EU_Commission, to random
@EU_Commission@social.network.europa.eu avatar

We are a Union of 27 countries and 450 million people sharing one future.

Diversity is what defines, unites us.
Diversity is also what makes us love the Fediverse.

As we mark two years on Mastodon, thank you for enlivening the conversation with insightful comments and content.

Love does not increase after the first day, but it deepens.

Let's make this journey even more engaging!

What topics did you like the most and would like to see more often 👇

Nickname,
@Nickname@mastodon.bayern avatar

@mihira @EU_Commission Yeah, it's currently really hidden, you have to click on "More share options".
At least all Social Media account that are selfhosted(by the ) or/and compliant should always be visible if any social media button is displayed at all.
Only afterwards show biggest or "More share options" button IMHO.

"More share options" Button at the bottom of EU websites.

clarinette, to Bulgaria
@clarinette@mastodon.online avatar

USING AWS, regardless of the localisation of the servers = data transfers to the U.S. https://www.privacycompany.eu/blog/update-dpia-for-surf-on-zoom-all-known-risks-solved

Jeremiah, to privacy
@Jeremiah@alpaca.gold avatar

My quick lunch read of this is that EDPB just ruled Meta’s forced consent (“pay or ok”) is a valid tactic (page 20). Prepare to pay for your right to click “deny all”. What a gross undermining of GDPR’s intent…

https://www.edpb.europa.eu/system/files/2024-04/edpb_opinion_202408_consentorpay_en.pdf

remixtures, to internet Portuguese
@remixtures@tldr.nettime.org avatar

: "Today, the EDPB has issued its first decision on "Pay or Okay" in relation to large online platforms such as Instagram and Facebook, as first reported by Politico. This decision prohibits Meta from using an unlawful consent request processing personal data. It seems that by now, Meta has run out of options to continue using people's data for advertising in the EU without a consent mechanism that actually complies with the law."
https://noyb.eu/en/statement-edpb-pay-or-okay-opinion

edri, to random
@edri@eupolicy.social avatar

In the latest , we draw your attention to:

🇬🇷 Record-high fine for Greece's Migration Ministry
🇪🇺 @europarl_en vote in favour of discriminatory
💰Meta's harmful push to charge for privacy
& more!

Read up & share: https://edri.org/our-work/edri-gram-17-april-2024/

chuso, to TierraSapiens Spanish
@chuso@mastodon.social avatar

El Comité Europeo de Protección de Datos dice que pedir una suscripción de pago para no ser rastreado como hace Meta para Facebook e Instagram no cumple la GDPR: https://www.edpb.europa.eu/news/news/2024/edpb-consent-or-pay-models-should-offer-real-choice_en

Frederik_Borgesius, to privacy
@Frederik_Borgesius@akademienl.social avatar

Dutch public broadcaster website on the 'pay or consent' guidance by the European Data Protection Board (EDPB).

https://nos.nl/artikel/2517179-privacywaakhonden-meta-mag-gebruikers-niet-dwingen-zich-te-laten-volgen

glynmoody, to meta
@glynmoody@mastodon.social avatar

Opinion: cannot rely on "Pay or Okay" - https://noyb.eu/en/statement-edpb-pay-or-okay-opinion "This decision prohibits Meta from using an unlawful consent request processing personal data."

noybeu, to random
@noybeu@mastodon.social avatar

🚨 Breaking via Politico: :

The EDPB takes the view that "large online platforms" like Meta cannot rely on a "pay or okay" system to get "freely given" consent. [Details to follow]

First noyb statement:

https://noyb.eu/en/statement-edpb-pay-or-okay-opinion

nf3xn, (edited ) to OpenAI
@nf3xn@mastodon.social avatar

OMFG is now mixing up details across different threads, causing confusing responses. This is bad within your current thread. Worse across all your threads. BUT REALLY BAD WHEN YOU DELETE ALL YOUR THREADS AND IT STILL REFERENCES THE DELETED DATA

remixtures, to Bulgaria Portuguese
@remixtures@tldr.nettime.org avatar

: "As well as the Belgian Data Protection Authority decision I criticised earlier this week, it appears the French DPA has issued similar guidance on the use of personal data to train AI models. My detailed analysis below shows that, in relation to purpose-specific AI systems, it makes no sense: the training of the system cannot be separated from the ultimate purpose of the system. This has a major bearing on the issue of compatibility.

