20 ms·
Facebook to change user terms, limiting effect of EU privacy law
- deleted 8y ago[deleted]
- mieseratte 8y ago> Facebook members outside the United States and Canada, whether they know it or not, are currently governed by terms of service agreed with the company’s international headquarters in Ireland. So would the GDPR have any protection for an Facebook-expatriate in the US who does not agree to the new terms, or would they still have no standing in European court as they are not citizen / residents?
- CiaranMcNulty 8y agoThe GDPR applies to people located within the EU, irrespective of citizenship. So it would protect a US national in Berlin, but not a German national in New York.
- ozim 8y agoBy people located you mean residents? Just to be more specific.
- m_eiman 8y agoResidency not required, I’ve heard.
- tialaramex 8y agoNo, just that's where they are. The law says a US citizen who happens to be in Berlin (maybe on vacation) is subject to German law. Fine says GDPR, I'm EU law, so I apply to that US citizen too.
- majewsky 8y agoThat's how most of the law works. If I commit a felony while on vacation, I'm subject to the penal code of the country I'm visiting, not the one where I have residence.
- ozim 8y agoThere are more scenarios. I am US citizen I have residency in US and I make new account (make contract) with company providing service that is based in US with rules as in US. I visit Berlin for a week and I log in into account to use the service. Is that falling under GDPR? I am US citizen I have residency in US and I go to Berlin where I make new account (make contract) with company providing service. Now I go back to US and login to use service. Is this one also falling under GDPR? Which law is applicable to contracts between two parties going into contract? Usually in formal contracts you have place and date. I assume you agree on laws of place where contract is made. So if you are at the moment in Germany that is the place of making contract. I think also criminal law and civil law are quite different in many ways so I would not draw conclusions based on how commiting felony is handled.
- paulkleenex 8y agoThat's simplistic. If you kill a Dutch in Berlin, you can be prosecuted by Germany, NL and your own country.
- desas 8y agoThe gdpr only applies to EU residents. People here on tourist visas are visitors not residents.
- deleted 8y ago[deleted]
- CiaranMcNulty 8y agoNo, physically present within EU jurisdiction
- Lionsion 8y agoSo could I, as an American resident, invoke legal rights given by the GDPR while I'm on vacation in the EU?
- s_dev 8y agoBeing on vacation doesn't entitle you to resident rights. This is typically known as a tourist visa.
- joering2 8y agoCouldnt they move all they servers to some thid world country and just dont care about Gdpr at all??
- keithnz 8y agoI don't think the servers matter, it's not really about the servers, it's about the business side of it, they operate a low tax business within the EU. I don't think they can move out of the EU without all of a sudden not having to pay a lot more for doing business with EU companies. So they still want to operate as a company within the EU to get the tax advantages, but then also are subject to the laws.
- meddlepal 8y agoIf FB moves all their operations out if the EU, how does the EU tax a company? Presumably EU companies can do business with non-EU companies without the other company having an EU presence? Genuinely curious. Not sure how this works as I'm not a bizguy.
- JumpCrisscross 8y ago> If FB moves all their operations out if the EU, how does the EU tax a company? If Facebook moved its servers and personnel out of the EU to avoid complying with EU law, I'd fully expect--and support--the EU to (a) punitively taxing EU businesses buying Facebook ads, (b) banning EU businesses from buying said ads, (c) extraditing Facebook executives to the EU and then (d) blocking Facebook in the EU. No jurisdiction reacts kindly to brazen, willful criminality.
- adventured 8y agoWhat that setup describes is a required implementation of the Chinese firewall and vast Internet controls by the EU over all persons within the EU. There's no other way to enforce such a scheme otherwise, you have to know all about user & business Internet use. Option C would never happen. Option D requires the Chinese firewall, very obviously. It's very aggressively courting fascism, practically begging for it; a return to militant European fascism would be the sole possible outcome over time. It would turn the EU into a walled garden network, which is constantly railed against in regards to Facebook.
- kumarharsh 8y ago> Earlier this month, Facebook Chief Executive Mark Zuckerberg told Reuters in an interview that his company would apply the EU law globally “in spirit,” How would they apply the law? They can't be prosecuted if they fail to uphold the same law. Saying "we'll apply the law in spirit" is just moral posturing IMO.
- nemothekid 8y agoAsking them to apply an EU law globally is posturing as well. Both the question and answer are nonsensical.
