I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…
> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.
An Eve Online corporation has been hit with a GDPR request from an ex-member
131–140 of 141 posts
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#132Earlier quoted context omitted.
> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.
That's fine. A quote isn't the original speaker's data. It's the quoter's data.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#133Earlier quoted context omitted.
>Like with almost every other Directive, the EU has made a huge mistake by not including de minimis exemptions in the regulation. Proportionality in the GDPR is based on the scale and sensitivity of your data activities. The size of your organisation or your technical capability is irrelevant; if you're not competent to safeguard the data you handle in accordance with the law, the EU doesn't want you to handle it. It…
Hmm. Good examples, but I note that they're both concerned with what the rules call "sensitive" personal data rather than the ordinary kind. The To/BCC one is both very important given the sensitivity of such data and a horrifyingly easy mistake for most organizations to make.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#134Earlier quoted context omitted.
> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.
That's fine. A quote isn't the original speaker's data. It's the quoter's data.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#135Earlier quoted context omitted.
> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.
That's fine. A quote isn't the original speaker's data. It's the quoter's data.
In particular the NYTimes reports on Joe Baddy doing something bad. That article arguably belongs to the NYTimes. Google indexes that article with permission from NYTimes. Right to be forgotten requires Google remove the link to NYTimes even though neither Google's index nor the article at NYTimes belong to user.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#136Earlier quoted context omitted.
1) you're simply wrong, or just don't understand the meaning of the word trading block: https://inshorts.com/m/en/news/european-union-is-worlds-larg... 2) I don't think you understand how GDPR works at all. GDPR says how data about EU citizens has to be processed in a certain way. If you want to do business with EU, you have to comply. If you don't want to comply, you don't get to trade with EU. No one is claiming ju…
I was quite clear what I meant by trading block, I wasn't aware that was a specific term of art, but that's not what I meant regardless and that's clear from my response. I understand it just fine, perhaps you don't understand what I'm saying. No, if an EU citizen comes to my US website, that does not grant the EU authority over me no matter what they claim. I live under US law, not EU law, not Chinese law, not North…
You have it backwards. It's not an EU citizen coming to your US website - it's your US website choosing, willingly, to serve EU citizens. You can also choose to not serve them - that's fine. And yes, EU cannot fine you in any way, there's no legal possibility to do that. However, if your operation was detrimental to EU citizens in any way, EU could ask US to cooperate in asking you to stop. Obviously US has the jurisdiction to do something about it, there's no question about that.
To maybe give a different example - if you were selling something that is legal in US but not legal in EU, advertising it, selling it and shipping it to EU customers could still get you in trouble, because at a certain point EU will ask US authorities to stop you from sending illegal products to their territory. You are not breaking US law, but countries do cooperate in this manner. Same would happen in the other direction - if someone was sending drugs that are completely legal in EU over to US, they wouldn't be braking EU law - but US definitely and absolutely would ask local authorities to find you and politely ask you to stop. Does that mean US suddenly has jurisdiction in the EU? No - but EU would most likely comply with such a request as a matter of international cooperation.
And yes, the same request sent from North Korea or from China would likely be ignored - that boils down to what I said earlier about negotiating power and international respect. EU countries are very likely to comply with requests like these coming from US, and EU can and does request things from US. It has nothing to do with the issue of jurisdiction that you are so very keen on.
>> I don't have to give a damn about EU law while operating my US business in the US.
Again, if your US business does serve EU customers, then you kind of have to give a damn. Just like an EU business has to give a damn about US laws when doing business with US customers. It's really not a difficult concept to grasp.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#137Earlier quoted context omitted.
The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?
Because that would be a loophole to sidestep EU laws? If you offer your services in the EU, you have to respect EU law.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#138Earlier quoted context omitted.
If your business wants to collect my data without providing the safety measures GDPR provides, then fuck your business, I don't want to deal with it or you. Of course if your business doesn't collect our data, there is no issue either way.
Nor do I want to deal with you, so good riddance.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#139Earlier quoted context omitted.
You have to make it clear to people that you're using these technologies and how long you keep their data. You should also explain how you keep this data safe. If you suffer a data breach you have to disclose this, and you are potentially liable for it if you could've protected users from that breach by technological means (applying patches, salting passwords, encryption, and so on). If your breach includes too much…
> a chan user might at worst suffer potential embarrassment being linked to posts Embarassment? People lose their jobs in America for espousing commonly-held conservative views. They can be arrested in Europe for the same thing.
That being said, if your "chan" provides a safe haven for illegal behaviour, you might have other non-GDPR problems as well.
Re: An Eve Online corporation has been hit with a GDPR request from an ex-member
#140Earlier quoted context omitted.
I was quite clear what I meant by trading block, I wasn't aware that was a specific term of art, but that's not what I meant regardless and that's clear from my response. I understand it just fine, perhaps you don't understand what I'm saying. No, if an EU citizen comes to my US website, that does not grant the EU authority over me no matter what they claim. I live under US law, not EU law, not Chinese law, not North…
>>No, if an EU citizen comes to my US website, that does not grant the EU authority over me no matter what they claim. You have it backwards. It's not an EU citizen coming to your US website - it's your US website choosing, willingly, to serve EU citizens. You can also choose to not serve them - that's fine. And yes, EU cannot fine you in any way, there's no legal possibility to do that. However, if your operation wa…
> It's not an EU citizen coming to your US website - it's your US website choosing, willingly, to serve EU citizens.
Wrong, they're coming to my site; I have no way to know they're EU citizens or not, there's a thousand reasons I wouldn't know, it's not like IP is a reliable means. People use vpn's, or EU citizens travel. The burden is not and cannot logically be on me to know where my customers come from. It's impossible to know the citizenship of your customers.
Perfect example, according to the GDPR, an EU citizen travelling in the US who uses my site from the US is still protected by the GDPR; that's horseshit and a technical impossibility; I can't know they're an EU citizen. This law was written by technically illiterate morons.