3 ms·
If it's a US site, I know that's a promise that it can't really make, due to US laws. If it's a EU site, then I could hold them legally responsible if it's just
by janto 5y ago
If it's a US site, I know that's a promise that it can't really make, due to US laws. If it's a EU site, then I could hold them legally responsible if it's just theater.
- rpdillon 5y agoThis hits the heart of the issue: how would you know if it's "just theater"? And if you did somehow find out, holding a random site legally responsible (I'm assuming you mean suing them?) will be dicey...even notable European sites don't comply with GDPR (the one example mentioned elsewhere in this thread was https://www.consilium.europa.eu/en/ https://www.consilium.europa.eu/en/, but I'm sure that's not an isolated instance).
- janto 5y agoFor larger businesses, relying on whistleblowers or auditing might be one way. For smaller ones using tools like the one discussed here. Or maybe a browser plugin that automatically notifies visitors. https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ "... is an overview of fines and penalties which data protection authorities within the EU have imposed under the EU [GDPR]"
- rpdillon 5y agoAh, I see, I think we're talking past one another. I was critiquing this approach from a technical perspective, since once data is sent over the wire, I don't know of any good way to figure out what's being done with it, and whether in complies with any given policy (including GDPR). E.g. we can see if the _browser_ is connecting to Cloudflare in the US, but what if a connection to a US server is happening on the backend? If I'm understanding your point, it's more along the lines of: "Lots of people are looking into this sort of thing, and we can aggregate resources about their findings." This makes sense to me, but wasn't what I was intending to critique.
- janto 5y agoThere can indeed be lots of magic going on in a backend and various ways GDPR violations may or may not be discovered. Here's an amusing 320k euro fine https://ico.org.uk/media/action-weve-taken/enforcement-notices/2616741/doorstop-en-20191217.pdf https://ico.org.uk/media/action-weve-taken/enforcement-notic... On 24 July 2018 the MHRA had executed a search warrant at the premises of Doorstep Dispensaree under the Human Medicines Regulations. In the course of its search, the MHRA discovered, stored in a rear courtyard, 47 crates, 2 disposal bags and 1 cardboard box full of documents containing personal data. MHRA estimated approximately 500,000 documents but cannot estimate the number of data subjects. MHRA have inspected the crates and the information contains: a. Names b. Addresses c. Dates of Birth d. NHS Numbers e. Medical Information f. Prescriptions The dates on the documents range from January 2016 - June 2018. The documents were not secure and they were not marked as confidential waste. Some of the documents were soaking wet, indicating that they had been stored in this way for some time. I doubt there is a purely technical solution to finding this kind of problem :) Edit: to be clear, the violation type here seems to have been "Insufficient technical and organisational measures to ensure information security"
- jtbayly 5y agoIn other words, the big claim that the GDPR applies to every site in the world... is not true. Just like I've said from the beginning.
- janto 5y agoActually, it could be applied in an extraterritorial way. The GDPR applies to processing of data of individuals located in the EU/EEU and states the rights of these "data subjects". If your business violates the GDPR and wishes to also operate within the European Economic Area, it could face fines and penalties.