13 ms·
Dutch DPA fines Uber €290M because of transfers of drivers’ data to the US
- deleted 2y ago[deleted]
- janandonly 2y ago[flagged]
- tpm 2y ago> How would the government even know that a big company is transgressing the rules? By investigating a complaint? From the article: The Dutch DPA started the investigation on Uber after more than 170 French drivers complained...
- znpy 2y agoYour comment and the article however don’t explain what the group complained about and how did they know data was being transmitted to the us, though. Did they made the allegations up and they happened to be right? I don’t think that’s the case.
- ivan_gammel 2y agoUnder GDPR an EU citizen has right to request the details of how their personal data is collected and processed. This and, for example, checking the traffic with your data (eg IP address of sender of an email from CRM) would be enough.
- codedokode 2y agoFor example, an email could come from US server containing their name. Or the website with the driver's account might be located on US server.
- bux93 2y agoThe DPA has powers of subpoena. They can basically raid the place. Usually, companies don't want this to happen and they co-operate. How exactly did the DPA know that Uber processes all data in their central IT department in the US? Uber probably told them and didn't try to pretend they have any local hardware or entity in charge of it. That would be a stupid thing to lie about? In any event the fine is mostly for not having adequate protections in place. Those protections? Better contracts between wholly-owned subsidiaries of Uber. So, not much protection at all! This is very much Uber shooting themselves in the foot by not doing their homework. Again. This is the DPA's press release: https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-d... The fine is here, and is 48 pages long, and in Dutch: https://www.autoriteitpersoonsgegevens.nl/documenten/boete-uber-doorgifte-naar-vs https://www.autoriteitpersoonsgegevens.nl/documenten/boete-u... The investigation report isn't included. It may surface if Uber decided to right the fine and take it to court. Or, if some-one takes an interest and tries to get it via the local 'freedom of information act' equivalent, though that might take just as long and will result in a heavily redacted version being made available.
- znpy 2y agoyou are missing the point entirely. the DPA has subpoena powers, sure. But before the DPA can get involved, there must be a complaint. Such complaint came from Ligue des droits de l’Homme (LDH) and here is my question: how was this group informed that Uber was sending data to the US? No doubt about what happens when the DPA gets involved, I'm not arguing over that.
- diggan 2y ago> In other words: the inner workings of a company are by definition a black box and only an insider can leak screenshots or damning data to prove they break a law in the first place. In reality, no one gets fined based on whims and wishes, but after investigations, just like in this case: > The DPA said it started the investigation after more than 170 French drivers complained to a French human rights interest group, which then filed a complaint to France's data protection watchdog. > Under the GDPR, a business that processes data in several EU countries must deal with the data protection authority where its main office is located. Uber's European headquarters are in the Netherlands. https://www.lemonde.fr/en/economy/article/2024/08/26/uber-fined-290-million-by-dutch-watchdog-for-failure-to-protect-drivers-data_6721808_19.html https://www.lemonde.fr/en/economy/article/2024/08/26/uber-fi... Seems the investigation uncovered that Uber didn't process data in their European headquarters but instead sent the data to the US, otherwise there obviously wouldn't be any basis for the fine.
- Cthulhu_ 2y agoIf a company operates in a country, they have to agree to audits. In this case - and I can't find any details about it - a group of French drivers made a complaint, presumably because they were aware that something fucky was going on with their data. It was enough of a lead to trigger an audit, to which the company has to cooperate with.
- jeltz 2y ago> If compliance or braking a law is simply some S3 buckets with a different latency and “zone” then breaking the law becomes trivially easy to do. And devilishly hard to check. If it is a genuine mistake the fine would be tiny if there would be a fine at all. At least that is how it has been in other cases. A this big fine indicates that the DPA found serious negligence or willfulness.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- crote 2y agoSo, what's your point? The same thing applies to insider trading, forming a cartel, or running a protection racket. Willfully not complying with authorities tends to be quite bad for your business, especially when you've already been investigated for breaking the law before. The DPA has previously fined Uber €600.000, €10.000.000, and now €290.000.000. Do you really think they won't do a follow-up investigation and issue another fine if they are found to still be in violation?
