Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

141–150 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#141
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

There's so many copies of personal data all out there, it would blow your mind. I have a friend who works in this industry. Brokers sell to other brokers who sell to other brokers, who might even sell it back to the original broker after it's been "enriched" with more detail from additional brokers.

I'm a pessimist. You will never remove your personal data. If you get it removed by one company, the others will pop up like mushrooms. Also, from what I've seen, a lot of this information is out-of-date or crap that is just plain wrong.

Re: How to effectively evade the GDPR and the reach of the DPA

#142
post #134

Earlier quoted context omitted.

One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.

Has the EU actually shown any teeth to these outfits? It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.

Has the EU actually shown any teeth to these outfits?

It's starting to.

https://dataprivacymanager.net/5-biggest-gdpr-fines-so-far-2...

There are 7-8 figure fines already this year, and two 9 figure ones that the UK regulator has given notice on.

Re: How to effectively evade the GDPR and the reach of the DPA

#143

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.

It may just not be worth bothering. Most of the time when I see someone complaining about a page being blocked for Europeans it's some local American news outlet serving a town of five thousand people whose IT department consists of one guy in a broom closet.

Re: How to effectively evade the GDPR and the reach of the DPA

#144

Earlier quoted context omitted.

One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.

In theory, yes. In practice... I'm not so sure. These processes are slow and I imagine that the regulators are drowning in complaints and are hugely understaffed. And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).

Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter?

As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.

Re: How to effectively evade the GDPR and the reach of the DPA

#145
post #44

Earlier quoted context omitted.

USD transfers even within same non-US based bank let's say same example in Poland is done with SWIFT, but unlikely it goes thru NYC bank as the cost is none and the transfer is instant. SWIFT is used only for addressing and accounting in such case.

Within the same bank it's just internal accounting. But when two different banks are involved, an USD transfer generally goes through USA.

No it doesn’t, https://en.m.wikipedia.org/wiki/Eurodollar.

Not to mention that since the USD is a CLS/FCC currency you can perform correspondent banking transactions with it without having any government involved in the process.

Re: How to effectively evade the GDPR and the reach of the DPA

#146
post #123

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

If the companies don't have assets in the EU that can be affected by EU prosecution, then the GDPR is not enforceable. It might be possible to prosecute and trial management, but again this has only consequences if they enter EU jurisdiction or if they are extradited. Such issues and questions always arise with laws whose reach is extraterritorial. Keep in mind that the US has a fair number of these laws as well.

deny entry or arrest executives of the company if they try to enter the EU. Surely some of these people travel...

Re: How to effectively evade the GDPR and the reach of the DPA

#147
post #76

Earlier quoted context omitted.

You do know that US law is imposed everywhere in the world, right? DMCA notices and stuff like that.

This is not true. It is the choice of the local jurisdiction (or sometimes the company so chooses) to abide. The US does exert leverage in many situations as one might expect the EU to do. But acting as if every country is 100% beholden to US law with no sovereignty is wrong and just excuse-making. There are many places that don't respect DMCA making your statement very false.

Maybe so but it is effectively imposed on all citizens of the world. Other than for the now rare cases that people are serving stuff up from their home.

Re: How to effectively evade the GDPR and the reach of the DPA

#148

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

Euro dollars are constantly traded without going through the US.

CLS currencies and any currency which is fully convertible can be used in transactions without any involvement of the jurisdiction that minted the currency in the first place.

The USD has a huge settlement infrastructure that is completely independent of the US.

Re: How to effectively evade the GDPR and the reach of the DPA

#149
post #131

Earlier quoted context omitted.

If you buy a stolen bike and could reasonably have known that it was not obtained with consent, you're also liable. For example, an unusually low price from someone who doesn't own a bike shop and wants cash can be indicators for that. In the case of data, it may be that they are able to provide lots of data without plausible source.

Sure, you might be liable, but do you think that in practice this will matter? It's not like it's somehow obvious that an advertising company has data on you that they shouldn't have. Somebody needs to actually suspect that for any investigation to happen.

I find it hard to say without a specific example, but I'm afraid that you might very well be right in the general case.

Re: How to effectively evade the GDPR and the reach of the DPA

#150
post #76

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

You do know that US law is imposed everywhere in the world, right? DMCA notices and stuff like that.

So it seems are parts of Chinese law. https://qz.com/1875863/hong-kong-national-security-law-cover...
Post reply on HN