Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

61–70 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#61
post #7

Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/

GDPR applies, it has worldwide scope for data on EU citizens. On the other hand, European courts lack jurisdiction to enforce their laws on companies without EU offices and assets. FWIW I'm really glad that EU courts lack this jurisdiction - any gain from privacy would more than be wiped out from losses to free speech, especially with the extensive history of libel tourism.

It’s hard to make an argument for the EU courts having that jurisdiction without also granting the same to Saudi Arabia and China.

Re: How to effectively evade the GDPR and the reach of the DPA

#62
post #7

Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/

Well in reality it applies if the US wants to enforce such judgments. If myself, as the king of Monaco, I declare a law that says that US companies should pay a tax to pay for air that transited through Monaco (and hence was cleaned by Monaco's trees), it's perfectly valid.

Re: How to effectively evade the GDPR and the reach of the DPA

#63
post #13
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

Can individuals sue and go to court? Or do complaints have to pass through privacy regulators. I’m curious how a class action hasn’t been formed around Verizon and Oath’s behaviour?

There's currently no equivalent of a class action suit under EU law, IIRC. Some jurisdictions within the EU have something equivalent, but there's nothing Union-wide. I vaguely recall some movement by the Commission to establish something like that though a few years back, but I don't recall where it went.

Re: How to effectively evade the GDPR and the reach of the DPA

#64
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

>And when you do request them to remove the same, they ask you to provide ID proof.

On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you.

It gets even worse when you realize that people can request all the data the company has collected of themselves. What happens when somebody impersonates you and requests all of your data?

You need to have some kind of verification method that leads back to a real identity. Otherwise this can be massively abused. I doubt that even asking for a real ID is enough.

Re: How to effectively evade the GDPR and the reach of the DPA

#65
post #26
post #16

Earlier quoted context omitted.

Your link is in reference to multi national companies. I don’t see how GDPR applies to companies that don’t do business with EU persons and without an EU presence.

They are selling into the EU though, right? So they do do business with EU persons.

Unless the payment processor is in the EU, the courts would have no jurisdiction.

Re: How to effectively evade the GDPR and the reach of the DPA

#66

Earlier quoted context omitted.

Good riddance

They'll still be operating, and serving you ads, just beyond the reach of EU laws.

They then can't make business with European publishers or show ads for European businesses as those are liable. And showing ads for things not available in Europe isn't really bringing revenue from an European audience ...

Re: How to effectively evade the GDPR and the reach of the DPA

#67
post #64
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Ok but he didn't subscribe on that website.

Re: How to effectively evade the GDPR and the reach of the DPA

#69
Lusha in NY does this too except they claim the deletion magically happened automatically because of "algorithms".

I'd made a subject access request because they'd sold my personal email address linked to my business position to random spammers. That association didn't exist in any legitimately accessible data, only in the linkedin data breach.

Re: How to effectively evade the GDPR and the reach of the DPA

#70
post #64
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Electronic signatures tied to your ID.

Don't delete instantly but after X days. Notify owner immediately.

Problem solved.

Post reply on HN