12 ms·
Things to know about the GDPR, Mozilla and Firefox
- dvfjsdhgfv 8y agoMoreover, many EU companies don't need to update it either.
- bausshf 8y agoYet they still do.
- Finnucane 8y agoPossibly they had user agreements that were so badly written they'd have been a problem even if they weren't actually collecting a lot of data.
- dvfjsdhgfv 8y agoMostly unnecessarily: https://www.theguardian.com/technology/2018/may/21/gdpr-emails-mostly-unnecessary-and-in-some-cases-illegal-say-experts https://www.theguardian.com/technology/2018/may/21/gdpr-emai...
- jhall1468 8y agoAnd a ton of non-EU companies don't, but are doing so for future purposes. Despite territorial scope, a company without any form of business in the EU, they can't entorce this against non-EU businesses.
- bausshf 8y agoThey can.
- daxorid 8y agoCare to elaborate? In which US court does the EU have standing to bring suit against a US citizen or corporation for violation of regulations the US does not recognize by either law or treaty?
- jhall1468 8y agoYeah, you aren't going to get what you asked for. There are no civil enforcement agreements between the EU and the US so they can do exactly nothing.
- bausshf 8y agohttps://politics.stackexchange.com/questions/30509/how-are-gdpr-fines-actually-enforced-for-us-companies-with-no-physical-presence https://politics.stackexchange.com/questions/30509/how-are-g...
- deleted 8y ago[deleted]
- krageon 8y agoYou are wrong. This is a misconception that has thankfully died down a bit over the past week or so, but apparently it is still a bit alive. There are accords in place between (for example) the US and the EU, which allows the EU to hand out fines overseas. The reverse is also true (the US can and does litigate in the EU).
- jhall1468 8y agoShow me case law where an EU government fined a US company and how they enforced payment of that fine.
- eatbitseveryday 8y agohttps://en.m.wikipedia.org/wiki/Microsoft_Corp_v_Commission https://en.m.wikipedia.org/wiki/Microsoft_Corp_v_Commission
- jhall1468 8y agoThat's not an example of what I asked for. Microsoft had offices in the EU when this case started, which made them an EU company for all intents and purposes.
- krageon 8y agoWhen did I mention case law? Shouldn't you be asking me for proof of the accords I mentioned, which is what I'm actually talking about?
- jhall1468 8y agoI asked for case law because that would give me evidence that this actually happened. That's because it can't happen. That's because you're dead wrong: https://community.spiceworks.com/topic/2007530-how-the-eu-can-fine-us-companies-for-violating-gdpr https://community.spiceworks.com/topic/2007530-how-the-eu-ca... "While we don’t yet have U.S.-EU negotiated civil enforcement mechanisms for the GDPR (and it is unknown whether we ever will), there is still the application of international law and potential cooperation agreements between U.S. and EU law enforcement agencies, which have been increasing in recent years." That's politician for "We have absolutely no recourse if the company doesn't have an established business in the EU." EDIT: That's a nice article. It goes to explain that if a company has no presence in the EU, it has to identify an agent in the EU to act on its behalf. So any company can simply NOT do this if they never intend to have EU offices and the EU has no recourse.
- pluma 8y agoFWIW while you're right, that's awfully shortsighted unless you're a mom & pop shop with no intent of ever expanding beyond your backyard. A lot of devs hanging out on HN are working for companies that have at least some B2B aspect. Being GDPR non-compliant means these companies will have to avoid you too, because even if they're themselves not affected by GDPR they may have customers who are and need the compliance to be able to do business with those customers. But that said, as an EU company, US companies are only an option if they're Privacy Shield certified and offer a Data Processing Agreement. And even then it's safer to go for a company in the EU or in an "adequate"[0] country. You don't want to be caught unaware when some court or orange person decides to blatantly violate the Privacy Shield guarantees and you have to treat it as a breach. [0]: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en https://ec.europa.eu/info/law/law-topic/data-protection/data...
- jhall1468 8y agoThe US is an enormous market. You could easily be a multi-billion dollar company without having a single presence in the EU. Hell you don't even have to stay in the US market, since Asia is a thing. Calling it a "backyard" is disingenuous. Most companies are going to follow this because they have global aspirations, but that doesn't mean it's impossible... or even all that hard.
- zhdc1 8y agoI've seen plenty of EU news sites try to get away with an updated 'cookie' privacy policy popup, so we'll see what happens.
- techsin101 8y agoWhere can you read about who needs to do what
- xd1936 8y agoThat's a powerful headline, but unless I'm being A/B tested, it has little to do with the article. Did you mean to link to "13 things to know about the GDPR"?
