T-Mobile USA doesn't comply with its German parent company’s GDPR policies
hasbrouck.org
hasbrouck.org
edit: Found it way down the page: https://www.telekom.com/resource/blob/323318/ce2bab699cb8cb2...
edit2: Fascinating, the term "independent stock corporation" seems to be exclusively used by German-speaking companies: https://duckduckgo.com/?q=%22independent+stock+corporation%2...
"Data collected in Europe shall be processed generally in accordance with the legal provisions of the country in which the data was collected, regardless of where the data is processed, but at the very least in accordance with the requirements of these Binding Corporate Rules Privacy."
His data wasn't collected in Europe.
" For Deutsche Telekom AG from July 01, 2014 in accordance with approval by the Board of Management on June 10, 2014. In the domestic Group companies, as per board approval or decision of the responsible board member."
Where's the board approval of the US board?
How about the GDPR?
" The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based organizations or not, known as “extra-territorial effect.”" (gdpr.eu)
Is he an EU citizen?
Based on his biography (hasbrouck.org/bio/whoami.html) I believe he is an American citizen. I see records about him being born in the USA and nothing about any moves to a European country (other than his world travels for activism and other short-term purposes). If he were a European citizen, I'd expect his complaints to be directed at his local DPA rather than at DT/T-Mobile directly.
I'm no lawyer so I'm not sure how legally binding his communication with T-Mobile/DT about the exact use of his data really is.
I always thought of the cost implication for T-Mobile before this thread, not that they are probably more concerned with legal exposure of people changing residency and trying to remain as customers.
They must comply to US law no matter if they are a subsidiary or not.
It's pretty naive to think otherwise
Enforcement is going to be difficult for companies owned and operating entirely outside the EU. Of course that doesn’t apply to T-Mobile.
It does apply as GDPR has no geographical limit according to the EU but they have to catch you and be able to prosecute which isn't going to be a straight pathway unless the business operates in the EU somehow.
I've always wondered that about GDPR compliance. Once your company has gone through all the effort and expense to comply with GDPR, why take on the additional expense and complexity trying to conditionally apply all this new business logic only to EU people? Wouldn't it be simpler to just use your GDPR-compliant business logic for everyone? Why maintain EU and non-EU silos?
It's like squaring the circle.
Targeting: say you are sitting in Paris and buy from a book store in the US. If that book store does not have a site in French, show prices in euros, or advertise in the EU; the fact that it is willing to, on a limited basis, ship to France almost certainly means it is not subject to GDPR.
Even the fact of offering prices in Euros is the subject of an active court case as to whether that counts as targeting.
- similarly abusive
- nationwide
- limited in number
- similar in price
You are almost always dealing with a case of government corruption. The high prices you pay for bad service are going to friends of the regulatory authority, just like a tax you never voted on.
You can see this in the US with retail banking, internet access, cell service, etc.
"We don’t care. We don’t have to. We’re the Phone Company."
Government corruption is rarely the main, or even among the main causes of oligopolies (in developed countries, YMMV elsewhere).
You're saying that the flu is a result of sneezing.
We also had very little competition due to written and unwritten agreements that allowed us to focus on specific regions.
I really think you're going to have to support this claim, because in my (admittedly US-centric) experience it is the only cause of them.
Sibling comment describing the US telco oligopoly talks about corrupt government behavior directly.
Fast die Hälfte der Millionen Kund:innen von T-Mobile in den USA waren vor einem Jahr Opfer eines riesigen Datenverlustes. Die Deutsche Telekom als Mutterkonzern verletzt seitdem ihre selbst auferlegten Verpflichtungen zum Datenschutz.
https://netzpolitik.org/2022/fast-50-millionen-us-konten-bet...
The USA desperately needs some law that says you can see what data a company has on you at anytime for free and request all of that data to be deleted as well. Anything less is just a loophole to be closed someday.
Correct me if I'm wrong, but California has some subset of this law already in place with CCPA. Unlike EU, it's theoretically possible a California judge could extend jurisdiction to my company in another state and drag my ass over there, so I have to care about it. EU has no such power over me unless I choose to operate over there and locate servers there.
