8 ms·
€1.2B GDPR fine for Meta
- jruohonen 3y agoIt is also a big blow to the DPC. There are also many other other questionable DPAs and national legislators, some of which are already under infringement proceedings. This is big news: "Furthermore, the EU's Collective Redress Directive must also be implemented this summer, which will for the first time allow collective actions by European user for GDPR violations."
- surgical_fire 3y ago> These hopes may however be shattered soon. It is not unlikely that the new deal will be invalidated by the CJEU - just like the two previous EU-US data deals (“Privacy Shield” and “Safe Harbor”). Such invalidations have retroactive effect. If I understood correctly, if they keep transferring data to the US before CJEU considers that the nee deal does satisfy regulations, they may just be setting themselves up to another record fine. I'm fine with this.
- wbl 3y agoThe locality where data rests on disk shouldn't matter for the legal process of getting access to it, and the US law takes this position. Otherwise we're going to have rampant protectionism under the guise of data protection which is part of the EU regulatory apparatus.
- surgical_fire 3y ago> The locality where data rests on disk shouldn't matter for the legal process of getting access to it This is not entirely true, though. If the data is kept abroad, that absolutely limits the legal access to the data unless the company complies - what do you do when the company decides to defy a court order and the servers are located beyond the area where you have monopoly of use of force?
- hunglee2 3y ago"The current conflict between EU privacy laws and US surveillance laws are also a problem for all other large US cloud providers, such as Microsoft, Google or Amazon" Globalised tech companies caught in the middle here, hard to see how they can continue to service global markets without a huge per-country localisation effort. Ones that could do it will increase cost (passed onto users of course), those that cannot withdraw from the market, furthering the fragmentation of the global internet. May not be a bad thing overall, especially for local players and for national sovereignty evangelists
- theGnuMe 3y agoAWS has zoned services and Amazon has country specific websites. It's not that difficult.
- bootloop 3y ago> May not be a bad thing overall, especially for local players and for national sovereignty evangelists Yep, especially if they have to play by different rules and have different values then the companies they try to compete against.
- e98cuenc 3y agoI don't see how they can continue the service, even with huge localisation effort. The capital sin is to be a US company. That subjects them to US law, including CLOUD act, which the UE considers to be incompatible with privacy guarantees. Even if cloud providers use local datacenters they are still in "violation". If the US makes a data request using CLOUD act, they will have to comply, no matter where these servers are sitting. Ironically, the UE intelligence services are happy to take the anti-terrorist information that the US is extracting with the CLOUD act and sharing with them.
- vman81 3y ago> which the UE considers to be incompatible with privacy guarantees. Well, the whole "global jurisdiction" is iffy for the rest of the world.
- 3y ago
- allendoerfer 3y agoLack of data protection is becoming a competitive disadvantage for US companies, costing the US tax money.
- capableweb 3y agoIs Meta a government entity now? Last time I checked, it was a public for-profit company, the money they pay the fine with is money they extracted from other companies, not from the government itself.
- avianlyric 3y agoLast I checked the US government taxed US corporations based on profits. One would assume that if US corporations are making less profit due to fines, then they’re also paying less taxes to the U.S. government.
- capableweb 3y agoGenerally I don't think you count profits that never happened as "cost to the taxpayer". What if Facebook spend 2B USD on a product that was supposed to be wildly successful, but it failed big time, does that count as "costing the US tax money" as they never made the profit they could have made?
- matsemann 3y agoThe point you're missing here is that it's US regulations ("we can look at your customers' data at any time and you can't even notify them") that makes it so that US companies are losing lots of money and customers from the EU. So it's not a company making a wrong bet or so. It's companies being directly hampered by their connection to the US.
- capableweb 3y ago> It's companies being directly hampered by their connection to the US. No, the companies are being hampered by not following local (EU) regulation, so they get fined because of it. Has nothing to do with where the company is from, it might as well have been Indian, Chinese or from South Africa, it has to follow the regulation in the places it does business.
- SSLy 3y agodupe kinda https://news.ycombinator.com/item?id=36028845 https://news.ycombinator.com/item?id=36028845 OTOH it's behind a stupid paywall
- ckastner 3y agoThe decision PDF is lengthy but boils down to the following two instructions on page 73: > 273. In light of the above, the EDPB instructs the IE SA to impose an administrative fine on Meta IE for the infringement of Article 46(1) GDPR that is in line with the principles of effectiveness, proportionality and dissuasiveness under Article 83(1). > 279. In light of the above, the EDPB instructs the IE SA to include in its final decision an order for Meta IE to bring processing operations into compliance with Chapter V GDPR, by ceasing the unlawful processing, including storage, in the US of personal data of EEA users transferred in violation of the GDPR, within 6 months following the date of notification of the IE SA’s final decision to Meta IE. I understand the financial incentive for Ireland to be an attractive host country for tech companies, but as the article points out, this took on truly ridiculous dimensions. Even more so after May 2018, when the GDPR was published, which -- by recognizing the protection of PII as a fundamental right -- dealt a massive blow to the "productize your customer" business model. > Ten years, three court proceedings and millions in legal costs. The Irish DPC’s role in this procedure is exceptional, as it has consistently tried to block the case from going ahead, in 2013 it rejected the original complaint as “frivolous” – requiring Mr Schrems to go all the way to the CJEU. The DPC then took the view that it cannot take action, given that Meta made use of so-called “Standard Contractual Clauses”, which was again rejected by the CJEU, who told the DPC that it must take action. Finally, the DPC tried to shield Meta from a fine and the deletion of data that is already transferred, just to be overturned by the EDPB. Overall these procedures lead to costs of more than 10 million Euro - the fine, however, will go the Irish state.
