Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

251–260 of 534 posts

Re: Shutting Down Forum (GDPR)

#251
post #86

Earlier quoted context omitted.

About 3 minutes. "Here's the privacy policy. Here's the data export page."

Haha data export page, what even is that? Let me just go to my SQL DB, redis, glacier backups, and Kafka logs and just click the data export button. It will only take 3 minutes.

There's a button to download the user's data on their profile page. You can direct them to that. There's also a function to anonimise a user, which scrubs records of IP addresses and usernames.

Re: Shutting Down Forum (GDPR)

#252

Earlier quoted context omitted.

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

The OP initially says if you’re small time they likely won’t target you. Are you really saying if you’re super small time, the EU is going to go after your payment processing? Of course anything is possible. It seems highly unlikely though. Then his/her last point is that they’ll give you a chance to correct things. Your post doesn’t seem to cover that either.

The way it's been done in the past, it usually starts by notifying you and giving you reasonable time (a month) to fix things then move up to sanctions.

But this is not a given every time and not everyone goes the nice route, some go directly to court. So when you are a small fish, you are better off doing your best to follow the GDPR in the first place than scrambling to avoid sanction in a limited time later. it is not that complicated to not collect data you don't need, ask before collecting it and informing about what you do with it.

Re: Shutting Down Forum (GDPR)

#253

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

If they thought they were likely to receive a lot of these they'd probably shut down.

Re: Shutting Down Forum (GDPR)

#254

Earlier quoted context omitted.

Same for GDPR, you just respond to the users with "I don't collect anything on my website". Now if you collect and track you may want to inform the users and let them opt-out. GDPR is similar in a way with the Don't spam me laws, I assume you had to write code to respect this law and I did not see people complaining that they need to write code to respect that law. Or you can not do business with EU citizens.

You haven't read it, i presume. The implementation requires a lot more than that.

No, because I am not a business owner so I am not interested in all the details, my interest is an internet user, I am fine with popups that allow me to opt out, I am also fine with websites that will block me(like the newspapers one) because I will find an alternative that does not track me.

I understand that you may have some small websites and you put on them who knows how many trackers/analytics and now is time consuming to go to those websites and implement something, but we needed this law the same as we needed the don't spam me law, it will take effort to fix existing sites but is for the best.

Re: Shutting Down Forum (GDPR)

#255

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Nonsense - they are shutting down because they actually received GDPR requests. They have not received any NSA letters, DMCA requests, and I don't think moderating forums by deleting posts could ever be construed as being as strenuous as trying to comply with the most comprehensive internet privacy law ever written.

Re: Shutting Down Forum (GDPR)

#256
post #176

Guy shuts down forum, goes through the nightmare letter dissecting each part as "good question" or "you should have this already" or "easy one". So what was his issue anyway?

Guys moves from discourse forum to subreddit for community discussion because he got a GDPR letter from a start up head or something.

links to what he thinks has been used to craft the letter he received.

Underlying issue is that guy does not have time to deal with GDPR and discourse does not offer the proper tools, so he went the easy route of outsourcing, but he overlooked that he's still probably still liable under GDPR.

Re: Shutting Down Forum (GDPR)

#257
post #219

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

You forgot to mention how this law hits your income quite hard, as you mentioned yourself a while ago: you're using internet advertising as supplemental income. And you're very likely using the services of one of the big players, like Google, the very ones you're suggesting should be explicitly targeted in another message below. Like I said before, including to you: the EU does not owe companies a business model, esp…

The costs are externalized yes but in many of these cases the person losing some privacy also benefits.

Re: Shutting Down Forum (GDPR)

#258

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action them would be to send a warning.

Re: Shutting Down Forum (GDPR)

#259
post #203

How can it be hard for a forum to comply to GDPR? What kind of private information does it really need to save?

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

Cannot he irreversibly delete user's data instead and send an empty file?

Re: Shutting Down Forum (GDPR)

#260

From the prototype letter: "I am a customer of yours." Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.

prototype letter comes from linkedin as a thought experiment:

https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

thing is if you require people to register to be able to buy from you they can be customer before actually paying anything.

Post reply on HN