- robryan 8y agoInteresting though as they are selling to the rest of the world from Ireland in the first place to tax dodge.
- Moru 8y agoAnd EU isn't totally ok with this either. No wonder Ireland got hickups when UK voted to leave EU.
- kumarharsh 8y agoI'm not saying they should apply the law. I'm just saying that FB shouldn't say things like this (and in the future, they'll just backtrack with a "we didn't mean that" or some other spinon we're sorry)
- sqdbps 8y agoIt would be corporate malpractice if they were not to do that, this way they limit their exposure to the exuberant fines and any other unintended consequences of this anti-american piece of legislation.
- donohoe 8y agoIt is not anti-American (its not all about you), its pro-privacy.
- lovich 8y agoNext this guy is going to say countries building armies to protect themselves is anti american because it doesn't let US companies take all their natural resources.
- dang 8y agoPlease don't make it personal. There's no need. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- ironjunkie 8y agoSo, does GDPR applies to ?: - European citizens only currently living in the EU ? - European citizens worldwide ? - Everyone currently living in the EU ? As a European living in the US, I'm wondering.
- tzs 8y agoSee Article 3, "Territorial Scope", here [1]. It's fairly clearly written. [1] https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/
- outside1234 8y agoI see it written there but that doesn't mean its enforceable.
- lenzm 8y agoYeah, I'm skeptical of the EU's ability to enforce their laws on someone outside of the EU (citizen or not) with a business outside of the EU.
- donohoe 8y agoNot impossible, but unlikely. There are enough businesses that have dealings in the EU that they need to be compliant.
- lovich 8y agoUnless they are willing to go to war they can't do shit to people outside their jurisdiction by definition, if they had power over that place it would be part of their jurisdiction. What they can do however is turn off access to any resources being acquired in the EU. As the EU is the largest economic bloc in the world atm, and with the massive connectedness of the modern global economy, there's no way for a major internatial to flaunt the EUs laws without losing money unless the EU decides to allow it
- 8y ago
- foxylad 8y agoI don't use Facebook, but could one build a service that automatically sets Facebook's privacy settings to sensible options? A large part of the problem is that changing these through the web site is painful in the extreme. I suppose I'm asking if their API provides read/write access to privacy settings. If so, there's a big opportunity here. More generally, I'd like to see governments mandate that all FB user's privacy settings be reset to the max, and force Facebook to realistically inform users who want to loosen them about why they might want to do so.
- kbsletten 8y agoI imagine they have documentation, but I also can't see a privacy permission ending well. How easy would it be to convince somebody to allow an app to turn off privacy entirely?
- theseatoms 8y agoPart of the problem is how often they change the privacy model, from what I gather. So the API and/or any integrations would have to support those recurring changes. Not a frequent user of FB, though I still have a profile.
- cjhopman 8y agoDo you consider your privacy settings your personal information? Do you believe companies should just be exposing that kind of information to random other companies through an api?
- pimmen 8y agoYou could use the OAuth authentication API and let the user consciously giving user settings access to the service. As long as the service doesn't do anything with that data the agreement with the user doesn't permit, and the data is deleted upon the user's request, the service is GDPR compliant.
- ahartmetz 8y agoImpossible for technical reasons, like data sharing between WhatsApp and Facebook proper. /s
- IBM 8y agoZuckerberg went to Congress and told them Facebook would support GDPR, as if the only thing GDPR is are just some controls you'd do at the user interface level (and as we learned today, that they're attempting to get around with dark pattern designs [1]). GDPR is much more comprehensive than that, but most importantly it gives data privacy regulators real teeth to enforce with (fines up to 4% of global revenue). The only way Americans (or anyone else besides EU citizens) will get GDPR protection is if GDPR-style regulation is enacted into law. [1] https://twitter.com/zeynep/status/986591125262749696 https://twitter.com/zeynep/status/986591125262749696
- sqdbps 8y agoWhy would the US congress want Facebook to go out of their way to maximise their liability to a piece of legislation intended to cripple US corporations and supplement EU budgets with US corporate profits?! Congress should convene a hearing about how current and incoming EU laws are thinly veiled protectionism against US corporations and what should be done about it.
- stochastic_monk 8y agoAre you certain it’s protectionism and not simply believing human beings have a right to privacy?
- sqdbps 8y agoPrivacy rights are well protected as it is, despite what the technophobic anti-corporate maximalists would argue, this law is about limiting and controlling what american companies can do on their platforms, it limits research and puts a roadblock in front of every data point with the threat of unconscionable fines on worldwide revenue which shouldn't be allowed under international treaties.
