Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

331–340 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#331

Earlier quoted context omitted.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

>global network of computers Global network of computers where data ultimately flowed to American mainframes. Countries realize data is a resource / liability / vunerability, and even if most struggle to profit from it, they'd still want sovereign control over it. You only really control things on your soil. Physical location / possession matters for control.

> You only really control things on your soil. Physical location / possession matters for control.

This feels like an outdated worldview that no longer really applies to data. Data can be exfiltrated from the EU in milliseconds and there's nothing that the EU can physically do about it short of setting up a great firewall a la China.

The only thing they can do about it to retain sovereignty is to tell companies they're not allowed to exfiltrate data. But if they can do that successfully, they can also just tell the companies what they're allowed to do with the data wherever it is in the world.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#332
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

It shouldn't be a problem for Europeans to access/process U.S. data that belongs to U.S. citizens - GDPR doesn't cover that AFAIK, so it's fine for it to cross borders. The issue is with GDPR protected data of EU citizens, as the law does not permit that data to cross non-EU borders unless it's for specific exemptions such as law enforcement.

You could be a citizen of the eu and us.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#333

Earlier quoted context omitted.

These laws have been created for good reasons, and US tech companies have had free reign to trample on people's privacy rights for a very long time. If a company acts in a honorable way, there's nothing to fear and they can easily do business world wide. It's when companies do things that are shady and should've been outlawed from the start that they run into trouble. The main issue here is that the US has the least…

"What about the users' freedom to live without being spied upon?" Pretty simple, don't use Uber.

Facebook showed this to be a stupid premise. You don't have to use a company to "interact with it" on the internet.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#334
post #312

Earlier quoted context omitted.

> Can someone clarify for me why the physical location where data is stored is a big deal? Because the place where data is collected and stored may have different rules around privacy and data protection then the place it is exfiltrated to. If I give my data to a company in one place that has strict laws on what may be done with that information, I don’t want it escaping to a low-protection jurisdiction where there a…

But again I ask, why does the physical location of the data matter? Why do the laws care? The EU has a law that said you must treat data of their citizens with respect. Fine, that's great. Any business that has a presence in the EU will need to follow that law. At that point, why does it matter where the bits are actually stored? Can the EU for some reason not enforce its privacy laws on Uber if Uber keeps its data s…

> Can the EU for some reason not enforce its privacy laws on Uber if Uber keeps its data somewhere else?

Maybe not, especially if they are separate corporate entities. Uber EU may choose to pay for operation of data storage by Uber US. Uber US is not under the same privacy restrictions and sells the data for profit, then what? Who sues who and for what?

This is also partly about governments - the US in particular is known for compelling access to servers that are on its soil and doing large-scale spying (not that EU powers don’t do the same, but bear with me). Companies operating in the US may not be legally able to guarantee data privacy. So having the data not enter US jurisdiction in the first place is considered safer.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#336

Earlier quoted context omitted.

That certainly is.... a take. Still a silly one if you ask me. If that were true they wouldn't fine EU companies either. Yet, that is also happening.

It's kind of like an ambulance-chasing lawyer. Yeah the driver at fault did real harm and owes money to the victim. But the lawyer is not a selfless justice crusader - he's looking for a payday. That's how I see the EU in these cases.

Sorry, you are not really making a better case for your argument. The budget of the EU largely comes from other places. Fines like these don't even register on there meaningfully. That alone should tell you enough.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#337

Earlier quoted context omitted.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

The reason why the physical location matters, besides latency, is that certain governments have laws in place that allows them access to any data in their territory. In the case of EU countries (I think its part of gdpr), services that handle personal data need to make sure that that data stays safe. The only way they can do that is to make sure that the data stays in a certain region. I think that is why op is advoc…

> certain governments have laws in place that allows them access to any data in their territory.

This explanation makes sense, but assuming "certain governments" includes the US then the remedy isn't stronger laws in the US, it's weaker laws—it means that the US was the first to break the borderless internet and it needs to rewrite its laws to be border-agnostic.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#338

[flagged]

It has indeed. American companies basically finance the EU superstate bureaucracy. I'd like to see some reciprocity on the American side, fining EU businesses dollar for dollar.

I don't think anyone from Europe would be against fining EU companies operating in the US that are violating US laws.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#339

Earlier quoted context omitted.

> Can someone clarify for me why the physical location where data is stored is a big deal? What can you do if your data is silently copied by third parties and used for other activities? What if I build a ghost profile of you and steal your identity when I have enough data? What if I relay that you have a fancy car to some people who have the means to get that from you while sleeping? What if I craft a good scam by t…

> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say. Meanwhile, a company that d…

That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence.

The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they themselves use, except without an EU presence that is hard to enforce.

In this case where there is one hop you could argue that it's the companies responsibility to ensure that their service providers are operating in compliance. Imagine the same scenario, but with one, two or more middlemen and the whole thing becomes an unenforceable mess of jurisdictions for the company to do meaningful due diligence on their service providers.

It's much easier for the EU to say EU data has to be stored in the EU, and know that any party touching the data is likely to be in compliance, and significantly easier to investigate if they are not.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#340

Earlier quoted context omitted.

What does "upset" mean here? How does this human emotion "upset" apply to the European Union ? Is Uber "upset"?

[flagged]

All governments are funded by "taking it from someone else", usually in the form of taxes. Member state contributions, VAT income, and customs duties provide over 90% of EU funding. These fines of companies are a drop in the bucket, not the main way the EU finances itself.
Post reply on HN