Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

261–270 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#261

Earlier quoted context omitted.

Personal experience of mine and within circle of my acquaintances. Most of the times there is some "GDPR form" you have to sing to receive any service. The blood test results leak from time to time as well. We might be living in different Polands though.

So, it’s anecdotal to your circle. Maybe you're just using some shady providers? Because that’s not my experience or the experience of those in my circle. You should be more careful when buying stuff online; this is where these things happen, not in doctors' offices.

Nope, it's the healthcare service providers. What do you mean by "shady" how do I recognize them? The blood test lab where local legit doctor sends blood is shady?

> careful when buying stuff online

I know what I'm doing online. You sound like communication from most of retail banks.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#262
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

It shouldn't be a problem for Europeans to access/process U.S. data that belongs to U.S. citizens - GDPR doesn't cover that AFAIK, so it's fine for it to cross borders. The issue is with GDPR protected data of EU citizens, as the law does not permit that data to cross non-EU borders unless it's for specific exemptions such as law enforcement.

Or, IIRC, if the destination country has privacy protections that are at least as strict as those in the EU, which the US legal regime for foreign intelligence definitely doesn’t provide (a non-US-citizen wouldn’t even have standing to sue wrt their personal data).

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#263
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

I'm not going to address your comment at the object level; I'm just going to point out that you've missed the point of my comment entirely. My comment is descriptive (the internet is going to become nationally siloed) not normative (a moral judgement on the conditions that are leading to this state of affairs).

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#264

[flagged]

Silly question, the EU simply has stricter privacy and data protection laws. As these came into effect relatively recently, a lot of these companies are trying to see what they can get away with. Or at the very least taking a calculated risk that the regulation authorities are not going after them. So the only way to actually get them to respect these laws is by attaching actual tangible consequences to breaking them…

I know EU has stronger data privacy laws. I just wonder if they're really all that upset about American companies breaking them. They get to use the new tech and fine the companies that bring that tech to them. It's a win-win.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#265

[flagged]

Alternative question: has breaking European laws become a major American industry?

If it is then Europe doesn't seem too upset about it. How could they be when it pays them so well?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#266
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

> Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously becoming inviable Why exactly would physical products have to comply with local laws when exported to other countries and not online services? Do you also call it "fiefdom wanting their cut and their say"? Do you disagree with the concept of laws altogether?

The thing that made a global internet possible is that it was understood that sending bits over a wire is different from shipping physical goods. The customs regime for physical goods is prohibitively expensive for bits.

I'm not interested in arguing if eliminating free transit of data is a good idea or not; I'm just pointing out the inevitable consequence of the current trends.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#267
post #170

Earlier quoted context omitted.

The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though…

> The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent. If i'm not mistaken, because of this (via[0]) > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or…

> catch some US criminal

https://en.wikipedia.org/wiki/CIA_black_sites

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#268

[flagged]

It's much harder to fine companies that break the law if they make up a substantial part of your economy. On the other hand, big US companies don't have as much lobby power in the EU, so the EU is "free" to fine them.

It's my impression that big US companies can do pretty much whatever they want in a number of European countries. Just look at Ireland for example.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#269
post #170

Earlier quoted context omitted.

The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though…

> The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent. If i'm not mistaken, because of this (via[0]) > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or…

> which is insane

It's completely sane from the EU's point of view. Why would they submit their citizens to forceful government eavesdrop?

I do agree it's insane. But the insanity is not on the GDPR.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#270
post #99

We are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously bec…

Uber’s right to do what ever the f they want stops at my right to control information pertaining to me. What’s freedom? GPL? BSD? Swinging a fist? Not getting hit on the nose?

You've missed the point of my comment. It has no normative claims, unlike your angry invective about rights. I'm just pointing out that the inevitable consequence of these new regulatory regimes is a nationally siloed internet. You can feel however you want about it; maybe that's a good thing from your perspective. But it's happening
Post reply on HN