A data ‘black hole’: Europol ordered to delete vast store of personal data
theguardian.com
theguardian.com
It’s refreshing, especially in comparison with how things are done in my country.
How much do Google and Facebook individually earn from illicit data collection & processing in just a single year? Significantly more than that. So far the only fine for Facebook is 51k (for a technicality, not actually related to their continuous GDPR breaches) and Google 50.6M which is more sizeable but still a drop in the bucket compared to their revenue.
We are "establishing new truths" here. I think it will have a good effect in the long run, even if it's not perfect.
> The watchdog ordered Europol to erase data held for more than six months and gave it a year to sort out what could be lawfully kept.
They even get a year to figure out in what way they broke the law, to legally keep as much data as possible.
The cases that make the news with 100 million dollar fines to trillion dollar companies are just the ones in which the prosecution can't even reach someone at the company cause 100 million dollars is a drop in the bucket not worth looking at.
Most of the time, when somebody contacts you because of these issues, you have 30 days to comply, and if you discover that the problem is bigger than anticipated, these deadlines can be negotiated.
The point of the laws in the EU isn't to collect fines, but rather to make sure that everyone complies. You don't win much by going to trial and letting the other party explain why complying in 30 days is physically impossible.
So as long as the other party is willing to comply, the first attorney letter get things moving, and then the issue is resolved.
Is this true? I thought they were based on a % of global revenue and that definitely hurts.
Keep in mind that large parts of the GDPR were already law in many EU countries, meaning there's years worth of enforcement activity that you can lookup to see how similar laws were enforced.
And mostly that has not been "handing out the biggest fines possible" and more "fines scaled to how grossly you violate the regulation". Companies who try their best to follow the law, have good processes and respond promptly, get a slap on the wrist or even just a warning if they remedy the issue fast. Companies that blatantly violate the law and stonewalling regulators get the harsh fines.
It doesn’t appear that they’re getting away with anything? It’s the first offence, so they get a reasonable period to address the issue and fix things. Give them not enough time and they complain about the regulators being unreasonable.
And it’s certainly refreshing compared to what happens in other America or Australia which is “basically nothing”.
Sure, better than doing nothing, but if you accept this as is you have been served a bad deal.
Also, set the budget for maintaining the dataset to zero.
Any other system is by definition warrant less surveillance, and therefore any data collection is a-ok because anyone “might” be a threat.
That’s why we made warrants required. It’s why needing warrants is literally part of the constitution.
Grumble grumble. Old man shouts at law enforcement.
How do we know how many criminals there are without making everyone a full-time suspect and surveil them 24/7?
in dubio pro reo is out of the window. Now we all have to prove that we're not part of <insert-criminal-activity>.
Another conclusion one could draw from the story as reported is that, contrary to an untold number of assertions I've seen made on HN, GDPR does apply to governments and their institutions. It's a point made in just about every single other thread on the law, and one would expect someone noticing they were wrong, which would seem to be perfect basis for a useful comment. Alas, they all missed this story. I'm sure they'll be back.
A close cousin is, of course, the sense that such institutions will choose to ignore the law, as in any law, anyway, and without any risk of blowback or even chance of becoming a matter of public interest. The story itself would seem to contradict that notion to a certain degree, but that doesn't seem to diminish the opportunity of updating one's belief system with even more evidence supporting everything one has always known to be true.
The need for data collection is not even questioned and blindly accepted. That warrants a lot of criticism. What is surveillance if not an expression of cynicism?
It's sad that the EDPS would get dragged for this, we should be encouraging them. Other than that, if you have a thirst for privacy from government and lack dementia, there really is no such thing as too much cynicism.
> Another conclusion one could draw from the story as reported is that, contrary to an untold number of assertions I've seen made on HN, GDPR does apply to governments and their institutions. It's a point made in just about every single other thread on the law, and one would expect someone noticing they were wrong, which would seem to be perfect basis for a useful comment. Alas, they all missed this story. I'm sure they'll be back.
Law enforcement are all but exempt from the GDPR, which has nothing to do with this. I'm not 100% sure but I think they're referring to the Europol regulation[0].
> A close cousin is, of course, the sense that such institutions will choose to ignore the law, as in any law, anyway, and without any risk of blowback or even chance of becoming a matter of public interest. The story itself would seem to contradict that notion to a certain degree, but that doesn't seem to diminish the opportunity of updating one's belief system with even more evidence supporting everything one has always known to be true.
We've just learned that an EU wide law enforcement agency is ignoring the law governing them, are backchanneling with the Commission to get a new law on the books to whitewash the whole thing, and that the Commission is game. And there is nothing about this in any major newspaper in the member state I'm residing in.
Do I have the facts wrong? Because it seems nuts to suggest this would be a good time for people suspicious of law enforcement and the EU to take a moment to reflect.
[0]: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...
> "drawn from crime reports, hacked from encrypted phone services and sampled from asylum seekers never involved in any crime"
Where are they getting these 1333MB CD-ROMs?
Also: that article's overloaded first sentence is NOT going to win any Pulitzers. And what kind of news article has an average sentence length of 29 words?
The Guardian usually has excellent writing -- and I for one don't mind reading long sentences. If anything, it's refreshing.
I struggle to think of a better measurement unit for a lay person.
So "the LHC produces 90 Petabytes of data per year, that's the same amount of data as streaming Avengers Endgame in 4K high-definition 40 million times! Bet their ISP wishes they hadn't offered them the unlimited data package!!" yadda-yadda?
