Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

111–120 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#111
post #19

Earlier quoted context omitted.

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere. It's probably the same reason why Hacker News does nothing to comply with the GDPR.

Jurisdiction is a tricky concept in cases like these where we are dealing with digital content. AggregateIQ could have ignored the GDPR-request, ignored any rulings and keep chugging along as long as they stuck to Canada (assuming Canada was not going to side with the EU). In short, if you're not in the EU, do not care about EU and never will, you can largely ignore the GDPR. Same as if some banana republic dictator…

>In short, if you're not in the EU, do not care about EU and never will, you can largely ignore the GDPR.

That's not entirely true. You can go to a Canadian court to enforce an EU judgement against assets in Canada. So for example, if you cause a car accident in Germany, the plaintiff can sue you in Germany to get a judgement and then sue you in Canada to enforce that judgement. How Canadian (or US or otherwise) courts will treat a GDPR judgement remains to be seen, but it's not a guarantee that it won't be enforced.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#112

Earlier quoted context omitted.

> America set the precedent with arresting foreign nationals for breaching US laws while on foreign territory with Dmitry Sklyarov It set the precedent for arresting foreign national for breaching US laws while on foreign territory considerably before Sklyarov's arrest in 2001; some notable prior examples include Humberto Alvarez Machain (1985) and Manuel Noriega (1989), though they weren't the earliest, either. Inso…

In which case Americans who haven't broken American law by ignoring GDPR requests from their EU clients should not be surprised if they are arrested if they ever go to Europe.

AFAIK, GDPR is a regulation with civil financial penalties, and not a criminal law, so, yes, anyone should be surprised if they are arrested for violating it.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#113
post #25

The subtitle is "[d]isgruntled ex-guildie effectively invents new way to grief in EVE" but it sounds like the request in question was sent to a website outside of EVE. This could happen with other games or, you know, websites unrelated to games at all...

Corp (guild) forums are an important part of EVE and preferred over posting news and operations on Discord for example since you can set it up to serve unique texts to each user, making it easier to find them if they leak to other corps, and hidden changes in the website that will give it away in case the corp news leak by screenshot.

/sidenote

I've tried playing Eve quite a few times, and it just isn't my thing. Reading about Eve, however, has always been an absolute joy.

Even comments like this (which makes complete sense in hindsight) shows me how much (for better or worse) people put into a "sandbox" or game like Eve.

I swear some of the stories are much better than the stuff they toss in theatres.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#114
post #103
post #101

Earlier quoted context omitted.

> Perhaps some people will say "good, if you cannot run a site conforming to all laws of the land then you should shutdown". If you think that, consider this: as these laws pile up it will get more and more difficult to operate, leaving only the very tech/law savvy, and big business. Some things are too dangerous to the public to allow part-time hobbyists to do. We don't allow part-time hobby doctors, or lawyers, or…

You realise this is equivalent to "the decentralised social web cannot be allowed to exist", and heading in the direction of "the public cannot be allowed general purpose computers"? Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. In practice this isn't a problem in most countries because there isn't enforcement against tiny operators ei…

>Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation.

Proportionality in the GDPR is based on the scale and sensitivity of your data activities. The size of your organisation or your technical capability is irrelevant; if you're not competent to safeguard the data you handle in accordance with the law, the EU doesn't want you to handle it. It's exactly the same principle we'd apply to toxic waste - you're not allowed to dump it in the woods just because you're a small business or a hobbyist.

Some examples of why there is no de minimis exemption:

A small charity accidentally sent a newsletter using "to" rather than "bcc". In doing so, it accidentally revealed the identities of 56 people who are HIV positive. It was fined £250 by the Information Commissioner's Office, because of the small size of the organisation and because the ICO was satisfied with steps taken to prevent further breaches.

https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...

