Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Next week's EU data protection "safe harbour" decision may require exactly that: Facebook may no longer be allowed to export personal data from the EU.

Edit: data protection would also have a huge effect on the "peeple" app, discussion of which seems to be banned on HN.



Nobody should be allowed to export personal data from such jurisdictions except for the owners of that data themselves. A U.S.-ian should be allowed to decide to trust their personal data to a company inside E.U. jurisdiction but that company shouldn't be allowed to trade that data anywhere else (especially, back to the U.S.). Of course, that's a complete pipe dream, and I'm just hallucinating.


How do you define "export"? Does that mean any website needs to have a server located in every single country in the world?


I imagine that would only apply to sites which store PII[1]. The database should be located under the same jurisdiction (which doesn't mean every country, since some will have treaties to allow exporting to certain places (EU for example)) as the person whose data it is, and the data should not be transferred through other jurisdictions.

[1]: https://en.wikipedia.org/wiki/Personally_identifiable_inform...


Well, pretty much any website stores an email, name and password. Every startup would need to look at all the bilateral treaties between every major country in the world. This is simply impractical.


If a German user shares data with Facebook, Facebook should not be allowed to give the data to any entities in the US.

You may never give userdata to anyone else or give anyone else access to userdata.

Embedding tracking scripts from third parties is equally problematic. Google Analytics should be globally forbidden.


What if the user shares the data directly with a server in the US? People don't care...


And what if Google Analytics tracks me? 3rd-party tracking needs to be illegal right now.


That would only force people to confront the uncomfortable reality that just because data is about you doesn't mean you own it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: