Europe’s new data protection rules export privacy standards worldwide
politico.eu
politico.eu
> Europe wants to conquer the world all over again.
So Europe makes new regulations that improve the life of european people and they try to spin it up as a global domination move. As a European I am really happy that I am more protected. If a company wants to make business with me I expect them to follow the local regulations! That is not a new world order plot, cmon.
Stronger regulation some times is better when made with the citizens in mind, see the TTIP. Why would we (europeans) want to reduce our food quality regulations? Why wouldn't we want a better data protection?
Specially after Equifax scandal, I am so happy that things are changing over Europe.
Edit: specified better what I think is non-sense
Politico Europe is a pretty pro-EU publication, so it would indeed be worrying if they saw a return to colonisation.
Luckily, the authors are just employing what's called a metaphor. The last sentence arguably does a better job of summing up the article's thesis:
“This is part of Europe’s exporting its soft power,” said Kuner, the co-chair of the Brussels Privacy Hub. “In terms of regulatory influence, Europe is definitely a superpower.”
The rest of the article provides real substance. Silly to claim the who article is nonsense based on one line.
> Data protection is a good example of Europe trying to extend its influence over other countries
> In response, legislators worldwide are scrambling to update their domestic legislation
> the upcoming data protection changes risks being viewed as yet another diktat handed down by former colonial powers in
> We’re already seeing a number of countries falling in line with Europe
I mostly see this as a way to fine big companies and put some money in the pocket. Also like with tax and other laws if the enforcement is delegated to the members we will have same situation like we do now with tax in Ireland or the way Volkswagen and Co. put their cars to sales first in specific countries to bypass German standards.
A lot of this also makes no sense from technology perspective, it would be easier to force browsers not to accept 3rd party cookies then to make me ruin user experience cos i have a youtube video embedded in the site.
EU learned a lot how to be a nanny state from Germans, which in a way and kills a lot of freedoms under guise of security... But I for one would rarely sacrifice freedom for security...
The EU law aims at giving citizens in the European Union more control over their own data. They should be informed what a company does with their personal information and they should need to consent to it. In other words, they have a right to make a transparent, informed decision.
I don't know what this has to do with nanny states or taking away anybody's freedom. In fact this is a great tool to give individuals freedom and ownership over their data.
For example Uber has a long time habit on trying to get drivers to do what they want by using their information in ways that drivers are likely not aware of. The goal of legislation in the future must be to empower those drivers to be conscious of this and have a right to demand in what way information is used to control them.
I don't want to end up in a world of nanny businesses because we're too afraid to legislate them.
Do you think think this will stop data collection and mining in anyway?
These kinda a laws is why germany has no free wifi anywhere cos owner gets fined for anything that happens on his wifi... so good luck to find decent hotspot in Berlin for example...
There should be regulations but when they are too stiff they don’t help anyone in this case
Oh please. Please be factual even in your rants. For one, a single notice is quite enough. And secondly, it's not about cookies, but all forms of user tagging, including e.g. browser fingerprinting, which does not require any client-side data.
Do you think think this will stop data collection and mining in anyway?
I hope not. I really look forward to those massive fines.
And it is about cookies too...
What about massive fines for small companies? Large ones will pay and continue making money off your data while the small companies will go bust for even simple mistakes.
The law has changed. Since October 13th 2017 the owner of the internet access point is no longer responsible for what happens through his access as long as he doesn't collude with those, that do mischief with his access.
This law has seriously impacted WiFi availability in Germany for some time.
Torrent laws are used by lawyers and scamers to send out fines to random people and scam them for money, what does a consumer get out of those laws? Nothing...
Same way this law imposes so many rules that for smaller companies it just makes things harder while the big companies will pay and forget about it.
If you are a provider of internet access for example via WiFi, and you didn't collude with the users to breach the law, and you are sent a Abmahnung by a lawyer, then you can demand them to take back the Abmahnung including any financial demands after explaining to them said situation and making credible that you weren't exclusively using your internet access. You also don't need to investigate who was the perpetrator, and no ask no tell works. If the laywers don't step back, you can sue them with a Negative Feststellungsklage.
All of these are different issues.
"U.S. policymakers argue that American data protection standards, enshrined in the constitution and enforced aggressively by the Federal Trade Commission, do more to guard against misuse than European standards, which often can be more bark than bite."
Can someone more familiar with the US constitution elaborate on what exactly it says about data protection?
GDPR would have attached more liability to equifax (though 4% of global revenues really isn't that much), including a much shorter timeline on reporting the breach.
Apart from the fine and the notification of the breach. Equifax would have been different because of.
- Consent : " companies will no longer be able to use long illegible terms and conditions full of legalese " - Right to Access : " Further, the controller shall provide a copy of the personal data, free of charge, in an electronic format. " - Right to be Forgotten - Data Portability - Data Protection Officers
But Europe ( the countries that i know about ) have different requirements rules for credit bureaus all together. So AFAIK there is little incentive for Equifax to hold European data at all.
So that people don't rely on your lack of understanding of the gdpr:
* consent isn't required; it's merely one basis to permit processing
* since consent isn't required, it will be an extraordinary stretch to exercise a right to be forgotten. In fact, credit reports are probably one of the canonical cases where LI override most rights of the data subject.
