Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

151–160 of 192 posts

Re: GDPR Hall of Shame

#151
post #75

Earlier quoted context omitted.

I think there's also a sizable number of companies that basically were already compliant... but aren't sure. It's not like you can submit your processes to the EU for approval. You don't actually know if what you're doing is OK unless, some day, a regulator decides it isn't.

This kind of problem is what lawyers are for. Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.

I promise: we're not all like that. In fact, I suspect there is a significant minority of people--including myself--that think just like you. I look forward to the end of all these data and privacy abuses.

Re: GDPR Hall of Shame

#152
post #147

Earlier quoted context omitted.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What s…

I think that's intentional as it massively increases the risk of doing something negative for the end user and leaves loopholes uncertain and prone to interpretation. It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing. Also it stops a whole legal and compliance industry appearing in the grey zone as no one wants to abstract liability.

It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing.

I'm not so sure. No-one knows where the line is, so many organisations can only be sure they're staying well clear by stopping all kinds of legitimate, reasonable data processing, which is throwing the baby out with the bathwater. An alternative, which I've seen quite a few small organisations and individuals adopting and now a few larger ones as well, is to just cut the EU off entirely if they're based outside and thus put themselves outside the scope of the GDPR for practical purposes, and then carry on as before under more liberal regimes like the US. Both of these strategies are harmful without really helping anyone.

Re: GDPR Hall of Shame

#153
post #105
post #93

Earlier quoted context omitted.

There are people here who invented ARPANet.

Perhaps that's why I asked if gerbilly was involved in ARPANet.

I was on the internet as an undergrad first at UofT in 1988, it was mostly FTP and usenet back then.

Our machines didn't even use DNS yet IIRC there was a HOSTS.TXT file sent around that had to be updated as new sites were added to the network.

It was fairly early, and I got to see the internet before the marketers started to take notice of it.

I remember the internet worm[1] and the Canter and Siegel usenet spam a bit later[2].

I'm glad the internet was made public of course but I wish the standards from back then had better security built in.

Of course encrypting everything back then would have been a significant drain on computational resources. We used to login 40 students at a time on TTYs to a Sun 3/280 (25mhz CPU!).[3]

[1] https://en.wikipedia.org/wiki/Morris_worm [2] https://en.wikipedia.org/wiki/Laurence_Canter_and_Martha_Sie... [3] https://en.wikipedia.org/wiki/Sun-3

Re: GDPR Hall of Shame

#154

Earlier quoted context omitted.

People in this thread saw the title "GDPR Hall of Shame", possibly read it. Now they are trying to discuss stuff relating to "General Data Protection Regulation". My wild guess is people who are commenting on this thread care.

Do they really care or have they been pushed to care?

What the heck are you implying? Are you implying there's astroturfing going on? If so, that's ridiculous.

Re: GDPR Hall of Shame

#155
post #138

Earlier quoted context omitted.

"Credit reporting agencies" in the USA sense aren't really a thing in EU, there are similar but substantially different (and nation-specific, not EU-wide) mechanisms of verifying the creditworthiness of customers, often with specific national laws regulating the usage this data which would override GDPR. Furthermore "please delete my data" doesn't really mean "delete all my data", it means something like "I revoke wh…

I'm curious, in what sense do you mean "Credit reporting agencies" in the USA sense aren't really a thing in EU"? I've lived in both the UK and USA and used credit products in each, and your access to such credit appears to me almost entirely determined by a handful of credit reporting agencies "scores" in both countries in a pretty similar way. Heck it's even often the same company - Equifax (one of the largest) ope…

There are many differences; it's hard to generalize because each EU country is different (there's no harmonization for this, and there are major differences especially along the "ex-Warsaw-Pact" border; half of EU had their whole financial system [re]built in 1990s), but you'll often see the following differences:

1) There's no "EU score", each lending market is somewhat separate. Past history in one location may or may not influence your score in another location.

2) Instead of a general/universal "credit score" calculated by an agency, there's often a concept of "credit history" which (depending on the country) may or may not list the amounts of existing loans, of previous loans, and history of late payments. The difference being that instead of lenders getting a score calculated by some agency, the lenders get the data and make their own decision, with possibly very different opinions on which factors are important. Not everywhere, of course, some countries (e.g. UK or Nordics) are more like USA.

3) The process tends to be highly regulated. If you're providing factual data as opposed to an opaque score, each item better be correct - distributing to all lenders "Bob defaulted on a loan in 1999" is libel if it's not true; the dispute process tends to be more consumer-friendly than USA - e.g. a requirement to remove the disputed items immediately and return them only if the debtor can prove its validity), maybe a requirement to expire entries of missed payments within x years, etc.

4) In some countries, that agency is run by the gov't, i.e. purely a central official registry of loans and/or bad loans, which is somewhat sufficient to verify creditworthiness. In others, it's like Equifax.

5) There often is a principle that the credit reporting agencies can't give/sell that data to anyone - you must give explicit permission for every company before they can gain access to that data.

