Live data from Hacker News

Ask HN: Has anyone leveraged GDPR to overturn automated bans?

news.ycombinator.com

21–30 of 77 posts

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#21
The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now.

The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator).

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#23
post #19
post #16

Earlier quoted context omitted.

If the human doesn't have agency, then it's not really a "human review", is it?

It still is.

Spirit of the law is a concept I would encourage anyone to think about when arguing about these things. I believe most people, and courts in particular, would not agree that a human rubber-stamping automated decision is in line with the spirit of the law. Clinging onto a technicality isn't going to go well.

I'd also like to point out that these laws don't just come out of nowhere in a vacuum, to be interpreted without any further context. In EU we have recitals and guidelines to give context and support the interpretation of regulations.

If you're interested, do read Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 (wp251rev.01).

https://ec.europa.eu/newsroom/article29/items/612053/en

Here's what it says about human intervention: "Any review must be carried out by someone who has the appropriate authority and capability to change the decision. The reviewer should undertake a thorough assessment of all the relevant data, including any additional information provided by the data subject."

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#25
Yes. I once got my account permanently locked at a well known service provider when I simply tried to make a payment for the first time. Support wasn't useful and all they could do was tell me that I somehow violated their Terms of Service for committing "fraudulent patterns" over and over again.

I could have and maybe should have just let it go, but it really got under my skin. I first tried out of band approaches to contacting somebody there. I didn't reach anybody, and you quickly realize how everybody else on the Internet just assumes you must either be lying or not telling the full story. Maybe it's just acceptable losses while doing business at scale.

So I finally just emailed them a polite GDPR request containing some spiel about Article 15(h), how I have the right to request my personal data, and also have the right to correct any inaccuracies in it, which must be the case since I committed no such fraudulent actions. I also requested a full list of all their data subprocessors, which I couldn't actually find listed anywhere on their site.

I'm not a lawyer, and I don't know if my request hit all the right notes or not. But literally one hour later, I got my account unlocked with a personal apology.

For what it's worth I also let them know that I'm not really looking to circumvent their systems, and I'm sure they have to deal with a lot of bad actors. But there really needs to be a better way to reach somebody to fix things when automated systems go wrong.

I also have the feeling that this approach would fall on deaf ears for big FAANGs, and there really needs to be some high profile ruling to put the fear in them.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#26
post #19
post #16

Earlier quoted context omitted.

If the human doesn't have agency, then it's not really a "human review", is it?

It still is.

And you've just demonstrated why programmatic enforcement of contracts doesn't work. Courts are actually able to see through that semantic nonsense, because humans are able to discern intent.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#27

GDPR Article 22 (the rule you refer to) also has exceptions: > Paragraph 1 shall not apply if the decision...is necessary for...performance of, a contract between the data subject and a data controller Which I can see applying as they probably have something in the ToS to enforce here. It also allows automated decision making to comply with EU law. I don't know EU copyright law well enough, maybe Google has a respons…

The ToS does not constrain the company! The agreement does not stipulate that the platform _has_ to enforce ToS, so this is not a necessary action to perform the contract.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#28

Yes. I once got my account permanently locked at a well known service provider when I simply tried to make a payment for the first time. Support wasn't useful and all they could do was tell me that I somehow violated their Terms of Service for committing "fraudulent patterns" over and over again. I could have and maybe should have just let it go, but it really got under my skin. I first tried out of band approaches t…

> I didn't reach anybody, and you quickly realize how everybody else on the Internet just assumes you must either be lying or not telling the full story.

I have observed the same. When I evaluate service providers, I'm curious to know how they handle dispute with customers.. it's quite depressing to see that on most online forums, it usually goes straight into victim blaming. You must have violated the TOS, you must be doing something sketchy, you're not telling the whole story, you're just holding a grudge so get over it, you're just entitled, etcetra. There's very little sympathy, and no giving benefit of the doubt.

> But literally one hour later, I got my account unlocked with a personal apology.

Congrats! This is a lovely anecdote, thank you so much for sharing.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#29
post #7
post #3

Earlier quoted context omitted.

There was a recent example with Google Drive where it explicitly disabled any way to appeal. I was able to reproduce the issue where it was flagging files that consisted of a single byte, sometimes followed by \r\n or \n. Here's the HN story: https://news.ycombinator.com/item?id=30060405 Screenshots of trying to "appeal" (Request a review) from when I recreated the issue show pretty clearly there is no human involved…

Are you suggesting that Europe has established a fundamental human right to have Google provide free static hosting services?

Arguably the opposite where the EU may have in effect outlawed may free services be requiring human review of many activities.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#30
post #19
post #16

Earlier quoted context omitted.

If the human doesn't have agency, then it's not really a "human review", is it?

It still is.

I think the chances that a judge would accept that argument is potentially a lot lower than you might expect.
Post reply on HN