Live data from Hacker News

When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

theguardian.com

141–150 of 151 posts

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#141

Earlier quoted context omitted.

Why? Lot of people use aliases or nicknames. I never had issues doing that.

I'd have to imagine it'd put some people off.

It's just another factor in computing compatibility.

There was a time when attaching your real identity online was considered a major safety risk. That time hasn't past.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#142

Earlier quoted context omitted.

Hmm but do you interpret that to be the act of processing while the consent was in effect is not retrospectively made illegal, or to mean that data shared/obtained while a concent was in effect is still legal to keep after the consent is withdrawn.

You do not have to delete the data once consent is retracted, unless it's the only basis for lawful processing and even then I'm not entirely sure if deletion is mandated as archiving is allowed. Also (from B&B): "Individuals can require data to be ‘erased’ when there is a problem with the underlying legality of the processing or where they withdraw consent." This is also a bit vague but it looks like withdrawing con…

Oh I know the two birds fairly well :-)

Completely agree that there are other basis for legality, but most of the seem to favor either the registered person or other laws. And that was sort of my thought when saying Tinder would have to delete if you withdraw consent: I would think consent would be the only grounds for processing data for a company like Tinder. Wrt 1 and 2 of article 6 you mention. I'd have though Tinder wouldnt be able to claim anything since for 1) the interest of the subject would the to delete it and 2) "Tinder making money on your data" cannot be considered a legitimate interest. And when it comes to Tinder havning to store due things like in the case of sexual assault they would still have to consider the priciples of limitation on what they use the data for (eg. cannot sell your sexual prefernces to adverticers if the only legal grounds is some law requirinh them to store data for a very scific cause), right? And then there is the whole notification to the subject thats going to be a major pain aswell.

Anyway, not a lawyer, and all the special cases you point out is probably valid. But thats why the only really interesting thing is to see the first cases and judgements on this so we can get some indication of interpretation. And ofcourse seeing EU will actually execute the high fines - if not then all this wont have any effect anyway

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#143

Earlier quoted context omitted.

Why? Lot of people use aliases or nicknames. I never had issues doing that.

I'd have to imagine it'd put some people off.

Never had that, actually lot of people don't use their real names on dating sites or even FB. And if someone asks you say its for privacy reasons, people do understand. Look at Okcupid, its all nicknames there ;) same goes for other sites. Same goes for Apps.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#144
post #103

> A few months earlier, 70,000 profiles from OkCupid (owned by Tinder’s parent company Match Group) were made public by a Danish researcher some commentators have labelled a “white supremacist”, who used the data to try to establish a link between intelligence and religious beliefs. The guy's name is Emil Kirkegaard and the paper and data is still available. I skimmed the paper and have no idea why he was labled a "w…

Is he related somehow with Soren Kirkegaard?

Don't think so, Kierkegaard is a somewhat common name in Denmark. Means graveyard or literally church yard.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#145
post #33

Earlier quoted context omitted.

Could you give some examples of this wiggle room?

The GDPR replaces the right to be forgotten with the right to erasure. But article 17 also gives the following grounds for refusal: Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: 1) for exercising the right of freedom of expression and information; 2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for…

But that's just the "right to be forgotten" angle, right? Isn't there more to the GDPR than that?

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#146
post #39
post #15

Earlier quoted context omitted.

You can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.

> assuming the EU court has jurisdiction If the company wants to do business with a EU customers, they have _some_ surface area in the EU, which is enough. > an income stream in the EU If the company cares for EU customers, there's probably also _some_ way to make money on them. Unless EU customers will exclusively get Netflix USA ads in the future (which are 100% useless to them) on an otherwise 100% free service, t…

Not only the money stream part, but if a big company pulls out of the EU, then they leave a big hole for someone else to fill. And you've just created a competitor who has a market base that you are choosing to not compete it.

e.g. if Facebook pulled out (unlikely), then someone can just make a new Facebook site (we already know what functionality to copy), and then suddenly Facebook has a competitor.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#147

Earlier quoted context omitted.

The country the data resides in is irrelevant. If the data is about an EU citizen, that's all that matters. I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.

eh. Maybe. If they copy the data to a 3rd party in America (i.e. sell the data a marketing company, for "research" purposes), then the EU can't really go after the marketing company. I'm not saying it's right. I don't see why they couldn't anonymize the data (morally or ethically). But, I don't own a marketing company.

> If they copy the data to a 3rd party in America (i.e. sell the data a marketing company, for "research" purposes), then the EU can't really go after the marketing company.

No, but they can go after the original company who transfered the data. Remember, under EU law, companies don't own that personal data. It's not theirs to give away.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#149
post #15

Earlier quoted context omitted.

You can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.

>You can take an American company to an EU court assuming the EU court has jurisdiction, Sure you can. EU Courts did it to Microsoft over (IIRC) internet explorer resulting in a brand new SKU. Microsoft tried the logic you used at which point the EU courts started levying 1.5m euro / day fines for noncompliance. Turns out that if you want to do business in a jurisdiction badly enough, it creates their leverage to enf…

Huh? You seem to be violently agreeing with me, while implying I'm saying something else.

I don't quite get what logic you think I used that doesn't agree fully with what you said above would be.

Re: When I asked Tinder for my data, it sent me 800 pages of my deepest secrets

#150
post #39
post #15

Earlier quoted context omitted.

You can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.

> assuming the EU court has jurisdiction If the company wants to do business with a EU customers, they have _some_ surface area in the EU, which is enough. > an income stream in the EU If the company cares for EU customers, there's probably also _some_ way to make money on them. Unless EU customers will exclusively get Netflix USA ads in the future (which are 100% useless to them) on an otherwise 100% free service, t…

That's not necessarily true for every site, though. A US site selling goods to EU consumers via US payment providers does not necessarily have any assets or income stream going through EU banks etc. that they could easily go after.

That said, that's usually only a problem with small companies. Very few large companies manage to avoid all financial exposure to the EU and still do business with EU residents, so it has relatively little practical impact.

Post reply on HN