Live data from Hacker News

Ask HN: Has anyone leveraged GDPR to overturn automated bans?

news.ycombinator.com

71–77 of 77 posts

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#71
post #69
post #63

Earlier quoted context omitted.

Set the do not track flag if you trust website owners to actually listen to your request. If you don’t trust them to listen to your request, then being forced to manually tell every website you visit not to track you is obviously pointless and worse.

It’s easier to trust a business to follow a law with teeth than to follow a mere non-binding header that politely requests the same thing.

What an utterly useless law. We have a convenient way for people to request universally that sites not track them. So let’s make a law that makes them have to ask “the right way” every. Single. Stinking. Site. On. The. Internet. Every. Single. Time. They. Visit. Every. Single. Site.

One might be forgiven for assuming that the law was actually intending to accomplish the reverse of the stated goal. It gives site owners tons of explicit opt-ins that nobody can complain about, even though they were coerced.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#72
post #33
post #11

Earlier quoted context omitted.

I think the point is they, based on the file content, no human could have been involved in the decision. If there was a human involved, the files never would have been flagged.

The discussion isn’t about the initial flagging, it’s about the review. That might be as simple as checking for the existence of legal documents claiming copyright infringement, or as reading a web page stating “we already removed X other copies of this file”. Neither is a fail-safe way of doing such a review, but doing a thorough review might be expensive even for Google. Does anybody know how many such reviews they…

Right, but I believe for those cases, the (automated) email also said that the ability to appeal was not available. So there is no human review, because there's no review at all.

Regardless -- and I know this is a "how the world should be, not how it is" type thing -- I really think the initial decision should not be allowed to be made by an algorithm. At the very most, an algorithm should be allowed to flag something for human review, but no action is taken until the human has a chance to review it and decide if the flag is warranted or not.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#73
post #61

Earlier quoted context omitted.

I hear people saying laws that require police reports, police enforcement or interactions with the court are useless. For people like yourself who feel this way, what alternatives do you propose?

what's the purpose of a regulator if they agree with you and can't do anything to enforce the law? it's privacy theatre, nothing more

The purpose is so they can make rules about complex situations. It’s like how in the US the aviation authority (FAA) and crash investigator (NTSB) don’t really enforce the law, even if a criminal act contributed to the crash. They’ll either forward the information to law enforcement or leave it up to the insurance companies and civil courts to arrive at justice.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#74
post #61

Earlier quoted context omitted.

what's the purpose of a regulator if they agree with you and can't do anything to enforce the law? it's privacy theatre, nothing more

The purpose is so they can make rules about complex situations. It’s like how in the US the aviation authority (FAA) and crash investigator (NTSB) don’t really enforce the law, even if a criminal act contributed to the crash. They’ll either forward the information to law enforcement or leave it up to the insurance companies and civil courts to arrive at justice.

believe it or not not every country has the same regulatory system setup as the United States

(thank god)

the data protection regulators have no ability to create rules... their job is (supposedly) to enforce it

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#75
post #74

Earlier quoted context omitted.

The purpose is so they can make rules about complex situations. It’s like how in the US the aviation authority (FAA) and crash investigator (NTSB) don’t really enforce the law, even if a criminal act contributed to the crash. They’ll either forward the information to law enforcement or leave it up to the insurance companies and civil courts to arrive at justice.

believe it or not not every country has the same regulatory system setup as the United States (thank god) the data protection regulators have no ability to create rules... their job is (supposedly) to enforce it

So you’re telling me ordinary cops and prosecutors in Europe are capable of investigating highly technical, civil crimes? I’m not an expert in European justice, but based on a few high-profile cases I’ve followed, this doesn’t seem to be the case.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#76
post #71
post #69

Earlier quoted context omitted.

It’s easier to trust a business to follow a law with teeth than to follow a mere non-binding header that politely requests the same thing.

What an utterly useless law. We have a convenient way for people to request universally that sites not track them. So let’s make a law that makes them have to ask “the right way” every. Single. Stinking. Site. On. The. Internet. Every. Single. Time. They. Visit. Every. Single. Site. One might be forgiven for assuming that the law was actually intending to accomplish the reverse of the stated goal. It gives site owner…

> We have a convenient way for people to request universally that sites not track them

DNT is utterly ignored to the point it’s officially deprecated in various browsers and the W3C working group for it disbanded:

https://en.wikipedia.org/wiki/Do_Not_Track

> It gives site owners tons of explicit opt-ins that nobody can complain about, even though they were coerced.

Coerced assent is expressly forbidden by GDPR, so we absolutely can and are complaining about this.

Re: Ask HN: Has anyone leveraged GDPR to overturn automated bans?

#77
post #49

Earlier quoted context omitted.

> I didn't reach anybody, and you quickly realize how everybody else on the Internet just assumes you must either be lying or not telling the full story. I have observed the same. When I evaluate service providers, I'm curious to know how they handle dispute with customers.. it's quite depressing to see that on most online forums, it usually goes straight into victim blaming. You must have violated the TOS, you must…

Having done a bunch of moderation work in various open source spaces, it's intensely aggravating that while the vast majority of complaints are from people who are lying about what happened there are also plenty of mistakes so stupid that they -sound- unbelievable and yet are in fact true. And I'd note that I am very very certain that I've made mistakes that stupid over the years.

This makes me think of two things, but I can't quite put my finger on how they intersect, although they do feel extremely related somehow.

1) Hanlon's razor (do not attribute to malice that which can be explained by stupidity)

2) It was discovered (unfortunately missing citation atm :< ) that people who fall for spam scams that exploit gullibility do so "completely" - most see the scam for what it is, but the ones that do fall for it will kind of double down, defend their actions and see through their part of the "deal" because in their mind it Will Work. So it's almost like there's a super-thin line somewhere where everyone rubberbands to one or the other extreme ("are you serious, that's a scam" vs "are you serious, of course this is real") depending on whether That Last Single Piece Of Straw is on the haystack or not. (I just realize you could substitute "a scam" for "fake" and potentially explain a substantial percentage of conspiracy theorists... hmm)

Post reply on HN