A non-profit trade organisation with a single employee worked to facilitate information sharing between construction companies. That information consisted of files on trade unionists, political activists and advocates for health and safety, constituting an effective blacklist of "known troublemakers". The organisation's files were seized by the Information Commissioner's Office, leading to enforcement notices against 14 construction businesses; settlements under the Data Protection Act totalled over £50m.

https://en.wikipedia.org/wiki/Consulting_Association

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#115
post #55

Earlier quoted context omitted.

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

And others would say it is unreasonable for businesses to store user data without consent and with no way to remove it. Please explain why any arbitrary site should have the ability to store user data without consent and then refuse to delete sensitive information. Are you going to accept liability if that data is leaked? If I walk into a store, can they copy my drivers license and phone number without asking me, and…

I can store anything you give me; that you exposed me to it is consent, it's not your data unless you keep it to yourself. When you walk around a public space, you don't get to control who looks at you and logs it. The products of my labor are mine, and that includes whatever I log in public spaces.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#116
post #103

Earlier quoted context omitted.

You realise this is equivalent to "the decentralised social web cannot be allowed to exist", and heading in the direction of "the public cannot be allowed general purpose computers"? Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. In practice this isn't a problem in most countries because there isn't enforcement against tiny operators ei…

>Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. Proportionality in the GDPR is based on the scale and sensitivity of your data activities. The size of your organisation or your technical capability is irrelevant; if you're not competent to safeguard the data you handle in accordance with the law, the EU doesn't want you to handle it. It…

Hmm. Good examples, but I note that they're both concerned with what the rules call "sensitive" personal data rather than the ordinary kind.

The To/BCC one is both very important given the sensitivity of such data and a horrifyingly easy mistake for most organizations to make.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#117
post #55

Earlier quoted context omitted.

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

>> Fuck the GDPR, they have no more authority over me than China or North Korea does. You are probably not trading with North Korea, so ignoring their laws has zero impact on anything. China is already getting more tricky though, although they are not choosing to throw their entire weight behind enforcing their demands abroad(yet). But ignoring the demands of the largest trading block on the planet? That's not going…

The EU is not a single trading block; it's many many individual trading blocks all different cultures and languages; the US is the single largest trading block in the world. And no, the GDPR is awful legislation, the notion that every foreign country can simply declare jurisdiction over other countries citizens violates national sovereignty is and flat out disgusting and will not stand.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#118
post #115

Earlier quoted context omitted.

And others would say it is unreasonable for businesses to store user data without consent and with no way to remove it. Please explain why any arbitrary site should have the ability to store user data without consent and then refuse to delete sensitive information. Are you going to accept liability if that data is leaked? If I walk into a store, can they copy my drivers license and phone number without asking me, and…

I can store anything you give me; that you exposed me to it is consent, it's not your data unless you keep it to yourself. When you walk around a public space, you don't get to control who looks at you and logs it. The products of my labor are mine, and that includes whatever I log in public spaces.

Even in the US which is hardly a bastion of consumer privacy that’s not true. If you as a hotel owner stick cameras in every shower you should expect a set of lawsuits, even though that’s your property and the people have knowingly bought a service from you.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#119
post #115

Earlier quoted context omitted.

I can store anything you give me; that you exposed me to it is consent, it's not your data unless you keep it to yourself. When you walk around a public space, you don't get to control who looks at you and logs it. The products of my labor are mine, and that includes whatever I log in public spaces.

Even in the US which is hardly a bastion of consumer privacy that’s not true. If you as a hotel owner stick cameras in every shower you should expect a set of lawsuits, even though that’s your property and the people have knowingly bought a service from you.

A hotel room is not a public space.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#120
post #119

Earlier quoted context omitted.

Even in the US which is hardly a bastion of consumer privacy that’s not true. If you as a hotel owner stick cameras in every shower you should expect a set of lawsuits, even though that’s your property and the people have knowingly bought a service from you.

A hotel room is not a public space.

Neither is a store or a website, which were the examples used. But we can translate the same example given to public spaces easily: you install a hidden camera in a grating in a public square and take upskirt shots of women walking over. That’s illegal at a federal level in the US so people absolutely have a legal right to control your ability to do that.
Post reply on HN