Google users in UK to lose EU data protection – sources
reuters.com
reuters.com
Not quite all of EU law will be retained:
https://researchbriefings.parliament.uk/ResearchBriefing/Sum...:
> [T]he UK is specifically not retaining:
> * the Charter of Fundamental Rights of the European Union;
> * the legislative instruments known as EU directives themselves (as opposed to the legislation implementing them or rights and obligations under them, which will be retained);
> * the principle of supremacy of EU law (for prospective legislation); and
> * the Francovich principle of state liability (in relation to post exit facts).
1. The Charter does not extend the ability of the Court of Justice of the European Union, or any court or tribunal of Poland or of the United Kingdom, to find that the laws, regulations or administrative provisions, practices or action of Poland or of the United Kingdom are inconsistent with the fundamental rights, freedoms and principles that it reaffirms.
2. In particular, and for the avoidance of doubt, nothing in Title IV of the Charter creates justiciable rights applicable to Poland or the United Kingdom except in so far as Poland or the United Kingdom has provided for such rights in its national law.
Article 2
To the extent that a provision of the Charter refers to national laws and practices, it shall only apply to Poland or the United Kingdom to the extent that the rights or principles that it contains are recognised in the law or practices of Poland or of the United Kingdom.
> "... does not intend to exempt the Republic of Poland or the United Kingdom from the obligation to comply with the provisions of the Charter or to prevent a court of one of those Member States from ensuring compliance with those provisions"
this is a common criticism of the EU and the ECJ: what was negotiated by the member states during treaty revision is irrelevant if the ECJ can strike out whichever bits of it pleases at will (with no appeal/recourse possible)
The GCHQ really, REALLY wanted out of the fundamental charters of rights. I mean the ECJ has ruled like twice or thrice against their mass surveillance activities, but they've managed to buy time by "updating the law" in ways in which a new ruling was needed to show once again that their mass surveillance laws are STILL violating the charter.
I would be more optimistic if the UK government didn’t appear to hold the position “pivot to a no-manufacturing/service-only economy while simultaneously aiming for a trade deal that only covers food, mining, and manufacturing but not services”.
That is basically true. And the economics of this sort of situation is kinda funny; the only way Britain will be materially worse off is if the EU was giving Britain a free ride before Brexit - otherwise market forces will probably kick in and not much will happen in practice. Realistically it is hard to see Britain being worse off because of anything externally inflicted. If anything, their biggest losses will be due to getting the stuff they want; like restricting migrant inflows for non-economic reasons.
economic losses
Isn’t that the point of the club? To give all of the members a free ride with each other? In a well-defined way that doesn’t hurt each member but still a free ride?
If everyone is underpaying then it isn't free riding; it is just sensible business.
I’m not going to be too precise with terminology, but I didn’t realise you were being precise either or I would’ve at least looked up the concept before my previous reply.
A simple sort of plan that British companies might have could be, for instance, to not require tons of annoying cookie popups on their websites.
In other cases expect laws to get tighter. EU financial regulation isn't as solid as the UK's is. This was a sore point after the collapse of the Icelandic banks. British regulators had raised the alarm over those banks but could do nothing to stop them because they were regulated by Iceland and under EU rules the UK had to allow them to trade. When they went pop and the Icelandic government refused to bail them out, the Brits were left carrying the can. Given that financial regulation is popular with the public I'd expect that to be one of the areas in which regulations diverge.
GDPR, and every other bit of EU privacy regulation, has included exemptions for the security services.
On the day thre results came in I had been of the opinion “it can’t be too bad, because only an idiot would hold a referendum on something important where the wrong result was possible” — Although it quickly became clear Brexit was inherently a terrible plan implemented by incompetent politicians, and therefore Cameron was in fact an idiot, adding to my reasons to leave the UK.
Perhaps you believe that whilst the member states are pro-mass surveillance, the EU itself isn't?
https://www.politico.eu/article/europe-spy-school-defense-po...
There's no real difference between countries on the matter of mass surveillance. I wish it were the case, but it's also hard to argue that they should be totally pro-privacy and shutting down their intelligence agencies when the public doesn't care and in fact, a big chunk of the public wants better protection from terrorism.
Whilst the consensus on sites like HN may well be that mass surveillance is dangerous and bad, that argument hasn't been won with the general public. At least, not yet.
