Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

291–300 of 534 posts

Re: Shutting Down Forum (GDPR)

#291
post #245

Earlier quoted context omitted.

It doesn't have to be lawyered.

Excuse me? How in the world am I supposed to know if it is sufficient for GDPR without a lawyer?

The context is a small forum that doesn't gather much user data and doesn't do weird things with it.

The forum owner should create a simple privacy policy that details what information is gathered; why it's gathered; how long it's kept; and how to correct mistakes.

If someone does report the forum to the regulator all that'll happen is that a letter will be written asking the forum to come back into compliance, and giving advice about doing so.

GDPR makes many references to proportionality. It also mentions standard practice.

EG here: https://gdpr-info.eu/art-24-gdpr/

> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.

> Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.

> Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.

Re: Shutting Down Forum (GDPR)

#292

Earlier quoted context omitted.

So you admit that GDPR is really just a trade barrier.

GDPR - the core of it - is about privacy, it's an increment on prior laws in EU countries. It's also in part a response to the data hungry US tech companies, without question. The 4% of worldwide revenue fine potential is exclusively targeted at the US tech giants. By my last count, the US has roughly 100 tech companies worth over $10 billion each (with trillions of dollars in worldwide revenue). Nobody taxes revenue…

[deleted]

Re: Shutting Down Forum (GDPR)

#293
post #96

Earlier quoted context omitted.

The response to the GDPR seems to me to be a bunch of people who fundamentally misunderstand how law works, especially in Europe, and who have a pathological relationship to regulators because their own legal system is fucked beyond all recognition. GDPR requires you to only gather the data you need; only keep it for as long as you need it; tell people what you're doing with it; and allow them to correct it if it's w…

... and document every instance of processing, as well as the legal basis for processing for each use of each piece of data, and how you decided that legal basis (and if you used "legitimate interest," you need to do a LIA -- the template I use is several pages before you enter the information). Then you have to negotiate different DPA terms with a dozen clients whose privacy lawyers told them they each need a differ…

> and document every instance of processing, as well as the legal basis for processing for each use of each piece of data, and how you decided that legal basis

But only if that's proportionate.

https://gdpr-info.eu/art-24-gdpr/

> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.

> Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.

Re: Shutting Down Forum (GDPR)

#294
post #289

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

I don't find this: https://www.aclu.org/other/text-digital-millennium-copyright... much easier to read than this: https://gdpr-info.eu/

Re: Shutting Down Forum (GDPR)

#295

Earlier quoted context omitted.

So you admit that GDPR is really just a trade barrier.

GDPR - the core of it - is about privacy, it's an increment on prior laws in EU countries. It's also in part a response to the data hungry US tech companies, without question. The 4% of worldwide revenue fine potential is exclusively targeted at the US tech giants. By my last count, the US has roughly 100 tech companies worth over $10 billion each (with trillions of dollars in worldwide revenue). Nobody taxes revenue…

Of course they're trying to harm companies when they fine them. That's implicit in the term "fine".

They target revenue because otherwise companies will just use Hollywood accounting to declare they make 0% profit, they just pay huge licensing fees to some cayman island company.

Re: Shutting Down Forum (GDPR)

#296
post #93

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

What you are saying is: don't use the internet. Google, Facebook, Twitter, etc. got websites to implement their like buttons everywhere. The information gathered by them is collected and everybody is being tracked wherever they go.

You can neuter the like button, thanks to tools like Privacy Badger.

Re: Shutting Down Forum (GDPR)

#297

Earlier quoted context omitted.

Do you believe that hobbyists must not follow laws & regulations when they interact with the public?

Private and general aviation have a different set of regulations. Small and large aircraft have a different set if regulations. I’ll let you figure out the rest.

GDPR is not applicaple to personal or household activities

https://gdpr-info.eu/recitals/no-18/

> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.

Re: Shutting Down Forum (GDPR)

#298
The GDPR does not apply if it is for personal use or for a hobby only. I don’t know how the structure of this forum is set up, but this can be a good reason to run such forums on your personal name.

Re: Shutting Down Forum (GDPR)

#299
post #289

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

Its predecessor regulation capped fines at around $750k. Guess how many were levied at or near the maximum? Zero. The only large fines were for serious, deliberate abuses, such as a group maintaining a secret blacklist of construction employees. This isn't like the massive fines from US regulators on foreign companies. The rules say that fines should be proportionate to the scale of the breach and the harm caused. The large fines are for serious, deliberate, repeat offenders. It's also to stop a company like Google deciding that they'd rather not comply, and treat a fine as a cost of business.

Re: Shutting Down Forum (GDPR)

#300

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

But I wonder if he would receive a US court order would he treat it the same way?

Court orders take a comparative mountain of effort before they land on someone’s doorstep. They require someone to determine that there is a legitimate cause of action against the site, consult their attorneys/legal department as to the best course of action, research the case and produce enough evidence of their claims to hopefully convince a judge to give them the order they seek, then prepare and file the legal paperwork. In most cases, by the time such an order is issued, several people have invested dozens or hundreds of hours in the effort.

By contrast, sending a “nightmare letter” is a matter of copying and pasting, which can be done by anyone in just a few seconds. Even a small site like the one at issue here could easily receive hundreds or thousands of such requests per year that the owner is obligated to produce detailed responses to, under the threat of enormous fines.

This regulation was written in a way that made it ripe for abuse. We are seeing real-world abuse now, and we are barely a week into it. Shutting down and/or at least blocking EU traffic is entirely reasonable in light of the situation that GDPR has created.

Post reply on HN