- codedokode 2y agoThere are actually many ways to look inside a "black" box, for example: an employee with high moral qualities might leak the info, or a company might send an email containing person's name from an US server, or an mobile app can be reverse egineered, or data might be available via foreign API server, or hackers might publish the leaked data, etc.
- ryukoposting 2y agoWireshark?
- bartread 2y ago> If compliance or braking a law is simply some S3 buckets with a different latency and “zone” then breaking the law becomes trivially easy to do. And devilishly hard to check. It's always trivially easy to break the law and not get caught for it. I'm currently in a small village and if I want to break the law right now I can go outside, get in my car, and accelerate to 90mph along the 30mph road running past the house. I'd probably get away with it too. But I wouldn't be doing it by accident: I'd be doing it because I'd chosen to. In the same way, whilst I could configure an S3 bucket in a different zone, I'd have to choose to do that. It's not that easy to get it wrong. I'm not about to do either of these things.
- oersted 2y agoI mean, relative to what? Most serious crimes I can think of have a hard-to-crack black box around them. Is it any easier to investigate violent crimes like murder? Financial crimes? Organized crime? Smuggling? Fraud? Criminal negligence (like food or environmental contamination)? I do agree though that with current cloud infrastructure and engineering standards it is rather easy to do accidentally.
- askonomm 2y agoLove it. Maybe one day U.S companies will learn that while they can steal and sell their own peoples information as they please, and they'll even have their own people brainwashed into such a state of stockholm syndrome that they will defend the corporations ability to do so, that's not the culture EU has, and it won't fly here. Corporations are not the peoples identity here, privacy and safety however are.
- xiphias2 2y agoOr maybe all companies will learn to leave EU behind in innovation. Even though the rules are great, I'm just not sure if it will be good or bad long term for EU.
- anonzzzies 2y agoToo much money here to leave it behind. This is a slap on the wrist anyway.
- llm_trw 2y agoThats what the Chinese through during the industrial revolution.
- croes 2y agoBut the west came back for cheap labor so a win for China in the long term
- llm_trw 2y agoThe century of humiliation is a funny name to call a period of winning.
- piva00 2y agoLet me know which tech company is willing to leave behind 1/2 to 2/3 of the revenue they make in the USA by quitting the European market. The analogy to China during the industrial revolution is simply non-applicable, to the point of not being even wrong.
- peterpost2 2y agoSeems fair.
- shinycode 2y agoIt’s good to know that GDPR is not just annoying banners
- ghusto 2y agoGDPR was never annoying banners, that's just malicious compliance.
- mattashii 2y agoIn most cases those banners are not even compiant, so "malicious non-compliance" is generally speaking more accurate.
- lifestyleguru 2y agoSince GDPR every interaction with public administration, healthcare, and employer within EU results with additional form or two "oh that's just a GDPR form, you have to sign it". I imply they are all malicious as well?
- WesolyKubeczek 2y agoIn fact, yes. It’s malicious in the vast majority of cases, with behavior patterns quite akin to cons where you are made into signing something under time pressure and are actively discouraged from asking questions. I had maybe one occasion where upon asking questions about how long they store my information and who exactly they give it to, I actually got answers and learned something. It was a dentist office, and by that time I had been visiting them so often that we were practically friends. The rest of the time (mostly in hotels), they didn’t like it very much that I took time to read through their GDPR forms and actively withdraw my consent from optional things, of which there was like 85%, and some dealt with sharing my data with undisclosed marketing partners. Some of this, especially the undisclosed bit, I think, is a no-no under GDPR, although a lawyer may promise you a way to weasel out of trouble. Note that when you deal with public administration, depending on the country, they may have you sign something to the effect that if they fine you and you don’t pay, your data will go to a debt collection firm, at which point you may assume it goes to all of them, because they trade debts between themselves, too. And of course, those share data with further companies according to agreements between themselves to which you are not a party, so I’m wondering if there is/should be a way to curb them…
- irdc 2y agoIn another article (https://nos.nl/l/2534629 https://nos.nl/l/2534629, Dutch language) Uber claimed to have been talking to the Autoriteit Persoonsgegevens about what they said was an “unclear law”. Via iOS Translate: > A spokesperson for Uber explains to the NOS that they have also contacted the AP themselves about the ambiguity surrounding the privacy rules. Then, according to Uber, the watchdog didn't say that the company violated the rules. Which is all fine and dandy but the rule really is that if it’s not clear to you (as a rich and well-lawyered company) that something is permitted, that doesn’t give you the right to then do it. And yes, the fine really has to be this high: fines can never be just a part of doing business; colouring within the lines has to have the attention of everybody involved, from the shareholders on down.
