Embedded social media posts might now be illegal
maya.land
maya.land
Compliant sites show some placeholder in gray typically with appropriate warnings. If the reader wants to reveal the element they need to click first.
Disclaimer: Not a web developer, not living in Germany, but German as a mother tongue.
You can embed social media.
What you can't do is embed a social media post without disclosing in the cookie notice (that must be approved beforehand) what will happen to the user due to you doing it.
The GDPR absolutely requires opt-in before setting cookies (or collecting user data in other ways, it isn't specific to cookies even) so the embeds would be in breach. Whether it's the responsibility of the parent website or the embedded element to ask for consent is another matter.
Could these laws that are increasingly unfriendly to the cooperation that the internet enables slow down innovation and make it too risky to invest in many kind of online services?
Is it realistic to think that one day in the near future we will get some kind of global law governing these things, and if not what other options are there to resolve these issues?
Since then there have been various problematic claims at universal jurisdiction, especially relating to money and gambling (poker sites serving the US, crypto regulation in general).
The situation remains .. stable, but fragmented around the edges. There's going to be a slow tick over of cases like this. I don't think it will affect investment, the "break the law and hope you become big enough to make a political win later" approach of Uber and AirBnB has become popular.
Global law is unlikely unless it's set by the US, and the US terms on privacy (very loose except for finances which are subject to total surveillance) is not in sync with the rest of the world.
"The GDPR applies to companies outside the EU because it is extra-territorial in scope. Specifically, the law is designed not so much to regulate businesses as it is to protect the data subjects’ rights. A “data subject” is any person in the EU, including citizens, residents, and even, perhaps, visitors.
What this means in practice is that if you collect any personal data of people in the EU, you are required to comply with the GDPR. The data could be in the form of email addresses in a marketing list or the IP addresses of those who visit your website. (See our article explaining what is considered personal data under the GDPR.)
You may be wondering how the European Union will enforce a law in territory it does not control. The fact is, foreign governments help other countries enforce their laws through mutual assistance treaties and other mechanisms all the time. GDPR Article 50 addresses this question directly. So far, the EU’s reach has not been tested, but no doubt data protection authorities are exploring their options on a case-by-case basis." - https://gdpr.eu/compliance-checklist-us-companies/
For enforcement to have teeth outside their jurisdiction don't they either need assets or revenue streams in the EU which can be confiscated/leveraged, or else good old fashioned extradition treaties? And don't the latter typically require said crime to be illegal in both jurisdictions?
"In theory it could be that the EDPB could place embargoes, on sales of Acme Cola’s products within Europe, but if Acme Cola has a strong voice in the Senate, or indeed in Washington, would the US authorities play ball and encourage them to pay the fines, or would they be lobbied and fall on the side of Acme Cola to say no, we do not accept that US companies should have to adhere to someone else’s law?"
And here's a potential test case unfolding:
https://iapp.org/news/a/does-the-recent-fine-for-a-canadian-...
My PoV is that an email address + first name in a mailing list should not be covered under GDPR.
William (billy69420@cbt.eu) does not identify anyone, does it?
I can also understand that the sex and weed references mean that you've probably not given a real e-mail in this example, but if it were real I might be able to infer an age range (or at least a level of maturity) of the user from that, although this would be unreliable as the user could have made the e-mail account some time ago and just still happen to be using it.
"If data are inaccurate to the point that no individual can be identified, then the information is not personal data. (e.g. If you refer to “the man who lives at 12 Mulberry Lane had a party last night,” when Mulberry Lane ends at number 10, that’s not personal data.).
I could guess "12" was a mistake and just send spam or visit the man living at number 10.
That's way more dangerous imo than an old skool email address and a first name. Yet it's apparently not considered personal data. That's why I asked, actually, since it confused me.
It is very wide and email address definitely fall within it. Also note IP is personal data, and an identifier like a UUID of the IDFA is personal data. The key point is that it must be related to an identified *or identifiable* data subject, ie even if that information is not enough to identify the person, the fact that it can contribute to it makes it personal data.
Here's a citation:
"If you cannot directly identify an individual from that information, then you need to consider whether the individual is still identifiable. You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual."
https://ico.org.uk/for-organisations/guide-to-data-protectio...
Back when GDPR was new there quite some discussion about the differences. Don't remember the details. Maybe someone can remind us.
In practice almost everyone in and out of the EU violates the GDPR because it is simply not enforced.
Not because it's impossible to hold foreign companies responsible, but because the authorities aren't even trying (except the very occasional headline grabber).
> Not because it's impossible to hold foreign companies responsible, but because the authorities aren't even trying (except the very occasional headline grabber).
I think this is a fairly cynical take. I think data privacy as a whole is greatly improved since the introduction of GDPR, and difficult questions are being asked of companies doing dodgy things with personal data (e.g. google, facebook).
I have some sympathy for the enforcement authorities who are relatively small organisations trying to enforce large changes across a huge swath of companies. They need to pick their battles, and going after lots of little fish is probably not a great strategy.
Which they are slowly winning. Ramping up regulations take time, but they work on tax schedule. They will win in the end.
