Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

71–80 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#71

Now watch the entire currently-EU based adtech industry relocate out of the EU...

I thought this was obvious. I've been saying since day 1 that GDPR won't help much with privacy. It might even do the opposite by making people feel that their data is safe. But a company beyond the jurisdiction of the EU can simply ignore GDPR and vacuum up all the data they want.

What will ultimately help with privacy is not leaking out this data in the first place. Push browsers and other such services/devices to stop leaking enormous amounts of information on the user.

That's not to say that GDPR isn't useful. It certainly is, because it stops the big legal businesses from doing it, but it also has the downside of harming European online businesses.

Re: How to effectively evade the GDPR and the reach of the DPA

#72

Now watch the entire currently-EU based adtech industry relocate out of the EU...

Ultimately, adtech has to broker between publishers and advertisers. If those have any business in EU, they will be liable for the data, even if the broker is outside of jurisdiction.

But the publisher and advertiser might not know where the data came from. The broker could easily just say "oh yeah, we have permission from these people to share this data".

I'm sure some of them will get caught, but how long will that take?

Re: How to effectively evade the GDPR and the reach of the DPA

#73
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

My understanding is that merely having a website that can be accessed from the EU may not by itself be enough to be subject to the GDPR. However collecting or processing data on EU citizens or residents certainly is. And almost all websites track users (even when it's not obviously useful to do so), so unless you go the USA Today route and create a site for the EU with no tracking, you have to comply.

There's also the question of who they sell the data to. It's hard to see why they would sell EU citizens/residents data to companies who don't have any EU presence themselves, so at least some of their customers are bound by the GDPR as far as these are concerned. Informed consent is required at every step, so for example they would need the EU subject's consent to buy that data from RocketReach.

Re: How to effectively evade the GDPR and the reach of the DPA

#74
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I have a complaint sitting agains Apollo.io as well. I'll make sure to post the outcome here.

Re: How to effectively evade the GDPR and the reach of the DPA

#75

Earlier quoted context omitted.

GDPR applies, it has worldwide scope for data on EU citizens. On the other hand, European courts lack jurisdiction to enforce their laws on companies without EU offices and assets. FWIW I'm really glad that EU courts lack this jurisdiction - any gain from privacy would more than be wiped out from losses to free speech, especially with the extensive history of libel tourism.

It’s hard to make an argument for the EU courts having that jurisdiction without also granting the same to Saudi Arabia and China.

The way it works is that the EU fines their EU-based operations or stops them from operating in the EU. And if they don't have any, those of their customers who do could not legally acquire their data on EU citizens without the subject's informed consent anyway.

Re: How to effectively evade the GDPR and the reach of the DPA

#76
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

You do know that US law is imposed everywhere in the world, right? DMCA notices and stuff like that.

Re: How to effectively evade the GDPR and the reach of the DPA

#77
The achilles heel of the GDPR is that you must act through a DPA. In the case of the Shrems he had to basically sue the Irish GPA in order for them to do their job. And instead of actually doing their job, the Irish DPA instead fought Shrems on behalf of Facebook.

As an EU citizen and resident, it's abundantly clear to me that getting a DPA to act in my best interest is mostly hopeless. I'm reminded of the CANSPAM Act where a US citizen can send their spam to the FTC and have them investigate it. Only they never will. All spam sent to the FTC just goes into blackhole, and next to no one is ever prosecuted. Even when it's clear who the spammer is.

I don't think many people realize this fact. That a politically motivated entity controls European's access to privacy restitution, and they're rarely motivated to actually do anything. This makes the GDPR is my eyes primarily a joke. It certainly isn't about securing my rights as an EU citizen. It seems more written to benefit lawyers and others who make money because things are complicated.

If the EU actually cared about my privacy rights they would allow all Europeans access to restitution without mediating it through national agencies. I want to be able to hire a lawyer and directly take abusive firms to court over GDPR violations. I shouldn't have to act via some pre-court mediator who gets to arbitrarily determine if my claims have merit.

Re: How to effectively evade the GDPR and the reach of the DPA

#78

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

Thanks, a reply like this is why I come to Hacker News!

Re: How to effectively evade the GDPR and the reach of the DPA

#79

Looks like rocketreach is aggregating information that is public on fb,linkedin etc. He forgot to mention that the google search result he got is already selling those, but maybe we ve become blind to that? Rocketreach is packaging and selling it directly, google does it indirectly. Same thing though, are those illegal?

Heh, I read that as "rocketroach" first.

Re: How to effectively evade the GDPR and the reach of the DPA

#80
post #19

Earlier quoted context omitted.

> The EU doesn't have such status or power over US companies. US companies operating in the EU are subject to EU law. Worst case the company itself doesn't operate in the EU, however that still leaves its customers (Intel, AirBnB, etc. ) potential targets to apply pressure on.

Does RocketReach have servers in the EU? Employees? Subsidiaries? I generally don’t know in this case. But in general my European friends seem to think that merely having someone from the EU access a website makes that website’s owner have a presence in the EU, even if the server that handled it isn’t. That seems like overreach to me. If that were the case, I’d block EU access for any of my domains, and I don’t think…

Why don't you just comply with EU regulation though? Just like we have to comply with the KYC/AML that the US forces on everyone.
Post reply on HN