I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.
On another note, does GDPR mean you can request credit report agencies to delete all their data on you?
GDPR Hall of Shame
91–100 of 192 posts
Re: GDPR Hall of Shame
#92The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…
I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin.
If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the size and scope of Yahoo!, it's not inconceivable they have legitimate (scare-quotes optional) uses for all those sub-processors.
Re: GDPR Hall of Shame
#93I've been in the internet since the 80s. Man what a nice thing we've built. We have turned the internet into a network where people snitch on each other to marketers for fractions of a penny.
The 80s? Were you involved in ARPANet or something?
Re: GDPR Hall of Shame
#94Earlier quoted context omitted.
Hi Brian, thanks for replying to my post. I apologise for my reactionary tone above, but do you understand how by declining to share specifics your tweet aroused suspicion? EDIT: I've just read through your privacy policy and I wish other companies had a privacy policy as clear, straightforward and detailed.
How is this a big deal? They probably sell your data or use it to show you ads or targeted content. Who cares?
Re: GDPR Hall of Shame
#95Re: GDPR Hall of Shame
#96The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…
> The Yahoo! one [1] is definitely in violation of GDPR, right? I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin. If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the siz…
Re: GDPR Hall of Shame
#97Earlier quoted context omitted.
Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?
It's worth noting that GDPR applies to EU citizens regardless of where they happen to be in the world (or if they're using a proxy), so an IP ban does absolutely nothing to help comply with the law. You'd think a real company would have talked to a lawyer about this.
Re: GDPR Hall of Shame
#98Earlier quoted context omitted.
For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.
A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.
Re: GDPR Hall of Shame
#99I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.
On another note, does GDPR mean you can request credit report agencies to delete all their data on you?
I don't have a good idea idea how legitimate a credit agency's legitimate interest really is. I might set aside some popcorn for seeing how this particular issue gets resolved.
Re: GDPR Hall of Shame
#100I nominate Slate https://slate.com/privacy for a creative interpretation of GDPR article 7.3 "It shall be as easy to withdraw as to give consent" (the "consent" happens through an uncloseable window with no other options where a single click sets that cookie): "The Right to Withdraw Consent. If you would like to opt-out at any time, please delete the “gdpr_consent_1” cookie from your browser window. You will have to…