Record €225m fine for WhatsApp Ireland over data protection breaches
rte.ie
rte.ie
> However, WhatsApp Ireland, which had previously set aside €77.5m for a possible fine
Right there. The cost of violations is priced in. Companies actually misbehave and simply accept a potential fine as a business expense.
> The company is also understood to feel that the fine is out of step with previous GDPR related fines.
It just sucks for our shareholders if the fine is higher than we expected.
> Sources close to the company, which is owned by Facebook, said rather than making its policy shorter and less complicated, the decision would mean it would have to add even more information to its already long and complicated privacy policy.
The lies, incredible. Just don’t collect data, then your privacy statement is very very simple. Only complicated agreements require complicated 5,000 word privacy declarations.
If it was designed to protect privacy, it is very clearly failing to achieve that objective.
I agree that it could be more effective and I would welcome more effective policy in regard to data collection/processing and its transparency.
It helps, of course, that they don't have domestic internet mammoths putting money in their pockets to get away with whatever they want (USA) or a state sponsored big brother / AI yoke programme that depends on data being collected from all around the world (China _and_ USA).
If anything, the EU is trying to prevent external (and increasingly hostile) powers to use EU citizens data for gain or plain aggression (Cambridge Analytica & Brexit, for example).
Well that’s the political pitch. But there’s not a shred of actual evidence to support the claim that the EU cares about privacy at all.
https://www.eff.org/deeplinks/2020/10/orders-top-eus-timetab...
https://www.ejiltalk.org/a-dangerous-convergence-the-inevita...
The only thing it regulates is industries that the EU has failed to become competitive in.
But instead you have administration that wants to ban encryption and increase surveillance as much as possible. The idea that the EU cares about privacy has no credibility at all.
I have a suspicion you're talking from a USA standpoint, where antitrust is enforced based on provable harm. This is not necessarily the set of values that the EU population wants to live by.
The Dieselgate was already deemed illegal, making your remark a case of whataboutism.
You think there's some >$225M benefit not adding a few extra lines to the terms of service or adding another annoying prompt?
If WhatsApp gains knowledge of an impending fine (exact amount might yet be unknown) that is to be paid at some point in the future, they have to earmark money to cover that liability.
Say you find rot in your roof, so you immediately set aside $X to pay for a roof replacement, since you now know that soon this cost will be incurred. Doing says nothing about your stance on preventative maintenance. This is similar, it's just accounting. They reserved money for the fine when the complaint was lodged since they knew they likely were going to incur some cost.
You can argue whether the violation was intentional or not, but setting aside money to pay a fine after you have been found guilty is not a signal that they intentionally broke the law.
As an aside, I think accounting for anticipated fines is required by the regulations. So at least they were following those regulations! Talk about irony, lol.
I don't get the point of this. Should Facebook not set aside an amount for likely litigation? The fact is that these regulations are very vague and regulatory authorities have a lot of discretion. Notice that the article simply says Whats app failed to provide "transparency of information provided to users about the processing of their data between WhatsApp and other Facebook companies." Imagine being in a company and your task is to prevent this sort of thing. What does this mean? I'm sure its in the disclaimer, terms of service and a number of other places. But it's not enough apparently.
And there's a huge financial incentive for these bodies to go after large companies. In the US a lot of the fine goes back to the prosecuting body.
For instance, in 2013 JP Morgan paid a $13 billion settlements, $7bn of which was distributed to various government authorities, including the prosecuting agencies.
https://dealbook.nytimes.com/2013/11/20/where-does-jpmorgans...
Even if it was security, which it isnt, they would still have to 'invest money' to comply post being sued. So they save the invesment, get sued for 255mil and have to spend the money anyway.
I find it unlikely that when they skimped on the t's and c's writing they 'saved' themselves 255milion in lawyer time? Whats that, say 51,000 lawyer hours billing out at 5k an hour? So 100 high priced lawyers billing 100 hours a week for an entire year to write the t's and c's?
Facebook should have done the right thing from the start. The conditons were clear.
