Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

131–140 of 192 posts

Re: GDPR Hall of Shame

#131
post #75
post #49

Earlier quoted context omitted.

For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.

I think there's also a sizable number of companies that basically were already compliant... but aren't sure. It's not like you can submit your processes to the EU for approval. You don't actually know if what you're doing is OK unless, some day, a regulator decides it isn't.

This kind of problem is what lawyers are for.

Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.

Re: GDPR Hall of Shame

#132

CCleaner deserves a special spot in this hall after the recent change with the "You cannot opt-out" privacy option in the free version of the program. [1] https://www.ghacks.net/2018/05/24/ccleaner-update-introduces... [2] https://forum.piriform.com/topic/51913-ccleaner-5436520-cann...

That's not how GDPR works. You're not allowed to make use of your product / service require acceptance of collection of data. You must either offer it without data collection as an option, or simply refuse service.

I'm guessing, if that's enforced, that a lot of these same organizations will opt to refuse service.

Re: GDPR Hall of Shame

#133
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

> So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. No, it can something as simple as "we cannot guarantee that all your data is deleted with our current storage system". It would be a lot better if people stop being so alarmist.

It would be a lot better if people stop being so alarmist.

Indeed. It's odd looking at discussions about the GDPR on HN.

On the one hand, we have people who argue that compliance isn't really that big a deal if you're not doing anything horribly wrong, most ethical businesses would already be mostly compliant anyway, etc.

On the other hand, we have people who argue that even if that is the case, the length and ambiguity of the regulations and guidance combined with the potential penalties still cause significant overheads and risks, particularly for smaller businesses without dedicated resources to deal with compliance matters.

There is some truth behind both of those positions, I think.

But then I've seen so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped. A noticeable number of people are advocating obviously vexatious use of the new subject rights, not in response to any specific concern or after some unsatisfactory attempt to resolve concerns reasonably, but as a weapon with the clear goal of causing maximum disruption and cost to organisations. I wonder how anyone can think giving so much "legal ammunition" to these people is a good idea.

Re: GDPR Hall of Shame

#134

Earlier quoted context omitted.

It does apply. All EU residents are covered regardless where they are.

The misunderstanding of this is widespread. GDPR does not make any mention of EU citizens OR residents. It only says "data subjects who are IN the Union". See my other comment for more detail: https://news.ycombinator.com/item?id=17143923

It is not defined what "who are in the Union" means. The safest bet is that it means a subject is European Union resident. If they mean that person should be physically present in the European Union, the law would have stated that, but it is not.

Re: GDPR Hall of Shame

#135
post #115

Earlier quoted context omitted.

80s were still fairly early for Internet access. I was on the ARPANET as early as 1979 or so but just trading the occasional email in a lab. "Real" internet access, first at work and then through my BBS, was probably more like the early 1990s.

Oh yeah, I didn’t do anything on the Internet in 1990 apart from typing ‘go internet’ into CIX (my BBS at the time), sitting there wondering what you could do with it, then killing the connection when my dad pointed out that we paid by the minute for the phone line :) I don’t think I knew anyone online that wasn’t on CIX either.

I used CIS for some things but as you say the charges were pretty high. I mostly used a private local BBS at the time. I’m guessing it was more like 1994 or thereabouts when I started FTPing files and getting into Usenet.

Re: GDPR Hall of Shame

#136

Earlier quoted context omitted.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

It certainly is related. One core argument is that the vast majority of currently stored personal data has no good reason whatsoever to be there, the company should not be collecting, using and storing any personal data. If half of the companies remove that private data which they shouldn't have, then that will reduce the impact of breaches, as there'll be twice less breaches where's something sensitive to leak.

I can't think of massive leaks that involved data that wasn't 'legitimate'. What's your go-to example?

Re: GDPR Hall of Shame

#137
post #67

Earlier quoted context omitted.

It's worth noting that GDPR applies to EU citizens regardless of where they happen to be in the world (or if they're using a proxy), so an IP ban does absolutely nothing to help comply with the law. You'd think a real company would have talked to a lawyer about this.

That is incorrect. GDPR makes no mention of EU citizens or residents. The 2 main groups it applies to are: 1. activities of an establishment of a controller or a processor in the Union (so if the company is in the EU, ALL processing has to be GDPR compliant regardless of where the user is) 2. processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union (i…

And that's the companies' out. Make shell companies that exist only in Europe to exfiltrate liability for the multinationals.

There's no real difference in "Facebook US" and "Facebook Ireland". The only difference is this methodology skirts the law.

Hopefully, the EU will climb up these jokes of shell companies and rightly smack them down.

Re: GDPR Hall of Shame

#138

Earlier quoted context omitted.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

"Credit reporting agencies" in the USA sense aren't really a thing in EU, there are similar but substantially different (and nation-specific, not EU-wide) mechanisms of verifying the creditworthiness of customers, often with specific national laws regulating the usage this data which would override GDPR. Furthermore "please delete my data" doesn't really mean "delete all my data", it means something like "I revoke wh…

I'm curious, in what sense do you mean "Credit reporting agencies" in the USA sense aren't really a thing in EU"?

I've lived in both the UK and USA and used credit products in each, and your access to such credit appears to me almost entirely determined by a handful of credit reporting agencies "scores" in both countries in a pretty similar way. Heck it's even often the same company - Equifax (one of the largest) operate in the UK as well.

Re: GDPR Hall of Shame

#139
post #100

I nominate Slate https://slate.com/privacy for a creative interpretation of GDPR article 7.3 "It shall be as easy to withdraw as to give consent" (the "consent" happens through an uncloseable window with no other options where a single click sets that cookie): "The Right to Withdraw Consent. If you would like to opt-out at any time, please delete the “gdpr_consent_1” cookie from your browser window. You will have to…

I'm pretty sure that no European court would accept that. I doubt most users (and most judges) even know how to delete cookies. I don't even know how to do that on my phone (not sure if that's possible?). And not allowing users with mobile browsers to withdraw consent is definitely a violation.

It would be acceptable if consent involved manually adding a specific cookie (slightly harder than deleting an existing cookie).

Thinking of it, adding cookies manually and maintaining a cookie whitelist could be a useful browser feature in the coming years. Most cookie-based tracking would be forced to disappear.

Re: GDPR Hall of Shame

#140

Earlier quoted context omitted.

I think we should reserve opinion here until bthdonohue gets back with fiiv's comment of "But what part of GDPR was it that caused you to have to close off European Union users?"

I'm not sure it's reasonable to expect an answer to that question; at least not from someone other than their legal representative.

Well, i'm reading their silence as "We don't give a fuck about protecting customers' data.... cause its mine!"

In the end, companies whom don't go through with the GDPR prep and implementation tell me precisely one thing: there's something in their process that makes it hard for them to comply. But not seeing "We're in progress to comply at $date" tells me that they're doing some pretty nefarious stuff. Is that actually the truth? Well, we don't know and can't figure that out.

It's either you comply with the GDPR globally, or for $reasons you don't. I choose to work with GDPR compliant orgs first. I know how my data will be used. And if I buy European IoT hardware, I know its not a spy-station.

Edit: FUCK rate limiting. Here's my response.

Given that I'm an American who has had many accounts exfiltrated or otherwise leaked, I'm frankly sick of companies treating me as a data pinata.

I could go on to cite countless examples, but that dead horse has been beaten time and again. And in many cases, my data is used even without my permission (sending to gmail addresses, facebook ghost profiles, etc).

It might be charitable initially, but I've seen my own impact on bad data practices. It was the wild west... And now the GDPR finally puts a stop to a lot of badness.

Post reply on HN