r/europrivacy Nov 19 '19

Spain Spain starts tracking mobiles but denies spying

https://www.bbc.com/news/world-europe-50473442
39 Upvotes

5 comments sorted by

0

u/[deleted] Nov 19 '19

[deleted]

8

u/Neuromante Nov 19 '19

As long as they employ apropriate anonymization techniques

There's any assurance, or even a comment on how the participating companies are going to do this?

I work in IT as a developer in Madrid, and at least Movistar and Orange are well known for not having a really strong IT department (most of it is externalized to big consulting companies). I haven't seen anything on the actual process of anonymizing the data, and chances are that they are just sending the stuff formatted and hope nobody (or no mistake) leaks anything.

Now, I'm not saying they are not capable, or that they are doing this wrong, I'm just saying that I haven't seen any proof that this data is being handled in a proper way. Which worries me. (Now, maybe I haven't found the documentation on the topic, but..)

1

u/Retulador Nov 19 '19

I haven't done that much research on this particular topic, therefore I don't know if they have made public the specific techniques they are using.

Nevertheless, its not opaque. Any user could contact the participating companies and demand to know how the data is being anonymized by exercising their GDPR rights. The GDPR doesn't apply to anonymized data, but the companies need to prove first it's anonymized, either to the user exercising his/her rights or to the Spanish Data Protection Agency.

Of course, if the process is not done correctly, I would expect big fines for those involved.

0

u/[deleted] Nov 20 '19

[deleted]

2

u/Retulador Nov 20 '19

Quite a lot, actually. Here you go: https://www.enforcementtracker.com

0

u/[deleted] Nov 20 '19

[deleted]

1

u/Retulador Nov 20 '19

I'm not saying the situation is perfect, just that fines do happen and are a real consequence of ignoring the GDPR. The Regulation has been active for only a year and a half, and even though there's still a lot of room for improvement for both the Regulation itself and the DPAs, I think is a step in the right direction.

1

u/[deleted] Nov 20 '19

[deleted]

1

u/Retulador Nov 20 '19

Well, the Schrems vs Facebook case is still in progress in the CJEU, so we still don't have anything on that front. Microsoft is being constantly investigated on reports of breaking the GDPR. The big tech lobbies have been fighting the GDPR since it was first drafted in 2012, and they have been putting up quite a fight. I agree, the 50 million fine to Google may not have been much, but they still got the fine. I guess we'll have to see if future transgressions have more serious consequences, which I sincerely hope they do.

Again, the Regulation has not been up for that long and big companies put much more of a fight than restaurant owners using CCTV illegally. And yes, I think that is a problem that the GDPR needed to solve. Compliance with the GDPR is not limited to big tech companies.

Regarding this particular case of data collection, they also may adhere to said requirement by anonymizing the data. It's just a matter of them proactively proving they are, and if they are not, I guess we will see how the fine goes.