How to effectively evade the GDPR and the reach of the DPA
1–10 of 200 posts
Re: How to effectively evade the GDPR and the reach of the DPA
#2LOL, yes.
I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others.
Likewise, various EU corporations do not meet the legal requirements of non-EU places like those. Would he prefer that they did?
Even more interesting, since he expects the US to follow EU law, how does he feel about the EU following US law? The US has that Patriot Act, and lots of EU companies are not compliant. Maybe he should report a few EU companies to the FBI.
Re: How to effectively evade the GDPR and the reach of the DPA
#3I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved.
That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve currency (trading in USD requires the transaction to route via the US, thus making the entity subject to US law).
The EU doesn't have such status or power over US companies. The most it can do is try to prevent them from operating in the region.
As a person who almost certainly has his personal information being sold on this platform, I'm not pleased, and would love to see something done to prevent this kind of activity. Unfortunately, that depends on the US government to take action, and the last 12 years haven't been a flying endorsement of the effectiveness of the current government system. (This is not meant as an statement regarding the effectiveness of either President, but rather a regarding the low output from the system as a whole)
Re: How to effectively evade the GDPR and the reach of the DPA
#4Re: How to effectively evade the GDPR and the reach of the DPA
#5Re: How to effectively evade the GDPR and the reach of the DPA
#6I assume that in the coming years (or decade?) there will be more efforts to ensure the enforcement of EU law for foreign companies that offer services to EU citizens as part of trade deals.
Right now there's e.g. a flourishing industry of data brokers in Israel that illegally collects data from EU (and US) citizens and sells it, a practice which is hard to stop as well since most of these companies don't have offices in the EU.
I think another possible strategy would be to go after the clients of these companies. If they can't legally sell their data to companies in the EU or US their business model would falter. The GDPR actually mandates that you as a data controller validate that companies which process data for you adhere to GDPR principles. Right now it seems this isn't being enforced much yet but I think it will be soon, which hopefully will have an effect on data brokers outside the EU as well.
Re: How to effectively evade the GDPR and the reach of the DPA
#7Re: How to effectively evade the GDPR and the reach of the DPA
#8Asserting a bunch of rights around personal privacy is great, but I've yet to see any compelling evidence that the relevant courts and bureocracies are capable of enforcing the law effectively. EVERYBODY is cheating.
Every time this is brought up on HN, the response is to wait for when the big fines start coming.
It's been two years. They're not coming.
Re: How to effectively evade the GDPR and the reach of the DPA
#9"Rocketreach has not met the requirement of the GDPR to name an EU representative (Art27) to account for the processing of European Personal Data. In their answer, the CNPD makes it sound like it is optional, it isn't. Instead of pursuing Rocketreach locally on that basis alone" LOL, yes. I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. Likewise, various EU corporat…
Likewise, EU companies should follow US law when they are doing business in the US.
Businesses should not operate in jurisdictions where they can't meet the legal requirements. At the very least, RocketReach should geoblock itself in Europe.
Re: How to effectively evade the GDPR and the reach of the DPA
#10Does GDPR apply here? They might not be selling to the EU, and they aren’t monitoring EU persons but just selling historic information. I don’t read GDPR as applying globally to any and all trade in EU personal data. https://gdpr.eu/companies-outside-of-europe/