- kmlx 2y ago> The appeals process is expected to take some four years and any fines are suspended until all legal recourses have been exhausted, according to the DPA. i guess we’ll hear more about this in 4 years.
- croes 2y agoI'm confused. Thanks to the CloudAct there is not protection of EU user data no matter the location of the servers.
- koollman 2y agoThat would be incorrect. IANAL, but cloud act purpose is to allow the usa government to ask data from USA-based or USA-related services providers, for offsense/crimes. It does not allow service providers to do anything else with that data.
- croes 2y agoBut what could Uber do with customer data on US servers what they couldn't do with the data on EU servers?
- deleted 2y ago[deleted]
- okasaki 2y agoMeanwhile the UK handed all of its patient medical records to Palantir.
- herodoturtle 2y agoSource?
- michaelt 2y agohttps://www.theguardian.com/society/2023/nov/21/patient-privacy-fears-us-spy-tech-firm-palantir-wins-nhs-contract https://www.theguardian.com/society/2023/nov/21/patient-priv... very widely reported on - you'll find lots more reporting on Google.
- manuelmoreale 2y agoEdit: since someone already posted the guardian link i'll update mine with this one https://theconversation.com/palantir-privacy-fears-over-handing-nhs-data-to-us-defence-provider-show-how-lack-of-trust-is-holding-back-much-needed-reform-218629 https://theconversation.com/palantir-privacy-fears-over-hand...
- wh0knows 2y agoPalantir runs on the customer’s own cloud, or a major cloud provider of the customer’s choosing in the region of their choosing. There’s no data aggregation/sharing across customers, it works similar to AWS.
- AlanYx 2y agoCan anyone explain how this relates to the EU-US Data Privacy Framework (also sometimes called the Trans-Atlantic Data Privacy Framework)? I thought that that framework was supposed to allow this (as a replacement for the EU–US Privacy Shield framework)? Presumably this wouldn't have been a problem under Privacy Shield (i.e., pre-2020), or am I getting that wrong?
- di4na 2y agoYou are getting this wrong. Basically the framework, like the Shield before, is the Commission trying to show "look, we fixed it". Sadly, for the previous two times, the ECJ pointed out after the fact that no framework can fix the lack of data privacy law in the US, and that as such, the Shield, just like its predecessor, was not allowing what it claimed to do. The Framework has not been tested in the ECJ so far, but the US has not significantly altered its laws so...
- jorams 2y agoThis article[1] by the Dutch DPA has some details about it: The Privacy Shield was invalidated in 2020, leaving only the Standard Contractual Clauses as a valid transfer tool. Uber stopped using Standard Contractual Clauses in August of 2021, before adopting the new Privacy Framework in 2023. For a period of two years they were transmitting extremely sensitive information without a valid way to do so. [1]: https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-d...
- deleted 2y ago[deleted]
- pyaamb 2y agoGood. This should be applied to Chinese EVs too.
- lr4444lr 2y ago[flagged]
- Avamander 2y agoDraconian enforcement of which laws, can you specify?
- wyager 2y agoWe are fortunate to have lived through a brief period where the internet was truly a global network. A person in the Netherlands or Nigeria [1] could access the best technology services the world had to offer. People could more or less interact freely across borders. Obviously this is coming to an end. Every fiefdom wants their cut and their say, to the point where the internet being a global network is obviously becoming inviable. It was fun while it lasted. [1]: https://www.reuters.com/technology/nigerias-consumer-watchdog-fines-meta-220-million-violating-local-consumer-data-2024-07-19/ https://www.reuters.com/technology/nigerias-consumer-watchdo...