- exikyut 8y agoIt seems to have been modeled off of https://www.reddit.com/r/firefox/comments/8m0f03/mozilla_will_not_update_its_privacy_policy_it/ https://www.reddit.com/r/firefox/comments/8m0f03/mozilla_wil...
- LandR 8y agoI got the email from mozilla too, where they say it's not another privacy policy update and link to that same blog post. I guess from the email it was implied that they are already compliant, but then the linked blog post in the email in no way confirms that... Weird. The email said: >> Does it seem like every service, app or subscription you've signed up for is sending you a privacy policy update? It's all because of the General Data Protection Regulation, aka the "GDPR," a sweeping new European regulation taking effect this Friday. GDPR has implications for many organizations, and that includes Mozilla. But unlike other organizations, Mozilla has always stood for and practiced data privacy principles that are at the heart of privacy laws like the GDPR. It feels like the rest of the world is catching up to where we've been all along.
- samfriedman 8y agoI don't see where the current headline fits in with the blog post linked. Perhaps a better article (though I still can't see as strong a headline) would be https://blog.mozilla.org/blog/2018/05/23/the-general-data-protection-regulation-and-firefox/ https://blog.mozilla.org/blog/2018/05/23/the-general-data-pr... >Our Firefox data collection review process is the cornerstone of our effort to meaningfully practice privacy-by-design and assess privacy impacts to our users. We believe it is consistent with the GDPR’s requirements for privacy impact assessments. Mozilla has had this process in place for several years and revamped it in 2017.
- dekrg 8y agoThat's interesting as what it's website privacy policy actually says looks the exact opposite of GDPR compliant. From https://www.mozilla.org/privacy/websites/ https://www.mozilla.org/privacy/websites/ which is linked from as Privacy link from https://addons.mozilla.org https://addons.mozilla.org. >We may use cookies, clear GIFs, third party web analytics, device information, and IP addresses for functionality and to better understand user interaction with our products, services, and communications. Learn More >You can control individual cookie preferences, indicate your cookie preferences to others, and opt-out of web analytics and optimization tools. Learn More
- gcthomas 8y agoIf the data collected is not personally identifying data, then GDPR is not interested in it. Maybe it is PII, but the quoted policies don't say that. > We may also use cookies, device information and IP addresses, along with clear GIFs, cookies and third party services to help us understand in the aggregate how users engage with our products, …
- throwaway2016a 8y agoOne of the most common interpretation I've heard is that IP address is PII according to GDPR. Even if not combined with other PII. So based on this description they are doing PII.
- pmlnr 8y agoIf they _store_ IP. You will see an IP with every single connection to a service. If you don't store it - but say, you store a country level geolocation instead - it's not PII.
- deleted 8y ago[deleted]
- pjc50 8y agoFrom the text of the directive: "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them. An IP address is an "identifier". However, an IP address does not in and of itself identify a natural person; you know that, I know that, and even the GDPR knows that. However, if you start building a map of IP addresses to user real names, or some other form of profile construction, then the IP addresses become personal information. (comment hoisted from other thread)
- stevespang 8y agoWhat a striking coincidence who the article uses as their sole example under "Violations": 10. Violations will cost big. Like, really big. In the past, penalties for irresponsible data collection and management were low enough that it was, perhaps, more profitable for big players to eat the fines. Now, however, “organizations in breach of the GDPR can be fined up to 4% of annual global turnover or €20 Million (whichever is greater).” While it’s still unclear what a “significant” violation would be, here’s how a fine could add up for for Alphabet, the holding company of Google. Alphabet made $110 billion in 2017, so a significant violation against the GDPR could result in a whopping $4.4 billion fine. (!!!)
- billysielu 8y agoOK great, can we have First Party Isolation enabled by default now? Y'know, for privacy. Browsers should be protecting users by default.
- JohnTHaller 8y agoJust have the browser present the user with the choice on install. ( ) Enable third party cookies. This may allow third party websites to track you across the internet. ( ) Disable third party cookies. This may break some functionality on some websites. It's no more confusing to end users than the endless sets of checkboxes websites have to use for GDRP or the pointless click OK to accept cookies notices.
- billysielu 8y agoYeah I'd be happy with that approach, should include upgrades as well as new installs though. Just to have every user aware that their browsers contain a single setting that can prevent vast amounts of tracking would be a huge improvement over today.
- zerostar07 8y agoYup thats how it should be. Technical solutions are always superior to regulations.
- coffeeiscold 8y agoIt seems like the regulations help to create an environment conducive to innovation. There is now a strong incentive to solve the problem "a better way". Let's hope it happens!
