17 ms·
Messenger API Updates for Europe
- mattlutze 6y agoHow do people here feel about these changes? I've the initial impression that this will be a good step for reducing the drift of user content into other websites and spaces where messages or user data may end up outside of the context for which it was generated.
- robert_foss 6y agoWhat are they claiming is motivating this change?
- voctor 6y ago> As part of our efforts to comply with new privacy rules in Europe
- rbinv 6y agoThat doesn't really say very much. What new rules? Why the API?
- mgraczyk 6y agoepd
- ratww 6y agoepd means e-Privacy Directive [1] for those who are not familiar with the acronym [1] https://edri.org/our-work/epd-faq/ https://edri.org/our-work/epd-faq/
- HatchedLake721 6y agoSorry but epd (ePrivacy Directive)[0] is from 2002 with last amendments in 2009 and has nothing to do with this. There's a draft for "ePrivacy Regulation"[1][2] introduced in 2017 that looks to replace ePrivacy Directive, but it's still in a draft and discussions stage. There's no guarantee it'll become a law. [0] - https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32002L0058 https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32... [1] - https://www.mckinsey.com/business-functions/risk/our-insights/what-will-europes-eprivacy-regulation-mean-for-your-business https://www.mckinsey.com/business-functions/risk/our-insight... [2] - https://en.wikipedia.org/wiki/EPrivacy_Regulation https://en.wikipedia.org/wiki/EPrivacy_Regulation
- nindalf 6y agoSorry but you’re mistaken. The original ePD applied to messaging services, ie, SMS providers. What changed this year is that a few months ago the EU decided that providers like Messenger should be covered by the regulation too. Source - worked on ePD compliance.
- Dayshine 6y agoCould this be why Google are withdrawing their free phone calls on Google home devices in the UK as well?
- HatchedLake721 6y agoThanks! But I don't understand how ePD with no changes from 2009 can suddenly include Facebook and others? Unless there have been other regulations passed? I can't find anything about ePD changes that forces Facebook to do this, all I can find is the upcoming ePR (ePrivacy Regulation) that will affect Facebook and others, but it hasn't been passed yet. I haven't heard of any privacy/GDPR/ePD changes recently other than the EU-US Privacy Shield invalidation. Is there anything I can read on the changes you're talking about?
- nindalf 6y agoSorry, everything I’ve read is internal material. The lawyers spoke to the EU and were told this needs to happen right away. So it is happening.
- HatchedLake721 6y ago> ...lawyers spoke to the EU and were told this needs to happen right away Sorry but this is not how EU works and it doesn't make any sense at all. You can't "speak with the EU", in the same way you can't "speak with the United States of America". You can speak with a data regulator in a specific country if you wish so. But each one of them is also part of the European Data Protection Board, which ensures the consistent application of data protection rules throughout the EU. I can understand lawyers speaking with one of the regulators, and been told about the ePR "ePrivacy Regulation" proposal that looks to repeal the ePD "ePrivacy Directive". But we live in a sane world (at least here in the EU) where impactful regulations and directives don't change overnight without any notice and implementation period. The ePR "ePrivacy Regulation" draft suggests a 24-month transition period, similar what happened with GDPR which was agreed in 2016 and went live in 2018. So the earliest ePR will take effect as of today is 2023. Having some "lawyers speak with the EU" about some unannounced "internal material" that "need to happen right away" doesn't make sense. So no, I don't see how your or Facebook changes were influenced by ePD "ePrivacy Directive" from 2002/2009.
- remus 6y agoJust speculating, but it could be to do with the recent ruling that the EU-US Privacy Shield data sharing agreement was invalid https://easygdpr.eu/2020/08/privacy-shield-invalidated-what-happens-now/ https://easygdpr.eu/2020/08/privacy-shield-invalidated-what-... This means that data sharing between the US and EU is a lot more complicated, as the EU ruling basically says that US data protection regulations are not sufficient to comply with the requirements set out in the GDPR.
