Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

51–60 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#51

Earlier quoted context omitted.

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…

US regularly tries to enforce it's laws on other countries, people / organisations in other countries

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#52
Guys think about the ranking lists.. you want your data deleted and you kind of also have to delete all related data to that account like everything. I can imagine already some people hacking top 100 ranking list accounts and deleting them to remove them from the ranking to get elevated themselves.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#53
post #30

Earlier quoted context omitted.

A website hosted outside of US jurisdiction will rarely get in trouble for breaking US specific laws.

Kim Dotcom and Megaupload is probably the biggest current and ongoing counterargument. But it's been standard behavior in other cases.

Which is why I added rarely; personally I was thinking of thepiratebay trials in Sweden. I do believe both Mega and TPB are as a result of breaking US law but TPB was at least tried in Sweden and found to be breaking Swedish law, not sure if the same goes/went for Kim.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#54
post #8

Earlier quoted context omitted.

Why should a European citizen abide by the laws of a different country (which may be illigal in their country BTW)

They shouldn't, but it's not their problem. If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws. The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.

Legally, the EU is claiming that if you do certain things which affect EU residents, then it will declare a judgment against you regardless of where you were when you did those things.

This idea is not new and certainly is not seen as unequivocally wrong in law.

If you produce libel against someone from another country, that person may sue you in their home country. That you performed the libel in another country is not generally seen as problematic to the libel laws of most countries. The US may refuse to recognize the judgment and you are fine as long as you do not travel to said country or a country with extradition agreements.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#55
post #45
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...] If it's only due to technical skills then this problem can be solved technically. The forum software needs to enable people to be GDPR compliant. > On a semi-related note: if you are a small SASS operator wantin…

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#56

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway.

Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#57
post #49

Earlier quoted context omitted.

Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…

Who has 'jurisdiction' in international law? According to your narrow definition of 'jurisdiction', nobody. Are you saying 'international law' doesn't exist? I mean, it wouldn't be wholly unreasonable; there are scholars of international law who essentially hold that position. Yet there are many other who don't. It's not as clear cut as you make it out to be. (FWIW yes I do have a law degree)

International laws aren't really laws, they're suggestions; the US ignores them all the time when it feels it's in its best interest.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#58
post #7

> the corp in question was blindsided by the request just as many real-life businesses were when the law came into effect last year “blindsided” bullcrap again

Probably because it's a single guy running a small forum for a 70 man guild in a spaceship MMO. Why would anybody in that situation expect to get a GDPR request? Especially when it's clear the person in question is just bullying the forum owner.

The greatest GDPR risk to my employer is from former employees wanting to cause hassle.

We have very little user data, just an email address and a name, and no tracking. Of course we have much more information about staff.

That's going to be a common situation, especially for non-tech or offline businesses.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#59
post #55
post #45

Earlier quoted context omitted.

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...] If it's only due to technical skills then this problem can be solved technically. The forum software needs to enable people to be GDPR compliant. > On a semi-related note: if you are a small SASS operator wantin…

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

And others would say it is unreasonable for businesses to store user data without consent and with no way to remove it. Please explain why any arbitrary site should have the ability to store user data without consent and then refuse to delete sensitive information. Are you going to accept liability if that data is leaked?

If I walk into a store, can they copy my drivers license and phone number without asking me, and then refuse to wipe my personal data from their systems?

I sincerely fail to see the downside with GDPR unless you think you have some assumed right to personal user information. Why does a site need info from me if I do not even have an account? Why do so many sites now insist that simply by visiting I agree to let them store cookies on my device?

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#60

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

I'd expect HN to be subject to the GDPR, since they show job adverts for startups in the EU on the front page.
Post reply on HN