This is another example of clueless EU regulators creating laws with no understanding of the implications
This is another example of clueless EU regulators creating laws with no understanding of the implications
You do not, but that is not what the ruling is about. This ruling is about Meta using standard contracts (SCC) to achieve mass acceptance for personal data transfers of EU citizens out of the EU. Which you are not allowed to do with the GDPR. If Meta had obtained individual permissions from you on your various personal information, then it would not have been illegal for Meta to share your information globally.
This isn’t really about what you share on FB either, it’s about all the data that Meta applications gather about you (often without your knowledge) that they then send outside the EU with a very generalised permission that you probably auto-accepted when you signed up. It’s exactly because the EU regulators know that people auto-accept those general agreements without ever reading them that the law has been made to make such agreements non-GDPR-compliant. The reasoning is that you cannot sign away your rights without understanding what you are signing away, and if corporations don’t want to make sure you know what you are agreeing to then the corporations are in violations of EU law.
Why is it important that this can be done? The "social graph" is for the benefit of the likes of Facebook. You already know who your friends are and how to talk with them. You don't need a third-party social graph for that.
On-Demand, i.e., if one of your friends actually visited your "node" (profile or whatever) and also by following the law for the country the data originates from, no need to store anything in the target country – i.e., like most of the internet already works (or worked), it's really not _that_ hard.
> This is another example of clueless EU regulators creating laws with no understanding of the implications
Meh, maybe some are clueless, but one sees also a lot head scratching and scapegoating from people that don't bother to even think on solutions or what the actual laws are about (i.e., are themselves clueless about the actual implications).
As said, it's really not that hard.
It’s not about protecting all data. It’s about protecting personal data.
“which is any piece of information that relates to an identifiable person.”
A very important aspect of GDPR is a consideration for the purpose of the processing of data. If your company is providing an international messaging service in order to harvest sensitive personal data from private messages, then yes that is very much illegal. But if the purpose is simply to provide a messaging service and you are taking the appropriate steps to secure the data of your users, then it is not illegal.
The government hates competition. Only they should have the right to do that and force back doors on encryption standards…
And then if they do e2e encryption where the EU can’t get to it, that runs afoul of another proposed EU regulation.
https://www.politico.eu/article/eu-commission-violation-priv...
It’s the perfect user experience!
Seems like FB was storing a little bit more than just social graph and for a bit longer.