Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

131–140 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#131
post #83

Earlier quoted context omitted.

GDPR fines won't ever repair any national budget, you're being cynical. > Domestically these countries have entities collecting personal data in the same evil way as US entities Can you provide sources for this allegation?

In Germany they're Schufa, Rundfunkbeitrag collection service, copyright predators. In Poland I don't even know the names, but if you ever leave your phone number at any doctor, dentist, or blood test lab, starting from next day you'll receive tons of phone calls offering "free products", invitations to "product presentations". Especially if your age is > 50.

> In Poland I don't even know the names, but if you ever leave your phone number at any doctor, dentist, or blood test lab, starting from next day you'll receive tons of phone calls offering "free products", invitations to "product presentations"

I don't know where you are getting your information from but that's not true.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#132

> The Dutch DPA started the investigation on Uber after more than 170 French drivers complained to the French human rights interest group the Ligue des droits de l’Homme (LDH), which subsequently submitted a complaint to the French DPA. I wonder on what the initial suspicion from the drivers was based.

Could be simple negligence on Uber's part.

Personal anecdote:

Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington.

I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started spamming me again. From the same address.

That's how I knew that they never deleted my info and kept it in the US.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#133

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

"These cannibals keep eating people because their country's laws allow it. It's not right to blame the cannibals, the governments should figure it out."

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#134

Earlier quoted context omitted.

In Germany they're Schufa, Rundfunkbeitrag collection service, copyright predators. In Poland I don't even know the names, but if you ever leave your phone number at any doctor, dentist, or blood test lab, starting from next day you'll receive tons of phone calls offering "free products", invitations to "product presentations". Especially if your age is > 50.

> In Poland I don't even know the names, but if you ever leave your phone number at any doctor, dentist, or blood test lab, starting from next day you'll receive tons of phone calls offering "free products", invitations to "product presentations" I don't know where you are getting your information from but that's not true.

Personal experience of mine and within circle of my acquaintances. Most of the times there is some "GDPR form" you have to sing to receive any service. The blood test results leak from time to time as well. We might be living in different Polands though.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#135

I guess this is always going to raise some eyebrows, with this amount of money it's hard to say it's not political. However I would like to say that the Dutch privacy authority actually seems pretty sincere at enforcing privacy legislation. It's just that until recently they were just sending angry letters, and now they've been given power to do more than empty threats.

> with this amount of money it's hard to say it's not political.

If by political you mean "aimed to be effective", then yes it is political. If the fine is too low and these companies make a healthy profit through these practices, they will just take the loss.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#136
post #132

> The Dutch DPA started the investigation on Uber after more than 170 French drivers complained to the French human rights interest group the Ligue des droits de l’Homme (LDH), which subsequently submitted a complaint to the French DPA. I wonder on what the initial suspicion from the drivers was based.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

Have you followed with a notification to your privacy authority?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#137
post #129

Earlier quoted context omitted.

EU citizens: We don't want our data in the US, where it can be siphoned off to other companies. US company: siphons data EU: You can't do that. HN commenter: Damn these fiefdoms wanting their cut, what has the internet become? I pine for a simpler time, when I could do anything I wanted with data against people's will and nobody could stop me, that truly was the golden age.

He was saying that Uber will no longer operate in NL/EU, the pining was for "equal access to US services", not your data. FWIW, I am annoyed myself about having to accept GDPR popups on every website I visit, so I too pine for a day where US companies have nothing to do with "EU citizens".

Right, but the reason EU citizens don't have equal access to US services is because EU citizens decided that the services they use need to be careful with the EU citizens' data. US services said "nah, that sounds too hard, I'm outta here" instead.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#138
post #101
post #87

Earlier quoted context omitted.

Your comment and the article however don’t explain what the group complained about and how did they know data was being transmitted to the us, though. Did they made the allegations up and they happened to be right? I don’t think that’s the case.

The DPA has powers of subpoena. They can basically raid the place. Usually, companies don't want this to happen and they co-operate. How exactly did the DPA know that Uber processes all data in their central IT department in the US? Uber probably told them and didn't try to pretend they have any local hardware or entity in charge of it. That would be a stupid thing to lie about? In any event the fine is mostly for no…

you are missing the point entirely. the DPA has subpoena powers, sure.

But before the DPA can get involved, there must be a complaint.

Such complaint came from Ligue des droits de l’Homme (LDH) and here is my question: how was this group informed that Uber was sending data to the US?

No doubt about what happens when the DPA gets involved, I'm not arguing over that.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#139
post #127

Does anyone know good best practices and software/DB patterns to model localized GDPR-compliance into global software systems? I know ASP.NET Core comes with some GDPR-related helpers but it's more interesting to know general best practices and patterns not related to a specific framework.

basically, make sure your data governance is on point. It should almost live outside of your software stack.

Tools like collibra, purview, informatica, ... that know you database, are your best tools at enterprise level.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#140

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

Since the company getting fined is also the company that spied on police car positions in the US I don't think that this type of shady behaviour helped in showing good faith in this case.
Post reply on HN