Meta fined $1.3B over data transfers to U.S.
wsj.com
wsj.com
(sane) Tech regulation is a long time coming and it's not coming out of the Five Eyes nations - good to see EU taking a lead
cons:
I wish this had been for a "harder violation. Yes it's bad. yes they are ignoring EU law. But it's you know drawing a social graph.
This leads to a fundamental issue - global capabilities (drawing a graph between all the people you know) should not be limited to arbitrary geographical boundaries. Social graph is fairly obvious - I have friends in US, where do we process the edge between those two nodes? If we cannot sort that one out we are going to struggle with epidemiology and medical inferences across boundaries.
Where data is processed should not affect the care with which it is processed. I can conceive of some verifiable processing package that ensures data can be processed wherever and still meet regulations. Can that be part of the future?
To an extent GDPR already allows this. The fines are only occurring because Facebook is transferring data into a jurisdiction which doesn’t have strong enough data protection laws to satisfy GDPR.
In the U.S. case specifically, it’s issues around laws that allow the U.S. government to force U.S. companies to handover data arbitrarily with very little (if any) due process. If the U.S. modified their draconian laws to ensure that everyone was afforded due process before their data was scooped up by the U.S. government, then there wouldn’t be an issue.
Unfortunately verifiable processes packages don’t solve the fundamental problem that the various three letter U.S. agencies can send a secret order, with effectively zero judicial oversight, to Facebook and compel them to handover data, plus gag Facebook from telling the individuals about the demand.
Fining foreign big tech over EU privacy nuances is like taking candy from a baby. The narrative zeitgeist on both sides of the pond is in support (stories of rigged elections for 4 years turned public opinion brilliantly).
While protecting your citizens rights is a noble cause, its hard not to see the moral hazard inherent in this approach.
Abusing your position as a desirable market to impose post-hoc tariffs via an endless stream of fines is questionable IMO. Especially while the US provides Europe with its extremely expensive military support blanket (NATO) against the angry bear at its door.
There's a simple scenario in which Meta wouldn't have had to pay these fines: Don't break the law. And don't continue breaking the law after being told to stop it. It's not abusive to remind companies that actions have consequences in the language they understand and respect.
EU to US data transfers used to be okay for years, then there was a single ruling that brought that into question. Because government moves slow, there hasn't been a new framework implemented. Ruling for Billions in fines during the interim, while the US government and EU are still negotiating the details of the new framework is not an environment conducive to full compliance. US companies would essentially need to stop operating in the EU altogether if they wanted to be fully compliant.
Combine this with giant companies which also are slow moving (albeit faster than government) and you have a recipe for never-ending fines no matter how much you try to comply in good faith.
That's exactly what they should've done to not break the law while there was no legal basis for what they were doing.
They didn't. Now they suffer the consequences for breaking the law.
If it was a domestic company, of course, assets could just be seized to pay the fine plus whatever non payment penalty. Is there a criminal charge after asset seizure? Or does this just never happen because there is no incentive to do it domestically?
Plus, Meta actually is a domestic company in the E.U. They handle all their E.U. business through an Irish subsidiary (which is why the Irish data protection agency is responsible for all of this) and they also have subsidiaries to manage political and customer relations in many other E.U. countries, as well as presumably data centers, etc. Removing all of this would be a big project and would give government agencies plenty of time to seize assets. These assets could also include non-tangibles, i.e. the .de/.fr domains for their websites.
EU to US data transfers were questionable for years, until a whole string of rulings through several levels of national and E.U. courts made clear that they weren't under some circumstances. Other companies have found ways to deal with that, Meta obviously could have, but chose not to (because profits). One obvious way would be for Meta to save E.U. customer data on E.U. servers exclusively, splitting the social graph (and advertising shadow profiles, which likely is what they really care about). Good faith does not enter into the equation, would be my guess.
Yeah, standing up a data center is not trivial, but Meta also hires the best in the world. Move fast and break things. In this case they didn’t even move at a medium speed, so they get no sympathy from me.
Yes, absolutely. Laws are never clear and require human beings to interpret.
Lawyers jobs are about assessing risk. While they might not have explicitly said "you will get fined $B", they will definitely say "here is the likelihood that the EU fines you" and then meta management would make a strategic (e.g. do we want to risk this based on how much money we can profit) decision based on that.
And law isn't binary, yes/no. Much US law is very murky and ambiguous. It takes litigation and court action to actually figure out what the poorly worded laws mean. Congress is really bad at creating law for some reason.
Or 260 engineers $1mil a year for 5 years with that money.
You honestly think it would take it would 2600-13000 engineers 10 years to do the work needed for compliance?
this will likely be found to be unlawful too in the way the last two were
the EU commission shouldn't be creating frameworks that it knows are unlawful (definition of malfeasance?)
a new framework passing wouldn't retroactively legalize the transfers happening before that, so this doesn't make sense.
Purely from a logical perspective, preventing the data of a company operating in the United States and Europe from contaminating or coming into contact is a pure utopia no matter how much effort it puts into goal or any other company operating in the same or similar field. There will always be a point of contact and a way for European data to be under the lens of some American agency or body.
In addition to Facebook is not really famous for its transparency in data management so any commitment to the contrary I see it as a paper promise
NATO's excuse that because the US finances then anything is allowed is a fallacious argument.
Black Books (S01E01) put it best:
> NICK VOLEUR: This new system, it's very closely modelled on the old system, isn't it?
> BERNARD BLACK: I'd go further than that, Nick, I'd say it was more or less exactly the same[.]
Given the US side of said framework is established by executive order[1] and the “court” it creates is part of the executive (much like the “ombudsperson” office that the CJEU struck down Privacy Shield over), it’s unclear if it will work, or if the Commission (an executive body who can establish these things but is subject to judicial review) is setting itself up for a Schrems III another ten years down the line for foreign-relations reasons. The EU privacy regulator very politely said it was dubious[2], while the relevant parliamentary committee[3] and later the full parliament[4] expressed open scorn.
The US diplomats, for their part, are trying for a “you too” defence[5]—which might well be factually true to some extent, just does not change anything about EU law.
> Its possible this fine was intended to pre-empt the passing of any new frameworks and cash in on the uncertainty in the interim.
As the legal basis for a transfer is fixed at the time it’s performed, a framework cannot be retroactive (but “the Commission was wrong, the transfers weren’t lawful after all” decisions can be). So while the FUD may be real, the case could just as well have been decided after the new framework had been passed.
[1] EO 14086, https://www.federalregister.gov/d/2022-22531
[2] https://iapp.org/news/a/edpb-welcomes-improvements-to-eu-us-...
[3] https://iapp.org/news/a/meps-urge-european-commission-to-rej...
[4] https://www.europarl.europa.eu/news/en/press-room/20230505IP...
[5] https://www.politico.eu/article/washington-to-brussels-we-wa...
What specifically has changed about US law relating to mass surveillance of foreign nationals that is going to make this one work?
Until it's struck down by the court again.
The agreement will not - it cannot - satisfy the requirements of the GDPR and CFR unless and until the US changes its law.
Or unless and until the EU changes its laws.
US: "we demand the right to spy on anyone for any reason, except US citizens where we absolutely must recognize their constitutional rights"
EU: "we demand basic protections for the rights of our citizens"
For another, if one looks past my vague wording, the EU (or at least Germany, which I'm most familiar with) doesn't have the dogma that it's required to set up a world spanning total surveillance state, no compromises beyond the ones absolutely necessary with their own constitution (and even those are followed within a rather "liberal" framework for the three-letter-agencies: they do have all possible data they can get their hands on, just pinky-promise to not abuse it, if US citizens are impacted, in the eyes of secret courts).
[0]: https://law.yale.edu/sites/default/files/area/center/china/d...
The reason we have regulations is that the opposite proved to be true.
