11 ms·
This is a good start, but I'm going to be very curious to see if EU data law ever starts getting enforced against european companies at scale, as opposed to int
by InTheArena 3y ago
This is a good start, but I'm going to be very curious to see if EU data law ever starts getting enforced against european companies at scale, as opposed to international companies.
- FirmwareBurner 3y agoIt does get enforced against European companies, they just don't make HN headlines because they're not big-tech so nobody here would have heard of them. Also EU companies tend to be more mindful and take data protection very seriously, even before GDPR was a thing, so finding gross offenders is a rare occurrence anyway.
- personomas 3y agoWhich ones?
- _puk 3y agohttps://www.enforcementtracker.com/ https://www.enforcementtracker.com/ Ironically, currently 2023 entries.
- personomas 3y ago[flagged]
- hef19898 3y agoHeadquarted countries founded in the EU? Please, tell me more, I always wanted my own nationstate!
- personomas 3y agoObviously I meant to write "companies" not countries. (fixed.)
- deleted 3y ago[deleted]
- cccbbbaaa 3y agoFrance against french companies: 40M€ for Criteo, 1M€ for Total, 1M+€ for AG2R, 2M€ and 800000€ for Carrefour, 600000€ for EDF, same for Accor, two 300000€ fines for Free, 125000€ for CityScoot, 500000€ for Brico Privé, 400000€ for the RATP. Perhaps others, didn't bother to check any further.
- personomas 3y ago[flagged]
- interactivecode 3y agoSo you haven't researched the actual fines and warnings the EU gave out to EU and non-EU companies. but you just feel like the vibes are totally off? I was really expecting better comments from hackernews. If we're talking about vibes you should acknowledge that it makes sense for the EU to protect their people and their personal information from really large foreign companies. Even more so from companies that are aligned with the state that has one of the largest military powers in the world.
- Timon3 3y ago> I was really expecting better comments from hackernews. You really shouldn't on topics related to the EU. There is an incredible amount of misinformation peddled, and asking for sources or actual analysis beyond simple statements that keep being repeated is usually met with either silence or insults.
- personomas 3y ago[flagged]
- cccbbbaaa 3y ago>Good research No. All I did was opening enforcement tracker, click on France, and look for familiar names. It was faster than writing my previous comment. I knew about one of the Carrefour cases, and the Criteo case though. >The authoritarianism and the insanity of the laws in the first place is/are a far bigger problem What is authoritarian or insane in GDPR? Or its previous iteration, the DPD (from 1995)? Oh no, we expect companies to handle personal data with care, the horror.
- jeroenhd 3y agoThe Netherlands DPA has fined CP&A, an unnamed orthodontic clinic, Transavia, a local political party, the municipality of Enschede, Booking.com B.V. (yes, Booking.com is Dutch), OLVG (a hospital), a redacted data trader, the Dutch national tennis association, an insurance company, another hospital, a semi-governmental organisation and 7 governmental bodies. Some of these do business in foreign countries, but all of them are unmistakably Dutch. I've left out the largest news organisation in the Netherlands, the Belgian company BPG Media, but they have bought up a bunch of local news organisations. Non-EU-originating companies on the list: - Tiktok - locatefamily.com Tiktok got fined by the Dutch DPA for not providing their privacy statement in Dutch while still doing business in the Netherlands. Further research into Tiktok was transferred to the Irish DPA (this fine). I suppose the Dutch DPA could've lodged a complaint with the Irish DPA for not providing the necessary documents in Dutch, but that seems rather silly to me. locatefamily.com did not have EU representation at all so there was no need to process the complaint anywhere else. I doubt the fine will ever be collected, but who knows, maybe the owners are stupid enough to open a business in Europe somewhere down the line.
- personomas 3y ago[flagged]
- hef19898 3y agoJust stop trolling...
- wincy 3y agoIsn’t SAP absolutely massive? Surely they count as big tech. Edit: for anyone wondering SAP has ~110,000 employees worldwide, Google has ~180,000, so comparably mega scale tech company.
- FirmwareBurner 3y agoWhen did SAP breach GDPR?
- izietto 3y agoSAP isn't a social platform, it isn't even B2C, so they don't really relate to GDPR
- esarbe 3y agoThe GDPR applies to all companies, social network platforms or not. It's not even about the internet in particular, it's about how companies can store and process private information of EU citizens.
- hef19898 3y agoSAP is B2B, the vast majoritybof personal data is professional (supplier and customer business contacts) and emoloyee data (payroll and such). Not much to fine here. Also, since SAP as a company isn't handling any of that data, SAP isn't really affected.
- generic92034 3y ago> Also, since SAP as a company isn't handling any of that data, SAP isn't really affected. I am not sure that is completely correct, considering SAP's cloud offerings.
- hef19898 3y agoWith EU based servers? Sure, GDPR applies. But so far I didn't hear anything about SAP not being compliant.
