Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

461–470 of 534 posts

Re: Shutting Down Forum (GDPR)

#461
post #33

I don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests.

In its majestic equality, the law forbids rich and poor alike to sleep under bridges, beg in the streets and steal loaves of bread or violate the GDPR. -- Anatole France (I might have edited that quote slightly)

I have seen many people complain about how it is unfair that small companies also have to do due diligence with people's data, not just he big ones. It seems really mind-boggling to me.

Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception?

Should only large restaurants be forbidden from serving rotten food? Should small car makers have exceptions to car safety and emission standards?

Re: Shutting Down Forum (GDPR)

#462
post #446
post #420

Earlier quoted context omitted.

> Fonts are easy enough to self-host But what’s special about fonts ? If I can’t reference an asset outside my own domain because the network request could allow the 3rd party to log an IP address, How is that not antithetical to the foundation of the WWW? Besides the fact that this goes against the last decade of advice on how to speed up your site...

Nothing says you can't link to those resources, but if the page automatically loads them (hotlinked images, scripts, remote fonts, etc.) then there's an issue. Is it really that unreasonable that loading a page to x.com should only load resources from x.com and 3rd-party resources compatible with X's privacy policy?

> Nothing says you can't link to those resources, but if the page automatically loads them (hotlinked images, scripts, remote fonts, etc.) then there's an issue.

Seems like a contradiction, and exactly my point. Trying to collect privacy policies and compliance statements from any place you might load an or from is extraordinarily burdensome and pointless besides. Totally absurd over-reach IMO.

And what about the 25 hops in between you and them which also collect your IP and the domain being contacted?

Re: Shutting Down Forum (GDPR)

#463
post #461

Earlier quoted context omitted.

In its majestic equality, the law forbids rich and poor alike to sleep under bridges, beg in the streets and steal loaves of bread or violate the GDPR. -- Anatole France (I might have edited that quote slightly)

I have seen many people complain about how it is unfair that small companies also have to do due diligence with people's data, not just he big ones. It seems really mind-boggling to me. Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception? Should only large restaurants be forbidden from serving rotten food? Should small car makers have exceptions…

Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception?

Funny you should say that because I'm an environmental studies major and we do, in essence, let small shops do exactly that. Most toxic chemicals are disposed of in residential and commercial trash because they are being disposed of in small quantities. You basically do have to exceed a certain threshold before certain regulations apply to your toxic waste, such as household batteries.

We encourage consumers to recycle tech. We sometimes tack on some kind of environmental related tax or surcharge to try to cover the cost, but it is paid up front, it is a small amount and we know the fee at the time of purchase. But we don't set bear traps that can ruin your life because you put an old computer in the trash can instead of disposing of it properly, for example.

Re: Shutting Down Forum (GDPR)

#464
post #319

Earlier quoted context omitted.

> Even before GDPR, one could receive a DMCA request, an US court order, a letter from FBI, a letter from NSA. And a data access request. This has always existed, but it was a directive which was implemented in each local law, and local legislators could give (more mild) fines but almost never did. GDPR is not new . And I'm not talking about 2016, I'm talking about the previous law from 1995 which is 95% the same for…

None of those laws were extraterritorial.

Again, nothing changed on that front. There are two answers to your comment:

- Yes they were. If you violated the law, even if your servers are outside, the country would claim the violation happened in their territory because the subject was in their country so the law was violated there, and they can sue you.

- Neither is GDPR. If you are outside the EU, they can't force you to pay a fine like your own government can. Without enforcement, the law doesn't really apply. (See GDPR from 2016 until now.)

Which one applies depends on a bunch of things, such as whether there's an extradition treaty and whether you have offices in the EU, etc. I've never gotten a straight answer on which law rules in such cases, but that's probably because there is no single ruling case. Both are sovereign states, who supercedes is not codified in any law because there is no higher instance to appeal to.

I mean, if a small island state makes a law that if one of their citizens visits another country, that country should pay tribute for the honor of being visited by one of theirs, how in the world is that going to be enforced? Same with GDPR: the EU claims it applies worldwide, but the only reason that holds any truth is because you probably want to do business with EU citizens. Banning your company is the only thing they can truly do to you, and that has always been the case.

Re: Shutting Down Forum (GDPR)

#465
post #110

Earlier quoted context omitted.

If you make special laws for a few companies, you are fighting the hydra. There will come something after you fined Google or Facebook long enough for being too big. Defining a size for "mega corporations" is also quite arbitrary and I'd quite worse because it doesn't fight the underlying problem: every human should have the right of privacy. > Do you have evidence that it is, in fact, reining them in? We will see wh…

I said dealing with these mega corporations per se . This in no way suggests making special laws for a few companies. If the entire world currently agrees that a handful of companies are The Problem, then there should be some means to go after said handful of companies and get them to stop being The Problem without creating blanket laws negatively impacting the entire world, especially smaller organizations. Dealing…

The problem is, it's not a handful of companies, it's a few hundreds or even thousands, which makes rigorous laws sensible.