Of course, this doesn't work if another country has such a law. But if it's a smaller country, then it doesn't have as much leverage (e.g. Facebook could accept the smaller fine or pull out).
These are not acceptable options to the EU.
Naïve libertarian takes like "let adults make their own informed decisions" are all fine and well, but when there's a track record of their harm that can be pointed to already, it is, as stated, a non-starter.
You do know how that worked out so far, right?
https://www.nytimes.com/2018/10/15/technology/myanmar-facebo...
https://www.amnesty.org/en/latest/news/2022/09/myanmar-faceb...
Your position is an ideology, and it is one with a poor track record; you're welcome to it, but thankfully you're not going to force it on Europe.
How much power do you want to give the government because you are incapable of making your own decisions?
Sounds like something that the US does routinely.
>"Especially while the US provides Europe with its extremely expensive military support blanket"
1) I think it is more than compensating by Europe agreeing to use USD as the reserve currency. The US gets enormous benefits as the result.
2) Angry bear seems not to be able to win over a single country. Beside the US does it for self serving reasons. It is not a charity. And if it did not I think the Europe is quite capable to create and maintain their own army and weapons.
There’s already been two attempts at this, both of which were ratified, then struck down by the ECJ.
There’s already clear indications that attempt there isn’t much better than attempt one and two, and the smart money is betting on it not being ratified, or being struck down if it is.
In the meantime it’s been illegal for a years to transfer EU data to the U.S. So even if it did suddenly become legal, those laws aren’t going to retrospect, and Facebook still engaged in blatantly illegal behaviour.
And, the 5-eyes(my term) still do collect some data behind the scenes that has minimal court oversight including GDPR.
Whatever TikTok is to the USA, Meta and the rest is the same for EU. TikTok has known links to the Chinese Communist Party and the American social media and tech in general has proven links to US intelligence and mass surveillance programs. You may say that CCP is adversary and US-EU are ally but then again the US has proven to be able to elect anti European government, so EU can't afford to rely on not having Trump or similar once again in power.
The Americans are considering to ban TikTok, do you want EU to adopt the same approach and ban TikTok along with Meta and the rest?
I like the EU approach better, even if it's not ideal its better than complete ban. Honestly, I'm terrified from banning becoming the norm because this will mean completely fragmented internet and this will mean the end of global society because the countries will be able to shape their society the way it suits them for internal politics.
if only...
Web sites which grab eyeballs grab dollars. There is no connection to truth, integrity, or honesty there. Right now, even with humans and Facebook-grade algorithms, that's leading to polarizing hatred. Things will get worse once LLM-style algorithms start generating content to optimize engagement.
We need individual free speech, but I'm much less sold on corporate free speech (or speech from algorithms optimized to a capitalist markets).
it should be the other way around.
Military umbrella that US provides to EU that includes military bases, transfer of military technology and freedom of navigation for middle east oil forces all parties to play much nicer. Fines to tech companies are fine (and often are supported by US regulators) but drastic steps like even seriously proposing banning big US tech companies are obviously over the line and are unacceptable.
Even beyond alliance, EU can start trade war but do not be surprised if then BMW and Mercedes cars surprising develop safety issues that requires full recall and compensation to all car buyers for harm.
(OK, that's snarky, but the car companies did actually have to pay out .. because they defrauded US consumers! Not all "crime" committed by companies is made up to sell trade restrictions!)
The US is still a vital ally of Europe and I'm optimistic that this relationship will continue. But Trump and the alignment of factions of the Republican Party with Russian interests have demonstrated that this relationship is no longer rock-solid. Even the Democrats are shakier than they used to be, and orienting for a more self-reliant US.
The US is preparing itself for the end of the post-Cold War liberal global order. The European-American alliance may survive this shift or it may not. Drastic action against US tech is absolutely still premature, but we should be prepared for European interests to no longer necessarily be the same as American interests.
hmmm
>>> already begun with the Inflation Reduction Act - the US is already turning protectionist
you do know that was a Democratic supported, passed and celebrated law right? Not republican.
I have no love loss for the republicans, but this idea that all the problems with US politics are because of Republicans (or worse the Trump bogey man) is moronic and ignorant.
>The European-American alliance may survive this shift or it may not.
This shift has to take place with Europe advancing more of it national defense itself, America simply can not afford to be the world police anymore. The American People are demanding ever increasing social programs, EU Style Social programs, which the EU has been able to have due to the protection umbrella the US as provided at great cost since WWII, to date almost none of the NATO Nations have ever honored their miniscule treaty requirements of 3% GDP defense spending, when they should be closer to 10-15%, but most are at 1-2% (or less)
@32 Trillion Dollars in debt, the US Bank is collapsing, and closed...
I addressed this - the Democrats are also orienting towards a more protectionist, isolated US. The European-American relationship is also deteriorating under the current administration. But it's not Democrats that are arguing for abandoning Ukraine and acquiescing to Russia, it's factions of the Republican Party.
The reality of which party does what is frankly irrelevant though - the perception of people and governments of Europe is that the US is not as reliably staunch of an ally as they once were, and this kicked off under the Trump administration. Europeans believe that a Republican administration is less supportive of a strong alliance, and this perception of flakiness is driving a push for European self-reliance.
> to date almost none of the NATO Nations have ever honored their miniscule treaty requirements of 3% GDP
This is already happening. Several of the biggest freeloading countries have promised massive increases in spending in response to the Russian invasion of Ukraine, most notably Germany. They haven't met their targets yet, but an era of European self-reliance in defence is coming, in spite of current struggles with inflation and supply issues. Things are moving slowly, but European governments largely no longer believe they are safe without playing an active role in their defence.
> when they should be closer to 10-15%
That'd be an insane spending on defence - for reference the US spends 3.5% and Russia spends 4.1%. Ukraine spends 34% and they're currently locked in a desperate struggle for survival.
It is not a perception, it is reality and people need to understand that. The US can not afford it any more.
>>But it's not Democrats that are arguing for abandoning Ukraine and acquiescing to Russia,
I dont know about "acquiescing to Russia" but some member of the republican party have long understood the fiscal reality, where the Democrats, (and other members of the Republican party) live in the fantasy land where money, and debt do not matter and the government can just spend spend spend, with no limit.
>>most notably Germany
I will believe it when they actually do it, they have been promising that for almost a decade now. They still have not promised 3%, only 2%, and they will IMO never get there.
I hope Poland emerges in EU leadership taking it from Germany
>> Russia spends 4.1%. Ukraine spends 34%
Now lets talk about corruption...
>That'd be an insane spending on defence
Maybe, but the US has been spending between 3-6% for decades building up the military to what is today, while the EU has been spending sub1% for those same decades, just matching US Spending is not going to cut it IMO.
Current US Military spending is at a all time low since WWII in % of GDP numbers, largely because the growth in the US Economy, in real numbers we still spend an INSANE amount of money.
There's currently some noise about costs because the president isn't Republican and it's an easy way to score asinine political points. None of that is coming from any sort of principled belief system, though.
I clearly said
>>*some* members of the republican party have long understood the fiscal reality, where the Democrats, (and other members of the Republican party) live in the fantasy land where money
See that second part, where "other members of the republican party" i.e the Bush "republicans"... the ones many refer to as "RINO's" in common political rhetoric today...
Republicans objecting to helping Ukraine because of cost are either blithering morons, compromised by Russian propaganda, or both. Take your pick.
Because that is what is happening today..
The same with Afghanistan. I disagree with Biden on many points but getting out of that country was the best possible course. Same situation as with Vietnam - with Taliban in power in Afghanistan there are zero negative consequences for US. What's more Taliban is apparently better than US or former "Afghan" government in suppressing actual terrorist activities that can threaten US.
Not every war is WW2 and struggle for world domination.
Maybe the problem is for people not realizing that they are dealing with 2 buttocks of the same butt. And it does not look like said butt is by the people / for the people. Instead of fighting between each other people could be better off doing something productive about it.
