Live data from Hacker News

Trello handed over my personal account to my previous company

community.atlassian.com

231–240 of 274 posts

Re: Trello handed over my personal account to my previous company

#231
post #213

Earlier quoted context omitted.

Meanwhile on Facebook you cannot create a page for a business(say you work in the marketing department) without linking your PERSONAL account to it. Absolutely fucking insane.

That's a completely different thing. One, Facebook is based around the concept of a real person being behind just about everything - when you administer a group, you can see which person posted the individual company/page posts. Two, nothing can happen to your personal account based on the actions of the company page or other people associated with it.

> One, Facebook is based around the concept of a real person being behind just about everything - when you administer a group, you can see which person posted the individual company/page posts.

So do it the same way every other website on the planet does it: have an organization and users who have roles within that organization. It's beyond aggravating the way they have them so strongly linked.

> Two, nothing can happen to your personal account based on the actions of the company page or other people associated with it.

.... I'm guessing this hasn't happened to you. Yes, they will block your personal account for "certain" infractions committed by the business manager. Nearest I can tell it depends on how you set up the business. If you set up the business FB page first, your personal account is considered primary so all blame flows to it. If you set up the business manager first, and THEN set up the page using the business manager (NOT the page creator), then it won't affect your personal account; and if you invite someone, no, that person's account won't (generally) be affected either.

Except that FB always drives you to create the business PAGE first and LATER suggests the business manager... thus increasing the likelihood of blocks. It's pathological. Especially because you can blocked for nothing other than their AI misidentifies something in an ad or a post, kills all your accounts, and then you have to beg to get them back.

Point is, that relationship shouldn't exist in the first place.

Re: Trello handed over my personal account to my previous company

#232
post #103

I have a single E-mail account that I use for everything. I decided more than ~20 years ago that my E-mail is tied to my identity and not to any particular E-mail service or employer, and I started managing my E-mail myself. Trello just notifided me that: > At least one of the email addresses linked to your account belongs to an organization: [...] > This usually means it's a work email. If this organization begins u…

If you only use a single email address and you manage it yourself, how does one of the email addresses on your account belong to an organization?

Re: Trello handed over my personal account to my previous company

#233
post #110

Earlier quoted context omitted.

I’m not sure I agree. I have provided GDPR consulting in the UK over the last three years. What exactly do you think was a violation?

If the boards contained personally identifiable information and then that data was transferred so that other people could access it, wouldn't that be considered a data breach? I guess people affected by this could submit a subject access request to get their data back.

> If the boards contained personally identifiable information and then that data was transferred so that other people could access it, wouldn't that be considered a data breach?

I believe so, however this doesn't constitute legal advice (etc, etc)

Re: Trello handed over my personal account to my previous company

#234

In this day and age, sharing this community forum discussion here is the only way to get resolution. I'm happy helping people out and tweeting my displeasure with companies, but we need some way to scale this. We can't just help the people that get enough publicity. We think we're helping, and we are, but only a small amount of situations end up getting front paged.

I wonder if a communication model like Amnesty International would work here.

Re: Trello handed over my personal account to my previous company

#235

Seems like unpopular opinion given comments on this thread, but here it is anyway. Using my employer's email addresses for services I want to control doesn't sound right. Of course, LinkedIn is a different story but for SaaS platforms like Trello, my employer should be the rightful owner of the data I store in there if I used it for work. Imagine the other scenario, if that Trello account's control didn't move to the…

I believe that is not entirely true. Here is the explaination https://news.ycombinator.com/item?id=22874704

Re: Trello handed over my personal account to my previous company

#236

You're a special kind of person if you are concerned about the privacy of your account and also enable your company's SSO on your account. I don't disagree that the conclusion of the story is that it sucks, but the moment you meld your private stuff with your company stuff you're asking for it. I generally have little sympathy toward people expecting privacy on assets provided by the company, wether that be hardware…

Would you consider changing your opinion given more context https://news.ycombinator.com/item?id=22874704

Re: Trello handed over my personal account to my previous company

#237
post #224

Earlier quoted context omitted.

> They used to create an account using my professional contact email without asking, of course I don't understand how this is an issue. Just don't confirm the account. Or are there SaaS platforms where you can add users with arbitrary emails without confirmation?

Of course there are! And it's all part of SV culture. A few years ago I tried to sign up to LinkedIn only to find out I already have an account. But it was not my account - it was someone else's, who has a similar name (and apparently thought my email address was his? I don't know...). I could reset the password and log in to his account. I was a bit scared when I contacted LinkedIn support, because I was worried the…

Funny, this happened to me before: some guy from Colombia used to operate his twitter from my @hotmail.com account. This was before 2009.

Ironic, considering that Twitter has started requiring phone validation recently!

Re: Trello handed over my personal account to my previous company

#238
post #156

Earlier quoted context omitted.

> GDPR protects personal data, which the EU interprets very broadly. This isn't accurate. Individual member states can and do interpret the GDPR differently. For a European company, the country they are "at home to" is the one that will govern them, not the state that the individual belongs to. If the company is not "at home" in the European Union (for example, because it is in the US and has no European offices and…

Personal data is data that identifies a natural person, or that can be used to identify a natural person, not that is produced by a natural person. What do you think the new subject access rights, notably the right to data portability, are intended to achieve, if you interpret the definition of personal data so narrowly? The GDPR actually defines personal data as "any information relating to an identified or identifi…

> What do you think the new subject access rights, notably the right to data portability, are intended to achieve, if you interpret the definition of personal data so narrowly?

I am not going to speculate.

> The GDPR actually defines personal data as "any information relating to an identified or identifiable natural person (‘data subject’)...", which is significantly different to what you wrote.

I can't speculate on what you think qualifies as "significantly different". I copied and pasted my definition from the ICO's website, which I also linked to. You can disagree with them, but I suspect strongly, even in the current Brexit climate, that the EU courts would agree with the ICO's interpretation over yours.

You might find the part that follows the "..." useful though. It's in Article 4 § 1, if you're unaware.

> It seems to be widely understood, including acknowledgement in various statements by EU officials, that these provisions were aimed squarely at businesses like social networks to avoid them locking users in by holding the user's data hostage. That seems to be exactly the scenario we're talking about here.

That may be part of your confusion. "We" weren't talking about anything to do with social networks, but whether a GDPR regulator is going to levy a heavy fine to Trello for this behaviour.

Re: Trello handed over my personal account to my previous company

#240

Earlier quoted context omitted.

That's ugly, I'm sorry. It's also why I oppose using social authentication with anything. While we have access to our [Facebook, Twitter, Github, Google, LinkedIn] account today, what happens if they shut it down? We have no clue of the real consequences and no appeals process. It's the worst of both worlds.

That’s one of the motivations for the “new” project Tim Berners Lee is working on, Solid. The amount of foresight people working on the web have is crazy. I read an article interviewing Lou Montulli the other day and was amazed to find out how how extensively he thought about the nefarious use of cookies when they were being designed

Can you share the URL for that interview with Montulli, please? Thnx!
Post reply on HN