From the prototype letter: "I am a customer of yours." Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.
Shutting Down Forum (GDPR)
211–220 of 534 posts
Re: Shutting Down Forum (GDPR)
#212How can it be hard for a forum to comply to GDPR? What kind of private information does it really need to save?
I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…
I strongly suspect this sufficient. Maybe it would be ideal to offer a "delete account" and "download account" button.
But there is no reason you should be processing letters from people.
I'm not even sure you need to offer removal of public information. But allowing deletions of accounts is hardly controversial.
Re: Shutting Down Forum (GDPR)
#213Earlier quoted context omitted.
You want a scary precedent ? look at DMCA and it's been used to intimidate and bully all over the world and outside US jurisdiction (the pirate bay case showed that US government outreach went to threat of economic sanctions to a foreign government). The GDPR is probably not what you think is, because it barely introduces new stuff, it only enforces what already existed but was ignored because it was based on self-re…
by comparison, you literally don't need to do anything to implement DMCA, except perhaps respond to emails. (I wonder why this is contestable? DMCA is an afterthought, GDPR requires a lot of actual work to implement even if you process minimal data like IPs)
Now if you collect and track you may want to inform the users and let them opt-out.
GDPR is similar in a way with the Don't spam me laws, I assume you had to write code to respect this law and I did not see people complaining that they need to write code to respect that law. Or you can not do business with EU citizens.
Re: Shutting Down Forum (GDPR)
#214Earlier quoted context omitted.
COPPA is frightening to web operators, at least in the abstract. The majority of web services online at least make a cursory effort to either ban users under the age of 13 from accessing the site or force them to give parental consent. Technically speaking, if you're under 13 you're not really supposed to be on sites like Twitter. The equivalent reaction for GDPR would be if everyone either started making half-hearte…
> ..started making half-hearted efforts to block European users (which isn't what EU wants.. Are we sure about that? GDPR seems like a gift to European startups who don’t like American competition. BlaBlah car in France got huge, incidentally right around the time the anti-Uber hysteria in France reaches a peak. The sale of Daily Motion to Yahoo was blocked by the French government under ridiculous national economic…
Otherwise the only person that seems to be "foaming a the mouth" is you, in this ridiculous Murica rant.
Do I need to remind you that your country is just starting an economic war on the rest of the world with illegal customs taxes ? Also, enjoy getting scammed by your own ISPs now that net neutrality effectively got cancelled on you.
You don't realize how little Europeans care about your precious American tech companies, and more about values such as not being the data points of international megacorps with shady business practices, or low-end programmers ready to milk people of all their data just to install a phone game.
Re: Shutting Down Forum (GDPR)
#215I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…
I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited.
So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor
Re: Shutting Down Forum (GDPR)
#216Earlier quoted context omitted.
> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. sensible regulation that defines workable limits of what personal information can be collected, combined with requirements for anonymization when needed is a better solution.
Some of the early results we are seeing from GDPR make one question how ‘sensible’ it really is.
GDPR is also quite weak in this regard as it has few new additions: explicit consent (thanks to snowden exposing prism and despite the largest lobbying campaign against it orchestrated by silicon valley[1]), max possible fine increased so actor like google and facebook would stop paying 150,000€ fines right and left while laughing in the face of European laws, and class actions.
Again it's only thanks to snowden revelations that the GDPR weakening personal data protection was overturned.
The real change that matters is that now the law can and will apply.
Re: Shutting Down Forum (GDPR)
#217Earlier quoted context omitted.
> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. sensible regulation that defines workable limits of what personal information can be collected, combined with requirements for anonymization when needed is a better solution.
Some of the early results we are seeing from GDPR make one question how ‘sensible’ it really is.
In this case the operator's usage of the word troll to describe what happened is telling. Anyone can send any kind of threatening letter they want, and they are free to report you for non-compliance, but that doesn't mean any action will be taken against you, let alone actual fines.
IANAL, but IMHO the chances of any solo forum operator being sanctioned by EU regulators is effectively nil—the purpose of the law is specifically to address usage of personal data, not old-school off-the-shelf forums and other one-off websites where the scope of the data is essentially the core of the service itself.
You can argue the only thing that matters is the end result, but I'm not sure there's any way to write meaningful privacy regulation that will not generate a huge wave of FUD, especially with the traditional SV stance that we ought by default to have carte blanche to monetize user data in any way that's effective.
Re: Shutting Down Forum (GDPR)
#218I'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.
> No lawyers required. Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.
It's like you're driving too fast on the highway, but if it's just you mom complaining and not a police officer you won't get fined :)
- that said, we should all respect the speed limit, they are there for a reason.
Re: Shutting Down Forum (GDPR)
#219I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…
And you're very likely using the services of one of the big players, like Google, the very ones you're suggesting should be explicitly targeted in another message below.
Like I said before, including to you: the EU does not owe companies a business model, especially when the costs of that business are externalized to citizens of the EU and of the world.
Your so-called alternative at the end is just more of the arrogant snubbing typical of the advertising industry.
Re: Shutting Down Forum (GDPR)
#220Earlier quoted context omitted.
If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future
So you admit that GDPR is really just a trade barrier.
The 4% of worldwide revenue fine potential is exclusively targeted at the US tech giants. By my last count, the US has roughly 100 tech companies worth over $10 billion each (with trillions of dollars in worldwide revenue). Nobody taxes revenue, that's about the most moronic thing you can possibly do - unless you're doing it to try to harm / punish companies. Very few EU tech companies have meaningful worldwide revenue to tax.