24 year old student lights match: Europe versus Facebook
identityblog.com
identityblog.com
You chose to use the Facebook service, you chose to provide this information to them, and you chose to agree to their terms of service.
Facebook isn't a government agency, it's a private organization that has persuaded people to give it armloads of data about themselves, and uses that for whatever completely legal purposes it so desires. It's not like they are taking out credit card applications or anything on behalf of these users.
What is it about this completely voluntary relationship that is so inherently evil? I really don't get the harsh kickbacks and complaints against things like "Facebook keeps records of pokes even if the user 'removes' them". So what? How is that something that is litigation or 'outcry' worthy?
How much of this data is just persistent in the system because they operate at a scale where data deletion or removal just cannot feasibly be accomplished[1]? Much like google - 'we dont delete anything'. Why should they legally or otherwise be required to verify something is actually deleted, instead of simply ensuring it's inaccessible in their system? Why is nobody complaining about NTFS or ext3/4 not actually zeroing out the file space when you delete something, and instead just 'marking it deleted' or 'removing the pointer in the inode'? How is that fundamentally any different at all?
Please, educate me, because I really don't get it.
Likewise, Facebook chose to operate under the laws of the various lands in which it operates.
Google's Tax Tricks: 'Double Irish' And 'Dutch Sandwich' http://www.npr.org/blogs/money/2010/10/21/130727655/google-s...
Dublin, Hamburg, London, Madrid, Milan, Paris, Stockholm.
Even if they didn't actually have physical offices in Europe, there are any number of situations in which Facebook may end up subjecting itself to some European laws. Consider:
* Taking advertising from European companies.
* Partnering with European developers on its platform.
* Using the services of European companies (datacenters, bandwidth, marketing...).
* Employing European employees, whether as ordinary employees or contractors.
* Attempting to enforce trademarks or copyrights in Europe.
In addition, if they wish European corporations to use Facebook to communicate with their customers, they need to not do anything that would expose those corporations to potential liability under European law.
There are a half-billion people in EU territory. They are on average relatively well-educated and wealthy consumers. That'd be one hell of a market to cut yourself off from financially.
Is that data privacy an inalienable, non-contract-surrendable right? That seems ridiculously draconian.
The other thing that I wonder is how much of the US not having the strict laws is due to Corporate Personhood. I honestly don't know, I'm just throwing it out there.
Particularly those parts in which certain large information business organizations were subject to hostile takeovers, rendering prior understandings of data acquisition and use obsolete.
I'm thinking in particular of, say, the German Bundesrepublic and Vichy France. Though you might argue that the former was sanctioned by democratic processes, I suspect even you would be hard pressed to say the same of the latter.
If nothing else, it'll keep you off HN for a few hours, which would be a net benefit for the rest of us. With a low p-value, you might actually accumulate a few drams of wisdom.
In the EU companies are required to disclose data about individuals to those individuals.
In both cases what happened was that policymakers tried to work against a (potential) market failure they (fore)saw.
if you know anybody who's worked in Somalia, you'd know about regulations there. It is just a little bit faster and less traditional when cease-and-desist is delivered using AK-47, and regulations change frequently as one "General" is replaced by another.
I don't believe that 99% of Facebook users would tick a box that said 'Please record every webpage I visit and store it for your own future use. I do not want access to, nor the right to remove, this data.' Voluntary or not, there's a right to at least see the data that anyone holds on you. Note that you don't have the right to remove data.
This is EXACTLY why data protection laws are there. At the time they were enacted it was largely credit reference agencies, public bodies and direct marketing businesses which were in the spotlight. Had they been written today they would be aimed firmly at Facebook, Google and Apple.
Why is this not a 'just don't use the service if you don't like it' deal?
Credit bureaus are significantly different - you have literally no choice in that manner; Facebook isn't providing data to be used in that type of decision though. If some secret, 'I cant see it but they show my boss' data existed, and that was used when applying for a job or something, I could understand that perspective.
This, however, is no more than a guy standing outside a row of stores, taking notes during the day of what people go in what stores, and how big their bags are when they come out. Is that illegal in Europe as well?
Edit because I can't seem to reply to comments below: That's fascinating. If even that sort of behavior is illegal in Europe, it makes the outcry against what Facebook is doing make more sense.
Yes. Usually, you cannot build a database (digital or paper) about people without their permission, and without allowing people to get access to their records, and allowing them to get their records deleted.
Then there are exceptions (e.g. you have implicit permission to build a database of the members of an association, or you have a contract with the person and what you record is "adequate"), or cases where you need to get an extra authorization from the data protection authority for example if what you record is sensitive (political affiliations, religious beliefs, sexual orientation, etc.).
In Finland you also have to have a public "registry declaration" available that tells what data you gather and what you do with it. Though quite a lot of websites violate that law due to laziness.
I guess it's really a strong difference of culture between Europe and America : laws are made in Europe to make sure that people should not have to make the effort of guessing if a company will mess with their data or not. The company has to make that effort.