I’m aware. The point is that a court that can override a government is the only way a private person like me could possibly limit such an agency to the strictly necessary — and even then only when their excess gets leaked, because the courts obviously can’t know about it before then.
I'm sorry, but the will of the people is never "wrong"
The city I live in has gold-coloured plaques on the ground outside random homes memorialising all those who died because the people elected a dictator.
Democracy is “least bad”, not “incapable of fault”.
Those people died "because" the people elected someone, in the same sense they died "because" that persons mother gave birth to them.
Did the dictatorial killing take place transparently within the rule of law?
Within the rule of law, yes — though the standards of international law were changed retrospectively after the event because of how obviously evil it was.
Transparently? I’m not sure. What would your standard be for that?
I’m not sure why you see your point as a relevant counter-argument though: the people voted, several minorities were systematically exterminated.
My point is, a mother had a child, several minorities were systematically exterminated.
It's the same dubious causal linking, unless the people directly voted to exterminate minorities.
I will not name him. Naming him serves no benefit, especially as I do not wish to conflate him with Leave, merely to demonstrate that democracies are capable of being wrong.
Are you possibly trying to avoid invoking godwin's law?
Remember the specific thrust of argument in this subthread isn’t to demonise Leave voters it’s just to demonstrate that it’s possible for democracy to give bad answers. Mentioning He Who Cannot Be Named isn’t going to help separate concerns here, rather the opposite.
If that implies true answers can be bad, I agree: they can upset whoever one is trying to communicate with to the point they shut you out entirely.
History is my source of facts, not me personally. If I am not being unambiguous already, then there is more than one example of the situation I have described.
Many people won't know about these. They're called "stolperstein" - "stumble stones". https://en.wikipedia.org/wiki/Stolperstein
> A Stolperstein (German pronunciation: [ˈʃtɔlpɐˌʃtaɪn]; plural Stolpersteine; literally "stumbling stone", metaphorically a "stumbling block") is a sett-size, 10 by 10 centimetres (3.9 in × 3.9 in) concrete cube bearing a brass plate inscribed with the name and life dates of victims of Nazi extermination or persecution.
> The Stolpersteine project, initiated by the German artist Gunter Demnig in 1992, aims to commemorate individuals at exactly the last place of residency—or, sometimes, work—which was freely chosen by the person before he or she fell victim to Nazi terror, euthanasia, eugenics, deportation to a concentration or extermination camp, or escaped persecution by emigration or suicide. As of 23 October 2018, 70,000[1] Stolpersteine have been laid making the Stolpersteine project the world's largest decentralized memorial.[2][3]
> The majority of Stolpersteine commemorate Jewish victims of the Holocaust.[4] Others have been placed for Sinti and Romani people (then also called "gypsies"), homosexuals, the physically or mentally disabled, Jehovah's Witnesses, black people, members of the Communist Party, the Social Democratic Party, and the anti-Nazi Resistance, the Christian opposition (both Protestants and Catholics), and Freemasons, along with International Brigade soldiers in the Spanish Civil War, military deserters, conscientious objectors, escape helpers, capitulators, "habitual criminals", looters, and others charged with treason, military disobedience, or undermining the Nazi military, as well as Allied soldiers.
It was a vote at one time, once, 4 years ago, with a 2% victory.
The "will of the people" excludes all desires and agency from 15m+ people, who did not want this, in a civilised society subsuming those people to be "wrong" or to be ignored is a recipe for some deeply unpleasant and authoritarian thinking.
Also, 17 million people elected Hitler in 1933 in Germany, that did not make it "right". Dangerous times.
What criteria should I cherry pick in order to invalidate a result? Can I apply the same logic the the one that added the UK to the EU?
> in a civilised society subsuming those people to be "wrong" or to be ignored is a recipe for some deeply unpleasant and authoritarian thinking
I didn't describe remainers as "wrong", I responded to a comment describing leavers as "wrong".
However, as to "ignored" - why not? I'm sure it's unpleasant to lose a democratic vote, but its not "authoritarian".
> Also, 17 million people elected Hitler in 1933 in Germany, that did not make it "right"
Make what right? That they elected him? or that he became chancellor?
Conflating brexit with Nazi elections is what I consider truly "dangerous". Many things happened after that election that contributed to the rise of Hitler.
Yes, and you must — otherwise the vote to leave isn’t legit in the first place.
> I didn't describe remainers as "wrong", I responded to a comment describing leavers as "wrong".
