Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

381–390 of 534 posts

Re: Shutting Down Forum (GDPR)

#381
post #374

Earlier quoted context omitted.

Yeah from what I have heard the main reason for this law is to stop obvious abuses to people's privacy. It seems that most overreactions are due to ignorance of the system behind the law or to make some kind of political statement.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

Incorporating in the UK is a great way to stop this.

The ICO is extremely reasonable and personable in my experience.

Re: Shutting Down Forum (GDPR)

#382

Can you send a GDPR letter to a public body, for example, the Office for National Statistics? Can you ask them to delete your data? Should they comply or are they waived from GDPR compliance?

> Can you send a GDPR letter to a public body, for example, the Office for National Statistics

Yes. They don't store personal data. All their data is strongly anonymised.

> Can you ask them to delete your data?

You can ask. GDPR does not introduce a blanket right to have your data deleted. There are a bunch of limitations to that right.

https://gdpr-info.eu/art-17-gdpr/

> Should they comply

They don't have to comply with deletion requests. i) they're not storing PII ii) if they're processing data for the reasons they've told you they do it then they don't need to delete upon request.

> or are they waived from GDPR compliance?

This isn't them being waived from GDPR compliance, this is the GDPR working the same for them as it would for any other processor.

Having said all this, "Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes"

That's not just government statistical departments, but includes university or history archives.

https://gdpr-info.eu/art-89-gdpr/

Re: Shutting Down Forum (GDPR)

#383
post #381
post #374

Earlier quoted context omitted.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

Incorporating in the UK is a great way to stop this. The ICO is extremely reasonable and personable in my experience.

Ever heard of Brexit?

Re: Shutting Down Forum (GDPR)

#384
post #294
post #289

Earlier quoted context omitted.

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

I don't find this: https://www.aclu.org/other/text-digital-millennium-copyright... much easier to read than this: https://gdpr-info.eu/

The full text of the law is for the regulators, not for armchair lawyers.

The ICO has produced a font of useful free guidance for getting compliant with the GDPR:

https://ico.org.uk/for-organisations/

That's what people should be reading.

Re: Shutting Down Forum (GDPR)

#385
post #383
post #381

Earlier quoted context omitted.

Incorporating in the UK is a great way to stop this. The ICO is extremely reasonable and personable in my experience.

Ever heard of Brexit?

If Brexit has any impact (which is unlikely, but admittedly still unclear[1], [2]), incorporating again in Ireland or France is very easy and has similarly-minded regulators.

[1]: http://researchbriefings.files.parliament.uk/documents/CBP-7...

[2]: https://www.ft.com/content/afff45a0-1597-3f1c-a6da-79c3f61e6...

Re: Shutting Down Forum (GDPR)

#386

I'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.

The owner of the forum received the "Nightmare letter" [1] which he is legally obligated to respond to, which as an open source project does not have the resources to be able to respond to them. [1]: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

Open source is totally unrelated to the matter at hands here. Any small operator is having limited resources and GDPR has been thought to allow everyone to answer requests.

It gave 2 year to get conformity to something which has been effective since 1995 through a European directive. The forum owner decided to ignore this a do nothing, now he's confronted with the consequences of his choices.

But again his reaction is akin to a knee jerk reaction as he is probably in capacity to answer the request while outsourcing to a third party does remove his responsibility and obligation to answer GDPR requests just now it's gonna get a bit more complicated as he has a third party into the loop which is probably not complying either.

Re: Shutting Down Forum (GDPR)

#387
post #282

Earlier quoted context omitted.

To answer that letter takes maybe 5 minutes for a simple forum operator.

I host a standard FluxBB forum on a stock Debian apache server. Can you please spent 5 minutes to answer that letter for me?

Show me the letter you received and we'll work from this.

You might want to get in touch with fluxBB dev to get a GDPR button extracting the relevant data from the database to avoid the pain of building the db query by hand.

Re: Shutting Down Forum (GDPR)

#388

Earlier quoted context omitted.

Maybe you could create some sort or reusable digital tool that could be used to aggregate all the data for any given user? Perhaps it be could be called a "script" or "program"?

[flagged]

"Can I have all my data that you hold?" isn't something that has been introduced with GDPR. It was introduced with DPA over 20 years ago. That was backed by £500,000 fines.

THe sky didn't fall.

Re: Shutting Down Forum (GDPR)

#389

Earlier quoted context omitted.

The forum owner wasn't getting "compliance requests" he was receiving "subject data access requests". Those requests can be: - Please give me all my data - Please delete all my data - Please stop doing things (processing) my data Or some mix of all the above. A site owner (controller) has 30 days from receiving such a request to respond or the person making the request can report them to their Supervisory Authority (…

So it looks like having a script to delete all user's data can get you out of trouble with any of these letters.

- Please tell me all the data you have on me

* furiously delete all user's data *

This is probably gonna get you in much more trouble than you could have been initially. For example France has law telling ISP they have to collect and retain customer data and activities for a year to able to retroactively identify who did what online at what time, failing this is not a matter of a report that could lead to warning and then to a fine but years of jail time instead.

Re: Shutting Down Forum (GDPR)

#390

Earlier quoted context omitted.

>If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited. So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor

As a side note, using Brave browser with all protections turned on by default, including Javascript disabled, and re-enabling Javascript (2 clicks) only on the websites you care and trust enough to, has made my Web browsing experience incredibly better, especially on mobile. Now everything loads in an instant, no more shenanigans that jump around the screen as I scroll, no Facebook/Twitter/Google buttons (that nobody…

I do the same on Firefox with Privacy Badger and Noscript extensions, supplemented with a PiHole on the network to disappear all those intrusive ads. On my phone, I use Naked Browser Pro, which lets you allow Javascript per site, along with Adaway.
Post reply on HN