Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

451–460 of 534 posts

Re: Shutting Down Forum (GDPR)

#451

Earlier quoted context omitted.

You can neuter the like button, thanks to tools like Privacy Badger.

It's more scalable to neuter the button server-side than client-side, though. That button is clearly so 'wrong' from the consumer's point - I hope this is the beginning of the end.

It is more scalable client-side. There are fewer browsers than Internet edges. The Internet is designed to circumvent any attempt to control the edges.

You can hammer one app Facebook but you can’t hammer all apps.

Just consider revery Chrome extension that is malware. You can though hammer Chrome to block functionality that enables malware.

Re: Shutting Down Forum (GDPR)

#452

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

>It seems like he has no time only for legislation from EU.

Yes, that is the entirely correct mindset to have for someone who does not live in the EU.

Re: Shutting Down Forum (GDPR)

#453

How can it be hard for a forum to comply to GDPR? What kind of private information does it really need to save?

>private information

GDPR is about personal information, not private information. Personal information is anything relating to an identified or identifiable person. Your forum account username, password, posts, private messages, votes, etc. are all in GDPR scope. If it's possible to use the same username, password, and writing style, etc. across the internet then at least some forum users are "identifiable" whether or not they have provided a real name, phone number, or anything like that.

Re: Shutting Down Forum (GDPR)

#454
post #374

Earlier quoted context omitted.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

This is exactly what I mean. Europe has functioning government that can't be fathomed on the other side of the Atlantic.

seriously? spain, italy, and greece don't have malfunctioning governments?

Re: Shutting Down Forum (GDPR)

#455
post #320
post #203

Earlier quoted context omitted.

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

It's not clear that a forum administrator would need to do anything under the GDPR except respond to emails with the standard template: "The forum does not collect or process any personal data." Technically, I suspect, this would be true. The GDPR and the right to be forgotten are subtle on this. If a user chooses, unprompted, to share PII it's not clear that collection has taken place. Imagine a user, out of the blu…

>Would anybody seriously believe that the business should be liable for failing to secure the PII data?

Yes: look at the reaction to Facebook "leaking" personal data through a well-documented public API.

Re: Shutting Down Forum (GDPR)

#456
post #319

Earlier quoted context omitted.

Even before GDPR, one could receive a DMCA request, an US court order, a letter from FBI, a letter from NSA. It didn't prevent people from creating websites though. GDPR requests are definitely less scary than a letter from NSA or an US court order: nobody will put you into jail for non-compliance, kidnap you or send a drone to you.

> Even before GDPR, one could receive a DMCA request, an US court order, a letter from FBI, a letter from NSA. And a data access request. This has always existed, but it was a directive which was implemented in each local law, and local legislators could give (more mild) fines but almost never did. GDPR is not new . And I'm not talking about 2016, I'm talking about the previous law from 1995 which is 95% the same for…

None of those laws were extraterritorial.

Re: Shutting Down Forum (GDPR)

#457

The owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.

Completely different issues. National Security letters and DMCA requests are for discrete, time bounded data points and complying has effectively no impact on future operations (unless you decide to shut down instead of responding like Lavabit did).

GDPR however requires that you actively set up data auditing and security policies and practices which may break or otherwise require re-architecture of parts of your company. In fact that is it's purpose. If the company or organization is small enough, then it might be easier to abandon the project instead of being compliant.

In this guy's case he had an easy offramp to reddit, so he took it. Simple. However it does offer now at least one data point to show that GDPR has decreased diversity in data ownership and risk. The question is, are drone.io users better off now that they will be utilizing reddit?

Re: Shutting Down Forum (GDPR)

#459
post #330
post #18

Earlier quoted context omitted.

From one of his responses in the link "I do appreciate the links. The gdpr documentation is quite long and I lack the domain expertise to read and comprehend the document in full. Perhaps this is cultural, since the United States is a very litigious society, but I would not feel comfortable accepting liability for gdpr compliance without consulting an attorney. It is also unclear how I am expected to respond to DPA e…

> The gdpr documentation is quite long and I lack the domain expertise to read and comprehend the document in full. As if he read all laws of his own country that apply to him. Raise your hand if you actually read and comprehend all laws that apply to you. I'm willing to bet there's not a single person on this planet who really reads and comprehends all laws completely. Usually you just go with common sense and readi…

>As if he read all laws of his own country that apply to him.

Drone.ci is treating GDPR like any other law by steering well clear of the territory it regulates. The US also has stringent rules about online gambling, payment processing, pornography, copyrighted material, etc. Normal website operators don't become familiar with these rules or how to thread a business through them. They simply don't engage in regulated activity at all, unless making a deliberate and well-capitalized entrance with the help of lawyers and compliance professionals. (Obviously there are some high-profile counterexamples, but those are, well, high-profile).

If the GDPR were a law about data brokerage or advertising, then forum operators would be similarly far away from it. But it's a law about the handling and storage of data related to people, which you definitely do if you're running a forum. Ordinary websites have never been that close to the boundaries of legality before, so people are scared.

Re: Shutting Down Forum (GDPR)

#460

Earlier quoted context omitted.

Garnishment. If the regulatory agency decides to fine you, and you don't successfully defend yourself against that in court, then you'll have to pay that fine. If you fail to pay the fine on time, any entities within the juristiction that owe you can be ordered to pay the fine instead (i.e., your payment processor will be ordered to redirect funds arriving for you to the state, which also, as far as their juristictio…

Sounds like a good reason to start only accepting crypto

Except that won't help you? Usually, payment processors are ordered to redirect funds as that is usually the easiest way, but if that is not an option, your customers will be ordered directly to redirect payments. As long as you have customers within the jurisdiction, they will find a way to make you not earn any money from them until your fine is paid.
Post reply on HN