Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

21–30 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#23
Data sharing seems so prevalent, and I would dare say even with EU companies, the chances of getting caught (let alone fined) by the GDPR are pretty slim.

An interesting exercise: If you have a Facebook account, go to this page[0] or this one[1] and see if you even recognize some of the companies that shared data about you. Not to mention gave explicit consent to sharing your data ...

My list includes companies I never gave consent to (e.g. Amazon, Uber), never signed up for or gave any details to (e.g. Robinhood, Triplebyte) and some I have zero clue about, but the name alone sounds dodgy (Opteo, Mindshare Biddable Digital ...).

[0] https://www.facebook.com/ads/preferences/?entry_product=info...

[1] https://www.facebook.com/off_facebook_activity/activity_list

Re: How to effectively evade the GDPR and the reach of the DPA

#24

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

> trading in USD requires the transaction to route via the US

Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

Re: How to effectively evade the GDPR and the reach of the DPA

#25

Looks like rocketreach is aggregating information that is public on fb,linkedin etc. He forgot to mention that the google search result he got is already selling those, but maybe we ve become blind to that? Rocketreach is packaging and selling it directly, google does it indirectly. Same thing though, are those illegal?

This information can also obtained from the chamber of commerce in the netherlands

Re: How to effectively evade the GDPR and the reach of the DPA

#26
post #16

Earlier quoted context omitted.

Yes it does apply. https://www.hipaajournal.com/american-companies-gdpr/

Your link is in reference to multi national companies. I don’t see how GDPR applies to companies that don’t do business with EU persons and without an EU presence.

They are selling into the EU though, right? So they do do business with EU persons.

Re: How to effectively evade the GDPR and the reach of the DPA

#27

Now watch the entire currently-EU based adtech industry relocate out of the EU...

Ultimately, adtech has to broker between publishers and advertisers. If those have any business in EU, they will be liable for the data, even if the broker is outside of jurisdiction.

Re: How to effectively evade the GDPR and the reach of the DPA

#29
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

A lot of the work that is done to become and stay compliant with the GDPR is invisible from the outside, but I can assure you that most large companies and a lot of the smaller ones are taking it serious.

The GDPR also has a "pull-in" effect on companies outside the EU that (often illegally) sell personal data because their clients in the EU (the data controllers) have to prove that these companies (their data processors) adhere to the GDPR if they want to do business with them. If a EU company buys personal data from a company outside the EU or sends personal data to that company they are liable if this data gets abused or if the personal data was not acquired in accordance with the GDPR. The whole "privacy shield" mess was about the question whether EU companies can still send personal to the US based on a self-certification process US companies go through (turns out they can't).

Some of the data brokers already feel this pressure and will be forced to change their business models unless they want to lose their clients within the EU. Sure there are still EU companies that do business with these data brokers today, but most of them know that they're exposing themselves to considerable risk and are already looking for alternatives.

Re: How to effectively evade the GDPR and the reach of the DPA

#30
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

>EVERYBODY is cheating.

All the big European companies I've worked for seemed to put lots of effort into complying.

Post reply on HN