HN user

srrr

476 karma

Data Analyst based in Berlin. Mostly web analytics and a/b-testing, but occasionally modelling and non web data to.

hckrn@kolowski.de

Posts1
Comments72
View on HN

The concern is about the Digital Markets Act and not the GDPR.

To quote https://www.bloomberg.com/news/articles/2023-07-05/meta-won-... :

A number of companies, including Meta, have self-designated themselves as “gatekeepers” under the DMA rules, which will potentially make them subject to stricter regulations around data sharing and giving preference to their own products.

Gatekeepers are banned from combining users’ personal data across different platforms under the DMA.

Threads is designed to let users follow the same accounts they’ve connected with on Instagram and keep their Instagram usernames, helping the social media giant leverage its billions of users to quickly gain scale.

I think the term gatekeeper makes more sense if applied to companies like Apple, Google, Microsoft & Co, with their search engines, maps, app stores, operating systems, browsers ... all these are gateways to "the digital market". Twitter might be to small and comparatively niche to be classified as a gatekeeper. There does not seem to be an exact definition that I could find. But social networks as a category and companies like Meta/Facebook are listed as gatekeepers.

The European Union Digital Markets Act, coming into effect in May 2023, explicitly forbids such behavior. (If twitter is classified as a "gatekeeper".)

https://commission.europa.eu/strategy-and-policy/priorities-...

Example of the “don'ts” - Gatekeeper platforms may no longer:

- treat services and products offered by the gatekeeper itself more favourably in ranking than similar services or products offered by third parties on the gatekeeper's platform

- prevent consumers from linking up to businesses outside their platforms

Our world in data has a nice graph showing some countries that where able to decouple CO2 emission from GDP growth showing that this is indeed possible: https://ourworldindata.org/grapher/consumption-co2-per-capit...

And I am totally for these "million other lefty-green things". Solar and wind is comparatively cheap to install and comparatively low effect on nature. The resulting energy is also cheap (if used locally). We have many (poor) villages here in Germany owning their own wind turbines and benefiting from selling this energy, greatly improving the financial situation for the local population. It's like farming but with wind turbines.

In the long run Germany will be better of. We just have to get through this painful transition.

A German court can not, in fact, serve a court order to Volkswagen America. (Technically it can, but the order is not enforceable.) A German court is also forbidden to force Volkswagen AG to reach into Volkswagen America because these are separate legal entities.

A German court would use judicial assistance and ask US law enforcement to help. US law enforcement would then adhere to local laws and protect the rights of US citizens while trying to help.

This is named Mutual legal assistance: https://en.wikipedia.org/wiki/Mutual_legal_assistance_treaty .

No, opening a connection and exchanging IPs falls under "technically necessary" processing of personal data.

But from a legal point of view we, as a European company, are forbidden to use any US infrastructure provider. We can't ask for consent to transfer data to an US based entity if our consent form itself is already hosted by an US based entity. And even if we did find a solution, like hosting the main infrastructure with a European company and asking for consent for some later data transfer, we are most likely forbidden to transfer data to US based entities at all.

From what my lawyer told me the ruling from https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-... applies to all services from AWS, Google Cloud, ...

There will be many rulings that follow. Everybody is just waiting for the Irish Data Protection Commission to actually do its work, but the Irish DPC does not seem to be much in favor of data protection: https://noyb.eu/en/irish-dpc-handles-9993-gdpr-complaints-wi... & https://bigbrotherawards.de/en/2022/lifetime-achievement-iri...

This will change soon. From what I heard work is underway to let national data protection offices handle cases without the Irish DPC or force the Irish CPC to work.

To add: The reason why US companies can't be GDPR complaint is because of Article 5 and the conflict with the Cloud Act: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f)

"(1) Personal data shall be: (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."

See also Schrems II: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II

From what I understand the legal exception to process personal data without consent is written down in Article 6 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph b)

"(1) Processing shall be lawful only if and to the extent that at least one of the following applies: (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;"

This is ok for GDPR complaint data processors. The reason why US companies can't be GDPR complaint is because of Article 5 and the conflict with the Cloud Act: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f)

"(1) Personal data shall be: (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."

See also Schrems II: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II

It doesn't even matter if you asked for consent or have other reasons to process the data (Article 6) if you are not complying with Article 5.

IP addresses (for connection setup) are personal data: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

You can process IP addresses without consent only if it is technically necessary: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph b)

But you always (!) need consent to transfer personal data to a non GDPR compliant entity: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f)

That is not true. IP addresses are explicitly stated as personal data. That they are a technical requirement for a connection only has repercussions on how you are allowed to store and process this data and the consent you need to get from the user for your data processing.

You are not allowed to send IP addresses (even if they are a technical requirement for connection set up) to companies under US government control before you get full consent from the EU user.

The "technical requirement" exception (to process data without consent) only applies to GDPR complaint data processors which US companies can't be because of the Cloud Act.

