Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

161–170 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#161
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

> Every fiefdom wants their cut and their say

You mean, the epicenter of that global network transformed it into a tool of influence and surveilance? [1] Or maybe that the companies participating in that global network saw interest in walling that global network ? [2] [3] Or maybe that global network is being reshaped by a few dominant actors so much that outside regulation becomes necessary? [4] [5]

No, of course not; it must be local barons trying to scrap a bit of power, not at all a reaction to massive abuses from the industry.

[1]: https://en.wikipedia.org/wiki/PRISM [2]: https://www.eff.org/fr/deeplinks/2013/05/google-abandons-ope... [3]: https://blockthrough.com/blog/the-walled-gardens-of-the-ad-t... [4]: https://www.theverge.com/c/23998379/google-search-seo-algori... [5]: https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#162
post #129

Earlier quoted context omitted.

EU citizens: We don't want our data in the US, where it can be siphoned off to other companies. US company: siphons data EU: You can't do that. HN commenter: Damn these fiefdoms wanting their cut, what has the internet become? I pine for a simpler time, when I could do anything I wanted with data against people's will and nobody could stop me, that truly was the golden age.

He was saying that Uber will no longer operate in NL/EU, the pining was for "equal access to US services", not your data. FWIW, I am annoyed myself about having to accept GDPR popups on every website I visit, so I too pine for a day where US companies have nothing to do with "EU citizens".

Hahaha, that will not happen. And if Uber against all odds actually leaves some other company will swoop in and take their market. Personally I prefer Bolt over Uber for rides here in Sweden.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#163
post #129

Earlier quoted context omitted.

He was saying that Uber will no longer operate in NL/EU, the pining was for "equal access to US services", not your data. FWIW, I am annoyed myself about having to accept GDPR popups on every website I visit, so I too pine for a day where US companies have nothing to do with "EU citizens".

Right, but the reason EU citizens don't have equal access to US services is because EU citizens decided that the services they use need to be careful with the EU citizens' data. US services said "nah, that sounds too hard, I'm outta here" instead.

What US services left? Only ones I know of are a couple of US centric newspapers. Virtually everyone stay in the EU market.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#164
post #129

Earlier quoted context omitted.

EU citizens: We don't want our data in the US, where it can be siphoned off to other companies. US company: siphons data EU: You can't do that. HN commenter: Damn these fiefdoms wanting their cut, what has the internet become? I pine for a simpler time, when I could do anything I wanted with data against people's will and nobody could stop me, that truly was the golden age.

He was saying that Uber will no longer operate in NL/EU, the pining was for "equal access to US services", not your data. FWIW, I am annoyed myself about having to accept GDPR popups on every website I visit, so I too pine for a day where US companies have nothing to do with "EU citizens".

Imagine how much poorer the world will be when one fewer jitney cab company operates in the Netherlands.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#165

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

>The EU keeps moving the goalposts on what constitutes “safe” transfers (we’re on the 5th round of this)

This is a wrong phrasing of the problem: The US is not, and has never been, a safe haven to transfer personal data to. However, it would significantly impact trade (and policing) concerns between the EU and the US if that statement were to be treated seriously. This is why the European Commission and the Parliament have repeatedly tried to create a framework which allows transfer of data despite the US' insistence on secret access to the data without due process (aka secret courts, which cannot be due process by any reasonable definition). European courts, again repeatedly, have taken the stipulations in various laws guaranteeing rights to citizens seriously, and keep striking down the badly made frameworks. It's not "shifting goal posts", but rather "not willing to accept the political costs of respecting citizens' rights".

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#166
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

NAL, but I think GDPR has exceptions for remote access, i.e. if a worker in India is viewing data held in the US, that is not necessarily formally considered a transfer from the US to India, even though the data clearly has made it to India if it's being displayed on a screen there.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#168
post #119
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

Access to tech is different from handling of personal data though -- the EU GDPR laws around that are clear and fair People have a right to know where their personal data is going, what is being stored, what it is being used for and should have a mechanism to correct it and delete The wider challenge is how that is handled in a compliant way with LLMs and generative tools which vendors do not seem to be taking partic…

> The wider challenge is how that is handled in a compliant way with LLMs and generative tools which vendors do not seem to be taking particularly seriously yet

I'm curious as to why people would want to train LLMs on personal identifying information. What's the benefit of an LLM that has a large collection of names, addresses, dates of birth etc.?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#170
post #143

> Since the end of last year, Uber uses the successor to the Privacy Shield. Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.

The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list

So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework?

Lots of unknowns though, since Schrems has already announced a challenge to the Framework. The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent.

Post reply on HN