- ndsipa_pomu 2y agoWell, I'm not sure that I'd equate "freedom" with companies exploiting people's personal identifying information and selling it for their own profit. Personally, I don't want my information that's protected by GDPR in my own country to be smuggled into another country where there's almost no legal protection for someone's data/privacy.
- imachine1980_ 2y agoFree as in corporate freedom to extract and abuse your personal information
- ndsipa_pomu 2y agoQuite - it reminds me of the "freedom" to own slaves, but obviously not nearly as abusive.
- jeltz 2y agoAnd this freedom was ended by companies like Google and Facebook who abused this freedom forcing governments to act. Internet was at its worst right before GDPR. I don't think we will ever get back to the old free Internet and instead we will have this power balance between big corps and governments.
- 2y ago
- shashanoid 2y ago[flagged]
- jb1991 2y agoEU has also realized that without enforcement, and deterrence, American companies will take advantage of European citizens.
- perch56 2y agoor … EU enforces strict privacy laws to protect individuals, and some companies that don't respect these regulations are getting fined as a result.
- Deukhoofd 2y agoEuropean organizations are often fined as well, it's just that the amount of fines depends on the income of an organization. This means that big American companies jump out more, because they tend to have bigger incomes. Here's a database of fines for GDPR: https://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- troupo 2y agoAh yes, the poor-poor American companies who assume that they God-given right to every single scrap of data on their users that they possibly can. Under the guise of "we and our 1400 partners would really like to track your every breath"
- robin_reala 2y ago1400? https://www.theverge.com/ https://www.theverge.com/ (to pick a site at random) has 3,615 in the optional cookies setting alone, and a further 514 in the “strictly necessary” section. I think they might be lying on the last point.
- edwinjm 2y agoJust take a look how much European banks are fined by the USA for not following their regulations. It’s many billions of dollars. https://www.enzuzo.com/blog/biggest-compliance-fines https://www.enzuzo.com/blog/biggest-compliance-fines
- agentcooper 2y ago> The Dutch DPA started the investigation on Uber after more than 170 French drivers complained to the French human rights interest group the Ligue des droits de l’Homme (LDH), which subsequently submitted a complaint to the French DPA. I wonder on what the initial suspicion from the drivers was based.
- shiandow 2y agoCommon sense if I had to guess. Or maybe the app connected to the servers in the US directly.
- troupo 2y agoCould be simple negligence on Uber's part. Personal anecdote: Many years ago I was involved with a US organization, and then happily forgot about it. Almost 15 years later they started spamming me with emails coming from their head office in Washington. I asked them to stop. They didn't. I threatened legal action under GDPR and requested deletion, also under GDPR. They said they complied. A year later they started spamming me again. From the same address. That's how I knew that they never deleted my info and kept it in the US.
- amarcheschi 2y agoHave you followed with a notification to your privacy authority?
- troupo 2y agoIn this case it really wasn't worth it, but I've done it in other cases
- einpoklum 2y ago> Could be simple negligence on Uber's part. The didn't slip, fall, and drop some USB flash drives into the hands of a US data processor... I doubt it is any sort of negligence, but if it is - it's not "simple".
- shiandow 2y agoI guess this is always going to raise some eyebrows, with this amount of money it's hard to say it's not political. However I would like to say that the Dutch privacy authority actually seems pretty sincere at enforcing privacy legislation. It's just that until recently they were just sending angry letters, and now they've been given power to do more than empty threats.
- creesch 2y ago> with this amount of money it's hard to say it's not political. If by political you mean "aimed to be effective", then yes it is political. If the fine is too low and these companies make a healthy profit through these practices, they will just take the loss.
