Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

81–90 of 192 posts

Re: GDPR Hall of Shame

#81
post #16

Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.

If the definition of personal data includes IP addresses then I'd be surprised there are any internet-connected products that don't process personal data in some way.

Re: GDPR Hall of Shame

#82
post #70

Earlier quoted context omitted.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

Well, if it's their data, shouldn't they be able to delete it at will?

If you know something about me why is it my right to make you forget about it?

Re: GDPR Hall of Shame

#83

CCleaner deserves a special spot in this hall after the recent change with the "You cannot opt-out" privacy option in the free version of the program. [1] https://www.ghacks.net/2018/05/24/ccleaner-update-introduces... [2] https://forum.piriform.com/topic/51913-ccleaner-5436520-cann...

That's not how GDPR works. You're not allowed to make use of your product / service require acceptance of collection of data. You must either offer it without data collection as an option, or simply refuse service.

Re: GDPR Hall of Shame

#84
post #25
post #21

Earlier quoted context omitted.

I think you've confused "if" with "if and only if"

The implication is clearly that you ought to pay for the products, so that you aren't the product. But if the incentives for paid and free products to monetize your data is the same, switching from one to the other doesn't help. You have to specifically seek out products where your privacy and data is taken seriously. This can happen for both free (open source?) and paid products.

I agree, that's a good point.

Re: GDPR Hall of Shame

#85
post #55

Hey! I made this, mostly just to poke fun at my inbox being here in Europe and experiencing it first hand. Feel free to fire me a reply with any good ones you've spotted; I'll be actively adding through tomorrow and beyond.

The Endomondo app is a doozy. They require opt-in to two items to carry on using the app, but then also say that by clicking continue, you're agreeing to their privacy policy, which indemnifies them against GDPR. It's slightly clever misdirection, in my opinion. I clicked 'OK' in the end because the EULA appears to be invalid anyway; by borking the consent process they have no legal basis for processing my data.

Re: GDPR Hall of Shame

#86
post #29
post #10

Earlier quoted context omitted.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

So you're saying user's data is worth $23052 per year?

Maybe, maybe not. If it's not I assume they'll be forced to lower their prices and go out of business. I don't have a problem with a company charging money for their product though.

The GDPR appears to be doing its job here because it's forcing a company out of a business model that is unethical and into one that's better for society, regardless of it's better or not for the company and some of its customers

Re: GDPR Hall of Shame

#87
post #27

Earlier quoted context omitted.

Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?

close off European Union users? I don't see any info about that.

Am I misunderstanding you here? Instapaper's email literally starts with:

> Starting tomorrow May 24, 2018, access to the Instapaper service will be temporarily unavailable for residents in Europe

Re: GDPR Hall of Shame

#88
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

I believe that they do lots of internal analytics but do not sell identifiable data on a per-person level; the laws regarding nondisclosure of banking data are old, well established and much stricter - for starters, intentional disclosure of confidential banking information outside of certain (though many) particular exceptions is an actual maybe-go-to-jail crime, not just a civil matter with some fines. Surveillance…

Does GDPR distinguish between "identifiable" data and "non-identifiable"? If so, how do you decide which is which? A list of credit card transactions is pretty easy to de-identify...

Re: GDPR Hall of Shame

#89
post #29
post #10

Earlier quoted context omitted.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

So you're saying user's data is worth $23052 per year?

No, that is just the cost of compliance.

Re: GDPR Hall of Shame

#90
post #55

Hey! I made this, mostly just to poke fun at my inbox being here in Europe and experiencing it first hand. Feel free to fire me a reply with any good ones you've spotted; I'll be actively adding through tomorrow and beyond.

The Endomondo app is a doozy. They require opt-in to two items to carry on using the app, but then also say that by clicking continue, you're agreeing to their privacy policy, which indemnifies them against GDPR. It's slightly clever misdirection, in my opinion. I clicked 'OK' in the end because the EULA appears to be invalid anyway; by borking the consent process they have no legal basis for processing my data.

Wow - got a screenshot of that one?
Post reply on HN