Live data from Hacker News

Ask HN: Has anyone leveraged GDPR to overturn automated bans?

news.ycombinator.com

41–50 of 77 posts

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#41

The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now. The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator…

Regulators have brought quite a few successful GDPR fines. The reason that people think the GDPR isn't enforced, in my experience, is usually that they've been misled about what it does and doesn't require. For example, the author you linked to is demanding a portable copy of all his personal data from all sources, which Facebook has no GDPR obligation to give him. He seems to have been misled by a form letter he fou…

I don't disagree that there's been a few successful fines, but by that logic I should quit my job tomorrow because I happened to get lucky at the casino a couple times.

GDPR enforcement has been extremely lacking as demonstrated by the web being littered by non-compliant data processing consent forms. A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of services currently don't comply (including big names like Google or Facebook) and entire businesses such as TrustArc have been built on providing non-compliant consent forms as a service.

For GDPR enforcement to be considered serious, the fines amounts should be higher than the profits of companies built on abusing user data. If we look at https://www.enforcementtracker.com/?insights we can see that 1,6 billion euros has been handed out so far over a period of 4 years across the entire EU. How much does Google or Facebook profit in a year?

The entire experience of reporting violations is also a major problem and suggests the regulators (at least the UK one) aren't actually interested in enforcing the regulation. The process with the ICO requires that you first get in touch with the company and try to resolve your concern. This takes time & admin work on your behalf and a malicious actor can drag out the process for months. But let's assume that after you've done that and haven't gotten anywhere, escalating to the ICO merely results in them sending a letter. And when the company ignores that too, guess what happens? Another letter which they will promptly ignore too.

This sets the example that breaching the GDPR does pay, because not only reporting a violation requires so much commitment that the vast majority of people won't bother, but even once the violation is reported, the response from the ICO isn't actually an effective deterrent either.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#42

The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now. The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator…

Same goes the for 'cookie law'. A significant fraction of the web is in violation. The lack of enforcement sends the message that non-compliance is acceptable, so it's become the norm.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#43

The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now. The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator…

> The problem is that the GDPR is pretty much not enforced.

17 companies were fined for GDPR violations just this month. Last year, Amazon was fined €746,000,000, Google €150,000,000, Facebook €60,000,000.

https://www.enforcementtracker.com/

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#44
Aside from using imap to backup my mail, what else should I do to help mitigate an arbitrary ban? I’ve had a gmail account for 20 years since 12 year old me got caught up in invite fomo. I’ve since moved to other providers but still there’s a fair amount tied into my account currently.

Mostly I’m scared of ‘multifactor’ where email access is considered a form of identity, but I’m not sure what else

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#45

The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now. The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator…

> The problem is that the GDPR is pretty much not enforced. 17 companies were fined for GDPR violations just this month. Last year, Amazon was fined €746,000,000, Google €150,000,000, Facebook €60,000,000. https://www.enforcementtracker.com/

I knew this link was going to come up so I've addressed it here: https://news.ycombinator.com/item?id=30141276

The 60M Facebook fine is a welcome development but my point still stands - how much did Facebook profit from breaching the regulation for the 4 years since it's been in effect? That fine should've had a few extra zeros at the end to actually serve its role, otherwise it's just a very small cost of doing business.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#46

Earlier quoted context omitted.

Regulators have brought quite a few successful GDPR fines. The reason that people think the GDPR isn't enforced, in my experience, is usually that they've been misled about what it does and doesn't require. For example, the author you linked to is demanding a portable copy of all his personal data from all sources, which Facebook has no GDPR obligation to give him. He seems to have been misled by a form letter he fou…

I don't disagree that there's been a few successful fines, but by that logic I should quit my job tomorrow because I happened to get lucky at the casino a couple times. GDPR enforcement has been extremely lacking as demonstrated by the web being littered by non-compliant data processing consent forms. A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of ser…

> A compliant consent form should make the "decline" option as prominent as the "accept" one - the vast majority of services currently don't comply (including big names like Google or Facebook) and entire businesses such as TrustArc have been built on providing non-compliant consent forms as a service.

Nothing in the text of the GDPR, nor of any regulatory guidance that I've seen, suggests that the "decline" option has any particular UI requirements beyond merely being present. Again, while I don't want to claim that this or any other regulatory process is perfect, I think the primary reason people in privacy circles find it so frustrating is that they keep trying to enforce things that aren't actually GDPR requirements.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#47

The problem is that the GDPR is pretty much not enforced. See https://ruben.verborgh.org/facebook/ where the author tries to get all his data from Facebook - the case hasn't moved since 3 years now. The regulators are useless (especially the Irish one which seems happy to shield big tech scum from having to comply with the law) which confirms my own experience raising complaints with the ICO (the UK privacy regulator…

Same goes the for 'cookie law'. A significant fraction of the web is in violation. The lack of enforcement sends the message that non-compliance is acceptable, so it's become the norm.

What cookie law? The one that states I have to make my website worse for everybody to use?

Yeah, I definitely ignore that law, and I wish 100% of website owners did. It feels to me like 99% of them follow it.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#48
post #2

From memory I believe FAANG etc all _claim_ that appeals you lodge are reviewed by a human. Now if you don’t believe them then you’d need to take them to court and show why you think that’s not the case. Which I guess means my question is why don’t you believe them and how likely is it that they are lying when they claim thy appeals are reviewed by a human?

> Which I guess means my question is why don’t you believe them and how likely is it that they are lying when they claim thy appeals are reviewed by a human? Why would we believe them? It's Google's responsibility to prove their assertion, versus regulators taking them for their (not so good) word. The default should be the assumption that the corporation is being dishonest.

If you’re taking them (or anyone else) to court, isn’t the burden of proof on you?

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#49

Yes. I once got my account permanently locked at a well known service provider when I simply tried to make a payment for the first time. Support wasn't useful and all they could do was tell me that I somehow violated their Terms of Service for committing "fraudulent patterns" over and over again. I could have and maybe should have just let it go, but it really got under my skin. I first tried out of band approaches t…

> I didn't reach anybody, and you quickly realize how everybody else on the Internet just assumes you must either be lying or not telling the full story. I have observed the same. When I evaluate service providers, I'm curious to know how they handle dispute with customers.. it's quite depressing to see that on most online forums, it usually goes straight into victim blaming. You must have violated the TOS, you must…

Having done a bunch of moderation work in various open source spaces, it's intensely aggravating that while the vast majority of complaints are from people who are lying about what happened there are also plenty of mistakes so stupid that they -sound- unbelievable and yet are in fact true.

And I'd note that I am very very certain that I've made mistakes that stupid over the years.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#50
post #19
post #16

Earlier quoted context omitted.

If the human doesn't have agency, then it's not really a "human review", is it?

It still is.

Here's a human review process for you:

1) Check whether the output of the machine learning model outputs Yes or No.

2) If yes, ban.

3) If no, no ban.

This is not a human review process. The review process is algorithmic, the human is only involved to relay the result.

Post reply on HN