Ireland blocks the world on data privacy
politico.eu
politico.eu
>As far back as 2014, the question of how Ireland would handle the new privacy rules under the GDPR was on the minds of Facebook’s leaders. As it happened, Ireland was in the process of choosing a new chief data regulator to replace Hawkes. Sandberg took it on herself to investigate the matter, lobbying then-Irish Prime Minister Kenny on the sidelines of the World Economic Forum in Davos and also at her offices in Menlo Park, California.
According to emails obtained by the Irish Independent via Freedom of Information requests, Sandberg wanted to know that Hawkes’ successor would be “as strong as” he had been in the role. But if the wrong choice was made, Sandberg suggested, there would be consequences for Ireland’s attractiveness as a destination for tech investment.
“The risk is that companies will revisit their investment strategies for the EU market,” she wrote in a June 2014 email to Kenny, adding that Ireland’s regulator should be a person who would “establish a strong collaborative working relationship with companies like ours.”
The choice of Dixon, a former Irish civil servant with a law degree but no background in law enforcement or regulatory investigation, was in line with Sandberg’s wishes. Before she became one of the most important privacy regulators in the world, Dixon had spent four years working for U.S. software company Citrix, followed by a stint at the business-friendly Irish Department of Enterprise, Trade and Innovation.
Oh, and that person makes, maybe, $150K a year. Anyone gets what I'm saying. We're all flesh and blood.
https://www.politico.eu/article/facebook-ireland-investigati...
But... let the pot-shots fly. Bad Ireland.
I live in Denmark, our data-protection agency has only recently gotten cases to a point where they could roll out fines. And that’s just for the small-scale offences that were legally easy to handle.
Some of the larger breaches will take many years to handle before a case is strong enough to be brought to the police. It’s also worth noting, that breaches of the GDPR don’t automatically lead to legal action. It’s only if organisations systematically abuse data or if they fail to fix whatever problems a GDPR audit points out to them, that legal action is the end result.
If you have a breach, like if a supplier forget to exclude an API key from their GitHub repository and I it leaves your employee names vulnerable to the entire world. But you find it, report it, fix it and tell the affected parties ie comply with the GDPR procedures. Then you’ll have breached the GDPR, but won’t have broken the law.
E.g. I think one of the recent fines was put in effect by the french privacy commissioner, even though, going by headquarters, the irish one would have been responsible. However, because french citizens were affected, the french commissioner was allowed to overrule. (At least that was my understanding how it worked)
I mean, Ireland's unwillingness to regulate internet companies is not exactly news. I imagine it was well-known when the regulation was designed (whether or not it actually influenced the design).
Where there are cross-border issues, though, the supervisory authority of the main establishment of the controller becomes the lead supervisory authority.
Sure, Ireland drags its heels but that does not prevent the data regulators in other countries from taking action.
To wit, article 56(1) of the GDPR:
>Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60.
and 56(6):
>The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.
"“We need to be careful and ensure that the margin for maneuver given by the GDPR doesn’t lead to an attractiveness competition between EU countries, as is already the case for taxation,” Marie-Laure Denis, France’s new chief privacy regulator, warned the French parliament in January, in a clear reference to Ireland."
The meta-problem here is (jurisdiction for international matters) is acute.
It totally hamstrings corporate imcome tax as a category of taxation. In the modern economy, that's a big problem. The winner-loser disparity is such that taxing company profits is the ideal strategy. The alternative is taxing revenue/sales, which is far less efficient. A Google or FB could pay a pretty hefty corporate tax without affecting their output much. They literally make more profit than they know what to do with... it's piling up. A VAT alternative doesn't distinguish between them and (eg) auto manufacturers. It also doesn't tax export revenue...
That's a done deal at this point. Politician planning on funding stuff through corporate income tax changes is a sign of naiveté and haplessness. ... international jurisdiction problems are just too unsolvable.
A regulator shopping regime for privacy regulations basically takes regular on off the table, as a viable tool.
It'll bleed into other areas as well.
>The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.
https://iapp.org/news/a/is-it-possible-to-choose-your-lead-s...
...do they? I'm an American, and I sure wish the GDPR would crawl back from whence it came. The only thing it does for me is show me gratuitous popup messages that I have to mindlessly click through.
Browser extensions to block them in the first place are still much more effective.
I contacted ICO in the UK about a breach (amazon sending unsolicited marketing emails through the order update system) - ICO told me to talk to Amazon, who said "Oh we're sorry" and ignored me. Just because it's against the law, doesn't mean companies wo'nt do it.
You can also appeal any decision of the ICO to the Information Tribunal if you're unsatisfied.
And you usually can get by those popups with reader mode - https://support.mozilla.org/en-US/kb/firefox-reader-view-clu...
Of course the big and wealthy countries in the EU want to make sure that the smaller countries aren't attractive for businesses. It reminds me of Macron's proposal to screw over truckers from Eastern Europe.
These regulators knew that GDPR was going to have an effect like this. Why are people acting surprised now? Whenever I see talk that pertains to the Irish not doing enough with the tech companies it's always politicians from countries like France and Germany. I'm guessing that they don't like that tech companies set up shop in a country that isn't theirs.
Where “not attractive for business” means “weak rule of law” tho
I'm not seeing that kind of thing happening at all.
It's just that the equation of how much to win (for a large number of Dollars brought into Ireland when Amazon opens a data center, for example), versus how much to lose (in lost regulatory power, tax revenue etc when domestic companies start asking for the same deal) looks different for a small country than it does for a large country.
...that is also the reason why tax havens tend to be small island countries. A country like Bermuda has a lot to gain from a zero-corporate-tax tax regime if it means it can fill the island with banks and law firms and little to lose if it has next to zero domestic economy and therefore it is by definition the case that the loss in tax revenue pertains to income that would have otherwise been taxed elsewhere anyway.
If you look at it objectively, most observers say the US is either the biggest or second biggest tax haven in the world.
Eg see this article https://www.bloomberg.com/news/articles/2018-01-30/u-s-seen-...
First, those islands hadn’t other ressources to sell. So to attract money in their banks they started no tax laws
And then it’s a nice place to spend a couple of days since they build hotels with the money they won on getting the no tax regulation.
Also, if Ireland wanted to be competitive for business they'd actually do something about having near-SF rents with 20-30%-SF wages. Or maybe try to foster our own companies for a change.