order effects, much as coal plants are responsible for pollution. At worst they are making money off of making people crazy by giving every crazy person a megaphone and making sure you have to hear from them.
I'm assuming that Scotland would not want any part of this, that's why I'm not including it.
* The UK is the "United Kingdom of Great Britain and Northern Ireland". Great Britain is the largest island in its archipelago (the British Isles); Northern Ireland is a region situated on the island of Ireland (another island in that archipelago).
* Another region of the island of Ireland is (the bulk of) the sovereign state the Republic of Ireland, a country which is part of the EU. The Republic of Ireland is the country where many companies headquarter in the EU for tax efficiency.
* Alongside Northern Ireland, the other three countries which make up the UK are England, Wales, and Scotland. Those three countries are all primarily located on Great Britain. Some other islands in the archipelago are not part of the UK at all (e.g. the Isle of Man); some other islands in the archipelago are part of one of England, Wales, Scotland, or Northern Ireland.
To confuse the island of Ireland with the United Kingdom, or to identify the Republic of Ireland as part of the UK, is deeply offensive to some (many?) Irish people. It is also a sore point to certain people across the island of Ireland that Northern Ireland is part of the UK, and that the island of Ireland is not a unified state.
Confusingly enough, citizens of the UK are almost always referred to as "British citizens" whatever their relation to the island of Great Britain; this is a strange piece of terminology because if "British" here means "Great British" then it appears to exclude Northern Ireland, while if it means "of the British archipelago" then it appears to include (for example) the Republic of Ireland.
(the Republic of) Ireland is not part of the UK, and remains in the EU.
This is about end user licence/privacy/terms agreements, not corporate taxation.