EU data protection law after the Safe Harbour judgment
eulawanalysis.blogspot.com
eulawanalysis.blogspot.com
You can't post this because it has a blocked link The content you're trying to share includes a link that our security systems detected to be unsafe:
http://eulawanalysis.blogspot.com/2015/10/the-partys-over-eu...
Please remove this link to continue. If you think you're seeing this by mistake, please let us know.
Well, other entries don't bad-mouth Facebook.
https://thecalmzone.net/2015/06/ask-facebook-to-remove-the-b...
That page says it's fixed, but it seems that FB is providing the wrong preview, linking to http://www.thecalmx/ instead of http://www.thecalmzone.net/
This spam filter carries a small risk of death, so it's pretty frustrating.
I for one do not welcome our new content curating overlords.
But someone downthread said the .co.uk version was not blocked (before you unblocked the .com). Are you implying the .co.uk version did not have the same "design elements"?
As to your proposed argument, I think selectively blocking well-reasoned analysis by law professors and letting memes go unblocked makes the most sense for your company.
Classifiers do weird things, and features you don't expect to be significant can suddenly have a much larger than intended effect. The domain name, as a feature, must've thrown it over the edge.
It's like that Google+ post where a picture of a couple of black people got tagged as "gorillas" by their auto-tagging ML system. No, Google isn't racist, their classifier just hates their PR department.
Ah, the joys of machine learning...
It would be interesting to see what other links that discuss FB can not be shared there and even more interesting at what level of FB the directive initiating this blockage originated.
It will give the contents of the blog, but not sure how modern browsers will render it as is. However if you save to a file with an .html extension then open in browser it should look fine.
Using .co.uk extension on the blogspot URL instead of .com may also work, as another commenter has suggested.
And then I managed to post the plain URL.... maybe they've unblocked it, or it's not blocked from within the EU.
Unless I'm misunderstanding it?
And besides this the rules for how private companies can handle my data are totally different in the UK to the US. In the UK private data comes with fairly strict obligations under the data protection acts and leaking (even accidentally or due to insufficient safeguards preventing malicious actions) can be punished robustly. As I understand it in the US the laws are rather different.
"I haven't received my package!"
"Well, we sent it 2 weeks ago"
"What address did you send it to?"
"Don't know"
EDIT: Also, "Why does this shopping website require me to re-input the shipping address every time I want to buy something? Why can't it remember it like every website used to?"
You could probably even keep a names and addresses database so long as it was something you needed to keep in order to conduct business with the customer.
Routine data mining, asking for irrelevant info, selling it on to third parties, not so much.
For instance, your email address and birthday, for, say, amazon.com, could easily be argued to "need to be kept in order to conduct business". After all, your email ... amazon spams it ... that's certainly part of the business they conduct (and frankly, they'd be more expensive if they didn't do that, so there's easy arguments that it'd be harder to do business if they didn't). Your birthday ... same. They spam you harder on your birthday ... also part of their business.
Laws like this won't protect anything. The simple fact is you can't have easy to use sites like google, facebook, amazon and the many millions of easy webshops and have protection of private data, it just wouldn't work as well. Since people prove time and time again that they want the webshops and "private" chats far more than they want privacy, there is no way to win this fight. Everything is decided already (and already today kids don't have anywhere near the expectation of privacy that adults have, this will get worse), there's just a few decades of denial remaining.
Take the single account (real name policy) on facebook. We all know that's the reason facebook comments don't work like youtube comments do. That's why not every second post on facebook is about hitler. That's why it's easy to find people on facebook. And so on. You can't drop it and expect the same functionality, and people have proven with their feet (/mouse) that they want the functionality more than they want multi-name policy.
Perhaps then I should have said to conduct transactions.
There is a substantive difference between holding information enough to allow people to buy stuff from you, and holding it to advertise, which usually requires extra permissions.
>> Laws like this won't protect anything.
This is too early to say. They may well protect lots of things, and they certainly can (for instance) be used as a place to start attacking ubiquitous tracking and tracing from.
>> The simple fact is you can't have easy to use sites like google, facebook, amazon and the many millions of easy webshops and have protection of private data, it just wouldn't work as well.
Then perhaps that's OK, because some things are actually more important than commerce. This stuff might have to be hard to get right.
It would be interesting to put some teeth in the "no sharing" rules about collected private information.
The option to not have my mailing address stored is a feature not a bug to me (and I guess other people that move regularly).
EDIT indeed many smaller shopping websites in the UK don't even attempt to store this sort of data -- presumably because they don't think that they can definitely comply with data protection laws.
[0] http://www.theguardian.com/world/2013/sep/09/nsa-spying-braz...
