Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

121–130 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#121
post #46

Currently there's not much the data protection authorities in the EU can do about foreign companies abusing the data of users. I assume that in the coming years (or decade?) there will be more efforts to ensure the enforcement of EU law for foreign companies that offer services to EU citizens as part of trade deals. Right now there's e.g. a flourishing industry of data brokers in Israel that illegally collects data f…

It is enforced and viral in EU. Think of it like radioactive materials, any operation needs to be fully tracked. While accessing any user personal details you need to have user consent to process their personal data. You can't simply buy the dataset and assume it has consent. When you buy data from data provider you need to make sure user gave consent to handle data by third-parties to that provider in accordance to…

While accessing any user personal details you need to have user consent to process their personal data.

Consent is only one of the lawful bases for processing data under the GDPR. In practice, it's the one almost everyone tries not to rely on unless they can't avoid it, because it comes with extra obligations that other bases might not.

Re: How to effectively evade the GDPR and the reach of the DPA

#122
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens.

Your argument reduces to "freedom of speech" == "freedom to take and distribute personal information" (They are not equal).

Your walled gardens cherry on top only highlights the deficiencies that some countries have to protect personal information - Saying this is making the internet into walled gardens is like promoting tax evasion by using Ireland (in this case the US == Ireland, because it is deficient)

Re: How to effectively evade the GDPR and the reach of the DPA

#123
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

If the companies don't have assets in the EU that can be affected by EU prosecution, then the GDPR is not enforceable. It might be possible to prosecute and trial management, but again this has only consequences if they enter EU jurisdiction or if they are extradited. Such issues and questions always arise with laws whose reach is extraterritorial. Keep in mind that the US has a fair number of these laws as well.

Re: How to effectively evade the GDPR and the reach of the DPA

#124

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

There have occasionally been efforts to do large international USD transactions which don't touch the US, usually because one or both of the participants is under US sanction. There is enough USD infrastructure in London that it may be an alternative to New York, but everyone involved has to scrupulously avoid any interaction with any machinery under US jurisdiction, which is quite difficult.

I learned about this from reading the case brought in he UK by the US government to try to stop this happening. I didn't bookmark it, and of course can't find it now.

Not this, but an example of how it can go wrong:

> According to the settlement agreement, BACB actively solicited U.S. dollar business from Sudanese banks and processed the transactions by way of an internal book transfer process that involved a nostro account maintained at a foreign bank (Bank B) located in a country that imports Sudanese-origin oil. (A nostro account is an account a bank holds in a foreign currency in another bank.) Although these transactions were not processed to or through the U.S. financial system, the process to fund BACB’s U.S. dollar nostro account at the foreign bank did involve transactions processed by or through U.S financial institutions in apparent violation of the U.S. economic sanctions.

https://www.nafcu.org/compliance-blog/ofac-dings-london-bank...

Re: How to effectively evade the GDPR and the reach of the DPA

#125

Earlier quoted context omitted.

It’s like drug cartels relocating from Mexico: noone will feel sorry.

They would be relocating their corporation only - they'd still be operating in the EU on EU customers.

In that case they would still be subject to the GDPR.

Re: How to effectively evade the GDPR and the reach of the DPA

#126
post #89

Earlier quoted context omitted.

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

> They definitely try to make it hard for you, and to dodge responsibility. Yes, but at the same time you do not want them handing over all your data with zero checks on identity right..?

My ID contains: first name, last name, date of birth, place of birth, length, issuance and expiration, document number, citizen service number (~SSN), citizenship, photo (2x), gender, issuing authority (in my case: a municipality so small that it's more specific than geoIP), and in some countries it also contains your place of residence.