- deleted 3y ago[deleted]
- PurpleRamen 3y agoIs there any reason to do that? European companies are more likely to follow the laws already, and taking less liberty in bending or even ignoring them. Mostly because the people working there have a better understanding and focus of them. On the other side, European companies are usually smaller, so their get lower fines, which won't make the headlines. Which is, why you might not hear so often about the fines against European companies, which still happen. And if we are honest, we usually only hear about the super-penalties anyway.
- personomas 3y ago[flagged]
- esarbe 3y agoYou keep throwing around the "unbelievable" and "unreasonable" fines. Why do you think that these fines are "unbelievable" and "unreasonable"? Because for me they are rather on the low side, given the business practices, the reach and the potential for abuse that these companies have.
- personomas 3y ago1) They stopped it 3 years when their was an inquiry. 2) 2.6% of revenue for a company that isn't even profitable. 3) 2.6% of revenue for a global company, how much of this then is only EU revenue?? Are they supposed to get their legs cut off just for breaking one law of the 5 million that they're suppose to comply with? 4) This was a first offense for this company. 5) They're not doing anything harmful with the data. It's a social media platform. We need to relax. The burden should be on the parents.
- Lacerda69 3y ago>Are they supposed to get their legs cut off just for breaking one law Yes, they wont learn otherwise.
- personomas 3y ago[flagged]
- ubercow13 3y agoHow else would regulation work?
- personomas 3y ago
- izacus 3y agoIt's absolutely trivial to confirm that EU countries get fined all the time: https://www.privacyaffairs.com/gdpr-fines/ https://www.privacyaffairs.com/gdpr-fines/
- personomas 3y ago[flagged]
- makeitdouble 3y agoYou should clarify the difference you perceive and why you think it's an issue.
- rsynnott 3y agoIf you ignore Ireland and Luxembourg there (most of the big multinationals are subject to one or the other), then you'll get a much more balanced picture. For most of the countries, most of the top offenders are European.
- personomas 3y ago[flagged]
- hef19898 3y agoI would honestly expect someone with such weak opinions so strongly held like you to do their own homework.
- personomas 3y ago[flagged]
- rsynnott 3y agoThe website in the comment you were replying to _literally does exactly that_. Bloody hell, this website...
- layer8 3y agoSee for yourself here: https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- noirscape 3y agoThey kinda are but most EU companies just avoid it by not really collecting your data to begin with beyond what they need for service operation. At least in my experience, when I deal with a service in the EU, their privacy policy fits on a few A4s, with the important bits frontloaded and written in an easily understandable way. Even most banks don't really hide what they collect on you and they explain why they collect it. It's only foreign companies that tend to insist on massive privacy policies that border on being incomprehensible and use them to skirt the law. Seriously, just look at Googles privacy page for example - it's a single giant page that mostly just restates over and over "Google may collect info about you". It's unclear what the data is being used for, it's extremely reliant on other pages to detail what's being used and your average person has probably lost the plot by now. It's difficult to put it in any other way, but foreign companies are the ones who think they can get away with breaking the law and make it as difficult as possible to trace what they're doing with your data. European companies just tend to actually follow the law. That's why all the landmark cases are against foreign tech giants.
- scyzoryk_xyz 3y agoThe boardroom can’t argue about whether or not to steal from the cookie jar when there is no cookie jar to begin with. These are the moments I’m grateful to be living in the EU. GDPR was a huge circus of blame on EU bureaucracy back when it was introduced. A lot of hate poured out that every single paper you sign now needs to have a second separate GDPR thing for you to sign. Stupid Brussels making your life more complicated! But now everyone seems to be used to it.
- personomas 3y ago[flagged]
- Scarblac 3y agoAnd every organization in the EU has had to deal with the fact that this is now law, and had to think what they needed to change to comply with it. All companies, but also e.g. tiny volunteer run organisations (my local scouts group asks for health insurance, medical information, allergies etc of the kids again and again for every camp they go on because they don't keep the forms around anymore for the next one like they used to) . It's probably different for organisations coming from outside the EU who get EU customers over the Internet.
- rsynnott 3y agoLots of European companies have gotten fined. But also, primarily European companies did generally take it a lot more seriously than multinationals. (Sometimes too seriously; while this has calmed down a bit, you'll sometimes see companies enforcing absolutely absurd policies around data on the basis that they incorrectly think they're required for compliance).
- InTheArena 3y agoIn my experience, this is absolutely not true. Sometimes mind-boggling so. For example, it was US companies that stopped serving ads until they had GDPR infrastructure in place, while some very bad actors in the UK where not collecting consent at all.
- rsynnott 3y agoAh, well, the UK. The UK is special.
- jdminhbg 3y ago> european companies at scale Such a thing would need to exist before the EU would be able to fine it.
- lucideer 3y agoThere's plenty of EU companies getting fined: on top of the fact HN will naturally bias toward reportage on well-known US unicorns, there's also a language barrier: most reportage of fines outside of Ireland won't be in the English language. The Irish DPC is also reportedly quite busy, by virtue of shouldering a disproportionate amount of the enforcement work for non-EU companies (due to tax-driven HQing there). They have taken cases against European entities as well however: notably they even even taken cases against the Irish government for violations around mandating biometric public service ID cards.
- suction 3y ago[dead]