Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

361–370 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#361

Earlier quoted context omitted.

Uber is a poor example of dominant American companies. They don’t really have a moat and they don’t really provide a better service than the alternatives in Europe. I don’t think people would miss them much if they left.

The famous companies with a moat are Apple, Google, Microsoft and Amazon(AWS) since they're vertically integrated so no start-up stands a chance of competing or like Reddit and you hold a large userbase knowledge repository. Food delivery companies, ride sharing companies, flight & boarding booking companies are all expendable. If one goes down, another one will spring up tomorrow.

Yes, and I don’t see them moving away any time soon. It’s too much on their balance sheets (Europe is a bigger market than China for Apple, and the other two are deeply embedded with the local administrations and companies). All of them are following the legislative frameworks and adapting.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#362
post #144

Earlier quoted context omitted.

> It's all very myopic and US-centered to focus on the company's freedom to do as it pleases. The Dutch DPA is not accusing Uber of doing anything nefarious. They are mad that Uber, as an American company, can be compelled by the US government to hand over data. Ultimately, their beef is not with US companies, it’s with the US government. This is all wildly ironic because the EU is constantly trying to spy on their o…

That's a nonsensical load of hyperbole, pardon my French. It's not particularly difficult to be careful with personal data, it's just inconvenient and prevents all kinds of uses that can make you money - which is why US corporations would prefer to not implement it. But if you want to do business in the EU, you need to play by their rules. Simple.

At my company, we do business in the EU. It's a wide market with many opportunities. We're extremely careful with personal data: we do not intentionally collect user data, we do not share data with any third-party (and certainly never sell it)!

Importantly though, the law does not suffice with "careful". We *think* we have our bases covered and are careful to try to ensure they are but we're not sure how to *know* our bases are covered. There's the fear that some logs that we believe are anonymous might be considered identifying by some data scientist armed with techniques we've never heard of. There's the concern that some third-party library might dynamically pull in a font-set that comes from a US-based CDN based on some user configuration that we don't foresee. There's the anxiety of asking "Did we forget something? Is the DNS server in us-east-1?" when trying to roll out new features.

These are all strawmen, but they represent the kind of anxiety we feel. Having done our best to respect the requirements and the spirit in which they were written, there's the fear that we were imperfect in our awareness and that that something could cost us a fine that would have gone to someone's salary.

I would very much condemn the indiscriminate collecting, reuse, and selling of personal data, but I would also caution that those of us wanting to play by the rules find them lacking in precision.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#363
post #209

Earlier quoted context omitted.

> The wider challenge is how that is handled in a compliant way with LLMs and generative tools which vendors do not seem to be taking particularly seriously yet I'm curious as to why people would want to train LLMs on personal identifying information. What's the benefit of an LLM that has a large collection of names, addresses, dates of birth etc.?

Free-form text like Reddit posts contains a whole load of PII. Since there is absolutely no regard for what goes into a LLM, naturally, they also contain this PII.

That's not something that I've encountered on Reddit - I've mostly seen people deliberately not using their real names.

If there is indeed a lot of personal identifying information from Europeans on Reddit, then they'd better get ready for a GDPR investigation.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#364
post #4

Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.

I think you’re reaching and acting like Americans don't understand the implication, we just don’t consider it something that’s bad. We are allies on a global market and therefore treat you no differently. This is why the US is concerned about data islands with China, but has no problem with European countries and companies with US data. Clearly the American capitalist strategy is working since all the products you ke…

[deleted]

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#365

Earlier quoted context omitted.

> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's…

Many countries have data residency laws (their citizen PII data cannot leave that country). https://incountry.com/blog/data-residency-laws-by-country-ov...

What does that even mean, though? Data does not have a location. It's just information. The fact that "I live on 123 Oak Street" is data. It's not anywhere. How can you say that it's in a particular country? This post might be read by people all across the world. Now that information is in many different countries? Or none at all? Is it simply about where the physical hard drive containing a textual representation of that data is located? What makes that relevant?