> As an example, in France it is forbidden to count the
> number of people who get in & out of a subway at a given
> station.
That seems lame. That number is highly anonymous. How does a statement like "between 8am and 9am 250 people boarded the subway, and 130 people exited the subway" affect a person's privacy?https://www.privacyinternational.org/article/france-privacy-...
European law tends to work on the assumption that it's up to the owner of a technology to show how it will safeguard against the abuse of it. Failure to do so in the past has had disastrous consequences in some parts of Europe.
Good to know there is at least one country where you'll be safe from that.
Well, until it gets so cheap that there's no way to know whose glasses or contacts are recording and compiling information about you as part of their lifelog. This sort of thing is like the tide coming in: legislation against it can only ultimately be effective by severe restrictions on allowed technologies for the people of the country.
I never expected it to possibly hit the mainstream this quickly though, and especially not with some of the possibilities that you are hinting at.
Substitute whatever anti-social mechanism you prefer.
The drone wars are coming: pilotless aircraft, possibly autonomous, from the size of a small car to the size of a gnat, with intel or lethal payloads.
Bioweapons or nukes. We've had suitcase nukes for a few decades, fortunately they haven't been used. Suitcase-sized conventional explosives are rather frequently deployed in some parts. Weaponized chemicals or biological agents are another option.
It's trivially possible to adulter drugs or drinks. Some of the oldest laws on the books deal with food and alcohol purity.
Having the technical capability to do something doesn't mean it must needs be accepted. Legal sanctions may be swimming upstream at times, but other norms (social, cultural, religions. technological) generally help keep us from tearing one another to pieces, most of the time.
If the <i>use</i> of any of that data -- for profiling, legal process, advertising, contact, etc. -- is prohibited, and the action of performing the surveillance exposes the entity to plausible legal consequences and/or obligations (notification, deletion requests, etc.), then its practice will be limited. Undisclosed phone recording in some states, for example (not admissible in legal processes, a violation of law of itself, etc.).
Much crime is economically motivated (not all, but much). Part of criminal theory revolves around making crime more expensive (to greater or lesser success, depending). There's an economic study of criminal activity as well.
Businesses tend not to undertake activities for which there isn't a net economic benefit. Shareholder obligations and all that. So yes, with an appropriate legal framework in place, it's quite likely that incentives for engaging in certain behaviors will be limited.
Laws like this are a legacy of a time before it was easier to just record everything that happens to a person or in an area than to make decisions about what to record. We're still in the tail end of that era, but only just.
Much crime is economically motivated (not all, but much).
It's estimated that the average American commits three felonies a day (but if you start thinking about this topic and the people around you, it will escalate sharply, since failure to report a felony you know about is itself a felony...). Given this, I think we can safely say that the vast majority of crime in the US is completely incidental and unknowingly committed. Even if laws about recording other people (like police and audio callers) remain on the books, the ubiquity and silence of continuous recording will mean that it falls into the list of things that people do all the time that the state technically bans.
Until a few years ago it was illegal to sell liquor on Sunday in Colorado. That was lame, but I never saw a liquor store open on Sunday. If any did, they'd probably get fairly good public support and letters to the editor in favor, but they would still lose their liquor license.
You seem to be stating in response that the law must be followed while it is in place. I'm unsure what your driving point is as I wasn't even advocating civil disobedience of said law.
http://www.mta.info/developers/turnstile.html
They even put ads for their data API in the subway.
http://europe-v-facebook.org/Compalint_02_Shadow_Profiles.pd...
You're the product.
What's particularly entertaining is how many people get annoyed at being reminded of this fact.
Soylent green is people.
http://www.ethannonsequitur.com/facebook-you-customer-produc...
http://en.wikipedia.org/wiki/Data_Protection_Directive
Some countries go further than these pan-European rules and for instance require you to delete the data on request.
Facebook having a Dublin subsidiary is going to hurt big time.
The reason why you can't respond to some comments is because of HNs anti flame-war measures, a cool-off period is active before a reply link appears. There are some tricks to get around that, I'm sure you'll be able to figure it out.
>Why is this not a 'just don't use the service if you don't like it' deal?
This philosophy goes both ways.
Facebook decided to do business in other countries and to do so they are bound to respect the laws of those countries. If they don't like those laws their are perfectly free to stop operating there and let other companies take their share of the market.
Because that's the law in Europe (according to the complainer). It doesn't matter that you're free to not use the service, the law says that if you do use it you have certain rights.
You're free to not use any service anywhere in the world. But if you do use a service in some jurisdiction, that service is subject to the law in that jurisdiction.
Facebook, being Big Boys (TM), must follow the law of the land. If they do business in Europe, that law (it seems) will be more favorable to consumers than they're used to here. Tough.
Personally, I think they'll get away with it. Corporations are becoming their own law. Facebook may have made that calculation too.
Actually, the law says that you have certain rights whether you use the service or not.
