Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

121–130 of 192 posts

Re: GDPR Hall of Shame

#121
post #109

Earlier quoted context omitted.

What if EU citizens who are visiting US make purchases from your site?

Almost certainly does not apply. [1] For that matter, the same FAQ suggests that it's probably not necessary to block IP addresses if you're not located in the EU and aren't actively marketing to EU residents. But I can certainly understand small companies taking a better safe than sorry approach if they don't do material EU business. [1] https://www.gdpreu.org/the-regulation/who-must-comply/

It wouldn't apply if you explicitly ask user if he/she is an EU resident, preferably by checking ID and route to /dev/null if user is.

Re: GDPR Hall of Shame

#122
post #40
post #34

Earlier quoted context omitted.

Sorry, had to go up a few sizes on DigitalOcean

Curious: what tier were you using and what tier did you move up to? In case I ever get to the frontpage, I'd like to be prepared :) And usually, what is it that causes outages like HN/reddit's hug of death? Number of open sockets / file descriptors? RAM? CPU? Network congestion?

If you have a static site, being on top of reddit/HN will barely be visible on the smallest instance you can find.

Re: GDPR Hall of Shame

#123
post #81

Earlier quoted context omitted.

If the definition of personal data includes IP addresses then I'd be surprised there are any internet-connected products that don't process personal data in some way.

>If the definition of personal data includes IP addresses Yes it does. > I'd be surprised there are any internet-connected products that don't process personal data in some way. Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows: "Processing shall be lawful if... processing is necessary for the purposes of the legitimate interes…

What's your theory about why so many seem to be doing such a bad job meeting the letter and spirit of the law? Are they consulting with lawyers or other legal experts and bending over backwards to do the best they can given the advice they're given? Or are they maliciously flouting the obvious requirements as part of a concerted, and possibly coordinated, effort to undermine the law?

Re: GDPR Hall of Shame

#124

Earlier quoted context omitted.

...which is made possible by both directly and indirectly collecting, evaluating, sharing or trading, and concatenating data about you.

...just so you can block and ignore the ads, all the same.

You're conflating control over personal data with one of the purposes for doing so, i.e., the presentation of ads. That is by far not what privacy or data protection is limited to.

Not to mention that blocking or hiding ads or trackers is not the same as preventing the collection of personal information. Unless you avoid visiting a service entirely, depending on the implementation you may not be able to inhibit any of it.

Re: GDPR Hall of Shame

#125
post #58
post #28

The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…

Yahoo is bad, especially concerning the opt-in, but by far not the worst. Those are Google and Facebook, which have made all of their services "all-or-nothing". If you don't accept every single bit of data processing, your only alternative is to delete your account. Literally runs counter to everything the GDPR stands for.

> Literally runs counter to everything the GDPR stands for.

If the idea is that no one should be able to avoid complying with the GDPR, even if they decide they no longer want to do business with whomever it is exactly that's covered by it, then maybe the whole thing was a bad tradeoff. I'll grant that Google and Facebook might be acting in bad faith – hell, I'll just assume they are – but surely, for some not-necessarily-insignificant number of other entities, it should be perfectly fine if they decide that the costs of compliance exceed the corresponding benefits.

Re: GDPR Hall of Shame

#126
post #35

Earlier quoted context omitted.

> So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. No, it can something as simple as "we cannot guarantee that all your data is deleted with our current storage system". It would be a lot better if people stop being so alarmist.

Why can't they comment on it? It's very suspect.

I'd guess they're afraid of legal liability.

Re: GDPR Hall of Shame

#127

Earlier quoted context omitted.

What if EU citizens who are visiting US make purchases from your site?

It does apply. All EU residents are covered regardless where they are.

The misunderstanding of this is widespread. GDPR does not make any mention of EU citizens OR residents. It only says "data subjects who are IN the Union".

See my other comment for more detail:

https://news.ycombinator.com/item?id=17143923

Re: GDPR Hall of Shame

#128
post #10

My favourite at the moment is sendwithus. They said their service will never be GDPR compliant. But fortunately they have a new "enterprise grade" product called sendwithus dyspatch. Same feature set, new price plus GDPR compliance. This is a price jump from $79/Month to a minimum of $24.000/year. And this is with discount for former sendwithus users. I would consider this to be mafia methods.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

I work for a competitor to sendwithus, and, while I can't speak to specifics or the industry as a whole, I can definitely say that it is proven possible to run a company whose revenue model is to charge something comparable to sendwithus's previous monthly subscription fees, be profitable, grow steadily, and not make a single dime on the side selling data to advertisers.

Re: GDPR Hall of Shame

#129
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

Even if you pay for the product, you are the product.

Re: GDPR Hall of Shame

#130
post #26

Earlier quoted context omitted.

That's extremely uncharitable.

I think we should reserve opinion here until bthdonohue gets back with fiiv's comment of "But what part of GDPR was it that caused you to have to close off European Union users?"

I'm not sure it's reasonable to expect an answer to that question; at least not from someone other than their legal representative.
Post reply on HN