Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

181–190 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#181
post #173

Earlier quoted context omitted.

We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…

Sounds like that company was as shady as rocketreach... someone who threatens their own customer in bad faith (or negligence) just for 30k is likely to be more trouble and of less value to you in the future if that's their focus of increasing revenue. Good call ditching them. [edit] speculative aside... What if they were intentionally feeding rocketreech miss-information? it might seem far fetched but these personal…

> someone who threatens their own customer in bad faith (or negligence) just for 30k is likely to be more trouble and of less value to you in the future if that's their focus of increasing revenue.

Yes, that was really strange. We though they might need quick money, as this was right at the beginning of the corona crisis. Still, not acceptable.

> What if they were intentionally feeding rocketreech miss-information?

That's possible but quite strange. This information is public in our country, so there is a known reliable source and they should've known better.

> Obviously there was no way I would pay them but it was extremely difficult to convince them to stop harassing me for this money even though they had no proof.

Yes, this is quite usual. We were seriously lucky we discovered the change; but, given that they backed up so quick after calling it a fraud, I'm seriously assuming it was.

Re: How to effectively evade the GDPR and the reach of the DPA

#182

Earlier quoted context omitted.

We used a product from a company (I'd prefer not to name them) and received an official letter from them that on of our customers had more than 10 million in revenue, which in turn would require us to buy a larger plan from them[0]. They cited the companies (inofficial) RocketReach page as a source and demanded 30k USD (iirc). They only retracted the thread after we could prove (via Google Cache and archive.org) that…

Thanks for explaining. (How surprised I would have felt, when first getting contacted about sth like that and a lawsuit)

Yes, we were shocked, too. Luckily one of us is a bit experienced in law and directly dug into this while keeping his cool. I saw our doors closing already, to be honest.

Re: How to effectively evade the GDPR and the reach of the DPA

#183
I've always wondered about the practical side of how GDPR is supposed to work for companies outside the EU.

If you've got actual stuff in the EU, it's easy. You get fined under GDPR and if you never show up to argue your side in court or an administrative hearing or whatever, they seize your real estate or bank accounts or physical servers or whatever, and sell it to pay your fines.

If you're US-based, how does it work? Hmm, if you're a modern shop you probably have stuff hosted by big companies, like servers on Amazon's AWS or code on Microsoft's Github. Then the EU could presumably tell those companies to stop hosting your stuff, or they'll become liable for fines as an accessory to the violation. Microsoft and Amazon probably have a lot of bank accounts and physical stuff in the EU that could be seized and sold, so they couldn't simply ignore the fine. They'll probably drop you as a customer immediately once Europe starts making them pay fines, and maybe try to sue you in the US court system to try to recover those costs.

I've never heard of this happening though. So maybe this isn't actually a thing.

If all your stuff is on US soil, and you're careful not to use providers with any European presence, how would they do it? Does the EU have some way to order all European ISP's to blackhole traffic from your company's IP ranges? When your executives come to Europe for vacation or conferences or whatever, could they get hauled off the plane in handcuffs and taken to a European jail over your company's GDPR violations?

Again, I haven't heard of this actually happening. But it seems to me that would be how they'd do it, if they really wanted to prevent overseas companies from simply ignoring GDPR.

If there's no threat of enforcement, why bother with GDPR at all, unless you're planning on having seizable stuff like real estate or bank accounts or physical servers in Europe someday?

Re: How to effectively evade the GDPR and the reach of the DPA

#184
post #46

Earlier quoted context omitted.

It is enforced and viral in EU. Think of it like radioactive materials, any operation needs to be fully tracked. While accessing any user personal details you need to have user consent to process their personal data. You can't simply buy the dataset and assume it has consent. When you buy data from data provider you need to make sure user gave consent to handle data by third-parties to that provider in accordance to…

While accessing any user personal details you need to have user consent to process their personal data. Consent is only one of the lawful bases for processing data under the GDPR. In practice, it's the one almost everyone tries not to rely on unless they can't avoid it, because it comes with extra obligations that other bases might not.

Could you list the others? Or at least provide some examples?

Basically all I know are based on either mandatory by law record keeping, or records used to fulfill whatever service/product/goods the user purchased, but even in these cases the processing must be described, right?

Re: How to effectively evade the GDPR and the reach of the DPA

#185

Earlier quoted context omitted.

I mean, sure, but OP indicated that he didn't want to provide the info they requested for verification. I don't see how their action here could be considered unreasonable. "I promise you that I am the only person on earth with this name" doesn't really seem like a sufficiently secure attestation.

OP here. My name is unique globally (there are no other people with this name), easily searchable, linked to my personal domain, and my personal email address on that domain. But even if we can't go by that, I gave them plenty of options that won't involve me disclosing my entire address history. How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my…

I'll be honest - based entirely on your description of events, with no other context, I wouldn't have approved this request either. Here's my reasoning:

> They then asked me to provide my address to confirm my identity...I wasn't keen on it.