For mobile they gave me a new 100% unlimited (data&speed) contract for 25€ a month. Cant really complain about that. For home internet its been rock-solid and I cant think of even one disconnection in the last years. Peering is better than Telekom as well.
I do understand that its not universal.
But O2 is a pretty good alternative. Especially if I consider than I pay one third of the price that a similar contract would cost me with Telekom.
Luckily, things have improved and network cells aren't overloaded all the time.
In the countryside, all networks are hit and miss.
However unlike mnet and Vodafone, DTAG never works, since they overload their peering links to other internet providers on purpose. This means that accessing any website or service that isn't explicitly paying DTAG to get unrestricted access to their customers, performs very poorly. See for example Youtube being barely usable in evenings for years. None of the other internet providers had that issue.
Sadly people in Germany will just blame the site being bad/slow, instead of having a closer look at their internet provider.
Yes, this is what I was trying to say. It's a while ago, so perhaps I remembered the details incorrectly.
However that's not my point. My point is that the service DTAG offers is just inferior and people that were never exposed to something better (be it never tried or just got unlucky with the alternatives when they tried), just stick with it. I would never get internet from them in Germany simply because I value having good internet connectivity (not just germany-net) and want data to flow a little bit faster than during the isdn-dialup days. The mafia-like behavior (of requiring payment from hosting providers to get usable connectivity to their customers) is just the cherry on top.
It's a very popular business model here, see DB.
DB is a bad example, fake-privatized and controlled by the government. It gets you the worst of both worlds.
I once worked for them, imagine my face when i had to call the internal IT to reset a password and ended up in a Callcenter in Bulgaria.
I was recently discussing the mediocre German internet infrastructure with a colleague and suggested that they’d probably be better off with 5G, only to find out that ‘unlimited’ 5G in Germany has insane prices (3-4 times that of neighboring countries)
Both the new connection and when I last moved (2 years ago) did not take months, but 1-2 weeks instead.
Oh, and I’m not behind CGNAT, though I don’t have IPv6 either.
This is not good for US standards, never mind European ones. It's been quite a few years since I had an hour long outage.
And this is a user who specifically tries to choose EU companies for privacy reasons. So no irony either.
"T Mobile US refuses to apply GDPR".
"This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
https://gdpr.eu/article-3-requirements-of-handling-personal-...
" The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based organizations or not, known as “extra-territorial effect.”" (gdpr.eu)
I don't see anything in GDPR or the recitals that limits that only to their processing of data of people in the Union. The recital for Article 3 section 1, recital 22, says:
> Any processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union should be carried out in accordance with this Regulation, regardless of whether the processing itself takes place within the Union. Establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.
Note it says "Any processing".
If what is being done with his data counts as Deutsche Telekom processing the data, then GDPR will apply regardless of his citizenship or location.
Note also that recital 22 says that it woulds still apply even if Deutsche Telekom were doing the processing through a subsidiary and even if the processing were not taking place in the Union. But I think that is only relevant if the processing is being done for Deutsche Telekom or under their direction, which doesn't sound like it is the case here.
For controllers and processors not established in the Union (which is what I think T-Mobile would count as) is covered by Article 3 section 2. That one is limited to data subjects who are in the Union, and applies when either of the following conditions hold:
a. the processing activities are related to the offering of goods or services (including free goods and services) to data subjects in the Union, or
b. the processing activities are related to the monitoring of data subject behavior as far as their behavior takes place within the Union.
The first requires some level of targeting data subjects in the Union. The mere fact that someone in the EU can reach your website and buy your goods or services is not sufficient. The way the relevant recital puts it they need to envisage offering goods and services in the Union.
In summary then, GDPR can apply to the processing of data of data subjects outside the Union, but only in the context of the activities of a processor or controller established in the Union (even if the processor of controller is having an entity not established in the Union do the processing). I don't think that is the case here though, so I don't think he's got much of a GDPR argument.
1. Deutsche Bahn (former state railroad)
2. Deutsche Telekom (former state telecom)
3. Deutsche Post (former state postal service)
What a coincidence.
