Live data from Hacker News

Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

autoriteitpersoonsgegevens.nl

81–90 of 414 posts

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#81
post #4

Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.

Instances like this really make me feel that capitalism is devoid of any morality. If there's no law guarding it, a company will abuse its power in order to make more money. It could be a morally good thing, a morally bad thing, it doesn't matter: more money is more money. It feels heartless. I wish there was a better system.

Capitalism is absolutely amoral, and has always been.

I'm honestly curious (and adding this as a disclaimer to be clear it's not an attack): why would you think there was any shard of imbued morality when the whole point of the system is based on greed?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#82
post #76
post #75

Earlier quoted context omitted.

This article[1] by the Dutch DPA has some details about it: The Privacy Shield was invalidated in 2020, leaving only the Standard Contractual Clauses as a valid transfer tool. Uber stopped using Standard Contractual Clauses in August of 2021, before adopting the new Privacy Framework in 2023. For a period of two years they were transmitting extremely sensitive information without a valid way to do so. [1]: https://ww…

Thanks. That gives a lot more information. With respect to the new framework, the article you linked to just says "Since the end of last year, Uber uses the successor to the Privacy Shield." Do you know if the Dutch DPA endorsed the new framework, or did they leave it ambiguous/unresolved as to whether post-2023 transfers are GDPR compliant?

I don't think endorsing the new framework is something the DPA does. The EC declared the new framework adequate[1], Uber got certified for it[2], so there is now a valid method in place for Uber to transmit data.

[1]: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... [2]: https://www.dataprivacyframework.gov/list (no deeplinks for some reason)

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#83
post #4

Love it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.

[flagged]

GDPR fines won't ever repair any national budget, you're being cynical.

> Domestically these countries have entities collecting personal data in the same evil way as US entities

Can you provide sources for this allegation?

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#84

[flagged]

> In other words: the inner workings of a company are by definition a black box and only an insider can leak screenshots or damning data to prove they break a law in the first place.

In reality, no one gets fined based on whims and wishes, but after investigations, just like in this case:

> The DPA said it started the investigation after more than 170 French drivers complained to a French human rights interest group, which then filed a complaint to France's data protection watchdog.

> Under the GDPR, a business that processes data in several EU countries must deal with the data protection authority where its main office is located. Uber's European headquarters are in the Netherlands.

https://www.lemonde.fr/en/economy/article/2024/08/26/uber-fi...

Seems the investigation uncovered that Uber didn't process data in their European headquarters but instead sent the data to the US, otherwise there obviously wouldn't be any basis for the fine.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#85
post #32

Meanwhile the UK handed all of its patient medical records to Palantir.

Palantir runs on the customer’s own cloud, or a major cloud provider of the customer’s choosing in the region of their choosing. There’s no data aggregation/sharing across customers, it works similar to AWS.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#86
post #22

Earlier quoted context omitted.

GDPR was never annoying banners, that's just malicious compliance.

Since GDPR every interaction with public administration, healthcare, and employer within EU results with additional form or two "oh that's just a GDPR form, you have to sign it". I imply they are all malicious as well?

Yes, because there are specific exceptions in the GDPR that allow data processing and storage in many of these cases. However, managers are pissed off by the law, or just ignorant, and they make you sign a document that has no legal value.

Heck, many documents that I saw while interacting with P.A. in my country are lacking the basics, such as "what are you doing with the data".

One clinic once made me sign a document where they said that I received a copy of the privacy policy (which was not given to me). I politely asked for the privacy policy, and they sent me the entire GDPR regulation PDF. I spent one hour explaining to them that they need to fix it.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#87
post #3

[flagged]

> How would the government even know that a big company is transgressing the rules? By investigating a complaint? From the article: The Dutch DPA started the investigation on Uber after more than 170 French drivers complained...

Your comment and the article however don’t explain what the group complained about and how did they know data was being transmitted to the us, though.

Did they made the allegations up and they happened to be right? I don’t think that’s the case.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#88

[flagged]

If a company operates in a country, they have to agree to audits. In this case - and I can't find any details about it - a group of French drivers made a complaint, presumably because they were aware that something fucky was going on with their data. It was enough of a lead to trigger an audit, to which the company has to cooperate with.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#89
post #80

Earlier quoted context omitted.

So you would say these systems are no true scotsmen ?

No. If you go looking, you will find plenty of counter-examples in History. You just made a statement that the top handful of catastrophic examples were representative of the bunch. You have massive selection bias in your sample. “Morally-based decision ends well” is not exactly something that makes headlines or that is seized upon by historians to explain memorable cataclysmic events. You don’t need to be an ethics…

You are carefully trying to stay vague and are avoiding to name even a single counter-example. You are just claiming that my examples are wrong. This is the definition of a "No true Scotsman" fallacy.

Name one non-capitalistic system more moral than the currently existing ones.

All rankings trying to quantify morality and order societies by it, are consistently topped by social market economies, a form of capitalism.

> Waving away all morality in moral nihilism is teenage-level ethical sophistication.

It is also something I have never done. With the edits to your post, its nature became more and more apologetic to dictatorships. I hope this was not what you have intended.

Re: Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US

#90
post #87
post #3

Earlier quoted context omitted.

> How would the government even know that a big company is transgressing the rules? By investigating a complaint? From the article: The Dutch DPA started the investigation on Uber after more than 170 French drivers complained...

Your comment and the article however don’t explain what the group complained about and how did they know data was being transmitted to the us, though. Did they made the allegations up and they happened to be right? I don’t think that’s the case.

Under GDPR an EU citizen has right to request the details of how their personal data is collected and processed. This and, for example, checking the traffic with your data (eg IP address of sender of an email from CRM) would be enough.
Post reply on HN