@Gargron The real question is whether Meta’s circumvention of Android’s safeguards for the advertising ID — and their ability to unmask real user identities — qualifies as a criminal offense under Germany’s anti-hacking law (§202a StGB) or similar international laws governing cyberattacks.
What Meta did wasn’t just a violation of GDPR. It involved bypassing built-in technical protections with the intent to extract and link data — potentially personally identifiable information (PII) — to users without their knowledge or consent.
That is the textbook definition of unauthorized access and data exfiltration.
We need to stop framing this as a regulatory issue or a privacy mishap. This was a malicious cyber intrusion, done knowingly and at scale, by a corporation with full awareness of the legal and technical boundaries it was crossing.
It’s time we start treating it as such.