Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

61–70 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#61
post #55
post #45

Earlier quoted context omitted.

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...] If it's only due to technical skills then this problem can be solved technically. The forum software needs to enable people to be GDPR compliant. > On a semi-related note: if you are a small SASS operator wantin…

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

>> Fuck the GDPR, they have no more authority over me than China or North Korea does.

You are probably not trading with North Korea, so ignoring their laws has zero impact on anything. China is already getting more tricky though, although they are not choosing to throw their entire weight behind enforcing their demands abroad(yet).

But ignoring the demands of the largest trading block on the planet? That's not going to go well if you do any sort of business with the EU. Unless you can just afford to ignore all EU customers entirely.

And no, thank fuck for the GDPR, it's a great legislation.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#62

Earlier quoted context omitted.

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

I'd expect HN to be subject to the GDPR, since they show job adverts for startups in the EU on the front page.

Yet they are not compliant and you cannot delete posts or accounts. Pretty sure YC does business in the EU as well. Enough to be subject to GDPR at least.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#63
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

Lots of software has functionality most users can't use.

You might as well tell them that compilers can provide the functions necessary to comply.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#64
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

It's not CCP? Because Iceland is not a member of the EU although I suppose they could be subject to this somehow(?)

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#65
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> They will be forced to either shutdown, or be in breach of law

Or just block EU traffic and ensure no seizable assets rest in the bloc.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#66

Earlier quoted context omitted.

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

Lots of software has functionality most users can't use. You might as well tell them that compilers can provide the functions necessary to comply.

> Lots of software has functionality most users can't use

If you are using software to process my personal data, and you don't know how to do that while protecting my personal data, then I'd like you to stop using that software right away.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#67
post #47
post #44

Earlier quoted context omitted.

An article you agreed to publish on a public encyclopedia hardly counts as personal data..

Person B mentions person A by name or by nym. Person B describes person A without mentioning a name, eg by describing person A in a way which is recognizable. (eg the pilot that shot down the death star.) The first is at least searchable...

But neither are in scope. The GDPR makes exceptions for journalistic use cases (An encyclopedia certainly counts; see Article 85 and 89), and it does not require that you link a person (e.g. in your second case; see Recital 26) if you have no other reason to do. If someone persists, Article 11 makes it possible to put the onus on the person to identify any data in this category.

- https://gdpr-info.eu/art-89-gdpr/

- https://gdpr-info.eu/art-85-gdpr/

- https://gdpr-info.eu/art-11-gdpr/

- https://gdpr-info.eu/recitals/no-26/

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#68
post #55
post #45

Earlier quoted context omitted.

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...] If it's only due to technical skills then this problem can be solved technically. The forum software needs to enable people to be GDPR compliant. > On a semi-related note: if you are a small SASS operator wantin…

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

> Fuck the GDPR, they have no more authority over me than China or North Korea does

Good luck with that champ

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#69
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> They will be forced to either shutdown, or be in breach of law Or just block EU traffic and ensure no seizable assets rest in the bloc.

[deleted]

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#70

Why they don't want to answer request? It's still would be a nice thing to do ever if not required by law.

They could probably spend all day every day answering these requests. How do they even know it's valid? Could I just request all your information?

> How do they even know it's valid?

They can require you to prove this before processing your application, under GDPR.

Post reply on HN