Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

171–180 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#172
post #132

Earlier quoted context omitted.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

> Could be simple negligence on Uber's part. The didn't slip, fall, and drop some USB flash drives into the hands of a US data processor... I doubt it is any sort of negligence, but if it is - it's not "simple".

Indeed. It’s about as plausible as the ‘I tripped and fell’ excuse for cheating.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#173

Earlier quoted context omitted.

Uber’s right to do what ever the f they want stops at my right to control information pertaining to me. What’s freedom? GPL? BSD? Swinging a fist? Not getting hit on the nose?

Freedom to some means creating a startup that willfully ignores regulations in virtually every market while playing a funding ponzi game until finally handing the consequences off to the foolish public (IPO).

We don't say "Ponzi scheme" here, we say "disrupting traditional markets" and "investment opportunity"

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#174
post #127

Does anyone know good best practices and software/DB patterns to model localized GDPR-compliance into global software systems? I know ASP.NET Core comes with some GDPR-related helpers but it's more interesting to know general best practices and patterns not related to a specific framework.

First off, just presume GDPR applies globally. Then, know your legal 'zones' and by default keep all data in those containers. Thirdly, if you need to send data from one zone to another, ask "Do I really need to?? really???" and only if the answer is 'yes' do you do a proper design and engage legal and security from the beginning of the project through to the end and on an ongoing basis.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#175

Earlier quoted context omitted.

It's pretty much part of your normal data management that you'd be doing anyway, except it now has an additional lifetime (on top of any you might have had). Since when ingesting the data you knew where it came from and on what timestamp, you also know when to next check for deletion. And since you also know where it came from (the owner), deleting/sending it on request (when applicable - not all data is always requi…

> You only keep what you need for the time that you need it Just to add that it's stricter than that - you can only keep the data that is required for the purpose that you detailed to the customer. e.g. If you ask for their email address for password validation, then you're not allowed to use that email for other communication unless you explicitly asked for that as well.

I completely agree, GDPR is definitely a more detailed ruleset than what I outlined, but from a data management superset perspective you would have the mechanisms and facilities to deal with the GDPR-specific rules anyway.

I've found that this is mostly a problem in organisations where data isn't managed, the government doesn't protect the people, or where some vague value is assigned to the data (so it does get stored, but when it leaks it is supposed to not have value and therefore do no damage). So looking at it from an "you will be managing it anyway" angle has worked well for me when trying to activate teams/units/orgs.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#176
post #132

> The Dutch DPA started the investigation on Uber after more than 170 French drivers complained to the French human rights interest group the Ligue des droits de l’Homme (LDH), which subsequently submitted a complaint to the French DPA. I wonder on what the initial suspicion from the drivers was based.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

Uber is very aggressive with notification span

Even worse when you move between countries and suddenly "Uber Country X" uses your account of "Country Y" to spam notify you about promotions in X. It's weird in a bad way

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#177
post #116

Earlier quoted context omitted.

> With the edits to your post, its nature became more and more apologetic to dictatorships. What are you talking about?(!)

It looked more and more like you wanted to say that morals are not an "all or nothing" thing from where it is easy to leap to being apologetic to just a little bit of (systematic) wrongdoing. But judging from your reaction, this is not what you were trying to set up.

Not at all. The main thread of my comment(s) was that moral value judgments are extremely prevalent. In fact nothing actually happens in society without someone making a value judgment. And most of the time nothing particularly crazy happens.

It’s easy to point to some barbaric act and say “see, this is what morally motivated policies result in”.

But in reality, moral value judgments are all around us in the most mundane of places. It’s moral value judgments that cause us to have anti-monopoly laws. It’s moral value judgments that cause us to configure tax codes one way or another. It’s moral value judgments that cause us to appreciate the things that capitalism gives us. Etc etc. You can’t escape it.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#178

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

The people advocating for more privacy in the EU and pushing legislation like GDPR aren’t necessarily the same people who want to weaken encryption. Lots of things going on in the EU at the same time.

I agree though that it can be hard for a US company to comply with GDPR as every country seems to interpret it slightly differently. The same difficulty is coming on the AI legislation side.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#179

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

>This is all wildly ironic because the EU is constantly trying to spy on their own citizens

I am assuming you refer to a law proposal that was rejected, but did you know americans were sponsoring and pushing that law proposal to spy on chats? Yeah same CP people.

Also there is a GIANT difference for a country to "spy" on their own citizens and USA spying on foreigners , a country has a consitution and lwas that protect the citizens freedom where USA has no laws that protect foreigners freedom so the NSA guys could watch an EU citizens photos, read their emails since they are not from USA they are lesser humans.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#180
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

Well technically data transfer according to GDPR has nothing to do with where the data is geographically. It’s what legal jurisdiction the controller or processor is under that matters. If you move data to a processor under another jurisdiction that is a transfer.
Post reply on HN