Live data from Hacker News

Google’s GDPR Workaround

brave.com

41–50 of 629 posts

Re: Google’s GDPR Workaround

#41
post #21
post #7

Earlier quoted context omitted.

It is very not legal, but I think the parent was saying these regulations are more onerous to small dev shops rather than Google and the fine for this will be minuscule. Hopefully companies will find paths to revenue that do not require selling out there users to this level, maybe by just having ad auctions without any identifying information at all.

The first GDPR fines handed down by the ICO have been hundreds of millions of pounds for negligent breaches - I don't think it would be out of the realm of possibility for breaches by _design_ to result in multi-billion pound fines.

Several billion pounds is still not much! They already broke GDPR once (or twice I think?) And received a 57MM$ fine.

57MM$ is nothing to Google. They've escaped even antitrust cases with minimal injury, it would be a truly shocking event if the EU actually managed to touch them.

Re: Google’s GDPR Workaround

#42
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

I believe the $5 billion was an antitrust violation, not related to GDPR. I could be wrong.

Re: Google’s GDPR Workaround

#43
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

> "control" over the data after broadcast, albeit legal control via contracts with advertisers

Now there's a claim only a court would buy!

A court probably would buy it, though.

Sigh.

Re: Google’s GDPR Workaround

#44
post #13

What is sad is that the EU commission doesn't take real action against Google. At best we are to expect a slap in the hand, at worst, the investigations will drag on and nothing will happen.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

The executives should face jail time. That would certainly light a fire under Google's ass to finally "do no evil".

Re: Google’s GDPR Workaround

#45
post #16
post #10

Earlier quoted context omitted.

It's not legal but there isn't much the EU can really do. It would be shocking if they actually managed to prosecute Google which has so far avoided much hassle in antitrust and the like, taking I think a billion dollar fine which sounds like a lot but is basically a slap on the wrist. That's why, IMO, GDPR sucks for small businesses that can be outed to the ICO for a minor oversight and not so much for big data abus…

That sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR? A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/

EU have shown that it's willing to scale up the fines all the way if the company in question keep on violating the law. Alphabet global revenue 2018 was $136.8 billion, so the maximum fine is $5.5 billion which is in the vicinity of fines they've already received. It's a separate post in their yearly financial report. The gain must be significant if they continually keep violating the laws.

Re: Google’s GDPR Workaround

#46
post #33

Earlier quoted context omitted.

Google has been fined a 5 billion dollar fine already last year, that claim simply isn't true. But I agree with the implicit demand, they clearly haven't gotten the message. The EU should slap them with billion dollar fines again until they learn their lesson.

That fine qualifies as a "slap in the hand" for Google if it happens infrequently enough (which is the case).

It's not that infrequent; they got another $1.7B fine this year. Remember that these processes take a long time, but they are running in parallel.

Re: Google’s GDPR Workaround

#47
post #16
post #10

Earlier quoted context omitted.

It's not legal but there isn't much the EU can really do. It would be shocking if they actually managed to prosecute Google which has so far avoided much hassle in antitrust and the like, taking I think a billion dollar fine which sounds like a lot but is basically a slap on the wrist. That's why, IMO, GDPR sucks for small businesses that can be outed to the ICO for a minor oversight and not so much for big data abus…

That sounds like something fairly trivially avoided by having the punishment be proportional to revenue. And I believe this is already the case for GDPR? A quick search indicates "Up to €20 million, or 4% of the worldwide annual revenue of the prior financial year, whichever is higher" https://www.gdpreu.org/compliance/fines-and-penalties/

This is being quoted in every comment but if you have enough lawyers anything is possible.

Google has come out of antitrust cases relatively unscathed. They've even violated GDPR itself once before explicitly, and got out with a 57MM$ fine. This case won't be any different than all the other times that Google has blatantly violated laws and walked away with a slap on the wrist.

I would be very very very shocked if the EU actually managed to touch Google. I welcome and hope to be proved wrong.

Re: Google’s GDPR Workaround

#48
post #11

Snippets from the article: > The evidence further reveals that Google allowed [...] > Google has no control over what happens to these data once broadcast [...] Is it possible that Google does have "control" over the data after broadcast, albeit legal control via contracts with advertisers (as opposed to technical control)? Perhaps Google's GDPR compliance strategy relies on the participating advertisers to comply wi…

The article doesn’t appear to claim that the author has been tracked in violation of the GDPR, only that the described mechanism makes it technologically feasible to do so.

Re: Google’s GDPR Workaround

#50
post #9

Earlier quoted context omitted.

The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…

Unless I'm misunderstanding what you mean by absolute and relative, I think the law is already relative: > The maximum fine under the GDPR is up to 4% of annual global turnover or €20 million – whichever is greater – for organisations that infringe its requirements. From here: https://www.itgovernance.co.uk/dpa-and-gdpr-penalties

[deleted]
Post reply on HN