6) In many countries there's no concept of "building credit" - where there only information provided is about negative events (e.g. defaults or missed payments), so having never taken a loan combined with good income gets a perfect rating, as it's not distinguishable from a long credit history and having never missed a payment.

So it's quite tricky - similar but different.

Re: GDPR Hall of Shame

#156
Could somebody help me understand the criticism in this article of companies like Instapaper blocking EU users? When you face fines of up to 20M EUR, you’re not going to take on that liability if you have a choice.

Most companies outside the EU will eventually block EU traffic. GDPR is just too big of a liability. It has nothing to do with “selling user data” or bad intentions with user privacy. I won’t take EU traffic for the same reason that I don’t drive at 140mph in a 25mph zone - it’s irresponsibly dangerous.

Re: GDPR Hall of Shame

#157

Earlier quoted context omitted.

>If the definition of personal data includes IP addresses Yes it does. > I'd be surprised there are any internet-connected products that don't process personal data in some way. Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows: "Processing shall be lawful if... processing is necessary for the purposes of the legitimate interes…

What's your theory about why so many seem to be doing such a bad job meeting the letter and spirit of the law? Are they consulting with lawyers or other legal experts and bending over backwards to do the best they can given the advice they're given? Or are they maliciously flouting the obvious requirements as part of a concerted, and possibly coordinated, effort to undermine the law?

IMHO the process in many of these places was ran something like delegating it all to the legal department and treating it as a challenge of adjusting their privacy policies and other legal documents, but not expecting (or allowing) that project to change any of their core business processes.

However, in many (most?) cases that cannot possibly be sufficient to comply, so we're seeing how the legal people have done as much as they could to cover their arses, given that the actual behavior of the company around them wasn't allowed to change.

It also may be that some companies are intentionally planning a delaying tactic - i.e. a plan to flip the switch on private data processing only when the regulators will get to them and start writing stern letters, so that they can reap the benefits of (ab)using user data for some more months.

Re: GDPR Hall of Shame

#158
post #61

Earlier quoted context omitted.

A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.

What if EU citizens who are visiting US make purchases from your site?

Recital 23 states that sites based outside the EU are not subject to GDPR unless it is apparent that they “envisage” the offering of their goods or services to EU residents. The test for this is translation to EU-only languages, mentioning of EU users, targeting EU users, using an EU based domain extension, etc.

The easiest way to announce to the world that I do not “envisage” servicing EU customers is to block EU customers. If one happens to use a VPN or otherwise evades this block, it doesn’t matter. I’ve met the clear definitions under Recital 23 and you have no legal right to GDPR protections on my site.

Re: GDPR Hall of Shame

#159

Earlier quoted context omitted.

>If the definition of personal data includes IP addresses Yes it does. > I'd be surprised there are any internet-connected products that don't process personal data in some way. Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows: "Processing shall be lawful if... processing is necessary for the purposes of the legitimate interes…

What's your theory about why so many seem to be doing such a bad job meeting the letter and spirit of the law? Are they consulting with lawyers or other legal experts and bending over backwards to do the best they can given the advice they're given? Or are they maliciously flouting the obvious requirements as part of a concerted, and possibly coordinated, effort to undermine the law?

I think that there are two contrary trends.

Large companies that substantially profit from personal data are testing the boundaries of GDPR. They've got competent legal advice and know that a blatant effort would earn the wrath of the regulators, so they're being subtle about it. They're creatively interpreting grey areas. They're using complex and confusing opt-outs justified by spurious technical issues. They're carefully planning a strategy that will allow them to drag out the enforcement process and gain as much ground as possible, while maintaining the pretence that they're making a good-faith effort to comply. They'd rather avoid a heavy fine, but they're not afraid of butting heads with the regulators.

A lot of small companies without in-house counsel are going a bit crazy. Maybe they've spoken to a data protection consultant who has fed them a bunch of FUD, maybe they've just read a few articles in the press, but they haven't really scrutinised the text of the GDPR or spoken to a regulatory authority. They don't understand what their obligations are under the GDPR or the overarching principles of data protection, but they're doing something. Sometimes that thing is completely overzealous, sometimes it's totally inadequate. I've seen a lot of misguided efforts by SMEs to indemnify themselves against GDPR, akin to the "no copyright intended" statements you see in YouTube descriptions. Many of these companies had been completely ignoring the old Data Protection Directive, so they've got a lot of catching up to do.

Re: GDPR Hall of Shame

#160

I nominate Slate https://slate.com/privacy for a creative interpretation of GDPR article 7.3 "It shall be as easy to withdraw as to give consent" (the "consent" happens through an uncloseable window with no other options where a single click sets that cookie): "The Right to Withdraw Consent. If you would like to opt-out at any time, please delete the “gdpr_consent_1” cookie from your browser window. You will have to…

NPR has decided that you either agree to let them do whatever they want with your data, or you're only allowed to see a ridiculously bare-bones plain-text version of the site lacking any functionality beyond links.

Ten minutes later I've got a user style set up and I'm quite happy with the plain version. But it's still a petty response from the organisation and shows that they don't feel they need to spend any time at all trying to help users control their own data.

https://choice.npr.org

Post reply on HN