"The right to privacy and to the protection of personal data are fundamental rights in the EU which must be – also online - effectively enforced using the widest range of means: from the wide application of the principle of "Privacy by Design" in the relevant ICT technologies, to dissuasive sanctions wherever necessary."
Neelie Kroes is commissioner for that digital agenda (http://en.wikipedia.org/wiki/Neelie_Kroes#Commissioner_for_D...). Her track record facing large companies should be a cause of concern to Facebook.
Why is this not a 'just don't use the service if you don't
like it' deal?
Because people are ignorant/lazy/desperate and need to be protected against themselves. That's one of the things we want our governments to do: to protect us when we overlook something in the complex reality of our daily lives, without caring for why we overlooked it.You can't sell yourself into slavery, you can't sell an organ and you can't sell the right to your private information without retaining the right to have that information disclosed to you. If you want to do business in the EU, be prepared to disclose any piece of data you have on a user, if he requests you to do so.
Maybe you want, I don't.
Facebook's complexity pales in comparison to the complexities of the government.
(Section 26) http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
Notes: 1 - this can cause surprises when companies go bankrupt and the bankruptcy courts allow the sale of the data (about you) to proceed without your knowledge or consent. It is very rare for you to be notified (such as in the current Borders bankruptcy), or the privacy policies of the dearly departed company to be honored by the courts. 2 - Just because you are willing to give the data to me does not necessarily make it legal.
http://yro.slashdot.org/story/11/10/18/1429223/facebook-is-b...
I'm not going to argue it's inherently evil but,
You are right that the service is completely voluntary. However, the opportunity cost associated with not having a Facebook account has been rising by virtue of the network effect and 3rd party services requiring a Facebook account to access functionality.
The fear is: as (if) Facebook becomes more and more a part of society, the cost of not having a Facebook account becomes high enough to make it practically compulsory to have a Facebook account. And if at this point Facebook acts as it does now, well then it's time to start worrying.
Picking up a hoe and tilling a field is completely voluntary, so why did slaves choose to do so? Because not doing so was too costly.
Zuck: They "trust me"
Zuck: Dumb fucks
People don't choose to be tracked on other websites by facebook. People don't even read the terms service. Most people just want to read what their friends write, and look at pictures of cats.
you have obviously never dealt with DoD or anybody close to it or even just with a serious enterprise/bank.
the kind that can prevent you from getting that job you want 15 years afterwards? Facebook may be a private company, but would you want them (or anyone) disgorging all their data on you that they've ever had in response to a government subpoena - for a background check or a security clearance, for example?
While that summary is not incorrect, I think it's worth noting those pictures you mentioned are valued somewhere above $80,000,000,000 (http://venturebeat.com/2011/09/27/facebook-valuation-sharesp...) Maybe there's more to it than that.
Short it is a monopoly, they have a lot of power and when you start to abuse it, like forcing users to accept your unfair terms of service, the government comes into play.
I never heard that Google doesn't remove stuff when you remove them inside your service. They advertise the huge space on Gmail by "never have to delete anything", that is completely different.
> Why is nobody complaining about NTFS or ext3/4 not actually zeroing out the file space?
I normally don't reply to such a stupid argument, but i have a related video: http://www.youtube.com/watch?v=1SCZzgfdTBo#t=3m20s
So how does Facebook have no alternatives?
If you don't like the product, or you don't like the way its run, or you don't like the way it handles your data, or you don't like the color of the log in button, then its simple. Don't use it.
As the original poster said, it is a private organization, and therefore you have a choice. This isn't social security, this isn't taxes. I can (and don't) use Facebook, but much to my dismay, I still pay my outrageous taxes.
This weeks' Monopoly is last weeks' MySpace when users choose to go elsewhere.
For most people like me it is a tool to communicate to over 150 people and they expect me to have it. With most of them i can't communicate with mail any more.
Facebook himself says it's Messaging is replacing Mail for young people, now they have to act responsible about it.
It is like a telephone number you give to all your friends and someone says "Hey when you don't like something about it, just don't use it". You are invested in these things, it is not that easy.
By analogy with predatory lending, i'd name it predatory social network lock-in. Hook 'em while they're young, while they don't know any better and while they not able to analyze consequences, ie. while they not able to make an informed decision.
Is this not word for word what a drug addict says to somebody who's clean?
I've used social networks and found all they did was replace real life social interaction with fake, scrubbed online interactions. I was never one of those "DELETE YOUR FACEBOOK PROFILE AND RUN" fad followers, I just found that I was able to get by and communicate just fine without it.
Facebook also caters very much to US culture. E.g. In middle school and high school you move between different classrooms so you make lots of different friends that way. In Denmark you sit with the same 20-30 kids every day for 10 years. It's a very different type of social conditioning.
So - if you're the outlier in the class who isn't connected and the party invites go out on FB, guess what? You have volunteered to get ostracized.
My point is that social pressure can often make people do things that they don't really want to do. And sadly, many people do not have the courage to stand up to their peers and tell them no.
