Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

321–330 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#321

Earlier quoted context omitted.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

> Can someone clarify for me why the physical location where data is stored is a big deal? What can you do if your data is silently copied by third parties and used for other activities? What if I build a ghost profile of you and steal your identity when I have enough data? What if I relay that you have a fancy car to some people who have the means to get that from you while sleeping? What if I craft a good scam by t…

> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it.

Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say.

Meanwhile, a company that does business in the EU would be subject to fines by the EU and wouldn't be able to dodge them without just stopping doing business in the EU. So why do the laws not just say "here's how you have to treat data belonging to our citizens if you want to continue to do business in the EU"? Why does the physical location of the data that is being thus protected matter at all?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#322
post #259
post #230

Earlier quoted context omitted.

> but it illustrates the depth of legal uncertainty that exists in architecting software systems in Europe that process personal information. Oh I agree with that. EC's behaviour in that case is appalling. > Corporations can't necessarily trust the EC's own interpretations of their own laws There is a way to be safe with regards to EU law, and it's to engineer systems where European data stays in Europe. Of course, t…

It's not that easy really. Several European countries have FISA s.702 functional equivalents that enable intelligence to get orders for interception of personal information on servers and entities within their legal jurisdiction. (e.g., The French Law on Intelligence and the German BND Act) It's easy to say that the US should just scrap s.702, but unless it's reciprocal with Europe scrapping their interception powers…

> that enable intelligence to get orders for interception of personal information on servers and entities within their legal jurisdiction.

That is common indeed. What's peculiar with US law is that it can mandate companies to move data about people outside of US jurisdiction that is stored outside of US jurisdiction and turn it over to US authorities, even when it violates local law.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#323
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

The reason why the physical location matters, besides latency, is that certain governments have laws in place that allows them access to any data in their territory.

In the case of EU countries (I think its part of gdpr), services that handle personal data need to make sure that that data stays safe. The only way they can do that is to make sure that the data stays in a certain region.

I think that is why op is advocating for stronger laws. Due to lax privacy laws in the US, it's impossible for European companies (and other privacy concerned companies) to host their data in the US, therefore your missing a share of the market

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#324

Earlier quoted context omitted.

It's much harder to fine companies that break the law if they make up a substantial part of your economy. On the other hand, big US companies don't have as much lobby power in the EU, so the EU is "free" to fine them.

> It's much harder to fine companies that break the law if they make up a substantial part of your economy. Any evidence of this in the EU? EU courts and regulators seem to give no hecks about economy or reason. Data protection is great and all, but GDPR is a dumpster fire.

For example, look at the fines German car manufacturers "faced" in the EU when their emission-cheating scheme was exposed...

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#325
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

>global network of computers

Global network of computers where data ultimately flowed to American mainframes. Countries realize data is a resource / liability / vunerability, and even if most struggle to profit from it, they'd still want sovereign control over it. You only really control things on your soil. Physical location / possession matters for control.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#326
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

Many countries have data residency laws (their citizen PII data cannot leave that country).

https://incountry.com/blog/data-residency-laws-by-country-ov...

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#327
post #170

Earlier quoted context omitted.

The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though…

> The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent. If i'm not mistaken, because of this (via[0]) > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or…

> If i'm not mistaken, because of this (via[0])

>> The CLOUD Act primarily...

As far as I understand (IANAL) the CLOUD Act has not been used as basis of decision at least for Schrems II. The primary issues court found were regarding surveillance programs authorized under Section 702 of the FISA & executive order 12333.

Full Schrems II judgement is available at https://curia.europa.eu/juris/document/document.jsf?text=&do...

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#328
post #312

Earlier quoted context omitted.

> Can someone clarify for me why the physical location where data is stored is a big deal? Because the place where data is collected and stored may have different rules around privacy and data protection then the place it is exfiltrated to. If I give my data to a company in one place that has strict laws on what may be done with that information, I don’t want it escaping to a low-protection jurisdiction where there a…

But again I ask, why does the physical location of the data matter? Why do the laws care? The EU has a law that said you must treat data of their citizens with respect. Fine, that's great. Any business that has a presence in the EU will need to follow that law. At that point, why does it matter where the bits are actually stored? Can the EU for some reason not enforce its privacy laws on Uber if Uber keeps its data s…

> Can the EU for some reason not enforce its privacy laws on Uber if Uber keeps its data somewhere else?

Yes. Even assuming these laws still work if data is in another jurisdiction (prob. not), they become unenforceable. If someone sells your data in, say, Somalia, how could EU gather evidence and start a legal process?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#329
post #222
post #199

Earlier quoted context omitted.

this take is naive. building alternatives takes time and resources. the EU has neither. a diverse, competitive tech ecosystem with both EU and non-EU players is better than a protectionist approach. hoping for an exodus of major global players when you’re leapfrogged by both China and the US…

> building alternatives takes time and resources. the EU has neither. Oh no. What would we poor Europeans do without a US company to lead us. /s Of course local and regional players would appear, as they always have and are already in place in multiple segments. Bolt, Glovo, Delivery Hero and many others are successful competitors to different Uber offerings in the different European markets they operate. The biggest…

>The biggest gap in Europe is not due to a lack of technical ability but rather of European wide capital that's not super risk averse.

It’s both. Copying a validated business model is not a sign of competency.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#330

[flagged]

It has indeed. American companies basically finance the EU superstate bureaucracy. I'd like to see some reciprocity on the American side, fining EU businesses dollar for dollar.

Such an US comment, the companies are doing something illegal and get the fine for it. They want to do business in the EU they should follow those rules.

Same goes the other way around, or do you think Philips isn't getting fined out of their nose for their mismanagement?

Post reply on HN