Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This comment is really inaccurate. Under GDPR you must have a legal basis for all data processing activities. In the case of maintaining a social profile, the legal basis is "explicit consent" pursuant to "serving the interests of the data subject". Therefore the posts on the wall can stay up as long as the user continues to consent to their staying up.

What cannot be kept indefinitely is the data that Facebook has not received explicit consent for -- the profiling in the background, scraping information from other sites, and so on.



HN seems united in its love of this legislation (someone even called me a "f*cking ignorant clown" in a flagged comment below), so I'll leave this thread with this. GDPR wouldn't be the first time that well-intentioned but broadly written laws have created the potential for unforeseen and very nasty results. One recent example is how the passage of FOSTA - a law designed to deter human trafficking - resulted in the instant shutdown of one of the largest and oldest personals sites on the Internet [1].

Broadly written legislation, whether intended by its authors or not, always winds up being used as a tool to gain leverage where the government didn't have it before. So yes, there will be some good things that result from this legislation, just as some good things will likely result from FOSTA. But because it is so broadly written and many things in it will be up to the interpretation of individual courts when actions are brought under it, mark my words: it will be used in ways that nobody defending it in this thread has thought about, to impose fines and other sanctions on companies (perhaps even some of the startups of HN users, should some government person in the EU take issue with their business) for reasons that you may very well not agree with.

[1] https://www.craigslist.org/about/FOSTA


I believe previous legislation regarding cookies was a mess like you said, and a big learning process for the EU.

I’ve worked with people who are experts on the new regulations. They don’t seem to be at all confused about what it means or implies. The only unknowns they’re talking about is the practicalities of someone like Facebook conforming eg requesting many different permissions. But that’s because businesses like Facebook are doing unethical stuff, ie they’ve been doing things you really won’t want to explicitly give them permission to do.


> always winds up being used as a tool to gain leverage where the government didn't have it before.

GDPR builds on previous law, such as PECR and DPA.

If it's not legal under GDPR there's a good chnce it was already not legal under PECR or DPA. And we didn't see those used by governments to get leverage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: