Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

101–110 of 534 posts

Re: Shutting Down Forum (GDPR)

#101
post #53

Earlier quoted context omitted.

> If there's a risk that someone could sue you over something, Which bit of GDPR introduces that risk?

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

Surely US law also has fines proportionate to what has happened. E.g. EPA has hit large companies with multi-million fines for systematically polluting water over a long time, but if your small company makes a small mistake that's not the same. GDPR explicitly has a list of criteria to assess when determining the fine, and there's no reason to believe courts won't hold regulators to that.

For past experience with German privacy regulators (as an example, since our old law was fairly strict too), I'll quote a recent comment of mine:

From what I know, the German DPAs (they are organized on state level) hand out like 2 fines per month each, generally way below the maxima (under old German law, the max was 300000 €), and concluding the majority of cases without a fine. E.g. from the Bavarian DPA (german doc: https://www.lda.bayern.de/media/baylda_report_07.pdf, page 151):

in the years 2015-2016 they had 173 proceedings that involved potential fines. 52 of those resulted in fines. 34 of those fines were

Re: Shutting Down Forum (GDPR)

#102
post #86
post #73

Earlier quoted context omitted.

How many hours should this person put in to respond to the request?

About 3 minutes. "Here's the privacy policy. Here's the data export page."

Haha data export page, what even is that? Let me just go to my SQL DB, redis, glacier backups, and Kafka logs and just click the data export button. It will only take 3 minutes.

Re: Shutting Down Forum (GDPR)

#103

Earlier quoted context omitted.

Just act in good faith and GDPR will not bite. Do you have $20million to make that gamble?

20 million is the max penalty for repeat offenders. See article 83 about fines being proportinate to the offense: https://gdpr-info.eu/art-83-gdpr/ This is a european thing, if any law says $x is the max fine or alike, then for a first time offense you usually get much less.

"usually" is the problem.

Re: Shutting Down Forum (GDPR)

#104
post #93

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

What you are saying is: don't use the internet. Google, Facebook, Twitter, etc. got websites to implement their like buttons everywhere. The information gathered by them is collected and everybody is being tracked wherever they go.

If a few mega corporations like google, fb, and twitter are The Problem, why are we making a law that generally applies to everyone and will disproportionately impact smaller organizations instead of dealing with these mega corporations per se?

If we aren't as a world terrified of what is being done by small groups like the open source organization announcing it is shutting down in the very post under discussion, why are you defending the GDPR on the idea that it somehow reins in the abuses of FB, Google, etc? Do you have evidence that it is, in fact, reining them in? Or are they just getting with their lawyers, finding cute ways around the problem and carrying on while entire organizations smaller than them suddenly shut down and die because the EU wrote words somewhere that these mega corps likely care relatively little about?

Re: Shutting Down Forum (GDPR)

#105
post #58

He's still obliged to respond to that letter. Can't hide like this. (guys, I'm being sarcastic)

Do you think if the complaint went to a government official in the EU they would throw down the hammer on a site that was up for all of a couple days in GDPR time? I have my doubts. I've got a handful of sites (ultimately for portfolio / coding practice type stuff) out there. Honestly it wouldn't take me too much to respond to someone's letter considering the simplicity of the site(s), not that anyone uses them. I al…

No, but it is more than enough to scare people. Doing a project that makes you zero or very small amounts of money does not justify any risk-taking, and certainly nobody wants to go into the trouble of sending emails to various DPA people in Europe if the need arises. This kind of treatment should be reserved for large companies or specific uses of private data. In addition, the approach of the law "guilty until proven innocent" is hugely off-putting.

Re: Shutting Down Forum (GDPR)

#106
post #37

It's really hard to know what exactly was asked of him by the letter and by whom. I get the nightmare letter scenario but is that the exact request he got? Can he not extract all that user's data and delete if that is what is being requested?

