Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

121–130 of 534 posts

Re: Shutting Down Forum (GDPR)

#121

Earlier quoted context omitted.

20 million is the max penalty for repeat offenders. See article 83 about fines being proportinate to the offense: https://gdpr-info.eu/art-83-gdpr/ This is a european thing, if any law says $x is the max fine or alike, then for a first time offense you usually get much less.

"usually" is the problem.

how is interpretation of the law not a problem with any law that was in effect before GDPR. It didn't stop anybody from starting businesses before and will not after.

Re: Shutting Down Forum (GDPR)

#122
post #53

Earlier quoted context omitted.

> If there's a risk that someone could sue you over something, Which bit of GDPR introduces that risk?

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

I posted this above, but the old maximum fine from the ICO was £500k which was never used. The same people worried about being put out of business by the $20M max I guess were okay with close to the ~$750k max? For a lone website operator the new maximum is effectively no different than before.

https://government.diginomica.com/2017/08/10/ico-maximum-fin...

Re: Shutting Down Forum (GDPR)

#123
post #11

People asking to exercise their rights on their own private information are not trolls.

> exercise their rights

These aren't their natural right. Some laws are just bad independent of whether most people support or agreed to them. This is most obvious in dictatorships, but dysfunction strikes all systems.

Re: Shutting Down Forum (GDPR)

#124
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

As someone who ran a forum centered around one of my passions, I was happy to help users out with small adminstrative tasks. Like you said, no big deal.

Now if I was legally required to act on every request in 30 days or face potential litigation, that's a totally different story. I'm doing something that's a fun hobby of mine for free that will benefit others with similar interests. The line is drawn when it can have real world consequences and take up a substantial amount of personal time in order to comply with frivolous requests. That's when it stops being fun and definitely not worth risking legal headaches.

Re: Shutting Down Forum (GDPR)

#125

Can't wait for future nightmare letters coming from Saudi Arabia when they find moral indecency on my web site or China finding imperialist propaganda that needs addressing. This will be used as a precedent for every other control freak pushing their values onto us. What happened to free and open internet?

This already happens. Russia sent notices to GitHub about certain documents that were hosted there. China and Saudi Arabia just straight up block things they don’t like.

Yea, but this emboldens them because they can now point to EU and say that this is what normal countries do, long arm[0] people around.

[0] https://en.wikipedia.org/wiki/Long-arm_jurisdiction

Re: Shutting Down Forum (GDPR)

#126

Earlier quoted context omitted.

> No lawyers required. Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.

>If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. Bad news: If you have a business, people can attempt to sue your business for whatever they want, and you might have to defend against it. There is nothing on the books that says lawsuits have to be reasonable before they can be filed, only that people…

Judges in the US routinely dismiss frivolous cases[1] with prejudice.

And in fact even filing a frivolous case can result in fines or jail time for contempt.

So no, you can’t in practice sue someone for anything.

[1]: https://en.m.wikipedia.org/wiki/Frivolous_litigation

Re: Shutting Down Forum (GDPR)

#127

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

The OP initially says if you’re small time they likely won’t target you. Are you really saying if you’re super small time, the EU is going to go after your payment processing? Of course anything is possible. It seems highly unlikely though.

Then his/her last point is that they’ll give you a chance to correct things.

Your post doesn’t seem to cover that either.

Re: Shutting Down Forum (GDPR)

#128
Goes to show that when an industry does not self-regulate, it gets over-regulated, which often disproportionately benefits incumbents, which incentivizes future lack of self regulation.

Re: Shutting Down Forum (GDPR)

#129
post #42
post #27

Earlier quoted context omitted.

How does GDPR affect people in other countries with no interest in doing business in Europe? If I host a forum in the US and you ask me to remove your posts and I tell you where to stick it, what legal consequences might I face? Erm, asking for a friend.

As much as I dislike Donald Trump, I am willing to hold my nose here and suggest encouraging the Trump Administration to go full MAGA and direct Congress to pass laws explicitly stating that no foreign judgements or fines may be enforced on US citizens.

[deleted]

Re: Shutting Down Forum (GDPR)

#130
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

> If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty.

> It would destroy the usefulness of a forum.

Couldn't you just anonymize their posts, for instance by updating their username to something like "Deleted User"? Wouldn't you be fine as long as there wasn't anything left to link them to their real identity?

Post reply on HN