Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

391–400 of 534 posts

Re: Shutting Down Forum (GDPR)

#391
I have a contrarian opinion to much I am reading here. Until a few weeks ago, I hosted my own web site and used blogger to host my blog on a subdomain. With huge reluctance I disabled comments, and then when Google’s patches for GDPR compliance didn’t work for me, I converted my 2000+ blog posts from the last 20 years to Jekyll and now host as part of my web site.

While it is nice to have total control, now I need to be using my laptop to post new blog posts, and I miss having readers comment. I also feel badly that the interesting things that readers have posted are lost to the Internet.

Even with all that, as a US citizen, I approve of GDPR and I wish it were universal. As much as I miss user comments, I am fortunate to have many readers engage with me directly via email discussions.

Re: Shutting Down Forum (GDPR)

#392
post #358

Earlier quoted context omitted.

Deleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the post…

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts. I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer…

Generally speaking, there isn't a right to force others to delete stuff you've posted to the internet - only stuff related to PII. If you anonymize posts (say, change the username to AnonymousCoward and delete real names, reset passwords, etc), you're 99% of the way there - and if the person in question comes back and says "you've not deleted PII that I posted in one of my posts", you can go and delete that or edit it out, you're not about to get fined if you make a best-effort attempt as a small company - only if you're obviously negligent.

There is no right to delete stuff that is not PII.

Re: Shutting Down Forum (GDPR)

#393
post #177

I'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.

Have you ever ran a business that, uh, intended to scale beyond one employee and a hobby website? I've never seen a company be threatened with some form of legal attack and not get lawyers involved. Especially with such a new law like the GDPR that has no judicial precedences upon which to build business processes. I've been in companies as small as 4 people, and we still had lawyers on retainer for stuff like this (…

GDPR is not new law, it's a mean to enforce a European Directive from 1995. Also there are several privacy precedents in the EU, for example max schrems.

Re: Shutting Down Forum (GDPR)

#394

Earlier quoted context omitted.

OMG this is perfect! I'm so stealing this quote. It applies to so much it's scary.

But in this context it really doesn't work well as an analogy. Few rich people have any inclination to sleep rough, whereas many wealthy tech companies have been happily selling their users' data as the law allowed it.

[deleted]

Re: Shutting Down Forum (GDPR)

#395
post #352

Earlier quoted context omitted.

No it applies to any organization offering data services/web sites to EU residents, including authorities. GDPR is only a regulation stating more explicitly what you're required (and were always required) to do for compliance with EU privacy laws. It obviously was needed since privacy violation has become so blatant. The GDPR legislation has been a long time in the making. It might be the case that privacy in Europe…

> please also consider the US's total and utter failure to get their antitrust regulations in gear: Facebook buying WhatsApp, Google buying DoubleClick and YouTube, etc. At a certain point, others will have to react to that kind of government-sanctioned monopolization to protect their markets. The European Union also green lit those acquisitions. Hence the fines against Facebook for essentially lying to the European…

It will be interesting to watch this unrolling, and I'd think criminal investigation is also on the table (vs Fb employees and EU officials).

Re: Shutting Down Forum (GDPR)

#396

Earlier quoted context omitted.

The owner of the store does have the right to record the sales transaction data. But that was never under dispute even with GDPR. GDPR specifically says that you do not have the right to be forgotten in the information is important for legal compliance (e.g. tax records), free speech, and a couple of other things. https://ico.org.uk/for-organisations/guide-to-the-general-da... See “when does [it] not apply?” GDPR alr…

> GDPR already applies to governments. What makes you think it is not? It doesnt apply to security-related services, and the governements are allowed to override it for most purposes as outlined in article https://gdpr-info.eu/art-23-gdpr/

There are three related reasons for this:

1. Each EU member state has a different legal framework and so a Regulation (which has direct effect, meaning it applies as-is and does not have to be "transposed" into national law) would not be appropriate when dealing with criminal investigations;

2. The EU can only act in areas where it has been given "competence" to do so under the Treaty on the European Union and Treaty on the Functioning of the European Union. Member states are reluctant to give the EU broad competence to establish criminal offences or to regulate the investigation and prosecution of offences;

3. The treaties explicitly exclude almost all activities related to national security because that is a fundamental feature of being sovereign, which EU member states are and the EU is not.