- List
Are you willing to give in to the demands:
- Just once
- Fake my data
- Always
- Never
This could and should have been all you see of GDPR. Maybee technical laws should also enforce a standard for consent interfaces.
Then they can offer incentives to you to justify you giving them more. That would be non-invasive, privacy centered & make the web a better place.
In my opinion the rights[1] and principles[2] it lays out are much more important in giving individuals control over their personal data.
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
[2] https://ico.org.uk/for-organisations/guide-to-data-protectio...
So if anything, at least it brought the conversation about personal data to the public and splattered it left right and centre for a while!
Compare the total fine amount for Facebook to its revenue (of which a sizeable chunk is earned by breaching the GDPR).
It is true that if the fine is smaller than the revenue (Facebook’s case, probably) then it’s just an entry in the ledger for these companies.
A similar situation is that I can listen to music on my phone with Spotify legally but if I plug my phone in to a speaker system and play the music for a large group in public, it’s no longer allowed. But the music actually came from Spotify so how is it different?
Tech people always feel entitled to loopholes in laws like “this file is just a bunch of bits, how can a number be illegal??” But this thinking is not useful for a functional legal system.
Can we apply this logic to downloading copyrighted material? I would love it if I could openly and legally download ROMs of all my games and archives of prime time broadcast television.
But since that's not how the legal system works, it's pretty obvious that getting something from the licensed distributor is different from getting a copy made and distributed by someone else, even if it's automated.
> But the music actually came from Spotify so how is it different?
The downloading is still legal. Spotify is still legal. The only problem is the new part you added. This is not analogous to the download vs. download comparison.
> Tech people always feel entitled to loopholes in laws
You know the test came from a highly regarded court, right?
With the photo, you are a single user browsing the photo on either website A or website B. Website A “owns” the photo, and website B has embedded it, but in both cases you are getting the photo from website A.
Since you are the same user both times, and are getting the photo from the same place both times, at first glance I would regard this as not breaking any license terms since the two parties (image host, end user) are the same, but I can accept that this is a point of contention.
Spotify's license is obviously not going to include permission from the artist to broadcast the work to large audiences.
Suppose I put a bowl of cookies on my lawn with a "free cookie" sign. Then I sue anyone who takes a cookie - not for taking the cookie, but for stepping on my lawn. I don't think a court would be willing to accept my stance that I didn't provide a license to enter my property.
If the difference is awareness (demonstrated) and profiting off it, would a banner ad on the page be enough?
Can I get into hot water when the content of the link changes after I link to it?
But then, the judges might not know the tech well, while I don't know much about law. Maybe the intent of the embedder to have the content displayed by embedding a link to it is all that's needed here? Without their embedding, the viewer would not see the copyrighted content.
Interested to hear more knowledgeable perspectives that can elaborate on the legal basis of these decisions.
You know perfectly well what the browser will do when presented to that link, you know the site doesn't follow the law, and you know your user will be harmed on this specific way. I don't see a problem with you being held responsible. (Also, civil laws have a tendency of spreading blame over as many parties as possible when the victim is seen as powerless. That's a very good tradition that the EU started by the way.)
If you didn't know that the linked site would misbehave, or what the browser would do, then you shouldn't be blamed. Still, if the victims are seen as very powerless compared to you, it's not rare for laws to still place you as an intermediary and require that you go settle your damages down with the other party. I think the GDPR shouldn't do that, but I don't know if it does.
This is a misunderstanding that has to stop: judicial opinions are not law! Judicial opinions represent a judge's interpretation of the law, and courts take such precedents into account, but precedent can be and is overturned. There are all manner of precedents that are clearly, absolutely wrong, and which have never happened to be reconsidered by another court in a similar case --- but that's no reason to allow yourself to be bound by them in your life. To change what is or is not legal, legislatures have to change laws.
The same, but less so, applies to mandates and orders issued by executive officials or agencies, at whatever level; they may be supported by law, but they are not themselves law, and since often the people making and enforcing those mandates and orders are not elected representatives, they do not have the authority that popular representation gives to actual laws.
IP has tumbled, stumbled and bumbled to its current state by way of haphazard precedents and half assed legislation. To the extent that it's intentionally tweaked (designed is too strong a word), it's adapted to protect high value industry or companies. What we're left with makes no sense.
Concepts like freedom of expression, the public domain, rights of artists and such have a part in IP's history, and rhetoric... but I can't think of any legislation, reform or regulatory/enforcement actions that actually set out to defend these.
I don't know if there's a one paragraph solution, but IP is central to a lot of centralisation phenomenon one way or another. The economic and legal dynamics of copyright, for example, centralize control over music revenues and often discovery. That's spotify now. It was record companies at one point. The first step in any commercial music endeavor, before a single note is played, is to separate artists from control and ownership of the music.
What the hell is the public benefit of giving social media sites these rights over content? If we accept T&C click throughs as valid contracts, the whole concept of determining content usage rights by agreement is absurd in practice.
No, I don't. Probably because I've blocked social widgets capable of tracking me.
Also, since Instagram has an embed feature, surely they have something in their ToS that ask the user to grant a license to Instagram to display the content not just on the main website but on any website that embeds the Instagram-hosted content?