5 ms·
The EU couldn't fix the EU-US privacy framework even for the third try, and when the previous one have been invalidated by the CJEU, nobody bat an eye and cont
by raron 2y ago
The EU couldn't fix the EU-US privacy framework even for the third try, and when the previous one have been invalidated by the CJEU, nobody bat an eye and continued to do the same thing.
GDPR is simply ignored by any bigger US company, it took 5 years for NOYB to facebook get fined which was less than 0.3% of their income, basically a small tax, not a huge fine.
Also GDPR is full of inconsistency (face biometric data is special data, but a photo of your face from what anybody can get the biometric data is not) and loopholes (required by law, legitimate interest).
They did something, but I wouldn't call that "a long way".
- zendist 2y agoThis is false. GDPR is not ignored, I can tell you that much.
- notyourwork 2y agoAnother checking in from the my company was and continues to be effected by GDPR.
- danpalmer 2y ago> GDPR is simply ignored by any bigger US company I work for a very large US company and can assure you that GDPR is something we pay a lot of attention to. This isn't the opinion of my employer, but my personal experience is that the big players take it seriously and meet and exceed all their obligations because it's too risky not to, and they have the necessary local legal teams to understand the law as best as is possible. I think it's the small/medium companies who are where most of the issues are. Small companies write a non-legalese privacy policy because they think that's better for their users, but in fact have written something legally meaningless that gives their users no protections. Some small companies just don't know their obligations because they think they won't apply as they're not in the EU. Then there are the companies who are big enough to know better, but small enough to know they can get away with it because all the scrutiny goes to big tech. I was asked by a medium sized advertising network to implement a keylogger on our website at my previous company so that the network could enforce their revenue sharing by detecting all user data input into our site and match it against their records. I laughed them out of the room, but they made it very clear this was how everyone did it.
- raron 2y agoOkay, with "any bigger US company" I thought mostly about Facebook and similar companies, of which many does continuously break GDPR rules even after many decisions and fines (simply because their business model is incompatible with privacy / data protection). But it is still true, that nothing happened after the Schrems II judgment, and many-many companies continued to transfer personal data to providers affected by FISA.
- SR2Z 2y ago> Some small companies just don't know their obligations because they think they won't apply as they're not in the EU. To be fair, unless a company has a business presence in the EU there is nobody to sue for GDPR violations. The EU cannot enforce its laws on an entity which isn't under its jurisdiction at all.
- account42 2y agoAs long as the business has EU customers or suppliers, or employees that might want to visit the EU then there is possiblity of enforcement.
- SR2Z 2y agoCustomers and suppliers can't be held liable for GDPR violations committed by someone else. The only way the EU could enforce the GDPR on a fully foreign website is to block it.
- ranger_danger 2y agoI would bet money they will start doing this.
- account42 2y agoCustomers and suppliers can be held liable for duing business with unlaful organizations.
- JumpCrisscross 2y ago> GDPR is simply ignored by any bigger US company GDPR is closely adhered to by big American companies. They may be the only ones to whom the EU is applying regulatory pressure on this. Chinese and Indian companies, on the other hand, as well as any non-enterprise American company, including start-ups, on the other hand, can and do safely ignore it. (Or follow it in broad strokes.)
- afuchs 2y ago> ... GDPR is simply ignored by any bigger US company, it took 5 years for NOYB to facebook get fined which was less than 0.3% of their income, basically a small tax, not a huge fine. ... From my experience working at multiple companies, and having interacted with others, the GDPR is not ignored by American companies. websites based out of the US block EU users to avoid fines, or these US based companies which don't block EU users have gone out of their way to comply with the GDPR as interpreted by their respective legal department.
- robertlagrant 2y ago> less than 0.3% of their income, basically a small tax That's not how tax works. You get taxed on your net, not your gross. 0.3% of gross is massive.
- account42 2y agoReal people get taxed on their gross income too.