What I wrote was “…only an idiot would hold a referendum on something important where the wrong result was possible” [added emphasis]. That’s not leavers being wrong, that’s leave being wrong. Politically, it was the wrong move for the PM and you can tell by him resigning immediately. I think that alone is sufficient to call him an idiot for having called the referendum, which is what I was doing. Him and his successors being idiots is the main reason why I think this is going to be much, much worse for the UK, not the mere fact of leaving the EU, the departure from which is something I estimate to be a “economically bad but if you want it that’s your call”.
There was no vote to join the EU, we joined when Edward Heath signed us into the EEC.
There was a vote a year later as to whether we should remain in the EEC, for which 'remain' won.
RIPA put a stop to a lot of the worst snooping, and gave real protections to citizens for the rest of it.
There are parts that are worrying (key disclosure), but so far that's not being misused.
https://curia.europa.eu/jcms/upload/docs/application/pdf/202...
regardless, the critisism of the ECJ still stands: it operates as a political court that almost always rules in such a way that extend the EU's power over that of its member states
even when the letter and the spirit of the treaty was the complete opposite (as in the above example)
Why not link to the actual source? http://curia.europa.eu/juris/celex.jsf?celex=62010CJ0411&lan... Perhaps because the judgement clearly says sensible things like:
> In addition, according to the sixth recital in the preamble to that protocol, the Charter reaffirms the rights, freedoms and principles recognised in the Union and makes those rights more visible, but does not create new rights or principles.
Additionally, let's consider the alleged opt out, Protocol (No 30), itself. Its Preamble literally says:
> the aforementioned Article 6 [TEU] requires the Charter to be applied and interpreted by the courts of Poland and of the United Kingdom strictly in accordance with the explanations referred to in that Article
In summary, the UK and Poland signed a legal document. They then, for political reasons, signed a meaningless political statement saying ‘we don't really like this’. Of course the political statement carries no legal weight compared to the legal document.
the ECJ later ruled that the opt-opt had no force
Poland alone isn't enough anymore to keep that view of the EU since the UK left.
This artifact alone is legitimate grounds for non-participation in any such union.
And there you have laid the foundation for the obliteration of liberal institutions.
This purview has taken hold in the last 50-ish years around the world, leading to Judicial Supremacy.
I would use a polite term like 'absurd', but I think 'stupid' is a better term for the powers that courts have evolved to have, to the point wherein they de-facto make the law, which is not correct.
If the EU legislators, with 1000's of the nation's top lawyers, cannot enact legislation that is lawful, then something is very deeply wrong. How is it that a handful of other lawyers, sitting in a different institution can have a fundamentally different reading of the same thing?
Any ruling by the court that overturns relatively recent legislation should cause calamity and consternation.
At very least there should be a means to translate legislation into law that facilitates the participation of some officials to make sure that it's legal.
It's ridiculous that Europe's top lawyers make a treaty, and then some of Europe's other top lawyers say that it's illegal, whilst all reading the same, plain document. If the constitutionality of a law is 'not apparent' to Europe's top lawyers, then it's definitely not apparent to the other lawyers at the ECJ either; there should be a different process for determining the constitutionality of laws, that is separate from more common judicial rulings. And definitely the ECJ should not be able to rule on its own jurisdiction, this is crazy.
Love this bit from Wikipedia:
"The court ruled that the Community constitutes a new legal order, the subjects of which consist of not only the Member States but also their nationals. The principle of direct effect would have had little impact if Union law did not supersede national law. Without supremacy the Member States could simply ignore EU rules. In Costa v ENEL (1964), the court ruled that member states had definitively transferred sovereign rights to the Community and Union law could not be overridden by domestic law."
These are revolutionary proclamations.
"Oh, by the way, that treaty you signed that you thought meant that thing, well, we're going to rule that we have all the power. So, guess what, it meant something you didn't understand, and what you didn't know is that you were literally handing over sovereignty to us. Thanks, we own you now"
Opting in after Law and Justice opted out is pretty much impossible because two-thirds majority is needed for that, and Law and Justice would block attempts to do so.
It quite literally says the opposite of that. I don't think Google could continue to do business in the UK if they just ignore regulation, nor could they ask users to waive their own rights.
All this seems to be is moving the location at which data-related requests for the UK are handled, which is probably because the Irish office is smaller and it is easier to keep them focussed solely on EU law.
This is very different from British privacy rules applying to private requests for data.
