Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

321–330 of 534 posts

Re: Shutting Down Forum (GDPR)

#321

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

> Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA. Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single…

Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data.

The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.

I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual legal threats and action. This just allows requests.

The DMCA helps big business at the expense of the general public. This does the reverse. It's no wonder there's been so much noise and scaremongering.

Re: Shutting Down Forum (GDPR)

#322
post #33

I don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests.

Even before GDPR, one could receive a DMCA request, an US court order, a letter from FBI, a letter from NSA. It didn't prevent people from creating websites though. GDPR requests are definitely less scary than a letter from NSA or an US court order: nobody will put you into jail for non-compliance, kidnap you or send a drone to you.

> nobody will put you into jail for non-compliance

ha

> kidnap you or send a drone to you

thank you for making it obvious you are arguing in bad faith. Hint: you are more likely to be fined 20 million Euros for violating GDPR than having a drone sent after you for ignoring a DMCA request.

If you actually believe you will have a drone sent after you for violating DMCA or ignoring a letter from the NSA go see a psychiatrist.

Re: Shutting Down Forum (GDPR)

#323

Earlier quoted context omitted.

So you admit that GDPR is really just a trade barrier.

How can it be a trade barrier when EU companies are more affected by it? (They have to provide these protections for everyone, whereas non-EU companies only have to provide them for people in the EU).

You just answered your own question. The cost of compliance is largely a fixed cost. So if only 50% of my users come from the EU, then my per-user costs are 2x what an EU-centric company's would be. So it skews the economics in favor of blocking the EU if your business is not EU-centric. This in turn means users are pushed to EU companies that have no choice but to comply.

Re: Shutting Down Forum (GDPR)

#324

Earlier quoted context omitted.

> Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA. Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single…

Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual lega…

>Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data.

Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented.

>The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.

Did I ever bring up litigation? What is your point here?

Re: Shutting Down Forum (GDPR)

#325

Earlier quoted context omitted.

Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual lega…

>Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented. >The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overrea…

You brought up it targeting non-European business. That was the main way it seems to have disproportionately affected them.

Re: Shutting Down Forum (GDPR)

#326

Earlier quoted context omitted.

There's a button to download the user's data on their profile page. You can direct them to that. There's also a function to anonimise a user, which scrubs records of IP addresses and usernames.

Are you talking about Disqus specific features? Because that is really beside the point and the fact that you are bringing it up shows how clueless you GDPR zealots actually are.

What's Disqus got to do with it? The fact you are bringing it up does you've no interest in the facts of this case. This is about a forum, which uses Discourse, which has these features. This is totally relevant.

Re: Shutting Down Forum (GDPR)

#328

Earlier quoted context omitted.

>Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented. >The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overrea…

You brought up it targeting non-European business. That was the main way it seems to have disproportionately affected them.

How about you try answering this question I posed to you

What is your point here? What is your point when you say that the EU is not litigious? Are you saying that I shouldn't expect to receive a fine for violating GDPR? Are you saying that I should just ignore GDPR data access requests if I am operating in a supposedly ethical manner and I am not selling user information?

Re: Shutting Down Forum (GDPR)

#329
post #320
post #203

Earlier quoted context omitted.

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

It's not clear that a forum administrator would need to do anything under the GDPR except respond to emails with the standard template: "The forum does not collect or process any personal data." Technically, I suspect, this would be true. The GDPR and the right to be forgotten are subtle on this. If a user chooses, unprompted, to share PII it's not clear that collection has taken place. Imagine a user, out of the blu…

Usernames can be identifying, as could other profile information. IP addresses in server logs. Those are easily under your control, and you should mention those as things you process, but also are easy to justify assuming you don't do anything weird with them.

Re: Shutting Down Forum (GDPR)

#330
post #18
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

From one of his responses in the link "I do appreciate the links. The gdpr documentation is quite long and I lack the domain expertise to read and comprehend the document in full. Perhaps this is cultural, since the United States is a very litigious society, but I would not feel comfortable accepting liability for gdpr compliance without consulting an attorney. It is also unclear how I am expected to respond to DPA e…

> The gdpr documentation is quite long and I lack the domain expertise to read and comprehend the document in full.

As if he read all laws of his own country that apply to him. Raise your hand if you actually read and comprehend all laws that apply to you. I'm willing to bet there's not a single person on this planet who really reads and comprehends all laws completely.

Usually you just go with common sense and reading a blog post or two when it seems relevant: that usually makes compliant and in the worst case it will get you a warning from the regulator (they give warnings for unintentional first-time violations, so they'll tell you if you're doing wrong and it bothers them enough (usually you're too small anyway), and you get a chance to improve).

Post reply on HN