Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

191–200 of 534 posts

Re: Shutting Down Forum (GDPR)

#191
So basically drone.io is saying that discourse is not RGPD compliant and reddit is better equipped to deal with RGPD requests so he's moving his community discussion from a self hosted discourse to reddit.

Looks like a knee jerk reaction and missing the point that you can evade RGPD by outsourcing to a third party, one can still send RGPD requests to drone.io and owner is still responsible for answering those but now has to deal with getting the relevant data from reddit.

Re: Shutting Down Forum (GDPR)

#192

Earlier quoted context omitted.

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

> they will target you through payment processors and ad networks How will they do that, and on what legal basis?

Garnishment.

If the regulatory agency decides to fine you, and you don't successfully defend yourself against that in court, then you'll have to pay that fine. If you fail to pay the fine on time, any entities within the juristiction that owe you can be ordered to pay the fine instead (i.e., your payment processor will be ordered to redirect funds arriving for you to the state, which also, as far as their juristiction is concerned, fulfills their debt towards you--as far as their legal system is concerned, the payment processor has paid you and you have paid the fine).

Re: Shutting Down Forum (GDPR)

#193

So basically drone.io is saying that discourse is not RGPD compliant and reddit is better equipped to deal with RGPD requests so he's moving his community discussion from a self hosted discourse to reddit. Looks like a knee jerk reaction and missing the point that you can evade RGPD by outsourcing to a third party, one can still send RGPD requests to drone.io and owner is still responsible for answering those but now…

no he wont be. reddit will

Re: Shutting Down Forum (GDPR)

#194
post #185
post #142

Earlier quoted context omitted.

This is so incredibly tonedeaf: do you honestly think that small hobby-scale websites have a privacy policy?

What? So just because you're small scale you can ignore people's privacy?

There’s a big difference between ignoring somebody’s privacy and having an official lawyered document that spells them out.

I’m sorry that this is a distinction you weren’t able to make.

Re: Shutting Down Forum (GDPR)

#195
post #142

Earlier quoted context omitted.

This is so incredibly tonedeaf: do you honestly think that small hobby-scale websites have a privacy policy?

Do you believe that hobbyists must not follow laws & regulations when they interact with the public?

Do you believe that anyone who has a hobby website with a forum needs an official privacy document, presumably vetted by a lawyer.

Re: Shutting Down Forum (GDPR)

#196
post #167

Earlier quoted context omitted.

The GDPR was passed by the European Comission, not the EP. Members of the EC are appointed, just like ministers in governments. But governments can only pass time limited decrees which then have to be signed into laws and voted for in Parliament. The EC which can pass binding regulations that apply indefinitely.

I think you mean "proposed" instead of "passed" - "passed" is usually used to mean "passed a law" The commission proposes legislation, the council & parliament pass it

[deleted]

Re: Shutting Down Forum (GDPR)

#197
The thing I have to wonder is who did this and more importantly, why?

If you're a startup competing against an open-source project, then this is potentially a great (not good) way to get a leg up. You get the benefit of access to the code until you don't need it anymore, then get the project shut down and reap the benefit of being the last man standing.

Sure, you might eventually run up against the license on the software you just lifted, but open-source projects can't afford the same protections that a well-funded startup has.

And if you somehow get sued for license violations, the penalties are usually more a slap on the wrist than an effective notice to knock that shit off.

I really hate the way my mind works some days.

Re: Shutting Down Forum (GDPR)

#198

Earlier quoted context omitted.

>If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. Facebook and other data aggregators build profiles of you even if you don't participate directly in those services. The web is different now than it was in 1996.

And GDPR doesnt help with that. I cannot send Facebook a request for my shadow profile, nor demand they delete all such data, as I have no way to ‘identify myself’ to them unless I have a Facebook account.

They seem to have no problem identifying you without an account and then linking your shadow profile to your real profile, should you create one.

I suggest using the identifier you received at birth to make the request plus your e-mail.

Re: Shutting Down Forum (GDPR)

#200

Earlier quoted context omitted.

If you walk into a store and buy something, does the owner not have a right to record relevant personal information as it pertains to the sale, such as when buying a car? This idea that those vendors ought to be required to delete records seems backwards — you aren’t required to interact with entities that do things you don’t like — unless it’s the government, no escaping that. Public records are potentially more har…

The owner of the store does have the right to record the sales transaction data. But that was never under dispute even with GDPR. GDPR specifically says that you do not have the right to be forgotten in the information is important for legal compliance (e.g. tax records), free speech, and a couple of other things. https://ico.org.uk/for-organisations/guide-to-the-general-da... See “when does [it] not apply?” GDPR alr…

> GDPR already applies to governments. What makes you think it is not?

It doesnt apply to security-related services, and the governements are allowed to override it for most purposes as outlined in article https://gdpr-info.eu/art-23-gdpr/

Post reply on HN