> It's really hard to know what exactly was asked of him by the letter and by whom

It says this right in the posting. >>

> In case anyone is interested, this basically described what has been happening to me: https://jacquesmattheij.com/so-your-start-up-receive-the-nig... 1.2k

> The sad thing is that one email came from the co-founder of a Startup out of Germany.

Re: Shutting Down Forum (GDPR)

#107
post #33

I don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests.

In its majestic equality, the law forbids rich and poor alike to sleep under bridges, beg in the streets and steal loaves of bread or violate the GDPR.

-- Anatole France (I might have edited that quote slightly)

Re: Shutting Down Forum (GDPR)

#108

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

I feel like when people talk about right to privacy they're often using a catch-all for several different concepts. There's a big difference between a right to anonymity and a right to be forgotten.

If you have a very strong right to anonymity, a right to be forgotten is less important because it's easier to separate yourself from your online identity. In fact, forgetting information is pretty harmful because anonymous systems need better tools for building and validating reputation.

If you have a strong right to be forgotten, anonymity is less important because you can just delete information you regret sharing. And similarly, anonymity is kind of harmful because you now need ways to validate who owns information and ways to control how it's spread.

EU seems to be less concerned with anonymity, and more concerned with managing and regulating information after it's already been created and shared. This also kind of rubs the anonymity crowd the wrong way because they've advocated for a while that information isn't necessarily something that you can own like property, and that the Internet should actually be far more immutable than it already is.

Re: Shutting Down Forum (GDPR)

#109
post #27
post #17

Earlier quoted context omitted.

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

How does GDPR affect people in other countries with no interest in doing business in Europe? If I host a forum in the US and you ask me to remove your posts and I tell you where to stick it, what legal consequences might I face? Erm, asking for a friend.

If you aren't in the Union, it applies to you if either [1]:

(a) you are processing data of data subjects who are in the union related to the offering of goods or services to such data subjects, or

(b) you are processing data of data subjects who are in the union related to monitoring of their behavior as far as their behavior takes place within the Union.

If you can avoid both of these, then I believe you can pretty much ignore GDPR.

If you have "no interest in doing business in Europe", it should be easy to avoid falling under (a). Recital 23 [2] discusses what it means to be "related to the offering of goods or services" to data subjects in the Union.

It means that you have to envisage offering services to such people. The mere accessibility of your website to EU people, or having an email or other contact details in the EU, is insufficient to show such intent. If you offer your website in EU languages that are not generally used in your non-EU country, accept EU currencies, mention your EU customers on your site, and things like that, will strongly suggest you are offering them goods and services.

What monitoring of their behavior means is discussed in Recital 24 [3]. It basically means tracking a person for profiling or analyzing or predicting their personal preferences, behaviors and attitudes.

Most sites selling things to end users probably don't need to do any such behavioral monitoring. If you do, just do a geoip check and exclude EU IPs. If you aren't trying to do business in Europe you probably want to do that anyway, because EU visitors are just noise in your data.

[1] https://gdpr-info.eu/art-3-gdpr/

[2] https://gdpr-info.eu/recitals/no-23/

[3] https://gdpr-info.eu/recitals/no-24/

Re: Shutting Down Forum (GDPR)

#110
post #93

Earlier quoted context omitted.

What you are saying is: don't use the internet. Google, Facebook, Twitter, etc. got websites to implement their like buttons everywhere. The information gathered by them is collected and everybody is being tracked wherever they go.

If a few mega corporations like google, fb, and twitter are The Problem, why are we making a law that generally applies to everyone and will disproportionately impact smaller organizations instead of dealing with these mega corporations per se? If we aren't as a world terrified of what is being done by small groups like the open source organization announcing it is shutting down in the very post under discussion, why…

If you make special laws for a few companies, you are fighting the hydra. There will come something after you fined Google or Facebook long enough for being too big. Defining a size for "mega corporations" is also quite arbitrary and I'd quite worse because it doesn't fight the underlying problem: every human should have the right of privacy.

> Do you have evidence that it is, in fact, reining them in?

We will see what happens. The first complaints against Facebook and Google have already been filed.

Post reply on HN