Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

201–210 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#201
post #99

Earlier quoted context omitted.

> I thought that this was allowed. No, that's one of the big wins of GDPR. You cannot just force the users to sign away their rights.

How is giving choice between paying with money or paying with data forcing users into signing their rights away?

I'm not sure if I've ever seen such choice being offered in the first place. It's always either "pay with your data or don't use it at all", or "pay with your money and your data, or don't use it at all".

Also, prior to GDPR, the "pay with your data" aspect wasn't even mentioned by the companies. Ultimately, GDPR doesn't prevent people from donating their data - it just requires that it's explicit and not mandatory.

Re: Grindr to be fined almost €10M over GDPR complaint

#202
post #19

Great news! They have been preying on a very vulnerable community.

Why do you say that? The app was founded in LA where I wouldn't describe the gay scene as vulnerable. Is the situation in Normay different?

And why would you say LA is 100% gay friendly? There's absolutely no hate crime? Absolutely every gay or LGBT person is perfectly happy with the intimate details of their sex life being shared? Every person who isn't openly gay is happy with their identity being shared?

Re: Grindr to be fined almost €10M over GDPR complaint

#203

Earlier quoted context omitted.

Well, now the GDPR gives you 10% of your revenue as a reason for not using SDKs that will not give you control of data collection. You always had "respect the privacy of users" as a reason not to use them before, but we all know how well that worked.

The problem here is that if you want to implement Facebook login in your app, you have to include the SDK. It is against ToS to do it any other way.

Then don't implement Facebook login in your app, unless SDK becomes adapted to make its use GDPR-compliant. It's really a problem between you and Facebook at this point.

Re: Grindr to be fined almost €10M over GDPR complaint

#204

Earlier quoted context omitted.

What kind of financial losses are we realistically talking about from being denied such tracking? what kind of percentages of lesser revenue?

Probably net zero, as long as everyone follows the same rules. Advertising is a zero-sum game, and changing the height of the playing field shouldn't impact relative revenue all that much.

As an advertiser, not true at all. Promoting products to any niche smaller than "man" or "woman" basically requires targeted advertising to make work.

Re: Grindr to be fined almost €10M over GDPR complaint

#205
post #78

Earlier quoted context omitted.

There's no special protection for LGTB, but sexual orientation is considered sensitive information. If you tell advertisers (implicitely or explicitely) whether a user is gay or straight, that requires explicit consent.

That is quite silly if it truly be so — are we moving to the Anglo-Saxon “protected classes” model now? If I understand this correctly, it is not a problem, or a lesser or different problem if such a company share that a client finds being stroked on his earlobes to be highly arousing, or is a big aficionado of the “big black cock”, as those are not “sexual orientations”? That seems like a rather arbitrary distinctio…

I just looked up the relevant section in the GDPR, and it's actually pretty clear:

It's section 9 "Processing of special categories of personal data"

https://gdpr-info.eu/art-9-gdpr/

> 1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited

> 2. Paragraph 1 shall not apply if one of the following applies:

> (a) the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject;

> (...)

Re: Grindr to be fined almost €10M over GDPR complaint

#206
post #29
post #27

Earlier quoted context omitted.

Also, EU has a ruleset adapted to the climate of central Europe and not to cold places where almost no food grows and eating seals and fighting polar bears is how you stay alive. This is an extreme example, but Norway is more dependent on fish for sustenance than many other countries.

> eating seals and fighting polar bears is how you stay alive Your image of Norway may be a bit off.. It's true though that Norway is overly protective of its food industry. And arguably for good reason since it wouldn't be competitive at all if integrated with the rest of Europe.

I am Norwegian, apparently I just didn't express myself clearly enough.

Re: Grindr to be fined almost €10M over GDPR complaint

#207

Earlier quoted context omitted.

I'm baffled by the number of companies that should not have any need for third-party cookies and still go full-on dark pattern. In particular online shops: I'm already on their site, why would they loudly advertise "we're shady and want to trick you into selecting all cookies"? I've cancelled more than one purchase because I didn't want to bother with this.

It's certainly down to bad legal advice. Lawyers are trained to take everything they can get. If it turns out that was too much, then they frame it as a bargaining chip, as leverage to at least recover some fraction of what they previously took. It's sneaky, immoral, unethical and illegal. It also works.

Taking everything one can get is not exclusive to lawyers. Many engineers would rather have more information/data than not enough. Better yet get all the data up front and then decide what you need later.

Re: Grindr to be fined almost €10M over GDPR complaint

#208

> Consent must be unambiguous, informed, specific and freely given. A bit ironic, for a dating app.

If I'm not wrong, dating apps are among the worst for user privacy. Google `dating apps user privacy` and you'll find no shortage of news articles.

Are you perhaps talking about services owned by Match group[1]? Though Grindr is not on the list, so maybe unrelated services are the same.

[1] https://en.wikipedia.org/wiki/Match_Group#Dating_services_ow...

Re: Grindr to be fined almost €10M over GDPR complaint

#209
Question in regards to the user consent pop-ups on websites: On sites that continue to let you browse without making a selection (say the consent banner in on the bottom of the browser window), If I don't make any choice, accept or reject, what happens? Am I giving consent by default?

Re: Grindr to be fined almost €10M over GDPR complaint

#210

The GDPR has always amazed me. It changed the playing field from "you can use our free app as long as you give us data for marketing or not use it" to "you can provide a free service in the EU as long as you dont collect data for marketing or dont provide it" Without making a judgement on the merits of the approach, as a user/individual I appreciate the power this gives to protect my data. As a company/developer the…

I see this as a "it's so hard to run a business with all these rules" argument. We both know rules are extremely clear and simple. They get complicated when companies try to go around them.

Same whining in finance. Every loophole is ruthlessly exploited, shady tactics employed, malicious compliance or borderline fraud are commonplace. The legislature changes to address that => the actors kvetch about red tape.
Post reply on HN