TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»GDPR Complaints Filed Against Eight International Streaming Companies
    Cyber Security

    GDPR Complaints Filed Against Eight International Streaming Companies

    January 22, 2019Updated:January 22, 2019No Comments8 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Have you been attacked? Digitpol the global investigation firm can help you, visit Digitpol’s website to learn more.


    European NGO noyb (‘none of your business’) filed ten GDPR-related complaints against eight international streaming services on January 18, 2019. The complaints allege that the concerned streaming services have not fully — and in some cases not at all — responded to the lawful ‘right of access by the data subject’ (Article 15 of GDPR) with ‘transparent information, communication and modalities’ (Article 12); and are therefore in breach of GDPR.

    Four of the companies concerned are large American firms: Amazon Prime; Apple Music; Netflix; and YouTube. Four are European: DAZN (London); Flimmit (Vienna); SoundCloud (Berlin); and Spotify (Stockholm). The maximum possible fines under GDPR range from €8.02 billion for Apple down to €20 million for DAZN and Spotify. The complaints have been filed under the authority of Article 80, which gives data subjects the right “to mandate a not-for-profit body, organisation or association which has been properly constituted”; in this case noyb.

    noyb is the brainchild of privacy activist and lawyer Max Schrems. While still a student, his complaints against Facebook made under the pre-GDPR (the European Data Protection Directive) laws ultimately led to the European Court of Justice striking down the original Safe Harbor between Europe and the U.S as unconstitutional.

    Schrems also has previous with GDPR-specific complaints. On the same day that GDPR was enforced (May 25, 2018), noyb filed four separate complaints against Google (Android), Instagram, WhatsApp, and Facebook. The Google complaint was examined by France’s CNIL data protection regulator. Co-incidentally or not, CNIL yesterday (January 21, 2019) announced a €50 million fine on Google as at least partial response to noyb. Noyb’s complaint was followed within days by a separate and similar complaint from France’s La Quadrature du Net (another internet freedoms organization).

    CNIL found that Google was in breach of GDPR in two primary manners. Firstly, it breached the principles of transparency and information; and secondly, it was in breach of the need to have a legal basis for its advertisement personalization processing. Matt Lock, Director of sales engineering at Varonis, comments, “The new fine facing Google will quickly dispel any lingering doubts that the EU would go easy on companies found in violation of the GDPR. The news should be hitting companies like a cold shower. It’s not a stretch to say that a proverbial storm is gathering as privacy groups rally to their cause and seek to uphold major global companies as examples of lax privacy controls.” Google will undoubtedly appeal this ruling.

    In the meantime, the transparency issue is of interest: transparency lies at the heart of noyb’s latest complaints. Working with eight users of the eight streaming services (effectively, proxies for noyb), Schrems’ group made data access requests against the streaming services. One month must be allowed for the response (the Apple Music request was, for example, made on October 2, 2018). DAZN and SoundCloud did not respond at all — the others did, but not to noyb’s satisfaction. Noyb measured the responses in terms of raw data, intelligibility, and background information.

    Only Flimmit provided raw data that satisfied Noyb. Only Flimmit and Netflix provided data that was intelligible. In all other cases where user data was provided, it was considered only partly acceptable — except for ‘background information’ which was partly acceptable from Flimmit and Netflix, and non-existent from the other companies. None of the eight companies — in noyb’s eyes — passes muster against GDPR, and all have had complaints filed.

    “Many services set up automated systems to respond to access requests,” commented Schrems, “but they often don’t even remotely provide the data that every user has a right to. In most cases, users only got the raw data, but, for example, no information about who this data was shared with. This leads to structural violations of users’ rights, as these systems are built to withhold the relevant information.”

    While at first glance the right of access to user data might seem a lower priority within GDPR, it provides direct access to the heart of the legislation. The background data should provide information, not merely on what data is held, but who it is shared with and where it is stored. Many people knowingly give consent for the collection of personal data, but few knowingly consent for that data to be shared with unknown third parties.