- landosaari 2y agoSpain fined Booking (Dutch company) 413M€ last month. For abusing its dominant position, the post has only 2 points [0]. Yet, this one has significantly more comments. The only political aspect is where the company comes from. Forum members then want to speak up. [0] https://news.ycombinator.com/item?id=41115644 https://news.ycombinator.com/item?id=41115644
- dtquad 2y agoDoes anyone know good best practices and software/DB patterns to model localized GDPR-compliance into global software systems? I know ASP.NET Core comes with some GDPR-related helpers but it's more interesting to know general best practices and patterns not related to a specific framework.
- dacryn 2y agobasically, make sure your data governance is on point. It should almost live outside of your software stack. Tools like collibra, purview, informatica, ... that know you database, are your best tools at enterprise level.
- oneplane 2y agoIt's pretty much part of your normal data management that you'd be doing anyway, except it now has an additional lifetime (on top of any you might have had). Since when ingesting the data you knew where it came from and on what timestamp, you also know when to next check for deletion. And since you also know where it came from (the owner), deleting/sending it on request (when applicable - not all data is always required to be deleted) is pretty straightforward. In essence it's like garbage collection for managed languages (like C#) but for your data. At the end of the day, no matter what you use (existing process, create a new process if you weren't managing your data so far, or use some product), treating data like radio active waste will generally lead to good designs. You only keep what you need for the time that you need it, everything else gets removed.
- ndsipa_pomu 2y ago> You only keep what you need for the time that you need it Just to add that it's stricter than that - you can only keep the data that is required for the purpose that you detailed to the customer. e.g. If you ask for their email address for password validation, then you're not allowed to use that email for other communication unless you explicitly asked for that as well.
- oneplane 2y ago
- pyrale 2y ago> Since the end of last year, Uber uses the successor to the Privacy Shield. Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.
- AlanYx 2y agoThe EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework (the replacement for Privacy Shield): https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6... and has begun "certifying" compliance with the Framework: https://www.dataprivacyframework.gov/list https://www.dataprivacyframework.gov/list So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? Lots of unknowns though, since Schrems has already announced a challenge to the Framework. The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent.
- pyrale 2y ago> The EC has issued an "adequacy decision" regarding the new EU–US Data Privacy Framework To bad the EC isn't the body that can judge whether that deal is legal, and has been caught repeatedly lying about past deals [1]. > So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework? As before, cases will go to the actual authority on the matter: the CJUE. I personally don't have high hopes for this deal to last. [1]: https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-round-cjeu https://noyb.eu/en/european-commission-gives-eu-us-data-tran...
- AlanYx 2y agoI tend to agree with you about what will happen, but it illustrates the depth of legal uncertainty that exists in architecting software systems in Europe that process personal information. Corporations can't necessarily trust the EC's own published interpretations of their own laws, nor the certification processes the EC has created, so the only risk-minimizing route is a maximally pessimistic approach about what is permissible.
- pylua 2y agoFunny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed. The US definitely needs stronger laws here.
- ndsipa_pomu 2y agoIt shouldn't be a problem for Europeans to access/process U.S. data that belongs to U.S. citizens - GDPR doesn't cover that AFAIK, so it's fine for it to cross borders. The issue is with GDPR protected data of EU citizens, as the law does not permit that data to cross non-EU borders unless it's for specific exemptions such as law enforcement.
- mananaysiempre 2y agoOr, IIRC, if the destination country has privacy protections that are at least as strict as those in the EU, which the US legal regime for foreign intelligence definitely doesn’t provide (a non-US-citizen wouldn’t even have standing to sue wrt their personal data).
- ruthmarx 2y ago> a non-US-citizen wouldn’t even have standing to sue wrt their personal data Sure they would, I think? They would just have to foot the bill to travel and file in a US court. And whatever user agreements they 'agreed' to might come in to play without legislation to supersede it. But they would have standing, I'm pretty sure.
