Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

101–110 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#101

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.

Because they cannot enforce it. This is the same reason websites don't comply with african law. Wether it is morally wrong or right is an other question.

Re: How to effectively evade the GDPR and the reach of the DPA

#102
post #98

Earlier quoted context omitted.

Some pretty big fines have been issued already. See: https://www.enforcementtracker.com/ Over time I expect them to go up further as companies can no longer claim they did not have enough time or were not aware of the law (that never was a defense anyway but DPAs tend to be lenient. So far). Since the GDPR has come into effect I see in my practice that companies are a lot more aware of their responsibilities towards…

I dont know. From what I can understand of German/Google translate, the third from top: https://www.enforcementtracker.com/ Link to .pdf: https://www.ris.bka.gv.at/Dokumente/Dsk/DSBT_20180927_DSB_D5... Is the Austrian Authorities making a 300 Euro fine to a "common citizen" making "illegal" use of a dashcam (it seems - but I am not sure about it - that the issue is that the car is not - how? - visibly marked as video…

Why would you pick that example, rather than the 16 million fine an Italian company received?

Re: How to effectively evade the GDPR and the reach of the DPA

#103

The achilles heel of the GDPR is that you must act through a DPA. In the case of the Shrems he had to basically sue the Irish GPA in order for them to do their job. And instead of actually doing their job, the Irish DPA instead fought Shrems on behalf of Facebook. As an EU citizen and resident, it's abundantly clear to me that getting a DPA to act in my best interest is mostly hopeless. I'm reminded of the CANSPAM Ac…

What about Article 79, "Right to an effective judicial remedy against a controller or processor"? It reads:

> Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

> Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

Re: How to effectively evade the GDPR and the reach of the DPA

#104
I had a very similar experience with Apollo.io. Somehow my professional data (business email, personal phone number, name, job title and my LinkedIn network and connections) ended up on this website without my consent. I’m assuming it was collected from several sources such as LinkedIn (Even though I had my privacy settings tight) and some conferences I attended in the past year. Either way I contacted them and they sent me a document to confirm my identity and then proceeded to remove my data from their website after I sent it back. I was a bit shocked as it’s basically asking to confirm my identity and give them more information about me when I haven’t even granted them permission in the first place. Such “data brokers” need to be regulated. The most annoying thing is that they only remove data under GDPR, CCPA if I am a resident of California, UK or EEA. Well what if I’m from a country that doesn’t fall under one of those 2 regulations?

Re: How to effectively evade the GDPR and the reach of the DPA

#105

Earlier quoted context omitted.

Ok but he didn't subscribe on that website.

OP here - That's the point. They are not a data controller by that very simple fact. They are processing this data on an illegal basis. Any lawyer around that want to assist me suing in the US?

[deleted]

Re: How to effectively evade the GDPR and the reach of the DPA

#106

Earlier quoted context omitted.

Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be. In other words, it's not a bug, it's an accidental feature.

I am sorry, how does that resolve the issue of them operating illegally? The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up. If this is an accidental feature it means you should be accidentally run out of business.

> how does that resolve the issue of them operating illegally?

Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request:

The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers.

1. https://gdpr.eu/recital-64-identity-verification/

Re: How to effectively evade the GDPR and the reach of the DPA

#108
Yes, it's hard for EU authorities to enforce its laws on a company that has no EU presence or revenues to threaten. At least the Luxembourg DPA is doing something about it, unlike the Irish DPA that deliberately does nothing (or worse, colludes with Facebook to help them skirt GDPR with highly dubious and most likely legally invalid semantic contortions).

Re: How to effectively evade the GDPR and the reach of the DPA

#109

Earlier quoted context omitted.

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

They obviously need to have a process to validate identity, and it's ridiculous to think that they would tailor that process for every request. It's also odd that you would want to give them your NEW address if they are likely validating against your OLD address. Why didn't you just give them your OLD address to check against?

In fact identity verification is one of Acxiom's lines of business, but that is US-centric and probably doesn't work very well for EU or global persons.

Disclaimer: I worked for Acxiom 2007-2009, but not in the data brokerage core business.

Re: How to effectively evade the GDPR and the reach of the DPA

#110
post #11

Earlier quoted context omitted.

> I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. China is the most straightforward example, companies cannot operate unless they basically do it through an - implicitly Chinese state controlled - partner company. China also has a literal Great Firewall monitoring, modifying or stopping all cross-border traffic. So yes, you have to play by their rules if you want a…

I think your information may be a bit out of date, in China you can own and operate as a WFOE https://en.m.wikipedia.org/wiki/Wholly_foreign-owned_enterpr...

Could be, I'm not an expert. I'm mainly based that on stories I read regarding Tencent, ASML etc.
Post reply on HN