Due to points 1 and 2, the EU passed the Law Enforcement Directive (2016/680/EC) which regulates processing of personal data in a law enforcement context. Being a Directive (and not a Regulation) means that each member state has latitude to adapt it to their respective legal frameworks when transposing it into national law.

Incidentally, point 3 will cause huge problems for the UK when we eventually leave the EU. The Court of Justice of the European Union - the EU's highest court - cannot take in to account laws of a member state relating to national security (insofar as they _only_ relate to national security) due to their exclusion by the treaties, but they can take in to account laws of a third country.

Re: Shutting Down Forum (GDPR)

#397

Earlier quoted context omitted.

They aren’t attempting to enforce legislation globally. If a company operates in the EU, it has to comply. For companies that don’t operate in the EU and have no EU customers or traffic, they don’t. Simple

Even if said foreign companies have EU customers, what can the EU do about it? If I were a foreign company, I would completely ignore GDPR requests. Like > /dev/null, not even bother reading them. This law will only make things (even) more expensive and cumbersome for EU companies wrt. the rest of the world. This is going to be the asinine Cookie Warning all over again, times a hundred.

> Even if said foreign companies have EU customers, what can the EU do about it? If I were a foreign company, I would completely ignore GDPR requests. Like > /dev/null, not even bother reading them.

EU regulators could domesticate their judgments in the jurisdictions where these companies are based. It's entirely possible to do this in most states in the US, for example.

Failing that, they could target assets held in the EU or take action whenever corporate officers travel to the EU.

Re: Shutting Down Forum (GDPR)

#398

Earlier quoted context omitted.

I think you are right about one thing, the misreading of European law that comes from living in a litigious society. Just act in good faith and GDPR will not bite.

We've seen a number of lawsuits posted here on HN with EU companies, either going after other EU companies, or US companies, or other EU US AU lawsuits. Sure a lot of it involves the bigger shops like Microsoft/Google/Facebook, etc .. but don't go saying it's not a litigious society. Lawsuits are used in a lost of western and eastern countries to try and right wrongs. Many of them use lawsuits to troll and money grab…

FYI, there are no lawsuits with GDPR: You file a complaint with the relevant data protection agency and they then decide whether to pursue this. Should they do that, the company can dispute the claim and only then elgal proceedings would follow (agency v company, no potential award for person filing complaint)

Re: Shutting Down Forum (GDPR)

#399

Earlier quoted context omitted.

Yes there is. If your email address is in the contact list harvested by facebook when people register on the website, it is linked to your shadow profile and can be used to show the lack of explicit consent and existence of your shadow profile. It's the path currently explored in a class action against facebook for forced consent and we'll see what happens.

Does Facebook have EU offices? If they do, this law will simply make it close them. If they don't, what is the class action even being based on?

>Does Facebook have EU offices?

Yes, they are based in Ireland.

Re: Shutting Down Forum (GDPR)

#400
post #118

Earlier quoted context omitted.

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. There are tons of companies processing my personal data that are not web companies. GDPR isn't about "data being on the web", it's about all handling of personal data.

If you walk into a store and buy something, does the owner not have a right to record relevant personal information as it pertains to the sale, such as when buying a car? This idea that those vendors ought to be required to delete records seems backwards — you aren’t required to interact with entities that do things you don’t like — unless it’s the government, no escaping that. Public records are potentially more har…

> This idea that those vendors ought to be required to delete records seems backwards

GDPR doesn't introduce a requirement to delete data upon request.

Post reply on HN