It's more common in US culture to do that, and largely encouraged by US societal norms, but that isn't always the case in other cultures. This is based on my experience growing up outside of the US (and also spending time in high school and college in the US).
Thankfully, since I never actively used any social networks as a kid, they never became a crutch for me, and any time there's a party worth going to, I'll know about it either through text, a call, or (what most kids seem to avoid these days) face to face social interactions with my friends.
True, but that doesn't help the people who don't use Facebook but who still have data about them collected.
Just did some research while writing this post and it seems that Google changed their ToC for Gmail from deleting emails within 60 days of being deleted by the user to "make reasonable efforts to remove deleted information from our systems as quickly as is practical".
Though the hacker who attacked his wife's account deleted all mail, Google were able to restore the messages -- first the current year's mails, and eventually the full history of the account.
This implies that, though deleted, the data persisted on Google's systems. This is actually a really good system design (most data destruction is accidental deletion by a user, not hacking, and a robust recovery system is a feature). It does raise certain troubling questions, and it would behoove Google (and any other SAAS service provider) to establish a clear policy as to what the grace period during which deleted data may be recovered is.
I've had my own experience where, shall we say, legal obligations made it expedient to remove certain content from our systems. Use of a CDN and extensive caching means that there's no longer a single point of existence for any given piece of data, and explicitly flushing large volumes of content from our systems was, if not horrendously complex at least non-trivial.
Under US contract law, misrepresentation is sufficient cause to rescind an otherwise binding contract. The contract users enter into with Facebook is to accept their terms of service in exchange for being provided with a certain service. If the user can make a case that the service was misadvertised, e.g. by promising a "delete poke" functionality that was not, in fact, provided as expected, then this can be construed as a breach of contract on Facebook's part.
For web based services the rules change dramatically, because you are no longer in control of the data. Because the past has shown that companies seem to have a hard time to play nice with the data they store on behalf of their unsuspecting users there now is in some parts of the world a government entity tasked with precisely that: making sure that users right with respect to their data are respected.
If you don't like the way your filesystem deletes the data you can always cut up the platters.
A given text object will exist in the primary database, in its replicas or clusters, and in backups. If the outfit is at all legitimate, multiple backups representing frequent points in time, stored in multiple locations.
A binary object (say an image, video, or audio file) may exist in its originally uploaded format, several variants of different size, resolution, sampling rate, etc., and is often served through some sort of a content distribution network (CDN), which will have its own content management interface. Some of these are surprisingly primitive -- web-based forms in which a few score objects might be entered at a time, if you're lucky. Even script-driven purge methods are frequently limited as to the number of objects which can be included in a single request, and the number of outstanding requests which may be pending.
Given the large numbers of individual objects, scaling variations, redundancy, etc., deletion overhead can easily scale to tens to hundreds of millions of objects in a relatively short period of time (days to weeks). Dealing with all of this is fairly non-trivial. Especially if the site architecture didn't take these needs into consideration.
(I'm talking about facebook here, not about the web in general)
If they're proper slaves / replications of one another, then yes.
If, as is commonly the case especially for marketing data, periodic cuts or dumps of the data are made at various points in time, and there's no mechanism for propagating deletions throughout the chain, then no, you're not assured of deletion. This isn't likely to be the case for a site's primary database, but could very well be the case for derived datasets. I can think of instances with, say, credit bureau reports in which erroneous data must be repeatedly deleted because it keeps getting re-injected into the system.
Facebook's September, 2010 outage in which cached data were being re-injected into the system exhibited a similar problem of cache coherence. http://www.facebook.com/note.php?note_id=431441338919
> Dealing with all of this is fairly non-trivial.
To Facebook's benefit, of course. I'm sure that Facebook would never think of using any user data flagged as 'deleted' in any sort of data mining...Facebook also has no incentive to spend the time to figure how to do deletions because the data is valuable to them. Why would they spent time and effort to make it possible to lose this valuable data?
I'm sorry but this seems like a huge ignorance on the part of you on how DSes are designed. These issues are important.
Have you actually read the Paxos papers and the rest of the literature on this?
From the EU charter of fundamental rights, which has constitutional force: Protection of personal data 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority
http://www.europarl.europa.eu/charter/pdf/text_en.pdf
I wouldn't bet on Facebook in this case. you will see more of this, since most people in the EU speak English and are avid consumers of broadband, but are not especially sympathetic to the American philosophy of contract law.
What can they do? It's the law.
Then make the thing public, disclose all your communication with your target, post the story to Hacker News and Reddit, maybe even get picked up by some important blogger or newspaper. Would look good on your resume to fight Google, wouldn't it?
Also, agreeing to use a website does NOT give the website the ability to break the law. Otherwise, we could have drug-trafficking sites completely in the open with a box saying "By checking this box, you understand that we sell extremely illegal drugs, and that you will not take any action against this site."
That's nice in theory, but of course you can't know which pages have the 'like' button on it until you hit them.
