Hacker News new | ask | show | jobs
by high_derivative 2421 days ago
So can Europeans send a GDRP right-to-be-forgotten request to all of these?
3 comments

That's two different things. And it's GDPR.

https://en.wikipedia.org/wiki/Right_to_be_forgotten

https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

But the GDPR does have the 'right to erasure' which replaces the 'right to be forgotten'.

I don't believe the right to be forgotten here is at all relevant. It only covers the indexing of data. For example if I commit a crime a media organisation will write a story about it, google will index it, after a number of years I have the right to ask google to unlink those stories, however I don't believe it covers removal of the original story.

Certainly it's hard to believe some of this would be completely compatible with the GDPR. Perhaps you could make the argument that there is a legitimate business need to prevent fraud but from what's included in the article the data goes far beyond what anyone would consider minimal.

don't take my word for it, but I believe that you can only if they have opened a subsidiary in EU. The fine is percent of global sales (not profit).
> don't take my word for it

We definitely should not. You are wrong. In that case you are supposed to have to appoint a local representative, see Article 27.

I believe that statement is incorrect :-)
As far as I understand it, if they are processing EU citizens' data then they are liable for GDPR regardless of where they run their business from.

https://www.techrepublic.com/article/the-eu-general-data-pro...

Then I'm curious how do they enforce it. Maybe with US there are some treaties signed, but what about a foreign country that has no treaties with the EU?
To date, the answer to that question appears to be: Sternly worded letters, which will be promptly ignored.

There's no actual enforcement mechanisms against an entity that does not exist in the EU and has no financial exposure to it. That includes with the US, as far as I can tell.

Go for the payment processors - seize any funds destined for the target company, for example.