Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

31–40 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#31

Why they don't want to answer request? It's still would be a nice thing to do ever if not required by law.

They could probably spend all day every day answering these requests. How do they even know it's valid? Could I just request all your information?

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#32
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data).

Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of view. You need to make sure that deletion requests also get honored when restoring from backup though, so ideally you want to store the requests in a third system and check them when you restore backups.

Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#33
post #24

Earlier quoted context omitted.

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you run a website, is "not blocking users from the EU" considered as providing services in the EU? I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.

There is no simple answer without more context, but if they are not doing any business from those users then the answer is likely no. There are several exceptions for normal operation of running a public website on the Internet.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#35
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

Responding to myself: Of course, this could have been the intention all along. It has long been recognized that big business loves difficult to conform with regulations (regardless of their protestations otherwise) because it is hard for smaller competitors to breach the effective moat that heavy/complex regulations provide incumbents.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#36

The subtitle is "[d]isgruntled ex-guildie effectively invents new way to grief in EVE" but it sounds like the request in question was sent to a website outside of EVE. This could happen with other games or, you know, websites unrelated to games at all...

Too bad geocities is gone, I could've GDPR'd every guestbook I'd ever signed.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#38

Earlier quoted context omitted.

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…

I think we mostly agree, especially when you bring China into it.

However, isn't the idea of forfeiting the personal jurisdiction defense? I am not a lawyer, but from what I understand, once you start debating the merits of the case, you waive the ability to claim that the court doesn't have jurisdiction.

It seems like there's a bit of a chance of that here - once you admit the EU or Chinese legal system is the appropriate place to redress things, you've given up lack of jurisdiction as a defense.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#39
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

Thank you for your thoughtful response and information. I need time to digest this information to see how it affects my opinions, which might take longer than the half life of this discussion, so my apologies in advance for probably not responding :-)

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#40
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

Re: the backups.

Rolling backups, e.g daily and weekly, are fairly common. When the request comes in, just acknowledge there will be a time period before the deletion is fully purged from system backups - as is still legal post-GDPR. The user data will still be removed from production data, which is of primary concern.

Post reply on HN