Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

161–170 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#161

Earlier quoted context omitted.

In that case they would still be subject to the GDPR.

...yet since it's unenforceable, then they probably don't care.

Why not? If they have offices in EU, raid them. If they have customers in the EU, freeze their bank accounts or sanction their payment processors.

Re: How to effectively evade the GDPR and the reach of the DPA

#162

Earlier quoted context omitted.

I am sorry, how does that resolve the issue of them operating illegally? The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up. If this is an accidental feature it means you should be accidentally run out of business.

> how does that resolve the issue of them operating illegally? Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request: The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. 1. https://gdpr.eu/recital-6…

This. I would go out on a limb and offer that Axciom has likely invested more in compliance in this regard than most other companies on the planet.

People may not agree with their stance, but it has yet to be successfully challenged in court to my knowledge.

Re: How to effectively evade the GDPR and the reach of the DPA

#164
post #57

Earlier quoted context omitted.

Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral

That's not legal, because that is still personal information being stored. They have to delete it all , upon request.

The implication (whether true or false) is that some company might treat the absence of a record in their database as suspicious.

Re: How to effectively evade the GDPR and the reach of the DPA

#165

Earlier quoted context omitted.

In theory, yes. In practice... I'm not so sure. These processes are slow and I imagine that the regulators are drowning in complaints and are hugely understaffed. And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).

Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter? As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.

Yes, absolutely. Yet the likelihood of Acxiom being fined anything other than some token amount in a case like mine is virtually zero.

Re: How to effectively evade the GDPR and the reach of the DPA

#166

Earlier quoted context omitted.

There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway." Every time I insisted they take it down, right now. Every time they have complied. There's so many it's basically pulling weeds at this point. The scarier companies are the ones collecting pictures of your face to train their private facial recognition softw…

> There's so many it's basically pulling weeds at this point. ...and they are often run by the same people. They use shell companies to basically avoid take-down requests. Their goals is to make it sufficiently annoying to take down your information, that most people give up. While at the same time removing it (regardless of the process) for anyone that occupies them too much time - because your individual data isn't…

I'd be interested to know if anyone has had success with any legal measure that would enjoin them or any other entity they're in any way affiliated with or that shares common ownership.

Re: How to effectively evade the GDPR and the reach of the DPA

#167
I don't know if there's another good example, but Poland fined an EU company under the GDPR for scraping profile data without giving proper notification: https://news.ycombinator.com/item?id=19530087

You shouldn't have to guess where your personal data is going, and how it's being used. When the GDPR was first coming into force, I remember getting bombarded with all these notification emails from all these companies coming out of the woodwork that I didn't recognize. But I don't think I've ever been notified by email, SMS, phone or smoke signal since then.

The biggest flaw of the GDPR in my opinion is that it leaves the definition of what's considered personal identifying information with too much wiggle-room for creative interpretation. Maybe it's hard to pin down exactly, but there's often too much emphasis on the word "identifying", as if it's otherwise OK to gather every intimate online detail and build a profile that is a unique identity in and of itself. It's even worse when real-world decisions can be based on it without your knowledge.

I recently had my own rude awakening learning about these data brokers and risk analysis services. The matter itself was relatively trivial, but I didn't realize the extent of this before and the scope of what personal information they're gathering. And it doesn't matter if you think it won't affect you, since you've done nothing wrong. From what I read elsewhere, even exercising fundamental consumer rights may be held against you. https://news.ycombinator.com/item?id=21440526

Re: How to effectively evade the GDPR and the reach of the DPA

#168
post #136

Earlier quoted context omitted.

Unless the payment processor is in the EU, the courts would have no jurisdiction.

The courts would have jurisdiction on the recipient though. The recipent has to evidence a valid reason according to GDPR to process a subject's data.

The recipient is outside the EU.

Re: How to effectively evade the GDPR and the reach of the DPA

#169

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens > If that were the case, I’d block EU access for any of my domains These two statements are at odds with each other ...

Yes, that’s my point. It’d be a tragedy.

Re: How to effectively evade the GDPR and the reach of the DPA

#170

Earlier quoted context omitted.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.

You do realize that Europeans et al have to deal with AML/KYC because of international agreements your countries have entered into? This isn’t just the US unilaterally saying “your banks and money processors must obey our laws.” The US passed extraterritorial laws, and then sought agreements from other countries to enforce these laws. The EU hasn’t done this. AFAIK there are no trade agreements or such that offer reciprocal rights to enforce GDPR. If the EU wants to enforce the GDPR globally, then that’s what they’d need to do.
Post reply on HN