If they just have my name, now they have a lot of extra information. That's why my government recommends[1] to both watermark the copy and blacken unnecessary fields like the citizen service number and your photo. Such fields don't help them identify you, so you shouldn't share it with them. But imagine actually doing that: the only non-black parts (the parts they can actually match against their database) would be my name. Or in the case of WiFi tracking: nothing. I had to submit ID but really they just looked up whatever MAC address I claimed; I could have claimed my ex girlfriend's MAC address for all they knew. It's also trivial to photoshop a document if all you need to swap around are a few letters.

Identification is completely useless unless done in person when they can actually hold the document against the light and compare it to the European database of what it should look like[2]. (I've never seen anyone do the latter; see also lichtbildausweis[3].) Online, the best you can do is ask to confirm data that you already have about the person. Asking to confirm that same data but on a photoshopped (watermarked and censored) piece of plastic doesn't help anything.

In conclusion, sure I agree that you shouldn't be able to request my data, but the point is about the means rather than the goal. Is providing a censored and watermarked picture of an identity document a means of reaching that goal a better means of reaching that goal than confirming some data like the calendar week during which I was in whatever hotel they have my data from (for example)? That's what GP was offering them: asking to confirm masked data rather than having to provide extra and unnecessary personal data.

[1] https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/v... In Dutch, but see the pictures near the bottom. This is the federal Dutch government's recommendation on how to provide a copy of your identity card.

[2] https://www.consilium.europa.eu/prado/en/search-by-document-...

[3] Original in Dutch: https://dewinter.com/2012/09/24/de-legitimatiecontrole-in-ne... TL;DR: a "lichtbildausweis" is the german word for "photo ID". But how many Dutch people know that? So when you order a photo ID from germany, for example from a website that sells company badges (like, upload your company logo and employee photo and they'll print a plastic card for you), make sure it contains all the fields that you'd generally expect on an ID card, and they'll take it for being a german ID.

Re: How to effectively evade the GDPR and the reach of the DPA

#127
post #71

Now watch the entire currently-EU based adtech industry relocate out of the EU...

I thought this was obvious. I've been saying since day 1 that GDPR won't help much with privacy. It might even do the opposite by making people feel that their data is safe. But a company beyond the jurisdiction of the EU can simply ignore GDPR and vacuum up all the data they want. What will ultimately help with privacy is not leaking out this data in the first place. Push browsers and other such services/devices to…

UE should do as China do. A big firewall that block all US business that do not comply with GDPR.

Re: How to effectively evade the GDPR and the reach of the DPA

#128
post #64
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Twitter/Facebook/whatever-the next-big-thing-is doesn't have 9 out of 10 fields that are on my ID card. If I show them a piece of blacked-out plastic with only my first name visible, since that's the only piece of information they have about me, it won't help them identify me.

Yes, you need to prove that you're the data subject matching their records before they should act on your request, whatever that request may be. But uploading a copy of your ID card almost never serves that purpose. See also a bigger comment I wrote elsewhere in this thread with sources and examples: https://news.ycombinator.com/item?id=23957503

Re: How to effectively evade the GDPR and the reach of the DPA

#129

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

The bank will either have a presence in the US itself, or it'll have a partner that does that it'll route the transaction through. If you've done a USD transfer, it'll most likely be a SWIFT transfer, and you can ask your bank for the SWIFT routing log. You'll most likely see an NYC bank (or NYC branch of your bank) in the middle.

SWIFT is a communication network, it replaces the letters and couriers ancient banks would have used to agree that payments have been ordered and funds have been moved. Payment don't "go through" any bank that hasn't been explicitly requested. The whole point of the SWIFT network is that it is global and it allows you to reach every branch of every bank.

There are of course banks whose SWIFT processing is handled by someone else, but they are usually service bureaus or central offices within a conglomerate, not partners in a specific country.

Re: How to effectively evade the GDPR and the reach of the DPA

#130

For most, you can simply ignore it since it doesn't apply anyways

I'd to hear why I was downvoted. it is a fact people forget. Most have websites have that stupid cookie notification when 99 don't need to. Here is how to evade the gdpr, ignore it like it doesn't exist
Post reply on HN