As a matter of principle and law, the creation and training of AI models/profiles for a specific purpose (be that direct marketing or health care) must be based on the legal basis relied on for that ultimate purpose.

The fact that the creation and training of the models/profiles is a “first phase” in a two-phase process (with the deployment of the models/profiles forming the “second phase”) does not alter that.

However, as an exception to this, under the GDPR, the processing can also be authorised by law or by means of an authorisation issued by a DPA under the relevant law (as in France), provided the law or DPA authorisation lays down appropriate safeguards. That is the only qualification I accept to the above principle." https://www.ianbrown.tech/2024/04/16/more-on-french-and-belgian-gdpr-guidance-on-ai-training/

Frederik_Borgesius, to Law
@Frederik_Borgesius@akademienl.social avatar

Sascha van Schendel - Regulating risk profiling by law enforcement. a task for data protection law, non-discrimination law and criminal procedural law - 2024 PhD

https://pure.uvt.nl/ws/portalfiles/portal/89561573/van_Schendel_Regulating_15-03-2024.pdf

openrightsgroup, to privacy
@openrightsgroup@social.openrightsgroup.org avatar

The battle to protect our data rights continues as the returns to the UK House of Lords today.

Our amendments to strengthen the Information Commissioner's Office are on the table. We need a strong, independent and effective data regulator to ensure our rights are enforced.

Here's why ⬇️

https://www.openrightsgroup.org/blog/how-a-weaker-data-watchdog-impacts-you/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Cyberattack on Dutch chipmaker Nexperia. Data theft. Unclear if just about personal data breach. https://www.nexperia.com/about/news-events/press-releases/Press-statement--Nexperia-IT-Breach

r_alb, to privacy
@r_alb@mastodon.social avatar

(1/2) If companies tell you that their processing of your data is legitimised by the GDPR‘s Recital 47, don‘t buy it! They usually refer to the Recital‘s last sentence, which states that direct marketing «may be regarded as carried out for a legitimate interest».
Instead, tell them to read the whole Recital. It mandates for a «careful assessment» of the interests involved, taking into account factors such as (the lack of) a relationship to a company.

clarinette, to uk
@clarinette@mastodon.online avatar

harm : the number of data subjects affected by central government personal data breaches has increased by 8000% since 2019, according to official statistics disclosed by the Information Commissioner's Office, in response to an FOI request. https://www.mishcon.com/news/data-breach-crisis-in-central-government-time-for-ico-to-act

r_alb, to privacy
@r_alb@mastodon.social avatar

Some of the issues us privacy people complain about may appear rather insignificant to you. I get that.
But please let me invite you to a different perspective: As we are currently setting a lot of precedents regarding data privacy rights, how we are handling the small issues today will have an effect on how we will deal with big problems tomorrow. That is why you should care about violations of your privacy, even if they don‘t seem like much today. Because tomorrow, they might.

bendrath, to random German
@bendrath@eupolicy.social avatar

The European Parliament adopted the report by @SLagodinsky on the procedures Regulation. Clear mandate to negotiate once Council gets its act together. Text here: https://www.europarl.europa.eu/doceo/document/TA-9-2024-0187_EN.html

jeridansky, to privacy
@jeridansky@sfba.social avatar

You know those cookie-related pop-ups you see on so many websites? I always click on "deny all" or the equivalent. But apparently, on many sites, the cookies will get used anyway.

https://www.malwarebytes.com/blog/news/2024/04/despite-eu-regulations-websites-still-have-their-hand-in-the-cookie-jar

h/t @mattotcha

rysiek, (edited ) to random
@rysiek@mstdn.social avatar

Here's a half-formed thought I need to mull a bit on:

Somehow, algorithmic (and especially "AI-driven") decision making tends to only be proposed in contexts where it can only — or mostly — affect those with the least power in the system.

