4 ms·
Facebook Use of Sensitive Data for Advertising in Europe [pdf]
- gtufano 9y agoThe study links to this tool (from the same authors) that seems interesting: https://fdvt.org https://fdvt.org
- HenryBemis 9y agoI am soooooooo looking forward to GDPR kicking in. I have already bookmarked this "nightmare letter" [1], that was posted on HN a few days ago. [1]: https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
- ucaetano 9y agoYep, it will cost money, but the big companies will have compliance automated, and will continue business as usual. Now about the small companies, the ones that can will shut down European operations and continue elsewhere; the ones that can't, in particular European startups and small tech companies, will have to close shop or face severe penalties every year. In the end, most of the damage will be done to small and medium European tech companies.
- news_to_me 9y agoFor a little while, until there's more general support from third parties to help small businesses address this. Just like taxes, insurance, and everything else small and medium businesses are required to deal with. Oh, and EU users finally get the privacy they deserve.
- ucaetano 9y ago> For a little while, until there's more general support from third parties to help small businesses address this. By subsidizing them? By exempting them? Both are terrible ideas.
- mercer 9y agoBy guiding their business to be compliant and privacy-conscious. I really do think that's a good thing in this case, even as someone who is generally not a fan of the 'we will help you navigate the bureaucracy' type companies. All this could backfire, but it's better than nothing, at least.
- ucaetano 9y ago> By guiding their business to be compliant and privacy-conscious. That doesn't solve any issues. The cost isn't knowing how to be compliant, but all the operations required for compliance. Even if they have a business model that is 100% compliant, they still have to account for the large costs of reporting and certifying the compliance. For example, replying to all those letters that OP mentioned.
- tmuir 9y agoThis is the very sector that has only achieved its current status by automating away the menial tasks that you claim will overwhelm them. If humans can figure out how to make two rockets land autonomously and concurrently, I don't really see us getting tripped up on this one.
- ucaetano 9y ago> This is the very sector that has only achieved its current status by automating away the menial tasks that you claim will overwhelm them. If humans can figure out how to make two rockets land autonomously and concurrently, I don't really see us getting tripped up on this one. Guess you didn't read my first comment, did you? Facebook and Google will be fine, as they are big enough to automate this. Smaller companies, especially local ones, won't.
- tmuir 9y agoI can make the very same retort to you: In a separate post, I said that solving these sorts of "burden of compliance" problems has continually defined the successful players of the internet industry for the last quarter century. I don't argue they've solved them all, nor that they don't fall prey to regulation themselves. The extent to which companies start wilting under this burden will also be the extent other companies will address those pain points like they always have, with machines that don't get stressed out because their data and requirements grew faster than they could. I don't see the immovable object here.
- mercer 9y agoYeah, there's a huge opportunity for 'pickaxe sellers' in this new world, and they'd actually be doing something valuable this time.
- dotsh 9y ago> Oh, and EU users finally get the privacy they deserve. Of course we do. GCHQ will defend us if someone want to violate our privacy. ;)
- TeMPOraL 9y agoGCHQ checked itself out of EU ;).
- raverbashing 9y agoThat's worse, not better Because then they only have to follow UKs laws (once this happens, of course)
- sandstrom 9y agoI run a small European tech company and disagree. We have a product that deal with quite a lot of personal information (top quintile). Sure, it’s a headache right now but certainly not insurmountable. The law itself is easy to read, sensible and not needlessly long. You definitely don’t need a lawyer to understand it. Also, I know that a younger/smaller company with a more modern tech-stack will have a munch easier time implementing data minimization, profile erasure tools and proper encryption/security. For many large companies data is spread out over so many products and systems that just mapping it all up is a painful task. Also, as a consumer I think 95% of the law makes a lot of sense! Citizens deserve it!
- ucaetano 9y agoAnd how will your costs increase when you have to provide data to dozens, hundreds, or thousands of letters like the one the OP posted, each one asking for different things? Managing the data is easy, managing the compliance and reporting will be the hard and costly part.
- lucb1e 9y agoDon't be all gloom and doom. I agree with your parent comment that it's a reasonable law, and the general sentiment that it's manageable both when you're small (not a lot of overhead in collecting one user's stuff and shipping it) and when you're large (automate all the things). And I don't think that many requests will come in, even while the new law is still hot. Also, 99% of the law already exists in the Netherlands. I did my first request last week actually, after I discovered a company did WiFi tracking on me. I got a reply today, very professionally and complete (and fast, I should add: they had 4 weeks). I was impressed and it gave me a lot more confidence in the company. And it didn't look like it cost them a lot of time, either.
- chundi 9y agomaybe show what you got under profile settings somewhere or button which will email you report with all or frequently requested information.
- mgpc 9y agoAs a European start-up founder, I agree with this. The unintended consequences of the GDPR will be to (1) cement the power of Google and Facebook, since they have logged in consent (2) kill third party retargeting companies, ironically French company Criteo being one of the promient examples (3) generally make life harder for Euppean companies, and sharpen the incentive to ignore the EU market where possible. As a user I do feel some privacy regulation is a good thing. There are certainly good things about GDPR (e.g. a lot of third party ad tracking deserves to die). However, I am far from convinced that the GDPR is the saviour some people think it is.
- TeMPOraL 9y ago> (1) cement the power of Google and Facebook, since they have logged in consent I might be missing something, but won't they actually have to get your consent again, on everything, but this time in details and with option for you to refuse without service degradation? > (2) kill third party retargeting companies Good riddance. That would be the second most annoying ad technique today, after ads interrupting your video streaming.
- disgruntledphd2 9y agoSo, both Google and FB track people around the web, as do many web-retargeters. The web-retargeters have no reasonable way to get consent, but big G and F do, so it's likely that they will fill the gap in the advertising markets created by the lack of web-retargeters, thus increasing their power. That's my understanding of the point anyway.
- simion314 9y agoPoor small companies, they want more data then they need, like the ones that track you in the browser and not even tell you that you are recorder, I hope that some of those would at least tell that I am recorder and give me the option to allow or not. You know that you can keep the data that is requiered to do business.
- Moru 9y agoThis sort of letter is now and then sent to swedish public offices asking for information. One recent one was asking for all information recorded the last year, sent in to the whole countrys public offices or whatever to call them. And here you don't get a full month to respond to those questions. The law says basicly "Drop everything and answer it now while the person stands outside your office waiting". You can also do this to any company about your own information since many years. In school the teachers often did it as homework for the pupils to select some private company and write to them asking for all information they have. This has been tuned down because of the load it put on private companies now though. Feels good that we have most stuff down already so not much changes.
- tpush 9y agoReally interesting table on page 10. Selfishly I have to say I'm glad to see my country (Germany) being the least affected.