How is this possibly the case when there are vastly different laws and rhetoric from both sides? I get you are implying that both are there are too benefit the wealthy, which is true, but they also do other things that affect people. Abortion, gay rights, spending, taxation, gun laws. How are they the same???
Then you ask people to do something productive, what? Revolution? That will likely destroy the US economy and possibly the global economy for years. It will also lead to a large loss of life. There's also no guarantee what happens after will be positive. Look at France, post revolution they had a bunch of shitty governments/dictators and then the king came back.
So what are you suggesting?
Both sides are OBJECTIVELY not the same. You can easily look at voting history and see that, even if you don't believe anything you hear on the news.
Think long and hard whenever someone tells you this fallacy.
I also believe this is the goal of many of the "both sides" people. Since not voting benefits Republicans[1] I believe those people have an ulterior motive to help them win
https://www.nbcnews.com/politics/elections/supreme-court-gop...
Non-voters are people disgruntled with the current 2 party system, the largest voting block in that group are libertarian leaning people who do not break democrat.
Your link it talking about various voting laws, which largely impact densely populated cities, things like ballot harvesting, out-of-precinct ballot disqualification, and other such rules that have an outside impact on voters in urban cities which are largely democrat.
Very very different things / topics
There are no “voting blocks” in the group of non-voters.
But still clear what I was getting at
What about local elections, most elections are isolated to a particular area? The reason the Republican lawyer made that statement was to show standing. Meaning , why would the Republican party be effected by the various voter restriction laws. They said because it benefits them if voting rights are restricted.
If you are saying that the laws in question reduce the ability of democrats to vote vs republican (as in reduces the numbers more in cities vs rural?) What's the difference? I'm connecting turnout to their success.
Here's a more clear analysis though it is an opinion piece showing that young voter turnout is important for the democrats.
https://www.cnn.com/2022/03/22/politics/young-voters-democra...
The reason I used the Republican party's lawyer is because he was under oath and they wouldn't fight this case if it didn't benefit them
Since when productive means Revolution? Productive in my book means forming new party with the proper platform and winning the election. Meanwhile protests against most egregious actions will do.
>"It will also lead to a large loss of life. There's also no guarantee what happens after will be positive."
That had never stopped the US from instigating and supporting numerous revolutions and coups.
I mentioned revolution as an example. Forming a third party will cause one of the main parties, probably the one whose voters are least fundamentalist, to lose. That's what happened in the past.
Very recent past and they will do it again no doubts.
>"Forming a third party will cause one of the main parties, probably the one whose voters are least fundamentalist, to lose."
Well it is you country and you are free to maintain status quo.
Use direct democracy at the state level, where state constitutions provide for this, to replace single-member FPTP systems with multimember proportional systems, creating multiparty democracy, and then advance it state by state until it becomes a national norm.
None of those things are constitutionally in the power of the federal government, nor should they be. Those are state level issues.
…and also includes spying on EU citizens on EU (and the Five Eyes) leaders' behalf (aka "sharing intelligence"). Don't forget that data transfer to the US also provides European leaders a way to circumvent their own privacy regulations, which is unacceptable.
That's how European leaders saw IRA. They didn't retaliate because of the current context, but I find it surprising that US technologists are so oblivious to this kind of context, while resenting so acutely when US companies are asked to respect EU law.
From the Banana Wars for the American Standard Fruit company, to getting PTSD in Iraq to make Dick Cheney wealthier, to who knows where next to defend Meta.
Nothing has changed in America. The military umbrella is watered with blood of lower and middle class boys and girls, but only to project Tycoons and Billionaires.
They could repel NATO, but if Europe slides with China then things will look very shitty for the Western Hemisphere.
Yes, of course.
But I think you're pretty clear on the fact that it does. We live in a non-abstracted world of atoms.
In particular, the EU believes that by transferring personal data to the US, it could potentially be accessed by law enforcement/three-letter agencies without 'adequate' process.
More here: https://www.osano.com/articles/privacy-shield-invalidated#:~....
In short, the US does not have "a level of protection essentially equivalent to that guaranteed within the EU".
Let the service do what it does with least permissions. If something doesn't work there should be a settings where you opt-in. Don't block my view, hoping I will click the dark pattern as you want me to, believing I don't get anything if I say no.
That's not informed consent. That's consent under duress.
There will be some cases where you need to explain what's going on to a customer before they should be allowed to do stuff — medical, financial, probably some others too — but I think the whole thing is getting abused so much it can't stand, and the exceptions probably need a specific license already anyway, and that license can just also say "and you not only get to have the popup, you are required to".
Preferably half that.
(Advertisers are allowed longer agreements because they can be expected to hire a lawyer to explain stuff to them).
For me, this hits a more fundamental issue: how do we govern global issues without a global government?
Edit: fine, more Mars land for me!
A global government is an entirely logical next step and could be a very valuable asset when dealing with truly global issues.
Such an idea is centuries away in the best case scenario.
Yes, the UN does lots of things. But it has no power to do those things without the voluntary buy-in of member states.
What I believe is happening here is the EU is setting a new standard that the US and UK and others will have to follow if they want to do business in the EU, unless they invest millions in infrastructure and staff.
I believe the same happens in the US, one state such as California will make progressive law changes that force companies to just apply the same standards across other states as it's less legal and regulatory burden, so effectively one state can actually change the system for everyone, no global super government required.
This is another example of clueless EU regulators creating laws with no understanding of the implications
On-Demand, i.e., if one of your friends actually visited your "node" (profile or whatever) and also by following the law for the country the data originates from, no need to store anything in the target country – i.e., like most of the internet already works (or worked), it's really not _that_ hard.
> This is another example of clueless EU regulators creating laws with no understanding of the implications
Meh, maybe some are clueless, but one sees also a lot head scratching and scapegoating from people that don't bother to even think on solutions or what the actual laws are about (i.e., are themselves clueless about the actual implications).
It’s the perfect user experience!
It’s not about protecting all data. It’s about protecting personal data.
“which is any piece of information that relates to an identifiable person.”
And then if they do e2e encryption where the EU can’t get to it, that runs afoul of another proposed EU regulation.
https://www.politico.eu/article/eu-commission-violation-priv...
A very important aspect of GDPR is a consideration for the purpose of the processing of data. If your company is providing an international messaging service in order to harvest sensitive personal data from private messages, then yes that is very much illegal. But if the purpose is simply to provide a messaging service and you are taking the appropriate steps to secure the data of your users, then it is not illegal.
As said, it's really not that hard.
You do not, but that is not what the ruling is about. This ruling is about Meta using standard contracts (SCC) to achieve mass acceptance for personal data transfers of EU citizens out of the EU. Which you are not allowed to do with the GDPR. If Meta had obtained individual permissions from you on your various personal information, then it would not have been illegal for Meta to share your information globally.
This isn’t really about what you share on FB either, it’s about all the data that Meta applications gather about you (often without your knowledge) that they then send outside the EU with a very generalised permission that you probably auto-accepted when you signed up. It’s exactly because the EU regulators know that people auto-accept those general agreements without ever reading them that the law has been made to make such agreements non-GDPR-compliant. The reasoning is that you cannot sign away your rights without understanding what you are signing away, and if corporations don’t want to make sure you know what you are agreeing to then the corporations are in violations of EU law.
Seems like FB was storing a little bit more than just social graph and for a bit longer.
Why is it important that this can be done? The "social graph" is for the benefit of the likes of Facebook. You already know who your friends are and how to talk with them. You don't need a third-party social graph for that.
Especially for unilateral users of such software? (if I could convince fellow proprietary service-users to use some obfuscating software that generated/filtered a bunch of fake communications, I could just convince them to use Free software instead of the proprietary service)
That said, effective chaffing is difficult and does little to mask methods used to surveil or profile. It's also highly ineffective against strong-intent signalling such as purchase behaviours, unless someone is willing to buy items of little interest or purchase-and-return with sufficient aggressiveness to likely provoke not only vendor cancellation but fraud or criminal investigation.
