7 ms·
I wonder how wayback machine will work after GDPR? I can't imagine they can just show content that the authors deleted from primary sources?
by thogenhaven 8y ago
I wonder how wayback machine will work after GDPR? I can't imagine they can just show content that the authors deleted from primary sources?
- rambojazz 8y agoI haven't read GDPR in details, but isn't GDPR concerned only with personal/private data? The Wayback Machine only archives public pages as far as I can tell...
- scandox 8y agoYes but the article itself is user-provided content to Medium that the author has a right to ask to be deleted (under GDPR), presumably? So perhaps it will be simply a matter of the The Wayback Machine having to have a policy to delete things if requested?
- deleted 8y ago[deleted]
- mjn 8y agoThe Wayback Machine has always had a policy to delete things if requested, so there's no real change there. The most common way site owners do that is by changing robots.txt. In line with the Oakland Archive Policy [1], the Internet Archive respects robots.txt retroactively, so a site owner can get archived versions deleted just by excluding them in the robots file. Besides that, they respond to DMCA takedowns, one-off removal requests [2], etc. [1] http://www2.sims.berkeley.edu/research/conferences/aps/removal-policy.html http://www2.sims.berkeley.edu/research/conferences/aps/remov... [2] http://archive.org/about/faqs.php#2 http://archive.org/about/faqs.php#2
- adventured 8y agoChanging robots.txt does not delete content from their archives. If you remove the robots.txt file, the content becomes viewable again. There's no scenario where they can respond to the vast scale of GDPR violations that their archive likely represents, when it comes to manually removing content. There are only three possibilities: avoid the EU as much as possible, dump the archives and start over with an entirely different approach, or shut down. Besides that, these laws are going to get a lot more strict and difficult to comply with, not less strict, over time. This is merely the beginning of aggressive regulation of the Internet. Regulation of the Internet will only move one direction from here, in the direction of increasing burden and ever greater regulation. It's hard to imagine Archive.org's archives surviving what's coming.
- icebraining 8y agoThere's no scenario where they can respond to the vast scale of GDPR violations that their archive likely represents, when it comes to manually removing content. "GDPR violations". What's that, exactly? As far as I know, you only have to remove personal data upon request, no preemptively. So I don't see how they are "violations". Will a lot of people make these requests? Possibly, but where's the evidence of that? People have been able to use copyright takedown requests (e.g. under the DMCA) forever, yet the Archive is still around.
- tankenmate 8y agoActually the recommended data handling says you should specifically state the purpose for needing the data, and that it should be reasonably limited to that need; i.e. if you don't need it any more you should pro-actively delete it.[0] [0]https://ico.org.uk/media/for-organisations/documents/1475/deleting_personal_data.pdf https://ico.org.uk/media/for-organisations/documents/1475/de... Pages 4-6
- drchaos 8y agoThey do have a legitimate interest (in the sense of article 6(1) of the GDPR), namely providing an internet archive.
- tankenmate 8y agoI would agree in the case of the wayback machine they have a very strong case under article 6(1).
- lbriner 8y agoNo! GDPR is about personal data, which is well defined in the regulations and does not include blog posts. The right to delete data (or "be forgotten") is nothing to do with GDPR. If the original post contained personal data, it is a different issue but if that was put out into the public domain, it is a hard problem to solve.
- jakeogh 8y agoSo add some "personal data" to the end of anything you might want to demand someone forget later.
- LaGrange 8y agoNo, if you intentionally made that data public then it's done. GDPR doesn't, say, force you to remove political views of Theresa May from newspapers, despite that being covered by personal data, because Theresa May made those views public.
- jakeogh 8y agoSo if was subject to the GPDR, and published my nginx logs in real time, I could stop worrying about scrubbing "personal" data from them on request?
- icebraining 8y agoOr you could send a good ol' DMCA takedown request. I'm not sure where this idea that nothing could be forced off the web before the GDPR came from.
- LoSboccacc 8y agoMost pages have an author section already.
- damontal 8y agoWhat if the blog post contains personal data?
