Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

141–150 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#141
post #4

Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.

I think you’re reaching and acting like Americans don't understand the implication, we just don’t consider it something that’s bad. We are allies on a global market and therefore treat you no differently. This is why the US is concerned about data islands with China, but has no problem with European countries and companies with US data.

Clearly the American capitalist strategy is working since all the products you keep regulating are made in the US. I’d welcome Europe to make some alternatives to what the US is providing before you just unilaterally say we’re immoral and wrong, because currently if all the US companies got fed up enough with the regulation and for some reason pulled out of the market it would cripple the digital life you’re used to in Europe.

Revenue has to come from somewhere otherwise a company can’t grow. “Enough revenue to survive” doesn’t incentivize the kind of rapid business development that consistently comes out of the US versus Europe and is just a naive economic worldview. You have to either sell user data, serve ads, or sell the product wholesale or a subscription. Currently the market (including European users) have decided that they’d rather click skip on an ad and have their usage data sold to drive those ads than pay for the product.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#142
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

>We are fortunate to have lived through a brief period where the world was truly a global trade network. A person in England could access the best tea the world had to offer. People could more or less interact freely across borders. >Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the world being a global network is obviously becoming inviable. It was fun while it l…

Point, but IIRC the end of the British Empire was met with a mix of "We didn't want it anyway it was so expensive"* and "We lost an empire but gained a continent".

(The latter followed by lots of pikachu surprise face because they weren't in charge of said continent).

* Not only an Aesop reference, but also an actual claim I've repeatedly encountered

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#143
> Since the end of last year, Uber uses the successor to the Privacy Shield.

Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#144

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

That's a nonsensical load of hyperbole, pardon my French. It's not particularly difficult to be careful with personal data, it's just inconvenient and prevents all kinds of uses that can make you money - which is why US corporations would prefer to not implement it. But if you want to do business in the EU, you need to play by their rules. Simple.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#145
post #132

> The Dutch DPA started the investigation on Uber after more than 170 French drivers complained to the French human rights interest group the Ligue des droits de l’Homme (LDH), which subsequently submitted a complaint to the French DPA. I wonder on what the initial suspicion from the drivers was based.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

> Could be simple negligence on Uber's part.

The didn't slip, fall, and drop some USB flash drives into the hands of a US data processor...

I doubt it is any sort of negligence, but if it is - it's not "simple".

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#146
Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed.

The US definitely needs stronger laws here.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#147

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

Government spying on citizens is one thing. Companies is another. GDPR applies mostly to the latter, and in practice, today, most people in Europe aren't being harmed by their governments spying on them, but they are being harmed by private business abusing personal data.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#148
post #83

Earlier quoted context omitted.

GDPR fines won't ever repair any national budget, you're being cynical. > Domestically these countries have entities collecting personal data in the same evil way as US entities Can you provide sources for this allegation?

In Germany they're Schufa, Rundfunkbeitrag collection service, copyright predators. In Poland I don't even know the names, but if you ever leave your phone number at any doctor, dentist, or blood test lab, starting from next day you'll receive tons of phone calls offering "free products", invitations to "product presentations". Especially if your age is > 50.

If that's really the case I recommend what I've done on the few instances I had my contact details shared between 3rd parties for marketing without my consent here in Sweden, contact them explicitly stating you want them to:

1. provide details about how the data was collected according to GDPR's Article 14 paragraph 1, I also request the information they should provide as delineated by paragraph 2.

2. send you all the data related to your person according to GDPR's Article 15.

3. complete erasure of all personal data they have collected in accordance with GDPR's Article 17.

So far I have not had to contact the Swedish DPA since the few times it happened the companies actually followed my GDPR request.

Edit: and even if you have given consent through some GDPR form you can withdraw it at any time, contacting the company with a GDPR request and explicitly stating you withdraw all consent to their processing of personal data should be enough.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#149
post #127

Does anyone know good best practices and software/DB patterns to model localized GDPR-compliance into global software systems? I know ASP.NET Core comes with some GDPR-related helpers but it's more interesting to know general best practices and patterns not related to a specific framework.

It's pretty much part of your normal data management that you'd be doing anyway, except it now has an additional lifetime (on top of any you might have had).

Since when ingesting the data you knew where it came from and on what timestamp, you also know when to next check for deletion. And since you also know where it came from (the owner), deleting/sending it on request (when applicable - not all data is always required to be deleted) is pretty straightforward. In essence it's like garbage collection for managed languages (like C#) but for your data.

At the end of the day, no matter what you use (existing process, create a new process if you weren't managing your data so far, or use some product), treating data like radio active waste will generally lead to good designs. You only keep what you need for the time that you need it, everything else gets removed.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#150
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

[deleted]
Post reply on HN