> The regulator has also ordered the messaging service to bring its processing into compliance by taking a range of specified remedial actions.
Now users also have to spend tax money on litigation. Fines need to be harder.
https://edpb.europa.eu/our-work-tools/our-documents/binding-...
That's rarely the case in the EU, though.
Fines are never directly going back to the prosecuting body in the EU and damages are strictly limited to compensatory. Fines just go back to the general budget. I think that's why the EU is generally a lot less litigious than the USA.
The official ToS themselves actually don't contain any information about their data collection, it's basically just a link to their privacy guidelines. Those privacy guidelines, in summary, just say "we collect information about how you use WhatsApp so we can improve our services". No word about what information they collect exactly, in what ways it is processed and linked with other data, what kind of meta-information they extract from it, nothing.
The GDPR is only vague for organisations that go as close to the edge of legality as possible.
https://www.whatsapp.com/legal/privacy-policy
> Information We Collect
> WhatsApp must receive or collect some information to operate, provide, improve, understand, customize, support, and market our Services, including when you install, access, or use our Services... The types of information we receive and collect depend on how you use our Services...
> Our Services have optional features which, if used by you, require us to collect additional information to provide such features. You will be notified of such collection, as appropriate...
> Information You Provide
> Your Account Information... Your Messages... Media Forwarding... Your connections... Status Information... Transactions and Payments Data
> Automatically Collected Information: Usage And Log Information... Device And Connection Information... Location Information...Cookies.
Yes, but that would have been against this complaint when it arose - So in 2018 when the action started they took a look and figured they would have to pay a fine, accounted for it appropriately. They will now allocate the remainder of the amount, continue to appeal and maybe in another 3 years finally make payment on that fine.
Your comment suggests that they have a slush fund and try and break enough laws each year deliberately so they can spend the $77.5 budget they have for fines.
I am not a lawyer or accountant, but a public company not reporting a contingent liability for litigation in progress in their accounts would probably be a violation of all sorts of things.
Similar to a reserve for doubtful accounts receivable. X% of receivables aged 90 days past due are unlikely to ever be collected. That gets booked onto the financials.
And if they want to run a free messaging service supported by advertising, there's plenty of ways to do that which are in compliance with the GDPR. For example, they could start by being really clear about what data is collected in their privacy policy and for what purposes. They could stop collecting data and just have worse advertising targeting. And so on.
But instead of any of that, they're actively choosing to break the law and now crying foul when the government takes them to task over it. Boo hoo. European countries have the right to make laws protecting their own citizens' data. Facebook isn't a country unto itself.
That is an inference that you should not make. The set aside of €77.5m was for this case, which has gone on for some time. [1]
[1] https://www.irishtimes.com/business/technology/whatsapp-irel...
Of course, in most rulings it's a fine in addition to the company changing their ways; it's not like the fine means they can keep doing that which they were fined for.
Really sucks for the shareholders that Facebook is giving away their profit for no good reason other than arrogance. I'm sure they'd rather see dividends than this drain on their profits. That's the one job shareholders have: worry about stuff like that.
> Right there. The cost of violations is priced in. Companies actually misbehave and simply accept a potential fine as a business expense.
this is standard procedure, nothing special. all companies, large or small, set aside funds for possible fines when facing an investigation.
You can consult the EDPB decision on that matter here: https://edpb.europa.eu/our-work-tools/our-documents/binding-...
EDIT: Max Schrems' reaction (NOYB):
>"We welcome the first decision by the Irish regulator. However, the DPC gets about ten thousand complaints per year since 2018 and this is the first major fine. The DPC also proposed an initial € 50 million fine and was forced by the other European data protection authorities to move towards € 225 million, which is still only 0.08% of the turnover of the Facebook Group. The GDPR foresees fines of up to 4% of the turnover. This shows how the DPC is still extremely dysfunctional."
source: https://noyb.eu/en/statement-dpc-issues-eu-225-million-fine-...
