Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

11–20 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#11
post #2

"Rocketreach has not met the requirement of the GDPR to name an EU representative (Art27) to account for the processing of European Personal Data. In their answer, the CNPD makes it sound like it is optional, it isn't. Instead of pursuing Rocketreach locally on that basis alone" LOL, yes. I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. Likewise, various EU corporat…

> I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others.

China is the most straightforward example, companies cannot operate unless they basically do it through an - implicitly Chinese state controlled - partner company. China also has a literal Great Firewall monitoring, modifying or stopping all cross-border traffic. So yes, you have to play by their rules if you want access to the market.

US, EU and other western countries also require you to follow their - much more lenient - laws and rules for access to their market, but for now it's rarely enforced through blocking etc. Saudia Arabia, Russia, India, Turkey and other "second world" countries block a lot of services that don't follow their laws or government commands. Same thing: follow da rulez or our market is closed to you.

North Korea has their own exclusive "internet" and blocks all access to the regular internet except for a few highly monitored and controlled locations like universities and government institutes, which are not connected to the NK internet. Not comparable at all.

> Even more interesting, since he expects the US to follow EU law, how does he feel about the EU following US law? The US has that Patriot Act, and lots of EU companies are not compliant.

This is effectively already the case for a large part. All non-china global IaaS companies are US, so everyone has to play by US rules and law. I don't believe for a second that the NSA cannot get the data from the European Google/Amazon/Microsoft data centers.

Re: How to effectively evade the GDPR and the reach of the DPA

#12

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

EU can and should sanction such businesses, individuals behind it and their suppliers. Basically, just do the same as USA does to Nord Stream 2. This will be painful enough.

Re: How to effectively evade the GDPR and the reach of the DPA

#13
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

Can individuals sue and go to court? Or do complaints have to pass through privacy regulators.

I’m curious how a class action hasn’t been formed around Verizon and Oath’s behaviour?

Re: How to effectively evade the GDPR and the reach of the DPA

#14
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

Some pretty big fines have been issued already. See:

https://www.enforcementtracker.com/

Over time I expect them to go up further as companies can no longer claim they did not have enough time or were not aware of the law (that never was a defense anyway but DPAs tend to be lenient. So far).

Since the GDPR has come into effect I see in my practice that companies are a lot more aware of their responsibilities towards their users, have better processes and security in place. Is it perfect? Not by a long shot but the improvement is immense and as time goes by and more companies end up setting an example of how things should be done and those that don't end up getting find I expect this trend to continue.

What I like most about the GDPR is that it steers towards compliance, not towards making life of businesses unnecessary harder.

Contrary to you I think the GDPR is a resounding success, the only thing that would make it much better still is if other areas of the world would take up similar legislation so the playing field would level.

Re: How to effectively evade the GDPR and the reach of the DPA

#16
post #7

Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/

Yes it does apply. https://www.hipaajournal.com/american-companies-gdpr/

Your link is in reference to multi national companies. I don’t see how GDPR applies to companies that don’t do business with EU persons and without an EU presence.

Re: How to effectively evade the GDPR and the reach of the DPA

#18
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

Some pretty big fines have been issued already. See: https://www.enforcementtracker.com/ Over time I expect them to go up further as companies can no longer claim they did not have enough time or were not aware of the law (that never was a defense anyway but DPAs tend to be lenient. So far). Since the GDPR has come into effect I see in my practice that companies are a lot more aware of their responsibilities towards…

I mean, I genuinely hope I'm wrong here, so I'm happy if other people are disagreeing with my interpretation.

Re: How to effectively evade the GDPR and the reach of the DPA

#19

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

> The EU doesn't have such status or power over US companies.

US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Re: How to effectively evade the GDPR and the reach of the DPA

#20
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

The larger fines are starting to trickle through[0], remember EU bureaucracy is usually less about flashy cases than US and more of giving people the tools to do the right thing.

[0]: https://www.enforcementtracker.com/

Post reply on HN