Endpoint

5/25/2018
12:10 PM

Privacy Group: Facebook, Google Policies Break GDPR Laws

Nonprofit 'None of Your Business' files complaints against Facebook, Google, WhatsApp, and Instagram.



Privacy activists are taking aim at major tech companies they argue are noncompliant with Europe's new General Data Privacy Regulation (GDPR), which came into effect today.

Nonprofit organization None of Your Business (NYOB), founded by Austrian Facebook litigant Max Schrems, has filed official data protection complaints against Google, Facebook, WhatsApp, and Instagram. Schrems created NYOB to fight back against companies that break GDPR rules, which state companies can only process users' data with legal justification.

There are multiple justifications for processing users' data, including consent, the GDPR states. However, users can't be forced into submitting their data in order to use a service.

NYOB says Facebook and Google violate GDPR by compelling users to agree to their privacy policies. The regulation is intended to give users a choice about whether to share their data, but the sense of freedom is eliminated when sites prompt people with "consent boxes," which state a service can no longer be used if the visitor doesn't consent to their data being processed.

"Facebook has even blocked accounts of users who have not given consent. In the end users only had the choice to delete the account or hit the 'agree' button–that’s not a free choice; it more reminds of a North Korean election process," said Schrems in a statement.

The primary Facebook complaint was filed in Austria; those for Instagram and WhatsApp were filed in Belgium and Germany, respectively. Another case against Google, which argues Android's consent requirements go against GDPR, has been filed in France.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
5/31/2018 | 8:55:15 AM
Re: NYOB
They sound like a modern version of Ralph Nader for the Internet :)
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:12:55 PM
Re: GDPR, will it really work?
Somehow I start getting advertisements of thing I ALREADY bought on Amazon. That must be about Amazon, they share your buying habits with expernal clients.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:11:18 PM
Re: GDPR, will it really work?
I don't have a google account That is great. However I would not want my gmail taken away.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:10:06 PM
Re: GDPR, will it really work?
Some of these consent forms are an all or nothing, even under GDPR. That is true, they are designed that way om purpose of course.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:08:55 PM
Facebook
Facebook has even blocked accounts of users who have not given consent. Giving that ths is facebooks business we should not expect the, to provide service without a consent.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:06:47 PM
NYOB
Never heard this group but nice name hopefully they get something achieved.
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
5/29/2018 | 10:14:13 AM
GDPR, will it really work?
I find this fascinating.  Some of these consent forms are an all or nothing, even under GDPR.  Fortunately I a) don't have a Facebook account and b) don't have a google account.  I refuse.  Last left is Amazon.  Somehow I start getting advertisements of thing I ALREADY bought on Amazon.  What the heck?  I don't need their suggestions.  I look for what I want when I need it, not because they advertise or 'recommend' something I don't want and don't need.
Weaponizing IPv6 to Bypass IPv4 Security
John Anderson, Principal Security Consultant, Trustwave Spiderlabs,  6/12/2018
'Shift Left' & the Connected Car
Rohit Sethi, COO of Security Compass,  6/12/2018
Why CISOs Need a Security Reality Check
Joel Fulton, Chief Information Security Officer for Splunk,  6/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12557
PUBLISHED: 2018-06-19
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items would be printed in the console. This could ...
CVE-2018-12559
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequ...
CVE-2018-12560
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring.
CVE-2018-12561
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.
CVE-2018-12562
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).