Live data from Hacker News

€1.2B GDPR fine for Meta

noyb.eu

41–50 of 68 posts

Re: €1.2B GDPR fine for Meta

#41
Politically, stopping data transfers to the US is not viable, because it would impact the deal between the EU and the USA (US covers EU defence for access to the EU common market).

For this reason, I don't think we'll ever see a Chinese-style expulsion of US tech companies from the EU.

Therefore, we've seen over a decade of a dance between the judiciary banning data transfers to the US (Safe Harbor ruling, etc) and then politicians overturning these rulings before it actually impacts anything.

Re: €1.2B GDPR fine for Meta

#42
post #37

Earlier quoted context omitted.

The decision goes further than a fine, though. It orders Meta to stop transferring personal data of people in the EU to the US.

How is this actually supposed to work in practice, other than sharding EU and non-EU customers and having them unable to communicate across the shards?

Meta’s chock full of very smart, highly paid people. I’m sure they’ll figure something out.

Re: €1.2B GDPR fine for Meta

#43

Politically, stopping data transfers to the US is not viable, because it would impact the deal between the EU and the USA (US covers EU defence for access to the EU common market). For this reason, I don't think we'll ever see a Chinese-style expulsion of US tech companies from the EU. Therefore, we've seen over a decade of a dance between the judiciary banning data transfers to the US (Safe Harbor ruling, etc) and t…

> US covers EU defence for access to the EU common market

Care to point me in the direction of more information about this?

Re: €1.2B GDPR fine for Meta

#44
post #30

> “It took us ten years of litigation against the Irish DPC to get to this result. We had to bring three procedures against the DPC and risked millions of procedural costs. The Irish regulator has done everything to avoid this decision, but was consistently overturned by the European Courts and institutions. It is kind of absurd that the record fine will go to Ireland - the EU Member State that did everything to ensu…

Wait. 10 years? So $120m/year fine? That’s a rounding error

Facebook has made approximately 20 billion in profit yearly for the last 5 years. They don't break down profit by country, but EU represents a small portion of users. About 10% overall. Speculating that overall profits are 2billion from EU means that the fine represents about 5% of profits.

Not that bad

Re: €1.2B GDPR fine for Meta

#45
post #8
post #4

"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot wi…

I don't see how they can continue the service, even with huge localisation effort. The capital sin is to be a US company. That subjects them to US law, including CLOUD act, which the UE considers to be incompatible with privacy guarantees. Even if cloud providers use local datacenters they are still in "violation". If the US makes a data request using CLOUD act, they will have to comply, no matter where these servers…

Don't try to paint the US as the victim here because it's honestly ridiculous.

Re: €1.2B GDPR fine for Meta

#46

> “It took us ten years of litigation against the Irish DPC to get to this result. We had to bring three procedures against the DPC and risked millions of procedural costs. The Irish regulator has done everything to avoid this decision, but was consistently overturned by the European Courts and institutions. It is kind of absurd that the record fine will go to Ireland - the EU Member State that did everything to ensu…

How often do you see a state-employee doing "everything in their power"? Did they have any special incentives?

Re: €1.2B GDPR fine for Meta

#47
post #46

> “It took us ten years of litigation against the Irish DPC to get to this result. We had to bring three procedures against the DPC and risked millions of procedural costs. The Irish regulator has done everything to avoid this decision, but was consistently overturned by the European Courts and institutions. It is kind of absurd that the record fine will go to Ireland - the EU Member State that did everything to ensu…

How often do you see a state-employee doing "everything in their power"? Did they have any special incentives?

Doing everything in their power here is to do nothing, so that's quite easy. My guess is push from above to be as lax as possible, so that companies choose to stay in Ireland vs other EU countries. Or the funding to the data protection agency is intentionally nerfed to keep them from being able to actually do anything.

Re: €1.2B GDPR fine for Meta

#48
post #4

"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot wi…

> hard to see how they can continue to service global markets without a huge per-country localisation effort You (the company) could maybe instead protect everyones data equally (or rather, avoid slurping up as much personal data as they possibly could), then you won't have to go through the whole process of making everything per-country localized. By GDP, the European market is the second largest in the world, it's…

You are suggesting two approaches, one (or even both) of which are not feasible.

The problem with protecting everyone's data equally (and the point of why EU courts are rejecting the current regime) is that national laws override company intent. If a US company is served a national interest letter, they are giving up the data and keeping mum about it, or someone is potentially going to jail. And nobody will go to jail to protect the data of a user of a free (or a $8/mo, whatever) service.

This happens similarly in other countries - China, obviously; UK has a similar "national interest" rule; I don't know about the EU but I wouldn't be surprised if their spies and law authorities have also codified access on an as-needed basis for themselves. It's all the other kids that must be kept out of the personal data sandbox.

Avoiding collecting the data in the first place is far more robust against this sort of government behavior. There are organized government efforts to mandate centralized data collection and facilitate access anyway (e.g. UK's attempts to ban end-to-end encryption), so we'll see if that approach holds.

Re: €1.2B GDPR fine for Meta

#49

Politically, stopping data transfers to the US is not viable, because it would impact the deal between the EU and the USA (US covers EU defence for access to the EU common market). For this reason, I don't think we'll ever see a Chinese-style expulsion of US tech companies from the EU. Therefore, we've seen over a decade of a dance between the judiciary banning data transfers to the US (Safe Harbor ruling, etc) and t…

What are you talking about? GDPR is pretty clear.

Re: €1.2B GDPR fine for Meta

#50

> These hopes may however be shattered soon. It is not unlikely that the new deal will be invalidated by the CJEU - just like the two previous EU-US data deals (“Privacy Shield” and “Safe Harbor”). Such invalidations have retroactive effect. If I understood correctly, if they keep transferring data to the US before CJEU considers that the nee deal does satisfy regulations, they may just be setting themselves up to an…

The locality where data rests on disk shouldn't matter for the legal process of getting access to it, and the US law takes this position. Otherwise we're going to have rampant protectionism under the guise of data protection which is part of the EU regulatory apparatus.
Post reply on HN