Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

111–120 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#112
post #7

Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/

It applies. Practical enforceability is another thing completely.

Re: How to effectively evade the GDPR and the reach of the DPA

#114
post #57

Earlier quoted context omitted.

Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral

But is it true? If not then I'm pretty sure in the UK at least there's some law against it.

There are certainly rules in the GDPR about automated decision-making that might be relevant.

https://gdpr-info.eu/art-22-gdpr/

https://gdpr-info.eu/recitals/no-71/

Re: How to effectively evade the GDPR and the reach of the DPA

#115

Earlier quoted context omitted.

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be. In other words, it's not a bug, it's an accidental feature.

One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.

Re: How to effectively evade the GDPR and the reach of the DPA

#116
post #57

Earlier quoted context omitted.

Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral

But is it true? If not then I'm pretty sure in the UK at least there's some law against it.

I don't know, but I'd think it's slightly true I'd guess you'll be marked in THEIR database, so if the hotel happens to use that company's lists, you might be marked, but not be high risk in anyone else's books...

Re: How to effectively evade the GDPR and the reach of the DPA

#117

Earlier quoted context omitted.

I am sorry, how does that resolve the issue of them operating illegally? The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up. If this is an accidental feature it means you should be accidentally run out of business.

> how does that resolve the issue of them operating illegally? Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request: The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. 1. https://gdpr.eu/recital-6…

That is true, but the word "reasonable" is significant. Taking reasonable steps to confirm a data subject's claimed identity is fair and necessary. Giving them the run around and hiding behind that verification obligation as an excuse is not.

Re: How to effectively evade the GDPR and the reach of the DPA

#118

Earlier quoted context omitted.

> how does that resolve the issue of them operating illegally? Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request: The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. 1. https://gdpr.eu/recital-6…

That is true, but the word "reasonable" is significant. Taking reasonable steps to confirm a data subject's claimed identity is fair and necessary. Giving them the run around and hiding behind that verification obligation as an excuse is not.

I mean, sure, but OP indicated that he didn't want to provide the info they requested for verification. I don't see how their action here could be considered unreasonable.

"I promise you that I am the only person on earth with this name" doesn't really seem like a sufficiently secure attestation.

Re: How to effectively evade the GDPR and the reach of the DPA

#119
post #70
post #64

Earlier quoted context omitted.

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Electronic signatures tied to your ID. Don't delete instantly but after X days. Notify owner immediately. Problem solved.

you mean like Estonia's digital signing? ;) and pretty sure that most sane-ish companies already delay and notify people of major stuff like account deletion and such, less hassle on both parts, company also benefits as it can just batch process requests weekly or monthly or so.

Re: How to effectively evade the GDPR and the reach of the DPA

#120
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

A noticeable number of websites outside the EU did block access to people who appeared to be from the EU when the GDPR was introduced.

As for over-reach, the practical reality is that laws can be enforced extra-territorially if, and only if, the country that wants them has leverage. In some cases, that comes from making deals with other governments, where one or both give weight to the other's claims voluntarily in their own territory.

In other cases, it comes from networking effects. If you are a US-based business running a US-based website with no presence of any kind in the EU, then maybe the EU can't do anything to hurt you. On the other hand, if you have any relationships with other businesses that are within reach of the EU, they might be used as leverage to reach you.

Worst case, you find that anyone connected with your business who travels to the EU or anywhere with a relevant extradition treaty gets arrested. Obviously a reaction that extreme is unlikely, but if perhaps a government thinks you owe them lots of tax money or the personal data you aren't processing according to their wishes relates to some matter of their national security, stranger things have happened.

Post reply on HN