Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

61–70 of 192 posts

Re: GDPR Hall of Shame

#61
post #49
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.

A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.

Re: GDPR Hall of Shame

#62
post #29
post #10

Earlier quoted context omitted.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

So you're saying user's data is worth $23052 per year?

User data could or could not be worth that much. Having a team of programmers implementing and maintaining features that make the software GDPR compliant is perhaps the biggest contributing factor the price increase

Re: GDPR Hall of Shame

#63
post #53

GDPR and policies like it are an existential threat to a Big Data future where so much can be possible if we are able to amass as much data as possible without fear of consequences. GDPR should be resisted by as many companies and startups as possible.

Whatever the case might be, companies have shown themselves to not handle people's personal data properly, as shown by the massive leaks in the past. Whatever utopia you're thinking of, it's not happening anytime soon, and GDPR is a rightful measure to slightly apply the brakes on rampant data collection and misuse.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

Re: GDPR Hall of Shame

#64
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

Re: GDPR Hall of Shame

#65
post #27

Earlier quoted context omitted.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?

close off European Union users? I don't see any info about that.

Re: GDPR Hall of Shame

#66
post #30

It'll be interesting to see how the EU reacts to all of the companies like Oath that, by default, share your data with 300+ ad agencies. After the GDPR hype has died down, hopefully new tech companies will think twice about data privacy

To me, that one was the most striking. It shows how widespread data sharing is. In the end to whom did they NOT sell user data?

Re: GDPR Hall of Shame

#67
post #27

Earlier quoted context omitted.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?

It's worth noting that GDPR applies to EU citizens regardless of where they happen to be in the world (or if they're using a proxy), so an IP ban does absolutely nothing to help comply with the law.

You'd think a real company would have talked to a lawyer about this.

Re: GDPR Hall of Shame

#68
post #49
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.

This is the entire point of the GDPR really. It appears to be working.

Re: GDPR Hall of Shame

#69
post #53

Earlier quoted context omitted.

Whatever the case might be, companies have shown themselves to not handle people's personal data properly, as shown by the massive leaks in the past. Whatever utopia you're thinking of, it's not happening anytime soon, and GDPR is a rightful measure to slightly apply the brakes on rampant data collection and misuse.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

It certainly is related. One core argument is that the vast majority of currently stored personal data has no good reason whatsoever to be there, the company should not be collecting, using and storing any personal data.

If half of the companies remove that private data which they shouldn't have, then that will reduce the impact of breaches, as there'll be twice less breaches where's something sensitive to leak.

Re: GDPR Hall of Shame

#70
post #53

Earlier quoted context omitted.

Whatever the case might be, companies have shown themselves to not handle people's personal data properly, as shown by the massive leaks in the past. Whatever utopia you're thinking of, it's not happening anytime soon, and GDPR is a rightful measure to slightly apply the brakes on rampant data collection and misuse.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

Well, if it's their data, shouldn't they be able to delete it at will?
Post reply on HN