Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

91–100 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#91
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

They obviously need to have a process to validate identity, and it's ridiculous to think that they would tailor that process for every request.

It's also odd that you would want to give them your NEW address if they are likely validating against your OLD address.

Why didn't you just give them your OLD address to check against?

Re: How to effectively evade the GDPR and the reach of the DPA

#92
post #35

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up. And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either. I somehow managed to…

There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway." Every time I insisted they take it down, right now. Every time they have complied. There's so many it's basically pulling weeds at this point. The scarier companies are the ones collecting pictures of your face to train their private facial recognition softw…

> There's so many it's basically pulling weeds at this point.

...and they are often run by the same people. They use shell companies to basically avoid take-down requests.

Their goals is to make it sufficiently annoying to take down your information, that most people give up. While at the same time removing it (regardless of the process) for anyone that occupies them too much time - because your individual data isn't valuable enough to waste defending against a take-down.

I suspect a (faux) lawyers letter is easier to get these takedowns processed than the calls/emails that most people try.

Re: How to effectively evade the GDPR and the reach of the DPA

#93

Typical of this kind of regulation: the real purpose is less about ensuring individual rights and more about giving bureaucrats more power. The GDPR is great in the latter sense. It’s impossible to predict the outcome of a legal process even if you do your very best to comply, and you can be slapped with incredible fines... Cross the wrong bureaucrat and your days are numbered (in an economic sense).

Ops, that was obviously a controversial standpoint. Just to be clear: I’m all for individual rights. But laws need to have predictable consequences and be fairly and equally enforced, and my impression is that the GDPR is not. As an example I’m pretty sure the local court here in Malmö, Sweden has violated my rights under the GDPR. Do you think anybody would give a rats ass if I complained? I highly doubt it...

Re: How to effectively evade the GDPR and the reach of the DPA

#94

Now watch the entire currently-EU based adtech industry relocate out of the EU...

It’s like drug cartels relocating from Mexico: noone will feel sorry.

They would be relocating their corporation only - they'd still be operating in the EU on EU customers.

Re: How to effectively evade the GDPR and the reach of the DPA

#95

Earlier quoted context omitted.

I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me. They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it. I mentioned that my full n…

Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be. In other words, it's not a bug, it's an accidental feature.

I am sorry, how does that resolve the issue of them operating illegally?

The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up.

If this is an accidental feature it means you should be accidentally run out of business.

Re: How to effectively evade the GDPR and the reach of the DPA

#96
post #64

Earlier quoted context omitted.

> And when you do request them to remove the same, they ask you to provide ID proof. On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you. It gets even worse when you realize that people can request all the…

Ok but he didn't subscribe on that website.

OP here - That's the point. They are not a data controller by that very simple fact. They are processing this data on an illegal basis. Any lawyer around that want to assist me suing in the US?

Re: How to effectively evade the GDPR and the reach of the DPA

#97
> Do we need a European Institution that handles extra-territorial investigations and fines?

No.

> Why should it take the time, money, and energy from an individual when the DPA is supposed to defend the rights of the data subjects?

Because it's your own problem. Do you think some blue collar worker should be taxed to subsidize your safety or privacy on the internet outside of the EU?

Re: How to effectively evade the GDPR and the reach of the DPA

#98
post #8

When are we going to admit that GDPR is a failure? Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating. Every time this is brought up on HN, the response is to wait for when the big fines start coming. It's been two years. They're not coming.

Some pretty big fines have been issued already. See: https://www.enforcementtracker.com/ Over time I expect them to go up further as companies can no longer claim they did not have enough time or were not aware of the law (that never was a defense anyway but DPAs tend to be lenient. So far). Since the GDPR has come into effect I see in my practice that companies are a lot more aware of their responsibilities towards…

I dont know.

From what I can understand of German/Google translate, the third from top:

https://www.enforcementtracker.com/

Link to .pdf:

https://www.ris.bka.gv.at/Dokumente/Dsk/DSBT_20180927_DSB_D5...

Is the Austrian Authorities making a 300 Euro fine to a "common citizen" making "illegal" use of a dashcam (it seems - but I am not sure about it - that the issue is that the car is not - how? - visibly marked as videorecording?).

Anyone more familiar with German (and legal German) can clear the matter/explain?

Re: How to effectively evade the GDPR and the reach of the DPA

#99
I had a similar experience with a company called RateSetter.

- They email me some marketing

- I respond with DSAR

- They acknowledge receipt of DSAR

- 6 months pass

- I bump the email thread

- They respond saying they have deleted my data as per my request (I requested access, not deletion)

- I point this out

- They apologise and offer £100 to drop the complaint

- I refuse and complain to ICO

- Obviously nothing happens

GDPR is toothless.

Re: How to effectively evade the GDPR and the reach of the DPA

#100
post #7

Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/

GDPR applies, it has worldwide scope for data on EU citizens. On the other hand, European courts lack jurisdiction to enforce their laws on companies without EU offices and assets. FWIW I'm really glad that EU courts lack this jurisdiction - any gain from privacy would more than be wiped out from losses to free speech, especially with the extensive history of libel tourism.

> GDPR applies, it has worldwide scope for data on EU citizens

Not quite. It applies to people who are "in the Union".

There is a very large overlap between "EU citizens" and people "in the Union", so most of the time there is no need to make the distinction but it is there.

Post reply on HN