Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

401–410 of 534 posts

Re: Shutting Down Forum (GDPR)

#401
post #374

Earlier quoted context omitted.

Yeah from what I have heard the main reason for this law is to stop obvious abuses to people's privacy. It seems that most overreactions are due to ignorance of the system behind the law or to make some kind of political statement.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

This is exactly what I mean. Europe has functioning government that can't be fathomed on the other side of the Atlantic.

Re: Shutting Down Forum (GDPR)

#402
post #2

Overbearing legislation applied by unelected representatives is being abused. If only there were technical solutions provided with an assumption of goodwill instead of 88 pages of mandates without such an assumption.

You do realise that the European Parliament is directly-elected, right?

Re: Shutting Down Forum (GDPR)

#403
Unless I’m missing something, shutting down the forum does precisely nothing to limit GDPR liability as the main drone.io site itself has an account/login area. Whilst it’s private beta currently, unless EU access is blocked, GDPR liability will continue to apply to any personal data collected via that.

The only benefit here is that there’s one fewer system to keep track of when it comes to tracking/deleting personal data - the need to respond to subject access requests, right to be forgotten, form letters etc remains.

Re: Shutting Down Forum (GDPR)

#404

Earlier quoted context omitted.

Legislation is usually applied by unellected people. Judicial independence is usually seen as a good thing. Perhaps you mean that the law was enacted by unellected people, which is also incorrect of course? So now I don't see your point at all?

The law has been proposed by the European Commission who is just nominated not elected.

Proposed by the European Commission, yes, but it also had to be passed by the directly-elected European Parliament.

Re: Shutting Down Forum (GDPR)

#405
post #167
post #87

Earlier quoted context omitted.

How are the representatives "unelected"? The European Parliament is elected every five years by the citizens of all EU member states and voted on the GDPR in 2016 after long talks. Some even say that the GDPR is not hard enough.

The GDPR was passed by the European Comission, not the EP. Members of the EC are appointed, just like ministers in governments. But governments can only pass time limited decrees which then have to be signed into laws and voted for in Parliament. The EC which can pass binding regulations that apply indefinitely.

You are wrong.

The GDPR was formally proposed by the European Commission, but it then went to the European Parliament (where it was amended). If the European Parliament had voted against it then it would have never become law.

Re: Shutting Down Forum (GDPR)

#406

Earlier quoted context omitted.

Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual lega…

>Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented. >The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overrea…

> there are hundreds of different pieces of forum software that may not have that feature implemented.

"Can I have all my data?" is not new to GDPR. It has existed in previous data protection law. How did people cope before?

Re: Shutting Down Forum (GDPR)

#407
post #358

Earlier quoted context omitted.

Deleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the post…

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts. I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer…

GDPR doesn't include a blanket right to delete your data.

And forums already had to protect against eg people under 13 registering, or people under 18 sharing nudes. Both of those pose significant risk to online services, but people cope.

Re: Shutting Down Forum (GDPR)

#408
post #365

Earlier quoted context omitted.

Not at all. If you don't pay me, you're a guest , not a customer. Should guests have rights too? Of course! But guest rights are very different than customer rights. Hosts should be held to a certain standard, and if they fail to meet that standard then they should expect to hear from regulators. What makes GDPR noxious is that it turns every individual interaction with the host into its own little mini-lawsuit, crea…

> What makes GDPR noxious is that it turns every individual interaction with the host into its own little mini-lawsuit, No, it really doesn't. In Europe action for civil torts is limited to what you've actually lost. There are no punitive civil claims. Courts are a method to get back to how you were, they're not a route to betterment. And GDPR is not enforced by each victim of a breach taking civil action through the…

No, it doesn't create a new tort, but that's why I said mini lawsuit. The mandatory response and per-instance fines create the same sort of burden, even if they're administered through a body other than the courts. In some ways it would almost be better if it were through the courts, because at least there are established rules about evidence, nuisance suits, appeals, etc., but that wouldn't solve the fundamental problem.

Re: Shutting Down Forum (GDPR)

#409

Earlier quoted context omitted.

The owner of the store does have the right to record the sales transaction data. But that was never under dispute even with GDPR. GDPR specifically says that you do not have the right to be forgotten in the information is important for legal compliance (e.g. tax records), free speech, and a couple of other things. https://ico.org.uk/for-organisations/guide-to-the-general-da... See “when does [it] not apply?” GDPR alr…

> GDPR already applies to governments. What makes you think it is not? It doesnt apply to security-related services, and the governements are allowed to override it for most purposes as outlined in article https://gdpr-info.eu/art-23-gdpr/

For an example that gets a bit meta:

https://twitter.com/bainesy1969/status/1001902266620764160?s...

> ICO rules that ICO failed to comply with timescales laid down in the FOI law that ICO regulates link: https://ico.org.uk/media/action-weve-taken/decision-notices/...

Re: Shutting Down Forum (GDPR)

#410

Earlier quoted context omitted.

> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. sensible regulation that defines workable limits of what personal information can be collected, combined with requirements for anonymization when needed is a better solution.

Some of the early results we are seeing from GDPR make one question how ‘sensible’ it really is.

Can you post to any of those results from the actual regulators?

So far there have been a few people just giving up before the regulators get involved, which seems like a massive over reaction.

Post reply on HN