Deutsche Bank is massively worse than any of them for society and to most customers. Vonovia is a stain on society. No doubt there are many many worse companies for various reasons than the three you listed.
Deutsche Bahn is inefficient. But I have no idea why you consider them all that terrible. Deutsche Post isnt even all that bad. Theyre one of the best companies in the public package delivery space.
DHL is bad because they underpay their employees so in a large city, employees will dump their packages at the first door, very annoying if you life in a large house with many flats, you have to search for the person who took the parcel - even if you're there they will not ring the bell, just dump everything.
Deutsche Post next to me you usually wait 30+ minutes in a long line (dozens of people) with the unfriendliest employees possible, it has a 1.9 (!) rating on Google.
(I have no car) Deutsche Bahn is incompetent, trains cancelled, too late, wrong car order, non working climate control, 1st class car missing, restaurant closed and much much more.
Deutsche Telekom wouldn't activate fiber for nearly a year although everything was build and finished. Computer said no, no one wanted to come and see that everything is ready (they installed everything) because the computer was in an inconsistent state (20+ calls plus a lot of escalation worked after nearly a year of me paying 99EUR/month 5G for my remote work).
The others pay worse, then. DHL has by far the best delivery for me, closely followed by Amazon, then it’s UPS (though they are used so rarely, my samplesize is tiny), and finally DPD and GLS. Oh, and of course there is "roll the dice delivery" aka Hermes.
When complaining about the quality of the "former state railroad", the emphasis is on "former". The Deutsche Bahn offered much better services, more efficiently and at higher reliability, when it was still state-operated.
Telekom has always been bad, of course. To be fair, some of it is due to bad regulation, but they also just seem shockingly mismanaged.
This must be a joke! DPD (DPDgroup, or whatever) is borderline incompetent.
I'm on vacation, and I needed a laptop. It was shipped from Germany ... after sitting somewhere for days. Then no information for 4 days on their tracking site. Then more information but I never had even an approximate day they would attempt delivery (let alone a 2h slot).
Said laptop is now returning to Germany, because DPD couldn't be assed to inform me they had a local partner in the country I'm visiting, or collection points, and because their local partner (owned by DPD, so corporate separation is no excuse) didn't feel like attempting delivery more than once.
It's not like they couldn't contact me: they had my email + phone + cellphone. They just didn't try (no, there's no mail in the spam folder).
I left them message on their website multiple time - it never had any effect on the "ballad of the laptop".
I've heard it from other people before, but now that I've seen it myself, DPDgroup is so utterly efficient that in comparison even USPS is a paragon of virtue at every level.
also deutsche post... what's so bad about it?
And lastly, it's way, way, way too expensive. They are seriously charging 100 € for a 2 hour trip through one state when you don't book weeks in avance.
I'm using Deutsche Bahn for 45+ years now. Before privatization trains were on time but employees thought they are managing a prision. Since privatization there are always problems. Late (they say 5min which means 10, they say 10 which means 15, they say 15 which means 30, they say 30 - it will never arrive). Trains are dirty, lots of ICE trains are old, you're very lucky when you get a new gen 4 train. Two weeks ago they had to vacate a railway car because the air conditioning broke down - everyone had to go to another railway car in an already full train. Which was a replacement ICE, because the the train I had a reservation for was cancelled. I was very lucky to be able to make another reservation in the next train, which was very full because of the cancelled train, and people were angry because they couldn't sit although they had paid for a reservation.
And they own the tracks so do everything to kneecap the competition. Some competitors that exist are much much better (e.g. ODEG).
The also had a legal monopoly on bus travel in Germany (fell after 70 years). And did everything bus travel was as unattractive as possible so people would use trains.
They have an app where you can check in. But only if you're going alone, if you travelling as a couple, you can't check in. We tried the app for some time and thought it was an UI problem or our stupidity, when a Deutsche Bahn employee confirmed that it's not possible to check in with two people sharing a ticket in one app. You need to buy two tickets - beware if you travel with two persons. As we say in Germany, #neuland.