Seriously, read through the list of complaints:
Shadow Profiles Facebook is collecting data about people without their knowledge. This information is used to substitute existing profiles and to create profiles of non-users.
Messages Messages (incl. Chat-Messages) are stored by Facebook even after the user “deleted” them. This means that all direct communication on Facebook can never be deleted.
Data Security In its terms, Facebook says that it does not guarantee any level of data security.
Applications Applications of “friends” can access data of the user. There is no guarantee that these applications are following European privacy standards.
I mean, really? None of these give you any pause for thought whatsoever?
Data Security: Anyone who says your data secure is bluffing. Your data is never secure, and people need to stop thinking it is. It's out there. Backups, in transit, in DB, on file system. There is going to be whole. Think about it. Encrypted backups - they are never updated and eventually that encryption is going to be easy to crack. FB could be taking the answer to the extreme, but it is actually a smart answer.
Applications: FB doesn't develop them. It would be similar to MS guaranteeing apps written by third parties. It can't do it. Apple can't even do it. Linux doesn't do it.
FB has it's issues. It's constant update of privacy and not letting the user to choose to expose what data they want. But this is no different than any other system thrown out there.
FB isn't the only one creating shadow profiles (how many tracking websites are out there that companies use to determine site usage). Do you think they are really being transparent? Don't you think the shadow companies could build a shadow profile if they wanted to?
My issues with FB is that when they release new features or alter settings ability they make it the least secure possible.
If they are violating the laws, then they need to be reprimanded for it. But this just has the feel of the MS monopoly issue. Where people are only going after them because they are so big when others are out there doing it as well.
In order to do business in the EU you generally have to comply with their laws. One of the privileges the EU generally grants their citizens is that companies must, on demand, produce all data they store about that person. Why should this be true? Because EU citizens living in democracies want it to be so.
If fb doesn't like it they are free to not do business there. Otherwise, they have to comply.
Now the fact that they collect this data and people voluntarily agree to it is precisely the evil part. People agree without realising what they are agreeing to. There is a more general problem here which isn't Facebook though - its that EULAs and fine print are given legal weight when nobody reads them and this is common knowledge.
Now... to tie this altogether I never realised Facebook would store my deleted messages that might have been in the agreement I "made" with them when I ticked that check box and pressed okay years ago. Now, flagging for deletion is fine, in their case though it costs them expensive storage space - maybe its cheaper than the processor time to delete things - either way its irrelevant because they shouldn't do this because the Data Protection Act says that information should be kept for no longer than is necessary.
I don't know if they have any need to comply with UK/EU law to allow accounts for people who live here - I don't think they do, but I would hope US law has something similar...
Even then, whenever EULAs get updated, rare is the company that highlights the change - most expect you to reread and figure out the difference for yourself. You also have no choice but to agree or lose your existing body of work - it's a unilateral license change, not a mutual change of contract terms.
The whole "but you voluntarily agreed to their terms!" concept is a canard which disguises how obfuscatory and misdirectional the EULA process is. It's the difference between "consent" and "informed consent", which is significant.
Still, it doesn't beat the 'voluntary' license where you can't read the license until you unseal the box, but unsealing the box indicates you agree with the license.
And I seem to remember that some court in some county decided that EULAs in general are not legally binding (to consumers at least) any more since no one can be reasonably expected to read them.
What a strange world we live in.
And were they government agencies, would the privacy concerns just have dissipated?
I think what it boils down to is: what is a right and what is a privilege? Is it that Facebook is a privilege, but my privacy remains my right?
Is there anything to 'right' and 'privilege' beyond legal context?
Essentially, the problem is that these voluntary relationships become not-so-voluntary as the privacy-compromising tools become more necessary to participate in society.
Arguably this lies outside of the complain domain, but it does
relate directly to the "not a big deal" stance. I find it
*shocking* that people accept it as a perfect norm what would
never fly in a physical world.
How many business owners wouldn't mind a post office retaining
a copy of their every mail? And furthermore using it to better
the type of junk mail being sent to the company.
Or how many regular folks would be OK with their alumni club
installing surveillance cameras in public and private places
to track their movement? Still not a big deal, eh?
Why do then things change when the very same businesses and people go online?
/rantWhat Facebook is doing is illegal in the EU (or at least, its legality is in dispute).
Whether or not you agree with those regulations or think they are absurd is another matter entirely, and quite irrelevant, since you don't make the laws and can't even vote for the people who make them (because you're from a different part of the world).
So while I agree, simply avoiding Facebook doesn't solve the problem.
However, I find it interesting why people get paranoid about the mindless jibber-jabber on facebook compared to the immense and more presice data google stores about individuals... and I imagine getting a CD out of google would be far harder than from facebook (by the looks of things).
Google are clever by being 'open' and allowing people to download 'some' of the data they hold about peoeple, but I am sure they would be as reluctant as facebook to make everything accesible.
Facebook chose to do business in Europe, Facebook chose to be governed by European law.