Cory Doctorow from a Reddit AMA a couple of years ago on chaffing's ineffectiveness:
Chaffing turns out to be pretty easy to detect, because people aren't random - generating data that is both plausible and doesn't leak anything is really hard.
The most common solution to this from information theory is to broadcast a steady volume of noise that is sometimes mixed with signal: for example, you start a Twitter feed that tweets out exactly 280 characters of random noise every minute. Sometimes, though, you push ciphertexts into that stream. Your counterparty analyzes EVERYTHING you tweet, looking for data that decrypts with their private key and your public key. Adversaries can't tell who you're talking to, nor can they tell when you're talking.
This is much harder to do with something like your web traffic....
<https://old.reddit.com/r/privacy/comments/j444u4/how_to_dest...>
And it's even harder with purchase history, postal mail, or phone-call activity.
In practice, the method would be unavailable to much of the public, and of and by itself a strong indication of surveillance interest, much as use of, say, PGP is long reported to be.
I believe your comment is somewhat true, but in your examples with the EU and California it’s mostly the case where (one of) the largest market(s) is able to set laws that govern the entire world. Which is great if everyone also happens to agree with the law, but it’s not the most democratic situation.
We're not going to structure a global government, such a thing is never going to exist and we're never going to have to worry about it existing. Fortunately.
At what governance level would this be acceptable for you? The existence of political minorities is invitable. The question is where do you draw the line: street, block, postal code, city, metro, region, state, or nation? When is it ok to dominate others because they got less votes? The same issue is reflected in red states grabbing power from blue cities, with the implication that the state-level domination is A-OK.
> with the EU and California it’s mostly the case where (one of) the largest market(s) is able to set laws that govern the entire world
this is not likely to be solved by yet another layer of government.
I dont want to say, that fighting for privacy rights is a bad thing, but as small time entepreneur, they seems to be on same side.
You don't need to hire a team, just a company. A lot of companies offer this exact service now and effectively.
For example: Drata.
What would the appropriate way for meta to handle a friendship between a Texan and a European be? They can’t process the Texans data outside Texas, and they can’t transfer the Europeans data outside of Europe. Disallow them to be friends?
I assume here the EU can't do the same?
It never was about "where it is processed" but "who can access it".
This is from the European Data Protection Board FAQ following the Schrems II ruling. Does the text of the new ruling say something different?
> 8) Can I rely on one of the derogations of Article 49 GDPR to transfer data to the U.S.?
> it should be recalled that when transfers are based on the consent of the data subject, it should be ... specific for the particular data transfer or set of transfers (meaning that the data exporter must make sure to obtain specific consent before the transfer is put in place even if this occurs after the collection of the data has been made)
> With regard to transfers necessary for the performance of a contract between the data subject and the controller, it should be borne in mind that personal data may only be transferred when the transfer is occasional. It would have to be established on a case-by-case basis whether data transfers would be determined as “occasional” or “non-occasional”. In any case, this derogation can only be relied upon when the transfer is objectively necessary for the performance of the contract
https://edpb.europa.eu/sites/default/files/files/file1/20200...
The EU isn't saying that personal data has to be processed only in the EU. They're saying it has to be processed somewhere with adequate standards of data protection.
This doesn't work when a law doesn't allow some foreign company to escape, though. Suppose Texas decides that toy makers are liable for toys that hurt children. A Swiss company that makes army knives for kids decides not to sell to Texas, but other people buy some and then resell them in Texas. If the original manufacturer can't avoid the local government, that's more complicated.
Separately, while I'm all for internet privacy and am generally aligned with the _intent_ of GDPR, having had to meet its requirements at the highest level of scale, I have no qualms saying that it's truly a _terrible_ piece of legislation. Clearly whole sections were written without any regard for technical accuracy, and it leaves a number of ambiguities and contradictions within its language that continue to go without clarification. I don't feel like getting in the weeds here, but if you ever want to see people getting in the mud about how to actually comply with it, just go take a peek at the higher-comment threads in /r/GDPR.
Personally, I'd much prefer a cascading set of standards coming from a technically oriented consortium of (ideally OSS) folks that could be enforced from the client side as much as possible, and then independently audited on the server side (like a UL certification, but for your server architecture). Most of us here are probably already using a ton of client extensions to enforce as much privacy as we can without breaking things, and if an OSS auditing standard came along for servers, it'd be sweet if I could e.g. set my browser to "EU data servers only" and have my browser give me an option to explicitly override it if I really need to (like we do today with bad SSL certs).
As for the data export and deletion controls...I get the argument that's only enforceable via regulation and government enforcement. But given the ease of data replication and laundering (made even easier in a post-ML world), I'm not optimistic that you can actually "catch" people violating it except against the absolute largest corps ("yeah, we totallyyyyyy deleted all your data, for sureeee"). Feels like it's enforceable at about the order-of-magnitude of insider trading in the US.
I almost bought a car from Carvana. They had all my info: driver's license images, SSN, etc. At the last minute they required a DocuSign signature, which I told them upfront I wouldn't use, so I canceled the deal.
Afterward, I told them I wanted all of my info deleted since we didn't do a transaction. They said they could only do that for CA residents. A CA law is not going to cause companies to follow that law for all US citizens if it's to the company's advantage not to follow it.
That’s called the Brussels effect (https://en.wikipedia.org/wiki/Brussels_effect), and indeed is similar to the California effect (https://en.wikipedia.org/wiki/California_effect)
By consensus. By willing participation of all. By individual countries actively deciding to operate in the agreed best interests of the whole. And when countries act egregiously badly, subsets of the larger group band together to employ military force against them. Government can exist without rigid structures. The enforcement of norms by the collective is a form of government. This is what they mean when diplomats speak of threats to the "international system" even though we lack any official world government.
Not every "enforcement of norms by the collective" (what's the collective?) can do that.
Imagine coding a program and there are no variables or methods with global scope. If you want to know the number of users in the program, you have to add up all the user variables from each object and each object defines a user in a different way. Also, to access the user variables in each object, you need to use different methods. Now imagine there are 190+ different objects. Some are similar, some different, and they are constantly changing in their structure.
How would you be able to run global functions?
I imagine having standardized ways to access the objects (variables and methods within) could really help improve the program.
If those 190+ objects are not objects but libraries with different developers and different API structures and maybe languages, it can get even more complex without some coordination from a higher-level perspective.
How does that analogy land for you?
1. Hitting the big companies for the minor violations is a bit like arresting the mob boss for tax evasion. It's a lot more black and white than arguing whether they performed the right balancing test for legitimate interests (though actually they have previously been hammered for that one too).
2.
> Where data is processed should not affect the care with which it is processed.
This is true, but it does affect the conflicting requirements it may be subject to. After all the Snowden revelations, it's clear the US data privacy regime is not sufficient, as the US government will take what it wants, and that's why transfers regimes to the US are repeatedly struck down.
Data privacy? That is definitely not what most people are talking about when they critique facebook. The free speech & misinformation lines of thought are directly in conflict.
So while the contemporary US discussion is far more dominated by elderly consuming political content, that doesn't mean nobody cared about privacy. You just need to see the furor about Cambridge Analytica or the Snowden leaks to see that that is a concern.
A whole lot of people are talking more about data privacy than free speech on Facebook, though. Is one discussed more than the other? I don't know -- but I suspect most are talking about neither, and which group appears to be the majority depends on which group you tend to hang around more.
The perfect user experience!
So in this context is your con really a con?
For a contact in an email adress book, that makes sense. But for a "friend" relationship in Facebook, which side owns that edge? Or how about a message sent from someone in the EU to someone in the US, who owns that, the sender or the recipient? And if it is just one, does that mean that different messages for the same conversation have to be stored in different regions?
