Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

111–120 of 534 posts

Re: Shutting Down Forum (GDPR)

#111

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

I feel like when people talk about right to privacy they're often using a catch-all for several different concepts. There's a big difference between a right to anonymity and a right to be forgotten. If you have a very strong right to anonymity, a right to be forgotten is less important because it's easier to separate yourself from your online identity. In fact, forgetting information is pretty harmful because anonymo…

> There's a big difference between a right to anonymity and a right to be forgotten.

Exactly. Privacy also doesnt mean being invisble when interacting with people or machines. It's not a well-defined right, and the limits can often be fuzzy (e.g. a problem that kids often have with parents). Pseudonymity / anonymity can also be subject to gradation.

Re: Shutting Down Forum (GDPR)

#112

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc.

sensible regulation that defines workable limits of what personal information can be collected, combined with requirements for anonymization when needed is a better solution.

Re: Shutting Down Forum (GDPR)

#113
post #101

Earlier quoted context omitted.

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

Surely US law also has fines proportionate to what has happened. E.g. EPA has hit large companies with multi-million fines for systematically polluting water over a long time, but if your small company makes a small mistake that's not the same. GDPR explicitly has a list of criteria to assess when determining the fine, and there's no reason to believe courts won't hold regulators to that. For past experience with Ger…

[deleted]

Re: Shutting Down Forum (GDPR)

#114
post #64
post #52

Earlier quoted context omitted.

This was linked to in the post: https://jacquesmattheij.com/so-your-start-up-receive-the-nig... It is a request for a lot of information.

Yeah i'm familiar with that. I was wondering if that was the exact request. It's not clear to me that the dude got that exact request. It's also not clear to me that anyone getting that letter must do what that letter says to the letter else face consequences. We haven't seen that situation tested yet (although I can get why someone might not want to test it them self) all we've seen are letters being sent from indiv…

Who wants to be a guinea pig for lawyers? what fun!

Re: Shutting Down Forum (GDPR)

#115
post #99

Earlier quoted context omitted.

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

European law tends to talk about the maximum available penalty under the worst possible situation. It then gives a list of factors to be taken into account. I'm not sure why that's a bad thing. Look at the US COPPA, with potentially $41,000 per violation. Why isn't this more scary for American website operators? https://www.ftc.gov/tips-advice/business-center/guidance/com... > A court can hold operators who violate t…

COPPA is frightening to web operators, at least in the abstract. The majority of web services online at least make a cursory effort to either ban users under the age of 13 from accessing the site or force them to give parental consent. Technically speaking, if you're under 13 you're not really supposed to be on sites like Twitter.

The equivalent reaction for GDPR would be if everyone either started making half-hearted efforts to block European users (which isn't what EU wants), or if everyone forced all of their users to agree to the same data collection before they signed up (which as far as I can tell is not legal).

From the law:

> However, an operator of a general audience site or service that chooses to screen its users for age in a neutral fashion may rely on the age information its users enter, even if that age information is not accurate.

This line is basically the entire reason why COPPA is generally not seen as a problem for US businesses.

Re: Shutting Down Forum (GDPR)

#116
post #110

Earlier quoted context omitted.

If a few mega corporations like google, fb, and twitter are The Problem, why are we making a law that generally applies to everyone and will disproportionately impact smaller organizations instead of dealing with these mega corporations per se? If we aren't as a world terrified of what is being done by small groups like the open source organization announcing it is shutting down in the very post under discussion, why…

If you make special laws for a few companies, you are fighting the hydra. There will come something after you fined Google or Facebook long enough for being too big. Defining a size for "mega corporations" is also quite arbitrary and I'd quite worse because it doesn't fight the underlying problem: every human should have the right of privacy. > Do you have evidence that it is, in fact, reining them in? We will see wh…

I said dealing with these mega corporations per se. This in no way suggests making special laws for a few companies.

If the entire world currently agrees that a handful of companies are The Problem, then there should be some means to go after said handful of companies and get them to stop being The Problem without creating blanket laws negatively impacting the entire world, especially smaller organizations.

Dealing directly with a problem company usually involves charging them under existing laws (anti-monopoly laws?) and things like that. It usually does not mean making unenforceable laws that name them by name or define things in a Jim Crow style that clearly targets them in specific and that is unlikely to stand up in court.

Re: Shutting Down Forum (GDPR)

#117
post #101

Earlier quoted context omitted.

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

Surely US law also has fines proportionate to what has happened. E.g. EPA has hit large companies with multi-million fines for systematically polluting water over a long time, but if your small company makes a small mistake that's not the same. GDPR explicitly has a list of criteria to assess when determining the fine, and there's no reason to believe courts won't hold regulators to that. For past experience with Ger…

Well, I'll operate under the assumption that EU posters know EU governments better than I do :)

If that's the case then I suspect you'll see fewer companies panicking over time. It may just take an adjustment period for companies to realize, "Oh, this legislation isn't actually filled with hidden land mines."

Re: Shutting Down Forum (GDPR)

#118

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc.

There are tons of companies processing my personal data that are not web companies. GDPR isn't about "data being on the web", it's about all handling of personal data.

Re: Shutting Down Forum (GDPR)

#119
Can't wait for future nightmare letters coming from Saudi Arabia when they find moral indecency on my web site or China finding imperialist propaganda that needs addressing. This will be used as a precedent for every other control freak pushing their values onto us. What happened to free and open internet?

Re: Shutting Down Forum (GDPR)

#120

Can't wait for future nightmare letters coming from Saudi Arabia when they find moral indecency on my web site or China finding imperialist propaganda that needs addressing. This will be used as a precedent for every other control freak pushing their values onto us. What happened to free and open internet?

This already happens. Russia sent notices to GitHub about certain documents that were hosted there. China and Saudi Arabia just straight up block things they don’t like.
Post reply on HN