Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

421–430 of 534 posts

Re: Shutting Down Forum (GDPR)

#421

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

"a data subject can't sue"

Didn't a data subject sue Google and Facebook for billions on day one of enforcement?

Re: Shutting Down Forum (GDPR)

#422
post #380

Earlier quoted context omitted.

> Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA. People send fake DCMA takedowns all the time. If someone sends you a GDPR data request, you can ask for administrative costs. You can even ask it to be mailed to you via post. If someone sends you a bogus and unreasonable GDPR data request, you can ask them to pay you a fur…

I felt the regulation text itself was clear that the first request is free. "1 - The controller shall provide a copy of the personal data undergoing processing. 2- For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs." https://gdpr-info.eu/art-15-gdpr/

The ICO says that the fee must be based on the administrative cost of providing the information which seems consistent.

Since you're allowed to respond to the first request with a list of the types of information you control, you should be able to do this without a search (and without undue costs).

Re: Shutting Down Forum (GDPR)

#423

Earlier quoted context omitted.

You haven't read it, i presume. The implementation requires a lot more than that.

No, because I am not a business owner so I am not interested in all the details, my interest is an internet user, I am fine with popups that allow me to opt out, I am also fine with websites that will block me(like the newspapers one) because I will find an alternative that does not track me. I understand that you may have some small websites and you put on them who knows how many trackers/analytics and now is time c…

I realize that I am sort of the pot calling the kettle black here because I also have not read it, but I am making meta commentary on observable and inferable unintended consequences disproportionately impacting smaller organizations while you are arguing the details of how to comply without really knowing anything about it. The kind of observations I am making are not actually dependent on me understanding the details of the law. The kind of rebuttals you are making that hand wave off the concerns of businesses and other organizations do hinge on knowing those details. Your rebuttals really have no basis.

Re: Shutting Down Forum (GDPR)

#424
post #353

Earlier quoted context omitted.

The implementation really doesn't require any more than that. The poster said "I don't collect anything on my website". Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.

Can’t square this comment with the long front page discussion just a couple days ago about whether ref’ing a Google font could violate GDPR. Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.

I think there is a lot of FUD around GDPR, for the fonts issue you can use fallback fonts for EU citizens, and if you insist to have those fonts ask for permission. I think the situation will clear out in a few weeks and in the end most people will know what is permuted and what not, is like with software licenses with a bit of research you know how to use GPL, LGPL,MIT etc no need to pay some law fird to research it for you.

Re: Shutting Down Forum (GDPR)

#425
post #253

Earlier quoted context omitted.

If they thought they were likely to receive a lot of these they'd probably shut down.

Not necessarily. Often, receiving your first request is by far the most expensive. You need to hire a lawyer, come up with a response plan, and educate employees on how to handle them. The second, third, and hundredth request is likely far less expensive or time consuming to deal with.

Yes exactly. I am not interested in subsidizing the one-time cost of hiring an attorney to draft a compliant privacy policy and create boilerplate email templates. It is just easier to outsource the forum to a company that can (reddit).

Re: Shutting Down Forum (GDPR)

#426

Earlier quoted context omitted.

Yes there is. If your email address is in the contact list harvested by facebook when people register on the website, it is linked to your shadow profile and can be used to show the lack of explicit consent and existence of your shadow profile. It's the path currently explored in a class action against facebook for forced consent and we'll see what happens.

Does Facebook have EU offices? If they do, this law will simply make it close them. If they don't, what is the class action even being based on?

This isn't true, you don't need to have offices in Europe for the GDPR to apply to your company. It's just if you're serving/having European customers. Which, if you compare it to shipping things across borders, makes sense (you can't just say "but it's legal in the US, where I'm sending the package from").

So closing the offices wouldn't help.

Re: Shutting Down Forum (GDPR)

#427
post #274
post #190

Earlier quoted context omitted.

It's going to be interesting to see what happens. My bet: Nothing.

From the several requests I've made already, that seems unlikely.

I second the sister comment's question: how did you go about sending them (like what phrasing did you use, for example?)

Want to write a short post on it?

Re: Shutting Down Forum (GDPR)

#428
post #342
post #257

Earlier quoted context omitted.

The costs are externalized yes but in many of these cases the person losing some privacy also benefits.

Smoking might cure anxiety but that doesn’t mean it doesn’t give you lung cancer...

So people shouldn't be allowed to smoke if they want to?

Re: Shutting Down Forum (GDPR)

#429

Earlier quoted context omitted.

OMG this is perfect! I'm so stealing this quote. It applies to so much it's scary.

But in this context it really doesn't work well as an analogy. Few rich people have any inclination to sleep rough, whereas many wealthy tech companies have been happily selling their users' data as the law allowed it.

The idea is large companies can afford the compliance costs.

Re: Shutting Down Forum (GDPR)

#430

I have a contrarian opinion to much I am reading here. Until a few weeks ago, I hosted my own web site and used blogger to host my blog on a subdomain. With huge reluctance I disabled comments, and then when Google’s patches for GDPR compliance didn’t work for me, I converted my 2000+ blog posts from the last 20 years to Jekyll and now host as part of my web site. While it is nice to have total control, now I need to…

Was your blog personal? Or was it commercial?

If it was personal the GDPR doesn't apply.

Post reply on HN