Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

261–270 of 534 posts

Re: Shutting Down Forum (GDPR)

#262
post #253

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

If they thought they were likely to receive a lot of these they'd probably shut down.

Not necessarily. Often, receiving your first request is by far the most expensive. You need to hire a lawyer, come up with a response plan, and educate employees on how to handle them. The second, third, and hundredth request is likely far less expensive or time consuming to deal with.

Re: Shutting Down Forum (GDPR)

#263
post #255

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Nonsense - they are shutting down because they actually received GDPR requests. They have not received any NSA letters, DMCA requests, and I don't think moderating forums by deleting posts could ever be construed as being as strenuous as trying to comply with the most comprehensive internet privacy law ever written.

Deleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the posts, that can be dealt with like any other moderation.

Re: Shutting Down Forum (GDPR)

#264
post #248

Earlier quoted context omitted.

Are you implying that free services like Facebook should be exempt from privacy laws like GDPR?

Well if you know that Facebook is bad, why did people even register in the first place? Or put their whole life onto it? It's ok if the privacy law only gone against stuff like analytics or horrible facebook buttons that even collected stuffs from people who clearly weren't users. i.e. tracking especially tracking outside their "domain" however GDPR goes against all and anything. I mean if I go to a supermarkt I can'…

I never registered on facebook because I knew. People who don't know or don't care is different, then there are other psychology explanation and network effect.

Your example is deeply misrepresenting the GDPR, seems like FUD to me. GDPR applies outside the internet, GDPR is very limited in scope as it kept the "legitimate interests" exemption from the 1995 directive.

Can you substantiate your claim that GDPR was made by people who do not understand what they do ?

Re: Shutting Down Forum (GDPR)

#265

I'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.

> No lawyers required. Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.

in the EU you cannot get huge amount of money out of nothing, fines are limited to the extent of the damage. So basically much less legal action in the EU and needs for lawyers.

Bigger companies do have legal teams, but smaller one can operate without ever needing a lawyer.

Re: Shutting Down Forum (GDPR)

#266
post #212
post #203

Earlier quoted context omitted.

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

On HN I can go to my user profile and see all comments/posts I've made. And I can delete them all. I strongly suspect this sufficient. Maybe it would be ideal to offer a "delete account" and "download account" button. But there is no reason you should be processing letters from people. I'm not even sure you need to offer removal of public information. But allowing deletions of accounts is hardly controversial.

Also it would be a good idea not to keep IP addresses forever. Two weeks retention is enough to detect mass registration.

Re: Shutting Down Forum (GDPR)

#267

From the prototype letter: "I am a customer of yours." Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.

Even if you pay someone, nothing except GDPR stops them from reselling your data for extra profit.

Re: Shutting Down Forum (GDPR)

#268

Earlier quoted context omitted.

Same for GDPR, you just respond to the users with "I don't collect anything on my website". Now if you collect and track you may want to inform the users and let them opt-out. GDPR is similar in a way with the Don't spam me laws, I assume you had to write code to respect this law and I did not see people complaining that they need to write code to respect that law. Or you can not do business with EU citizens.

You haven't read it, i presume. The implementation requires a lot more than that.

The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website".

Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.

Re: Shutting Down Forum (GDPR)

#269
post #212
post #203

Earlier quoted context omitted.

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

On HN I can go to my user profile and see all comments/posts I've made. And I can delete them all. I strongly suspect this sufficient. Maybe it would be ideal to offer a "delete account" and "download account" button. But there is no reason you should be processing letters from people. I'm not even sure you need to offer removal of public information. But allowing deletions of accounts is hardly controversial.

> And I can delete them all.

How? I can only delete for a small amount of time after posting. I cannot delete any of my past comments. If there is an option to remove old(er) comments I would sure like to know about it, seems to be hidden pretty well.

Post reply on HN