This isn't right for two reasons:
1. Under EU law there are certain rights that you can not sign away in a contract. They are yours and you keep them no matter what any bit of paper or click-through license says. This might seem disingenuous, signing to say you'll give them something but not doing so, but the law is actually the other way around: they should not be asking you to sign that right away in the first place.
2. It would seem that facebook are not only tracking people who sign-up. See http://yro.slashdot.org/story/11/10/18/1429223/facebook-is-b... (or search for "facebook shadow profiles"). This is most definitely against the data protection act in the UK, and they haven't even asked those people to sign away the right to not have that data stored unnecessarily.
As for the idea that Facebook is to big to effectively delete information, that's unacceptable. If you're that big and you can't figure out a way of routinely deleting data then you need to find a way of collecting more data or making your data easier to delete, or not giving the user the 'delete' option. There are a number of alternate verbs which describe the process they are going through, none of which are as clear or commonly understood as 'delete', but which are more accurate. 'Hide' and 'make data invisible' come to mind.
I don't have as much of a problem with the saving of messages which others will also read, but on deleting a Facebook account, this could be handled more gracefully if the user wishes. This is a more difficult problem to solve, which would require Facebook itself to store messages with under the covers public key cryptography which sounds like the type of thing they wouldn't do.
From a technology standpoint it seems it's more desirable to just keep throwing storage at the problem and spend time working on ways to store and manage even more data. Data is valuable after all, so the incentive is there to accumulate and process as much of it as possible. That's exactly why we need some form of external stimulus (eg: laws) to force people to work on the problem of how can we be getting rid of data when we need to without breaking everything.
Well, that and violatng the laws of some of the countries in which they operate.
After all, the users get just about nothing out of it, if you like something that much an email will do just as well (to the select number of people that you think your liking a particular subject will appeal to).
The main winners are the publishers (they hope for some more traffic) and facebook (by extending your profile, not just by being able to count the 'likes' but also by the lesser value of those sites that you simply visit).
Like buttons and other third party javascript are a huge vector for privacy violations, basically any website that places any kind of third party javascript on their pages is giving full control over the privacy of their users to the party that hosts the javascript component.
If that party also happens to host a service that a large number of people have signed up for at some point in the past, and that they are possibly signed in to right this minute the potential for abuse is staggering.
Nobody asked the techies if this could be a trojan horse.
Has Facebook considered using benefits of modern technology and delivering the requested info electronically by, for example, setting up a web site where users could access/browse/download the requested info and may be even let some other users, like their friends, to access the info as well?
:)
This is why checks take up to 14 business days to clear (to make a quick buck in those days), why you have to wait 30 minutes on hold "for the next available representative" (to discourage you calling in), and why most rebates are mail-in (in hopes that you will forget).
Of course, in light of reading about this, I sometimes wonder if Facebook really deleted the information contained in my old account.
[1] http://www.leg.bc.ca/37th4th/3rd_read/gov38-3.htm#section23
1. Facebook has bases, and operates, in Europe. Thus they MUST abide by our data laws. This means that, under our European laws they MUST supply ALL information they have on people. Currently this is not being done and as such they are breaking the law by not providing ALL information they hold on people. If they want to have HQ's in Europe and want Europeans to use their service they must abide by our laws, this is regardless if we as a user decide to sign up or not. These laws cannot at anytime be waived REGARDLESS if it is indeed us as Europeans deciding to use their service.
2. Quite simply, if they offer the option of "deleting" posts/likes/mails, then they should do just that, delete it. Anything other than this and they are quite blatantly misleading users.
3. They SHOULD NOT be gathering information on ANYONE who does not use their service. This is not legal and should not be allowed to happen. The old saying "knowledge is power" comes to mind, but these "big corporations" should not be able to gather data on people who have no connection what-so-ever to their company/services. Britain recently has been rocked by such scandals as phone hack etc aswell as the big argument about Google cars collecting data from wireless networks that they were not authorised to do so from. Is facebook gather information on people who have no connection to them any different from hacking someone’s phone and listening to their messages? Or any different from a Google car passing your home and gathering information for your wireless network? My opinion is that it isnt any different. New of the world have had to pay out massive amount of compensation to the people who could prove that their phones were hacked. It is a breach of privacy and more importantly, THE LAW. Google also had to agree to delete all information gathered by its Google cars as this was deemed to be illegally collected.
Facebook should be made to adhere to our laws if they wish to be present in our countries. Thus they should be made to supply ALL information held on people who make subject access requests, they should delete all e mails/post/likes that have been deleted by the original (or any recipicants) and should also delete ALL information they have gained about people who no longer/have never used their service.
I joined facebook when it first came out as would say i was pretty young and naive, I didnt read all the agreements etc and certainly didn’t know what I was signing myself up for (alot of which has not came out until recently). If facebook want to use the argument that everyone who signs up agree to their t&c then they should respect the fact that only peoples over the age of 18 should be allowed to join in Europe. (this is currently not the case with children as young as 8 and their pet dogs having profiles)....