* data access is not new; see DPA
* Equifax does, in fact, have an EU business; it is in the UK. And has offered £2 access to credit reports since 2010-ish. I recognize 2 > 0, but it is not significantly different.
I don't really know of anything that deals with giving people more power to direct how private entities can use (or not use) their data.
Frankly, US privacy and data protection laws are terrible, and what little we do have ends up being weak enough that companies and the government can usually find ways around it when it's inconvenient for them.
Not sure how well the GDPR will work in practice; this is going to rely on broad but even-handed enforcement. The fines are hefty enough that not complying would actually do financial harm to companies, but that'll only work if the EU actually enforces the law properly. Only time will tell if they do.
Among the problems is that Europe doesn't have "class action" lawsuits. Coupled with the fact that any single individual usually incurs only relatively small harm from privacy violations, the incentives to invest in lawsuits just aren't there.
Public enforcement is also delegated to privacy watchdogs in each member state. Because jurisdiction is based on a company's registration, there is an obvious conflict of interest in these positions. This has played out, for example, in numerous cases against Facebook: It is (like Google and others) registered in Ireland, where the government has long been rather sympathetic to industry interests.
The US Constitution says absolutely nothing about privacy, but the Supreme Court has found it reading between the lines of the 4th (unreasonable search and seizure), as well as the 1st. There's also the 9th ("This list of rights is not intended to be exhaustive" or something to that effect). In practice, US data protection lacks the EU by a wide margin, except for certain, specific cases such as video surveillance (which the UK uses far more) and health data (HIIPA seems to work rather well).
"If you’re not sure about their compliance, time to act. You’ll need to contact them and make sure they confirm they’re GDPR complaint. That image needs to be 100% completed."
Here is a correct explanation in English of GDPR from the Irish regulator: http://gdprandyou.ie/
Also the UK regulator: https://ico.org.uk/for-organisations/guide-to-the-general-da...
This leads to the situation where the interpretations can vary greatly from country to country. We might see a very pro business Irish agency saying one thing and the Danish saying another.
Remains to be seen if that will lead to compliance shopping like in some finance regimes or if every enforcement group will get to come after every firm.
The EU has many regressive regulations based on outdated notions with regards to the rights of individuals.
Just one example: in the US if someone is involved in egregious fraud (such as ripping off thousands of individuals in a scam) then the US says that such information constitutes news and that even if its old information from a decade ago its relevant, and a platform like Kickstarter or Google can keep the information online for users to assess before transacting with the individual.
In Europe this could be deemed illegal. There's a right to be forgotten in Europe. And sometimes even relevant and newsworthy information can be ordered to be purged from databases.
The Europeans don't want companies or users deciding on the rules for platforms. They want to make one rule and apply it across all platforms. Not only that, they don't really think through the implications of some standards. Like if there is a right to be forgotten, can companies like Kickstarter really afford to scrutinize every request for deletion of data and use a lawyer to determine if the request is justified? Of course not. They will just make an algorithm and automatically delete the information. The value of the platform in the long term will decline as fraud from years ago is purged.
There is a cost and benefit to all types of censorship. Censorship of information about individuals isn't always just positive. There are lots of serial fraudsters who get away with decades of shenanigans because information about them is not readily available.
Also, and this is more controversial, I happen to think many types of privacy (but not all) are really just cultural artifacts of right now and don't have much utility from a political and economic perspective. Of course there is a value to protecting the privacy of private communication to prevent the rise of totalitarian states, etc., but some other kinds of privacy are really just around to avoid personal embarrassment. But the standards for embarrassment are always changing. At one time we were all running around half-naked and fornicating in small tribes where there was literally no privacy. So there's nothing innate in our nature that says that certain activities must be kept private. Its merely custom that such and such activities can be used to embarrass an individual.
In the future, it may be that even presidential candidates will have some embarrassing selfies distributed online, and maybe even some dic pics or boob shots from their youth ... and probably nobody will care much ... except to say ... damn, my future president has a fire crotch ... or something like that. But it will be said in passing, and nobody will care much. Just like nobody gave two shits about Obama smoking choom.
> Just one example: in the US if someone is involved in egregious fraud (such as ripping off thousands of individuals in a scam) then the US says that such information constitutes news and that even if its old information from a decade ago its relevant, and a platform like Kickstarter or Google can keep the information online for users to assess before transacting with the individual.
So long as it's profitable, scammers are going to find ways to scam no matter what, such creating fake identities in this case. I'd rather trade that against a teenager committing suicide because of revenge porn.
The teen suicide issue is unrelated. Facts, such as news stories about fraud, are not the same thing as media, such as a porn video. Regulations can easily bifurcate between the two so its a false tradeoff. What is telling is that the regulators in Europe have chosen NOT to make this distinction. And in fact they have EXPLICITLY protected people's right to purge news stories about their fraud ... showing a disdain for making such a judgment in favor of information freedom.
I do think fraudsters will attempt to use the GDPR to erase their fraud histories. Companies will need to carefully delineate what data is used as a legitimate interest vs consent bases to make sure they can continue to use fraud histories in their anti-fraud efforts.
And don't forget those GREAT cookie privacy popups on every site you visit! /s
I do. Say what you will about that connector, but it was definitely an improvement over the situation that preceded its standardization.
The fact that every website now has like 5 3rd parties tracking visitors is what requires the popup.