Earlier quoted context omitted.
Uber is a poor example of dominant American companies. They don’t really have a moat and they don’t really provide a better service than the alternatives in Europe. I don’t think people would miss them much if they left.
The famous companies with a moat are Apple, Google, Microsoft and Amazon(AWS) since they're vertically integrated so no start-up stands a chance of competing or like Reddit and you hold a large userbase knowledge repository. Food delivery companies, ride sharing companies, flight & boarding booking companies are all expendable. If one goes down, another one will spring up tomorrow.
Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
361–370 of 414 posts
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#362Earlier quoted context omitted.
> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…
That's a nonsensical load of hyperbole, pardon my French. It's not particularly difficult to be careful with personal data, it's just inconvenient and prevents all kinds of uses that can make you money - which is why US corporations would prefer to not implement it. But if you want to do business in the EU, you need to play by their rules. Simple.
Importantly though, the law does not suffice with "careful". We *think* we have our bases covered and are careful to try to ensure they are but we're not sure how to *know* our bases are covered. There's the fear that some logs that we believe are anonymous might be considered identifying by some data scientist armed with techniques we've never heard of. There's the concern that some third-party library might dynamically pull in a font-set that comes from a US-based CDN based on some user configuration that we don't foresee. There's the anxiety of asking "Did we forget something? Is the DNS server in us-east-1?" when trying to roll out new features.
These are all strawmen, but they represent the kind of anxiety we feel. Having done our best to respect the requirements and the spirit in which they were written, there's the fear that we were imperfect in our awareness and that that something could cost us a fine that would have gone to someone's salary.
I would very much condemn the indiscriminate collecting, reuse, and selling of personal data, but I would also caution that those of us wanting to play by the rules find them lacking in precision.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#363Earlier quoted context omitted.
> The wider challenge is how that is handled in a compliant way with LLMs and generative tools which vendors do not seem to be taking particularly seriously yet I'm curious as to why people would want to train LLMs on personal identifying information. What's the benefit of an LLM that has a large collection of names, addresses, dates of birth etc.?
Free-form text like Reddit posts contains a whole load of PII. Since there is absolutely no regard for what goes into a LLM, naturally, they also contain this PII.
If there is indeed a lot of personal identifying information from Europeans on Reddit, then they'd better get ready for a GDPR investigation.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#364Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.
I think you’re reaching and acting like Americans don't understand the implication, we just don’t consider it something that’s bad. We are allies on a global market and therefore treat you no differently. This is why the US is concerned about data islands with China, but has no problem with European countries and companies with US data. Clearly the American capitalist strategy is working since all the products you ke…
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#365Earlier quoted context omitted.
> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…
Many countries have data residency laws (their citizen PII data cannot leave that country). https://incountry.com/blog/data-residency-laws-by-country-ov...
These laws seem to have been written for the age of fax machines, not for today.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#366Earlier quoted context omitted.
I don't understand, are you saying the intended effect of these laws is that non-EU countries don't enter the EU market?
Not necessarily, but it should "change the calculus of launching an existing product in Europe", factoring in privacy laws. Either don't launch, or make sure that your product complies.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#367Earlier quoted context omitted.
What policies within GPDR are dumpster fires? Likewise, afaict it only applies to doing business with EU citizens... So if you don't want to comply, or not be subject to the fees, don't? I would expect the US to eventually adopt its own more intentional variant of online privacy laws, and software infra to get better at supporting the GPDR flavor, at which point I would expect most US tech companies at least would fi…
> What policies within GPDR are dumpster fires? Every company I have worked for (including banks, FSP and retailers) have different interpretations of GDPR and do vastly different things. National agencies were also responsible for specifying which certifications cloud providers should have to be GDPR compliant, but they did not do that for years, and I think they still have not done it. The end result was that you w…
Overall, many of the 'problems' here seem natural, signs of it working, and even good?
Ex - variety: I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Even within the same industry & weight class, I would expect different companies to have different risk appetites -- that's ultimately a commercial decision -- and thus different takes on what they consider appropriate risk-adjusted compliance
Ex - certainty: While I am a (strong!) advocate of making checkbox compliance provide an optional automatable conformance testing API, I also recognize that making such an interface a hard requirement would lead to excessive rigidity. The real world has ~400 million companies with all sorts of edge cases who benefit from ambiguity & interpretation in policies. The compromise here and elsewhere has been the same: As you get bigger, bring in security experts and auditors. If you've done anything like SOC2, HIPAA, etc, it seems normal, and in my experience, successfully reveals issues that get fixed / starts the paper trail for corporate malfeasance?
Ex - GCP: I would think a bank better understand how its cloud data processor is working enough to answer basics like where customer data is flowing, whether another country or company sees it, etc? And if not, that's a pretty core problem both with the bank and the cloud data processor?
I'm not sure what the problem with the cookie thing is. Companies can choose not to track, improve their EULAs, etc. Maybe it's that it's too easy for companies to just do a popup and trick/force users into being tracked... and you want something stronger than gpdr?
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#368Earlier quoted context omitted.
> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say. Meanwhile, a company that d…
That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence. The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they the…
As far as I understand, the EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection. In the EU's opinion, the Cloud act, as well as the whole NSA situation, mean that the US doesn't fulfill this definition.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#369This puts the total fines from the EU on American tech businesses at $14.8B in the last few years: https://loeber.substack.com/p/20-no-more-eu-fines-for-big-te... I think this substack is good, it makes a pretty clear case that US tech companies may not leave Europe any time soon, but they wield the power in the relationship much more so than the Europeans. Those regulators are overplaying their hands.
What happens then? They leave a vacuum and then what? Noone fills that vacuum? Assuming there is zero competence in the EU, which is highly unlikely since both the best image generation model right now and very respectable open source llms are from the EU, and on top of this several countries in Europe have exceptional tech talent (especially in the East), the Chinese would jump in immidiately.
Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
#370Earlier quoted context omitted.
I don't understand, are you saying the intended effect of these laws is that non-EU countries don't enter the EU market?
Not necessarily, but it should "change the calculus of launching an existing product in Europe", factoring in privacy laws. Either don't launch, or make sure that your product complies.