Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

161–170 of 192 posts

Re: GDPR Hall of Shame

#161

Earlier quoted context omitted.

It certainly is related. One core argument is that the vast majority of currently stored personal data has no good reason whatsoever to be there, the company should not be collecting, using and storing any personal data. If half of the companies remove that private data which they shouldn't have, then that will reduce the impact of breaches, as there'll be twice less breaches where's something sensitive to leak.

I can't think of massive leaks that involved data that wasn't 'legitimate'. What's your go-to example?

No particular single example in mind, but just going through random large leaks:

The Republican National Committee leak (https://gizmodo.com/gop-data-firm-accidentally-leaks-persona...) - all the involved companies which swapped data records to make up this trove would not have had the permission to have much of that data under GDPR.

World Wrestling Entertainment 2017 leak - the leaked data included home and email addresses, birthdates, as well as customers' children's age ranges and genders where supplied, and even ethnicity; there's simply no reasonable reason why they should have had data like that in the first place. It it hadn't be collected, it couldn't have been leaked.

Joblink breach (https://www.identityforce.com/blog/americas-joblink-data-bre...) leaked among other things birthdate and social security number. There's no good reason to ask the birthdate in the first place, and to store the social security number after you've run whatever verification they do (presumably it gets used for background screening).

The big point is that almost always data minimization would have reduced the consequences. Companies keep old data forever, and that creates extra risk; Companies ask for and store more data than they need and that creates extra risk; Companies buy and sell data that shouldn't be bought and sold, and so the data copied in multiple organizations and again, creates extra risk.

Re: GDPR Hall of Shame

#162
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

Everything is, there was a big deal here in the Netherlands about the local governments having to be compliant as well. The first thing that the dutch agency will check (no fines, but just make sure) is that each municipality has things set up properly. On top of that, I don't think there's anything in the GDPR limiting it to internet related things, so brick & mortar stores will have to be compliant as well, afaik.

It's digital data that's covered by GDPR, so a bricks and mortar outfit with solely paper records wouldn't be affected.

Re: GDPR Hall of Shame

#163

Earlier quoted context omitted.

The misunderstanding of this is widespread. GDPR does not make any mention of EU citizens OR residents. It only says "data subjects who are IN the Union". See my other comment for more detail: https://news.ycombinator.com/item?id=17143923

It is not defined what "who are in the Union" means. The safest bet is that it means a subject is European Union resident. If they mean that person should be physically present in the European Union, the law would have stated that, but it is not.

Equally, if they had meant resident, they would have stated that.

Re: GDPR Hall of Shame

#164
post #96
post #92

Earlier quoted context omitted.

> The Yahoo! one [1] is definitely in violation of GDPR, right? I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin. If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the siz…

Oh, it's perfectly fine to have as many sub-processors as they want. But default opt-in is non-compliant; if I understand the regulation correctly, the user has to manually opt into every processor. An opt-out dark pattern is specifically prohibited in GDPR.

Depends on what those dials actually represent (the screenshot is blurry for me). If the legal basis for the sub-processors is Legitimate Interest, then consent isn't required and the dials represent a Right to Erasure request. That would all be above-board and legit.

If the legal basis is Consent, then you are correct, it must be opt-in rather than opt-out.

Re: GDPR Hall of Shame

#165

Earlier quoted context omitted.

This kind of problem is what lawyers are for. Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What s…

>riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced"

You could be describing a very large proportion of laws.

To pick a random example, I'll go with the Road Traffic Act 1991 (England and Wales).

It is an offence under this act to drive a mechanically propelled vehicle dangerously on a public road. The definition of dangerous driving is: a) the way he drives falls far below what would be expected of a competent and careful driver, and b) it would be obvious to a competent and careful driver that driving in that way would be dangerous.

That's it. Are you driving like an absolute dick? Is it obvious that you're driving like an absolute dick? If so, you're committing an offence. We have lots of other, more specific motoring laws, but you can be convicted and sentenced based on those two subjective factors. We have lots of case law and guidelines, but the matter of whether your driving definitively is or isn't dangerous can only be decided in court.

https://www.legislation.gov.uk/ukpga/1991/40/part/I/crosshea...

