Hacker Newsnew | past | comments | ask | show | jobs | submit | buzer's commentslogin

The article says "deal". I assume that means settlement between these parties rather than actually evaluating the law?

> I am just an American, but I live in Portugal and it is legally not allowed to film people in public without their consent

If that's actual law that's a bit surprising. In many EU countries there are journalistic exceptions (which may or may not apply in this specific case depending on local law)

> (you also can't have a street facing surveillance camera like in the US)

And same here. Usually the limit is that if you do it within GDPR household exemption then you cannot have it facing street, but if you do it on GDPR scope then you need to fulfill the GDPR requirements (e.g. posting notice, be ready to answer GDPR requests, perform balancing tests for recording etc.).


According to https://superhuman.com/legal/dpa they claim that their role is processor. Processor is only allowed to use personal data they obtained from controller under controller's documented instructions. Unless those included authorization to send such an email to controller's users it's quite likely that they exceeded those. GDPR-wise (and likely that DPA-wise) that is a breach on it's own.

This was civil injunction & damages case. For court to declare judgement against Google (or any other company) someone needs to sue them. That's expensive and people in EU are not nearly as sue-happy as people on other side of Atlantic. Many courts in EU also have loser-pays model so there is huge financial risk in suing huge multinational corporation whose final legal bill might be bigger than person's lifetime earnings. And depending on country they might not even have personal bankruptcy available to discharge that.

This also heavily relies on recent CJEU ruling (WebGroup/Coyote, 16 June 2026, C-188/24) which essentially opened up the E-Commerce Directive's liability shield that platforms have been relying on so far. Essentially it said that that platform's are not necessarily neutral hosting providers when they control the algorithms that determine the dissemination. So I would expect more rulings to come, but it will take time.


GDPR Hub article, contains (machine translated) judgement: https://gdprhub.eu/index.php?title=LG_Frankfurt_am_Main_-_2-...

No. For example:

https://www.enforcementtracker.com/ETid-3171 Yangoo. UAE.

https://www.enforcementtracker.com/ETid-1912 Criteo. French.

https://www.enforcementtracker.com/ETid-3162 Intesa Sanpaolo. Italian.

https://www.enforcementtracker.com/ETid-2864 Shein. Chinese.

https://www.enforcementtracker.com/ETid-2306 Enel Energia. Italian.

American companies fines tend to be highest since they are biggest and revenue affects the fine amount.


A European-only, or even one that only primarily serves Europeans, likely won't make it to the front page as easily on the moderately American-centric HN - which further makes it seem like the only companies getting sued in the EU are American

I’d think that EU companies are also have a better shot at not running into trouble given that they’re hopefully more familiar with them

And people complained about Symbian menus...

There are multiple reasons for it. One of the major issues is that some DPAs pretty refuse to enforce GDPR (e.g. DPC in Ireland). Hopefully the changes to cross-border enforcement that are coming in force next year will help with this as it at least has some deadlines unlike currently.

Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.

Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.

Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.


They keep trying it via e.g. chat control

The US has also tried it multiple times. So has Canada. It's been shut down each time. This isn't a unique to the EU problem.

Didn't UK had "The Snooper's Charter" as well?

Encryption backdoors is not a case of extending reach for a government, but an effort to get the capabilities back.

They were able to do that before. They just want to be able to continue now.

Note: No, I don't support the idea of backdoors. On the contrary.


The fact that other countries have tried to do <bad thing> does not mean it's acceptable for another country to do <bad thing>

So why is the criticism about it disproportionately leveled at one jurisdiction?


Isn't that simply how politics works, though? People who are invested in security keep lobbying for their interests. Generally when political actors fail they dust themselves off and try again, on any issue. Also you haven't shown how the EU is diffrent from any other jurisdiction in this regard.

In the end, US doesn't need encryption backdoors because most chat and email protocols are not end-to-end encrypted and the TLS data streams are decrypted in the datacenter owned by US companies.

The protocols themselves are not important anymore. It's all variants of http to Google or Amazon. What's important is control of the end user device, and Google and Apple keep a remote root connection with "their" terminals at all time. Any data that is obtained remotely will be from the presentation layer, not the network layer. This is also harder to US adversaries to access, so an argument could be made that for the majority of normal people this is a net increase in security.

If you wanted to make the corresponsing strong argument for Chat Control and its ilk, the EU just wants (the juicy part of) what the US already has. The remote root level control of most end user devices is not under EU juristiction. So they naturally want companies operating in the EU to give them one piece of access to the presentation layer, too.

This argument is what one must be prepared for, the encryption itself is less relevant..


Exactly right.

Chat control is merely their newest attempt at this, carefully navigating around the reasons it was opposed last year.

They keep trying to legislate encryption backdoors by any means, and once they manage to get their foot into the door every other country will use that as a precedent to also mandate it.


Discussion from yesterday (811 comments): https://news.ycombinator.com/item?id=49752056

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: