Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

381–390 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#381
post #356

Earlier quoted context omitted.

Uber HQ is in the Netherlands. They like the tax system here..

That's one way of saying "Europe is full of nations who provide unethical tax shelters for businesses (while criticizing any nation that doesn't provide their level of social programs), so they can regulate and fine and fill their coffers with money from businesses all over the world." But yeah, blame it on the companies that take advantage of the tax shelters EU nations choose to provide and the EU chooses to allow.

Maybe our definitions of "Tax shelters" are a bit different, but I think of Cayman Islands or Bermuda when I hear that, and Netherlands is not like that in the context of Europe. Probably Ireland is the closest you get, so would have been a much better example.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#382

Earlier quoted context omitted.

> What policies within GPDR are dumpster fires? Every company I have worked for (including banks, FSP and retailers) have different interpretations of GDPR and do vastly different things. National agencies were also responsible for specifying which certifications cloud providers should have to be GDPR compliant, but they did not do that for years, and I think they still have not done it. The end result was that you w…

I'm pretty unclear from your post how GPDR is different from any other compliance standard Overall, many of the 'problems' here seem natural, signs of it working, and even good? Ex - variety: I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Even within the same industry & weight class, I would expect different companies to have different risk appetites -- that'…

> I'm pretty unclear from your post how GPDR is different from any other compliance standard

I never said it was different, I said it is a dumpster fire. Most regulation being dumpster fires does not somehow absolve the GDPR from being a dumpster fire.

> I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR.

Maybe we are using different definitions of the word interpretation, but if nobody knows how to comply with your regulation because they don't understand what it means, it is bad regulation. Regulation that is entirely open to interpretation is a massive "do not invest" red flag to businesses, which incidentally, is one of the reasons why innovation in the EU is so bad.

> I also recognize that making such an interface a hard requirement would lead to excessive rigidity.

If compliance is uncertain it makes business more expensive and wasteful. If nobody knows whether they are complying with regulation and the only way to find out is litigation, it is bad regulation.

> Ex - GCP: I would think a bank better understand how its cloud data processor is working enough to answer basics like where customer data is flowing

There is much more to GDPR than to what country data is flowing. Again, I don't know how to express this more clearly: National agencies neglected their responsiblity in setting out certification processes. As useless as they were at their job, at the very least they could see this is needed, they just did not do their job because they had no incentive to do it.

> I'm not sure what the problem with the cookie thing is.

It could have been implemented by browsers as a header in HTTP requests. Having a popup on every site is not a clever strategy.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#383
post #79

Earlier quoted context omitted.

That would be incorrect. IANAL, but cloud act purpose is to allow the usa government to ask data from USA-based or USA-related services providers, for offsense/crimes. It does not allow service providers to do anything else with that data.

But what could Uber do with customer data on US servers what they couldn't do with the data on EU servers?

[deleted]

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#384
post #170
post #143

> Since the end of last year, Uber uses the successor to the Privacy Shield. Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.

The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though…

No, the EC asked ChatGPT to rewrite the Privacy Shield but give it another name, and the CJEU is expected to retroactively invalidate the law again. This will only change if the US provides essentially equivalent privacy protection laws, which they don't.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#385
post #378

Earlier quoted context omitted.

It isn't possible for an American company to actually comply.

That's not a EU problem. If the US puts laws in place that prevents their company from expending overseas, that's a problem that Americans need to fix.

There is nothing the companies can do about it.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#386

Earlier quoted context omitted.

I'm pretty unclear from your post how GPDR is different from any other compliance standard Overall, many of the 'problems' here seem natural, signs of it working, and even good? Ex - variety: I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Even within the same industry & weight class, I would expect different companies to have different risk appetites -- that'…

> I'm pretty unclear from your post how GPDR is different from any other compliance standard I never said it was different, I said it is a dumpster fire. Most regulation being dumpster fires does not somehow absolve the GDPR from being a dumpster fire. > I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Maybe we are using different definitions of the word interp…

The cookie law, and none of the other related privacy laws, say anything about cookie banners. They only state that users must be given clear explanations and a chance to consent (or not).

Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties. You'll notice Github for example doesn't have any kind or banners or popups about cookies, and they're GDPR compliant.

I suspect the next course of action will be that the EU tightens what the law means - aka no, selling my data to 1100 "partners" isn't legitimate interest. But this isn't a failing of the GDPR, it's a failure on the part of the scummy companies that just can't help but poke the nest for every crumb of data.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#387

Earlier quoted context omitted.

How would you suggest they express their disapproval, if not through the legal system? I'm personally not opposed to holding conpany executives personally accountable, including jail time in severe cases, but I don't think this would go over well with the US government.

France has picked that method with Telegram.

Can you imagine if the CEO of Telegram was a US citizen? It wouldn’t just be HN people losing their minds.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#388
post #378

Earlier quoted context omitted.

That's not a EU problem. If the US puts laws in place that prevents their company from expending overseas, that's a problem that Americans need to fix.

There is nothing the companies can do about it.

They can lobby, right? I mean what are those $billions being spent on? Weakening environmental or consumer protections?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#389
post #387

Earlier quoted context omitted.

France has picked that method with Telegram.

Can you imagine if the CEO of Telegram was a US citizen? It wouldn’t just be HN people losing their minds.

U.S. citizens are arrested and convicted for breaking laws in other countries all the time. It's rare that they get out of it because they are a foreigner. It doesn't matter if the laws and punishments are different - whether that be a caning for spitting, a prison sentence for besmirching the king, or even the death penalty for drug dealing. People are obligated to obey local laws, even if they disagree with them, or suffer the consequences.

Not saying there can't be an international uproar, but if laws were broken the local justice system is legally entitled to punish the perp, even a foreigner.

People loose their minds for all kinds of reasons, I can't speak to that ;-)

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#390

Earlier quoted context omitted.

> I'm pretty unclear from your post how GPDR is different from any other compliance standard I never said it was different, I said it is a dumpster fire. Most regulation being dumpster fires does not somehow absolve the GDPR from being a dumpster fire. > I would expect a bank vs a retailer vs a startup to have significantly different implementations of GDPR. Maybe we are using different definitions of the word interp…

The cookie law, and none of the other related privacy laws, say anything about cookie banners. They only state that users must be given clear explanations and a chance to consent (or not). Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties. You'll notice Github for example doesn't have any kind or banners or popups about cook…

> Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties.

I take exception to that. I have worked for many companies that are not in the least bit "scummy" and have popups. Even our government sites here in Norway have the popups [1]. All this points to is again that the regulation is bad.

And again, because of the lack of certification, it's not possible to claim that GitHub is compliant. All you can say is that a court has not found them non-compliant yet. That is not the same as being compliant.

[1]: https://i.imgur.com/0csPRqT.png

Post reply on HN