| ▲ | maccard 13 hours ago | ||||||||||||||||
I understand. I'm generally a proponent of the spirit of the law rather than the wording of the law, and I've argued that is how the EU works here in the past. I think GDPR is a much, much better attempt at solving the problem, and has made meaningful change in tech industries. The ePrivacy directive just added pseudo-mandatory popups to every company without a technical lawyer. | |||||||||||||||||
| ▲ | spwa4 13 hours ago | parent [-] | ||||||||||||||||
Why? The whole point of the GPDR was to prevent medical information being used for insurance and all sorts of purposes. Then come the lists of what exceptions are approved. Your medical info is used for divorces (anything involving court cases, anything involving criminal law), the police has access to it, your mayor has access to it, tax departments have access to it (think you can not pay tax and pay for your kid's cancer treatment instead? In Europe, think again). Insurance (if you get treatment for getting hurt in traffic your car insurance goes up). Unemployment (if you get treated for anything drug-related ...). Hospitals and doctors can use your medical information without your permission (for billing, for other treatments, for deciding if you should be interned, ...). And so on and so forth. Oh and there are even silent exceptions. You see, YOU can't sue anyone under the GPDR. You can only ask a specific "supervisory authority" (you can't even choose which one) They are under control of the executive, and so it is in most cases the currently elected party that decides if your GPDR complaint does anything, NOT the courts. Not the police. Not the public prosecutor. None of that. And it's even closed on the back end: you don't agree with these "supervisory authority"'s actions? Doesn't matter if you're complainant or defendant. You can't sue them either. You can't get a judge on your case, only appointed politicians. There are even organizations that the GPDR supposedly applies to that have their own supervisory authority. Interpol violated your rights? No worries, file your complaint here in this building. You know, the building with "Interpol" on it in big letters. So really, we do not even know the full list of exceptions. More generally, the GPDR was supposed to prevent further encroachment of all sorts of organizations on privacy, with a big focus on medical data. It has achieved the opposite of that. FOR NOW (and not in every country) the only way to get a private medical file is to only use private medical care. For now that is still possible. It's like the DMA (Digital Markets Act). Prevents organizations from using control of the OS to implement policy. There's a few exceptions though. Google gets an exception. Apple gets an exception. Through specific deals made with these organizations and the EU commissioner of Nobody seems to have thought to scream into the commissions face: "THEN WHAT'S THE POINT?". Well, who made those deals? Thierry Breton. He currently serves as a remunerated member of Bank of America’s Global Advisory Council (who have huge investments in Alphabet and Apple). Yeah, I get why you want to focus on the intent only and not on what practically happened. Theory and practice are very, very different and the EU is incredibly pro-business and uses their power to literally grant billionaires exceptions to laws. That's how Goldman Sachs got it's first communist president (Barosso, who saved Goldman Sachs as president of the EU commission). That's reality, but of course the intent is thoroughly disguised, and you don't want to talk about the difference. | |||||||||||||||||
| |||||||||||||||||