Facebook cant have it all their own way and must respect the laws of the land, PERIOD.
1) The analogy between hacking your phone and reading messages is really NOT the same as Facebook storing data that you supplied to their system.
2) Google did nothing that should be considered illegal regardless of what European courts decided. The data they collected was on OPEN WIFI routers. This is the same as being accused of breaking the law because you listen while having a conversation in a crowded room. Open wifi comes with the implicit idea, that the owner of the router is actively allowing others to use the router.
Usually any communication has two parties. So, you can collect information with neither party consenting (phone hacking, wiretapping, etc.), one party consenting, or both parties consenting.
I would think that most of the information they collect would count as one party consenting, so it's a step up from phone hacking. But it's still worrying, of course, because the single consenting party often doesn't know they are consenting (whether they should know or not is a different matter).
Why? One might argue that European laws MUST be changed. Pointing to laws is hardly a moral argument, there are tons of terrible laws and facebook might as well be a victim of one of them.
As for your argument, why is that a terrible law? Why is it bad that users have a right to know what companies have on them? To be honest, I think it's a pretty bloody great law.
Facebook is a victim of itself. If it didn't track users in the first place, it wouldn't be in hot water.
> And the truth is that Facebook is breaking our laws and need to be prosecuted for such. That's what we are having an argument about. I agree that they are breaking our laws, but I don't think that they should be prosecuted. I think the laws should be changed instead, because they are bad.
> Why is it bad that users have a right to know what companies have on them? Because it isn't the state's business what customers and companies agree with each other. If facebook states in its contracts with their customers that they will make this data available then they should be prosecuted for breach of contract if they don't.
I'm against the state (or the EU or whoever) making laws that deal with private matters because lawmakers are notoriously bad at thinking things through. This leads to a bunch of unintended consequences and ultimately is bad for both customers and companies and anybody else. E.g.: copyright laws, patent laws, immigration laws, drug laws etc...
Actually, they aren't bad at thinking things through, it is impossible to think things through. http://www.nobelprize.org/nobel_prizes/economics/laureates/1...
> Facebook is a victim of itself. If it didn't track users in the first place, it wouldn't be in hot water.
I don't want to defend facebook. Maybe what they do is bad, I'm sure that's an interesting discussion, I really don't know. What I'm saying is: Even if what they are doing IS bad, then the state still shouldn't intervene if they don't breach the contracts with their customers. Facebook doesn't force you to use their services, and if you do so voluntarily then it's on facebook's terms, though luck.
WRONG! Think about all the sites that have Like buttons. Facebook never showed me a form or a checkbox to use that, did they? Yet they're gathering information on the sites I go to and setting up "shadow profiles" (as europe-v-facebook put them).
You're right, Facebook doesn't make me use Facebook -- they're trying to force me to.
And sure, I can just use hosts to block the Facebook site, but I shouldn't have to do that just to stop them from tracking me.
As a European I feel that I should have access to any information a company holds on me.....both MORALLY and legally...
If you give up information voluntarily (even if you aren't aware of it) why should it obligate anybody who collects it to spend resources on informing you what they know about you? Morally, why does gathering information imply obligation to provide certain information? This is a total non-sequitur.
Much the same way i wouldnt want to be contacted/emailed/telephoned/written to by companies i have in no way solicited to contact me....
Ghostery[0] prevents this, IIRC.
Prevents non-facebook domains from knowing when you are logged into facebook.
"Facebook is hosting enormous amounts of personal data and it is processing all data for its own purposes. It seems Facebook is a prime example of illegal 'excessive processing'."
Since the user has no way of knowing if a page he's about to visit will have a Fb like button or not; and the user probably doesn't realise that Fb will gather the data with no user interaction on the button; that seems like excessive collection and processing.
I am technically a Dutch citizen since I still have my Dutch passport, but I live in the United States with a green card.
We even sent out letters requesting information as an assignment. I sent to a bank, I think. Not very interesting back then, but it would certainly be a lot more interesting now!
EDIT see http://en.wikipedia.org/wiki/Double_Irish_Arrangement
So if FB & Google & Amazon etc. were to 'leave' EU, then lots of EU companies would be legally unable to use their USA services.
It's less to do with a country enforcing it's laws abroad, and more to do with companies setting up a physical presence in a country.
Personally I find his arguments a bit flawed - e.g. in one instance apparently he objects to the fact that Facebook knows when he was ill because he can do a quick CTRL-F on the text "ill" (german: krank) in the text he received from Facebook. My question is - isn't he the one who posted that content in the first place?
Secondly, he complains that deleted messages are still retained by Facebook. Could that just be a referential integrity constraint - since most messages require 2 or more parties. Therefore, although he deletes the messages, the other party still has the message in their inbox. Therefore, Facebook cannot simply delete the message. Furthermore, since the message has him linked, even if he deletes it from his side, Facebook needs to retain that information on their side.