Google, Facebook, Twitter have a roster of the web pages you have viewed, whether you interacted with them or not.

Verizon, AT&T, T-Mobile and every other phone company has a complete log of your location history (for mobiles), message & call history, and unencrypted browsing history. They have no need for it to provide service (beyond the month or two in which these actions occured), but they do sell it to third parties, the list of which you have never seen.

Your credit card company does the same with your credit transactions.

This is already 30 companies or so, just in the US, and it is just the tip of the iceberg.

GDPR says "a person's data is their own property", which is easy to understand and enforce. You may not like it, but it's along the line of copyrights and trademarks, except the beneficiary is mostly the common man.

Re: Shutting Down Forum (GDPR)

#466

Earlier quoted context omitted.

I think you are right about one thing, the misreading of European law that comes from living in a litigious society. Just act in good faith and GDPR will not bite.

Just act in good faith and GDPR will not bite. Do you have $20million to make that gamble?

Let's not talk theory. I am making that gamble. Business is about risk judgement, and I have judged the risk to be miniscule.

Re: Shutting Down Forum (GDPR)

#467

Earlier quoted context omitted.

Legislation is usually applied by unellected people. Judicial independence is usually seen as a good thing. Perhaps you mean that the law was enacted by unellected people, which is also incorrect of course? So now I don't see your point at all?

The law has been proposed by the European Commission who is just nominated not elected.

Proposed yes. Just like in the UK un-elected civil servants propose all kinds of laws and regulation. Just like with the EU commission you only get to propose laws. The council of ministers (heads of states for EU countries) and the directly elected EU parliament actually get to enact regulation.

Being able tho propose a law is not ther same as enacting a law, and is not the same as applying a law which is what the parent comment said.

Re: Shutting Down Forum (GDPR)

#468

Earlier quoted context omitted.

Legislation is usually applied by unellected people. Judicial independence is usually seen as a good thing. Perhaps you mean that the law was enacted by unellected people, which is also incorrect of course? So now I don't see your point at all?

I'm not in the EU but must comply to their regulation. The internet at it's base abstraction is a borderless medium without regard to locality. Imposing legislation by user region is a dangerous precedent as each region can now impose fee-seeking legislation on internet companies.

So what do you propose no laws at all for the internet? Or each jurisdiction makes orts own law? In which case would the US mind getting the hell back inside it's borders and stop trying to extradite British teenagers who alledgedly broke some 'hacking' law?

Sounds like Team America again.

The government's of the world are struggling with internet jurisdiction issues, currently the US is taking the stance that any act against their companies is a US matter, whereas the EU is looking at abuse of its citizens is an EU matter. Weaker states have no recourse at all. I find it hard to judge that the US stance is ethically better than the EU's

Re: Shutting Down Forum (GDPR)

#469
post #203

How can it be hard for a forum to comply to GDPR? What kind of private information does it really need to save?

I'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people do…

The forum uses discourse, an open source forum software. I'm sure someone will soon add the functionality for users to download their data from discourse. And then you only need to have a standard email reply pointing GDRP requesters to that functionality.

Why are US companies/citizens overreacting so much? I haven't seen any company or sideproject from a different country react this way. (please let me know if I'm wrong)

Re: Shutting Down Forum (GDPR)

#470

Earlier quoted context omitted.

I think you are right about one thing, the misreading of European law that comes from living in a litigious society. Just act in good faith and GDPR will not bite.

We've seen a number of lawsuits posted here on HN with EU companies, either going after other EU companies, or US companies, or other EU US AU lawsuits. Sure a lot of it involves the bigger shops like Microsoft/Google/Facebook, etc .. but don't go saying it's not a litigious society. Lawsuits are used in a lost of western and eastern countries to try and right wrongs. Many of them use lawsuits to troll and money grab…

IANAL but my understanding is that contrary to US, several EU countries have limitations to what on can claim in court. Claim can not exceed damage. If you burn yourself with a hot coffee in a mc donalds your medical expense will covered and you might get a couple hundreds or a thousand while in the US you can be awarded millions in punitive damage by a jury.

This limitations means there's less frivolous litigation in the EU, unless it's a rich person or entity trying to silence someone, then they will waste money on frivolous litigation until the other party is unable to take it anymore (SLAPPs) a well known example of this is what happened to journalist Denis Robert who went through 10 years of multiple litigations in several countries for daring to expose the money laundering scheme happening in the European banking system in Luxembourg.

Post reply on HN