Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> if you want better protection for your data than the US provides: do not send your data to the US.

You don't have a choice. A citizen of Brussels who doesn't have a Facebook account could be surfing a website that Facebook doesn't own and Facebook will still be tracking and recording that person's activity without consent.

So the situation essentially becomes similar to a phishing scammer in India making fraudulant phone calls to U.S. Citizens pretending to be the IRS. Did that person break U.S. law? They sure did. Did they break Indian law? Maybe not. Should they be extradited to the U.S. to face our jurisdiction? Of course, because they were taking advantage of their geographic location to undermine our jurisdiction.

It wouldn't be that hard for a global company worth hundreds of billions of dollars to implement some sort of geo-fence that properly identifies EU citizens and complies with local laws on a local level. Facebook wrote their own hard drive firmware for their data centers. Why do we care about the feasibility or financial repercussions of asking Facebook to comply with laws to protect actual people?



Should they be extradited to the U.S. to face our jurisdiction?

I don’t think so. I don’t want India to have the power to extradite me if I send an email to a someone in India that they deem blasphemy or destabilizing or whatever. You’re talking about clearcut fraud, which is more sympathetic but the underlying legal precedent is what terrifies me.

It is a violation of human rights to subject people to laws that they have no democratic say in.

Also, in your example about Facebook, you do have a choice. Leaving aside that they’re global and have an EU presence and should thus be complying, if Facebook was US-based only, you are sending a request to their servers. You’re responsible.

Now, maybe the site in question also bears some culpability for what their partners do with their customers’ data, but I don’t see how Facebook is responsible for every law and jurisdiction for where those requests originate. If you don’t want Facebook to have your data, don’t send it to them! Blocking those requests is incredibly trivial, and the onus should be on you the sender, not the receiver.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: