Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

151–160 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#153
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens

> If that were the case, I’d block EU access for any of my domains

These two statements are at odds with each other ...

Re: How to effectively evade the GDPR and the reach of the DPA

#154
post #11

Earlier quoted context omitted.

> I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. China is the most straightforward example, companies cannot operate unless they basically do it through an - implicitly Chinese state controlled - partner company. China also has a literal Great Firewall monitoring, modifying or stopping all cross-border traffic. So yes, you have to play by their rules if you want a…

I think your information may be a bit out of date, in China you can own and operate as a WFOE https://en.m.wikipedia.org/wiki/Wholly_foreign-owned_enterpr...

WFOEs indeed exist, but there are many restrictions on the types of business they can conduct, both directly[1] and indirectly because activities require licenses[2] that WFOEs can't get. The grandparent post was wrong in the details, but it's still a different world from the USA or EU.

1. https://www.fdichina.com/blog/china-company-registration/ftz...

2. https://www.china-briefing.com/news/entry-strategy-chinas-on...

Re: How to effectively evade the GDPR and the reach of the DPA

#155
The Privacy Shield framework that was just declared invalid by the EU included a requirement that US companies make themselves available for arbitration of disputes brought by EU data subjects. GDPR by itself doesn't include that concept. But if GDPR is going to be enforceable, the negotiation around a successor to Privacy Shield should probably include it.

Re: How to effectively evade the GDPR and the reach of the DPA

#156
post #54

We've actually been threatened with a lawsuit because RocketReach displayed some obviously inflated revenue for one of our customers. Luckily, we were able to prove that the numbers were changed recently and threatened to report them for fraud, which ended this pretty quickly. Seriously shady company.

> threatened with a lawsuit I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?

We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc).

They only retracted the thread after we could prove (via Google Cache and archive.org) that the page was very recently modified to show such a big revenue and threatened to report them for fraud.

We probably could've deflected the case since the company was public and therefore its revenue was also public, but, as a very small company, we had neither time nor money to spare for an useless lawsuit. And we assume that this was their bet. We switched to a competitor after this, obviously.

[0] It later actually turned out that this AGB change was after our purchase and not yet affecting us, but we didn't know that at the time.

Re: How to effectively evade the GDPR and the reach of the DPA

#157

Earlier quoted context omitted.

They would be relocating their corporation only - they'd still be operating in the EU on EU customers.

In that case they would still be subject to the GDPR.

...yet since it's unenforceable, then they probably don't care.

Re: How to effectively evade the GDPR and the reach of the DPA

#158
post #76

Earlier quoted context omitted.

You do know that US law is imposed everywhere in the world, right? DMCA notices and stuff like that.

So it seems are parts of Chinese law. https://qz.com/1875863/hong-kong-national-security-law-cover...

A country claiming its law is enforceable everywhere does not make it so.

Re: How to effectively evade the GDPR and the reach of the DPA

#159

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.

Because I didn't vote for it, not even indirectly.

Re: How to effectively evade the GDPR and the reach of the DPA

#160
post #57

Earlier quoted context omitted.

There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway." Every time I insisted they take it down, right now. Every time they have complied. There's so many it's basically pulling weeds at this point. The scarier companies are the ones collecting pictures of your face to train their private facial recognition softw…

Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral

That's not legal, because that is still personal information being stored. They have to delete it all, upon request.
Post reply on HN