    So just as the Google complaint centered around the transparency with which data is collected, these complaints focus around the transparency with which it is shared to third-parties.

    All eight complaints have been filed with the Austrian Data Protection (DSB) authority. The DSB will pass the complaints to the regulator in the country of primary operation of the streaming services. So, for example, it should handle the Flimmit complaint itself, and pass the DAZN complaint to the UK’s Information Commissioner’s Office. These two services are de facto in breach of GDPR since they did not respond to the access request at all.

    The remaining six services did respond, so the complaints are that they did not respond adequately. Amazon Prime should be handled by the Luxembourg regulator, Apple Music in Ireland, and Netflix in The Netherlands. It is not clear at this stage which regulator will handle the YouTube complaint. 

    How long it will take for the complaints to be processed is anyone’s guess at this stage. “How long the process will now take is an unknown given the volume of [GDPR] complaints which have reportedly been made,” David Flint, senior partner at law firm MacRoberts LLP, told SecurityWeek. “although this week the French Supervisory Authority did impose a €50m on Google in response to what NOYB is hailing as one of their complaints – so possibly 9 months to a year of investigation.” 

    He believes that regulators have so much work that they are prioritizing based on apparent importance. “In the UK (and perhaps elsewhere) much of the focus appears to be on the use of data in politics following the Cambridge Analytica revelations,” he added. This, noticeably, seems to be happening on both sides of the Atlantic, with the FTC currently thought to be considering a major fine on Facebook over the same incident.

    The Apple Music complaint is interesting since Apple CEO Tim Cook has recently been attempting to differentiate Apple from other tech giants via its apparent support for personal privacy. In a speech in October 2018, he expressed support for both European and U.S. privacy laws, and commented, “Our own information, from the everyday to the deeply personal, is being weaponized against us with military efficiency.” 

    This noyb complaint will either confirm Apple’s commitment to personal privacy or expose it as marketing hype. However, it also shows the weakness in the complaints against the six companies that did respond. The Apple complaint includes phrases like, “There is a well-founded suspicion that the respondent…” and, “In addition, the Respondent seems to retain…”

    It is worth noting that the complaints seem to be based on a single access request. This is partly the reason for UK-based lawyer Dr Brian Bandey’s comment, “We don’t know at this stage what noyb is trying to do.” It has requested fines of a ‘dissuasive’ nature. But Bandey told SecurityWeek, “The key to understand is that fines and other types of sanctions bear a proportional relationship to the loss and damage suffered by data subjects. In the ‘noyb’ scenario, we cannot tell whether the GDPR Breaches have been identified through an activity undertaken to test them. If one was running such a test – it’s plausible to argue that Data Subjects would be chosen since theyíre not at risk.”

    Bandey points to noyb’s own literature, which says, “In addition, noyb will follow the idea of targeted and strategic litigation to maximize the impact on the future of your right to privacy.” Bandey isn’t sure at this stage whether the complaints are designed to be ‘structural’ (that is, serious complaints against the structure of the companies concerned), or strategic (that is, designed to highlight current GDPR weaknesses to get them improved). “As I say,” he said, “one can’t tell.”

    If the complaints are upheld, this doesn’t point to the huge fines like that from CNIL against Google. Six of the respondents did respond, just not to noyb’s satisfaction. It may be that noyb is attempting to highlight weaknesses in the companies’ GDPR implementation rather than dramatically punish them. The symmetric nature of the complaints (four U.S. companies, four European companies across at least seven different European regulators) lends some weight to the idea that these are strategic complaints.

    SecurityWeek wrote to noyb, the UK ICO, and Apple to try to get a better understanding on what is happening. None of these organizations responded. If any do, their comments will be appended to this article.

    Related: GDPR: A Four-letter Word With Global Ramifications 

    Related: Would Facebook and Cambridge Analytica be in Breach of GDPR? 

    Related: Marco Rubio Proposes New Federal Data Privacy Bill 

    Related: State vs. Federal Privacy Laws: The Battle for Consumer Data Protection 

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.