They push draconian surveillance laws then claim sainthood when they go after Facebook.
I guess you can hate Facebook et al and welcome this stuff but it's hard to deny how these laws are basically trade barriers aimed at the US tech industry.
They push draconian surveillance laws then claim sainthood when they go after Facebook.
I guess you can hate Facebook et al and welcome this stuff but it's hard to deny how these laws are basically trade barriers aimed at the US tech industry.
I don't want to undermine Facebook's business model because I hate them. I hate them because they run on a business model I want undermined.
There are real, present dangers to having your data hucked around like it's going out of style.
<Tinfoil hat section>
Let's also think for a second about the unprecedented level of propaganda and general bullshittery this stuff enables.
The whole reason we're so desperately divided right now is because the marketing managers in politics have been able to see with fine-grit granularity what makes people tick, so they know precisely which buttons to push to start the next distraction/flamewar every time people start talking about dangerous topics like election reform, lobbying, and antitrust - all stuff that people on both sides of the aisle have no trouble getting behind. Quick, get em talking about guns and gays!
</Tinfoil>
That being said. The branches that are working to secure citizen privacy and the branches that are working to ruin online encryption and monitor everything we do are often very sepperate parts of the government. So it's not exactly the same people.
2. The EU has no honest respect over the people's privacy as they fully surveil their citizens
Thus it ia very safe to conclude that the EU pretends to care about people's privacy as an excuse to protect it's industry against the ultra-high yields of US tech companies
What is your source for that? Because that would be illegal in most EU countries.
I would say it's more a problem of the US companies, if they can't do business without violating EU regulations.
Why should the web's profitability or lack thereof, be my problem as a user? That the SV elite can't buy platinum plating on their yachts? Are they sharing that wealth with me? Then, good riddance! My privacy is more important than your wealth.
There's been profitable SW companies and careers before user tracking became the norm. Remember when Windows came without any ads and blogs and forums had generic non-targeted ads?
Same how the big tobacco industry got kneecapped for our own health and the greater good, a similar tech industry correction is long overdue. Is this the world you want for your kids?
But I still think that "don't track your users without their informed consent" is a good summary of the intention of the law.
And I would also say that's it's only really complex to implement if you were already tracking your users and now you need to change everything. If you weren't doing that, you'd probably find it remarkably easy to implement.
You must list all kinds of data processing you perform, find the appropriate legal basis (and data retention duration, etc.), make sure you only gather data you need (data minimization), know to who you transfer data, make your services secure by default, monitor for unauthorized access, and tell affected people when there is a breach. Perhaps make a risk assessment, but it depends on the processing you do.
Yes, it's work. But quite frankly, I'm cool with a law that expects anyone who processes personal data to secure their service, to properly inform people, and holds them accountable.
>‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
An IP address, or an email address is personal data. Even a pseudonym or a session ID is personal data. Yes, having a log for security purposes (GDPR recital 49) captures personal data (even just access dates and requested URLs may be considered to be personal data). Yes, a comment section on a blog may capture personal data.
Once again, I'm fine with all of this. But ignoring GDPR by not capturing personal data is more complex that it might seem.
No cookies... so no language preferences. That is a profile cookie.
Right to erasure. What about invoices and orders? When can it be anonymous and when is it old enough to anonymize.
Do I get away with replacing personal data random data? Do I replace references to real people with 'anonymous person'? Will my sql constraints still work?
When I restore data from backup and someone has been anonymized in the meantime, what mechanism will be used to anonymize the user after restore?
Right to data portability. How much of the database and in what format?
You can find guidance or good advice online for all of your questions.
> No cookies... so no language preferences. That is a profile cookie.
This is one of the examples of “strictly necessary” cookies, which do not require consent. See section 3.6 here: https://ec.europa.eu/justice/article-29/documentation/opinio...
> Right to erasure. What about invoices and orders? When can it be anonymous and when is it old enough to anonymize.
Invoices should typically fall under the “legal obligation” legal basis (article 6(1)c). See for how long the law requires you to keep them. In my country, it's 10 years.
>Do I get away with replacing personal data random data?
Yes, see WP216.
>Do I replace references to real people with 'anonymous person'? Will my sql constraints still work?
How do you do when someone deletes their account?
>When I restore data from backup and someone has been anonymized in the meantime, what mechanism will be used to anonymize the user after restore?
It's up to you to decide.
>Right to data portability. How much of the database and in what format?
The same as for a DSAR. As for the format, it's up to you to decide, provided it is a commonly used format.
Similarly you could argue that the companies are US based, simply because the US have pretty terrible privacy rules which makes it easy for them to get started with a fair amount of users/targets.
I do argue this. The state of privacy rules in the US is abominable.
You make an excellent point about the EU surveillance laws. They clearly don’t give a shit about privacy. None of the folks disagreeing ITT seem to be willing to discuss that point.
The EU spends more resources regulating US corporations than they do building their own. If they want to reverse course on their economic trajectory they’re gonna have to start competing in a genuine way.
You can be for privacy and against survailance. Often the politicians who work to implement data protection laws and politicians who work to increase survailance come from opposite sites of the political middle. So it's not really a very good point unless you can only deal in black and white.
The EU can clearly be good on some areas and terrible on others. As it is with most things. Another example could be how the green party members of the EU are working toward clean energy while the conservative branch is working to increase the markets for fossil energy simultaneously. They do so by positioning them in the legalislative branches where they get the most influence acording to their political agenda, and while that may be "weird" to people from a "winner-takes-all" sort of system, it's how the vast majority of the EU democracies work.
Is this a typo? Of course you can they’re literally opposites.
You’re performing mental gymnastics if you think that the EU is somehow “pro privacy” just because they created cookie banners via GDPR. State sponsored surveillance is FAR worse than corporate sponsored surveillance.
The companies tried to track you created those banners.