Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

341–350 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#341

Earlier quoted context omitted.

Or, IIRC, if the destination country has privacy protections that are at least as strict as those in the EU, which the US legal regime for foreign intelligence definitely doesn’t provide (a non-US-citizen wouldn’t even have standing to sue wrt their personal data).

> a non-US-citizen wouldn’t even have standing to sue wrt their personal data Sure they would, I think? They would just have to foot the bill to travel and file in a US court. And whatever user agreements they 'agreed' to might come in to play without legislation to supersede it. But they would have standing, I'm pretty sure.

Not a lawyer and not going to find the relevant references in the US’s vast body of law in reasonable time, so let’s check what the CJEU concluded?

Schrems I [1] (the old CJEU judgment invalidating Safe Harbor) endorses (§90) the opinion that:

> [D]ata subjects [whose personal data was transferred to the US] had no administrative or judicial means of redress enabling, in particular, the data relating to them to be accessed and, as the case may be, rectified or erased.

In what reads like a reference to FISA, it continues (§95):

> Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter [of Fundamental Rights of the European Union].

It then stops short of calling out FISA by name, instead (IIUC) invalidating on the basis that the adequacy of the legal regime was not addressed in the Safe Harbour decision to begin with. Privacy Shield came next and did, so Schrems II [2] (the newer judgment invalidating Privacy Shield) states (§181–2):

> According to the findings in the Privacy Shield Decision, the implementation of the surveillance programmes based on Section 702 of the FISA is, indeed, subject to the requirements of PPD‑28. However, although the Commission stated, in recitals 69 and 77 of the Privacy Shield Decision, that such requirements are binding on the US intelligence authorities, the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities. Therefore, the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter [...].

> As regards the monitoring programmes based on E.O. 12333, it is clear from the file before the Court that that order does not confer rights which are enforceable against the US authorities in the courts either.

It sounds like the official legal position of the US executive is that individual foreigners do not have standing to contest FISA 702 surveillance of them. (I could not quickly find the text of that position.) This is a 2020 judgment in a case from July 2018 regarding a European Commission decision from 2016, so the implications of the CLOUD Act, signed in March 2018, do not look to be in scope.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...

[2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#342
post #339

Earlier quoted context omitted.

> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say. Meanwhile, a company that d…

That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence. The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they the…

Thanks, this explanation makes sense.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#343

Earlier quoted context omitted.

It has indeed. American companies basically finance the EU superstate bureaucracy. I'd like to see some reciprocity on the American side, fining EU businesses dollar for dollar.

Or at least stopping US tax money from subsidizing the EU in areas like defense.

What would the hit to the U.S. economy be if Europe turned into a Russo-Chinese protectorate? Besides, almost all NATO members have been doing exactly what the Americans have asked and increased their defense spending to 2% of GDP (a lot of that money flows in the U.S. economy through weapons purchases, thereby subsidising the U.S. economy)

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#344
post #340

Earlier quoted context omitted.

[flagged]

All governments are funded by "taking it from someone else", usually in the form of taxes. Member state contributions, VAT income, and customs duties provide over 90% of EU funding. These fines of companies are a drop in the bucket, not the main way the EU finances itself.

Fines were less than 1% of the revenue of the EU in 2023, to be more precise. I don't know how people here got the idea that the EU can fund itself only with such fines, to be honest.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#345

Earlier quoted context omitted.

> It's much harder to fine companies that break the law if they make up a substantial part of your economy. Any evidence of this in the EU? EU courts and regulators seem to give no hecks about economy or reason. Data protection is great and all, but GDPR is a dumpster fire.

What policies within GPDR are dumpster fires? Likewise, afaict it only applies to doing business with EU citizens... So if you don't want to comply, or not be subject to the fees, don't? I would expect the US to eventually adopt its own more intentional variant of online privacy laws, and software infra to get better at supporting the GPDR flavor, at which point I would expect most US tech companies at least would fi…

> What policies within GPDR are dumpster fires?

