Funny they are being fined in the Netherlands, because Uber is almost invisible there, as regular taxis have been protected. I don't have accurate data, but it's at least 15€ per inhabitant, so it seems like a very very steep fine. I can't imagine how much this is per driver, €25000? It seems the dutch regulator is saying "why don't you just go away?". The feeling is likely mutual.
> a very steep fine > > The appeals process is expected to take some four years and any fines are suspended until all legal recourses have been exhausted, according to the DPA. fine is suspended. it will take 4 years of appeals :)
Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
221–230 of 414 posts
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#222Earlier quoted context omitted.
The sooner the better. This way local EU players can fill the void they'll leave. This insular isolation also fueled China's domestic SW sector.
this take is naive. building alternatives takes time and resources. the EU has neither. a diverse, competitive tech ecosystem with both EU and non-EU players is better than a protectionist approach. hoping for an exodus of major global players when you’re leapfrogged by both China and the US…
Oh no. What would we poor Europeans do without a US company to lead us. /s
Of course local and regional players would appear, as they always have and are already in place in multiple segments.
Bolt, Glovo, Delivery Hero and many others are successful competitors to different Uber offerings in the different European markets they operate.
The biggest gap in Europe is not due to a lack of technical ability but rather of European wide capital that's not super risk averse.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#223I guess this is always going to raise some eyebrows, with this amount of money it's hard to say it's not political. However I would like to say that the Dutch privacy authority actually seems pretty sincere at enforcing privacy legislation. It's just that until recently they were just sending angry letters, and now they've been given power to do more than empty threats.
For abusing its dominant position, the post has only 2 points [0].
Yet, this one has significantly more comments.
The only political aspect is where the company comes from.
Forum members then want to speak up.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#224Earlier quoted context omitted.
The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though…
> The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework To bad the EC isn't the body that can judge whether that deal is legal, and has been caught repeatedly lying about past deals [1]. > So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? As before, cases will go to the actual authority on the matter: the CJUE. I personally don…
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#225Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.
Well technically data transfer according to GDPR has nothing to do with where the data is geographically. It’s what legal jurisdiction the controller or processor is under that matters. If you move data to a processor under another jurisdiction that is a transfer.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#226I think this substack is good, it makes a pretty clear case that US tech companies may not leave Europe any time soon, but they wield the power in the relationship much more so than the Europeans. Those regulators are overplaying their hands.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#227Which big tech company will be the first to stop doing business in Europe? It's going to happen sooner or later.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#228Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.
Instances like this really make me feel that capitalism is devoid of any morality. If there's no law guarding it, a company will abuse its power in order to make more money. It could be a morally good thing, a morally bad thing, it doesn't matter: more money is more money. It feels heartless. I wish there was a better system.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#229This puts the total fines from the EU on American tech businesses at $14.8B in the last few years: https://loeber.substack.com/p/20-no-more-eu-fines-for-big-te... I think this substack is good, it makes a pretty clear case that US tech companies may not leave Europe any time soon, but they wield the power in the relationship much more so than the Europeans. Those regulators are overplaying their hands.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#230Earlier quoted context omitted.
> The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework To bad the EC isn't the body that can judge whether that deal is legal, and has been caught repeatedly lying about past deals [1]. > So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? As before, cases will go to the actual authority on the matter: the CJUE. I personally don…
I tend to agree with you about what will happen, but it illustrates the depth of legal uncertainty that exists in architecting software systems in Europe that process personal information. Corporations can't necessarily trust the EC's own published interpretations of their own laws, nor the certification processes the EC has created, so the only risk-minimizing route is a maximally pessimistic approach about what is…
Oh I agree with that. EC's behaviour in that case is appalling.
> Corporations can't necessarily trust the EC's own interpretations of their own laws
There is a way to be safe with regards to EU law, and it's to engineer systems where European data stays in Europe. Of course, the issue is that corporations would then be liable under US' FISA 702.
That's the big issue: the United States made a law that basically states that no US company should follow EU law, and the US admin manages to beat EC officials into submission every few years with another flawed agreement to keep the ball rolling.