Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

371–380 of 534 posts

Re: Shutting Down Forum (GDPR)

#371
post #289

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

> no one knows what a typical fine looks like

The EU has had data protection law for twenty years. The EU has enshrined proportionality of penalty in all EU law as a fundamental right. There is plenty of case law at the CJEU defining this.

All you need do is read the FAQs that EU ICO's have been putting up. The UK has never, in 20 years, applied the full penalty of the previous DPD, and under 0.1% of all reports got any fine at all.

A "typical" penalty will be help to comply. Perhaps a strongly worded letter.

Re: Shutting Down Forum (GDPR)

#372
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

As someone who ran a forum centered around one of my passions, I was happy to help users out with small adminstrative tasks. Like you said, no big deal. Now if I was legally required to act on every request in 30 days or face potential litigation, that's a totally different story. I'm doing something that's a fun hobby of mine for free that will benefit others with similar interests. The line is drawn when it can hav…

> act on every request in 30 days or face potential litigation

That's not what happens though. You get a request, you have 30 days to respond to it (and for the vast majority the privacy policy is ok as a response) and if the requester isn't happy they report it to the regulator who writes for more information. In that situation you again send off your privacy policy, maybe with a bit more detail.

The regulator either tells you that you're wrong, and explains why, and gives you advice to come back into compliance, or agrees with you and tells the requestor that they've misunderstood the law.

And all of this has provisions for proportionality. The regulators will recognise that small forums run for small projects will not have resources to respond to many requests.

Re: Shutting Down Forum (GDPR)

#373
post #214

Earlier quoted context omitted.

> ..started making half-hearted efforts to block European users (which isn't what EU wants.. Are we sure about that? GDPR seems like a gift to European startups who don’t like American competition. BlaBlah car in France got huge, incidentally right around the time the anti-Uber hysteria in France reaches a peak. The sale of Daily Motion to Yahoo was blocked by the French government under ridiculous national economic…

BlaBlaCar is about carpooling, it is not a Uber ripoff, but you'd know that if you had travelled once to Europe. It is about different values - solidarity, ecology, social relationships - than just underpaying the guy-next-door to do anything you're willing to pay for with your smartphone. Otherwise the only person that seems to be "foaming a the mouth" is you, in this ridiculous Murica rant. Do I need to remind you…

I have to point out that blablacar is not about solidarity, ecology or social relationships, to the contrary actually, it's about being a vampire draining money from solidarity and ecology and market domination.

I mean carpooling was about solidarity and ecology, then blablacar seized the market and turned it into "no mobile phone, no credit card, no access to carpooling", "give us money first". I used to carpool before blablacar and many times I did not ask that much money or even no money at all, sometimes I got barter out of carpooling. Or the other way around, people enjoyed my company and refused my money. Now this social link is over because everybody is using blablacar and blablacar requires expensive upfront payment.

I hate how blablacar turned something that was about helping each other and bringing people together into a capitalist profit making venture aiming for world market domination.

Re: Shutting Down Forum (GDPR)

#374

Earlier quoted context omitted.

A lot of the US over reaction to the GDPR probably stems from the fact that they assume that Europe has a system where parties sue each other, the jury system, as opposed to the state suing parties, the inquisitorial system. Getting sued in Europe is a huge deal, getting sued in the US is part of doing business.

Yeah from what I have heard the main reason for this law is to stop obvious abuses to people's privacy. It seems that most overreactions are due to ignorance of the system behind the law or to make some kind of political statement.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

Re: Shutting Down Forum (GDPR)

#375
post #355
post #353

Earlier quoted context omitted.

Can’t square this comment with the long front page discussion just a couple days ago about whether ref’ing a Google font could violate GDPR. Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.

The problem there is that you can't just say "no tracking", you have to be able to argue that there really is no tracking. If you put in content from a third party and have no legal promise by them that they don't track, you can't know if your users are tracked or not.

Then just put that in your privacy policy and you are off the hook.

