Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

81–90 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#81
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me.

They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it.

I mentioned that my full name is globally unique, but they refused. I tried to ask them to share some masked data that I can confirm in full (e.g. "give me a partial address and house number, I can give you the full address"). They refused.

They definitely try to make it hard for you, and to dodge responsibility.

Re: How to effectively evade the GDPR and the reach of the DPA

#82
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

How does this apply to Clearbit which saves the Google Contact list of everyone who installs their extension [0][1] and then sells this data [2] ?

They have >150K extension users, so they are syncing a massive contact list with personal information that they are then selling via their different products like Prospector [3].

[0] https://connect.clearbit.com

[1] https://chrome.google.com/webstore/detail/clearbit-connect-s...

[2] https://clearbit.com

[3] https://clearbit.com/prospector

Re: How to effectively evade the GDPR and the reach of the DPA

#83
Typical of this kind of regulation: the real purpose is less about ensuring individual rights and more about giving bureaucrats more power. The GDPR is great in the latter sense. It’s impossible to predict the outcome of a legal process even if you do your very best to comply, and you can be slapped with incredible fines... Cross the wrong bureaucrat and your days are numbered (in an economic sense).

Re: How to effectively evade the GDPR and the reach of the DPA

#84
post #64
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Would anyone actually be upset to discover that apollo.io was no longer tracking their information?

Re: How to effectively evade the GDPR and the reach of the DPA

#85
Fundamentally the thing which everyone is missing is that the regulatory authorities can simply say that the data can not be used within the European Union by Rocket Reach. They may not be in the European Union but they can make their product useless in the European Union.

Re: How to effectively evade the GDPR and the reach of the DPA

#86
post #72

Earlier quoted context omitted.

Ultimately, adtech has to broker between publishers and advertisers. If those have any business in EU, they will be liable for the data, even if the broker is outside of jurisdiction.

But the publisher and advertiser might not know where the data came from. The broker could easily just say "oh yeah, we have permission from these people to share this data". I'm sure some of them will get caught, but how long will that take?

A free-market solution would be to establish strict liability for the publishers and advertisers, regardless of intent. Establishing liability creates an incentive to manage the risk, and therefore establishes an insurance market. The insurance companies would gather additional information in order to price the insurance accordingly, including audits of the data brokers and determining risk factors of each data broker. Doing business with a disreputable data broker would then lead to higher insurance premiums. While this cost would larger be passed through to the purchaser (the companies purchasing adtime), the cost would be lower for advertisers that deal only with reputable data brokers and follow best practice, thus having a market advantage for well-behaved advertisers.

Granted, this relies on several levels of the efficient market hypothesis. At some point, it is more efficient to ban poor behavior than to introduce 3rd-order effects that slightly discourage poor behavior.

Re: How to effectively evade the GDPR and the reach of the DPA

#87
post #57

Earlier quoted context omitted.

There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway." Every time I insisted they take it down, right now. Every time they have complied. There's so many it's basically pulling weeds at this point. The scarier companies are the ones collecting pictures of your face to train their private facial recognition softw…

Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening". Well played. Absolutely legal but totally immoral

But is it true? If not then I'm pretty sure in the UK at least there's some law against it.

Re: How to effectively evade the GDPR and the reach of the DPA

#88
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be.

In other words, it's not a bug, it's an accidental feature.

Re: How to effectively evade the GDPR and the reach of the DPA

#89
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

> They definitely try to make it hard for you, and to dodge responsibility.

Yes, but at the same time you do not want them handing over all your data with zero checks on identity right..?

Re: How to effectively evade the GDPR and the reach of the DPA

#90

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

EU can and should sanction such businesses, individuals behind it and their suppliers . Basically, just do the same as USA does to Nord Stream 2. This will be painful enough.

And their clients, if necessary.
Post reply on HN