Earlier quoted context omitted.
In that case they would still be subject to the GDPR.
...yet since it's unenforceable, then they probably don't care.
How to effectively evade the GDPR and the reach of the DPA
161–170 of 200 posts
Re: How to effectively evade the GDPR and the reach of the DPA
#162Earlier quoted context omitted.
I am sorry, how does that resolve the issue of them operating illegally? The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up. If this is an accidental feature it means you should be accidentally run out of business.
> how does that resolve the issue of them operating illegally? Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request: The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. 1. https://gdpr.eu/recital-6…
People may not agree with their stance, but it has yet to be successfully challenged in court to my knowledge.
Re: How to effectively evade the GDPR and the reach of the DPA
#163Re: How to effectively evade the GDPR and the reach of the DPA
#164Earlier quoted context omitted.
Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral
That's not legal, because that is still personal information being stored. They have to delete it all , upon request.
Re: How to effectively evade the GDPR and the reach of the DPA
#165Earlier quoted context omitted.
In theory, yes. In practice... I'm not so sure. These processes are slow and I imagine that the regulators are drowning in complaints and are hugely understaffed. And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).
Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter? As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.
Re: How to effectively evade the GDPR and the reach of the DPA
#166Earlier quoted context omitted.
There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway." Every time I insisted they take it down, right now. Every time they have complied. There's so many it's basically pulling weeds at this point. The scarier companies are the ones collecting pictures of your face to train their private facial recognition softw…
> There's so many it's basically pulling weeds at this point. ...and they are often run by the same people. They use shell companies to basically avoid take-down requests. Their goals is to make it sufficiently annoying to take down your information, that most people give up. While at the same time removing it (regardless of the process) for anyone that occupies them too much time - because your individual data isn't…
Re: How to effectively evade the GDPR and the reach of the DPA
#167You shouldn't have to guess where your personal data is going, and how it's being used. When the GDPR was first coming into force, I remember getting bombarded with all these notification emails from all these companies coming out of the woodwork that I didn't recognize. But I don't think I've ever been notified by email, SMS, phone or smoke signal since then.
The biggest flaw of the GDPR in my opinion is that it leaves the definition of what's considered personal identifying information with too much wiggle-room for creative interpretation. Maybe it's hard to pin down exactly, but there's often too much emphasis on the word "identifying", as if it's otherwise OK to gather every intimate online detail and build a profile that is a unique identity in and of itself. It's even worse when real-world decisions can be based on it without your knowledge.
I recently had my own rude awakening learning about these data brokers and risk analysis services. The matter itself was relatively trivial, but I didn't realize the extent of this before and the scope of what personal information they're gathering. And it doesn't matter if you think it won't affect you, since you've done nothing wrong. From what I read elsewhere, even exercising fundamental consumer rights may be held against you. https://news.ycombinator.com/item?id=21440526
Re: How to effectively evade the GDPR and the reach of the DPA
#168Earlier quoted context omitted.
Unless the payment processor is in the EU, the courts would have no jurisdiction.
The courts would have jurisdiction on the recipient though. The recipent has to evidence a valid reason according to GDPR to process a subject's data.
Re: How to effectively evade the GDPR and the reach of the DPA
#169Earlier quoted context omitted.
Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…
> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens > If that were the case, I’d block EU access for any of my domains These two statements are at odds with each other ...
Re: How to effectively evade the GDPR and the reach of the DPA
#170Earlier quoted context omitted.
Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…
Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.