- lucideer 6y agoSome further context on the case, with dates: https://www.irishtimes.com/business/technology/transatlantic-data-transfers-once-again-in-the-dock-1.4299500 https://www.irishtimes.com/business/technology/transatlantic...
- rethab 6y agoGreat news! Less so for Switzerland? Because this does not seem to apply to Switzerland, which has signed the EEA agreement, but did not join.
- yvan 6y agoI am wondering about the same, even though Liechtenstein is mentionned which has the same agreements as CH with Europe.
- 3np 6y agoSo instead of making their system less-privacy-invasive (which I have seen no indication should be impossible wrt the APIs mentioned here), they just shut down services where this is regulated. Not surprised, but there's no way to spin this in a way that doesn't make Facebook look shady and bad. So much for "working with regulators".
- bzb6 6y agoWhat makes you think the APIs could be changed to comply? Maybe there’s no way to implement what they used to do legally.
- asutekku 6y agoYou can see what API calls do not work on the listed page. Most of those should not require any privacy breaking features so it should absolutely be possible to implement them legally. They just don't like to do so.
- red_admiral 6y agoThis is just speculation on my part, but if facebook implemented these API calls in a privacy-respecting way for the EU market, then it would be very easy for the US government to suggest that the already-existing privacy-respecting version should be used in their jurisdiction too. Maybe that's what facebook wants to avoid?
- matthewmacleod 6y agoIt does say: "We are currently working to restore these features and will continue to update this document and the changelog section with the details as they are available." Doesn't this suggest that they aren't being shut-down?
- diggan 6y agoIt might be temporary, but removing features "temporary" certainly sounds like being shut down, but temporary. Interesting that Facebook and everyone else has been knowing that these rules have been coming for years, they still haven't been ready. Certainly reads like they haven't been working with anyone, and their last resort is now to temporary shut down the features they were unable to fix, during these years.
- antihero 6y agoWhile Messenger is linked to our Facebook account state, where you can be arbitrarily banned for any reason without any accountability or recourse, the idea of relying on Messenger as a communcations app is an absurd proposition.
- ajsnigrutin 6y agoProblem with this is, that you have a massive number of users on facebook, and not wanting to do business using them, could be a massive hit to your sales. I know people, who only look for businesses on facebook, ask for support questions there, and dont't care if the business doesnt have a full webpage, if it has a facebook page (and even if it has, sendin an email is a lot "harder" than just clicking "chat" on a facebook page, to ask something (eg. if they're open now, due to pandemic,etc.).
- antihero 6y agoI mean, if I was a business I'd look at using it purely for that, but as a personal service? Absurd.
- bryanrasmussen 6y agoI guess, for GDPR purposes, they would need to show why they can't provide the service without privacy invasion.
- pjc50 6y agoThis is desperately short on explanation? The very high granularity suggests that some features are more privacy-invasive than others, but not why that is. (Also, listing the UK under EEA is .. complicated and subject to change in the next few weeks. https://en.wikipedia.org/wiki/Membership_of_the_United_Kingdom_in_the_European_Economic_Area https://en.wikipedia.org/wiki/Membership_of_the_United_Kingd... )
- jon-wood 6y agoWhile come January the UK won't be part of the EEA, at least initially GDPR will continue to apply as most EU law has been grandfathered into UK law post-transition.
- pjc50 6y agoYes, but as far as I'm aware the question of whether the UK will be a "third country" for purposes of data transfer outside the EU after January 1 is still undecided? (Where is Facebook's data center anyway, is it Ireland?)
- fnord123 6y agoForest City, North Carolina; Altoona, Iowa; Fort Worth, Texas; Los Lunas, New Mexico; Clonee, Ireland; Lulea, Sweden; and Odense, Denmark
- legulere 6y agoEU laws and regulations still apply to the UK. It’s not clear though what the situation will be starting with the first of January next year.
- rsynnott 6y agoThe UK is subject to EU law and is part of the EEA today; they have to go on what's true now, not what may be true in a few weeks. In any case the UK will inherit most EU data protection rules; they'll presumably change the wording in January, but the rules won't change.