- pwinnski 8y ago> Privacy rights are well protected as it is Yes, the US regulations protecting our privacy rights are well-known, which is why the current Cambridge Analytica scandal couldn't happen, and triggered all sorts of... what's that? In fact, we have no privacy protections whatsoever? Oh.
- stevespang 8y agoAs always, Zuckerberg is a lying slithering scumbag, I predict the EU will play his cat and mouse lawyer game and rewrite their law as much as need be to make it enforceable for facebook as it applies to their territory, and the fines will start rolling immediately . . . what will facebook do then ? Pull all any and all FB locations out of EU and snub them on the fines ?
- chrischen 8y agoUser's generally won't care about privacy, but they will care about money. What this essentially boils down to is Facebook is charging users by taking their data, which is worth some amount of money.
- _rpd 8y agoWebsite terms and conditions could ask for a pint of blood from their firstborn and people would still click okay. No one reads these things. The GDPR is just going to end up being a more annoying version of the cookie law.
- CiaranMcNulty 8y agoUsing consent as a basis to handle personal details under GDPR requires: * Consent is gained granularly, prominently, and separately from other terms and conditions * Consent is opt-in and individuals can refuse to consent without detriment
- sgeisler 8y agoI'd be interested if you could ask your users if they are _not_ a EU resident. Only if they click yes go ahead, otherwise show that you will not serve them. Probably 90% would learn to click the "Not from EU" button. Who should hold you accountable for false user input in that case?
- PeterisP 8y agoFor the reasons you describe, if a user simply clicks 'Agree' to something like the current T&C, it will not be considered as informed, freely given consent by GDPR and thus will not give the website any rights to process that user's data.
- dingo_bat 8y agoIsn't this what EU wanted? Facebook is complying perfectly. You cannot protect citizens who are literally dumbfucks, no matter how draconian a regulation you pass.
- kalleboo 8y ago> But the fact that the button to reject the new Terms of Service isn’t even a button, it’s a tiny “see your options” hyperlink, shows how badly Facebook wants to avoid you closing your account. > When Facebook’s product designer for the GDPR flow was asked if she thought this hyperlink was the best way to present the alternative to the big “I Accept” button, she disingenuously said yes, eliciting scoffs from the room of reporters. I wonder if I could live with myself if this was my job. Although I guess if I got paid really well I would end up justifying it to myself somehow.
- NegativeLatency 8y agoIt is the best way for the true customers of Facebook (the paying advertisers)
- sametmax 8y agoIt's the best way, just not for us.
- kartan 8y ago> I wonder if I could live with myself if this was my job. You are in the company, you have a job to do, everybody else is doing it. Other people share your concerns, but in the end, you have a feature to deliver and you don't want to fail your team. Some people is really concerned, they try to change things, they quit, they are tired of the pressure of going against the managers and making it more difficult for their own teams. Peer pressure, management pressure, etc. is an important factor. I don't think that the people that do this things get paid better than anyone else. I have been in too many situations where your team is in the "hamster wheel" and is just doing without thinking. Fast-growing companies have the incentive to run forward, quite often without so much direction. It is easier to not join a job that you don't want, that to not do it once you are already in. So, think before joining if that is what you want to do. Once in, you will see that they are not evil people, that they are trying the best to do their jobs. And that to change things is hard, even when is in the company best interest, so much harder when the company will lose revenue.
- sorokod 8y ago
- deleted 8y ago[deleted]
- maaaats 8y ago> Facebook to change user terms, limiting effect of EU privacy law Ironically, EULAs ar not really enforceable in the EU. So had this been the other way EU citizens would also have been protected.
- ckastner 8y agoThis isn't about EULAs.
- rdiddly 8y agoSo it's a weasel move. Let the record show that Facebook and Mark Zuckerberg weaseled out of GDPR to the greatest degree possible given the opportunity. It's all perfectly legal, but decidedly non-excellent and non-exemplary.
- siruncledrew 8y agoNot surprised at all. Facebook is not going to change.
- lagadu 8y agoUnfortunately that is roughly as surprising as the sun rising in the morning.
