TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

German court rules Facebook use of personal data illegal

650 pointsby HoppedUpMenaceover 7 years ago

14 comments

limaover 7 years ago
That article doesn&#x27;t summarize the ruling very well. Here&#x27;s a short tl;dr of the actual ruling[0]:<p>Part A: Privacy settings<p>- Facebook tried to claim that it is only subject to Irish law. Court disagrees since Facebook operates in Germany, so local law applies. [side note: this kind of confusion is exactly why the GDPR is needed]<p>- Law states that the imprint must be &quot;easily&quot; accessible. Court found this not to be the case (it took three clicks and was hidden behind a link called &quot;explanation of your rights and duties&quot;).<p>- Law states that explicit, informed consent is necessary for the kind of data processing Facebook does. Facebook pointed users to the privacy settings page where all settings were enabled by default. Court found that this constitutes neither explicit nor informed consent - the settings would have to be opt-in, or the user needs to be explicitly informed about the full extent of how his data is used (&quot;without any doubt&quot;).<p>Court explicitly states that presenting an opt-out <i>after</i> registration and login is not sufficient, especially if it is presented as an optional &quot;privacy tour&quot; that most users are going to ignore.<p>- Plaintiff stated that Facebook incorrectly claimed it was &quot;free forever&quot;, when users were in fact incurring hidden costs by volunteering their personal data [&quot;paying with their data&quot;]. Court strongly disagrees - no money is changing hands, after all. They do recognize that there&#x27;s a counterpart, but it&#x27;s immaterial and as such does not constitute a &quot;hidden cost&quot;. Court basically states that the meaning of &quot;free&quot; is not up to debate.<p>Part B: Terms of Use<p>- Terms of use state that the user &quot;acknowledges&quot; to have &quot;read&quot; the privacy policy during registration. This is invalid in two different ways - a mere &quot;acknowledgment&quot; is insufficient, since it puts the burden on proof on the user, and since parts of the privacy policy are invalid, the user can&#x27;t legally agree to it its entirety anyway.<p>Court explains that &quot;read and understood&quot; clauses like this one are invalid. Clearly, the user didn&#x27;t actually read and understood the whole thing - but the language in the terms forces him to admit he did, which would disadvantage him by implying informed consent about everything in it when he didn&#x27;t explicitly consent to anything.<p>- There&#x27;s a clause in the ToU stating that the user &quot;agrees to use his real name&quot;. This does not constitute informed consent since the user isn&#x27;t properly informed - Facebook does not state <i>why</i> his real name is required and how it will be used.<p>The court states that it is questionable whether a real name policy is at all legal, underlining the need for proper consent due to the significant consequences of volunteering one&#x27;s real name.<p>- Same for &quot;agreeing that personal data is transferred to the US&quot; - no explanation why data is transferred, what it will be used for or even what data is transferred. In addition to that, there&#x27;s no indication which data protection standards are applied.<p>- Similar case for &quot;agreeing that the profile picture is used [...] commercially&quot;: no informed consent since the user is not informed about the consequences.<p>... and a few more clauses where the court finds that no informed consent is given by the user due to very broad clauses with little explanation.<p>- It&#x27;s OK to have the user agree that he&#x27;s 13 years or older. Facebook cannot possibly check whether it&#x27;s true, and the age doesn&#x27;t matter anyway since the contract would be valid even if it weren&#x27;t the case.<p>- Plaintiff complained about a few informational clauses in the privacy policy. Court rejected this since they weren&#x27;t part of the terms of use due to their purely informational character (user isn&#x27;t agreeing to anything).<p>This was a very interesting read. It is very clear that the courts take the requirement of &quot;informed consent&quot; very seriously, as they should. Is is not enough to present the user with a 100+ page privacy policy and have him agree to it, they actually need to present it such that the user realizes what they&#x27;re agreeing to.<p>[0]: <a href="https:&#x2F;&#x2F;www.vzbv.de&#x2F;sites&#x2F;default&#x2F;files&#x2F;downloads&#x2F;2018&#x2F;02&#x2F;12&#x2F;facebook_lg_berlin.pdf" rel="nofollow">https:&#x2F;&#x2F;www.vzbv.de&#x2F;sites&#x2F;default&#x2F;files&#x2F;downloads&#x2F;2018&#x2F;02&#x2F;12...</a> (interesting part is page 22 onwards)
评论 #16363705 未加载
评论 #16364273 未加载
评论 #16363390 未加载
评论 #16366326 未加载
评论 #16364735 未加载
评论 #16363629 未加载
评论 #16366210 未加载
评论 #16369122 未加载
评论 #16364122 未加载
waytogoover 7 years ago
Wait until GDPR is in place in May and German and other EU courts will rule FB to death.<p>IDK how FB will ever be compliant with GDPR and survive that huge upcoming fines in the long term or in the worst case the withdrawal from these markets.
评论 #16362066 未加载
评论 #16362270 未加载
评论 #16362674 未加载
评论 #16362033 未加载
评论 #16362921 未加载
评论 #16363592 未加载
评论 #16369311 未加载
评论 #16366089 未加载
1risover 7 years ago
German news reports have a very different angle on this.<p>German law forbidds a real-name policy, has to allow pseudonymous usage and advertise this fact as long as it&#x27;s technically possible and feasible.<p>German law is obvious, but not weather facebook is bound to it. The court ruled it is.
