Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

81–90 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#81

Earlier quoted context omitted.

Your legal concept isn't valid. Hacker News can comply with GDPR today and choose not to comply the next day. They forfeit nothing in the process of selectively abandoning GDPR, in regards to being governed by US law and not EU law. If my company is located in the US and only governed by US jurisdiction (eg I do not operate in the EU in any manner), there's no such concept as admitting the EU has jurisdiction over my…

I think we mostly agree, especially when you bring China into it. However, isn't the idea of forfeiting the personal jurisdiction defense? I am not a lawyer, but from what I understand, once you start debating the merits of the case, you waive the ability to claim that the court doesn't have jurisdiction. It seems like there's a bit of a chance of that here - once you admit the EU or Chinese legal system is the appro…

A GDPR Deletion Request is not a court case, it's a non-formal notification that you want someone to delete data about you.

If someone follows that request and if the EU has jurisdiction are orthogonal issues; plenty of services offered deletion before the GDPR.

The question of jurisdiction will come up if you ignore requests or otherwise violate the GDPR and a national agency that is responsible for handling violations contacts you.

In which case you can still choose to ignore them, if you're not on EU soil, then it's up to the extradition or similar laws on what happens; the agency will likely file a court case (or you file), then the court will handle out the details with your national legal system; in most cases this means nationalizing any punishment. Ie, the court case will be handled and if you don't show up after being invited, will be ruled upon in your absence. Then the fine will be forwarded to your country where the courts in your country with your countries jursdiction will then collect it, probably take a fee and then forward the remainder back to the EU. An alternative outcome would be that the entire court case is moved into your country.

Either way, complying to GDPR-related requests doesn't mean admitting jurisdiction of the EU; disagreeing the responsible government agencies involved is a good way to test if those have jurisdiction.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#82
post #24

Earlier quoted context omitted.

Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.

If you run a website, is "not blocking users from the EU" considered as providing services in the EU? I am genuinely curious because in that case GDPR seems to impact many companies disregarding whether they actually do any business here.

If you offer a Czech or Polish translation, probably: yes

If you offer a French or Spanish translation: maybe

If you run ads in Germany: certainly

If you advertise accepting Euro: most likely

If you embedded ads from an ad network which sends localised ads to Europeans: most likely

When having a site reporting news on local events in an African municipality most likely not.

There is no clear line, as writing that down is impossible and always requires judgement. Also the question is whether EU can enforce it. If you have no European subsidiary and live abroad there is little they can do.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#83

What's interesting, and pointed out by a Reddit comment: https://www.reddit.com/r/legaladvice/comments/acsdf3/comment... There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove…

This right of access to your personal data has existed in the EU for 20 years. This is not new.

And yes, there is a need to verify IDs. Most companies don't have online forms for this so the way has always been to send an email and enquire, or to write on paper with a copy of a valid ID.

This is not new.

The question is whether data submitted under a pseudonym (e.g. forum activity) are actually personal information by law since the individual cannot be identified.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#84
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

>Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO

This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sentence opinion comment which I posted under my real name. I didn't stop to think for a minute that it would cause me any problems.

It did. I discovered that I couldn't get to work on any government projects because when a background check was carried out on me, the above comment was found and according to Revenue (the gov agency responsible for such checks) it indicated that I was hostile to the governments IT plans.

I asked the blog owner (same country as me) to please remove the comment, they refused. So I submitted a right to be forgotten request to Google to stop the blog post appearing in searches for my name.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#85
post #8

Earlier quoted context omitted.

Why should a European citizen abide by the laws of a different country (which may be illigal in their country BTW)

They shouldn't, but it's not their problem. If I, as the prince of Princeton, was to pass a law that each time one of my subjects visits your website, you must pay me $1, you'd think that's mad. And you'd be right - since you're not bound by Princeton laws. The EU is claiming that sites in other countries are bound by EU laws - and that's just as wrong as if Princeton passed the laws.

The US as a ban on banks to do business with Iran. This also affect bank that are not US-based but do business with US (see [1]). The banks are free to do business with Iran, but they will then get ban from doing business in the US.

The GDPR is exactly the same. EU says that you have to comply with the GDPR if you process EU-citizen data. So company have the same choice: Comply with the EU GDPR or don't do business with the EU. I don't think it happen yet, and I think that the framework for this is not even ready yet, but nothing would prevent EU from banning your service in the EU if you don't want to comply with the EU GDPR.

I honestly don't understand why there is such an outcry about it. It always worked like this: you want to do business with a country, you apply the law of the country. Internet is not a magical international space with no regulation.

You can argue that this kind of laws, that is a form of protectionism in a way, is bad. But it has been this way for a very long time and GDPR is absolutely not the first time such a law was put in place.

Just another example, if you are a US citizen creating a bank account in the EU, the bank (even if it is a EU bank), will have to declare it to US authorities (apparently due to your tax system that also apply if you are resident abroad).

[1] https://en.wikipedia.org/wiki/United_States_sanctions_agains...

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#86

Guys think about the ranking lists.. you want your data deleted and you kind of also have to delete all related data to that account like everything. I can imagine already some people hacking top 100 ranking list accounts and deleting them to remove them from the ranking to get elevated themselves.

You don't have to delete everything. In case of ranking lists, it would sufficient to tombstone the data; replace the name with "[deleted account]" and link it to a page that explains the account data was requested to be deleted.

GDPR Deletion Requests only cover data for which's processing you either used consent, used the legitimate interest clause or is part of a protected category (sexuality, religion, etc.). Some parts of "legitimate interest" that continue to be legitimate interest (like for example, billing information for tax and fraud prevention) you may continue to keep it around as well.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#87
post #53

Earlier quoted context omitted.

Kim Dotcom and Megaupload is probably the biggest current and ongoing counterargument. But it's been standard behavior in other cases.

Which is why I added rarely; personally I was thinking of thepiratebay trials in Sweden. I do believe both Mega and TPB are as a result of breaking US law but TPB was at least tried in Sweden and found to be breaking Swedish law, not sure if the same goes/went for Kim.

The question is: Are you breaking the Swedish law while targeting Swedish people?

For isntance: Germany has laws around limiting usage of Nazi symbolism. If you create a web page glorifying Nazis and their symbols this is illegal under German law. If you run such a site targeting Americans no German state attorney or Court will take the case (exceptions exist for stupidity or ego or power play reasons) however if you host a page in the U.S. aiming at German Nazis that way (for example by commenting on German politics and German language) they will try to go after you. (Which might not lead far, as the site is probably protected by US freedom of speech, thus US authorities won't assist, but you might want to avoid travelling to Germany and countries which might cooperate with Germany)

P.S. I don't want to imply that you have any such plans for such a site, but it's a specific example working fully virtual

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#88
post #34

How would this work if the data was stored on an immutable blockchain?

Storing it on an immutable blockchain probably violates the GDPR in the first place, at least if you have no method to render the data unreadable.

To wit, Article 25 of the GDPR ("Data protection by design and by default"):

> 1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.

> 2. The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#90
So the GDPR is only about personal data? What are my responsibilities if I run a chan, i.e., I store no personal data about my posts other than the IP address where they originated? What if I use some tracking technology such as a cookie or localStorage to identify unique browsers regardless of their IP address?
Post reply on HN