Now is this technically optimised (for the company) - no and irrelevant (IMO) in the context of how much control/power a user has. You could extend this to messages too. What messages I sent, what messages I received. I didnt send it - I dont own it. What about shared documents you say? Here users are explicitly sharing with other users for collaboration (the contents of said documents totally are of no business to the company).
See providers are providing a service(?). If the services needs to harvest data I still question who is benefiting from that harvesting? If the user is not actually seeing value (apart from subsidizing the cost of the internet) are we then not just using technical/UX complexities to justify a low-value (to the user) solution?
I don't see where there's any ambiguity on this issue. Each individual has the right to not be subjected to spying and monitoring, which includes collecting personal and private information. A social graph is not a data dump where you are a mere drop in the ocean. A social graph is an ocean of personal and private data collected from you. Therefore, it's quite obvious that individuals have the right to not have all this ocean of personal and private data collected on them, specially without their explicit and informed consent, and they should have the right to force anyone to delete this info, both all or subsets, automatically and reliable and verifiably.
Just because I don't mind hearing what my aunt has to say about what she baked or who she chatted with, that does not grant you the right to get my credit score or where I went to highschool with or who I met years ago or where I lived, just because third parties and other edge nodes in a social graph posted that information and data that enabled you to piece it together. What is there to be discussed?
Alice tagged you in a photo with Bob
Bob liked the photo
Now, let’s say Alice and Bob are both EU citizens, and I live in the US.Can Facebook tell me that Alice tagged Bob in the photo? Can Facebook show me the photo I was tagged in? Can Facebook tell me Bob liked it?
and you are aware the NSA has far reaching access into the FB data pool?
this possibility to filter out "the gays" or "the trans" mixes very poorly with say, DeSantis or Trump concepts of a clean and neat and ordered country.
_that_ is the concern of the EU.
the perfectly legal processing of personal data in the US, which is meeting all US regulations. "Kleinman. ls that with an ''ei'' or an ''ie''?"
we may agree to disagree but I think this is orders of magnitude more concerning than microtargeting political campaigns (brexit & co)
and _that_ already is bad.
https://policyreview.info/articles/analysis/regulation-onlin...
Not with US laws. The whole problem are US laws essentially allowing government to force any company to disclose whatever they need with little reason. That's the problem. That the moment data are processed by US company (not even neccesarily in US), US government have right to violate privacy
It would be great if the US (and Chinese) governments didn’t act in this way (I’m sure the EU would act in the same way if they had tech companies) but it seems to be their nature.
No, the problem is that the US has specific laws that allows the government to require companies to secretly violate privacy, and punish them if they refuse, or even for just disclosing that the request was made.
The administrations of china and the USA are different of course, but not so different. The big difference is in the institutions and norms.
Transferring the private data of EU citizens to China or Russia would also be a major crime.
> The big difference is in the institutions and norms.
In theory yes; however the US has a strong norm of following the letter of the law, so what the letter of the US law says is important.
There will be no consequences whatsoever to anyone involved. The laws are for you to obey and for them to prosecute you, not the other way around.
But I'm curious if you explicitly believe that EU/EEA member countries unilaterally _don't_ spy on their citizens. Because I'd be inclined to say that's unlikely (at best) given what we know about the nature of intelligence organizations, namely that they're basically data lake vacuums in the 21st century.
The US has laws that give them the legal right to snoop on any data about EU (avd other foreign) citizens.
Those laws make it impossible to follow EU privacy laws as a US company.
One of the two have to give, and the US should make exceptions for EU citizens, or rescind the CLOUD act.
It's frustrating how many people are stuck in this loop, where they think any company can "easily" follow GDPR by just swapping data regions with their cloud provider. It's not that simple and never was.
This is a broader political spat between two of the largest government bodies in the world, not about facebook.
The EU is not the global privacy champion everyone makes them out to be. They just don't like that US companies can access EU citizens data specifically (since most of the internet is run by US companies). Whether they're okay snooping on their own citizens themselves is a separate issue--they've also regularly challenged encryption domestically.
I'm also certain the EU is not upset that certain 3 letter agencies in the US have access to Russian's private data when in the context of the war in the Ukraine. Like all governments, the EU only cares about their own interests, not about the philosophical idea of privacy in general.
Now imagine micromonoliths with shared data. Much more soothing IMO.
I want microservices where appropriate, and I want my world global. Geographic boundires outlived themselves.
Then people would notice how laughably small those fines are.
> Meta was fined 12 hours of revenue for violating your fundamental human rights for years of profit.
2022 Meta revenue was 116 billion USD [1]. So the fine was 1.1% of yearly or revenue, or pretty close to 4 days of revenue.
In terms of yearly net income, it is 5.6% or 20 days of income. Don't think this is a trivial fine.
[1] https://www.statista.com/statistics/277229/facebooks-annual-...
You can't really fully seperaten EU revenue. I as a European write very intelligent and relevant posts on Facebook, thus people from other regions go there to read them. (well, I don't post anything on Facebook these days, but the point stands)
If Meta made zero money in EU whilst still offering a service to EU users, and still exfiltrating their data, should the fine be zero?
A few years ago I was on around AUD90,000 and driving my wife's car which to me she had failed to register.
I got a AUD990 fine.
So I equate this fine to Meta getting busted for driving an unregistered car.
Not even close to a drink driving charge.
This "fine" just feels like "cost of doing business in the EU" to me...
Ok, realistically it's unlikely to happen exactly that way, ...
Nothing to do with taxes.
It's not off topic at all.
> unlike the US they largely enjoy that right thanks to laws which are enforced
This is categorically not true.
Facebook also has private messaging.
But to play along, what happens to the data depends on where it is stored. If the data center is in the US then the government can get a court order to seize that data. Which is not the same as in some other countries, is it?
If companies view it as cost of doing business, it's akin to a tax and the rights you hold dear are not respected
The people on the ground didn't do anything with this
GDPR laws are so popular that 17 countries outside the EU already have similar laws.
For example now random security camera operator can't just take some scenes and post it on youtube, as that would violate GDPR in several ways and few companies paid tens to hundreds of thousands in fines for that.
It also cut sooo much bullshit when it comes to PII management. Because there is actual teeth behind it very little companies will try the old trick of "oh you wrote email to us ? Let's just send marketing stuff on that", as that would require separate consent.
Of course we all find tech valuable, but that is absolutely stupid money for what I get out of their services, which is almost nothing hence I've not opened FB for weeks and I open Instagram for 2-3 minutes every day and turn it off, lately maybe every other day.
Even with more engaged users it's hard to believe it's worth that much money. Is the advertising really this effective ? Insane.
That's why it's a free product! Revenue is from the value they deliver to advertisers. Meta's average revenue per user is significantly higher than other ad platforms (except Google).
For someone selling to a particular group of people, getting ads to that specific group, and ONLY that group, is really valuable.
Actually meta had bigger year last year so a bit less than that.
Cost of business ?
https://noyb.eu/en/edpb-decision-facebooks-eu-us-data-transf...
So, the fine is ridiculously low. 130 million per year?
Would I enjoy it? Certainly not.
Would I change my behavior if it was generating billions in revenue? Certainly not.
How is this supposed to dissuade FB at all?
If my company transacted $1T in some boring business model that netted a few million to the company coffers and employee pay then fining me on the $1T would simply wipe the company out many times over
It obviously doesn't work.
So in Amazons case you absolutely see a fine greater than their net income, but still only 1% of their revenue, and obviously such a fine would have a greater impact on Amazon than the equivalent 1% fine applied to Facebook.
What if your company is set up with the usual tax tweaks where all net income is zeroed out by some licencing agreement about hand-wavy IP from a sibling company in the corporate family?
Taking it a step further, will you get a fine-back as a reward for breaking the law if your accountants manage to declare negative income?
