> I am just an American, but I live in Portugal and it is legally not allowed to film people in public without their consent
If that's actual law that's a bit surprising. In many EU countries there are journalistic exceptions (which may or may not apply in this specific case depending on local law)
> (you also can't have a street facing surveillance camera like in the US)
And same here. Usually the limit is that if you do it within GDPR household exemption then you cannot have it facing street, but if you do it on GDPR scope then you need to fulfill the GDPR requirements (e.g. posting notice, be ready to answer GDPR requests, perform balancing tests for recording etc.).
According to https://superhuman.com/legal/dpa they claim that their role is processor. Processor is only allowed to use personal data they obtained from controller under controller's documented instructions. Unless those included authorization to send such an email to controller's users it's quite likely that they exceeded those. GDPR-wise (and likely that DPA-wise) that is a breach on it's own.
This was civil injunction & damages case. For court to declare judgement against Google (or any other company) someone needs to sue them. That's expensive and people in EU are not nearly as sue-happy as people on other side of Atlantic. Many courts in EU also have loser-pays model so there is huge financial risk in suing huge multinational corporation whose final legal bill might be bigger than person's lifetime earnings. And depending on country they might not even have personal bankruptcy available to discharge that.
This also heavily relies on recent CJEU ruling (WebGroup/Coyote, 16 June 2026, C-188/24) which essentially opened up the E-Commerce Directive's liability shield that platforms have been relying on so far. Essentially it said that that platform's are not necessarily neutral hosting providers when they control the algorithms that determine the dissemination. So I would expect more rulings to come, but it will take time.
A European-only, or even one that only primarily serves Europeans, likely won't make it to the front page as easily on the moderately American-centric HN - which further makes it seem like the only companies getting sued in the EU are American
There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.
Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.
Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.
Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.
I am not sure if you replied in good faith, but here you go.
The reason is that they have been trying again and again to do this in various forms, slightly modifying tactics so any opposition to it has to start from scratch.
Isn't that simply how politics works, though? People who are invested in security keep lobbying for their interests. Generally when political actors fail they dust themselves off and try again, on any issue. Also you haven't shown how the EU is diffrent from any other jurisdiction in this regard.
In the end, US doesn't need encryption backdoors because most chat and email protocols are not end-to-end encrypted and the TLS data streams are decrypted in the datacenter owned by US companies.
The protocols themselves are not important anymore. It's all variants of http to Google or Amazon. What's important is control of the end user device, and Google and Apple keep a remote root connection with "their" terminals at all time. Any data that is obtained remotely will be from the presentation layer, not the network layer. This is also harder to US adversaries to access, so an argument could be made that for the majority of normal people this is a net increase in security.
If you wanted to make the corresponsing strong argument for Chat Control and its ilk, the EU just wants (the juicy part of) what the US already has. The remote root level control of most end user devices is not under EU juristiction. So they naturally want companies operating in the EU to give them one piece of access to the presentation layer, too.
This argument is what one must be prepared for, the encryption itself is less relevant..
Chat control is merely their newest attempt at this, carefully navigating around the reasons it was opposed last year.
They keep trying to legislate encryption backdoors by any means, and once they manage to get their foot into the door every other country will use that as a precedent to also mandate it.
reply