Live data from Hacker News

€1.2B GDPR fine for Meta

noyb.eu

1–10 of 68 posts

Re: €1.2B GDPR fine for Meta

#2
It is also a big blow to the DPC. There are also many other other questionable DPAs and national legislators, some of which are already under infringement proceedings.

This is big news:

"Furthermore, the EU's Collective Redress Directive must also be implemented this summer, which will for the first time allow collective actions by European user for GDPR violations."

Re: €1.2B GDPR fine for Meta

#3
> These hopes may however be shattered soon. It is not unlikely that the new deal will be invalidated by the CJEU - just like the two previous EU-US data deals (“Privacy Shield” and “Safe Harbor”). Such invalidations have retroactive effect.

If I understood correctly, if they keep transferring data to the US before CJEU considers that the nee deal does satisfy regulations, they may just be setting themselves up to another record fine.

I'm fine with this.

Re: €1.2B GDPR fine for Meta

#4
"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon"

Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot withdraw from the market, furthering the fragmentation of the global internet. May not be a bad thing overall, especially for local players and for national sovereignty evangelists

Re: €1.2B GDPR fine for Meta

#5
post #4

"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot wi…

> May not be a bad thing overall, especially for local players and for national sovereignty evangelists

Yep, especially if they have to play by different rules and have different values then the companies they try to compete against.

Re: €1.2B GDPR fine for Meta

#8
post #4

"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot wi…

I don't see how they can continue the service, even with huge localisation effort. The capital sin is to be a US company. That subjects them to US law, including CLOUD act, which the UE considers to be incompatible with privacy guarantees.

Even if cloud providers use local datacenters they are still in "violation". If the US makes a data request using CLOUD act, they will have to comply, no matter where these servers are sitting.

Ironically, the UE intelligence services are happy to take the anti-terrorist information that the US is extracting with the CLOUD act and sharing with them.

Re: €1.2B GDPR fine for Meta

#9
post #8
post #4

"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot wi…

I don't see how they can continue the service, even with huge localisation effort. The capital sin is to be a US company. That subjects them to US law, including CLOUD act, which the UE considers to be incompatible with privacy guarantees. Even if cloud providers use local datacenters they are still in "violation". If the US makes a data request using CLOUD act, they will have to comply, no matter where these servers…

The intelligence services are not advocates for privacy laws.

Re: €1.2B GDPR fine for Meta

#10
The decision PDF is lengthy but boils down to the following two instructions on page 73:

> 273. In light of the above, the EDPB instructs the IE SA to impose an administrative fine on Meta IE for the infringement of Article 46(1) GDPR that is in line with the principles of effectiveness, proportionality and dissuasiveness under Article 83(1).

> 279. In light of the above, the EDPB instructs the IE SA to include in its final decision an order for Meta IE to bring processing operations into compliance with Chapter V GDPR, by ceasing the unlawful processing, including storage, in the US of personal data of EEA users transferred in violation of the GDPR, within 6 months following the date of notification of the IE SA’s final decision to Meta IE.

I understand the financial incentive for Ireland to be an attractive host country for tech companies, but as the article points out, this took on truly ridiculous dimensions. Even more so after May 2018, when the GDPR was published, which -- by recognizing the protection of PII as a fundamental right -- dealt a massive blow to the "productize your customer" business model.

> Ten years, three court proceedings and millions in legal costs. The Irish DPC’s role in this procedure is exceptional, as it has consistently tried to block the case from going ahead, in 2013 it rejected the original complaint as “frivolous” – requiring Mr Schrems to go all the way to the CJEU. The DPC then took the view that it cannot take action, given that Meta made use of so-called “Standard Contractual Clauses”, which was again rejected by the CJEU, who told the DPC that it must take action. Finally, the DPC tried to shield Meta from a fine and the deletion of data that is already transferred, just to be overturned by the EDPB. Overall these procedures lead to costs of more than 10 million Euro - the fine, however, will go the Irish state.

Post reply on HN