These laws seem to have been written for the age of fax machines, not for today.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#366

Earlier quoted context omitted.

I don't understand, are you saying the intended effect of these laws is that non-EU countries don't enter the EU market?

Not necessarily, but it should "change the calculus of launching an existing product in Europe", factoring in privacy laws. Either don't launch, or make sure that your product complies.

It isn't possible for an American company to actually comply.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#367

Earlier quoted context omitted.

What policies within GPDR are dumpster fires? Likewise, afaict it only applies to doing business with EU citizens... So if you don't want to comply, or not be subject to the fees, don't? I would expect the US to eventually adopt its own more intentional variant of online privacy laws, and software infra to get better at supporting the GPDR flavor, at which point I would expect most US tech companies at least would fi…

> What policies within GPDR are dumpster fires? Every company I have worked for (including banks, FSP and retailers) have different interpretations of GDPR and do vastly different things. National agencies were also responsible for specifying which certifications cloud providers should have to be GDPR compliant, but they did not do that for years, and I think they still have not done it. The end result was that you w…

I'm pretty unclear from your post how GPDR is different from any other compliance standard

Overall, many of the 'problems' here seem natural, signs of it working, and even good?

Ex - variety: I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Even within the same industry & weight class, I would expect different companies to have different risk appetites -- that's ultimately a commercial decision -- and thus different takes on what they consider appropriate risk-adjusted compliance

Ex - certainty: While I am a (strong!) advocate of making checkbox compliance provide an optional automatable conformance testing API, I also recognize that making such an interface a hard requirement would lead to excessive rigidity. The real world has ~400 million companies with all sorts of edge cases who benefit from ambiguity & interpretation in policies. The compromise here and elsewhere has been the same: As you get bigger, bring in security experts and auditors. If you've done anything like SOC2, HIPAA, etc, it seems normal, and in my experience, successfully reveals issues that get fixed / starts the paper trail for corporate malfeasance?

Ex - GCP: I would think a bank better understand how its cloud data processor is working enough to answer basics like where customer data is flowing, whether another country or company sees it, etc? And if not, that's a pretty core problem both with the bank and the cloud data processor?

I'm not sure what the problem with the cookie thing is. Companies can choose not to track, improve their EULAs, etc. Maybe it's that it's too easy for companies to just do a popup and trick/force users into being tracked... and you want something stronger than gpdr?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#368
post #339

Earlier quoted context omitted.

> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say. Meanwhile, a company that d…

That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence. The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they the…

There's also the Cloud act, which makes it illegal for US cloud providers to refuse data access requests from the US government.

As far as I understand, the EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection. In the EU's opinion, the Cloud act, as well as the whole NSA situation, mean that the US doesn't fulfill this definition.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#369
post #226

This puts the total fines from the EU on American tech businesses at $14.8B in the last few years: https://loeber.substack.com/p/20-no-more-eu-fines-for-big-te... I think this substack is good, it makes a pretty clear case that US tech companies may not leave Europe any time soon, but they wield the power in the relationship much more so than the Europeans. Those regulators are overplaying their hands.

What happens then? They leave a vacuum and then what? Noone fills that vacuum? Assuming there is zero competence in the EU, which is highly unlikely since both the best image generation model right now and very respectable open source llms are from the EU, and on top of this several countries in Europe have exceptional tech talent (especially in the East), the Chinese would jump in immidiately.

If your concern is privacy, moving to Chinese services is not the answer.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#370

Earlier quoted context omitted.

I don't understand, are you saying the intended effect of these laws is that non-EU countries don't enter the EU market?

Not necessarily, but it should "change the calculus of launching an existing product in Europe", factoring in privacy laws. Either don't launch, or make sure that your product complies.

Yeah. But even if you act in good faith there's still a chance you'll make mistakes and run afoul of the law. And now the cost of a mistake is not "we'll end up losing money in this new market" it's "our business might fail worldwide".
Post reply on HN