Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

191–200 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#191

Earlier quoted context omitted.

I'll be honest - based entirely on your description of events, with no other context, I wouldn't have approved this request either. Here's my reasoning: > They then asked me to provide my address to confirm my identity...I wasn't keen on it. This means one of the primary avenues of verification (possibly the only avenue for some shops) is unavailable. In the scope of GDPR, it's important to remember that they aren't…

I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database. If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact…

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision.

> I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.

As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.

You can prove that you have access to that email, but you still need to prove that you're you.

> If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity

This brings up the same problems as before: what if the number has been recycled? What if the letter is intercepted by someone living at an old address? Then they've given up the store again. Just because someone else is doing it doesn't mean it's a good idea.

> I hope you see the huge imbalance here.

I do, but you also need to look at it from the other side of the screen. As much as you have a legal interest in accessing your own data, they have a legal interest in ensuring that you are actually the one accessing it.

What you've run into here is one of the other...accidental features of GDPR: it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.

Re: How to effectively evade the GDPR and the reach of the DPA

#192
post #184

Earlier quoted context omitted.

While accessing any user personal details you need to have user consent to process their personal data. Consent is only one of the lawful bases for processing data under the GDPR. In practice, it's the one almost everyone tries not to rely on unless they can't avoid it, because it comes with extra obligations that other bases might not.

Could you list the others? Or at least provide some examples? Basically all I know are based on either mandatory by law record keeping, or records used to fulfill whatever service/product/goods the user purchased, but even in these cases the processing must be described, right?

The GDPR itself is actually quite readable, so if you're interested in the details, you can got to the source. There's a neatly formatted version hosted here:

https://gdpr-info.eu/art-6-gdpr/

What the source material won't tell you, for better or worse, is how these are interpreted in reality by data controller, processors and regulators. The two main things to know in that respect are:

1. Relying on the subject's consent is usually the last resort. It comes with lots of extra strings attached.

2. The "legitimate interests" provision is open to interpretation. It is widely used as an excuse for processing that many of us might consider far from desirable. But it is also a risk for data processors doing things many of us might consider reasonable, because any regulator can take a different view and they get to win by default.

Re: How to effectively evade the GDPR and the reach of the DPA

#193

Earlier quoted context omitted.

I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database. If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact…

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision. > I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure the…

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.

That seems a rather optimistic assumption, given the historical way data brokers and those who use them have operated. Plenty of businesses, including some household names, have been caught with their hands in the cookie jar on this one before. No doubt plenty are still doing it and hoping not to get caught or that any penalties will be small enough to be worth it.

As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.

There are few ways to know anything with true certainty unless someone in your organisation personally knows someone you're dealing with. It is more about being reasonable.

If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights, the GDPR-esque solution to the problem is to shut that processing down entirely until the organisation can get its house in order, or permanently if it can't find a way to do that. If that kills the data broker's business model, maybe they shouldn't have been using that business model in the first place, or should have discontinued it when the GDPR came into effect.

Allowing the organisation to deny data subjects their legal rights by hiding behind the verification obligation is at best against the spirit of the law but probably against its letter as well, and certainly justifies a regulatory investigation if it's being done systematically by a big organisation that should know better.

Re: How to effectively evade the GDPR and the reach of the DPA

#194

Earlier quoted context omitted.

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision. > I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure the…

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. That seems a rather optimistic assumption, given the historical way data brokers and those who use them have operated. Plenty of businesses, including some household names, have been caught with their hands in the cookie jar on this one before.…

> That seems a rather optimistic assumption

I'm just basing this on my experience working on products in this space and specifically dealing with compliance and "retroactive" consent in the run-up to GDPR implementation. I could definitely be wrong.

> If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights...

I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?

Re: How to effectively evade the GDPR and the reach of the DPA

#195
post #161

Earlier quoted context omitted.

...yet since it's unenforceable, then they probably don't care.

Why not? If they have offices in EU, raid them. If they have customers in the EU, freeze their bank accounts or sanction their payment processors.

> If they have offices in EU, raid them.

They won't - that's what relocation means.

> If they have customers in the EU, freeze their bank accounts or sanction their payment processors.

This is comical. The government isn't going to start shutting bank accounts for GDPR violations on small foreign corporations, as if they're smuggling nuclear fuel to Iran. Half the bank accounts in the world would be closed if we were so sensitive to regulations.

Re: How to effectively evade the GDPR and the reach of the DPA

#196

Earlier quoted context omitted.

