I mean an Iranian company using American products and expecting EU protection?! None of it makes any sense.
Slack just wiped out our data overnight
11–20 of 35 posts
Re: Slack just wiped out our data overnight
#12> If Slack has to comply with the export control law, they also need to comply with GDPR. Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so th…
Slightly unrelated but note that many "American companies" are explicitly headquartered in the EU for tax reasons, and by structuring themselves in this way they are explicitly putting themselves under EU jurisdiction. Examples include Apple and Google (headquartered in Ireland) and Amazon (headquartered in Luxembourg).
A quick search found that Slack is actually headquartered in America. But if they are dealing with the EU market then they very likely need to have an EU subsidiary (and looking again they have a Dublin office and so are likely incorporated in Ireland). However, GDPR only applies to EU/EEA residents -- so you can't just send a GDPR request if you are not resident within EU/EEA.
Re: Slack just wiped out our data overnight
#13Want to maintain professionalism and integrity? Due process is important. You can't just slam the door closed in peoples' faces arbitrarily and go radio silent or word's going to get out that you're untrustworthy. Do right by people; don't be a dick. Otherwise: problems.
Re: Slack just wiped out our data overnight
#14Lots of people shaming companies this week, but all of them including this one just don't sound justified at all. I mean an Iranian company using American products and expecting EU protection?! None of it makes any sense.
It should be noted that Slack has an office in Dublin so it very likely has an Irish subsidiary (just like Apple, Google, and half of the tech industry so they can avoid taxes) and thus is subject to EU requirements. The GDPR applies to them, and since they have an EU company they (I believe) need to obey GDPR requests from any source. [EDIT: This is incorrect.]
But I can understand why Slack would cancel their account, since violating export sanctions is a really easy way to end up in gaol.
Re: Slack just wiped out our data overnight
#15Lots of people shaming companies this week, but all of them including this one just don't sound justified at all. I mean an Iranian company using American products and expecting EU protection?! None of it makes any sense.
> I mean an Iranian company using American products and expecting EU protection?! None of it makes any sense. It should be noted that Slack has an office in Dublin so it very likely has an Irish subsidiary (just like Apple, Google, and half of the tech industry so they can avoid taxes) and thus is subject to EU requirements. The GDPR applies to them, and since they have an EU company they (I believe) need to obey GDP…
It covers data for EU/EEA citizens and residents data held by companies “doing business” with people in such areas. An off the top of my head example. An Australian citizen who has never been to the EU can not use the GRPR against Microsoft just because MS have a office in the EU.
Edit: My bad, I think the Australian would be under the Dublin office in the slack case. But the GDPR rules are focused on data of EEA/EU residents/citizens and not (always) data of people outside of the EEA/EU collected by companies within the EEA/EU.
Re: Slack just wiped out our data overnight
#16Earlier quoted context omitted.
> I mean an Iranian company using American products and expecting EU protection?! None of it makes any sense. It should be noted that Slack has an office in Dublin so it very likely has an Irish subsidiary (just like Apple, Google, and half of the tech industry so they can avoid taxes) and thus is subject to EU requirements. The GDPR applies to them, and since they have an EU company they (I believe) need to obey GDP…
Nope. It covers data for EU/EEA citizens and residents data held by companies “doing business” with people in such areas. An off the top of my head example. An Australian citizen who has never been to the EU can not use the GRPR against Microsoft just because MS have a office in the EU. Edit: My bad, I think the Australian would be under the Dublin office in the slack case. But the GDPR rules are focused on data of E…
Re: Slack just wiped out our data overnight
#17> If Slack has to comply with the export control law, they also need to comply with GDPR. Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so th…
> Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so they opened those tools up to everyone not just those within the EU. But that doesn’t mean…
None of this matters to the GDPR. The GDPR targets companies “doing business” with EEA/EU residents no matter where the company is actually located. Even if you are a solely US company, if you are accepting orders from EU/EEA residents you have to be able to process GRPR requests. Think of it as a cost of doing business in that area. If you don’t want to do that, the. You are free to no longer process any EU/EEA residents data (some websites, the LA Times is one example iirc just completely lock EU IP’s because of this).
When it gets “merky” is defining that “doing business”.
Sure accepting payments and offering a service is clearly covered. But what if you ad supported. Are you doing business because you are exchanging access to your site for ad impressions which you get paid for? Who is processing that data? You or if the ad network one of your business partners who you have offloaded a task too? (Which is why domes of people/companies/ad men were shouting that the end was nigh before it came into force.)
But yeah as I said to you in another comment. Even if they were allowed to do business in Iran, the GDPR wouldn’t come into play here as they are not in the EU.
If they had any team members in the EU, they could try that route.
Re: Slack just wiped out our data overnight
#18> If Slack has to comply with the export control law, they also need to comply with GDPR. Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so th…
> Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so they opened those tools up to everyone not just those within the EU. But that doesn’t mean…
Re: Slack just wiped out our data overnight
#19Earlier quoted context omitted.
> Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so they opened those tools up to everyone not just those within the EU. But that doesn’t mean…
Any EU citizen is protected by GDPR if the company is doing business in EU. Doesn't matter where the HQ is.
One of the biggest things people bring up against the GDPR is "how will the EU punish companies outside of their jurisdiction". The answer is that most "American" companies actually use EU tax breaks and thus can most definitely be punished by the EU.
Also, the user was based in Iran. He doesn't have relevant rights under the GDPR.
Re: Slack just wiped out our data overnight
#20> If Slack has to comply with the export control law, they also need to comply with GDPR. Slack is an American company, GDPR is a EU law and OP is Iranian. That’s not how this works... Sure companies that operate within the EU have created tools to export your data automatically (they still have contact points to request the same data if you don’t have an account or were banned so can’t use the automated tools) so th…