- mikekchar 8y agoThis article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their terms of agreement to now say that people outside of the US are doing business with the US company. This means that only people in the EU will be covered by the GDPR. Probably that's what they should have been doing all along, but there were probably massive tax advantages to running their international company in Ireland. For what it's worth, I'm a huge proponent of GDPR and I would probably do the same thing -- at least initially. They have a lot of users and GDPR is really tricky to implement when dealing with any manual processes. Limiting your exposure is common sense. I'm looking forward to seeing what actually happens to Facebook when GDPR comes into force. You know people are going to exercise their rights and I just can't imagine they are prepared. As I've been going through this stuff in my job I can't see any easy ways to sweep this under the carpet -- you not only need to inform the user about what's going on, you actually need to record the lawful basis that you've told them you are using. If you just say, "Oh I have consent" then the user can withdraw consent. If you actually needed that information (like the user's name!) then you are absolutely screwed. I fully expect some thoughtful users to nail them to the wall. And when that happens, I expect them to implement everything world wide because it will be a lot easier/cheaper than maintaining different processes all over the place.
- Johnny555 8y agoThey have a lot of users and GDPR is really tricky to implement when dealing with any manual processes. Though they have a lot of users in the EU (population 700M), it seems that once they figure out how to do it for their 250M (?) EU users, expanding it to 2B users is not a huge stretch.
- donkeyd 8y agoIt's not hard to do, but it limits a lot of stuff that their business is built on. So implementing it world-wide could have a negative business impact and will definitely impact the stock price in the short term.
- phonebucket 8y agoIs this news? Facebook had already stated that it wasn’t applying GDPR to non-Europeans. Also, the headline is misleading: it makes it sound like FB is trying to get around laws. Really, all it’s doing is applying laws in the required jurisdictions, which is how things always work. Where’s the controversy?
- rmc 8y ago> Is this news? Facebook had already stated that it wasn’t applying GDPR to non-Europeans. Yes. Previously anyone not in the USA or Canada had a legal agreement with Facebook Ireland Ltd. So there was an Irish/EU company which was processing personal data for lots of people (inside & outside the EU). The GDPR says it applies to (i) people in the EU or (ii) companies in the EU who process any personal data. So if Facebook Ireland Ltd did something against EU law with the personal data of (say) someone from South Africa, then EU law could take that up. BTW The GDPR never mentions citizenship, merely presence in the EU. non-Europeans in the EU are covered too.
- gaius 8y agoOn May 26th I would like to log into FB one last time and say “permanently really-delete all my data and never gather any on me ever again”. Will that be possible?
- majewsky 8y agoProbably better to send a letter.
- ggm 8y agoHmmmm. Does this mean that the Irish Dutch triple sandwich tax thing will break and facebroke is now paying US taxes?
- whostolemyhat 8y agoThe article mentions that they'll still try to claim revenue through Ireland for non-EU users, but that non-EU users technically have an agreement with the US company. So no idea, basically.
- buro9 8y agoHow do they manage the "no tax implications"? If the Irish entity has a licence for the IP, and 70% of the value of their licence is transferred elsewhere, than how does this not realise that value to the Irish entity and not be taxable? I am obviously not learned in this area, but the sleight of hand to move such a huge amount of value from one entity to another seems to me to create a huge tax liability now that the value would be leaving the tax domain.
- return1 8y agoFacebook users don't pay facebook however, only advertisers do. It seems only a small percentage of non-EU advertisers went through the ireland HQ
- furyg3 8y agoHow does Facebook determine if a user resides in the EU? Based on the location that they give Facebook? Based on their IP address? Phone number?
- apexalpha 8y ago99% of people give FB their location. Perhaps as just if (EU IP | EU LANGUAGE | EU PHONE NUMBER | EU LOCATION SET) == EU. Just to be safe for a massive 4% of global REVENUE fine.
- stordoff 8y agoNot sure if you could use language, as that would include English and Spanish, which I presume would make up a large percentage of their non-EU users (unless people are reliably set to the regional variants of those languages?).
- furyg3 8y agoYeah my question is not does facebook know your location (they do), but what criteria are used to determine if you are under the legal regime of the GDPR. If it's just the location you set, I would advise my non-EU friends to set their location to somewhere in the EU.
- rmc 8y agoFacebook has oodles of data on a massive percentage of their users. They have GPS data from the facebook app, from metadata in photos that are uploaded.
- blklivesmatter 8y agoFacebook sucks more than my socks
- mtgx 8y agoIt would be hilarious if a future U.S. government enacted even stronger user privacy protections than the GDPR. What will Facebook do then?