The closest thing I can think of is 1T laptop drives.
Now I know that sounds dumb decause 1T is really just a number and you might as well just say the real number instead some other number, also, why add the pointless word "laptop"?, but the point is to make the number meaningful by comparing it to something a person actually has some concept of. I have no idea what 4 petabytes means really, but I have a some idea what a gigabyte means, and from that at least a hint of what it means that my 1T laptop drive is only 20% used.
So "1T laptop drives" is actually a more meaningful unit than petabytes.
Don't bother pointing out that laptops come with different size drives, or that probably today most people don't even have a laptop but just a phone, and have no idea how much storage it has in any real undrstanding kind of way. I know, I know. Just proves your original point.
https://old.reddit.com/r/BrandNewSentence/comments/i7p1on/ro...
"Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway." --Andrew Tannenbaum
It wouldn't surprise me that there are archive rooms lost to memory somewhere in Europol/Interpol full of CD's of data.
Are you talking about north or south?
Not legitimized by any constitution, no defined responsibilities, these Brussels organizations (sorry, the Hague!) appoint each other and assign themselves budget, and the bureaucracy grows every day.
Everyone agrees that such data exists!
I don’t know how EU pulled that off, but the work of the NSA is illegal just like Google storing EU citizen’s data in USA without GDPR enforcement is illegal too. Not to say it’s applicable.
In fact, you could break the US law from abroad. Ask Assange.
https://www.theguardian.com/music/2018/oct/12/israel-fines-n...
And, realistically, the EU can’t enforce GDPR outside the EU. If somebody in the UAE, for example, were to hoover up all the EU citizen data they can get their hands on what is the EU going to do? Send a strongly worded letter?
What would your country do to protect your rights?
https://www.dataguidance.com/news/uae-uae-enacts-new-federal...
Step 1: Declare yourself the lawful sovereign of your citizens in customary international law and be accepted as that both internally and globally.
Step 2: Define a fundamental (constitutional) human right to data privacy, see charta of fundamental rights of the European Union Article 8
Step 3: Create regulations that define how to lawfully handle the data of european citizens (-> GDPR, Police Directive, ...) and what happens if one disregards the fundamental right.
Honestly the whole thing becomes much easier to understand if one substitutes any other fundamental right, like the right to bodily integrity. A foreign corporation is not allowed to harvests our citizens organs without lawful basis (like written consent), even if it claims the law of its home country allows it to harvest organs as it pleases.
Transfer would be super slow but presumably the extreme file length would hinder decryption of the payload.
Of course the whole scheme would break down if the adversary knew the length/position of the pointer data.
Security through size?
Even if Europol miraculously agrees to delete one ZFS data pool, the other N-1 remain. So yeah, it's a PR theater. Pretty sure that the moment they found out what EDPS knows, a few sysadmins were ordered not to sleep until a big redundancy ratio has been achieved.
But it's still VERY impressive that a discussion about the tradeoffs between privacy and security is possible. That's a huge plus (if the discussion comes to being in the first place but still).
If Europol only deletes "one data pool" then it could just as well say that it will not abide.
I'm very cynical towards intelligence agencies. They will not let go of what they perceive as valuable intel.
Would love to be proven wrong but I don't see how. They can claim anything and everything and do something else where nobody is looking.
Also 4 petabytes is kind of nothing,granted you can do a lot with little to nothing when it comes to intelligence, we don't need corporation-sized exabyte oceans.
> ...
> The tussle that followed is captured in a series of internal documents obtained under freedom of information laws. They show Europol stalling for time and the watchdog telling them that they have failed to resolve “the legal breach”. The police agency appears to be holding out for new EU legislation to provide retrospective cover for what it has been doing without a legal basis for six years.
> The European Commission’s nervousness over a public clash was enough to pull Monique Pariat, the EU’s director general for home affairs, into a meeting between the two agencies in December 2021. Sources said the watchdog had been encouraged to “tone down” its public criticism of Europol.
Typical. Any talk of privacy in EU circles is mere marketing speak, void of everything. Europol won't be deleting anything and the Commission has their back on it.
It's just amazing. Anytime I read something about the Commission and compare what I've just read with the priorities they themselves have announced, it becomes clear their stated priorities are complete fiction, something someone wrote just to fill a page. You can throw in a new set of stooges every now and then but I guess a rotten institution just stays rotten.
I have observed this with many other areas, not just privacy.
Very sad to see this in contrast with what the EU could be.
Apart from survey data, there have been many referenda on EU membership or aspects of it over the years, with similar results.
Even for the most critical of countries, at the high point of anti-EU propaganda, opposition reached just a hair over 50%, which has turned out to be very unfortunate timing for the UK.
Edit: I had looked for, but forgot to include, the data: https://www.pewresearch.org/global/2020/11/17/majorities-in-...
Yeah, just not the EU power centers (the Commission for one), which were never voted for, and increasingly moved state power over to bureaucracy and unelected shadow bodies.
>Apart from survey data, there have been many referenda on EU membership or aspects of it over the years, with similar results.
Yes. And when they failed, they were repeated to taste or merely ignored.
(And ahead of those, the EU bodies devoted lots of funds to "educational" campains on those matters to promote the desired results in the press, yielded bribes, sorry, developmental packages and exerted pressure, in a carrot and stick manner, to get nation states to vote favorably).