This means one of the primary avenues of verification (possibly the only avenue for some shops) is unavailable. In the scope of GDPR, it's important to remember that they aren't allowed to retain any information you provide for this purpose for any reason other than keeping a record of the request.

> I mentioned that my full name is globally unique, but they refused.

I would have absolutely no way to validate this, because I don't have a comprehensive listing of all 7 billion-odd people in the world. Even if I did, and it was, it's still only a single factor - I doubt you'd want me to release your data to anyone else based only on them knowing your name and that it's unique.

> My name is...easily searchable, linked to my personal domain, and my personal email address on that domain

This can't be relied on, obviously, because there's no identity verification on (most) domain registrations. For all I know, the email address that I have attached to your profile isn't even yours (because we have no preexisting relationship, this has never been proven.)

> I tried to ask them to share some masked data that I can confirm in full...They refused.

I don't think this is actually allowed under GDPR, but assume it is. Let's say you do this twice with two different data controllers - they each provide you with a masked address, but they've masked different parts (because there's no standard).

If you were a malicious actor, you'd now have the subject's complete address and could use that to gain access to the rest of their data. It opens up a significant attack vector.

> How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...

Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.

> I think I was very reasonable, and they weren't.

At the end of the day, you're going to have to give them something to prove who you are. If you won't even provide your old addresses, then absent a government-issued ID (which I assume you also would be reticent to provide on the same grounds) I don't know how else I would even attempt to conduct verification.

Re: How to effectively evade the GDPR and the reach of the DPA

#186

Earlier quoted context omitted.

Ok but he didn't subscribe on that website.

OP here - That's the point. They are not a data controller by that very simple fact. They are processing this data on an illegal basis. Any lawyer around that want to assist me suing in the US?

Did you reach La Quadrature Du Net ?

https://www.laquadrature.net/

Also check other CCC co-organizers & the political activist sphere.

Re: How to effectively evade the GDPR and the reach of the DPA

#187
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

Maybe post the CEO’s email here so we can all get our data removed as well?

tim

Re: How to effectively evade the GDPR and the reach of the DPA

#188
post #134

Earlier quoted context omitted.

Has the EU actually shown any teeth to these outfits? It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.

Note that in principle it's not up to the EU to enforce because the GPDR is a directive; it's up to the individual member states to enforce the directive as enshrined in their law.

GDPR isn't a directive, it's a regulation. It's literally what the R stands for.

The major difference between the two in terms of how the EU makes laws is that directives are the indirect one: individual member states are required to incorporate the provisions into their own legal systems to give them force of law. An EU regulation is the direct equivalent: it carries force of law across all member states immediately. In the case of the GDPR, the UK government has also stated that its provisions will continue here after Brexit and the related transition arrangements.

However, you're right that enforcement will normally be done by an individual member state, because it is typically the national data protection or privacy authority in each state that acts as regulator and has enforcement powers under the GDPR. In theory, there's supposed to be some coordination so one of those regulators will take the lead on any given investigation or enforcement action instead of 28 different organisations all diving in at once, but it doesn't seem to be clear yet how that aspect will work post-Brexit.

Re: How to effectively evade the GDPR and the reach of the DPA

#189

Earlier quoted context omitted.

OP here. My name is unique globally (there are no other people with this name), easily searchable, linked to my personal domain, and my personal email address on that domain. But even if we can't go by that, I gave them plenty of options that won't involve me disclosing my entire address history. How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my…

I'll be honest - based entirely on your description of events, with no other context, I wouldn't have approved this request either. Here's my reasoning: > They then asked me to provide my address to confirm my identity...I wasn't keen on it. This means one of the primary avenues of verification (possibly the only avenue for some shops) is unavailable. In the scope of GDPR, it's important to remember that they aren't…

I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.

If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact is, they didn't suggest any reasonable alternative.

> Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.

The fact that they're big is irrelevant. They already shared my data without my explicit consent. They're a company I never ever signed-up for, interacted with in any way, yet they hold data on me. They share it and make profit out of it. I'm definitely not keen on sharing any additional info with a company that aggregates my data as their core business.

I hope you see the huge imbalance here. To get my data I need to jump through hoops and expose even more data about myself (to a data broker which makes money off of it). To sell, aggregate, share and abuse my data without my consent and very likely in violation of GDPR requires no validation that indeed the data belongs to me, nor even an attempt to contact me and ask for consent.

Re: How to effectively evade the GDPR and the reach of the DPA

#190

Is crunchbase/owler/cb insights and every other public data aggregator/lead generator service also illegal by the same logic?

define illegal. and no, those aggregators don't process PII / Personal Data.

They typically have a person's different social media account links and work history. Isn't that personal data?
Post reply on HN