Under the GDPR, and presumably British law, a private person can get a copy of your data and demand that it be deleted. According to your quote, there's no suggestion that will continue to be available.
It may, or it may not, but it is not specified.
UK citizens also won't be able to appeal all the way up the EU courts: it stops at the UK supreme court.
And most importantly: now that the UK is out of the EU, it is a tiny, barely relevant factor in multinational corporate online practice. Any business that gets told by the UK to follow their GDPR can quite comfortably go "lol, no" and barely affect their bottom line, as opposed to having the entire EU block go "obey our GDPR or we won't let you do business in any of these 27 nations, a large portion of which make up a substantial cut of your global revenue".
The biggest players won't, of course, but smaller companies?
How can you comply with one but not another given they are exact copies of each other?
Poorly informed comments like this pop up a lot, they don't understand the reality of just how big the UK economy is compared to the vast majority of coutnries that make up the EU.
The UK was 20% of the EU's GDP, 1/5th of the total GDP out of 27 countries.
I agree with you that the language barrier is stop going to be at least somewhat important.
Obviously exact orders will depend on the estimate and how fair it is to use 2019 figures and then subtract the UK from them.
But however you slice it, the UK is not pocket change. Maybe smaller companies can ignore all but the largest three, but I doubt it.
It's more likely that the UK will prefer a more liberal market, and for that reason their laws will be a little ignored - they won't enforce them and will forever be planning their repeal even if they never quite get there.
Fair. I mean in the sense of being influential enough to set the rules, standards, and norms.
> Maybe smaller companies can ignore all but the largest three, but I doubt it.
I guess the logical question is: How many companies ignore the Japanese or Indian markets?
1) United States 20,544,343.46
2) China 13,608,151.86
3) Japan 4,971,323.08
4) Germany 3,947,620.16
5) United Kingdom 2,855,296.73
6) France 2,777,535.24
7) India 2,718,732.23
8) Italy 2,083,864.26
9) Brazil 1,868,626.09
10) Canada 1,713,341.70
So out of "EU" it's only Germany which was larger according to those figures (from the World Bank).Of course things will have changed over the last couple of years, but I doubt it is substantially different in terms of order.
In reality the EU is not a unified market for e-commerce because of the language barriers and very large discrepancies in laws. For example, France has some pretty crazy stuff to protect the French language, Germany is very strict about certain subjects and the denial of them like the holocaust. And while there are some top level EU laws or efforts to police the bigger internet players, enforcement is still mainly regional too.
I'm under no pretensions that the UK is far, far from the super-power status of the US or now China, or previously USSR.
But if we're a blip, most countries in the world aren't even a notch.
That is the impression I’ve been getting from what economists have been saying. Of course, not being in economist myself, there is no way for me to tell if I’m reading real economists or merely people wearing economist clothing.
California emissions standards for automobiles dictate how cars are made for the entire USA. The UK has almost double the population of California and is a huge online market.
https://techcrunch.com/2019/12/19/more-legal-uncertainty-for...
So it’s not unlikely that the US and UK will be considered unsafe countries for handling personal data of EU citizens due to their aggressive stance on digital spying and surveillance.
This means that Google is removing data protection from UK users. There is absolutely no way to claim in good faith that you can protect your users when the data exists (or is touched in any way by, but that's another story) in the US, the examples for which we've seen often enough that every reader can be assumed to be familiar with them by now.
On the other hand, the EU has been threatening to refuse to agree on the same for the UK, despite both having the exact same data protection frameworks as it currently stands. The actual rules have at least as much to do with internaational politics as they do with protecting people's privacy.
For a while playing games with physical location was a neat legal hack in the US specifically, but the USG closed that loophole a few years back if I recall correctly and can now force US firms to give up data even if it's in a foreign datacenter.
The issue is not about technical feasibility, it’s about exposure to legal repercussions.
You can argue that respecting EU laws might expose you to prosecution in US and vice-versa, and that’s absolutely true. International law is messy.
Essentially UK data protection says you can't put data beyond UK's law ability to enforce data protection rights, as that's clearly 'getting around' the law.
The privacy shield is the latest pretense that somehow having the data under US jurisdiction, with a promise to behave nicely, is ok. However that promise is fundamentally worthless as US law takes precedence over that promise. Specifically the US government can demand US companies hand over the data, whatever they have promised to UK customers.
That kind of issue is exactly why UK data protection law talks about jurisdiction in the first place.
