If this was some random small company you could imagine that the regulators have bigger fish to fry, but in this case this is the #1 offender worldwide when it comes to privacy - if there are "fish to fry", this is the biggest fish, and the regulator's lack of serious action (such as the million-dollar fines everyone is fear-mongering about) suggests they're either incompetent or complicit.
Maybe suing your local privacy regulator in local court is the next step? Open Rights Group is taking that approach in the UK: https://www.openrightsgroup.org/press-releases/privacy-organ...
Ban it. It's the only way.
Why not, out of curiosity? We don't make this distinction for low-income folks who get parking tickets. If you don't make them truly punitive why comply? It just gets factored into the cost of doing business.
But fines and tickets being pegged to income is a good idea. Fixed amounts for fines are really expensive if you don’t make much money. Similarly, they aren’t much of a deterrent if they are a small amount of your income.
Facebook has a distinctly high profit ratio (2020 Facebook revenue was $85 billion, net income $29 billion), so 4% of revenue means a lot less to Facebook than other companies that GDPR restrains. 4% of their revenue is $3.4 billion which is 11% of their net income.
And the potential negative impact of Facebook's negligence in data handling is distinctly greater than other companies, Facebook collects far more data than most other companies and has access to far more personal data. They have somehow managed to convince a huge portion of the world's population to share a significant tap of data into their lives.
Another venue is to go directly after Facebooks European customers and make it illegal for any company to pay Facebook for ads targeting European customers.
In the end this would force Facebook to abandon Europe and lead to local competitors taking over that market weakening Facebooks network effects in non-US markets.
this is an escalation and delaying game and so far facebook is banking on some political saving grace that probably wont come as well privacy is considered an human rights by European courts and not something an simple short term political majority can simply erase because it's convenient for some US megacorp.
If the showdown happens in the highly independent German court system, i just don't see how American political pressure is going to stop the slow but steady path of escalating measures likely to be taken if Facebook refuses to comply with court rulings.
The US needs to implement an equivalent privacy law.
They'd have to close everything in the EU. I can't imagine the rest of the EU would be fine with it.
And that's probably more than Facebook is willing to do - it would mean no advertising in the EU.
Of course, they could defy that order as well and hope that their assets are safe elsewhere in the world. Or, you know. their executives have seen enough of Rome and Paris.
Facebook violates China's content policies. As a result, China blocks Facebook.
Likewise, the EU is welcome to set up a firewall and do the same. Facebook isn't obligated to do anything other than cease operation of local offices.
The EU actually has a huge leverage to push things, it just chooses not to exercise that power most of the time.
The RCEP isn't an internal market. In its ideal outcome it's a partial trade agreement, not all-inclusive. In its present condition, given relations between its members keeps getting worse, it's barely a functioning trade agreement at all. The odds are overwhelming it'll rip apart, and soon. See: China vs Australia & Co.
https://web.archive.org/web/20200813235643/http://slawsonand...
> Article 3(2), a new feature of the GDPR, creates extraterritorial jurisdiction over companies that have nothing but an internet presence in the EU and offer goods or services to EU residents[1]. While the GDPR requires these companies[2] to follow its data processing rules, it leaves the question of enforcement unanswered. Regulations that cannot be enforced do little to protect the personal data of EU citizens.
> This article discusses how U.S. law affects the enforcement of Article 3(2). In reality, enforcing the GDPR on U.S. companies may be almost impossible. First, the U.S. prohibits enforcing of foreign-country fines. Thus, the EU enforcement power of fines for noncompliance is negligible. Second, enforcing the GDPR through the designated representative can be easily circumvented. Finally, a private lawsuit brought by in the EU may be impossible to enforce under U.S. law.
[snip]
> Currently, there is a hole in the GDPR wall that protects European Union personal data. Even with extraterritorial jurisdiction over U.S. companies with only an internet presence in the EU, the GDPR gives little in the way of tools to enforce it. Fines from supervisory authorities would be stopped by the prohibition on enforcing foreign fines. The company can evade enforcement through a representative simply by not designating one. Finally, private actions may be stalled on issues of personal jurisdiction. If a U.S. company completely disregards the GDPR while targeting customers in the EU, it can use the personal data of EU citizens without much fear of the consequences. While the extraterritorial jurisdiction created by Article 3(2) may have seemed like a good way to solve the problem of foreign companies who do not have a physical presence in the EU, it turns out to be practically useless.
I mean what are they going to do, invade Silicon Valley with their armed forces? It's not really enforceable. They can set up a firewall if they like and censor Facebook, that's the most they can do.
And hee hee, the freedom-loving EU citizens will riot if they try to censor the internet, we all know that :)
Checkmate, GDPR is not enforceable.
The real way to solve the problem is the US should implement its own privacy laws, and preferably better ones than requiring some stupid annoying cookie popups.