What's interesting, and pointed out by a Reddit comment: https://www.reddit.com/r/legaladvice/comments/acsdf3/comment... There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove…
An Eve Online corporation has been hit with a GDPR request from an ex-member
11–20 of 141 posts
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#12> the corp in question was blindsided by the request just as many real-life businesses were when the law came into effect last year “blindsided” bullcrap again
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#13Earlier quoted context omitted.
The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?
Why should a European citizen abide by the laws of a different country (which may be illigal in their country BTW)
If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws.
The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#14Why they don't want to answer request? It's still would be a nice thing to do ever if not required by law.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#15What's interesting, and pointed out by a Reddit comment: https://www.reddit.com/r/legaladvice/comments/acsdf3/comment... There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove…
Doesn't Even have some sort of user profile? Bob could update it saying "yes, I made a GDPR request to X on date Y".
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#16I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…
It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#17Earlier quoted context omitted.
Why should a European citizen abide by the laws of a different country (which may be illigal in their country BTW)
They shouldn't, but it's not their problem. If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws. The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#18> the corp in question was blindsided by the request just as many real-life businesses were when the law came into effect last year “blindsided” bullcrap again
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#19I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…
It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.
AggregateIQ could have ignored the GDPR-request, ignored any rulings and keep chugging along as long as they stuck to Canada (assuming Canada was not going to side with the EU).
In short, if you're not in the EU, do not care about EU and never will, you can largely ignore the GDPR. Same as if some banana republic dictator declares you persona non grata - if you never intend to visit and otherwise have no business in that country, who cares?
The difference is that the EU is not a banana republic (opinions may vary), and so many choose to respect and accept this their judgement in cases like this to stay on good terms.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#20I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…
It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.
Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law.
If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my company and granting the EU new global powers (such that I can provide the EU jurisdictional reach into the US so that it overrules or competes with US law). That isn't my decision to make if I operate inside the US jurisdiction. The US solely decides jurisdiction within its zone of political control. That is, the US has the final say legally in all regards in that case. I could choose to voluntarily comply with GDPR, however the EU has zero power to force me to. I can flip flop back and forth a thousand times, or not, it makes no difference.
If you ever find yourself wondering about these concepts, change the scenario to China. Under what scenario does the EU or US have power to dictate laws within China? None. It provides a perfect clarification every time. Nobody could possibly be confused about who is in charge of law within China.