Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

171–180 of 192 posts

Re: GDPR Hall of Shame

#171
post #55

Hey! I made this, mostly just to poke fun at my inbox being here in Europe and experiencing it first hand. Feel free to fire me a reply with any good ones you've spotted; I'll be actively adding through tomorrow and beyond.

Could you take another look at Yahoo? I don't see the link you mentioned to walk through the huge list --I couldn't find any link that gets me to those two pages.

Thanks! :)

Edit: Thank you for making this!!

Re: GDPR Hall of Shame

#172

Ive been enjoying all the emails from companies and watching them put on a show how they support user privacy and just needs me to continue agreeing to accepting being the product. I dont think so. There are very few companies I actually use in my life, and less than a handful of them are online. The rest - bugger off.

> Ive been enjoying all the emails from companies

I've been receiving so many "here is our policy, if you continue your use, you accept it, kbye" emails... I truly hope EU will take the default-opt-in problem seriously.

Re: GDPR Hall of Shame

#173
post #169

Earlier quoted context omitted.

Oh yeah, I didn’t do anything on the Internet in 1990 apart from typing ‘go internet’ into CIX (my BBS at the time), sitting there wondering what you could do with it, then killing the connection when my dad pointed out that we paid by the minute for the phone line :) I don’t think I knew anyone online that wasn’t on CIX either.

People don't understand just how expensive early online access was. Here's a page from 1988 Whole Earth Catalogue "Signal - Communication tools for the Information Age" http://tinypic.com/view.php?pic=2janfrd&s=7#.WwcJwiAh200 Compuserve, charging $11 per hour, had "more than 250,000 subscribers". The Source, charging $8 per hour, was popular for its conferencing system "parti". Delphi, charging $6 per hour had a loya…

CIX supplied Ameol (a most excellent offline reader) which could connect quickly and disconnect. In the UK we didn’t have the luxury of the US’s free local calls, so that was an added expense on top of that.

Re: GDPR Hall of Shame

#174
post #16

Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.

[deleted]

Re: GDPR Hall of Shame

#175
post #16

Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.

I must admit, even as a critic of the GDPR in some respects, as an individual I am hoping that its heavy-handed approach will mean I can buy everyday things again without having spyware, telemetry, and so on coming as standard. I don't want a "smart" phone or a "smart" TV or a "connected" car, where the scare quotes denote entirely unnecessary invasion of privacy and/or security and safety risks. I buy a phone to com…

Then just buy older stuff nobody says you need a smartphone.

Re: GDPR Hall of Shame

#176
OK but maybe your website should not use cookies without asking? You don't have a privacy policy either so not clear how u re going to use them. And maybe don't use google analytics without a privacy policy? Or at least anonymize the IP?

Re: GDPR Hall of Shame

#177
post #169

Earlier quoted context omitted.

People don't understand just how expensive early online access was. Here's a page from 1988 Whole Earth Catalogue "Signal - Communication tools for the Information Age" http://tinypic.com/view.php?pic=2janfrd&s=7#.WwcJwiAh200 Compuserve, charging $11 per hour, had "more than 250,000 subscribers". The Source, charging $8 per hour, was popular for its conferencing system "parti". Delphi, charging $6 per hour had a loya…

CIX supplied Ameol (a most excellent offline reader) which could connect quickly and disconnect. In the UK we didn’t have the luxury of the US’s free local calls, so that was an added expense on top of that.

>In the UK we didn’t have the luxury of the US’s free local calls

Although free local calls could be quite limited in area. Intrastate long distance (which could be as little as 15 or 20 miles away) could actually be more expensive than interstate long distance. I don't remember the details but I used a private BBS service in the nearest major city in the 80s. I had some sort of phone plan that optimized for this but I still used offline tools to minimize my online time. (i.e. Login, suck down content, logoff, read and reply offline)

I used similar tools for Compuserve. As you say, it was extraordinarily expensive by today's standards. People complain about the pricing of a lot of things but telecoms and pretty much everything related to computing is incredibly cheap.

Re: GDPR Hall of Shame

#178

Earlier quoted context omitted.

The misunderstanding of this is widespread. GDPR does not make any mention of EU citizens OR residents. It only says "data subjects who are IN the Union". See my other comment for more detail: https://news.ycombinator.com/item?id=17143923

It is not defined what "who are in the Union" means. The safest bet is that it means a subject is European Union resident. If they mean that person should be physically present in the European Union, the law would have stated that, but it is not.

EU can apply its laws "in the Union", in its territories. If we want to expand those territories, we need wars etc.

Re: GDPR Hall of Shame

#179

Earlier quoted context omitted.

It is not defined what "who are in the Union" means. The safest bet is that it means a subject is European Union resident. If they mean that person should be physically present in the European Union, the law would have stated that, but it is not.

Equally, if they had meant resident, they would have stated that.

"Resident" has a full scope of protection, whereas your interpretation has limited cover. I wouldn't have thought that GDPR would protect me only if I was physically in the EU territory - as if somehow once I stepped out of the EU my personal information is no longer worth protecting. Your interpretation makes no sense.

Re: GDPR Hall of Shame

#180

Earlier quoted context omitted.

Equally, if they had meant resident, they would have stated that.

"Resident" has a full scope of protection, whereas your interpretation has limited cover. I wouldn't have thought that GDPR would protect me only if I was physically in the EU territory - as if somehow once I stepped out of the EU my personal information is no longer worth protecting. Your interpretation makes no sense.

I think you are missing some context here.

Firstly if the company is established in the union then they need to be compliant for all their users no matter where they are [1] (so US resident, EU resident, whatever are equally protected).

So the relevant section for this is:

"This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

the monitoring of their behaviour as far as their behaviour takes place within the Union."

So lets look at Amazon. They are a US company offering goods in the EU. So if you make a purchase from them as an EU resident (living in Germany) from amazon.de to your home address, then any personal data you give them as part of that purchase needs to be handled in a GDPR compliant way.

If you now go on holiday to the US and order something from Amazon.com to be delivered to your hotel, even though you are an EU resident, they do not need to handle that personal data in a GDPR compliant way. But just because you are now in the US doesn't mean the data they hold on you about your purchase on amazon.de is suddenly free from GDPR protections.

Or to put it another way. Imagine the law did mean EU resident. What does Amazon.com do? How do they ensure they process an order in the US to a US address in a GDPR compliant way for an EU resident? They can't without asking for additional data to establish each persons residency. Which GDPR doesn't allow.

[1] https://gdpr-info.eu/art-3-gdpr/

Post reply on HN