Live data from Hacker News

EU data protection law after the Safe Harbour judgment

eulawanalysis.blogspot.com

71–80 of 80 posts

Re: EU data protection law after the Safe Harbour judgment

#71
post #59
post #52

Earlier quoted context omitted.

In general one is allowed to store data for a limited time for specific purposes. A delivery address, for instance, is vital to deliver a package to. You could probably even keep a names and addresses database so long as it was something you needed to keep in order to conduct business with the customer. Routine data mining, asking for irrelevant info, selling it on to third parties, not so much.

Maybe it's just me, but these rules are contradictory. The sentences seem explicitly designed to make that so. For instance, your email address and birthday, for, say, amazon.com, could easily be argued to "need to be kept in order to conduct business". After all, your email ... amazon spams it ... that's certainly part of the business they conduct (and frankly, they'd be more expensive if they didn't do that, so the…

Just because you are anti-privacy and anti people's rights it doesn't mean that my countries laws should support you.

Re: EU data protection law after the Safe Harbour judgment

#72
post #59
post #52

Earlier quoted context omitted.

In general one is allowed to store data for a limited time for specific purposes. A delivery address, for instance, is vital to deliver a package to. You could probably even keep a names and addresses database so long as it was something you needed to keep in order to conduct business with the customer. Routine data mining, asking for irrelevant info, selling it on to third parties, not so much.

Maybe it's just me, but these rules are contradictory. The sentences seem explicitly designed to make that so. For instance, your email address and birthday, for, say, amazon.com, could easily be argued to "need to be kept in order to conduct business". After all, your email ... amazon spams it ... that's certainly part of the business they conduct (and frankly, they'd be more expensive if they didn't do that, so the…

Except that the law doesn't say "Whatever the company claims is needed for their business". There are courts and judges who decide if a particular bit of information is actually necessary.

Re: EU data protection law after the Safe Harbour judgment

#73
post #51

Earlier quoted context omitted.

This was a mistake due to this specific blog post sharing some design elements as some spammy blogspot posts and it was fixed. If we really wanted to censor this story wouldn't we block all criticism of Facebook and not a pretty straightforward and well-reasoned analysis of Safe Harbor? Wouldn't we block the "I declare that I am a wizard and Facebook can't use my content blah blah" memes?

Thanks for fixing this. I personally did not assume this was necessarily censorship, but don't be surprised by the reaction of users though, I think you'll see more of these reactions for a while, after the Safe Harbor ruling.

True. I doubt facebook will do anything that prevents a healthy discussion (unless its unlawful) for its USP is users.

Re: EU data protection law after the Safe Harbour judgment

#74
post #31

Earlier quoted context omitted.

It'll do wonders for EU start ups using EU infastructure.

using EU infastructure ...which in many cases doesn't exist yet. In particular, Europe lags significantly in "on-line" services. Obviously it would solve some problems if this were not the case. However, given that for now it is the case, the price of enforcing a total ban on exporting personal data outside Europe would be closing down vast numbers of on-line European small businesses that aren't intentionally doing…

> ...which in many cases doesn't exist yet.

There is suddenly a good business case for them to exist, and hence probably more funding available now

> it will be addressed by adjusting the relevant European-level legislation

The judgment was based on the Charter of Fundamental Rights of the European Union, and is basically the EU's Bill of Rights. Legislation isn't so flexible here.

> that disclosure to allied governments

Is the USA allied to many EU governments or the EU? It has tapped the phones right at the top of the German government.

Re: EU data protection law after the Safe Harbour judgment

#75
post #66
post #30

Earlier quoted context omitted.

> We may even end up with a special Snowden version of the cookie warning Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent. Update : Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128

It looks like the DPC of Ireland has been "considering" this question since 2011, and still not got anywhere: http://europe-v-facebook.org/EN/Complaints/complaints.html

Low tax rate and compliant DPC. That's Irish pitch to foreign companies.

Re: EU data protection law after the Safe Harbour judgment

#76
post #30

Earlier quoted context omitted.

> We may even end up with a special Snowden version of the cookie warning Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent. Update : Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128

I don't believe such a ruling will be allowed to stand for long, if it really is effectively a blanket ban that can't be overridden by reasonable consent. Enforcing something like that really would have the potential to block international trade on an economy-damaging scale.

The party who broke the deal was the USA, with it's unrelentent mass spying of as many people as possible. If you want change, start there.

Re: EU data protection law after the Safe Harbour judgment

#77
post #37

Earlier quoted context omitted.

Then treat personal data as radioactive. Don't store it. Don't collect it if you don't need it. If you have it, try to get rid of it, and delete it ASAP.

That's not practical. "I haven't received my package!" "Well, we sent it 2 weeks ago" "What address did you send it to?" "Don't know" EDIT: Also, "Why does this shopping website require me to re-input the shipping address every time I want to buy something? Why can't it remember it like every website used to?"

> EDIT: Also, "Why does this shopping website require me to re-input the shipping address every time I want to buy something? Why can't it remember it like every website used to?"

The option to not have my mailing address stored is a feature not a bug to me (and I guess other people that move regularly).

EDIT indeed many smaller shopping websites in the UK don't even attempt to store this sort of data -- presumably because they don't think that they can definitely comply with data protection laws.

Re: EU data protection law after the Safe Harbour judgment

#78
post #51

Earlier quoted context omitted.

I also cannot share this on FB. Amazing. The fact that FB is censoring this content deserves its own HN exposure. It is an article about international law with nothing offensive, but FB blocks it.... this is going further than I'd have thought FB would ever do. The future doesn't look so bright for social media.

This was a mistake due to this specific blog post sharing some design elements as some spammy blogspot posts and it was fixed. If we really wanted to censor this story wouldn't we block all criticism of Facebook and not a pretty straightforward and well-reasoned analysis of Safe Harbor? Wouldn't we block the "I declare that I am a wizard and Facebook can't use my content blah blah" memes?

If people can't tell the difference between your spam filter and a censor, at least you've passed the Turing test.

Re: EU data protection law after the Safe Harbour judgment

#79
post #30

Earlier quoted context omitted.

> We may even end up with a special Snowden version of the cookie warning Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent. Update : Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128

I don't believe such a ruling will be allowed to stand for long, if it really is effectively a blanket ban that can't be overridden by reasonable consent. Enforcing something like that really would have the potential to block international trade on an economy-damaging scale.

Then the US needs to stand up and write some laws that respect human rights.

Re: EU data protection law after the Safe Harbour judgment

#80
post #76

Earlier quoted context omitted.

I don't believe such a ruling will be allowed to stand for long, if it really is effectively a blanket ban that can't be overridden by reasonable consent. Enforcing something like that really would have the potential to block international trade on an economy-damaging scale.

The party who broke the deal was the USA, with it's unrelentent mass spying of as many people as possible. If you want change, start there.

That doesn't change the issue of data transfers to third countries that are not approved though.
Post reply on HN