- kevincox 6y agoIt seems like some of these features were loading images directly from the client. So presumably this could have been used to get info like your browser and IP as your phone made the request to the server that they provided. The recommended work around to to just send the link which now makes it explicit to the user that they are connecting to the third party.
- miohtama 6y agoIf this theory is correct, sounds like they want to avoid another Cambridge Analytics incident.
- jrochkind1 6y agoHow is prohibiting sending audio/video attachments in messages related to complying with privacy regulations?
- Shorel 6y agoThe way this page destroys my browser history and disables the back button is a bit troublesome...
- jFriedensreich 6y agoWe need a decent gdpr compliant business dependable rich messaging platform for europe. it is ridiculous, now the rest of the world has wechat, messenger, kakao and line, but in europe there is nothing.
- howlgarnish 6y agoI thought both Teams and Google Chat claim GDPR compliance?
- jFriedensreich 6y agoGoogle chat is not business dependable because google shuts down and replaces its messaging product every 4 years or so. Teams is not a platform in the sense that you could not eg. start selling pizza to random endusers with a pizza bot. I mean something that can be a european wechat revolution.
- _a1_ 6y agoGreat news, I feel much safer now. Now I'm waiting for EU to completely ban computers, this way I will never be attacked by anyone online. But seriously, if anyone had doubts what GDPR will achieve, I think this person is pretty naive. GDPR is not a progression, but a regression, and it will seriously hit (already does) online businesses in the long run. Same thing with cookie warnings. No normal person will read tons of legal text on every website they visit. And even if the normal person will read it, they won't be able to decline the cookies, because the site will not work. But let's say you're a technically savvy person that is actually interested in cookie privacy; I'm really surprised you're not using "cookie autodelete"-style plugins already. Creating laws only to have laws will never work. It only creates cost for everyone in order to be compliant. And people always go where the cost is lower.
- Allezxandre 6y ago> But let's say you're a technically savvy person that is actually interested in cookie privacy; I'm really surprised you're not using "cookie autodelete"-style plugins already. I feel this is like saying "we don't need safety legislations at work because businesses take a hit trying to stay compliant, if you don't want to be hurt at work, I'm surprised you're not wearing a helmet already." Thing is, I wouldn't need "cookie autodelete" style plugins in the first place if companies cared about data privacy.
- _a1_ 6y agoYou shouldn't wear a helmet because other people tell you need to wear it. Instead, you should wear it in order to be safe. The problem with law is that only good guys abide the law. And you don't need to defend yourself from the good guys, only from the bad guys. And bad guys will violate the law anyway.
- kalleboo 6y agoCookies that are required for the site's functionality (like login, shopping cart, etc) are allowed without even an opt-in dialog
- spunker540 6y agoSeems like a huge hit to the myriad business-to-consumer chat startups that sell premium messenger experiences to brands for customer service etc. It’s also a hit to any business who has invested in chat as a service/sales channel, assuming that all chat APIs will be subject to the same limitations. These APIs that are being limited have very little to do with user privacy and mostly impact usability. For example it looks like handoffs between chat apps are no longer possible in Europe- a company could have an entry point chat bot that routes to a live human, or routes to an order-taking bot. That routing is no longer possible without the “handoff protocol”. It looks like users can no longer send attachments to a business either. (Or rather they can still send the attachment, but the business can’t use the api to access it?). I don’t believe this is a win for users and just shows some unintended side effects of EU legislation.
- KIFulgore 6y agoUnintended by the legislators, maybe, but I'd wager this punitive reaction by Facebook is very intentional. Many EU businesses are going to have their commerce and customer service flows break 9 days before Christmas. It will be interesting to see how much backlash from these businesses is leveled at the EU regulators and how much is directed toward getting off Facebook's platform.
- jj2702 6y agoI've added a guide here to help you figure out the impact on chatbots specifically: https://medium.com/chatlayer/breaking-facebook-messenger-api-updates-for-chatbots-in-europe-4db39ae3a330 https://medium.com/chatlayer/breaking-facebook-messenger-api...