- rusk 8y agoCould conflict with “right to be forgotten” however
- adventured 8y agoGiven the immense scale of Archive.org, there must be a truly incredible number of sites & pages with personal data & content in the pages. Millions upon millions of pages, due to the repeat archiving. Comments with usernames. Comments with ip addresses (sometimes old comment systems would allow you to comment without registering but they'd show all or part of your ip address). Comments with personal information in the messages. Comments with email addresses. Blog posts with all sorts of personal details from the author. Personal user account pages, such as the kind you see on sites like Ask.fm or similar, with vast amounts of user information and personal details that can't be deleted. And on it goes. Archive.org is storing all of that and does not allow it to be deleted. Further, it would be nearly impossible to figure out what content is compliant and what is not within the archives. It's a giant GDPR violation system. Their only sane bet is to stay way from the EU jurisdiction wise as much as possible, or shut down.
- merinowool 8y agoIf public page can be linked back to you then can be considered personal information and therefore be subject of GDPR.
- josteink 8y agoNo. That’s not how it works. Read the law before posting wildly misleading comments like this. If you explicitly make something public, you can’t later come and claim that this information is actually crucial to your privacy. If so, you yourself was the one who violated that privacy, not the company later archiving/caching/processing your public article. GDPR is all about decency and common sense wrt. user data and privacy. No need to spread FUD about something that simple. SV proved tech companies can’t be trusted to act ethically, so here comes the regulation. Deal.
- rusk 8y agoI guess they could vest it in some corporation that has no feet down within the EU. Aside from actually cordoning off a section of the Internet there's not much they could do otherwise. Though now that I think of it, perhaps blocking [the archive.org crawler] could then become mandatory for GDPR compliance ...
- rusk 8y agoThis seems to have annoyed a few people. I didn’t mean this as an actual practical strategy, or facetiously, was more meant as a commentary on modern global corporotisation, and a thought experiment on the limits to which the EU can enforce itself online.
- alerighi 8y agoThey can't, and I would like to know what Europe wants to do about it. Block wayback machine in Europe ? Well, I can still access it with a VPN if I want. Also I want to know what they will do about git and GitHub, or even blockchain project (how you delete something from a blockchain ?) The problem is that GDPR is a stupid legislation written by incompetent people that doesn't understand the subject and imposed with no possibility of choice on member states, like all the regulations from the EU (cookie banner law, for example). And of course GDPR doesn't impact to much the companies that they aim to fight, like Facebook, Google, etc, they have teams of layers payed millions with the sole purpose to find ways to circumvent these regulations, they will just update the terms of services and done, the ones that will be more affected are small companies, startups, personal no project side projects, people that doesn't have money to spend in a layer for a project that doesn't make him any revenue. I think that in Europe it's not more possible to do anything, if you have a good and innovative idea and you want to realize it, better take a flight to the US...
- simion314 8y agoThe law is meant to allow me to delete my account from your cool SV startup, and delete meaning actually delete the data and not deactivate the account but continue using or selling my data. The cookie law is a problem because lazy web developers did not implement it right, probably you complain about don't spam me law because it adds a bit of extra work for adding the unsubscribe link and implement the requierements. The laws are done for the good of the society and not for helping a minority to implement some move fast break things, pivot and try again.
- jfaucett 8y agoThere is big difference in law and regulation between intention and real-world effects. For instance, making marijuana illegal has the intention of decreasing drug addiction and dependence but has the effects of disproportionately encarcerating youth aka "criminals" under the new law for drug consumption, and thus limiting their opportunities in the socio-economic system. If you look into it I think parent is most likely correct with his predictions since they are easily verifiable i.e. big coorps do have massive teams and monetary funds to deal with this legislation, startups and one-man shops do not. This is completely ignoring the deontological question of what should be the case, where I think most would be in agreement.
- detaro 8y agoI assume they'll continue as now: take down copies on request. It's not like they didn't have to deal with content people didn't want to archive them before.
- jakeogh 8y agoI doubt it. GDPR is the obvious next step in the war on GPC (memory specifically). archive.org exists to fix that. If they fall because some other country has no 1st, they fail. Other people have copies. Who exits next?