The only real logical legal solution to this is to have a world court on these issues - but everybody is trying to avoid that politically unpalatable outcome.
You can talk about Brexit- but this is the real sovereignty issue in the 21st century.
As I understand it, The GDPR is mostly concerned with the protection of routine usage of data, mostly by business and lower levels of government, rather than the government or security agencies accessing the data as part of a legal request or investigation. Indeed, the UK pretty encourages the NSA to access data on UK citizens as part of Five Eyes (and other parts of the EU as SSEUR and Nine Eyes).
I'm no expert, but I'm guessing the idea behind those safe harbour type agreements is that both the US government has a well developed legal framework and was willing to sign a law allowing EU companies to enforce DPA violations on their own companies in the relevant context. As long as the companies have the legal requirement to protect EU data in an equivalent way to an EU company, and there are legal routes to enforce it, I don't see anything particularly wrong about them in principle.
The issue of US companies allowing access to EU citizen data is an important one, and one I believe needs more attention, but it's unlikely to get it because it's by design at this point. And storing data in AWS UK doesn't exactly get around that, because the US government can just force their UK subsidiary to exfiltrate the data. But also I don't think it's strictly relevant to the GDPR safe harbour style provisions.
But if there is US law which overrides that promise then it's not legally enforceable. That's why jurisdiction is so important.
I'm not picking on the US particularly - I might have the same concern if I was an EU citizen and my data was in the UK post brexit. Or I was a US citizen with data aboard.
> And storing data in AWS UK doesn't exactly get around that, because the US government can just force their UK subsidiary to exfiltrate the data.
I'd agree even keeping it in the UK is now not a help from a US law perspective. The following case is very instructive: https://en.wikipedia.org/wiki/Microsoft_Corp._v._United_Stat...
Essentially the CLOUD Act - tries to give US government the right to demand US companies move data to the US - as I said - any promise a company makes is worthless. A lot of countries might see this as a the US trying to extend it's legal reach beyond what is reasonable.
The EU say the CLOUD act is not compatible with GDPR without further international agreements. https://www.insideprivacy.com/data-privacy/european-data-pro...
Currently the EU is playing nice, but it could decide to then charge the US companies officers with crimes ( stopping them ever visiting the EU ), or investigate the local offices etc.
If we don't sort this out internationally then it could easily escalate - with the companies stuck in the middle.
At the moment that has been a lot of LALALAL nothing to see approach to this, but the law is catching up with the technology - these issues can't be glossed over forever.
Now that Britain has Brexited it needs to make a trade deal with the US. Why won't the US insist on things like lesser data protections and software patents as part of the trade deal? Now that Britain is in a weaker bargaining position, how will it avoid implementing these things?
However it hasn't happened yet, so we don't know. What we do know is that there will need to be an act of parliament and we won't just magically lose protections at some arbitrary date
On the 28th February 2019 The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019[0] was made.
These Regulations basically patch the GDPR to remove the buts about working with supervisory authorities in the EU, changes the references to supervisory authorities to name the Information Commissioner, confers power on the Secretary of State instead of the Commission and stuff like that.
The substantive provisions of the GDPR remain unchanged. There's what's known as a "Keeling Schedule" (which is essentially a visual diff of the changes) available as well.[1]
[0] https://www.legislation.gov.uk/uksi/2019/419/introduction/ma...
[1] https://assets.publishing.service.gov.uk/government/uploads/...
Recent examples include Mark Zuckerberg (Facebook over Cambridge Analytica) and Irene Rosenfeld (Kraft; reneged on promises to UK government over take over of Cadburys. Refused 3 times).
Or if we were able to successfully extradite US suspects in the same way our citizens could be extradited to US. Recent examples are.. so numerous and high profile you can just google yourselves.
The UK might not have a “small” economy right now whilst we’re still in the transition phase but we’re still not powerful enough to get justice from US corporations as it is.
How will the balance of power shift after we’ve negotiated new trade agreements from a position of weakness?
https://www.hipaajournal.com/does-gdpr-apply-to-eu-citizens-...
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Otherwise there would be no way to know who you are without having your data in the first place which means the law is a catch 22. The only working interpretation is based on physical location.
Surely my physical location is no less part of my data than my citizenships? I guess if it's being processed immediately when it's collected it's possible to gdpr it or not, but if it's an offline process, then how can you do that?
