Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

171–180 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#171

Earlier quoted context omitted.

Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter? As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.

Yes, absolutely. Yet the likelihood of Acxiom being fined anything other than some token amount in a case like mine is virtually zero.

It feels like that, but I wonder how long it will be before one of the regulators decides to make an example of one of the big data-hoarding companies. Their whole business model is morally and now also legally dubious, and it's so obviously against the spirit of the GDPR that it seems like a matter of time before someone decides to pick a fight. I doubt it will be a single case like yours that starts it, unless perhaps it provides a convenient excuse to start an investigation, but it will be a thousand or a million situations like yours that motivate it.

Re: How to effectively evade the GDPR and the reach of the DPA

#172
> Instead of pursuing Rocketreach locally on that basis alone, the CNPD just gives up arguing it has no jurisdiction in the US.

Which is true and obvious. Why anybody ever thought the GDPR would have teeth outside the EU is beyond me. It was always laughable to me that anybody believed that the EU had made a law that applied to every company in every country in the world.

Re: How to effectively evade the GDPR and the reach of the DPA

#173

Earlier quoted context omitted.

> threatened with a lawsuit I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?

We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…

Sounds like that company was as shady as rocketreach... someone who threatens their own customer in bad faith (or negligence) just for 30k is likely to be more trouble and of less value to you in the future if that's their focus of increasing revenue.

Good call ditching them.

[edit] speculative aside...

What if they were intentionally feeding rocketreech miss-information? it might seem far fetched but these personal data collecting companies like rocketreach or even equifax obtain their information from a variety of untrustworthy sources.

I was a victim of this through my own foolishness a couple years ago:

I was using a car insurance comparison site and guessed one piece of the required information I couldn't completely remember - a speeding ticket date - I couldn't remember the exact year. Turns out I entered it exactly one year off, and it was so long ago anyway that it had no bearing on the quotes.

After continuing with my existing insurer, a few months later my insurer sent me a demand for a rather large quantity of money... that's right, they attempted to backcharge me for 5 years worth of insurance over an extra speeding ticket they had "discovered". Obviously there was no way I would pay them but it was extremely difficult to convince them to stop harassing me for this money even though they had no proof. Even after demanding they provide evidence of their discovery which they refused.

It's scary how easy this is to do, and I wasn't even trying.

Re: How to effectively evade the GDPR and the reach of the DPA

#174

Earlier quoted context omitted.

> threatened with a lawsuit I don't understand, who threatened you with a lawsuit? Why did they care about RocketReach?

We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…

Thanks for explaining. (How surprised I would have felt, when first getting contacted about sth like that and a lawsuit)

Re: How to effectively evade the GDPR and the reach of the DPA

#175

Earlier quoted context omitted.

> The ideals of the Internet are free exchange of ideas and information, no country-specific walled gardens > If that were the case, I’d block EU access for any of my domains These two statements are at odds with each other ...

Yes, that’s my point. It’d be a tragedy.

It seems like you're trying to absolve yourself of responsibility by using a passive voice, similar to this recent trend of abusing the 451 status code. You would be the one choosing to block the EU and further balkanize the Internet.

Re: How to effectively evade the GDPR and the reach of the DPA

#176
post #123

Earlier quoted context omitted.

If the companies don't have assets in the EU that can be affected by EU prosecution, then the GDPR is not enforceable. It might be possible to prosecute and trial management, but again this has only consequences if they enter EU jurisdiction or if they are extradited. Such issues and questions always arise with laws whose reach is extraterritorial. Keep in mind that the US has a fair number of these laws as well.

deny entry or arrest executives of the company if they try to enter the EU. Surely some of these people travel...

Yes, that would work. It's what the US does after all. I'm not optimistic though thah the EU is capable and mature enough to handle the ensuing diplomatic heat. At least not yet.

Re: How to effectively evade the GDPR and the reach of the DPA

#177
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

How does this apply to Clearbit which saves the Google Contact list of everyone who installs their extension [0][1] and then sells this data [2] ? They have >150K extension users, so they are syncing a massive contact list with personal information that they are then selling via their different products like Prospector [3]. [0] https://connect.clearbit.com [1] https://chrome.google.com/webstore/detail/clearbit-connec…

Couldn't find anything on those links or Google about them scraping your contact list.

Would you have any proof or evidence supporting that statement?

Re: How to effectively evade the GDPR and the reach of the DPA

#178

I had a very similar experience with Apollo.io. Somehow my professional data (business email, personal phone number, name, job title and my LinkedIn network and connections) ended up on this website without my consent. I’m assuming it was collected from several sources such as LinkedIn (Even though I had my privacy settings tight) and some conferences I attended in the past year. Either way I contacted them and they…

Vote for a better government that cares about its citizens digital rights?

Re: How to effectively evade the GDPR and the reach of the DPA

#179
post #134

Earlier quoted context omitted.

One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.

Has the EU actually shown any teeth to these outfits? It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.

Note that in principle it's not up to the EU to enforce because the GPDR is a directive; it's up to the individual member states to enforce the directive as enshrined in their law.

Re: How to effectively evade the GDPR and the reach of the DPA

#180

I don't know if there's another good example, but Poland fined an EU company under the GDPR for scraping profile data without giving proper notification: https://news.ycombinator.com/item?id=19530087 You shouldn't have to guess where your personal data is going, and how it's being used. When the GDPR was first coming into force, I remember getting bombarded with all these notification emails from all these companies…

> The biggest flaw of the GDPR in my opinion is that it leaves the definition of what's considered personal identifying information with too much wiggle-room for creative interpretation.

Note that this is the totally normal approach for Civil Law systems: you define the general principles of what the menace is, and leave it down to the courts to determine whether or not those principles have been violated. In essence, you can view it as every case being decided on the basis of the mischief rule as exists in many Common Law systems.

Post reply on HN