Live data from Hacker News

India bans MasterCard from adding new customers

techcrunch.com

151–160 of 180 posts

Re: India bans MasterCard from adding new customers

#152
post #105
post #82

Earlier quoted context omitted.

It's a billion person country. It might not make sense for every country to demand things like this, but that doesn't mean it doesn't make sense for giant countries too, and it doesn't make it inefficient. At India's scale costs are already amortized anyways, but worse, consider India's physical location. It's surrounded by hostile nations (Myanmar, China, Pakistan, make a wall around it). To get data out of the coun…

Data can also move by satellite.

Nowhere near enough.

Re: India bans MasterCard from adding new customers

#153
post #2

FYI, American Express and Diners Club have already been banned from adding new customers in India due to the same thing. https://www.reuters.com/article/india-banking-american-expre...

Third paragraph from the bottom in the post you're literally commenting on :)

Re: India bans MasterCard from adding new customers

#155

Earlier quoted context omitted.

From my understanding (I could be wrong) and why I have to follow all these rules here in Canada, is the USA made a homeland security law in like 2007 that said law enforcement can have access to any foreign individuals data without a warrant/good reason. So now when picking services I am not allowed to host on any non Canadian servers if we are hosting personal information about staff/users etc. It can be a simple e…

Ultimately, isn't it the owner of the server who's targeted by the laws? Where the server is really doesn't matter that much.

One thing is that usually the local server would be owned and managed by a local subsidiary of that foreign company - it may even be a requirement, to have them be run by a local company (even if fully owned by a foreign entity) with local responsible officers.

Another issue is establishing jurisdiction; if the server is held locally, then it's clear that local laws apply to things done on that server - the owner of the server can't claim that they e.g. got a US subpoena and did some stuff in USA that fulfills all the USA legal requirements and everything that's it; if the server was physically located in e.g. Canadian soil, then it means that the violation (if any) happened "in Canada" even if it was done by USA-located USA citizens of USA company.

Re: India bans MasterCard from adding new customers

#156

Earlier quoted context omitted.

> I'd much rather store properly encrypted personal information or financial data in North Korea than storing it unencrypted in my home country. What do you mean by "properly encrypted"? MasterCard is not going to let you be the sole holder of your encryption keys. And if you aren't holding them, then they they hold it, and then they must be holding in at least one given country. And that country has the power to for…

That country already has the power to force them to turn these keys over (or use the keys to decrypt data of interest). Every non-tax-haven country which regulates its financial sector does (so, every country). It's unclear what is added by forcing them to store data locally.

In most cases you can't easily tell that company to hand over data that is held in another country though.

Re: India bans MasterCard from adding new customers

#157

Earlier quoted context omitted.

I agree that will have a bigger effect, and boo Brexit. But it's actually only transactions on EU shops by UK cards that face higher fees, which is a really small percentage of purchases. Definitely not every transaction. I'm sure they'll raise the other fees later though. Probably just dipping their toes.

Even more reason to accelerate instant payment system rollouts to avoid private payment systems that charge interchange fees.

What instant payment systems? Are there actually viable competitors to Visa/MasterCard?

Re: India bans MasterCard from adding new customers

#158
post #66

Earlier quoted context omitted.

To expand on this a bit, if you want leverage over companies like MasterCard, Visa, and American Express, it definitely helps to have the data in your jurisdiction. As you noted, they will shut off mobile internet to support the state. If Visa decides that it doesn't want to give the government data on someone's transactions, it helps to have that data in the country. "Oh, but the data is encrypted." Sure, but the co…

Still not really buying the physical control of data argument. If you need to force a company like MC to comply, you can always solve that problem at the point of sale, or (like they're doing right now) stop banks, which are firmly under your jurisdiction, from issuing cards. A company will hand over data rather than be banned from operating in the country, just the same. The amount of leverage you have with data bei…

As far as I can tell, there's a fair bit of difference between "decreed a crime" and "we've backed up a truck to the DC, and physically seized your data, do as we say if want it back"

Re: India bans MasterCard from adding new customers

#159
post #130

Let us imagine a scenario where Mastercard holds EU or US citizens data in China or Russia and refuses to move it to EU/US. If it is a bit hard to digest, perhaps one needs to extend the same respect to India's sovereignty.

Generally HN thinks highly of that, and will never visit the EU so they don't have to face punishments for GDPR violations

How real are these laws at all, by the way? Is it really a case when one company has to store their data separately and (inaccessible from other places). What do these laws enforce, networking-wise only?
Post reply on HN