Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

411–420 of 534 posts

Re: Shutting Down Forum (GDPR)

#411

Goes to show that when an industry does not self-regulate, it gets over-regulated, which often disproportionately benefits incumbents, which incentivizes future lack of self regulation.

Not exactly. GDPR only applies to the EU. China isn't going to rewrite its laws to make the EU happy and mirror GDPR, neither is the US. It's more accurate to say that when an industry doesn't self-regulate, the EU over-regulates and shoots themselves in the face. The US and China will race even further out ahead accordingly. In the US I can easily unleash a large user data hungry AI at will, experimenting all day lo…

GDPR does not restrict EU companies' activities in less regulated markets. They are still just as free to abuse the privacy of users in USA as are their competitors overseas.

Your anxiety appears to be about American AI companies' competiveness in the face of even worse abuse of users' privacy in China than in USA.

In a race to the bottom do you really want to be the winner, no matter what?

Re: Shutting Down Forum (GDPR)

#412

Earlier quoted context omitted.

Which business schools are those?

Harvard Business School and its wannabes.

Give me a break. HBS does not teach students anything remotely close to ignoring problems and never taking responsibility for your actions.

Re: Shutting Down Forum (GDPR)

#413

Earlier quoted context omitted.

Not exactly. GDPR only applies to the EU. China isn't going to rewrite its laws to make the EU happy and mirror GDPR, neither is the US. It's more accurate to say that when an industry doesn't self-regulate, the EU over-regulates and shoots themselves in the face. The US and China will race even further out ahead accordingly. In the US I can easily unleash a large user data hungry AI at will, experimenting all day lo…

GDPR does not restrict EU companies' activities in less regulated markets. They are still just as free to abuse the privacy of users in USA as are their competitors overseas. Your anxiety appears to be about American AI companies' competiveness in the face of even worse abuse of users' privacy in China than in USA. In a race to the bottom do you really want to be the winner, no matter what?

https://gdpr-info.eu/art-3-gdpr/

> This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

Re: Shutting Down Forum (GDPR)

#414
post #358

Earlier quoted context omitted.

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts. I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer…

Generally speaking, there isn't a right to force others to delete stuff you've posted to the internet - only stuff related to PII. If you anonymize posts (say, change the username to AnonymousCoward and delete real names, reset passwords, etc), you're 99% of the way there - and if the person in question comes back and says "you've not deleted PII that I posted in one of my posts", you can go and delete that or edit i…

That's good to know. I had the impression it was more expansive.

Re: Shutting Down Forum (GDPR)

#415
post #407
post #358

Earlier quoted context omitted.

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts. I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer…

GDPR doesn't include a blanket right to delete your data. And forums already had to protect against eg people under 13 registering, or people under 18 sharing nudes. Both of those pose significant risk to online services, but people cope.

Forums only had to have a checkbox or user agreement saying "you must be over 13", and are protected from liability for users posting illegal content in the US by section 230 of the CDA.

Re: Shutting Down Forum (GDPR)

#416

Earlier quoted context omitted.

If youve ever dealt with the uk ico youll know its true. They refuse to do anything about individual complaints. The gdpr also states that samctions will be determinedby the gravity of the violation and number of users affected, among other factors. Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.

It’s not ‘nothing to worry about’ until the various enforcement bodies across the EU all establish predictable patterns of behavior and sanctions. Until then, nobody wants to be the first wrist slapped just to see how much it hurts.

The ICO has had 20 years to establish their pattern, and it seems to be pretty well set by now. They basically do fuck all about individual complaints, unless perhaps it's something incredibly serious. I recently had to take a data bureau to court for selling my details without permission (and won an out of court settlement for 500GBP) for spam, because the ICO did fuck all. I have another case pending against the very large UK company that used 2 separate data bureaus to spam me without permission.

So if the ICO won't sanction a very large company for clearly violating PECR, I really wouldn't worry. They only take action if they get thousands of complaints. I very much doubt that GDPR is going to change this behaviour, but I would love to be proven wrong.

Re: Shutting Down Forum (GDPR)

#417

Earlier quoted context omitted.

Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual lega…

A lot of the US over reaction to the GDPR probably stems from the fact that they assume that Europe has a system where parties sue each other, the jury system, as opposed to the state suing parties, the inquisitorial system. Getting sued in Europe is a huge deal, getting sued in the US is part of doing business.

I'm in favor of GDPR, but this is how it can be trivially used to target non-EU companies. EU regulators can be pressured to more aggressively pursue dominant foreign companies (or lay off important domestic companies) which many people already believe they do in various industries (banking/finance especially, as well as tech, automotive, aerospace, pharma...).

Re: Shutting Down Forum (GDPR)

#418
post #289

Earlier quoted context omitted.

DMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.

Its predecessor regulation capped fines at around $750k. Guess how many were levied at or near the maximum? Zero. The only large fines were for serious, deliberate abuses, such as a group maintaining a secret blacklist of construction employees. This isn't like the massive fines from US regulators on foreign companies. The rules say that fines should be proportionate to the scale of the breach and the harm caused. Th…

That's not a realistic decision for companies to make in the face of actually aggressive regulators, because regulators will simply levy the relatively smaller fines every day the company remains in violation (which EU regulators have threatened/done to US tech companies). Instead of making that decision, Google just stopped operating services (Google News) in countries that tried to aggressively control how they did business.

You're right though, that it is always a relatively pure cost/benefit calculation for the company.

Re: Shutting Down Forum (GDPR)

#419
post #380

Earlier quoted context omitted.

> Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA. Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single…

> Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA. People send fake DCMA takedowns all the time. If someone sends you a GDPR data request, you can ask for administrative costs. You can even ask it to be mailed to you via post. If someone sends you a bogus and unreasonable GDPR data request, you can ask them to pay you a fur…

I felt the regulation text itself was clear that the first request is free.

"1 - The controller shall provide a copy of the personal data undergoing processing. 2- For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs."

https://gdpr-info.eu/art-15-gdpr/

Re: Shutting Down Forum (GDPR)

#420
post #378
post #375

Earlier quoted context omitted.

Then just put that in your privacy policy and you are off the hook. If Google tracks something, whether it is via their fonts, by putting some cookie on your site or whatever, it is their problem (and they actually said so, in that Github post referring to the font issue). They are the ones collecting and processing the data, not you, so they will have to deal with the GDPR compliance.

That's their interpretation, and they don't face consequences if it's wrong. Since I've gotten advice to the contrary from lawyers looking into GDPR, I won't trust it until there's clear feedback from regulators or courts about it. Fonts are easy enough to self-host.

> Fonts are easy enough to self-host

But what’s special about fonts? If I can’t reference an asset outside my own domain because the network request could allow the 3rd party to log an IP address, How is that not antithetical to the foundation of the WWW?

Besides the fact that this goes against the last decade of advice on how to speed up your site...

Post reply on HN