Anyways it's based on physical location. There are lots of specifics around what PII is but in this case: 1) your location alone cannot identify you individually, and 2) nothing specific is stored and IP/network to region lookup for applying GDPR rules is acceptable.
Also, hat part of my comment do you believe that you quoted? The only quote I see if from the article I linked to in the revised comment.
Incidentally, when it comes to the GDPR, the term is "personal data", not "personally identifiable information" which is a US term.
2) The point of location data not identifying you is in response to the parent comment saying that location could also be considered personal data. It can, but only if used in conjunction with enough other data to uniquely identify you; not to just check if you're currently in the EU.
3) Using a VPN prevents GDPR enforcement if your location is inaccurate. Again it comes down to the law preventing your personal data from being used before you consent, so whether your location is a fact or not doesn't matter when the service provider isn't allowed to use it in the first place and must rely on network lookup for a best guess.
Now the question is if any random corner store in Indonesia is going to respect the EU decision.....
I also looked at the text in Article 3, "Territorial scope"[1], and that says it only applies to EU-based organisations and "data subjects who are in the Union". It seems to me that "in the Union" means "residing in", and not "citizen of"?
The third clause says it applies to "a place where Member State law applies by virtue of public international law", but I don't think this applies to Indonesia?
IANAL, but I think that is primarily a reference to member state embassies, consulates, overseas military bases, ships having member state flag in international waters, aircraft registered in a member state, and spacecraft operated by a member state. So GDPR would apply to data kept in a member state embassy/consulate in Indonesia.
In practice, a lot of the work embassies/consulates do may fall into one of the exemptions from the GDPR – national security, etc. But embassies/consulates often also do other stuff, like host conferences, workshops, dinner parties, etc. GDPR may well apply to data collected for those purposes.
Also the law is based on physical location (either companies or people in the EU at the time), not your nationality or citizenship which would be unknown without access to the very data the law is trying to protect.
If you're a foreign company selling to EU citizens you can be subjected to EU fines because there's usually a trade deal that says so.
But yes, checking the nationality of all your customers isn't feasible, but I bet the waters get murky when requests, such as data access or deletion requests, come after the fact, with proof of EU citizenship.
As for trade deals, the Safe Harbor agreement that would have allowed this was repealed before (and partly because of) GDPR. The only deal in place now is Privacy Shield which is completely voluntary and has no cross-border enforcement.
If none are then the GDPR does not apply
...
Your service provider and data controller is now Google LLC: Because the UK is leaving the EU, we’ve updated our Terms so that a United States-based company, Google LLC, is now your service provider instead of Google Ireland Limited. Google LLC will also become the data controller responsible for your information and complying with applicable privacy laws. We’re making similar changes to the Terms of Service for YouTube, YouTube Paid Services and Google Play. These changes to our Terms and privacy policy don’t affect your privacy settings or the way that we treat your information (see the privacy policy for details). As a reminder, you can always visit your Google Account to review your privacy settings and manage how your data is used. If you’re the guardian of a child under the age required to manage their own Google Account and you use Family Link to manage their use of Google services, please note that when you accept our new Terms, you do so on their behalf as well, and you may want to discuss these changes with them.
At least they have their own independence day now.
Under section 3 of the European Union (Withdrawal) Act 2018,[2] the GDPR will be incorporated directly into domestic law immediately after the UK exits the European Union.
[1]: https://en.wikipedia.org/wiki/Data_Protection_Act_2018 [2]: http://www.legislation.gov.uk/ukpga/2018/16/section/3/enacte...
over time UK law will diverge from EU law (in the same way that US law diverged from UK law after 1776)
Realistically you can only write your own laws if you're the top dog.
https://www.techdirt.com/articles/20180605/22253339978/eu-co...
Consent should be given by a clear affirmative act [...] Silence, pre-ticked boxes or inactivity should not therefore constitute consent. [...]
So, all those websites that have preticked boxes where you share data unless you untick them are in violation of the GDPR (unless the personal data is required for the site to function). So are websites that only present an 'accept/ok' option, since processing personal data is typically not necessary to retrieve the page:
When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Websites that are designed to let unattentive users consent to data by e.g. clicking the most visible button are probably in violation as well, since it is not a clear affirmative act.
Don't track your users and boom: you need no cookie banner. EasyI
The cookie pop-ups is definitely not GDPR - it is a separate thing called the ePrivacy Directive and came about many years before GDPR.
GDPR and ePD are both wonderful for consumers. I am fairly annoyed that the implementation and skirting by 90%+ of websites is due to them not being able to monetize our data or track us.
