Earlier quoted context omitted.
Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter? As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.
Yes, absolutely. Yet the likelihood of Acxiom being fined anything other than some token amount in a case like mine is virtually zero.
How to effectively evade the GDPR and the reach of the DPA
171–180 of 200 posts
Re: How to effectively evade the GDPR and the reach of the DPA
#172Which is true and obvious. Why anybody ever thought the GDPR would have teeth outside the EU is beyond me. It was always laughable to me that anybody believed that the EU had made a law that applied to every company in every country in the world.
Re: How to effectively evade the GDPR and the reach of the DPA
#173Earlier quoted context omitted.
> threatened with a lawsuit I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?
We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…
Good call ditching them.
[edit] speculative aside...
What if they were intentionally feeding rocketreech miss-information? it might seem far fetched but these personal data collecting companies like rocketreach or even equifax obtain their information from a variety of untrustworthy sources.
I was a victim of this through my own foolishness a couple years ago:
I was using a car insurance comparison site and guessed one piece of the required information I couldn't completely remember - a speeding ticket date - I couldn't remember the exact year. Turns out I entered it exactly one year off, and it was so long ago anyway that it had no bearing on the quotes.
After continuing with my existing insurer, a few months later my insurer sent me a demand for a rather large quantity of money... that's right, they attempted to backcharge me for 5 years worth of insurance over an extra speeding ticket they had "discovered". Obviously there was no way I would pay them but it was extremely difficult to convince them to stop harassing me for this money even though they had no proof. Even after demanding they provide evidence of their discovery which they refused.
It's scary how easy this is to do, and I wasn't even trying.
Re: How to effectively evade the GDPR and the reach of the DPA
#174Earlier quoted context omitted.
> threatened with a lawsuit I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?
We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…
Re: How to effectively evade the GDPR and the reach of the DPA
#175Earlier quoted context omitted.
> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens > If that were the case, I’d block EU access for any of my domains These two statements are at odds with each other ...
Yes, that’s my point. It’d be a tragedy.
Re: How to effectively evade the GDPR and the reach of the DPA
#176Earlier quoted context omitted.
If the companies don't have assets in the EU that can be affected by EU prosecution, then the GDPR is not enforceable. It might be possible to prosecute and trial management, but again this has only consequences if they enter EU jurisdiction or if they are extradited. Such issues and questions always arise with laws whose reach is extraterritorial. Keep in mind that the US has a fair number of these laws as well.
deny entry or arrest executives of the company if they try to enter the EU. Surely some of these people travel...
Re: How to effectively evade the GDPR and the reach of the DPA
#177This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…
How does this apply to Clearbit which saves the Google Contact list of everyone who installs their extension [0][1] and then sells this data [2] ? They have >150K extension users, so they are syncing a massive contact list with personal information that they are then selling via their different products like Prospector [3]. [0] https://connect.clearbit.com [1] https://chrome.google.com/webstore/detail/clearbit-connec…
Would you have any proof or evidence supporting that statement?
Re: How to effectively evade the GDPR and the reach of the DPA
#178I had a very similar experience with Apollo.io. Somehow my professional data (business email, personal phone number, name, job title and my LinkedIn network and connections) ended up on this website without my consent. I’m assuming it was collected from several sources such as LinkedIn (Even though I had my privacy settings tight) and some conferences I attended in the past year. Either way I contacted them and they…
Re: How to effectively evade the GDPR and the reach of the DPA
#179Earlier quoted context omitted.
One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.
Has the EU actually shown any teeth to these outfits? It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.
Re: How to effectively evade the GDPR and the reach of the DPA
#180I don't know if there's another good example, but Poland fined an EU company under the GDPR for scraping profile data without giving proper notification: https://news.ycombinator.com/item?id=19530087 You shouldn't have to guess where your personal data is going, and how it's being used. When the GDPR was first coming into force, I remember getting bombarded with all these notification emails from all these companies…
Note that this is the totally normal approach for Civil Law systems: you define the general principles of what the menace is, and leave it down to the courts to determine whether or not those principles have been violated. In essence, you can view it as every case being decided on the basis of the mischief rule as exists in many Common Law systems.