You know the best solution to protect yourself from Facebook's data privacy policies - get off Facebook or at least be cautious when you post! I personally love the service and think one should be smart about what they post on publicly accessible social networks since that data remains for eternity!
So now the statement is that if you don't want facebook to know anything about you, then you shouldn't tell your friends, colleagues, etc. anything - after all, they may enter it on facebook.
</quote> http://slashdot.org/comments.pl?sid=2481922&cid=37750358
If you visit pages that might contain Like button then facebook will know about you even without your acquaintances.
I don't understand, why all law must be proactive. Let people try and experiment, let norms evolve. Why must we prelegislate things, wait until facebook or someone else starts doing horrible things before passing a law.
You may want to read up on your history before you call European laws to protect the privacy, freedom and very lives of it's own citizens "draconian".
They are only draconian if you believe the rights of corporations trump those of the people. Which is basically what the US has been doing for quite a while now, not really an example other countries care to follow.
Can't they just update the content of the message (on both sides) as "deleted", but keep the record itself? It would annoy the other party though.
This would be really annoying, when it comes to chat logs.
As far as I know, what matters is that Facebook targets EU citizens (by having subsidiaries in the EU, by running ads, by explicitly accepting users from abroad etc.)
I think you'll find some pointers at: http://en.wikipedia.org/wiki/Conflict_of_laws
Note this is entirely different when a company has a presence in the US, any of the servers are in the US, or even if the DNS servers are in the US.
The personal info can't be used for anything else other than what the customer agreed to. When the information is no longer required or whatever it was used for is finished the information has to be securely destroyed, until that point it has to be stored and guarded as securely as is possible.
Anyway after all that they proudly said we have a TRUSTe rating and showed other sites which also have it one of which is Facebook. Something seems wrong with that picture.
If its a best practices for business thing (do not bend over more than you have too) then C'MONNN! This is the post baby boomers age, bro - the digital age. Get with the show, be good.
Why would they delay sending others the data? In fact, I would use this opportunity to gain the trust that left the building with the long lost battle about privacy (settings)
Of course I presume all the data they collect is within the bounds of legal and ethical lines.
WHAT IS THE PROOF! (also known as 'consider the author', 'read the article', etc)
Now I can't say with certainty that any of these claims are false or true, but it occurs to me that a lot of these claims are based on what facebook MIGHT be doing with your data. I decided to take a look at the complaint and attachments for the shadow profiles case, I don't see any evidence that these shadow profiles exist, just that there is the possibility that they exist.
And for those that will inevitably say that proof isn't necessary, that means you don't trust facebook. If thats the case, there is nothing they can do to prove to you what they're doing is legitimate short of open sourcing their entire stack (and even then, you must trust that what they're running == the source they give you). So either trust that what they're saying is true, find evidence that they're doing something they aren't supposed to, or stop using the service entirely.
For example, if I "delete" an email in google it is not deleted, it goes to my 'trash/bin' folder - is this also a breach of the law? and are we sure which definition the "Delete Forever" button is using?
...I suppose its up to the terms and conditions to define this.
they need to get there shit together
"If you're not paying for something, you're not the customer, you're the product being sold" *Andrew Lewis
In some issues, consumer rights have the same importance than big-fat-company.
I don't know if in other continents everybody is pro unscrupulous vendors.
Greetings.
https://www.facebook.com/settings
Click 'Download a Copy'
I know someone here mentioned why don't they set up a site where anyone can access it.
This is not to say that Facebook will not or should not offer its services in Europe. Simply that there are possible legal environments where Facebook would be legally allowed to offer its services, but where it would be economically unsustainable for it to do so... and that it is often quite difficult to understand these sorts of effects ahead of time.
Edit: clarification
Specifically, have a look at complaint #2:
"Shadow Profiles. Facebook is collecting data about people without their knowledge. This information is used to substitute existing profiles and to create profiles of non-users."
http://europe-v-facebook.org/Compalint_02_Shadow_Profiles.pd...
I do not use Facebook. They still try to get my data.
Well, they would if they could, and wouldn't be shitlisted by at least four layers of filters (NoScript, Ghostery, AdBlock, RequestPolicy). Still, I can't block Facebook trying to get people to identify me on photos I might happen to be on. While pretty much anyone I am closer acquainted to knows that we'd be through if they'd ever put pictures of me on Facebook, I can't control this for obvious reasons. I can't control photos taken of me on, for example, concerts, either. It's this loss of control that worries me the most.
What I am also concerned about is the fact that people who are not aware of the dangers that Facebook poses might learn one day - and then there will be no way to correct their mistakes anymore.
Finally, I am deeply anxious about the future of the net if stupid ideas like the Facebook login gain traction. I don't want to see a web where Facebook or Google are mandatory to do anything useful. It's already extremely disturbing how much of the net runs on stuff made by Google. This amount of dependency on a single, commercial entity is insanity, no matter how persistently they might insist on their "Don't be evil" policy.