Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/
GDPR applies, it has worldwide scope for data on EU citizens. On the other hand, European courts lack jurisdiction to enforce their laws on companies without EU offices and assets. FWIW I'm really glad that EU courts lack this jurisdiction - any gain from privacy would more than be wiped out from losses to free speech, especially with the extensive history of libel tourism.
How to effectively evade the GDPR and the reach of the DPA
61–70 of 200 posts
Re: How to effectively evade the GDPR and the reach of the DPA
#62Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/
Re: How to effectively evade the GDPR and the reach of the DPA
#63When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.
Can individuals sue and go to court? Or do complaints have to pass through privacy regulators. I’m curious how a class action hasn’t been formed around Verizon and Oath’s behaviour?
Re: How to effectively evade the GDPR and the reach of the DPA
#64This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…
On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you.
It gets even worse when you realize that people can request all the data the company has collected of themselves. What happens when somebody impersonates you and requests all of your data?
You need to have some kind of verification method that leads back to a real identity. Otherwise this can be massively abused. I doubt that even asking for a real ID is enough.
Re: How to effectively evade the GDPR and the reach of the DPA
#65Earlier quoted context omitted.
Your link is in reference to multi national companies. I don’t see how GDPR applies to companies that don’t do business with EU persons and without an EU presence.
They are selling into the EU though, right? So they do do business with EU persons.
Re: How to effectively evade the GDPR and the reach of the DPA
#66Earlier quoted context omitted.
Good riddance
They'll still be operating, and serving you ads, just beyond the reach of EU laws.
Re: How to effectively evade the GDPR and the reach of the DPA
#67This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…
> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…
Re: How to effectively evade the GDPR and the reach of the DPA
#68Re: How to effectively evade the GDPR and the reach of the DPA
#69I'd made a subject access request because they'd sold my personal email address linked to my business position to random spammers. That association didn't exist in any legitimately accessible data, only in the linkedin data breach.
Re: How to effectively evade the GDPR and the reach of the DPA
#70This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…
> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…
Don't delete instantly but after X days. Notify owner immediately.
Problem solved.