Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

281–290 of 534 posts

Re: Shutting Down Forum (GDPR)

#281
post #195

Earlier quoted context omitted.

Do you believe that hobbyists must not follow laws & regulations when they interact with the public?

Do you believe that anyone who has a hobby website with a forum needs an official privacy document, presumably vetted by a lawyer.

Why do you think the document needs to be vetted by a lawyer?

The regulation makes repeated reference to proportionality.

> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.

For a simple forum this is a simple privacy policy.

And forums should already have something like this if they're complying with EG US COPPA or similar.

Re: Shutting Down Forum (GDPR)

#282

Earlier quoted context omitted.

The owner of the forum received the "Nightmare letter" [1] which he is legally obligated to respond to, which as an open source project does not have the resources to be able to respond to them. [1]: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

To answer that letter takes maybe 5 minutes for a simple forum operator.

I host a standard FluxBB forum on a stock Debian apache server. Can you please spent 5 minutes to answer that letter for me?

Re: Shutting Down Forum (GDPR)

#283
post #76
post #5

Is it legal to publish the name of the requestor? Name and shame?

> The sad thing is that one email came from the co-founder of a Startup out of Germany. They should definitely name and shame them.

Having lived in Germany, "Co-founder of a Startup out of Germany" conjures up the image of one of the many economics-degree-holding bros who strut around and "network", bullshitting everyone (themselves included) that they're going to be the next Zuckerberg.

Then again, my remote impression is that Silicon Valley isn't that much different nowadays.

Re: Shutting Down Forum (GDPR)

#284
post #144
post #68

Earlier quoted context omitted.

> But if they then said that I need to remove _all of their posts_, that's really shitty. Why do you think GDPR forces forum owners to delete posts? Which bit of GDPR do you think introduces this requirement?

In order to reply to your questions, the mark would have to study the GDPR one way or the other to answer them. That by itself is way too much hassle.

Well, yes, if someone has no idea what's in GDPR they're probably going to be more fearful of all the bullshit being spread about it.

Re: Shutting Down Forum (GDPR)

#285

Earlier quoted context omitted.

Does that continue to be true if the US citizen goes to visit an EU country? It'd really suck to get arrested on your vacation because you ignored some troll's GDPR-based harassment. I don't know how this works.

If youve ever dealt with the uk ico youll know its true. They refuse to do anything about individual complaints. The gdpr also states that samctions will be determinedby the gravity of the violation and number of users affected, among other factors. Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.

So what you're saying is that all the small businesses feverishly seeking to comply with GDPR are wasting their time, because actually the law doesn't apply to them?

Re: Shutting Down Forum (GDPR)

#286

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

They aren’t attempting to enforce legislation globally. If a company operates in the EU, it has to comply. For companies that don’t operate in the EU and have no EU customers or traffic, they don’t. Simple

Even if said foreign companies have EU customers, what can the EU do about it? If I were a foreign company, I would completely ignore GDPR requests. Like > /dev/null, not even bother reading them.

This law will only make things (even) more expensive and cumbersome for EU companies wrt. the rest of the world. This is going to be the asinine Cookie Warning all over again, times a hundred.

Re: Shutting Down Forum (GDPR)

#288

Earlier quoted context omitted.

And GDPR doesnt help with that. I cannot send Facebook a request for my shadow profile, nor demand they delete all such data, as I have no way to ‘identify myself’ to them unless I have a Facebook account.

Yes there is. If your email address is in the contact list harvested by facebook when people register on the website, it is linked to your shadow profile and can be used to show the lack of explicit consent and existence of your shadow profile. It's the path currently explored in a class action against facebook for forced consent and we'll see what happens.

Does Facebook have EU offices? If they do, this law will simply make it close them. If they don't, what is the class action even being based on?

Re: Shutting Down Forum (GDPR)

#289

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down.

GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

Re: Shutting Down Forum (GDPR)

#290

Earlier quoted context omitted.

If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future

So you admit that GDPR is really just a trade barrier.

How can it be a trade barrier when EU companies are more affected by it? (They have to provide these protections for everyone, whereas non-EU companies only have to provide them for people in the EU).
Post reply on HN