[1]http://www.theguardian.com/world/video/2014/feb/07/eu-us-dip...
https://en.wikipedia.org/wiki/Parable_of_the_broken_window
Artificially creating additional work by imposing additional requirements does not necessarily improve the situation just because it employs people to do that work, whether you personally like those requirements or not.
The ruling to declare "Safe" Harbor invalid is not breaking anything but a step to fix a system that is systematically violating constitutional rights.
In the light of US companies not effectively safeguarding european data against access by US authorities, judgements are needed to rectify the situation.
In the case of safe harbour, the window was already broken. Data being passed from Europe to the US was not being handled correctly, despite the promises inherent in Safe Harbor.
If protections had already been in place (i.e. if data service providers were actually adhering to the promises of safe harbour) then service providers have already fixed the window. Those that were safeguarding data correctly have no further engineering work to do (although there might be further regulatory/compliance effort to prove it depending on how individual nations implement the stopgap safeguard laws to replace Safe Harbor).
The only engineering work required to "fix the window" is work that should already have been done according to the safe harbour agreements, and threads like this prove how broken Safe Harbor was to begin with.
...which in many cases doesn't exist yet. In particular, Europe lags significantly in "on-line" services.
Obviously it would solve some problems if this were not the case. However, given that for now it is the case, the price of enforcing a total ban on exporting personal data outside Europe would be closing down vast numbers of on-line European small businesses that aren't intentionally doing anything unreasonable or customer-hostile. Clearly this isn't going to be accepted readily by anyone involved.
A more realistic result when the dust has settled might be yet another disclosure that businesses are required to make prominently when someone buys or signs up for something, in order to be deemed to have explicit consent from the data subject to export the data. This appears at first sight to be a reasonable way to handle the ruling, and in principle I think it's hard to argue with requiring a business to disclose fairly what they're really doing with personal data. Indeed, I've noticed that in recent years organisations like my insurers have started adding terms that explicitly say they're going to export personal data and foreign governments might get access to it, and that if you want to deal with them at all then you have to accept that. (I'm not sure how I feel about such conditions when having the insurance is mandatory by law, as for example with motor insurance for drivers, and based on my experience so far it looks like literally everyone offering such insurance is now imposing similar conditions.)
Then again, for on-line businesses at least, isn't that what privacy policies have evolved to deal with? Separate to this case, under the new consumer protection rules, it seems likely that such policies would now be considered to fall under the same general rules about fairness and transparency as the main terms of a consumer contract. Assuming that is true, I'm not sure there is a huge advantage in cluttering up on-line order/sign-up forms with explicit wording about routine things, while there is certainly a disadvantage in making such forms any more complicated than they need to be. The question then becomes one of reasonable expectations about what a normal customer would consider routine.
I suppose that brings us back to approximately where we came in, other than the fact that it's now a matter of public record that the US government itself was violating those reasonable expectations and opened Pandora's box. Somehow I suspect that if some sort of basic disclosure/consent on sign-up doesn't deal with this issue, it will be addressed by adjusting the relevant European-level legislation so that disclosure to allied governments in the interests of national security is a blanket exemption, and enough people won't know or care about the implications that this will pass even though privacy advocates would surely oppose it.
There is suddenly a good business case for them to exist, and hence probably more funding available now
> it will be addressed by adjusting the relevant European-level legislation
The judgment was based on the Charter of Fundamental Rights of the European Union, and is basically the EU's Bill of Rights. Legislation isn't so flexible here.
> that disclosure to allied governments
Is the USA allied to many EU governments or the EU? It has tapped the phones right at the top of the German government.
So even if data protection rules were perfectly adequate in every single country on this planet, there would still be justified concern about transferring data across borders.
That's a situation that must change, and it can change without taking away the bowl of sweets from security agencies altogether (which will never happen).
This is going to be generally true of most countries. If it weren't the case, most forms of espionage would be subject to prosecution in the spy's home state.
There's no new policy and no court orders to do particular things. What's likely to happen is an extensive legal limbo. We may even end up with a special Snowden version of the cookie warning: "Data stored on this system is subject to mass surveillance and may be accessed by the security services without a warrant or due process".
Depends. The courts might rule that that sort of "click-through" agreement is invalid and doesn't count as consent.
Update: Already happening. DPA of Schleswig Holstein: Transfer on the basis of Model Clauses unlawful. from https://twitter.com/CarloPiltz/status/654214641975984128
Oh good, I was worried a little about that one.
> Undoubtedly (as the CJEU accepted) national security interests are legitimate, but in the context of defining adequacy, they do not justify mass surveillance or insufficient safeguards.
Another good thing. I wasn't sure if this ruling affects spy agencies, too, or just companies.
(Shadow profiles are plainly a violation of data protection law; do they exist for EU users?)
(Irish Data Protection Commissioner is clearly running this at the slowest speed they can get away with)