- JohnTHaller 8y agoExcept they don't. If they'd simply legislated that all web browsers have to ask that question, awesome. Instead, they legislated that every business on earth has to explain it to end users and separately ask for consent. So, even if all web browsers were updated to correctly ask for third party cookie permission, every business on earth still needs to do all the expensive hoop jumping.
- kuschku 8y agoGreat, so about:addons doesn’t use tracking Google Analytics cookies anymore? Or has a visible way to disable it (you need to enable DNT to get rid of this). And Firefox Nightly does not track personally identifiable telemetry anymore? No. Mozilla still tracks every step I take. What the fuck, Mozilla? EDIT: Example. Go to If you go to view-source:https://addons.mozilla.org/en-US/firefox/ https://addons.mozilla.org/en-US/firefox/ — In the code you’ll find Google Analytics, and if you open the page, it’ll set tracking cookies. No cookie notice, no opt-in, at all. How the FUCK is this supposed to be GDPR-compliant? Cambridge Analytica is more GDPR-compliant than this. EDIT 2: See also https://github.com/mozilla/addons-frontend/issues/2785 https://github.com/mozilla/addons-frontend/issues/2785 to show that about:addons loads addons.mozilla.org, including the Google Analytics trackers without opt-in. EDIT 3: See also https://www.mozilla.org/en-US/firefox/channel/desktop/ https://www.mozilla.org/en-US/firefox/channel/desktop/ which explains that Nightly and Beta always send telemetry, which can not be turned off in any way, and your only way to avoid it is to stop using the product, which again violates the GDPR section on "free consent".
- djsumdog 8y agoIt makes me think back to the Mr. Robot ad fiasco a while back.
- Sylos 8y ago...in which no personal data was collected at all. Just because in some ways it's technologically possible for Mozilla to track your stuff, does not mean that they actually do it, that they actually violate their privacy policy or now the GDPR.
- jacquesm 8y ago> Go to If you go to view-source:https://addons.mozilla.org/en-US/firefox/ https://addons.mozilla.org/en-US/firefox/ Good catch!
- GlitchMr 8y ago> Great, so about:addons doesn’t use tracking Google Analytics cookies anymore? Or has a visible way to disable it (you need to enable DNT to get rid of this). I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. > EDIT 3: See also https://www.mozilla.org/en-US/firefox/channel/desktop/ https://www.mozilla.org/en-US/firefox/channel/desktop/ which explains that Nightly and Beta always send telemetry, which can not be turned off in any way, and your only way to avoid it is to stop using the product, which again violates the GDPR section on "free consent". Options -> "Privacy & Security" > "Nightly Data Collection and Use" Also, it uses word "automatically", not "always", and "Learn more" link on this page tells you how to disable that. Additionally, telemetry information is NOT personal data - it stores information like how many times you have opened web browsers, how many tabs do you use, but it doesn't send personal data. Crash reports may contain personal data, but even on nightly, they aren't automatically submitted.
- AznHisoka 8y agoGood. Now make sure you don't email me to tell me your privacy policy has not change please :)
- deaps 8y agoI've gotten emails from sites I signed up for at least a decade ago. I find it troubling that that many sites I've signed up for had to actually change their privacy policies because of this. But I guess in the end, it's a good thing that they're all changing.
- OldSchoolJohnny 8y agoPretty much every site you ever had to sign up for has had to change things, it's part and parcel of the process.
- kadenshep 8y agoGDPR is the best thing to have happened to the internet in a long while.
- diego_moita 8y agoI downvoted because your comment doesn't add anything to the discussion and, in the context of this post, looks a bit like trolling. There are people that like and do not like the GDPR. Telling that you belong to one group is not even information.
- kadenshep 8y agoI'm stating an affirmative position. You wrote two paragraphs explaining why you clicked a button because you don't think my post adds anything to the discussion, or is somehow trolling.
- antR3 8y agoDoes it mean they will stop tracking us with google analytics on their websites ??
- throwaway974 8y agoI have a profitable, bootstrapped SaaS business. It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication. I've been talking to a very well known giant corporation for months. The VP and director love my product and want to start using it right away for their department. But their legal team is scared shitless with 4% fines in GDPR. They are putting some draconian clauses, (various ISO certifications and such) in the contract that I, as a small company, cannot comply. That's their interpretation of GDPR. It doesn't matter whether it's right or wrong. The VP and Director are really nice people and I've developed very good rapport with them. But I'm afraid their patience will run out soon and they'll go back to using spreadsheets. A lose-lose situation. This is the side-effect of GDPR. I'm all up for GDPR. I have uBlock, have blackholed all Facebook domains, etc. But don't assume that GDPR doesn't affect normal business transactions. Anyone who says, "Oh, how hard could it be?" has no idea what they are talking about.