Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

391–400 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#391
post #339

Earlier quoted context omitted.

That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence. The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they the…

There's also the Cloud act, which makes it illegal for US cloud providers to refuse data access requests from the US government. As far as I understand, the EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection . In the EU's opinion, the Cloud act, as well as the whole NSA situation, mean that the US doesn't fulfill this definition.

> EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection.

Yes, we have a GPDR compliant law in place, and we can interoperate with EU.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#392
post #327

Earlier quoted context omitted.

> The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent. If i'm not mistaken, because of this (via[0]) > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or…

> If i'm not mistaken, because of this (via[0]) >> The CLOUD Act primarily... As far as I understand (IANAL) the CLOUD Act has not been used as basis of decision at least for Schrems II. The primary issues court found were regarding surveillance programs authorized under Section 702 of the FISA & executive order 12333. Full Schrems II judgement is available at https://curia.europa.eu/juris/document/document.jsf?text=…

That makes more sense then. Is it still right to say that they're afraid of a US company being compelled to access data at the request of the US gov when it's stored in the EU, or is it still only trying to avoid EU data actually going to the US during _regular_ operations of a business (paragraph 63)? I feel like it's still a threat if some US employee could access servers inside the EU as a one-off for NSA/etc surveillance?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#393

Earlier quoted context omitted.

Many countries have data residency laws (their citizen PII data cannot leave that country). https://incountry.com/blog/data-residency-laws-by-country-ov...

What does that even mean, though? Data does not have a location. It's just information. The fact that "I live on 123 Oak Street" is data. It's not anywhere. How can you say that it's in a particular country? This post might be read by people all across the world. Now that information is in many different countries? Or none at all? Is it simply about where the physical hard drive containing a textual representation of…

This is clearly about where the information is stored.. And therefore under which jurisdiction and laws it falls.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#394
post #132

Earlier quoted context omitted.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

Have you followed with a notification to your privacy authority?

In this case it really wasn't worth it, but I've done it in other cases

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#395
post #132

Earlier quoted context omitted.

Could be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started sp…

> Could be simple negligence on Uber's part. The didn't slip, fall, and drop some USB flash drives into the hands of a US data processor... I doubt it is any sort of negligence, but if it is - it's not "simple".

negligence: failure to exercise the care that a reasonably prudent person would exercise in like circumstances.

Most companies are negligent. Many of those are also deliberately negligent

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#396
post #144

Earlier quoted context omitted.

That's a nonsensical load of hyperbole, pardon my French. It's not particularly difficult to be careful with personal data, it's just inconvenient and prevents all kinds of uses that can make you money - which is why US corporations would prefer to not implement it. But if you want to do business in the EU, you need to play by their rules. Simple.

At my company, we do business in the EU. It's a wide market with many opportunities. We're extremely careful with personal data: we do not intentionally collect user data, we do not share data with any third-party (and certainly never sell it)! Importantly though, the law does not suffice with "careful". We *think* we have our bases covered and are careful to try to ensure they are but we're not sure how to *know* ou…

> These are all strawmen, but they represent the kind of anxiety we feel.

No idea why you would feel the anxiety. If you're found lacking, you will forest get s notification from the DPA asking you to remedy the situation. You wont even be fined

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#397

Earlier quoted context omitted.

\s, I hope? Not using US-made products is basically impossible in the modern world.

There's Bolt where I am from, they are an Estonian company and have better and cheaper services than Uber.

Fair point; I should have clarified I wasn't really talking about Uber, specifically, but about American products (e.g. Windows and MacOS) in general :)

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#398
post #144

Earlier quoted context omitted.

That's a nonsensical load of hyperbole, pardon my French. It's not particularly difficult to be careful with personal data, it's just inconvenient and prevents all kinds of uses that can make you money - which is why US corporations would prefer to not implement it. But if you want to do business in the EU, you need to play by their rules. Simple.

I have soberly explained the actual situation to you. I know it’s impossible to have a rational conversation about privacy on HN and my comments go against the narrative everyone has stuck in their heads here, but I urge you to look further into this issue. This is an ongoing geopolitical spat and compliance in good faith is currently impossible. I have spoken to many lawyers about this. Any US company operating in t…

> Any US company operating in the EU is at risk of constant fines no matter what you do, due to this geopolitical issue.

So why don't the poor trillion-dollar supranational corporations do anything about it?

I can tell you why: they are happy about this. And you can often find they sign their support for these laws in the US.

--- start quote ---

The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.

The CLOUD Act received support from Department of Justice and of major technology companies like Microsoft, AWS, Apple, and Google.

https://en.wikipedia.org/wiki/CLOUD_Act?wprov=sfti1#

--- end quote ---

Boohoo cry me a river about the plight of these poor hapless companies.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#399

Earlier quoted context omitted.

Sorry, you are not really making a better case for your argument. The budget of the EU largely comes from other places. Fines like these don't even register on there meaningfully. That alone should tell you enough.

The fact that a 290 million euro fine isn't considered meaningful does tell me a lot.

The EU is the largest economical block in the world. 290 isn't that much for them.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#400

Earlier quoted context omitted.

The cookie law, and none of the other related privacy laws, say anything about cookie banners. They only state that users must be given clear explanations and a chance to consent (or not). Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties. You'll notice Github for example doesn't have any kind or banners or popups about cook…

> Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties. I take exception to that. I have worked for many companies that are not in the least bit "scummy" and have popups. Even our government sites here in Norway have the popups [1]. All this points to is again that the regulation is bad. And again, because of the lack of certif…

I'm not sure what you're looking for, given how the rest of compliance works? What is the compromise?

I suspect people would hate it even more if every company needed to go through an official gov GPDR certification. In the US, SOC2, and EU, ISO, are voluntary (not gov), and generally doesn't happen till most companies hit 8 figure revenue (and earlier in enterprise).

What I would expect to start happening is, similar to FedRAMP or UK's CHECK, govs will accredit third-party firms for auditing. Companies can - and typically do - already use these without gov's blessing for SOC2, ISO, yes, GPDR. Certification by a 3PAO is not indemnity, just a good faith positioning for when the enforcement agency gets a complaint and audits on related topics. (And in the case of inept management who doesn't cheap out, a wakeup.)

In areas like bank regulations, the gov is even more high-touch, and I really wouldn't wish that on the 400M businesses out there.

Post reply on HN