- mananaysiempre 2y agoNot a lawyer and not going to find the relevant references in the US’s vast body of law in reasonable time, so let’s check what the CJEU concluded? Schrems I [1] (the old CJEU judgment invalidating Safe Harbor) endorses (§90) the opinion that: > [D]ata subjects [whose personal data was transferred to the US] had no administrative or judicial means of redress enabling, in particular, the data relating to them to be accessed and, as the case may be, rectified or erased. In what reads like a reference to FISA, it continues (§95): > Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter [of Fundamental Rights of the European Union]. It then stops short of calling out FISA by name, instead (IIUC) invalidating on the basis that the adequacy of the legal regime was not addressed in the Safe Harbour decision to begin with. Privacy Shield came next and did, so Schrems II [2] (the newer judgment invalidating Privacy Shield) states (§181–2): > According to the findings in the Privacy Shield Decision, the implementation of the surveillance programmes based on Section 702 of the FISA is, indeed, subject to the requirements of PPD‑28. However, although the Commission stated, in recitals 69 and 77 of the Privacy Shield Decision, that such requirements are binding on the US intelligence authorities, the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities. Therefore, the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter [...]. > As regards the monitoring programmes based on E.O. 12333, it is clear from the file before the Court that that order does not confer rights which are enforceable against the US authorities in the courts either. It sounds like the official legal position of the US executive is that individual foreigners do not have standing to contest FISA 702 surveillance of them. (I could not quickly find the text of that position.) This is a 2020 judgment in a case from July 2018 regarding a European Commission decision from 2016, so the implications of the CLOUD Act, signed in March 2018, do not look to be in scope. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62... [2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...
- herdonbesecker 2y ago[dead]
- childintime 2y agoFunny they are being fined in the Netherlands, because Uber is almost invisible there, as regular taxis have been protected. I don't have accurate data, but it's at least 15€ per inhabitant, so it seems like a very very steep fine. I can't imagine how much this is per driver, €25000? It seems the dutch regulator is saying "why don't you just go away?". The feeling is likely mutual.
- Manfred 2y agoIt's a fine meant to be a punishment, not damage settlement. > All DPAs in Europe calculate the amount of fines for businesses in the same manner. Those fines amount to a maximum of 4% of the worldwide annual turnover of a business.
- peterpost2 2y agoUber europe is headquartered in the Netherlands, which is why the fine was handed out there, the complaint was passed from the french privacy watchdog to the Dutch one.
- decide1000 2y agoUber HQ is in the Netherlands. They like the tax system here..
- jgowdy 2y agoThat's one way of saying "Europe is full of nations who provide unethical tax shelters for businesses (while criticizing any nation that doesn't provide their level of social programs), so they can regulate and fine and fill their coffers with money from businesses all over the world." But yeah, blame it on the companies that take advantage of the tax shelters EU nations choose to provide and the EU chooses to allow.
- diggan 2y agoMaybe our definitions of "Tax shelters" are a bit different, but I think of Cayman Islands or Bermuda when I hear that, and Netherlands is not like that in the context of Europe. Probably Ireland is the closest you get, so would have been a much better example.
- philip1209 2y agoWhich big tech company will be the first to stop doing business in Europe? It's going to happen sooner or later.
- nehal3m 2y agoMy first instinct would say if someone pulls out I hope that would finally spur some competition. You don't need to apply anti-trust to companies that don't operate in your market. Maybe a competing video platform or phone operating system would get a chance at organic growth. Maybe a pipe dream though. I haven't given it serious thought.
- Rinzler89 2y agoThe sooner the better. This way local EU players can fill the void they'll leave. This insular isolation also fueled China's domestic SW sector.
- kmlx 2y agothis take is naive. building alternatives takes time and resources. the EU has neither. a diverse, competitive tech ecosystem with both EU and non-EU players is better than a protectionist approach. hoping for an exodus of major global players when you’re leapfrogged by both China and the US…
- Rinzler89 2y ago>building alternatives takes time and resources. the EU has neither. This is kind of a FUD fueled false dichotomy, when the truth is we can't know if the EU doesn't have time or resources if it never tries. What the US has that EU doesn't is the infinte money to throw in the bonfire at moonshot projects knowing that 99% will fail and the 1% will be hugely successful, but now the market is mature with less untapped opportunities, and the EU doesn't have to spend like the US did to achieve the same results, since we now know what works and what doesn't and how to make an Uber that's compliant with local regulations while using less money.
