France latest to slap Clearview AI with order to delete data
techcrunch.com
techcrunch.com
They wanted me to upload a photo ID to verify my identity and I was stupid enough to comply.
One commenter said:
This is a case of 'never click "opt-out" on spam'. Clearview is not to be trusted. One should not go through their process. They are not likely to delete the data, and if they have none, they are likely to create a profile for you.
I should have listened, lesson learned.I think you perfectly highlight the difficulty of the current opt-out process.
I do not know how it should be done without revealing more information, except maybe by using an attorney that would have the legal power to act in your name while only revealing his information, and not yours.
> Enforcing fines on companies without an EU base does present a regulatory challenge, however.
Understatement of the year.
The question is rather: would the US step up and put pressure on the French if events would unfold in this way?
> To be clear, Clearview AI has not violated any law nor has it interfered with the privacy of Australians. Clearview AI does not do business in Australia, does not have any Australian users.
> The UK ICO Commissioner’s assertions are factually and legally incorrect. The company is considering an appeal and further action. Clearview AI provides publicly available information from the internet to law enforcement agencies. To be clear, Clearview AI does not do business in the UK, and does not have any UK customers at this time.
> Clearview AI’s technology is not available in Canada and it does not operate in Canada.
This time, and the last three times, Clearview have made the same legal argument. That because they have no physical basis in a country, and because their customers aren't in that country (though several times that has occurred post-breach), they cannot possibly have breached that country's laws.
Despite the privacy laws of every nation being around the _citizen_, not their physical location. All four places have extraterritoriality baked into their privacy laws, and all four have trade agreements with the US in place that could mean that they could ask the US to enforce compliance and make it into a diplomatic issue.
How many more times do their lawyers have to be told the same thing before they try and come up with a new argument?
How many more times do these bodies need to pass "orders" that don't result in any action before they come up with a new approach?
The US does not have GDPR. Period. Flat out. Full stop. Once you understand that, things will make a lot more sense.
And no, extraterritoriality means absolute zero here. That french citizen traveling in America? Heads up, US Customs does not have to respect to GDPR. Neither does the walmart he shops at. Neither does Amazon if he orders something online.
Claiming they do is weird, that's not how it works.
Before we are snarking about clearview having to come up with new arguments, let's evaluate how well their current arguments are working?
Pretty darn well.
And my guess is the US government, rather than shutting them down, will PAY them to do their stuff, ESPECIALLY on overseas nationals. This is exactly the type of big government "anti terrorism" surveillance style databases govts love.
Customs is part of a sovereign nation. What customs can and can't do has precious little bearing on what companies can and can't do. It's basically irrelevant.
> Neither does the walmart he shops at. Neither does Amazon if he orders something online.
Sure, if both are OK with not being able to operate in the EU _and_ believe the US government will take the political heat for refusing to enforce the EUs laws.
We also don't strictly _have_ to extradite criminals to other countries. But we usually do.
International law functions nothing like domestic law, because there is no higher power to say "no, you can't do that". If the EU can get the US to punish US companies through diplomacy, force or trades, then that's how things work. If they can't, then it's not how things work.
My guess is that the US won't shield them. It's not critical for US defense, largely redundant with data available from Facebook, and we're already fighting to keep our existing tech giants abroad. Clearview is more useful as a sacrificial pawn than trying to get it crowned a queen.
American's by and large don't want others laws enforced here. Not China's, not middle eastern laws, and they fought a war of independence against having European laws apply in the US (ie, the US killed folks over this).
A current political issue is partly the US enforcement of its laws overseas, which has rubbed many countries the wrong way. Because of the significance of the US in the current financial system the US has exercised really outsized power internationally.
As far as I know a country won’t extradite one of their citizens for something that isn’t illegal in their home country.
Or extradite for something that is legal in the country else we’d be seeing a bunch of Saudi expat women getting extradited for gasp driving a car or something.
Just raising tarrifs on some US made stuff, until this is resolved, will make many larger and stronger companies phone the US administration directly and make a deal.
As for how well tarrifs worked, see the story of the Chicken Tax and light trucks.
How many more times does France need to be told to fuck off before it stops trying to legislate in other countries?
edit: hilarious that all the people critical of the US just assume other people are American.
The social web is definetly a poorer experience without pictures, but this is the way our capitalist masters have decided to destroy our commons.
GDPR applies also outside of the EU? who exactly thought this one up? how can the EU possibly think it can enforce this and does the EU think europeans should be subject some special rules when in a foreign country?
The US does not have GDPR. The US has no law giving weight to these data commissioner orders (which appear to target US companies)