5 ms·
They don't have a choice under GDPR.
by cromulen 8y ago
They don't have a choice under GDPR.
- 01001010 8y agoTo what extent will GDPR require them to include the information they have to serve and target you ads? Does anyone even know yet?
- r3bl 8y agoNot only will it require them to include the info they're using to target you with ads, but also their source for that info (if it wasn't submitted by the user itself), the existence of automated-decision making, and "meaningful information about the logic involved". https://gdpr-info.eu/art-15-gdpr/ https://gdpr-info.eu/art-15-gdpr/
- dvfjsdhgfv 8y agoThat's yet to be seen. Can you imagine the ire when Europeans are able to download a rich set of information on how they're being tracked and so on, whereas Americans and the rest of the world has no access to that information? I can't. What is more probable is tha FB will try a legal trick claiming they are an American company and they follow the laws of California, not EU, even if they gladly accept European advertisers's money via Ireland.
- JumpCrisscross 8y ago> What is more probable is tha FB will try a legal trick claiming they are an American company and they follow the laws of California, not EU This would be an enormously stupid move. It guarantees not only failure but an acidic backlash.
- matlock 8y ago"What is more probable is tha FB will try a legal trick claiming they are an American company and they follow the laws of California, not EU, even if they gladly accept European advertisers's money via Ireland" That is specifically not possible under GDPR. It doesn't matter where your company sits, if you store data from europeans (or people living in europe) you have to follow the GDPR with potential for severe punishment. There really is no loophole afaik.
- lamename 8y ago> ... if you store data from europeans (or people living in europe) you have to follow the GDPR ... Does that mean the company has to follow it even for non-European users?
- hvidgaard 8y agoNo. For all users within EU it must follow the GDPR. If you are a US citizen and access FB from EU, they must follow the GDPR, as far as I understand it. And being FB, they really do not have a choice, since the EU do have leverage over them because they're doing business here.
- r3bl 8y agoI live in the EU. If I'm your "customer" (as in, you store my personally identifiable data), you have to comply with GDPR, regardless of where your company is. Hope that simplifies things.
- deleted 8y ago[deleted]
- jotato 8y agoHow can the EU punish a business with no EU location? An American company is not bound by another countries laws
- btilly 8y agoIf you do business within a country and that country rules against you, they can certainly stop you doing business within that country. They can also file a case in the country that you do belong you to get you to pay your fines in the original country. This sometimes works.
- Spivak 8y agoA company is bound by the laws of every country it does business in under threat of not being able to continue doing business there.
- dmoo 8y agoThis is why FB has moved data for 1.5b users back to the USA
- mtremsal 8y agoHas there been any conversation on HN regarding what this move achieves? I cannot see any clear benefit with regards to GDPR.
- mattmanser 8y agoIt's so the non-EU users won't have any rights under the GDPR. All non-US users were officially being served by Facebook Ireland instead of Facebook US, which would have put them under GDPR too (like India, Australia, etc.). The discussion is here: https://news.ycombinator.com/item?id=16872542 https://news.ycombinator.com/item?id=16872542 I don't see it in a quick scan, but I wonder if that means all the revenue from those countries will no longer be shielded from US taxes, which might indicate how seriously FB see the GDPR as a threat. EDIT: pdkl95 mentions in another comment, they claim it doesn't.
- pdkl95 8y agoAccording to Reuters[1], "Facebook said the latest change does not have tax implications." If they are still paying taxes through Ireland for the profit they make off those 1.5b users, they seem to be choosing to EU jurisdiction (which would include the GDPR) regardless of any contract of adhesion they forced users "agree" to. [1] https://www.reuters.com/article/us-facebook-privacy-eu-exclusive/exclusive-facebook-to-put-1-5-billion-users-out-of-reach-of-new-eu-privacy-law-idUSKBN1HQ00P https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
- dragonwriter 8y agoFacebook could have made a startegic decision to permanently repatriate profits based on US tax law changes before making the GDPR decision, which would make the GDPR decision tax-consequence free.
- 8y ago
- Silhouette 8y agoThey don't have a choice under existing data protection legislation in much of the EU either, but that doesn't appear to have stopped them.
- rrix2 8y agoGDPR's right to portability only extends to things you provide directly, or are collected on the basis of explicit consent, or wmthings which are required to fulfill a service or contract, like status and photos. There are explicit exclusions for a lot of things like things collected in service of antifraud & security efforts, and for things collected offline (IIRC), leaving a big set of holes that they can hide quite a bit. They're also not allowed to infringe on the data rights of other users which is why the friends list export is so anemic, for example.