Hopefully this will motivate the DPC to be a little more active in the future (nobody likes to be wrong, especially wrong in public).
Some DPA are unwilling to act, the best thing to make them is to file complaint or support organisations that do (see the comment on NOYB). They are bound by laws to act, let's make them !
Brexit in no way breaches the GFA. Threatening a return to violence in Ireland over Brexit is what I mean by "making things difficult".
The Troubles were not about sausage shipments between Belfast and Dublin.
:)
In fact, they signed up for exactly that not even 2 years ago.
It seems, though, that they were just kicking the can down the road and never really had intentions to live up to their side of the deal.
Global Britain! Yeah, right...
> Threatening a return to violence in Ireland over Brexit is what I mean by "making things difficult".
Recognizing that putting in jeopardy an international agreement that brought an end to the troubles might incite violence, is not the same thing as threatening violence. It's common sense.
> The Troubles were not about sausage shipments between Belfast and Dublin.
You're right, they were an ethno-nationalist conflict, during which the British government sanctioned the murder of its own citizens, and now continues to protect those murderers from prosecution.
Bit early for the drink, no?
Can you point to the line or lines in the GFA which would have been breached by Brexit?
https://en.wikipedia.org/wiki/Brexit_and_the_Irish_border#Go...
I asked for a reference in the GFA, you've provided a Wikipedia link. Fantasy stuff in the HN comment threads as usual.
I suppose I should have expected it when you blamed the EU for the self-inflicted woes of Brexit.
> If you can't see why an open border is vital for the continued peace, and why removing it would place tension on a peace that took decades to achieve, then you've already made up your mind.
I didn't say that, and I'm not even going to engage your straw man.
And I did not blame the EU for Brexit woes, I made a pretty basic statement of fact that would probably cover any negotiation, one which was intended only to signal compromise -- hence why the UK did not leave entirely -- not woe or blame.
The UK also doesn't want a border between Ireland and Northern Ireland but that's stricly an issue between the Republic of Ireland and the UK. Obviously as Ireland is a member and the EU is a constructive and diplomatically open entity, it was more than ready to negociate. Actually, multiple solutions have been proposed and at least one was tentivaly accepted before being reneged by the UK government.
I mean at some point in a negociation if the weak party can't come to its sense, you have to stop wasting everyone's time and tell them to get lost which is more or less what's happening with the UK.
The UK is a third country and no more an EU member.
Leaving is very simple if you're willing to face the consequences.
And this is the true problem of the UKs exit. That they're neither willing to face the truth nor the fact that's it a third country now with all restrictions that come with that status.
Ireland, as far as I know, is not part of the UK. While Northern Ireland, Wales, Scotland and England are all out.
Which part of the UK is still in the EU?
(Honestly curious)
I didn't consider NEs current status.
This will open another can of worms, when some of the exceptions run out by the end of September.
You should also take note of my comment below - there is no "they" wrt the UK, as the country was divided, and actively fighting over the issue - with some actively trying to prevent a brexit.
I'm not suggesting that at all. Actually I think that it was enormous stupidity to send that letter before England even defined what it wanted exactly.
It didn't help at all that Ms. May tried to appease the Brexit extremists in the conservative party. People that, as we now know , cannot be appeased, ever, since they just move the goal post to an even more extreme position.
> You should also take note of my comment below - there is no "they" wrt the UK, as the country was divided, and actively fighting over the issue - with some actively trying to prevent a brexit.
I appreciate that. Nevertheless 52% of people that bothered to vote wanted out.
Pissing off their European partners at every turn also certainly doesn't help
Unless Britain gives up it's extremist position I predict a world of hurt once the EU is no more willing to kick the can further down the road.
