Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

21–30 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#21
post #6

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

[deleted]

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#22
post #6

Earlier quoted context omitted.

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you offer your services on the Internet, and someone chooses to use them from the EU, that does not mean you "offer your services in the EU".

Or do you plan to make all of your web services "respect" the laws of 200+ countries in the world, and for that matter all the sub-jurisdictions of those countries (such as states or provinces or cities) that have their own laws? The EU is not special in that regard, they're just one more jurisdiction that the service isn't hosted in.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#23

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

It is very doubtful there is any need to search posts. The data are still necessary for the purpose they were originally collected, and there is also a archiving exception which may apply.

If I was them I would just send the person their login profile and delete that from the site. Everything else is excepted, including backups which are kept for security.

A good community example to look at is Wikipedia. I will star to worry if and when I see them start deleting profiles and articles. Until then I see this kind of articles like a bit of scared interpretation of how nations might implement and apply GDPR.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#24
post #6

Earlier quoted context omitted.

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you run a website, is "not blocking users from the EU" considered as providing services in the EU?

I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#25

The subtitle is "[d]isgruntled ex-guildie effectively invents new way to grief in EVE" but it sounds like the request in question was sent to a website outside of EVE. This could happen with other games or, you know, websites unrelated to games at all...

Corp (guild) forums are an important part of EVE and preferred over posting news and operations on Discord for example since you can set it up to serve unique texts to each user, making it easier to find them if they leak to other corps, and hidden changes in the website that will give it away in case the corp news leak by screenshot.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#26
post #6

Earlier quoted context omitted.

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

Are they? I don’t mean to be fussy, well maybe a little, but when you ask for something from Atlantis, and Atlantis responds, is that interaction at your place? Is it in Atlantis? Some weird combination of the two?

I don’t outright disagree, I don’t think it’s settled or even established yet.

Mail is probably going to be a big precedent. Everything from play by mail chess to ordering from Sears will have to be considered.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#27
As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to either shutdown, or be in breach of law.

Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business.

This is not the democratization of information that the web promised oh so many years ago.

On a semi-related note: if you are a small SASS operator wanting to comply with such requests, what are you meant to do about your DB backups that contain data that is meant to be forgotten?

[edits: punctuation/grammar]

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#28
post #6

Earlier quoted context omitted.

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

Unfortunately, it's not that clear. Per Recital 23, the service must intend to have EU users, and merely being accessible in the EU is not enough to ascertain that. It must have some signs, such as accepting European currency or mentioning advantages to European users. Thankfully most sites clearly want to accept money from all currencies, but if this corp didn't charge, it might be difficult to show that they envisaged having EU users.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#29
post #24

Earlier quoted context omitted.

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you run a website, is "not blocking users from the EU" considered as providing services in the EU? I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.

See my sibling comment. Merely being accessible is in fact not enough to be considered as providing services in the EU.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#30

Earlier quoted context omitted.

They shouldn't, but it's not their problem. If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws. The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.

Countries (or conglomerates of them) applying their laws world-wide has long been what the US does on the internet. It's a bit too late to put that genie back in the bottle.

A website hosted outside of US jurisdiction will rarely get in trouble for breaking US specific laws.
Post reply on HN