- andersa 2y ago[flagged]
- thinkingtoilet 2y agoIf you are an American company you still have to comply with local laws. It's not absurd at all. If Uber doesn't like it, it is free to leave the EU.
- mattashii 2y ago> Uber is an American company with all systems running in the US The company registration with headquarters in the Netherlands begs to differ, as do all those European Uber drivers
- kergonath 2y agoThey interacted with a local subsidiary. Being subsidiaries of an American company does not mean that they get to ignore local laws. Funnily enough, even Americans get to follow the rules in other countries. So they sent their documents to the local company, which in turn transferred them overseas. I really fail to see how this is the drivers’ fault.
- ricardo81 2y agoIt's more like 'if you want to do business in the EU, abide by EU rules'. Applicable to every company.
- eclecticfrank 2y agoYour explanation is in the second paragraph: "In Europe, the GDPR protects the fundamental rights of people, by requiring businesses and governments to handle personal data with due care", Dutch DPA chairman Aleid Wolfsen says. "But sadly, this is not self-evident outside Europe. Think of governments that can tap data on a large scale. That is why businesses are usually obliged to take additional measures if they store personal data of Europeans outside the European Union. Uber did not meet the requirements of the GDPR to ensure the level of protection to the data with regard to transfers to the US. That is very serious."
- akudha 2y ago
- nomoreusernames 2y ago[dead]
- qqcqq 2y agoThis puts the total fines from the EU on American tech businesses at $14.8B in the last few years: https://loeber.substack.com/p/20-no-more-eu-fines-for-big-tech https://loeber.substack.com/p/20-no-more-eu-fines-for-big-te... I think this substack is good, it makes a pretty clear case that US tech companies may not leave Europe any time soon, but they wield the power in the relationship much more so than the Europeans. Those regulators are overplaying their hands.
- eclecticfrank 2y agoTwo of your last three comments refer to loeber.substack.com
- berikv 2y agoThe counterpoint to that article is: US Big Tech could also abide to EU laws and avoid fines altogether.
- pembrook 2y agoUS companies literally cannot abide by EU laws, because they are subject to US laws, which conflict with EU laws. This is what all these European judgements are disagreeing with. The companies are not at fault here. The governments are at fault for dropping the ball on coming to an agreement. We’re on like the 5th round of this. Compliance is impossible. Until the two governments fix this, US companies cannot operate in the EU without being at risk for pilfering from EU government.
- silent_cal 2y ago[flagged]
- StrLght 2y agoAlternative question: has breaking European laws become a major American industry?
- exe34 2y agobreaking the law is how American companies grow out of control.
- silent_cal 2y agoIf it is then Europe doesn't seem too upset about it. How could they be when it pays them so well?
- OKRainbowKid 2y agoHow would you suggest they express their disapproval, if not through the legal system? I'm personally not opposed to holding conpany executives personally accountable, including jail time in severe cases, but I don't think this would go over well with the US government.
- philipwhiuk 2y agoFrance has picked that method with Telegram.
- com 2y agoCan you imagine if the CEO of Telegram was a US citizen? It wouldn’t just be HN people losing their minds.
- mikem170 2y agoU.S. citizens are arrested and convicted for breaking laws in other countries all the time. It's rare that they get out of it because they are a foreigner. It doesn't matter if the laws and punishments are different - whether that be a caning for spitting, a prison sentence for besmirching the king, or even the death penalty for drug dealing. People are obligated to obey local laws, even if they disagree with them, or suffer the consequences. Not saying there can't be an international uproar, but if laws were broken the local justice system is legally entitled to punish the perp, even a foreigner. People loose their minds for all kinds of reasons, I can't speak to that ;-)
- baxtr 2y agoThey will filed it under “cost of doing business in Europe” and add it as markup on their prices.
- flanked-evergl 2y agoAt this point, I would pay to have my data stored somewhere outside the jurisdiction of the EU.
- peterpost2 2y agowhy?