Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

101–110 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#101
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business.

Some things are too dangerous to the public to allow part-time hobbyists to do. We don't allow part-time hobby doctors, or lawyers, or banks, or toxic waste disposal services, and most of us think that's the correct tradeoff. GDPR puts processing people's personal data in the same category; given how much damage a careless processor of personal data can cause, that seems appropriate.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#102

Earlier quoted context omitted.

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

>Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sente…

Ireland? In Ireland, civil servants are not allowed to express political affiliation or opinion, so rather than it being a case of "we don't like what you said", it would be a case of "you said something political, and it persists."

I'm not sure if the contract for Revenue is exactly the same as the civil service, but I would presume on this front it is very similar.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#103
post #101
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

> Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business. Some things are too dangerous to the public to allow part-time hobbyists to do. We don't allow part-time hobby doctors, or lawyers, or…

You realise this is equivalent to "the decentralised social web cannot be allowed to exist", and heading in the direction of "the public cannot be allowed general purpose computers"?

Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. In practice this isn't a problem in most countries because there isn't enforcement against tiny operators either, but the fear and confusion it creates is very real.

(On the other hand, without this kind of thing you get phone companies selling your real-time location to criminals. If only there were such a thing as a sense of proportion)

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#104

What's interesting, and pointed out by a Reddit comment: https://www.reddit.com/r/legaladvice/comments/acsdf3/comment... There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove…

Isn't this solved by making "Delete My Account" a self-service button on the user account page?

It really should be automated anyway. PII for billing and contractual reasons isn't covered by the right to be forgotten (as I read the regulations) because they're required for other legal reasons.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#105

Earlier quoted context omitted.

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

>Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sente…

> I discovered that I couldn't get to work on any government projects because when a background check was carried out on me, the above comment was found

Well, that's kind of Orwellian.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#106
post #55
post #45

Earlier quoted context omitted.

> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...] If it's only due to technical skills then this problem can be solved technically. The forum software needs to enable people to be GDPR compliant. > On a semi-related note: if you are a small SASS operator wantin…

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

If this is your attitude, then your business is an unreasonable burden on me and I hope you go under.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#107
post #90

So the GDPR is only about personal data? What are my responsibilities if I run a chan, i.e., I store no personal data about my posts other than the IP address where they originated? What if I use some tracking technology such as a cookie or localStorage to identify unique browsers regardless of their IP address?

"Personal data" is defined differently in the GDPR than in most US legislation.

>‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

An IP address or tracking cookie is an identifier. It is not, in isolation, personal data. The other stuff you store like posts and access logs become personal data if those identifiers allow you to associate that stuff with a natural person. If you strip the data of identifiers to the extent that it can no longer be connected to anyone, then it ceases to be personal data within the scope of the GDPR.

https://gdpr-info.eu/art-4-gdpr/

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#108

Earlier quoted context omitted.

America set the precedent with arresting foreign nationals for breaching US laws while on foreign territory with Dmitry Sklyarov

> America set the precedent with arresting foreign nationals for breaching US laws while on foreign territory with Dmitry Sklyarov It set the precedent for arresting foreign national for breaching US laws while on foreign territory considerably before Sklyarov's arrest in 2001; some notable prior examples include Humberto Alvarez Machain (1985) and Manuel Noriega (1989), though they weren't the earliest, either. Inso…

In which case Americans who haven't broken American law by ignoring GDPR requests from their EU clients should not be surprised if they are arrested if they ever go to Europe.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#109
post #103
post #101

Earlier quoted context omitted.

> Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business. Some things are too dangerous to the public to allow part-time hobbyists to do. We don't allow part-time hobby doctors, or lawyers, or…

You realise this is equivalent to "the decentralised social web cannot be allowed to exist", and heading in the direction of "the public cannot be allowed general purpose computers"? Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. In practice this isn't a problem in most countries because there isn't enforcement against tiny operators ei…

> You realise this is equivalent to "the decentralised social web cannot be allowed to exist"

I'd put it as: the decentralised social web cannot be allowed to exist unless and until a way to do robust privacy enforcement on it can be found.

> and heading in the direction of "the public cannot be allowed general purpose computers"

Slippery slope fallacy. GDPR exists not out of some abstract desire to regulate but as a response to the massive privacy breaches that have directly affected the general public. If and when general purpose computers are shown to have a similar negative effect on society, we can have a conversation about whether regulating them is appropriate given the costs and benefits of doing so.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#110
post #35

Earlier quoted context omitted.

Responding to myself: Of course, this could have been the intention all along. It has long been recognized that big business loves difficult to conform with regulations (regardless of their protestations otherwise) because it is hard for smaller competitors to breach the effective moat that heavy/complex regulations provide incumbents.

It is quite easy to comply with GDPR - store as little data as needed - protect the data in state of the art ways - make transparent what you store and process and why - establish a process to delete data once it's not needed anymore It is only complicated if you want to build a company around the abuse of data, as common in the ad world.

How about "data accuracy" - you are obliged to make sure that data you store are accurate and be able to prove that you've asked users to confirm that data are accurate.

How about the duty to export user data on request?

How about player consent management? Consent updates, etc.

Those are not simple thing neither to implement nor to manage, especially if someone will accuse you and you need to prove that you are compliant.

Post reply on HN