Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

361–370 of 534 posts

Re: Shutting Down Forum (GDPR)

#361

From the prototype letter: "I am a customer of yours." Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.

Are you implying that free services like Facebook should be exempt from privacy laws like GDPR?

Not at all. If you don't pay me, you're a guest, not a customer. Should guests have rights too? Of course! But guest rights are very different than customer rights. Hosts should be held to a certain standard, and if they fail to meet that standard then they should expect to hear from regulators. What makes GDPR noxious is that it turns every individual interaction with the host into its own little mini-lawsuit, creating a potentially infinite burden and liability. It's actually an approach I usually think of as typically American, usually coming from the "don't need regulators because everything can be a tort" libertarians. For it to come from Europe is almost ironic.

In any case it's the wrong way to address the problem, and its ill effects are seen in cases like this. It's actually easier for "free services like Facebook" to comply because they can hire full-time compliance staff. The worst effects fall on smaller sites and individuals, making them less able to compete - individually or collectively - with the entrenched big sites. Some have even painted it as a form of regulatory capture, though I think that's a bit of a stretch.

Re: Shutting Down Forum (GDPR)

#362
post #208

Earlier quoted context omitted.

They're shutting down because they're privacy-ignorant and that doesn't fly in the EU any more. People apparently have a hard enough time understanding invisible things such as privacy, but this goes double for those whose income depends on violating the privacy of everyone.

Can you provide examples of websites shutting down due to GDPR ?

http://gdprcasualties.com

Re: Shutting Down Forum (GDPR)

#363
post #33

I don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests.

What websites are shutting down ? I have not heard of anything like this yet.

http://gdprcasualties.com

Re: Shutting Down Forum (GDPR)

#364

Earlier quoted context omitted.

If youve ever dealt with the uk ico youll know its true. They refuse to do anything about individual complaints. The gdpr also states that samctions will be determinedby the gravity of the violation and number of users affected, among other factors. Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.

So what you're saying is that all the small businesses feverishly seeking to comply with GDPR are wasting their time, because actually the law doesn't apply to them?

If they are not in the EU and not doing anything out of the ordinary then yes.

Life is full of risk and the GDPR is right down towards the bottom of things to worry about at this point if you are outside the EU. I suspect this is also the case if you are inside the EU too, but we will soon know.

Re: Shutting Down Forum (GDPR)

#365

Earlier quoted context omitted.

Are you implying that free services like Facebook should be exempt from privacy laws like GDPR?

Not at all. If you don't pay me, you're a guest , not a customer. Should guests have rights too? Of course! But guest rights are very different than customer rights. Hosts should be held to a certain standard, and if they fail to meet that standard then they should expect to hear from regulators. What makes GDPR noxious is that it turns every individual interaction with the host into its own little mini-lawsuit, crea…

> What makes GDPR noxious is that it turns every individual interaction with the host into its own little mini-lawsuit,

No, it really doesn't.

In Europe action for civil torts is limited to what you've actually lost. There are no punitive civil claims. Courts are a method to get back to how you were, they're not a route to betterment.

And GDPR is not enforced by each victim of a breach taking civil action through the courts, but by victims reporting to the regulator and allowing the regulator to take action.

The reason people in Europe seem so blasé about this is because we've had decades of experience with regulation, and we know that they don't have many teeth, and tend not to use the teeth they do have.

GDPR isn't changing this.

Re: Shutting Down Forum (GDPR)

#366
post #354

Earlier quoted context omitted.

>If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited. So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor

> 25 third parties that know what you visited Ever try running traceroute ?

How is that relevant here? You mean that when I connect to A there will be some intermediate points, that is true but those points are not setup there to track me, some points will differ, there are protocols to work around tracking at that level(using proxies and VPNs). But if I don't block the tracking scripts and cookies and I have 2 tabs with 2 different sites and both have FB code in it, FB will know I am the same person, they will search in the shadow profiles, find me, add this extra data to the profile. Then 24 more trackers will do the same,

Re: Shutting Down Forum (GDPR)

#367
post #248

Earlier quoted context omitted.

Are you implying that free services like Facebook should be exempt from privacy laws like GDPR?

Well if you know that Facebook is bad, why did people even register in the first place? Or put their whole life onto it? It's ok if the privacy law only gone against stuff like analytics or horrible facebook buttons that even collected stuffs from people who clearly weren't users. i.e. tracking especially tracking outside their "domain" however GDPR goes against all and anything. I mean if I go to a supermarkt I can'…

GDPR isn't limited to the Internet. It includes most automated processing.

https://gdpr-info.eu/art-2-gdpr/

> This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

Re: Shutting Down Forum (GDPR)

#368

Earlier quoted context omitted.

I can't comment on the effectiveness of GDPR on the large data farmers such as Facebook and Google. However, I think that the alternative that you are proposing for lawmakers to go specifically after the current infringers of privacy would set a scary precedent. We shouldn't have specific corporations operating under a different set of laws than the rest of society, as that would undermine the rule of law.

We should handle companies that have >1M data records differently from smaller companies. Most countries handle private persons with larger income differently, e.g. they need to pay more income tax. Most countries handle startups differently, e.g. they don't need to pay taxes in the first years. Most countries handle farms differently than other corps, e.g. they give subsidies to them. Most countries handle people wi…

> We should handle companies that have >1M data records differently from smaller companies.

What makes you think we don’t already do that? GDPR is about privacy 101; there’s nothing in it that shouldn’t apply to small companies.

Do we allow small restaurants to poison their clients because they’re just starting and you-know-it’s-hard-to-build-a-restaurant-so-let’s-wait-a-bit-before-applying-regulation? Of course no.

Re: Shutting Down Forum (GDPR)

#369

Earlier quoted context omitted.

COPPA is frightening to web operators, at least in the abstract. The majority of web services online at least make a cursory effort to either ban users under the age of 13 from accessing the site or force them to give parental consent. Technically speaking, if you're under 13 you're not really supposed to be on sites like Twitter. The equivalent reaction for GDPR would be if everyone either started making half-hearte…

> ..started making half-hearted efforts to block European users (which isn't what EU wants.. Are we sure about that? GDPR seems like a gift to European startups who don’t like American competition. BlaBlah car in France got huge, incidentally right around the time the anti-Uber hysteria in France reaches a peak. The sale of Daily Motion to Yahoo was blocked by the French government under ridiculous national economic…

Let's look at the timeline to check your claim about blablacar vs Uber:

blablacar exists since 2004, it was first covoiturage.fr and had became the market leader in France in 2008, in 2009 the began opening services in foreign countries, in 2011 the bought main competitor which started in 1997 and are confident that their market domination allow them to pivot from free to taking a 20% commission.

january 2012, Uber launches in France.

in 2013 they change their name to blablacar so it's the same name in the 10 coutries they operate, uber grows to operate in two cities in France.

2014: uber grows to 6 cities in France, blablacar adds ukraine, russia, brazil and gets 100 millions funding to tackle world market and now transports 1 million people per month.

2015: france his 2nd biggest market for uber in Europe with over 500k users per year, blablacar buy German competitor Carpooling, Hungarian competitor AutoHop and Mexican sart-up Rides now totalling 20 millions users in 19 countries and rises 200 millions to speed up world market deployment. UberPop is forced to suspend operation due to operating illegally by evading legal obligations.

2017: uber still operates illegally without a licence and European Court confirms the UberPop suspension while also confirming that Uber is a transportation company and has to follow laws and regulations.

As we can see here, by the time Uber arrived in France, blablacar had already seized the french market for quite some time, blablacar operates lawfully while uber evades legal obligations and kept at it despite repeated warnings which is probably the reason why it got into trouble.

And this is coming from someone who strongly dislike blablacar.

Then again if US tech companies paid their taxes instead of engaging in heavy tax evasion (hello apple, facebook, amazon, google, ...), and respected local laws maybe they would not get so much flak.

Re: Shutting Down Forum (GDPR)

#370
post #48

Earlier quoted context omitted.

There are litigious people even here, though. Someone who has an axe to grind for whatever reason can keep annoying the DPA until they do go after you.

No, that simply doesnt happen. Ive annoyed the ico in the uk many times and they refuse to do anything for one complaint. I recently got a 500gbp out of court settlement in a spam lawsuit that the ico did fuck all about.

> that the ico did fuck all about.

I think this is the really important bit that Americans are missing.

We've had decades of regulation from ICO, and we've seen them do fuck all about a lot of stuff. GDPR isn't going to change their approach.

Post reply on HN