I think the GP meant that you should see the fine in relation to the net income, rather than that the fine should be computed in terms of the net income.
E.g. if a company has 100b revenue and a net income of 4b, then a 1.3b fine has a large impact. If a company has a net income of 50b, then 1.3b is peanuts.
(I don't necessarily agree, but just elaborating what they probably meant.)
Whatever ills people may ascribe to Meta, EU DPAs aren't in the business of social activism, or taking their annoyance out on multinational corporations. The job is to get Meta to comply with GDPR. If that fine will do the trick, mission accomplished. If it won't, the next one will be bigger, and then fining will continue until compliance improves.
(There's a sub-story here about Irish DPC, but that's orthogonal to the size of GDPR fines issued.)
Comparing to revenue is a stupid way to think about things. Profit is the incentive to conduct business. Not revenue. And not global profit, but in this case Ireland/EU profits only, because that is the location fining them.
People are so eager. Every. Single. Time. To say that a fine does not matter even if it clearly outpaces multiple years of profits for the area given.
Because it is and it isn't. Companies can make people filthy rich while not making a single dollar of profit thanks to the stock market where the price does grow, broadly, in terms of revenue.
Talking of the future doesn’t help much because both numbers will change. And punishing a company based on its future state is… not possible
Yes, the fines are small enough that they are normalized by the violating corporate as just as small additional cost of doing business. A dramatic negative externality gets trivialized. The signal to other corporates is: go ahead feasting on the corpse of user privacy, just do a proper cost-benefit analysis.
But, these fines are legal events, in jurisdictions that are relevant to large numbers of people.
The common argument "people don't care about privacy" is more truthfully "people assume that widely popular online businesses are legal and ok, since services that are not ok are generally not allowed to operate". In fact, when all sort of public institutions are actually on facebook (and other adtech platforms) and even encourage people to join and interact there, they actually endorse that implied legal status. This has been a fiasco that has cut to size any "proud" democracy out there.
News headlines of legal fines help puncture that implied institutional endorsement. The average user doesn't know that the fine is just 12 hours of revenue. They actually have no clue what sort of lucrative business is running behind their backs and against their interests. Using these legal events, provided they get some press, does help the argument of those pushing to use (where available) privacy-respecting alternatives.
Of course such is the ability of the public to get desensitized to any uncomfortable truths that eventually that effect will wear out too.
Non-compliance just causes another fine. So they could be up to 8% of turnover (not income) a year
- EU fines a company a small percentage of its annual revenue. "Laughably small", "cost of doing business", EU has no fangs, blablabla.
- EU fines a company a large percentage of its annual revenue. Damn EU bureaucrats, trying to make money on the back of hardworking US multinationals, zero innovation over there so they steal from America, blablabla.
What do you want? For the EU to impose such large fines that they put every tech company out of business? No one wins at that game.
Does it seem ridiculous at the edges? Sure, but it also makes the fine an actual punishment for all rather than a rule that the better off can afford to ignore. This is true even in the case of driving laws. Sure, you might lose your license regardless of finances - but only one of them can fairly easily afford the reinstatement fees and the extra costs of not driving.
[1]: https://www.euronews.com/2023/01/04/finlands-progressive-pun....
Maybe it is (or maybe folks disagree with the UN on privacy) but people should actually make that case instead of treating it as self-evident.
Probably a lack of integrity.
Facebook/Meta are at the "cigarette company fighting for its right to operate" stage of its existence. They know they prey on people, and are ultimately "responsible" for a coming mental health crisis, disinformation, and potentially worse in some countries.
My bet is, just as with cigarette and oil companies, we will discover in 30 years time that Facebook had unpublished research into just how bad for the world some of their activities are.
0: https://www.bbc.co.uk/news/uk-60410636
> The move puts the former Lib Dem leader on a par with Mr Zuckerberg himself
> Mr Zuckerberg said Meta needed "a senior leader at the level of myself... who can lead and represent us for all of our policy issues globally".
Ahem...
Facebook researchers have found that 1 in 8 of its users report engaging in compulsive use of social media that impacts their sleep, work, parenting or relationships, according to documents reviewed by The Wall Street Journal.
https://archive.is/zhGBCMaybe data privacy turns out to be the "lower receiver" of social media but I doubt it.
https://www.theguardian.com/politics/2015/may/12/nick-clegg-...
The Lib Dem’s then made the fatal mistake of actually making it into government, which they obviously never anticipated happening when they originally made the tuition fees promise.
Personally I think Clegg and Lib Dem’s did a fantastic job of reigning in the worst aspects of the Tory party, and the UK public raking them over coals for tuition fees has only benefited the Tories by removing the only thing that stopped them going off the rails completely. Which of course happened immediately after the Tories got rid of the Lib Dem’s and we got Brexit a year later
https://en.wikipedia.org/wiki/2011_United_Kingdom_Alternativ...
It was an absolutely extraordinary level of bullshit, especially the ads trading off changing the voting system cost vs NHS funding, which was really a prelude to how bad the Brexit debate would be.
I'd like to know what the fantastic job they done was, because if it's solely holding off a Brexit situation for 5 years I could argue their relatively weak opposition whilst in coalition actively enabled a shift further to the right and their extremely weak position by 2015 allowed Cameron to be so assured of the centre-right vote that he could court the UKIP vote with a referendum he assumed would never pass.
He did get voting reform to the point of a referendum in the UK at least, which regardless of how badly it was executed is something (and I don't think I can blame him for that too much, it was doomed with the UK's media), it's just a shame that seems to be the entirety of what he managed.
-- Upton Sinclair
There are good odds that a sociopath will start to show up...and who wants to tell others how to live their lives....sociopaths and antisocial people....great choice of leaders but time and again...they lie and cheat and steal and make sure they look good for the pictures....so you elect them to give themselves raise, increase homelessness, increase poverty and spread policies that kill.....and enslave the future.
If a Facebook user in the US are friends with a user in the EU, how are they able to communicate and share profiles without transferring data from the EU to the US?
I bet you could find a dozen or more websites summarizing your legal obligations if you wanted to create one web page.
Since the context was Facebook, I was speaking about what businesses should do. And especially large businesses. As far as I've heard, the EU isn't chasing folks who run a small website.
But they could, which has already had a chilling effect on small businesses. Even though the intent (and current enforcement) is to punish large companies, GDPR is written in a way that puts a large compliance burden on many small companies and startups.
Doing your accounting, paying taxes, and following labor laws are also burdens on small businesses. Not every small business is profitable enough to manage those things and that's ok.
Collecting that data on a web page is a choice.
A semi-hidden security benefit of GDPR is that it makes people think twice before collecting and keeping data - you can't leak data that isn't in your database in the first place.
Now "Talking over Facebook messenger" is a complete change of subject.
It is on Facebook, not you, to operate Facebook messenger in a legal way.
Facebook has not claimed it's not technically possible.
Yeah, it does. A person in the US is not a server in the US. It's an iPhone in the US, not a server.
Does it really take that much of a leap of logic to understand that the server doesn't have to be on the same continent as the user?
There's a word for businesses that are systemically unable to comply with the law.
I don't know if Facebook is one of those, but it might be. Shutting down is always an option for that kind of company. Nothing of vale would be lost.
You really don’t see the added complexity of this and how this makes a worse user experience?
Do you think the overwhelming amount of people say that they really glad that cookie banners infest the internet is a good thing?
If you haven’t heard, Apple is not exactly great at social media or anything that your data needs to be synced between devices.
Just as Facebook must obey Apple's rules if they want to be in the app store.
Similar privacy laws applied to some EU phone companies long before Facebook existed.
These laws are good and should stay. If better privacy has side effects, that's fine. Do business elsewhere if you don't like the legal preferences of the locals.
And you never answered the question, how do you have a social graph with people in the US or send messages to people in the US without storing data in the US?