- matsemann 3y ago> “It took us ten years of litigation against the Irish DPC to get to this result. We had to bring three procedures against the DPC and risked millions of procedural costs. The Irish regulator has done everything to avoid this decision, but was consistently overturned by the European Courts and institutions. It is kind of absurd that the record fine will go to Ireland - the EU Member State that did everything to ensure that this fine is not issued." Kinda crazy how Irish regulators did everything in their power to avoid this outcome. But I guess that's why Meta and other big players are situated in Ireland, they rely on them not enforcing stuff and some meager taxes.
- rmm 3y agoWait. 10 years? So $120m/year fine? That’s a rounding error
- M2Ys4U 3y agoThe decision goes further than a fine, though. It orders Meta to stop transferring personal data of people in the EU to the US.
- mschuster91 3y agoHow is this actually supposed to work in practice, other than sharding EU and non-EU customers and having them unable to communicate across the shards?
- seydor 3y ago[flagged]
- hellotheremis 3y agoAnd the high tech of the US is privacy and rights violations?
- 0zemp2c 3y ago[flagged]
- deleted 3y ago[deleted]
- ragebol 3y agoWhat is so weird about having to adhere to the law? Can EU companies just ignore US law as well?
- tephra 3y agoIt's actually worse since the company that this opinion talks about is an _EU_ company (Meta platforms Ireland Limited). The fine is based on the global revenue but the company being targeted here, and the company that didn't follow EU laws, is an EU company.
- ahofmann 3y agoExactly. When I'm doing anything with money here in Germany, like creating a bank account, or borrowing money, I have to answer multiple questions about me being a citizen of the USA or not. Why is that? Because everyone adheres to USA law. But this should work both ways.
- WA 3y agoGood point, but not entirely true. It's not that Germans have to adhere to US law, but that US fines can be outrageously high and German institutions want to keep that risk in check. Insurance premiums are a lot higher if you do business with people from/selling to the US.
- mschuster91 3y ago> When I'm doing anything with money here in Germany, like creating a bank account, or borrowing money, I have to answer multiple questions about me being a citizen of the USA or not. Why is that? Because everyone adheres to USA law. Simple: the USA assumes global jurisdiction over anything involving the US dollar and they do not shy away from muscling over US-local branches of foreign companies to get their will.
- black_puppydog 3y agoThe team at noyb is consistenaly amazing. Makes me really happy that I'm a card carrying member. (Yes, supporters get a plastic member card. It has no function afaict, but it's the one useless thing I carry in my wallet at all times, just so I can call myself a card-carrying member. It's the only such card I carry, for anything.)
- thomascarney 3y agoPolitically, stopping data transfers to the US is not viable, because it would impact the deal between the EU and the USA (US covers EU defence for access to the EU common market). For this reason, I don't think we'll ever see a Chinese-style expulsion of US tech companies from the EU. Therefore, we've seen over a decade of a dance between the judiciary banning data transfers to the US (Safe Harbor ruling, etc) and then politicians overturning these rulings before it actually impacts anything.
- brtkdotse 3y ago> US covers EU defence for access to the EU common market Care to point me in the direction of more information about this?
- hkt 3y agoAs far as I can infer I think they might be referring to NATO?
- theGnuMe 3y agoWhat are you talking about? GDPR is pretty clear.
- thomascarney 3y agoI mean, I would agree. The EU courts have ruled pretty much every cross-border data sharing agreement with the US as illegal (e.g. Safe Harbour ruling eight years ago). The EU Commission considered that data transfers to US were not compliant back in 2000, which led to the Safe Harbour in the first place. Despite all of this, we haven't seen any creation of an EU internet, and even in this latest ruling, they've suspended the ruling until they hope the new system comes into place that will allow cross-border data transfers to the US. The point being that politically, there is no desire in the EU to cut themselves off from the US internet as you see in China, Russia, etc.
- xipix 3y agoI always thought this would be a cool thing to do if I ran Evil Corp... A = <totally random bits> B = <personal data> XOR A Store A in USA Store B in EU The data is not stored in EU, and it's not stored in USA either. It's not stored elsewhere. But Evil Corp still has it!
- jlpcsl 3y agoShould be much higher. Time for some more fines for others of Big-Tech/GAFAM spyware corporations.