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. That seems a rather optimistic assumption, given the historical way data brokers and those who use them have operated. Plenty of businesses, including some household names, have been caught with their hands in the cookie jar on this one before.…

> That seems a rather optimistic assumption I'm just basing this on my experience working on products in this space and specifically dealing with compliance and "retroactive" consent in the run-up to GDPR implementation. I could definitely be wrong. > If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subje…

I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?

There obviously needs to be something confirmed to verify the identity, but by definition personal data is data about an identifiable subject, so there must be something that can be checked.

If a big data hoarder has personal contact details, attempting to reach someone using those in response to a subject request isn't unreasonable. The hoarder will also have obligations under the GDPR regarding keeping data correct and up-to-date, so they should be in a position to do this in most cases or they're probably in violation already.

Some contact details might be checkable against an external reference to confirm they really are still up-to-date before relying on them, in which case a single attempt using that method might be sufficient.

Otherwise, if you can reach someone via two different and reasonably secure methods associated with their profile then it's probably reasonable to assume they are who they say they are.

If the hoarder doesn't have contact details they can use, then apparently there is some other identifying characteristic of the data subjects that makes it personal data, and in that case presumably you'd have to look at that and see how it could be used for verification.

Re: How to effectively evade the GDPR and the reach of the DPA

#197

Earlier quoted context omitted.

I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database. If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact…

I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision. > I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure the…

> I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.

Well, I definitely didn't. Even if I did give consent for processing my data, sharing with Facebook isn't something I would ever in a million years agree to. An explicit consent should have been specific about it. Evidently Acxiom shared my details with Facebook. But let's leave it aside for now.

> You can prove that you have access to that email, but you still need to prove that you're you.

That's where the huge imbalance lies, isn't it? They link my email, along other details, and they also share my email with Facebook. Yet, when I'm contacting them, from the same email address, then suddenly it's not enough.

But let's say one piece of info isn't enough, they have other pieces? let's match them. Send me a letter, give me a phone call, give me the postal code and ask me to complete the address (or other parts of the address), provide a reasonable way for me to prove my identity. Without effectively asking for my entire address history, or compromising even more data about myself.

> it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.

We completely agree on this one. They're as strict as possible when subjects try to exercise their rights, but loose as a cannon when it comes to sharing data, making sure they get real and explicit consent etc.

Re: How to effectively evade the GDPR and the reach of the DPA

#198
post #98

Earlier quoted context omitted.

I dont know. From what I can understand of German/Google translate, the third from top: https://www.enforcementtracker.com/ Link to .pdf: https://www.ris.bka.gv.at/Dokumente/Dsk/DSBT_20180927_DSB_D5... Is the Austrian Authorities making a 300 Euro fine to a "common citizen" making "illegal" use of a dashcam (it seems - but I am not sure about it - that the issue is that the car is not - how? - visibly marked as video…

Why would you pick that example, rather than the 16 million fine an Italian company received?

As a counter example to the "success" you mentioned.

Again if I got it right a "common user" got stinged because of a dashcam.

The Italian example you refer to is actually a success, like most other ones, I was objecting not to the Law in itself (that is IMHO a good one) but rather on how it is applied, here and there, in spots and seemingly in a random way.

Re: How to effectively evade the GDPR and the reach of the DPA

#199

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

> If there's a sufficient need, Polish banks could establish an interbank settlement system through which they could transfer USD directly (e.g. similar to the one they have for transfering Polish zloty), but it's a hassle and has costs, so currently they have not done so because for them it's generally not a problem to route all USD payments through USA.

Doesn't it still need to be involved with USA? I mean, sure, they can use this settlement system to trade between each other independent of Fed, but ultimately the funds in the settlement system have to be stored as reserves in Fed, i.e. in some bank under US jurisdiction. So, after all, US still has control over this new settlement system, but now they can't freeze individual accounts in it, they can only freeze funds in reserve account(s) that this system consist of, potentially affecting many (innocent) parties. Am I right?

Re: How to effectively evade the GDPR and the reach of the DPA

#200

Earlier quoted context omitted.

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

Euro dollars are constantly traded without going through the US. CLS currencies and any currency which is fully convertible can be used in transactions without any involvement of the jurisdiction that minted the currency in the first place. The USD has a huge settlement infrastructure that is completely independent of the US.

Doesn't it still involve accounts in US banks though? Please see my direct reply PeterisP for explanation. I cannot see how could it work without Fed oversight as it would allow it to "print" dollars.

Also, could you please share more info? I'm very interested in financial settlement system, especially for USD and EUR, but sadly there's too little public resources.

Post reply on HN