Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

41–50 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#41
post #30

Earlier quoted context omitted.

Countries (or conglomerates of them) applying their laws world-wide has long been what the US does on the internet. It's a bit too late to put that genie back in the bottle.

A website hosted outside of US jurisdiction will rarely get in trouble for breaking US specific laws.

But if the owners of that website visit the US they’re liable to be arrested (assuming the site has enough impact). Same in reverse.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#42
post #6

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

[deleted]

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#43
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

Backups has many potential exceptions, some being security and archiving for the public, but there is also language like reasonable steps and to not have the data influence any future decisions.

But backups has to be stored securely, and the data within can't naturally be used if restored beyond exceptions.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#44
post #23

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

It is very doubtful there is any need to search posts. The data are still necessary for the purpose they were originally collected, and there is also a archiving exception which may apply. If I was them I would just send the person their login profile and delete that from the site. Everything else is excepted, including backups which are kept for security. A good community example to look at is Wikipedia. I will star…

An article you agreed to publish on a public encyclopedia hardly counts as personal data..

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#45
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...]

If it's only due to technical skills then this problem can be solved technically.

The forum software needs to enable people to be GDPR compliant.

> On a semi-related note: if you are a small SASS operator wanting to comply with such requests, what are you meant to do about your DB backups that contain data that is meant to be forgotten?

This hasn't been tested in court, yet. But there are several possible approaches. Like delete on restoration or backing up in slices, so that the personal data becomes anonymous unless you have all the parts.

Don't forget that the "right to be forgotten" is not an absolute right. It doesn't trump everything else. Nobody would expect somebody to sue ESA for their "right to be forgotten" for a public message that they could send to ESA to put on a CD on a probe they sent into space and win.

First of all, it forces everybody involved with personal data to think about how they handle personal data and inform the users about that.

If you state "due to technical limitations, your personal data in backups can't be erased at the time of the request but will be deleted on restoration" up front during the signup of the user, this is already an improvement over the past where nobody knew what happened with their data.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#46
post #23

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

It is very doubtful there is any need to search posts. The data are still necessary for the purpose they were originally collected, and there is also a archiving exception which may apply. If I was them I would just send the person their login profile and delete that from the site. Everything else is excepted, including backups which are kept for security. A good community example to look at is Wikipedia. I will star…

data being necessary for original purpose doesn't help; you can withdraw consent

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#47
post #44
post #23

Earlier quoted context omitted.

It is very doubtful there is any need to search posts. The data are still necessary for the purpose they were originally collected, and there is also a archiving exception which may apply. If I was them I would just send the person their login profile and delete that from the site. Everything else is excepted, including backups which are kept for security. A good community example to look at is Wikipedia. I will star…

An article you agreed to publish on a public encyclopedia hardly counts as personal data..

Person B mentions person A by name or by nym.

Person B describes person A without mentioning a name, eg by describing person A in a way which is recognizable. (eg the pilot that shot down the death star.)

The first is at least searchable...

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#48
post #30

Earlier quoted context omitted.

Countries (or conglomerates of them) applying their laws world-wide has long been what the US does on the internet. It's a bit too late to put that genie back in the bottle.

A website hosted outside of US jurisdiction will rarely get in trouble for breaking US specific laws.

Kim Dotcom and Megaupload is probably the biggest current and ongoing counterargument. But it's been standard behavior in other cases.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#49

Earlier quoted context omitted.

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…

Who has 'jurisdiction' in international law? According to your narrow definition of 'jurisdiction', nobody. Are you saying 'international law' doesn't exist? I mean, it wouldn't be wholly unreasonable; there are scholars of international law who essentially hold that position. Yet there are many other who don't. It's not as clear cut as you make it out to be.

(FWIW yes I do have a law degree)

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#50

Earlier quoted context omitted.

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you offer your services on the Internet, and someone chooses to use them from the EU, that does not mean you "offer your services in the EU". Or do you plan to make all of your web services "respect" the laws of 200+ countries in the world, and for that matter all the sub-jurisdictions of those countries (such as states or provinces or cities) that have their own laws? The EU is not special in that regard, they're…

It is context based. In the case at hand, I think it is fairly clear that the Eve corp wants users from Europe, since otherwise other corps which take users from Europe would out compete them. I'm not an Eve player, but my understanding is that you want your corp to be as large as possible to produce certain ships/stations? Other contexts, like a company offering investments to US based startups is unlikely to be seen as offering services to European residents even if Europeans can create accounts there.

As to jurisdiction, you can always sit in your home country and ignore any rulings against you from other countries so long as you are sure that your own country will not extradite you for such a thing (I am confident that Canada would not extradite a Canadian residence for such a thing). Just don't ever try to cross the border into a European country.

Post reply on HN