Long queues at immigration, when vacationing in Spain will be the least of your worries.
b. The Hungarian SA raised an objection on 21 January 2021;
c. The Dutch SA raised an objection on 21 January 2021;
d. The Polish SA raised an objection on 22 January 2021;
e. The French SA raised an objection on 22 January 2021;
f. The Italian SA raised an objection on 22 January 2021;
g. The Baden-Wurttemberg SA raised an objection on 22 January 2021; and
h. The Portuguese SA raised an objection on 22 January 2021
As for undermining regulations, the EU has procedures for ensuring member states enact compliant legislation, and after that the country has its own legal system, not more corrupt than average. It might be that they're applying the law as they understand it and that the judiciary has some independence from commercial interests.
You're welcome to make the case otherwise, but making accusations as you've done isn't what I'd consider constructive dialogue.
Honestly, I'm not sure that the time to prove Ireland tax heaven will be that tough. Of course, the EU does not designate Ireland as a tax heaven, but you should have to keep in mind that Ireland is a member state of the EU and the tax heaven list is approved with unanimous vote which might be a cause for a conflict of interests.
The fine related to 'state aid' in the form of advice to Apple, and was appealed as the Exchequer makes far more money from Apple and other big tech then this fine would ever cover.
Have a look at the effective tax rates between Ireland and France if you want an eye opener
As for being a tax haven, this is something that is said by others who are outside of the Irish tax system and only look at the low corporate tax (they fail to see they other hidden taxes businesses have to pay like water tax, bin tax etc). Im not suggesting that the companies are fully "paying their way" but that it is too simplistic to only look at 1 tax requirement.
If you have worked in Ireland you would understand that the Irish tax system is extremely complex.....as employee you could pay tax in 3 separate income tax calculations, then a "bank bailout tax" that has remained even though the banks were bailed out. It is not uncommon for middle / high income workers to pay approx. 50% of their wage in deductions. Similarly if you tried to set up a company you would understand that the rules are not black and white but rather "you apply this tax calculation on a Friday, if the moon is full and the grass is blowing to the west"
It's that corporate profits can be artificially shifted there and are then not or barely taxed.
Just read the wikipedia article please:
> Ireland ranks in all non-political "tax haven lists" going back to the first lists in 1994,[n][30] and features in all "proxy tests" for tax havens and "quantitative measures" of tax havens. The level of base erosion and profit shifting (BEPS) by U.S. multinationals in Ireland is so large,[4] that in 2017 the Central Bank of Ireland abandoned GDP/GNP as a statistic to replace it with Modified gross national income (GNI*).[104][105] Economists note that Ireland's distorted GDP is now distorting the EU's aggregate GDP,[106] and has artificially inflated the trade-deficit between the EU and the US.
> Ireland's base erosion and profit shifting (BEPS) tools give some foreign corporates Effective tax rates of 0% to 2.5% on global profits re-routed to Ireland via their tax treaty network.
Do you really think like this?
https://www.nytimes.com/2021/07/08/business/ireland-minimum-...
Here's a recent story from the meeting between the Irish and French leaders. The differing view on taxation is clearly there (though it's more that we're worried about a mandated EU premium on top of it, not that we're against a global minimum). But on every other key issue the French openly say we're working closely together. https://www.irishtimes.com/news/politics/differences-over-co...
That's a fair distance from 'undermining every EU regulation'.
> The objection raises that not all computationally possible numbers are indeed assigned. Therefore, the lossy hash refers not to at least 16 numbers but to a maximum of 16 numbers. Furthermore, if additional data is stored along with the lossy hash, the number of individuals represented by the associated phone numbers can be reduced as data subjects not matching this additional data can be excluded. If e.g., so the DE SA, the gender is also stored, it is possible to at least divide these 16 in half.
So their hashcodes can be mapped to 16 different users, which can be trivially reduced to a single person if you have any additional information about them.
They stated to the merger review committee that the WhatsApp takeover couldn't feasably lead to data sharing with Facebook. And got fined 110m EUR for that, a pittance. You couldn't take out an insurance policy against a successful merger for that money. From [0]:
"When Facebook notified the acquisition of WhatsApp in 2014, it informed the Commission that it would be unable to establish reliable automated matching between Facebook users' accounts and WhatsApp users' accounts. It stated this both in the notification form and in a reply to a request of information from the Commission."
