Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

351–360 of 534 posts

Re: Shutting Down Forum (GDPR)

#351

Earlier quoted context omitted.

> they will target you through payment processors and ad networks How will they do that, and on what legal basis?

Garnishment. If the regulatory agency decides to fine you, and you don't successfully defend yourself against that in court, then you'll have to pay that fine. If you fail to pay the fine on time, any entities within the juristiction that owe you can be ordered to pay the fine instead (i.e., your payment processor will be ordered to redirect funds arriving for you to the state, which also, as far as their juristictio…

Sounds like a good reason to start only accepting crypto

Re: Shutting Down Forum (GDPR)

#352

Earlier quoted context omitted.

So you admit that GDPR is really just a trade barrier.

No it applies to any organization offering data services/web sites to EU residents, including authorities. GDPR is only a regulation stating more explicitly what you're required (and were always required) to do for compliance with EU privacy laws. It obviously was needed since privacy violation has become so blatant. The GDPR legislation has been a long time in the making. It might be the case that privacy in Europe…

> please also consider the US's total and utter failure to get their antitrust regulations in gear: Facebook buying WhatsApp, Google buying DoubleClick and YouTube, etc. At a certain point, others will have to react to that kind of government-sanctioned monopolization to protect their markets.

The European Union also green lit those acquisitions. Hence the fines against Facebook for essentially lying to the European Commission about the merger.

Re: Shutting Down Forum (GDPR)

#353

Earlier quoted context omitted.

You haven't read it, i presume. The implementation requires a lot more than that.

The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website". Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.

Can’t square this comment with the long front page discussion just a couple days ago about whether ref’ing a Google font could violate GDPR.

Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.

Re: Shutting Down Forum (GDPR)

#354

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

>If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited. So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor

> 25 third parties that know what you visited

Ever try running traceroute?

Re: Shutting Down Forum (GDPR)

#355
post #353

Earlier quoted context omitted.

The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website". Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.

Can’t square this comment with the long front page discussion just a couple days ago about whether ref’ing a Google font could violate GDPR. Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.

The problem there is that you can't just say "no tracking", you have to be able to argue that there really is no tracking. If you put in content from a third party and have no legal promise by them that they don't track, you can't know if your users are tracked or not.

Re: Shutting Down Forum (GDPR)

#356

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

Exactly. It is more likely that your office will burn down or you will get injured on the way to work than you will be targeted under the GPDR if you are outside the EU doing boring standard web things. Worrying about the GPDR as a non-EU company is like worrying about being struck by a meteor.

Re: Shutting Down Forum (GDPR)

#357

Earlier quoted context omitted.

How can it be a trade barrier when EU companies are more affected by it? (They have to provide these protections for everyone, whereas non-EU companies only have to provide them for people in the EU).

You just answered your own question. The cost of compliance is largely a fixed cost. So if only 50% of my users come from the EU, then my per-user costs are 2x what an EU-centric company's would be. So it skews the economics in favor of blocking the EU if your business is not EU-centric. This in turn means users are pushed to EU companies that have no choice but to comply.

But the cost is the same for both companies inside and outside of EU, so US companies "not being forced" just mean they have the luxury to decide whether EU customers/visitors are a concern to them - EU companies HAVE to do it, even if 95% of their userbase is in the US (but I think those US users will appreciate it still).

Imagine a law that forced all companies in the EU to be polite to their customers no matter what or face fines. In that case you could also say that users would be pushed towards EU companies because they were "forced" to be polite, but I think that would be deserved and US companies could just do the same. Similarly to GDPR, if one side is forced to treat my data with respect and actively have me consent, then I would chose them, law or no law.

Re: Shutting Down Forum (GDPR)

#358
post #255

Earlier quoted context omitted.

Nonsense - they are shutting down because they actually received GDPR requests. They have not received any NSA letters, DMCA requests, and I don't think moderating forums by deleting posts could ever be construed as being as strenuous as trying to comply with the most comprehensive internet privacy law ever written.

Deleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the post…

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts.

I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer sufficient protection for the forum operator.

And more generally, prior to GDPR, a person could casually put up a forum on a website and not have a meaningful legal compliance workload. GDPR changes that.

Re: Shutting Down Forum (GDPR)

#359

Earlier quoted context omitted.

You haven't read it, i presume. The implementation requires a lot more than that.

The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website". Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.

Perhaps a look here will help

https://www.reddit.com/r/gdpr/

Re: Shutting Down Forum (GDPR)

#360

Earlier quoted context omitted.

The point is to make companies stop misusing data. The fines are the teeth for if they don't stop.

So I should be afraid of litigation?

No. The only reason anybody will be fined is if:

a) They are doing the thing we have collectively decided is bad for society (misusing personal data)

b) Do nothing about this when somebody invokes one of their new legal rights, whether that be to retrieve the data you have on them or remove the data you no longer have a grounds under any of the six legal basises to store (which includes 'consent', which can be revoked, as well as five other bases which cannot be revoked but have more limited scope with what you can do with the data)

c) Be reported for this

d) Refuse to work with the compliance group

At this point, judging by how the EU has historically used fines as an enforcement mechanism, you're looking at a small fine designed as a wakeup call. The 20 million EUR figure (or % of revenue) is a _cap_, not a floor, and the EU has never gone for maximum fines except when it is obviously required to enforce compliance.

Post reply on HN