4 ms·
https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ I see ten fines applied to big tech companies that are over 10 million Euro and three t
by s_dev 5y ago
https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
I see ten fines applied to big tech companies that are over 10 million Euro and three that are over 50 million Euro.
GDPR is definitely being enforced but mostly on big tech companies not small ones which I'd imagine is part and parcel of the intent of the regulation.
- kiba 5y agoIt's the annoying banners and all the likely useless business information that sites think worth collecting.
- Nextgrid 5y agoCompare the amount total fine amount to Google or Facebook with their yearly profits, the majority of which are earned by illicit data collection. Not to mention, to this day both these companies are still breaching the GDPR, so the fines clearly didn't have any effect and they are still happy to continue acting in bad faith regarding personal data.
- _v7gu 5y agoThe reason the fines are low is because they exist to push for compliance, not to punish. That's also why they are increasing up to 4% global revenue. If that's not enough, the maximum can always be increased. More money for the EU countries. It's really funny how US-oriented thinking made HN go up in arms about how GDPR fines were too excessive to how ineffective they are meanwhile the fine structure didn't change at all.
- Nextgrid 5y ago> they exist to push for compliance, not to punish Well that clearly doesn't seem to be working. > It's really funny how US-oriented thinking made HN go up in arms about how GDPR fines were too excessive to how ineffective they are meanwhile the fine structure didn't change at all. Just FYI I'm UK-based and never had any of these US-centric concerns regarding the GDPR.
- _v7gu 5y agos/US/common law/ The fines are not enough right now, but they'll just keep on increasing until compliance is satisfied. There's no reason to start high and bringing small companies to ruin when everything will work out in the long term
- pgeorgi 5y ago> Well that clearly doesn't seem to be working. Those "privacy score cards" for apps on both iOS and Android, filled out for 1st to 3rd party apps? GDPR in action. The ability to reject tracking (which might cost money for a subscription or something - which will actually be tracking-free, instead of earning on both ends of the market, by selling a subscription _and_ tracking the hell out of their customers)? GDPR in action. There are some dark patterns around the cookie consent popups, but it's up to people to report them, there's no EU privacy police squad digging up these cases on their own. There are only so many hours Max Schrems can spend every day (it's rumored to be 24hs or less, except maybe for one day a year) on running his non-profit to do that for you, me and everybody. That stuff has ramp-up time, and as mentioned, the goal is compliance, not collecting fees. As practices _under GDPR_ are becoming established, and stuff went through court a few times, I'd expect schedules for compliance to shorten. It would be a PR disaster for all things privacy if DPAs were to go all in on some case (taking 4% of global annual revenue), then losing the case in court. Given how many media companies are big in advertising and surveillance tech as well (with media mostly existing to attract eyeballs for their "real" business[0]), there'd be no end to the assault on privacy. Rather take it slow. [0] e.g. https://venturebeat.com/2015/09/29/business-insider-buyer-axel-springer-just-lost-its-case-against-adblock-plus/ https://venturebeat.com/2015/09/29/business-insider-buyer-ax... "Adblock Plus said Axel Springer’s lawyers asserted that “The core business of the plaintiff is to deliver ads to its visitors. Journalistic content is just a vehicle to get readers to view the ads.”"
- Nextgrid 5y ago> Those "privacy score cards" for apps on both iOS and Android The GDPR already requires clear disclosure for data processing. If the "privacy score cards" were due to the GDPR then we should've seen them 3 years ago. The privacy score cards actually demonstrate the lack of enforcement of the GDPR. A private company (Apple) successfully did something in a few months that the regulation couldn't in years. That shows how these potential "4% of global revenue" are really seen and they're not as threatening as they sound. > The ability to reject tracking Where? The vast majority of apps and websites still include Facebook SDK malware and similar, and in the rare cases where they actually do ask for consent there's no easy "decline" option, or the decline option is a sham (as in "disable cookies in your browser so we fall back to browser fingerprinting"). > but it's up to people to report them, there's no EU privacy police squad digging up these cases on their own [...] There are only so many hours Max Schrems can spend every day [...] on running his non-profit to do that for you, me and everybody. This seems like a problem if the effort of investigating breaches is offloaded to laypeople, especially when finding out non-compliant cookie banners can be done automatically with a trivial web scraper. > It would be a PR disaster for all things privacy if DPAs were to go all in on some case (taking 4% of global annual revenue), then losing the case in court. Why is doing nothing considered better then? In either case nobody is complying with the regulation. At least an in-progress court case (that's likely to take years) is going to be a much bigger threat than current situation of nothing.
- techpression 5y agoThe only decent fine was the Amazon one and even that one was minuscule compared to their net income. It was also covered in secrecy and will likely be overturned and drastically lowered like the other big cases like British airways and Marriott. This for a law that took four years to finalize, to me it sums up to a very mediocre outcome, at best. You are right that it’s being enforced, there’s just not very much force in the enforcing.
- s_dev 5y agoWhats app was fined 250 Million. It might be a small % of their revenue but it's a significant cut of their profits for that year.
- C19is20 5y agoWhere do(es) the [income from the] fine(s) go?
- Nextgrid 5y agoIs WhatsApp still a separate company? The real reason WhatsApp exists is to provide Facebook a backdoor into people's contacts so they can infer their social graph. Whatever "revenue" WA earns is peanuts, the real value is the collected data.
- techpression 5y agoIf you only look at it as pure loss, which would be wrong, WhatsApp (Facebook) most likely made a lot more money (and will continue to so) with the data, than they were fined.
- still_grokking 5y agoThat's simply not true. That is a laughable case count compared to all the violations just everywhere. If it would be enforced all of US BigTech would need to be outright banned from the EU until the US fixes its no-go issues like CLOUD Act or that secret FISA court. That's the one part. The other part is that also almost no domestic companies comply. More or less every business and all the country governments in the EU breach the GDPR in one or another way (for example by using US BigTech products behind the scenes as all governments do, or simply just collecting personal information without consent labeling it "legitimate interest" like almost every websites does). All big German media outlets have for example right now a case in court for noncompliance with the GDPR. It will take years in court of course, and than nothing will happen, as every time before. The same goes for things like "Privacy Shield v3.0" the EU Commission is working on. This new version is obviously illegal for the same reasons as it was the case for v1 and v2. But they don't care. The courts need many years to stop it again. Until then this illegal regulations that obviously violate the GDPR will stay in place.