5 ms·
No, they cannot https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ You probably refer to "legitimate interests". If you play that card, yo
by anticristi 3y ago
No, they cannot https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
You probably refer to "legitimate interests". If you play that card, you are required to show a "Legitimate Interest Balancing Test", in which you show that your interests are arguably more important than the interest of the consumer: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
Source: I love to watch Facebook becoming the first GDPR unicorn, i.e., a company with more than 1 billion € GDPR fine.
- JumpCrisscross 3y agoGDPR isn't a good fit for the American system. The principles that animate it [i.e. rights of access (Art. 15), erasure (17) and objection (21)] should be incorporated into law. But a combination of public and private enforcement, plus a strong civil regulator (but one who isn't obligated, by law or practice, to respond to complaints), is a better start. > watch Facebook becoming the first GDPR unicorn They're paying $725mm to users in America [1]. Difference being the damages go to users, not a regulator. [1] https://www.popsci.com/technology/meta-725-million-lawsuit-cambridge-analytica-settlement/ https://www.popsci.com/technology/meta-725-million-lawsuit-c...
- mindslight 3y agoThe problem is that no form of data personal protection is really a good fit for the American (political) system, because the US leans heavily into the fallacy that if it's legal for one individual to do some as private activity, then allowing to be scaled up to mass corporate behavior is inherently reasonable. So telling Surveillance Valley to stop building Stasi 2.0 is akin to telling your friends that they must forget your birthday. Furthermore, the American concept of "consent" mostly functions as a legal fiction whereby less powerful parties are coerced into signing a bunch of binding legal documents. Hence the desire to copy the GDPR verbatim - because if a privacy law used the American version of "consent", why even bother? One way to port the overall idea of the GDPR into the US legal system might be to define a non-transferable property right in personal information (information about yourself), which could only be licensed revocably. Those two key bits would be tough though, given widespread deference to the Coase fallacy that has blessed much corporate looting.
- JumpCrisscross 3y ago> no form of data personal protection is really a good fit for the American system Not true. We have the Privacy Act of '74, HIPAA, GLBA and COPPA, to say nothing of e.g. California's CCPA and Virginia's CDPA [1]. Or Illinois' biometric privacy protections [2]. > the US leans heavily into the fallacy that if it's legal for one individual to do some as private activity, then allowing to be scaled up to mass corporate behavior is inherently reasonable This is true for rights, which don't get diluted through assembly. Not rules or the law. Plenty of laws exempt small businesses and natural persons. > the American concept of "consent" mostly functions as a legal fiction whereby less powerful parties are coerced into signing a bunch of binding legal documents Not entirely true. See: EULA enforceability as it pertains to natural persons [3]. > to define a property right in personal information (information about yourself), making it non-transferable and revocable at any time One generally defines a property right to enable transferability. Revocable property isn't property, it's a license. Making information one's inalienable property that can only be revocably licensed sounds neat, but it doesn't add value over enumerating data rights. [1] https://www.comparitech.com/data-privacy-management/federal-state-data-privacy-laws/ https://www.comparitech.com/data-privacy-management/federal-... [2] https://www.jacksonlewis.com/sites/default/files/docs/IllinoisBIPAFAQs.pdf https://www.jacksonlewis.com/sites/default/files/docs/Illino... [3] https://en.wikipedia.org/wiki/End-user_license_agreement#Enforceability_of_EULAs_in_the_United_States https://en.wikipedia.org/wiki/End-user_license_agreement#Enf...
- mindslight 3y ago> This is true for rights, which don't get diluted through assembly Calling it "assembly" is disingenuous (this is directed at the legal canon, not you). Generally companies aren't just mere assemblies of people, but rather are separate legal entities whose members have limited liability. Just as it's accepted for a company to say to an employee "if you want to get paid your 1st amendment rights are irrelevant", it would be reasonable for the government to say "if you want to have a statutory liability shield, your 1st amendment rights are irrelevant for activities facilitated by the shield". > Not entirely true. See: EULA enforceability as it pertains to natural persons I didn't say there weren't exceptions. Just overwhelmingly when a new regulation is created that requires "consent", the main result is for there to be a new piece of paper that people are forced to sign to "give consent". Rarely is there spelled out a path where the individual can refuse to give consent and still obtain a service that didn't intrinsically require it. > Making information one's inalienable property that can only be revocably licensed sounds neat, but it doesn't add value over enumerating data rights. The value is that trying to carve out new rights is an uphill battle, whereas dovetailing into the customs of commerce might just be possible. For example you had mentioned carve outs in the various state attempts at privacy laws due to the 1st amendment. Whereas those carve outs (unfortunately) don't exist for copyright! But sure, I do support trying to carve out completely new rights to repudiate our burgeoning surveillance society. It's just that the way the legislative process works in this country, it will be an amazing feat if the drafting process doesn't end up gutting most individual rights while still creating a bunch of red tape to stifle competition. Hence the attraction to copying GDPR wholesale and letting the courts sort it out.
- Hamuko 3y ago>Difference being the damages go to users, not a regulator. Doesn't a class-action lawsuit just mean that like a third of it goes to private law firms?