Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

61–70 of 534 posts

Re: Shutting Down Forum (GDPR)

#61
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

I guess posts are considered 'User Generated Content' which I think falls under the directive.

Does that also mean then that quoted content counts? What if another user merely copies/pastes text someone said into their own reply (like you have to do on HN)?

Re: Shutting Down Forum (GDPR)

#62
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

He received the "nightmare letter"[1][2] asking for everything possible under GDPR and then some. 1: https://www.linkedin.com/pulse/nightmare-letter-subject-acce... 2: https://jacquesmattheij.com/so-your-start-up-receive-the-nig...

The nightmare letter is bogus scaremongering bullshit. THe forum owner should just i) post a link to the privacy policy (which surely explains things like legitimate needs) and ii) supplies a copy of the data being held.

Re: Shutting Down Forum (GDPR)

#63
post #33

I don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests.

Everyone was saying that you don't need to worry about GDPR unless you are a scumbag that is selling user information. This open source project owner must have been doing something unethical if they are shutting down their forum due to GDPR.

Re: Shutting Down Forum (GDPR)

#64
post #52
post #37

It's really hard to know what exactly was asked of him by the letter and by whom. I get the nightmare letter scenario but is that the exact request he got? Can he not extract all that user's data and delete if that is what is being requested?

This was linked to in the post: https://jacquesmattheij.com/so-your-start-up-receive-the-nig... It is a request for a lot of information.

Yeah i'm familiar with that. I was wondering if that was the exact request. It's not clear to me that the dude got that exact request.

It's also not clear to me that anyone getting that letter must do what that letter says to the letter else face consequences. We haven't seen that situation tested yet (although I can get why someone might not want to test it them self) all we've seen are letters being sent from individuals to individuals. Now how any enforcement would actual play out IRL.

Re: Shutting Down Forum (GDPR)

#65
post #27
post #17

Earlier quoted context omitted.

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

How does GDPR affect people in other countries with no interest in doing business in Europe? If I host a forum in the US and you ask me to remove your posts and I tell you where to stick it, what legal consequences might I face? Erm, asking for a friend.

Maybe you do business with someone that does have a footprint in the EU? They can put the screws to them I guess.

I imagine visiting an EU member would be unwise as well.

Re: Shutting Down Forum (GDPR)

#67

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

They aren’t attempting to enforce legislation globally. If a company operates in the EU, it has to comply. For companies that don’t operate in the EU and have no EU customers or traffic, they don’t. Simple

Re: Shutting Down Forum (GDPR)

#68
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

> But if they then said that I need to remove _all of their posts_, that's really shitty.

Why do you think GDPR forces forum owners to delete posts? Which bit of GDPR do you think introduces this requirement?

Re: Shutting Down Forum (GDPR)

#69

Earlier quoted context omitted.

I think you are right about one thing, the misreading of European law that comes from living in a litigious society. Just act in good faith and GDPR will not bite.

Just act in good faith and GDPR will not bite. Do you have $20million to make that gamble?

First, that is the maximum. Second, no one scare mongered about the old maximum fines of £500k (which BTW were never used).

https://government.diginomica.com/2017/08/10/ico-maximum-fin...

Re: Shutting Down Forum (GDPR)

#70
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

In that sense, is hn not GDPR compliant?
Post reply on HN