Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

91–100 of 192 posts

Re: GDPR Hall of Shame

#91
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

Of course, but the result will propably be like an american who has never used a credit card: You can't get credit anywhere.

Re: GDPR Hall of Shame

#92
post #28

The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…

> The Yahoo! one [1] is definitely in violation of GDPR, right?

I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin.

If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the size and scope of Yahoo!, it's not inconceivable they have legitimate (scare-quotes optional) uses for all those sub-processors.

Re: GDPR Hall of Shame

#93
post #54

I've been in the internet since the 80s. Man what a nice thing we've built. We have turned the internet into a network where people snitch on each other to marketers for fractions of a penny.

The 80s? Were you involved in ARPANet or something?

There are people here who invented ARPANet.

Re: GDPR Hall of Shame

#94
post #39

Earlier quoted context omitted.

Hi Brian, thanks for replying to my post. I apologise for my reactionary tone above, but do you understand how by declining to share specifics your tweet aroused suspicion? EDIT: I've just read through your privacy policy and I wish other companies had a privacy policy as clear, straightforward and detailed.

How is this a big deal? They probably sell your data or use it to show you ads or targeted content. Who cares?

People in this thread saw the title "GDPR Hall of Shame", possibly read it. Now they are trying to discuss stuff relating to "General Data Protection Regulation". My wild guess is people who are commenting on this thread care.

Re: GDPR Hall of Shame

#96
post #92
post #28

The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…

> The Yahoo! one [1] is definitely in violation of GDPR, right? I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin. If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the siz…

Oh, it's perfectly fine to have as many sub-processors as they want. But default opt-in is non-compliant; if I understand the regulation correctly, the user has to manually opt into every processor. An opt-out dark pattern is specifically prohibited in GDPR.

Re: GDPR Hall of Shame

#97
post #67
post #27

Earlier quoted context omitted.

Hi Brian! Thanks for taking part in the discussion. But what part of GDPR was it that caused you to have to close off European Union users?

It's worth noting that GDPR applies to EU citizens regardless of where they happen to be in the world (or if they're using a proxy), so an IP ban does absolutely nothing to help comply with the law. You'd think a real company would have talked to a lawyer about this.

How would that even make sense? A country enacts some arbitrary rule such as "You are not allowed to provide access to social media for its citizens." How do you possibly enforce that for citizens visiting or living in the US? (Short of demanding all users to verify their citizenship to access the site.)

Re: GDPR Hall of Shame

#98
post #61
post #49

Earlier quoted context omitted.

For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.

A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.

What if EU citizens who are visiting US make purchases from your site?

Re: GDPR Hall of Shame

#99
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

It does mean you can request it. It doesn't necessarily mean they have to delete said data. The Right to Erasure is not absolute, if the data controller can state an 'overriding legitimate interest' for the preservation of the data.

I don't have a good idea idea how legitimate a credit agency's legitimate interest really is. I might set aside some popcorn for seeing how this particular issue gets resolved.

Re: GDPR Hall of Shame

#100

I nominate Slate https://slate.com/privacy for a creative interpretation of GDPR article 7.3 "It shall be as easy to withdraw as to give consent" (the "consent" happens through an uncloseable window with no other options where a single click sets that cookie): "The Right to Withdraw Consent. If you would like to opt-out at any time, please delete the “gdpr_consent_1” cookie from your browser window. You will have to…

I'm pretty sure that no European court would accept that. I doubt most users (and most judges) even know how to delete cookies. I don't even know how to do that on my phone (not sure if that's possible?). And not allowing users with mobile browsers to withdraw consent is definitely a violation.
Post reply on HN