The broad nature of GDPR is a feature, not a bug. Nothing about the way it is worded is particularly new or unusual. Large sections are cribbed from the Data Protection Directive, which came into force in 1995.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

Re: GDPR Hall of Shame

#166

Earlier quoted context omitted.

> So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. No, it can something as simple as "we cannot guarantee that all your data is deleted with our current storage system". It would be a lot better if people stop being so alarmist.

It would be a lot better if people stop being so alarmist. Indeed. It's odd looking at discussions about the GDPR on HN. On the one hand, we have people who argue that compliance isn't really that big a deal if you're not doing anything horribly wrong, most ethical businesses would already be mostly compliant anyway, etc. On the other hand, we have people who argue that even if that is the case, the length and ambigu…

    > so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped
I think it's pretty reasonable to have that premise when those businesses can't tell their users what they did or will do with personal data. No one could even tell whether it's evil or good if you don't show me some details. And sometimes, you assume it's good for me, but I think it's bad for me. Thank you for your good intention but all I want is just an opt-in option, not opt-out, is that so hard to accept? When you drag me into something I don't want, why would I assume you are doing something good? Users being alarmist is not users' fault, data companies' unethical use of data made users react this way.

    > "we cannot guarantee that all your data is deleted with our current storage system".
If so, just say it. But after that, you may want to explain to me why you can't even take care of my data while claiming you respect it. Did you collect my data then just forget where you store it? If the deletion is that hard, why should users trust such company in the first place?

GDPR is an action of defense, not a weapon for invasion. Only predator would think it's a weapon and be afraid. GDPR is not perfect for now, but complaining the ambiguity of it doesn't make internet companies' vague ToS or Privacy Policy clear as crystal. Let's not play double standards here.

I'm quite aware HN is full of people work in data industries, I just have to say it.

Re: GDPR Hall of Shame

#167
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

Hi Brian, I've downloaded all my data to move to self hosting and deleted my account due to this. I hope you've actually deleted everything :)

P.S. I still have access in the UK...

Re: GDPR Hall of Shame

#168
post #53

Earlier quoted context omitted.

Whatever the case might be, companies have shown themselves to not handle people's personal data properly, as shown by the massive leaks in the past. Whatever utopia you're thinking of, it's not happening anytime soon, and GDPR is a rightful measure to slightly apply the brakes on rampant data collection and misuse.

Massive leaks are a security issue, and have nothing to do with users being able to delete their data at will.

Why do you think users can delete their data at will?

Re: GDPR Hall of Shame

#169
post #115

Earlier quoted context omitted.

80s were still fairly early for Internet access. I was on the ARPANET as early as 1979 or so but just trading the occasional email in a lab. "Real" internet access, first at work and then through my BBS, was probably more like the early 1990s.

Oh yeah, I didn’t do anything on the Internet in 1990 apart from typing ‘go internet’ into CIX (my BBS at the time), sitting there wondering what you could do with it, then killing the connection when my dad pointed out that we paid by the minute for the phone line :) I don’t think I knew anyone online that wasn’t on CIX either.

People don't understand just how expensive early online access was.

Here's a page from 1988 Whole Earth Catalogue "Signal - Communication tools for the Information Age"

http://tinypic.com/view.php?pic=2janfrd&s=7#.WwcJwiAh200

Compuserve, charging $11 per hour, had "more than 250,000 subscribers".

The Source, charging $8 per hour, was popular for its conferencing system "parti".

Delphi, charging $6 per hour had a loyal but small (less than 10,000 users) following.

BIX, $9 per hour, grew from a magazine. I like the quote: "This is the computer industry as it used to be: people sharing ideas and solutions without the greed and grit with associated with today's corporate driven, litigation-laced, industry" (written 30 years ago).

http://www.wholeearth.com/issue-electronic-edition.php?iss=1...

Re: GDPR Hall of Shame

#170
post #28

The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting. Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally? [1] Hidde…

> The Yahoo! one [1] is definitely in violation of GDPR, right?

They either made it much worse after the author did the screenshots, or it was already extremely bad --that I could not find the link to open up that huge list of third parties.

I clicked on all the links I could find in that screen except for that huge 'I Agree' button.

Post reply on HN