I suspect the rate of non-compliance is closer to 99%+ considering most of the annoying cookie banners I see pop up are actually not following the guidance.
Cookiebot seems the closest to me (defaults to only required cookies, etc.)
I don't think that's a bad bet given that Downing Street is keen to make clear food standards and the NHS are also up for grabs.
If anything, data protection is so badly understood as being important to ministers, it would not surprise me if they trade it away in order to protect food standards and the NHS because they're more prevalent in the headlines and scarier to the over-50s that predominantly voted for Brexit and this government.
But it's also a bit weird. I mean, I guess the issue with the NHS is drugs. Australia has long had policies the US doesn't like, like the single purchaser PBS and parallel imports. But we still have a FTA with the US.
I believe they called it project fear
Quite why these scare stories persist is beyond me. Has rationality left Hacker News as well?
You can call them scare stories, but in truth your denial running contrary to all known actual evidence is a real problem here.
For example, I lived in the UK when I opened my Google account(s), but now I live in Portugal. Do I need to inform Google of this somehow. Do they look at my payment information, or at my recent logins? I certainly cannot see any 'what country do you live in' options in my account settings.
I'd certainly prefer to keep any EU data protections should I have the choice.
I assume that means my account now counts as Danish.
However, the lede is somewhat buried:
“There’s a bunch of noise about the U.K. government possibly trading away enough data protection to lose adequacy under GDPR, at which point having them in Google Ireland’s scope sounds super-messy,” Kissner said.
It's possible that, over time, the UK will adjust its laws and lose EU "adequacy". This currently seems unlikely so the game, from Google's point of view, is to work out whether to move out early and cause a sensation or to wait until it happens (if it happens) and then make a rush then.
It's complicated because things may change gradually, over a long period of time, and there may be some things that are advantageous earlier or later. Also, Google might not want to put itself in a position where it appears to be trying to influence British law: "if you change that particular thing, we'll move out". If they do it up-front under the guise of Brexit then they put themselves in the best possible position to use the data as they wish (within whatever law applies) and avoid such accusations later.
This is complex and involves a lot of game theory.
Smaller companies don't really need to comply since the possibility of prosecution is negligible.
Big companies do because the possibility of prosecution is almost certain.
That is not a bad bet given briefings from Downing Street on trade deals.
GDPR is nightmare that has not improved anything except now we have to click for both cookies and GDPR form. I don't feel protected by it, mostly annoyed. And a lot of sites did the smart thing - just cut off access for EU ips - thanks Brussels.
It seems like US institutions like to take a big player, make a huge case and then hope everyone else is scared enough to follow. In EU on the other hand the first inquiry would be validate the practices, allow corrections and if they aren't timely start stepping up the fines.
In the end you end up with the huge cases like for example the browsers or Apple tax payment and by that time you have a law with regulations and previous judgements to stand on creating a system that's hopefully understandable and easy enough to follow for the regular user with good intentions.
This is a big improvement - there is a sense of companies going from hoovering up every PI data point they could, to treating PI as a liability. That's a big deal.
I mean seriously. If the GDPR had any teeth, the companies that do this shit would be made to suffer. But since all they do is make us suffer and the EU dgaf I wonder what the point is. It's just so much privacy theatre.
Maybe there's a shift somewhere. But I can't feel it as a user.
See e.g. [1] and [2].
Is it perfect? No. But these kind of things don't change overnight.
[1]: https://www.zdnet.com/article/guess-what-gdpr-enforcement-is...
Nice! I was entirely wrong about what I thought would happen. If I were starting up I'd probably ignore building the entire framework to start with and deal with it when I have to.
https://www.enforcementtracker.com/ https://en.wikipedia.org/wiki/GDPR_fines_and_notices
If not, you can go to the data agency of the hosting provider's country and lodge in a formal complaint that can lead to an actual investigation and fine. It really works!
Did the author mean "US", or "UK?
This article seems confused. I don't think the author knows what they are writing about.
> This article seems confused. I don't think the author knows what they are writing about.
They meant US, and the authors clearly weren't confused:
> If British Google users have their data kept in Ireland, it would be more difficult for British authorities to recover it in criminal investigations.
> The recent Cloud Act in the United States, however, is expected to make it easier for British authorities to obtain data from U.S. companies. Britain and the United States are also on track to negotiate a broader trade agreement.