Earlier quoted context omitted.
Ultimately, adtech has to broker between publishers and advertisers. If those have any business in EU, they will be liable for the data, even if the broker is outside of jurisdiction.
But the publisher and advertiser might not know where the data came from. The broker could easily just say "oh yeah, we have permission from these people to share this data". I'm sure some of them will get caught, but how long will that take?
How to effectively evade the GDPR and the reach of the DPA
131–140 of 200 posts
Re: How to effectively evade the GDPR and the reach of the DPA
#132Earlier quoted context omitted.
That is true, but the word "reasonable" is significant. Taking reasonable steps to confirm a data subject's claimed identity is fair and necessary. Giving them the run around and hiding behind that verification obligation as an excuse is not.
I mean, sure, but OP indicated that he didn't want to provide the info they requested for verification. I don't see how their action here could be considered unreasonable. "I promise you that I am the only person on earth with this name" doesn't really seem like a sufficiently secure attestation.
But even if we can't go by that, I gave them plenty of options that won't involve me disclosing my entire address history. How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...
They didn't come up with any concrete suggestions that won't involve disclosing much more information about myself than I think it's reasonable to require in order to release my own personal info.
I think I was very reasonable, and they weren't. Legally I'm not sure what the situation is. IANAL.
Re: How to effectively evade the GDPR and the reach of the DPA
#133Earlier quoted context omitted.
Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be. In other words, it's not a bug, it's an accidental feature.
One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.
And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).
Re: How to effectively evade the GDPR and the reach of the DPA
#134Earlier quoted context omitted.
Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be. In other words, it's not a bug, it's an accidental feature.
One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.
It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.
Re: How to effectively evade the GDPR and the reach of the DPA
#135Earlier quoted context omitted.
Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…
You do know that US law is imposed everywhere in the world, right? DMCA notices and stuff like that.
Re: How to effectively evade the GDPR and the reach of the DPA
#136Earlier quoted context omitted.
They are selling into the EU though, right? So they do do business with EU persons.
Unless the payment processor is in the EU, the courts would have no jurisdiction.
Re: How to effectively evade the GDPR and the reach of the DPA
#137Earlier quoted context omitted.
But the publisher and advertiser might not know where the data came from. The broker could easily just say "oh yeah, we have permission from these people to share this data". I'm sure some of them will get caught, but how long will that take?
If you buy a stolen bike and could reasonably have known that it was not obtained with consent, you're also liable. For example, an unusually low price from someone who doesn't own a bike shop and wants cash can be indicators for that. In the case of data, it may be that they are able to provide lots of data without plausible source.
Re: How to effectively evade the GDPR and the reach of the DPA
#138We've actually been threatened with a lawsuit because RocketReach displayed some obviously inflated revenue for one of our customers. Luckily, we were able to prove that the numbers were changed recently and threatened to report them for fraud, which ended this pretty quickly. Seriously shady company.
I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?
Re: How to effectively evade the GDPR and the reach of the DPA
#139Typical of this kind of regulation: the real purpose is less about ensuring individual rights and more about giving bureaucrats more power. The GDPR is great in the latter sense. It’s impossible to predict the outcome of a legal process even if you do your very best to comply, and you can be slapped with incredible fines... Cross the wrong bureaucrat and your days are numbered (in an economic sense).
Ops, that was obviously a controversial standpoint. Just to be clear: I’m all for individual rights. But laws need to have predictable consequences and be fairly and equally enforced, and my impression is that the GDPR is not. As an example I’m pretty sure the local court here in Malmö, Sweden has violated my rights under the GDPR. Do you think anybody would give a rats ass if I complained? I highly doubt it...
Re: How to effectively evade the GDPR and the reach of the DPA
#140Earlier quoted context omitted.
I thought this was obvious. I've been saying since day 1 that GDPR won't help much with privacy. It might even do the opposite by making people feel that their data is safe. But a company beyond the jurisdiction of the EU can simply ignore GDPR and vacuum up all the data they want. What will ultimately help with privacy is not leaking out this data in the first place. Push browsers and other such services/devices to…
UE should do as China do. A big firewall that block all US business that do not comply with GDPR.
Also, I do remember reading some kind of EU document that this is what they were thinking of.