Tharkunover 7 years ago
FB have taken out huge newspaper and billboard ads in Belgium, pretending to care about your privacy. They&#x27;re trying to divert attention from their real privacy issues, by saying &quot;you can choose who can see your stuff&quot;.
评论 #16362221 未加载
评论 #16362544 未加载
评论 #16362243 未加载
AndrewKemendoover 7 years ago
I&#x27;d argue there is no way to properly communicate to the average facebook user how their data is being collected and used in a way that is transparent but not confusing.<p>For example, explain to someone who is illiterate in technology how the act of you &quot;tagging&quot; your friend in a photo is to offload image labeling work to train a deep neural network to infer your friend&#x27;s face.<p>If you radically simplify the issue in line with GDPR by saying something like:<p>&quot;Whenever you tag a friend in a photo you to help teach our computers to recognize what your friends face looks like&quot;<p>It makes it seem way more terminator&#x2F;ominous than it is to the average person.<p>Ok now do the same thing with all of the nlp, voice etc... data points.<p>I just don&#x27;t see how facebook is going to deploy a worldwide education effort on big data effectively.
评论 #16362645 未加载
评论 #16362331 未加载
评论 #16362379 未加载
评论 #16392019 未加载
paxyover 7 years ago
The ruling and article only mention Facebook but I don&#x27;t see how everything in it doesn&#x27;t apply to every single app&#x2F;website that does targeted advertising.
评论 #16362032 未加载
评论 #16361874 未加载
评论 #16361960 未加载
评论 #16361898 未加载
Feniksover 7 years ago
1 try not to get hacked<p>2 don&#x27;t sell your soul to marketing parasites<p>Seems like common sense really but it has (US) companies scrambling. Good. We are GDPR!
thinkloopover 7 years ago
A thought I was having recently: any communication medium (Messengers, social networks, email services, contact apps, etc) that does not use end-to-end encryption and has access to the data, may be in violation of privacy&#x2F;data laws or moral obligation that will soon become law.<p>For example in email, people can, and do, send everything including documents with sensitive information, pii, account&#x2F;payment numbers, etc. to each other - which are likely not being stored in pci compliant, and&#x2F;or other responsible ways, by the providers.<p>Social networks run platforms that facilitate <i>others</i> to provide information about <i>you</i> when you did not agree: whether you&#x27;re on Facebook or not, you&#x27;re on Facebook.<p>Same with contact apps where you fill in all your friends&#x27; contact info then simply pass it all to a company without the consent of your contacts: mass legal doxxing.<p>Any communication medium where the platform has access to the contents of the communication might be susceptible to serious future legal&#x2F;moral ramifications. There is a non-zero possibility that today&#x27;s business models might be fully illegal at some point. Perhaps replaced by decentralization&#x2F;encryption&#x2F;privacy&#x2F;crypto&#x2F;etc.
raverbashingover 7 years ago
Good<p>A lot of Germans use Fb with a fake name anyway
评论 #16361928 未加载
评论 #16361924 未加载
machinesmachineover 7 years ago
Took them long enough
neulandover 7 years ago
If the appeal doesn&#x27;t go Facebook&#x27;s way, what is the resolution to this? It sounds like they&#x27;ll just have to update their terms of service to say that you agree to allow Facebook to use your data in XYZ ways. Of course, that&#x27;ll be buried in the fine print and no-one will even notice.
评论 #16361878 未加载
peoplewindowover 7 years ago
I think if I was creating a new social media website today I&#x27;d probably not set up any presence in the EU. The sheer quantity of fines for vaguely specified &quot;crimes&quot; being handed out makes it a deeply unattractive business environment and it seems to be getting worse. I remember when Facebook was new, one of its big competitive advantages was its easy and comprehensive privacy controls. I didn&#x27;t see other social networks go significantly further in the years since. Now Germany - having failed to clone Facebook domestically (StudiVZ) - sits around extracting money on the grounds that users somehow did not consent to their data being used when they directly uploaded it to the site.<p>I don&#x27;t see the Valley&#x27;s hold on social networking loosening any time soon. For all its faults the USA doesn&#x27;t constantly fine its firms for not doing &quot;enough&quot;, whatever that means.
评论 #16361904 未加载
评论 #16361893 未加载
评论 #16361871 未加载
评论 #16362157 未加载
评论 #16362016 未加载
评论 #16362061 未加载
评论 #16361922 未加载
评论 #16361873 未加载
评论 #16362371 未加载
评论 #16362000 未加载
评论 #16362051 未加载
评论 #16361882 未加载
评论 #16362337 未加载
评论 #16362017 未加载
评论 #16362160 未加载
评论 #16362224 未加载
评论 #16362405 未加载
评论 #16366373 未加载
评论 #16363646 未加载
评论 #16361975 未加载
评论 #16361837 未加载
评论 #16361927 未加载
webreacover 7 years ago
If you decentrelize social networks, courts would need as many trials as there are networks and would get smaller fines.
评论 #16363218 未加载
salsadipover 7 years ago
I think it&#x27;s interesting that more antitrust lawsuits seem to be brought and won against big SV companies recently in Europe. Is it just recently because because bureaucracy takes its&#x27; time, or is it because nowadays there is more political will to act against American companies since EU-American relations worsened since Trump came into office?
评论 #16361956 未加载
评论 #16361978 未加载
评论 #16362159 未加载
评论 #16361949 未加载
评论 #16361991 未加载