4 ms·
Would that even be legal in the EU? “Upscale furniture store Restoration Hardware said that it had sent "your name, address and what you purchased" to seven oth
by racbart 14y ago
Would that even be legal in the EU? “Upscale furniture store Restoration Hardware said that it had sent "your name, address and what you purchased" to seven other companies, including a data "cooperative" that allows retailers to pool data about customer transactions”
- belorn 14y agoThe short answer is yes. The long answer is a bit more complicated by it will result in the same answer. Companies in EU can send data over to NA to have it "processed". Once there, the data is outside the protection of EU law, and can be sold without hindrance.
- karambahh 14y agoSaying it is indeed possible is akin to say that "tax evasion is possible".... possible yes, legal, I don't think so My understanding of my (EU) country law is that you cannot send data outside the EU to have it processed if the data is deemed "sensitive". Even if you are allowed to export it, you have to guarantee that data won't sold once it has left EU.
- belorn 14y agoFor patient data, there are some exceptional laws in some countries. While I hope it does become EU law someday, we are not there yet. I have never heard of any laws that allow one to export data but then to give some guarantee that the data won't be sold. Source? But for the general case (ie a normal business venture), people are already using services that will exploit/refine any personal data being sent there. Gmail is one, but Facebook is a better example. Facebook will use the data even if it about someone who aren't a Facebook user. Cloud services could be doing things, but I am not sure its true in practice yet. Mobile apps are already getting and selling data, and has a long history of doing exactly that. Webshops that use paypal are sending their customer data to paypal. If one read their privacy policy, one can see that they use the data to: a) compare information and verify it with third parties. b) Send to companies that perform marketing and "other services" for paypal. c) Send aggregated statistical data to their business partners. d) send any data to eBay Inc. corporate family—like eBay, Skype or Shopping.com (https://cms.paypal.com/au/cgi-bin/marketingweb?cmd=_render-content&content_ID=ua/Privacy_full&locale.x=en_AU https://cms.paypal.com/au/cgi-bin/marketingweb?cmd=_render-c...)
- jrabone 14y agoThat PayPal data almost certainly also goes directly to Palantir (another Peter Thiel company), to be added to the vast corpus of information they (and by association the three letter agencies & DoD contractors) hold on you. Palantir arose from the anti-fraud work that PayPal was having to do 10 years ago and is now supposed to be a big deal in data mining for govt, defence etc. Want to bet that they have quite a few "exceptional laws" on their side?
- thisone 14y agoI'd bring up the Safe Harbor[1] framework Though, the last time I read a report on the audit of Safe Harbor[2] and US companies that say they abide by it, I decided not to recommend trusting our data to US companies. 1: http://export.gov/safeharbor/ http://export.gov/safeharbor/ 2: http://www.galexia.com/public/research/assets/safe_harbor_fact_or_fiction_2008/safe_harbor_fact_or_fiction.html http://www.galexia.com/public/research/assets/safe_harbor_fa...
- karambahh 14y agoExcept that Gmail and Facebook are US companies. I tend to think that using a belgian/czech/italian (you get the idea) website, my data couldn't be easily exported/sold outside the EU. I am currently building a data crunching company in the EU. I chose, both from a legal and marketing standpoint, not to export any of my (customers') data outside of EU. In fact, I chose not to export any data outside of my country's borders. It simplifies (a bit) my legal paperwork, but it also serves as a marketing claim along the tune of "we are doing no evil with your data, and not putting them into the hands of anyone else".
- summerdown2 14y agoI think you mean the short answer is no. This would breach principle 8 of the data protection act unless the same legal safeguards are placed around the data in North America http://www.ico.gov.uk/for_organisations/data_protection/the_guide/principle_8.aspx http://www.ico.gov.uk/for_organisations/data_protection/the_... It is illegal in the EU to transfer data out of the EU without this safeguard, done variously by contract (EU model contract), two party agreement, assessment of adequacy, or approved safeguards (safe harbour).