Edit: typo
[0] https://ec.europa.eu/commission/presscorner/detail/en/IP_17_...
As EU citizen, I am more than happy to support them through membership, and I urge any fellow citizen who is interested in privacy issues, to inform themselves over nyob, and support them!
[0]: https://noyb.eu/en [1]: https://noyb.eu/en/data-voodoo-credit-ranking-agency-crif-cr...
I hope so too. It's something that's been on my mind in general terms - it feels like all organizations (both for- and nonprofit) decay over time, eventually becoming corrupt. I'm not sure there's a cure for this. So we can either never support any organization, or support them while they're still pristine, stop when they go bad, and hope someone else will appear to carry the torch. Not supporting is the easy choice, but you can't build a civilization that way.
So I guess vigilance is the name of the game. I'm gonna support noyb until they go bad.
Furthermore, at this point I'm having two questions about it:
1. The notice clearly said that if I didn't accept I wouldn't be able to continue to use WhatsApp after some date in the past (I don't remember it exactly). This is clearly not true. Wouldn't this fact be grounds for invalidation of all consents they gathered before?
2. At this point I must have declined accepting at least 100 times. Shouldn't it be required to have a "no, never" option in there? In its absence, shouldn't I be able to make the case that the one time I click on "agree" it was by mistake? How is this method of agreement valid whatsoever?
> Additional Information On How We Handle Your Data. Our updated Terms and Privacy Policy provide more information on how we process your data, and our commitment to privacy.
How nice! However, this is specifically targeted at GDPR-covered users. GDPR won't allow them to do anything that is not explained (and hence "consented" to by the user).
To me, the logical conclusion is that their lawyers went "we can't do XXX, YYY, ZZZ unless we explain them explicitly". Then their marketing team spun it up as "look at how nice we are".
The reality is that they wouldn't explain shit unless they absolutely need to. Since they didn't explain before, I'm pretty sure there are things they can't (legally) do with my information under the previous agreement that they would be able to (legally) do with the new one.
But I discovered my SO is doing as well, not because she really cares, but because she is used to dismissing any popup she sees - I am curious how many people haven't accepted yet just because they have a muscle memory to close pop-ups that get in their way
It's amazing what we can habituate with little or no annoyance.
> It is the largest fine ever imposed by the DPC and the second largest penalty ever levied on an organisation under EU data laws
The more interesting question is what the impact will be. Based on the article, it might be just changes to a privacy policy that no normal human will read anyway:
> It is understood that WhatsApp believes the fine is not about its data sharing practices but the level of detail provided in its 2018 privacy policy.
It's a nuisance because now some schmuck has to come up with a way to bypass these issues while maintained the same operation.
These fines won't cripple a company, it will just allow them to test what limits they can push and so on.
Jerry: How is it a write-off?
Kramer: They just write it off.
Jerry: Write it off what?
Kramer: Jerry, all these big companies, they write off everything.
Jerry: You don't even know what a write-off is.
Kramer: Do you?
Jerry: No, I don't.
Kramer: But they do. And they're the ones writing it off.
Now that share holders are aware of it that can only go on for so long before they'll have to find cheaper toilet paper.
Deliberately misunderstanding here, but I think it adds to the discussion.
Or are many of these headlines just a pay day for lawyers?
In order to have any deterrence effect, any fine should probably be at least 20 times higher. Otherwise, it is almost always better for those large companies to violate the law, reap profits, pay the fine and benefit from their disregard of the law.
This is a first fine, and note that the original article states that both FB and Instagram are under investigation also, so it could easily be 3x this current fine, which is not insignificant, even for Facebook.
It makes it much easier to accept all cookies than to reject, without any good technical reason to do so, and presents the "accept all" as the default choice.
This is irrelevant
It's a clear demonstration to FAANG and others that nine-digit fines are on the table even in Ireland - the country that tech corporations love the most because of tax advantages, the country long criticized for pandering to said corporations instead of fulfilling their data protection obligations.