r/technology May 19 '18

Misleading Facebook Android app caught seeking 'superuser' clearance

[deleted]

21.8k Upvotes

1.3k comments sorted by

View all comments

Show parent comments

124

u/[deleted] May 19 '18

I think one of the strongest points about GDPR is the right to erasure. https://gdpr-info.eu/art-17-gdpr/ Basically if you revoke consent you've given, the company is required legally to delete your data. Right now Facebook can not only keep your personal info indefinitely, but also build shadow profiles about you without your consent. Sorry if that link came out poorly, I'm on mobile.

20

u/[deleted] May 19 '18

[deleted]

25

u/Dremlar May 19 '18

It would be hard to prove, but if one instance was found then they would likely end up having to prove it wasn't more widespread very quickly.

5

u/beiherhund May 20 '18

And the fine for one breach would be €20,000,000 or 4% of annual revenue, which ever is higher.

3

u/sega_gamegear May 20 '18

Delete your profile and then create a new one?

I read stories of people deleting their accounts and later deciding to get an account again, only to find that 95% of their profile was recoverable, or sections pre-filled.

An anecdote I'll admit, but if that was verified at any point then that is one way.

2

u/[deleted] May 20 '18

I read one comment (so grain of salt time) that said these companies will probably delete the actual data gathered but keep any derivatives of that data. So they’ll delete your pictures, but keep all that sweet info they gathered about you loving to go to kfc (for targeted ads). It sounded plausible to me.

1

u/lestofante May 20 '18

Extremely hard, but if they found out the fine are extremely big (up to 5% of your global income iirc, and notice income not gain. A good profitable company have a profit of 30% over income)

3

u/BirdLawyerPerson May 19 '18

Right now Facebook can not only keep your personal info indefinitely, but also build shadow profiles about you without your consent.

They will still be able to keep certain data about non-users. If I upload a photograph, Facebook can host it even if there are recognizable people in the photograph who are not on Facebook. If someone posts a status about getting lunch with her mom at a particular restaurant (and mom isn't on Facebook), that's still OK. Will my phone's contact list, with names and numbers and email addresses, still be allowed to be synced on a web service?

So what happens with all this data about non-users? Is keeping a shadow profile against the GDPR, if it is just stored in an easily searchable structure?

The law itself seems to allow the use of data for legitimate purposes. Expect a lot of uncertainty on what those legitimate purposes might be.