If Google tracks something, whether it is via their fonts, by putting some cookie on your site or whatever, it is their problem (and they actually said so, in that Github post referring to the font issue). They are the ones collecting and processing the data, not you, so they will have to deal with the GDPR compliance.

Re: Shutting Down Forum (GDPR)

#376
post #152

Earlier quoted context omitted.

Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.

Even in the worst case scenario you have the option of going out of business and filing for bankrupcy if you are incorporated in the EU and do get hit by a 20M fine. The EU can certainly try to take that amount from the company, but if it's a Ltd. or Gmbh. or equivalent its liability is limited by its shares. Or you can incorporate outside of the EU (Guernsey or soon enough the UK perhaps?) and ignore the GDPR. At wh…

The only way to get hit by a 20M fine is to do something really wrong on a very large scale and ignoring warnings and refusing to fix it.

Re: Shutting Down Forum (GDPR)

#377

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

Honestly, that sounds like the most sensible advice. If I run a small US-based business and I receive one of these letters, I'm almost certainly just going to ignore it--as I'm sure many are already doing. It's not like I'm ignoring an official government notice. It's just an email from someone random making an assertion/request.

Maybe I put a notice up and geofence EU IP addresses but it seems that would just raise my visibility and suggest that I think I'm doing something wrong (whether or not I am).

At the least I'd wait for some indication that a random US ecommerce site (or whatever) actually has something to worry about.

Re: Shutting Down Forum (GDPR)

#378
post #375
post #355

Earlier quoted context omitted.

The problem there is that you can't just say "no tracking", you have to be able to argue that there really is no tracking. If you put in content from a third party and have no legal promise by them that they don't track, you can't know if your users are tracked or not.

Then just put that in your privacy policy and you are off the hook. If Google tracks something, whether it is via their fonts, by putting some cookie on your site or whatever, it is their problem (and they actually said so, in that Github post referring to the font issue). They are the ones collecting and processing the data, not you, so they will have to deal with the GDPR compliance.

That's their interpretation, and they don't face consequences if it's wrong. Since I've gotten advice to the contrary from lawyers looking into GDPR, I won't trust it until there's clear feedback from regulators or courts about it. Fonts are easy enough to self-host.

Re: Shutting Down Forum (GDPR)

#379
post #144
post #68

Earlier quoted context omitted.

> But if they then said that I need to remove _all of their posts_, that's really shitty. Why do you think GDPR forces forum owners to delete posts? Which bit of GDPR do you think introduces this requirement?

In order to reply to your questions, the mark would have to study the GDPR one way or the other to answer them. That by itself is way too much hassle.

It would certainly be interesting to quantify how much money has been spent just trying to understand it

Re: Shutting Down Forum (GDPR)

#380

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

> Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA. Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single…

> Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA.

People send fake DCMA takedowns all the time.

If someone sends you a GDPR data request, you can ask for administrative costs. You can even ask it to be mailed to you via post. If someone sends you a bogus and unreasonable GDPR data request, you can ask them to pay you a further reasonable fee.

This can almost be an auto-response. Trolls will get bored.

> Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development.

This is not true. Recital 62[1] says you don't have to give them any data they already have, and Recital 57[2] says you aren't obliged to determine which of your data identifies them if you aren't going to do it anyway.

[1]: http://www.privacy-regulation.eu/en/recital-62-GDPR.htm

[2]: http://www.privacy-regulation.eu/en/recital-57-GDPR.htm

> I agree however that they are both horrible laws.

I like the GDPR a great deal, and I think it'll be good for companies big and small in the long run. Disclaimer though: I'm doing some GDPR consulting, so you might prefer to think I'm getting paid to like the GDPR.

The scary bit seems to be for companies that approach compliance from the point-of-view of centralising understanding, and minimising the impact and costs of that compliance. They're looking for someone to tell them "this is enough effort", but the point is that Europeans don't want people playing chicken with their data[3].

As soon as companies realise that embracing the spirit of the GDPR is cheaper, it starts becoming a real opportunity for them.

[3]: https://www.sec.gov/Archives/edgar/data/33185/00011931251815...

Post reply on HN