Migrants and asylum seekers.
Prisoners.
Families using any form of state support (child benefits, foodstamps, etc).
Palestinians in Gaza.

It somehow never gets proposed for use-cases where it might affect the wealthy and powerful.

One wonders why. 🤔

🧵/1

CubeThoughts,
@CubeThoughts@mastodon.social avatar

@rysiek Article 22 of the EU gives people the right to not be subjected to "decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

Quite perceptive that they identified these risks in 2016. Of course, it's allowed if authorized by law (with appropriate safeguards).

https://gdpr-info.eu/art-22-gdpr/

HonkHase, to random German
@HonkHase@chaos.social avatar
LukaszOlejnik, to privacy
@LukaszOlejnik@mastodon.social avatar

Proposal of U.S. Federal data protection regulation. American Privacy Rights" It would be different to GDPR but cover more specific things like data brokers or targeted advertising. Allows schemes like 'See Ads or Pay Fee' (like Meta introduced). Introduces Privacy Impact Assessment, and Algorithmic Impact Assessment. It's also a cybersecurity regulation: "... establish, implement, and maintain reasonable data security ..." https://d1dth6e84htgma.cloudfront.net/American_Privacy_Rights_Act_of_2024_Discussion_Draft_0ec8168a66.pdf

image/png
image/png
image/png

ilumium, to Skydiving
@ilumium@eupolicy.social avatar

Holy shit, I thought I knew how evil the industry was but here we are:

Two-thirds of European websites just ignore your choice and track you anyways, researchers from found. 🤯

https://www.usenix.org/system/files/sec23winter-prepub-107-bouhoula.pdf

Jeremiah, to random
@Jeremiah@alpaca.gold avatar

Meta is back to pushing its coerced "consent" tactic on Instagram users in the EU: pay or agree to give us all your data.

Do NOT give consent. Force quit Instagram and relaunch to get around the block.

This screen went away for a few months, but is back as a ruling from the European Data Protection Board (EDPB) is expected soon.

@noybeu is fighting this fight for us. Read more: https://noyb.eu/en/pay-or-okay-1500-eu-year-your-online-privacy

Jeremiah,
@Jeremiah@alpaca.gold avatar

Instagram is now blocking web access to force consent as well. Here is how to get around giving consent:

Instagram redirects to a URL like this:
[https://www.instagram.com/consent/?flow=ad_free_subscription&params_json=](https://www.instagram.com/consent/?flow=ad_free_subscription&params_json=)...

Change ad_free_subscription to anything, like ad_free_subscription1, hit enter.

Instagram then will show an error, but you can then navigate anywhere from there.

MartinTilo, to Finance
@MartinTilo@mastodon.gamedev.place avatar

🤔 I'm pondering to sue my Bank.

IANAL but as I understand Art. 20, they kinda have to offer me API access to my Bank statements?

I'm just getting really tired of their 5 Step CSV export that results in a broken CSV format that they don't accept as being a bug because Excel just ignores null chars while my current CSV-to-QFX solution doesn't. I hacked a fix but that adds a step.

Plus they upped our non-profit sports club's account fees from 100 DKK p.a. to 1200 p.a. 😡

MartinTilo,
@MartinTilo@mastodon.gamedev.place avatar

Well, they've been completely non helpful and kept misrepresenting the law in their favor, willfully leaving out entire sentences that were inconvenient to them. Particularly Art. 20 1. (b):

"the processing is carried out by automated means."

And 2.:
"the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible."

And they have a solution for their business customer so they've already proven it's feasible.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • rosin
  • Youngstown
  • ngwrru68w68
  • khanakhh
  • slotface
  • InstantRegret
  • mdbf
  • osvaldo12
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • ethstaker
  • Leos
  • magazineikmin
  • thenastyranch
  • modclub
  • GTA5RPClips
  • tacticalgear
  • provamag3
  • normalnudes
  • cubers
  • Durango
  • tester
  • megavids
  • anitta
  • lostlight
  • All magazines