Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

171–180 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#171
post #160
post #156

Earlier quoted context omitted.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine. All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt. The idea that we should hold companies that profit off people's personal data b…

I used to have a website that did stuff with GPS data that was uploaded by users. It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat. Those ads probably made it a for profit business. I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so. Those are the kind of websites that you lose. I consider that a loss.

GDPR doesn't prevent you from collecting personal data. It only requires you to have a clear reason for collecting everything and being transparent about what data is collected and how it is processed.

Re: GDPR Enforcement Tracker: List of GDPR fines

#172
post #106
post #13

Earlier quoted context omitted.

Austria has had a ban on dashcams for years, though, so it is not a new thing brought by GDPR. Another EU country with a similar ban is Luxembourg.

Based on this article [1], it looks like EU country laws on dashcams ranges from similar to the US, to legal but with restrictions on the duration, retention, or use of the footage, to illegal to use subject to fines, to illegal to use subject to prison, to illegal to even own one regardless of whether or not you are using it. How aware are EU drivers of these differences? Is it well known to those in places with les…

It's basically impossible to know. Even laws which should be really clear, such and if and when you need winter tires are not clear.

At the end of March I drove across Europe from south of Spain, and had summer tyres on. The weather conditions were good, so I was fairly confident I would be ok without winter tyres, but a lot of European countries have laws requiring then at certain points of the year.

I knew in my destination country you needed winter tyres until April 1st, but I couldn't find anything clear on all the countries in-between. Austria was actually the toughest, my understanding is their laws are you need winter tires if the road conditions dictate you need them. In some cases snow chains can be used, but not on highways. But this was based on reading English forum posts from 10 years ago, so I have no idea if it's still correct. I tried to find something clear from an official authority (probably doesn't help I don't speak German) or an automobile association website, but couldn't.

Re: GDPR Enforcement Tracker: List of GDPR fines

#173
post #160

Earlier quoted context omitted.

I used to have a website that did stuff with GPS data that was uploaded by users. It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat. Those ads probably made it a for profit business. I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so. Those are the kind of websites that you lose. I consider that a loss.

Why could GDPR possibly make someone shutdown such a website? Pure FUD. EDIT: Downvotes don't change reality. The OP is spreading FUD. Edit: unless the website was actually abusing users privacy in which case I'm glad it is gone.

Well, suppose he does some transformation involving position. GPS points also have altitude in them. He neglects to sanitize altitude at the point of collection, and is therefore collecting and retaining more data than necessary to perform the service. He plots positions on a relatively zoomed-out map. Only the first six significant figures make a perceptible difference in the map position, but he retains the same precision that was uploaded, usually higher. Again, failure to minimize. Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.

Now he has "decided to build a business around profiting from the abuse of personal data" and the consensus in this thread looks on his destruction with glee.

Re: GDPR Enforcement Tracker: List of GDPR fines

#174
post #89

Earlier quoted context omitted.

Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…

> We have no idea how many attempts and warnings to get them to comply were sent first. True. But I doubt that even the most ruthlessly efficient GDPR enforcement authority could multiple enforcement requests between mid July and end July.

They almost certainly got complaints from the users on that list. You tend to get pretty swift response from that.

Very likely that they just ignored it.

Re: GDPR Enforcement Tracker: List of GDPR fines

#175
post #94
post #58

Earlier quoted context omitted.

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…

> unless you're sure you that can afford making these kinds of mistakes, don't provide a service on the internet DOT sounds good

What does DOT mean?

Re: GDPR Enforcement Tracker: List of GDPR fines

#176

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

> This seems to be proof that the GDPR is being weaponized against people and organizations one doesn't like.

Well, against people who publicly share private info of 150 other people who trusted them those emails. 2K euros is not that huge money in Germany, it's not like they'll loose their house over it, and that certainly is a practice that needs to be stopped. Just being an amateur is not an excuse when you deal with other peoples' data.

Re: GDPR Enforcement Tracker: List of GDPR fines

#177
post #171
post #160

Earlier quoted context omitted.

I used to have a website that did stuff with GPS data that was uploaded by users. It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat. Those ads probably made it a for profit business. I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so. Those are the kind of websites that you lose. I consider that a loss.

GDPR doesn't prevent you from collecting personal data. It only requires you to have a clear reason for collecting everything and being transparent about what data is collected and how it is processed.

The examples here make clear that "a clear reason for collecting everything" means an ironclad justification for each field, each bit of precision, each minute of retention. That is not a casual thing. As in, one of the fines here is for retaining a phone number to fulfill a need to communicate, when postal mail could have worked instead.

It is doable, if you have the lawyers and the time. But that's not a degree of scrutiny you want to gamble your life savings on for a personal project.

Re: GDPR Enforcement Tracker: List of GDPR fines

#178

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

If the story linked elsewhere in this thread is the one in question, this wasn't an accident. It was a guy running some kind of harrassment campaign. His "little mailing list" was of people he was harrassing, not subscribers to a newsletter.

https://www.rosepartner.de/blog/bussgeld-fuer-offenen-e-mail...

Re: GDPR Enforcement Tracker: List of GDPR fines

#179

Earlier quoted context omitted.

You don't seem to have brought up any cases where we know that fines were imposed without a warning, nor any reason to believe this particular case was special. If, out of all the cases that we do know whether warnings were issued, warnings were in fact issued in the vast majority of them (or even 100% of the known cases), then for a case where we don't know and have no reason to believe is special, isn't the reasona…

Once again, under GDPR, it is entirely legal to issue fines without a warning. Therefore, in any case where it does not say that there was a warning, one can reasonably assume that no warning occurred - especially given that in some cases (according to you, most cases) they did say something about a warning. The absence of the mention of a warning in this context implies that there wasn’t one. The point is, and no on…

Once again under UK drug law it is entirely legal to send someone to prison for five years (I think) for an eighth of weed. Except it never happens. To get straight to a maximum penalty there would be very damning circumstances.

It's why we have regulators, judges and magistrates - to apply judgement and proportionality. Sure there's a few headline cases of some absurdly harsh sentence - and just about always the details reveal there were a lot of very damning circumstances that make the sentence seem pretty reasonable.

Do US judges rubber stamp a maximum sentence each and every time? No. Does every visit by police result in prosecution? No. Is every warning and scaling mechanism offenders get in the US expressed perfectly in statute? No. Otherwise you would have fired all the judges as surplus to requirements.

You're just spreading FUD. Understand the legal system in Europe before spreading such rubbish.

Re: GDPR Enforcement Tracker: List of GDPR fines

#180

Earlier quoted context omitted.

Why could GDPR possibly make someone shutdown such a website? Pure FUD. EDIT: Downvotes don't change reality. The OP is spreading FUD. Edit: unless the website was actually abusing users privacy in which case I'm glad it is gone.

Well, suppose he does some transformation involving position. GPS points also have altitude in them. He neglects to sanitize altitude at the point of collection, and is therefore collecting and retaining more data than necessary to perform the service. He plots positions on a relatively zoomed-out map. Only the first six significant figures make a perceptible difference in the map position, but he retains the same pr…

> Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.

This is typical FUD. GDPR allows backups. Right to be deleted doesn't mean grovelling through backups. If those snapshots are rotated out after e.g. 3 months he is fine.

And regarding sanitizing altitude. Again pure FUD. There is no way that that would be a problem.

Of course if he stores the data in a personally identifying way and then is either incompetent or abusive then he could attract a fine...

In the real world GDPR enables such websites because users can trust that he has to follow some minimum standards.

Post reply on HN