- marksomnian 8y agoGPC?
- rainbowmverse 8y agoI assume they mean General Purpose Computing.
- MatthewWilkes 8y agoHow will it work with copyright law, or defamation law?
- BlackFly 8y agoGDPR doesn't change anything in this respect. Copyright law applies. Why would the owner of the copyright make a complaint to the data protection authorities of the EU who might choose to do nothing when they could directly file a copyright infringement case? I suppose you could add insult to injury, but the data protection agency is likely to rule that the issue is one of copyright infringement.
- jakeogh 8y agoI post a letter on a pole. You take a picture of it. I sue you for sharing that pic, and pretend you still have free speech.
- chaosite 8y agoI'm not sure what you think free speech is, because the definition I'm aware of does not apply in any way to that situation.
- martin-adams 8y agoI thought free speech was the ability to make commentary on the letter on the pole, but not to reproduce it. It's the equivalent of it being technically illegal to take a photo of the Eiffel tower at night, because the light show is a copyrighted artistic display.
- chii 8y ago> pretend you still have free speech. free speech is the right to speak about any topic without the gov't attempting to punish or censor you. Free speech isn't the right to speak at any (private) forum, nor is it about having the right to be heard.
- stale2002 8y agoIt absolutely is the right to speak at any private forum that allows you to do so, AND it is the right to be heard by people who are purposefully choosing to listen. Yes, if a private forum chooses to not let you speak, you can't force them to accept you. But if they DO choose to let you speak, then you do have that right. Also, this IS about the government attempting to censor people. It is the Internet Archives freaking website, that they own!
- dspillett 8y agoGDPR shouldn't have a major impact here. They already take down pages on request and retro-actively apply robots.txt rules so that solves "right to be forgotten" or other circumstances where PII is present and shouldn't be. They have sufficiently defensible reason to keep and present the archived information otherwise. Their key problem will remain copyright and publishing rights arguments not matters of personal data, at least not more so than currently. (caveat: while I have an understanding of the regulation due to it very much having an effect on our clients and to a lesser extent on us directly, I am not a lawyer by any definition so don't take my interpretation as gospel in any way)
- teamhappy 8y agoWhy would GDPR apply to the internet archive? It's a US based nonprofit. As far as I can tell they don't do anything that even remotely hints at them providing services to EU residents (like offering their site in European languages, having the €-symbol somewhere on their donations page or any of the other more subtle things mentioned in GDPR).
- merinowool 8y agoBecause the data they have might have been produced by EU citizens.
- jakeogh 8y agoSo what? The EU does not get to make laws for other people. That's why we have countries.
- fredoliveira 8y agoYou are missing the point. The EU makes laws that govern - and at least try to - protect its citizens. If a document on the archive is created by a European citizen, then it is under EU law. That's why every company in the world right now that deals with European citizens is working on supporting GDPR. That also applies here.
- soziawa 8y agoyeah, but GDPR doesn't affect copyright.
- icebraining 8y agoNitpick: EU residents, not citizens, as far as I understand it (the text says people "in the Union", and doesn't mention citizens at all).
- donohoe 8y agoNot quite. The EU might want that but it gets into jurisdiction. The EU cannot enforce its law on entities that are entirely US based. It can only enforce it on non-EU sites if that site has some sort of business that’s within the EU (like offices or employees).
- josteink 8y agoGDPR is not relevant to this. It’s not about enforcing copyright on people’s work. It’s about ensuring that companies only store and process privacy-sensitive information about people which they are given consent to store and only used for the purposes the consent was given. There is nothing privacy related wrt the author in a public article published worldwide for everyone to read. Clearly outside the domain of GDPR. It’s not hard people, just common sense. Just treating user-data with respect. Let’s not fool ourselves into thinking it’s harder than it actually is.
- walshemj 8y agoHowever from experience GPDR will also be abused by jobsworths to avoid doing something either through laziness or for more suspect reasons. Just like H&S and the Data Protection act are abused today.