Every company I have worked for (including banks, FSP and retailers) have different interpretations of GDPR and do vastly different things. National agencies were also responsible for specifying which certifications cloud providers should have to be GDPR compliant, but they did not do that for years, and I think they still have not done it. The end result was that you would spend months with internal deliberations with incompetent lawyers internally trying to determine if you can, for example, use GCP — while government agencies in the same country are using GCP — and ultimately, there is no way to know without the agencies doing their job which they did not do.

Then there is the cookies popup mess.

> Likewise, afaict it only applies to doing business with EU citizens... So if you don't want to comply, or not be subject to the fees, don't?

I have not worked for one company that is subject to GDPR that actually knew for sure if they are compliant with GDPR. So, easier said than done. In practice, it's a racket to enrich lawyers.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#346

Earlier quoted context omitted.

>global network of computers Global network of computers where data ultimately flowed to American mainframes. Countries realize data is a resource / liability / vunerability, and even if most struggle to profit from it, they'd still want sovereign control over it. You only really control things on your soil. Physical location / possession matters for control.

> You only really control things on your soil. Physical location / possession matters for control. This feels like an outdated worldview that no longer really applies to data. Data can be exfiltrated from the EU in milliseconds and there's nothing that the EU can physically do about it short of setting up a great firewall a la China. The only thing they can do about it to retain sovereignty is to tell companies they'…

Someone illegally exfiltrates data from within your jurisdication and you can use _your_ legal instruments. Someone uses your data stored on another jurisdication and your legal options more limited or even powerless. Data is too leaky to prevent, so states focus on having the most tools to deter, including legal. And for some legal instruments to have maximum effectiveness, the location of physical molecules are important.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#347

[flagged]

It has indeed. American companies basically finance the EU superstate bureaucracy. I'd like to see some reciprocity on the American side, fining EU businesses dollar for dollar.

Oh really? You are saying that American companies are fined to the sum of roughly €160 billion to €180 billion each year? Because that's what the EU budget is (roughly 1% of the EU GDP).

The biggest ever fine was against Google and 4.3 billion several years ago (2018). As far as I know that has been fought over in court for several years and I am not sure if that actually has been paid yet.

So it certainly isn't a steady income stream and doesn't even come close to the actual EU budget.

I am all for discussions about topics like this. But it really is ridiculous to see takes like this, where clearly no single thought or piece of research has gone into the comment. Do better.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#348
post #146

Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.

Except that the US authorities have the right to access the data you stored on Apple or Google & Co. servers whenever needed, without your consent and even if you are completely innocent.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#349

[flagged]

It has indeed. American companies basically finance the EU superstate bureaucracy. I'd like to see some reciprocity on the American side, fining EU businesses dollar for dollar.

In reality, fines represent less than 1% of the EU's revenue.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#350

Earlier quoted context omitted.

> You only really control things on your soil. Physical location / possession matters for control. This feels like an outdated worldview that no longer really applies to data. Data can be exfiltrated from the EU in milliseconds and there's nothing that the EU can physically do about it short of setting up a great firewall a la China. The only thing they can do about it to retain sovereignty is to tell companies they'…

Someone illegally exfiltrates data from within your jurisdication and you can use _your_ legal instruments. Someone uses your data stored on another jurisdication and your legal options more limited or even powerless. Data is too leaky to prevent, so states focus on having the most tools to deter, including legal. And for some legal instruments to have maximum effectiveness, the location of physical molecules are imp…

> Someone uses your data stored on another jurisdication and your legal options more limited or even powerless.

If that someone is a legal entity within your jurisdiction, you have lots of options.

I edited my original comment to link to someone who gave a good explanation—what I hadn't considered is how difficult tracking suppliers and subcontractors recursively and ensuring that they all have a presence in the EU would be. I think it's a bad solution to that problem, but it does make sense.

Post reply on HN