Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
The Dutch government is clamping down on the way in which large organisations use its citizen's personal data.
The Dutch Data Protection Authority (DPA) threatened Google with a fine of €15m (£11.9m, $18.7m) on Monday, saying the search giant had breached various provisions of the Dutch data protection act via a privacy policy it introduced in 2012.
The company has been given until the end of February 2015 to change how it handles personal data, especially in regard to the tailoring of adverts based on keyword search queries, video viewing habits, location data and the content of email messages.
Jacob Kohnstamm, chairman of the Dutch DPA, said:
Google catches us in an invisible web of our personal data without telling us and without asking us for our consent. This has been ongoing since 2012 and we hope our patience will no longer be tested.
Kohnstamm explained how, under Dutch law, Google should have informed users that it was gathering data across a number of platforms - such as YouTube and Gmail - and obtained permission before combining or analysing that data.
The regulator has now demanded that Google obtains "unambiguous" consent from users before combining their data, "via a separate consent screen", rather than through its more generalised privacy policy.
It also ordered the company to add clarification to the policy so that users are better informed as to how each of the company's services is using their data.
Furthermore, Google is required to make it clear that YouTube is part of its setup, though the DPA did note that this already appeared to be underway.
Five other regulators - in France, Germany, Italy, Spain and the UK - have recently received a letter from Google detailing how it intends to comply with European privacy laws but the Dutch DPA says it has yet to establish whether the proposals will suffice within its own jurisdiction.
While the DPA's gripe with Google awaits resolution, it has now moved onto fellow data gatherer Facebook.
In another statement (in Dutch - view Google translate version) released on Tuesday it announced it would investigate Facebook's new privacy policy.
The social network announced last month that it intends to make changes to its policy, effective from 1 January 2015.
As Facebook has a physical presence in the Netherlands, the DPA says it is authorised "to act as supervisor", as per a European Court of Justice ruling on Google vs. Spain on 13 May 2014 (the 'right to be forgotten' case).
As such, it has asked Facebook to hold fire on its new privacy policy until it has had the chance to investigate how the changes may impact Dutch users, including how Facebook obtains permission for the use of their personal data.
The latest iteration of the policy states that Facebook can use:
your name, profile picture, content, and information in connection with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us. This means, for example, that you permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you. If you have selected a specific audience for your content or information, we will respect your choice when we use it.
Given how the key points of the policy have not changed since it was last revised in November 2013, it seems unlikely Facebook will comply with the DPA's wishes.
According to The Telegraph, the company responded by highlighting how it is "a company with international headquarters in Dublin", which routinely reviews its policies and procedures with its own regulator, the Irish Data Protection Commissioner.
Facebook said it is confident that its new privacy policy is compliant with all relevant laws.
Follow @Security_FAQs
Follow @NakedSecurity
Image of Dutch citizen courtesy of Shutterstock.
Microsoft would prefer if the US Department of Justice (DOJ) refrained from reaching over the ocean and past international law to ransack its Irish servers.
Why does Jay-Z want to know who we're talking to?
For those Facebook users who are allergic to any notion of privacy whatsoever and would prefer that the entire world be privy to contents of their #dinner or antics of their adorable #children, Wednesday was a high and holy day indeed, for that was the day that Facebook embraced the hashtag. 
Currently, users control the audience for their posts, including those with hashtags.
The US Congress on Thursday sent Google a letter [PDF] listing eight specific privacy areas concerning Glass that legislators would like to know quite a bit more about. 
Is Facebook Home the long rumored Facebook phone? Nope.
What Facebook Home is supposed to do is replace your plain vanilla lockscreen with a continuously-updated feed from your Friends, a feature they call Cover Feed.
The feature people seem to like the best is called Chat Heads.
Europe v. Facebook, an Austrian student organization that keeps tabs on Facebook's privacy transgressions, recently discovered that Facebook's latest timeline redesign allowed friends of friends to see the total number of Events a user has attended, even if that person's privacy settings were set to only allow friends to see such events. 

Those complaints were built on the work of meticulous document requester and researcher Max Schrems, who in 2011 extracted a pile of 1,200 pages that comprised his then-current personal-data Facebook dossier.
Are you suffering from CFF - Chronic Facebook Fatigue? The mental and bodily malaise that comes from constant tweaking of privacy options in the Land of the Face? 


Another negative change is the removal of the ability to hide yourself from people searching for you by name.
Do you have photographs on your smartphone that you don't want others to see? If an app publisher tells you that they will keep your secrets safe would you trust them?






Sooner or later I expect we'll see an app developer being held accountable for leaked secrets. After all, they promised the unsuspecting user that they would protect those secrets.
At any rate, there's still hope for Jennings, he told Ars, given that Broome could still be found liable under the Computer Fraud and Abuse Act.
Not that we should trust the cloud to protect our precious documents, mind you.
After agreeing earlier in the month to cough up a record $22.5 million in a settlement with the Federal Trade Commission for sneaking tracking cookies past Safari browsers' no-tracking controls, Google is creating a privacy "Red Team" to police its products' own privacy bugs and dangers. 
The Quora website launched two years ago, collating questions-and-answers on a variety of topics and receiving favourable write-ups in the media.