Not my problem how you implement it. That's Facebook's problem. My rate is $600 an hour and I'll guarantee I can come up with a GDPR compliant solution within a year or you don't have to pay. That's far less expensive than the fines, isn't it?
Just maybe the EU regulators are technologically illiterate?
And I see that you also punted because you know it’s impossible
Of course they are because
1) all regulators are technologically illiterate, these are not exceptions
2) regulations of this kind are fundamentally about people not microchips. They talk about results to people, not coding constructs or network topologies. If it's technically possible to do it, but not technically possible to do it legally, then maybe it's a bad thing and don't do it at all? If there's a new technology, is it exempt from current standards? Would you say, "hey, new weapon invented, it's legal to murder people with it!" ?
NB: I'm fairly certain that Instant messaging can be done legally; what maybe can't and shouldn't be done legally, is the FB business model of monetising user data over that. IDK why someone would defend it so strongly.
And some US state is banning one app rather than trying to find sensible privacy protection that applies to any app.
I'm not sure of your point, TBH. It doesn't follow at all from the above.
So it follows that you are against W2s encryption because it will be impossible to do securely and allow a backdoor.
Bluntly said: IDGAF, and neither should you. Who cares if it's harder for facebook/meta to program? Must we waive our rights because of incompetent or cheap engineering?
You didn’t waive your rights. You as an adult have the right to not use Facebook instead of waiting for the nanny state to “protect you”
> nanny state
Sadly, technology is nearly incomprehensible to most people, and the state must protect their rights. The rest is either an authoritarian or libertarian fantasy under the pretense of liberty.
So I’m sure you’re in favor of Apple’s “walled garden” to protect ignorant users, you want to make alcohol, cigarettes, sugar and everything else illegal that’s bad for users?
It’s sad that so many people are willing to give up their own agency because they don’t trust themselves to make intelligent choices.
We give up a bit of control to avoid losing more. That's a social contract that has worked very well, and I'd like to keep it that way. I'm sure you also benefit from it.
You lose no control by not using FB.
As I remember, the EU-US data sharing agreement was killed (Schrems II) because of the US CLOUD Act, which infamously doesn't care where the data is stored - as long as the company is under US jurisdiction, it has to let the government snoop at will.
So, it seems to me that Facebook putting data on EU servers wouldn't matter? A three-letter agency could still go to their SV office and legally demand "give me an API key to query through your Irish datacentre and don't tell anyone". To protect EU citizens from that, the Facebook servers in the EU should treat non-EU FB servers exactly like third parties, using OAuth or similar restricted access protocols.
Try to have an EU tech scene without Microsoft, Azure, Google, Google Cloud or AWS. Or Salesforce. Datadog. Etc
It will take time until this one get enforced.
https://www.privacycompany.eu/blogpost-en/new-dpia-for-the-d...
But the legal situation is such that a controller needs to be very precise about what they transfer and how they justify doing that. Which is difficult, which is why there has been so much noise about trying to find something that again lets companies just say "processing in the US is possible under the same standards as in the EU, so we can do all our processing wherever we think is convenient", which saves them a ton of work. But I'd expect until the US is actually willing to make legal changes any such thing will be rightfully rejected by the courts again.
If a Facebook user in the US is friends with a user in North Korea, how much data are the North Korean authorities allowed to get on that US user?
Aside from the fact that Facebook has no presence in NK (hence the stretch), the answer quite likely is "none".
You can hypothetically have a case were two jurisdictions both demand that data be stored locally.
Let’s make the biggest social networks Meta, TikTok, etc incur fines in the tens of billions for every investigation of significant privacy violations (like Meta’s existing case) of its users and pay back their users in compensation over that until the company either changes or exits the market the regulators reside in. This is far better than a ban and the regulators and users get free cash out of it.
Given that we have the regular ‘all social networks do this’ excuses on collecting data, the standard for large social networks in the 1B+ daily active users collecting user data should have much larger fines in the billions.
The idea that it 'wouldn't be tolerated' suggests - correct me if I read this wrong - that the country where the company originated would then do some kind of tit-for-tat with companies from the other country. But: where were those comments when VAG and other car manufacturers broke the law in the US? (and probably elsewhere too?). My position hasn't changed, they deserved their comeuppance as much as FB does right now.
'Meta didn't actual do anything wrong' -> they did.
Facebook has worked the same way for more than a decade. First EU law changed and it was fine because the US and EU had a data sharing agreement, then US law changed. If you what Meta did wrong is not completely rearchitect Facebook in response to a US/EU squabble then your bar for right and wrong is really really low.
There's a lot of things you can point to that Meta does that are shady, but they thing they actually got fined for didn't have to do with any of them.
Funny, this is essentially what happens with tobacco taxes. Cigarettes are prohibitively expensive and thus have caused that industry to falter in the US.
Technically, you're correct they aren't, but how realistically are they are any different? In both cases the government profits from a corporation's behavior.
If Meta are relying on SCCs to safeguard against the transfer of cross-border data processes from EU to US, the same clauses which was recommended by the CJEU from the Schrems II case, what is the legal challenge?
Does anyone have any links to the actual decision so I can read the technical points of the judgment?
Here is the official decision, it also summarises the dispute.
From the press release:
> The inquiry was initially commenced in August 2020, and was subsequently stayed by Order of the High Court of Ireland, pending the resolution of a series of legal proceedings, until 20 May 2021. Following a comprehensive investigation, the DPC prepared a draft decision dated 6 July 2022. Notably, it found that:
> 1. the data transfers in question were being carried out in breach of Article 46(1) GDPR; and
> 2. in these circumstances, the data transfers should be suspended.
Based on the EDPB Decision [1], it seems the most weight of the decision is from paragprah 107:
> As explained by the EDPB in its Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data (hereinafter ‘EDPB Recommendations on Supplementary Measures’) 243, when assessing third countries and identifying appropriate supplementary measures, controllers should assess if there is anything in the law and/or practices in force of the third country that may impinge on the effectiveness of the appropriate safeguards of the transfer tools that they are relying on 244. In this regard, the EDPB notes that, according to Meta IE’s assessment, ‘the level of protection required by EU law is provided for by relevant US law and practice’ and that Meta IE implemented supplementary measures in addition to the 2021 SCCS in order to ‘further ensure that an adequate level of protection continues to apply to User Data transferred from FIL to FB, Inc’ 245 . In other words, Meta IE has implemented supplementary measures on the basis of an assessment which concluded that there was no need for such measures, since, in Meta IE’s view, the relevant US law and practice were already providing a level of protection equivalent to the one provided under EU law
My follow on question, let's say they understood the risk, I fail to see any safeguards which could be equivalent to the EU law? FISA 702 + other intrusive surveillance laws basically make this impossible.
So it seems that because Meta:
> seems to identify its own test for determining suitability of supplemental measures by lowering the standard to include measures that can “address” or “mitigate” any “relevant remaining” inadequacies in the protections offered by US law and practice and the SCCs’ 249, and concludes in the Draft Decision that ‘Meta Ireland does not have in place any supplemental measures which would compensate for the inadequate protection provided by US law’
I'm just confused what would have been sufficient for Meta in this circumstance?
The decision continues in paragraph 121 to say:
> In this regard, the EDPB recalls that the IE SA carries out a detailed assessment of whether Meta IE implemented supplementary measures that could address the inadequate protection provided by US law 273. More specifically, the IE SA analyses the organisational, technical and legal measures implemented by Meta IE and concludes that these measures cannot, ‘whether viewed in isolation, or in tandem with the 2021 SCCs and the full suite of measures outlined in the ROS’, compensate for the deficiencies identified in US law and cannot provide essentially equivalent protection to that available under EU law 2
I am aware of zero technical and organsiational measures which could protect against 702 FISA DOWNSTREAM (PRISM), short of not transfering the data to US?
Thoughts?
[1]: https://edpb.europa.eu/system/files/2023-05/edpb_bindingdeci...
There are no other real way.
What would have been sufficient is to process all data in EU jurisdiction and transfer HQ to equivalent country.
If they do not, why would the rest of the world let them interact with them and endanger everyone?
After that we can extend to deeper Human Rights but let's start with the basics.
An unofficial summary[1] of Schrems II doesn’t put it quite like that: Schrems II invalidated Privacy Shield, did not invalidate SCCs in general, but said that the latter are only valid insofar as they can provide EU-mandated privacy protections given the legal regime of the destination country.
Arguably, because of the last point, a US company is incapable of entering a contract that provides such protections: they include judicial review of privacy violations, while US law says that noncitizens don’t have standing to sue over those for surveillance under the FISA mandate (expires this December but will probably be renewed).
[1] https://gdprhub.eu/index.php?title=CJEU_-_C-311/18_-_Schrems...
And HN thread for that link: https://news.ycombinator.com/item?id=36029050
That's a slap on the wrist: it's cheaper to pay the fine than to follow the law. The correct amount of money for a fine is a multiple of the amount of revenue gained from ignoring the law. I don't know what that is in this case, but I'm fairly certain it's at least an order of magnitude larger than $1.3B.
Reading the comments on this thread makes me wonder how many commenters have been close to real company operations in the past.
A fine of even 20% of revenue would basically kill any company, big or small.
And we are talking revenue, not profit.
> big or small
That's exactly the point. Flat fines (not saying $1.3B is a flat fine, in this case) only kill small companies and act as a small "break the law fee" for big companies.
> And we are talking revenue, not profit.
Right, you cannot fine based on profit, because profit is a gameable number (Hollywood Accounting).
I'm not actually saying $1.3B is the wrong number: it's possible that's 3x to 5x of the revenue they gained from brazenly and wantonly breaking the laws of the country in which they operated. I haven't done enough research to say. What I was responding to was this:
> I do not think there is any amount of money that could be fined that HN commentators would not call a slap on the wrist.
Most fines for most offenses against most companies are slaps on the wrist, because they are less than the gain. This is why.
> I can’t tell if you’re trolling
This is a bad-faith attempt to dismiss an argument without considering it.
If a company breaks the law, it gets to continue to break it by paying some money. And claim that doing wonderful technological development and innovating shit.
I mean, if I have the option to get a get-out-of-jail card for 20% of my income I'd probably take it.
Except courts repeatedly mentioned that US law does not provide the necessary protections for non US citizens rendering all these statements invalid. The root of the issue are the FISA courts.
TIL that ACLU filed[1] a motion in the FISC to have its pre-2015 precedent-setting decisions released (post-2015 the USAFREEDOM Act makes such release mandatory); FISC denied jurisdiction (aka “go tell Congress to fix their stuff”, which I suppose is OK?), FISCR as well (same), the Supreme Court refused to review that (?!..).
[1] https://www.acludc.org/en/cases/re-opinions-and-orders-court...
The non-US citizens thing is a related issue[1], but it's not what started this current row of GDPR export lawsuits. However, I don't see the EU courts letting this go until and unless the US and friends drop the whole "noncitizens don't have rights" shenaniganery.
[0] https://en.wikipedia.org/wiki/American_Service-Members%27_Pr...
[1] Five Eyes - effectively the Anglosphere's spymasters - realized that if you say "only citizens are protected by privacy law", then nobody is protected by privacy law, because you can hire your allies to infringe upon your own citizens' privacy.
If someone doubts the legality of a request they should be obligated to report it internally to a member of a formal organization like lawyers and doctors have. Lose their title if they do not act on a report along with fines and prison sentences. Long prison sentences if they are new.
We pay the giant salaries to people with great responsibilities. Why would we shield them from responsibility? They should earn even more and have even more responsibilities.
It sounds like a blunt weapon but people are asked to do things that could have terrible implications all the time. With each data breach [for example] there was a dev who could have said no. It should have just enough personal implications to at least report it internally. If legal wants to stick their neck out for it personally the dev and their management are off the hook.
A few years back companies here were forbidden to pay speeding tickets for their employees. It was funny how some got a bill in stead of a pay check.
And further that there are probably a lot of GDPR violations going on in the U.S but those are obviously harder to actually enforce (GDPR enforcement is already a big issue _within_ the union).
Without a footprint in the EU, there is no legal action the EU can take against a foreign organization. Sure, the EU might ban your organization from operating legally in their markets, but again, there is no legal recourse for the EU. You might as well circumvent the ban too.
I’m thinking for startups, maybe default to servers in EU. Until you get big enough where you can handle complex geographical distributed infrastructure.
This statement had triggered Mark Zuckerberg to the core that they became foes over the disagreement [1].
[1]Breaking Point: How Mark Zuckerberg and Tim Cook Became Foes:
https://www.nytimes.com/2021/04/26/technology/mark-zuckerber...
Given that Meta has gotten another fine in the billions it is time for another privacy violating social network that has done similar [0] [1] and even worse privacy violations [2] [3] than Meta, and that is TikTok, which should also be fined in the billions just like Meta.
[0] https://www.independent.co.uk/tech/tiktok-user-data-europe-u...
[1] https://theguardian.com/technology/2022/nov/02/tiktok-tells-...
[2] https://www.buzzfeednews.com/article/emilybakerwhite/tiktok-...
[3] https://futurism.com/tiktok-spy-locations-specific-americans
The second consequence is that they have to stop doing this, which is far more damaging than the fine.
They can appeal it to hell and back and negotiate installments. They can do a lot.
They already have a legal team. This is just the cost of doing business.
Meta is a tumor that has to be cut down from society but I think we all know it's not happening. Either too much money is promised through lobbying, or the policy-makers are asleep at the wheel.
Facebook did pay 725 million out of the original 5 billion to the FTC over Cambridge Analytica's scandal. That is a hefty fine still. [1]
Another $122 million out of $276 million over Whatsapp merger [2]
Granted, it does get negotiated down, but it really is the most they can do.
[1] https://www.bbc.com/news/technology-64075067
[2] https://www.reuters.com/article/us-eu-facebook-antitrust-idU...
"What has happened before will happen again. What has been done before will be done again. There is nothing new in the whole world."
Microsoft was also once a plucky young startup. And Apple, and Oracle, and Dell, and…
True, and exactly because of that they have much more leverage.
The only true wind shift would be for the regulators to get sick of their crap and start hitting hard at the first sign of misdemeanor. And that's the part I am skeptical about.
Can they, though?
Placing sanctions on owners and board members might be more effective. And goverments appear to use that tactic more and more.
> Facebook owner Meta Platforms was fined $1.3 billion by European Union privacy regulators for sending user information to the U.S., according to people familiar with the matter, a record for the bloc.
> The ruling, expected to be announced later Monday, raises pressure on the U.S government to finalize a deal that would allow Meta and thousands of multinational companies to keep sending such information stateside.
> Updates to follow as news develops.
FSVO "funny". You have indeed quoted the entire article.
It seems to be a diplomatic way to handle this thing.
I'm Not Saying Let's Go Kill All The Stupid People… I'm Just Saying Let’s Remove All The Warning Labels And Let The Problem Sort Itself Out.(1) https://www.nbcnews.com/business/autos/judge-approves-larges...
Already, the EU is mostly a breeding ground for talent that is then extracted by the US. The more hostile and bureaucratic they become, the grater the pressure for the talent to leave.
It may appear that what the EU is doing is being hostile to US companies - and some individual US companies will indeed suffer. But the actual effect is to incentivize these companies to extract talent out of the EU as an insurance plan in the event of a pull out.
I work for a European tech company, and we have a noticeable uptick of American applicants over the years. Common (as in: almost every time) interview questions I answer are "Is it safe there? I work in [say, Portland] and we had just had gunshots again across the street" and "Can my kids ride the subway alone?". Colleagues who made the leap tend to tell me they are "glad they got out".