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Yes, that might be a real difference. (But I, personally, find sugar very addictive. YMMV) But what happens if we compare the health implications? Obesity, and sugar as one of many parts of this problem, might be more deadly than nicotine. The thing is... I don't know! But it is startling how different the discussion in the UK is compared to the US. https://www.gov.uk/government/publications/e-cigarettes-an-e...

There is so much politics and misinformation in this discussion. That's not good.

ps: For me the upside of nicotine is fun. The same with alcohol. (I say this as someone who is vaping once a month and uses nicotine as a drug but does not want the downsides of cigarettes.)

So does sugar. So what's exactly the argument? If we forbid everything that might be dangerous the world would look very different. Half our food would vanish. Cars get banned...

To have a fair discussion I think we should compare to other substances we legally consume.

15 years ago when I worked in the music streaming space we also had to push users to playlists instead of albums. The reason, in Germany at least, was that a playlist only payed 1/10 the royalties to the GEMA [1] than an album playthrough. Playlists were classified as ¨radio¨ and thus a performance of the radio station but an album was the performance of the original artist.

Our interface was optimized for low royalties, not the end user. Maybe it is the same situation now.

[1] https://en.wikipedia.org/wiki/GEMA_(German_organization)

While thinking about it I found an interesting fact: If they don't produce the data that lead to the account ban because they they "don't have it", they don't actually have proof of fraud anymore. If they don't have proof of fraud you can invoke GDPR article 16 "Right to rectification" and "unfraud" your account. Theoretically they can't argue against it because they don't have any data to argue with...

If they don't unfraud you AND don't produce the data they are not in compliance of either article 15 or article 16 and have delivered the proof noncompliance themselves.

I don't think so. I have not worked on many fraud detection systems but in all cases there was a very detailed record in the logs of what happened and how the decision came to be. In addition, if there was a human review additional data is often generated. You can't just flip a bit in the customer record, or can you? (Edit: And if no information is in the logs I would argue that all information is in the input data and fraud detecting algorithm and thus the algorithm itself gets part of the data. Whatever happened, if the action can not be "replicated" / understood with the data you got after the article 15 request the data is not complete.)

Since the domain and account belongs to you as a person, this is all personal information under GDPR.

In this case cloudflare has produced a legal effect with putting the domain into pending delete because this is an ownership transfer back to the registrar (of a property they don't even own, so stupid...).

For me deleting my domain would be far worse than deleting my telephone number and significantly affect me. But yes, this is a case by case decision.

I just wanted to say something like: You have rights. Don't be afraid to use them. These companies are not above the law.

If you live in the EU the article 15 of the GDPR grants you the right to ask about the details. Often companies reply that they don't need to answer because of ¨security¨ but this is not true. You can in detail ask about ALL personal data that was used as an input for this decision, information about the ¨automated decision-making¨ (algorithm), and all personal data that resulted out of this process. https://gdpr.eu/article-15-right-of-access/

If any of this data is false you have the right to rectification. https://gdpr.eu/article-16-right-to-rectification/

On my system spatialite is 10% the speed with the Germany extract compared to PostgreSQL. Bigger extracts don't work properly.

But loading data directly from a osm.pbf or loading data via the QGis QuickOSM plugin into a spatialite file gives two problems:

1) You can not transform the data to fit your personal usage. Raw osm data is not nice to work with.

2) I had many problems with areas stored as relations (example: islands in lakes) and relation handling overall is a mess.

For the first steps and to toy around osm data in spatialite works. But don't fear osm2pgsql. For standard use cases it's a oneliner.

I do a cycle map with my own style and these are my steps and tools:

1) Download a region from geofabrik. 2) Extract, transform and load the data into pgsql with osm2pgsql. I use the osm2pgsql flex mode. QGis can load osm extracts direcly, but the resulting layers have many errors in the details and using pgsql is much faster while viewing and rendering. Imposm is also a good alternative to osmpgsql. 3) Use QGis for styling the map. 4) Generate static tiles with https://docs.qgis.org/3.10/en/docs/user_manual/processing_al... (With DPI 250 and a tilesize of 512x512 for use on high resolution screens.) 5) Upload the tiles to my own server. 6) Load the tiles in OSMAnd as a custom map.

Qgis has a build in tile server https://www.qgis.org/de/site/about/features.html#qgis-server and leaflet can load the tiles via https://leafletjs.com/reference-1.6.0.html#tilelayer-wms . But this does not work for OSMAnd.

QGis can also create beautiful print maps with the "Atlas" feature.

As long as your measurement is a random sample everything is okay. Even if it is not, it is much more information than you had before. You just need to keep it in mind when evaluating conclusions. We are not talking about drug tails here and no one dies if the measurement is not 100% accurate.

I am able to measure everything 100% accurate. But this is really really expensive. It's a trade-of.

To optimize the bounce rate metric even further a funnel can be created and measured. This allows to see bounces for each part of the funnel up to your conversion(s). It is often really valuable to see how a change on your website improves one part of the funnel but impairs another one, and than to think about the reason why this happens.