Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

231–240 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#231
post #2

Note that this is 10% of revenue so it is quite substantial.

And 30% of profit, looks like: > Authority imposes a fine of 100 Mio NOK (€ 9.63 Mio or $ 11.69 Mio) on Grindr. An enormous fine, as Grindr only reported a profit of $ 31 Mio in 2019 - a third of which is now gone.

I mean, if they're still make profit then it's not really hurting, is it? Any impact on the decision makers?

Re: Grindr to be fined almost €10M over GDPR complaint

#232
post #77

They are sending all of their user's data with an "opt out" flag and leaving it to the ad companies to honor it? Slow clap? It also caught my eye that their TOS didn't allow users a choice in data sharing, it was either agree or don't use the app. That might have some wide ramifications, I've encountered many web sites that won't let you past the sharing opt-in until you click agree - i.e. it is impossible to disagre…

> If they have no assets in Norway I imagine it may be hard to collect from them. I thought, but have never verified, that fines given as GDPR enforcement can be collected throughout the EU/EEA. If this is true, and if European courts uphold the fines when Grindr undoubtedly challenge them, then it's my understanding that the Norwegian DPA can have Grindr assets elsewhere in the EEA seized. Does anyone know for sure?

If they are "established" somewhere in the EU, then all GDPR complaints get forwarded to the DPA for the country where they are established. This is called the "one-stop shop mechanism."

If the Norwegian DPA is the one handling this case, probably that's because Grindr's EU operations are legally established in Norway. If they don't have an "establishment" in the EU, then I think it's up-for-grabs, and my gut is that NOYB would have preferred to file in France or Germany.

This is why GDPR actions against Facebook, Google, etc. all go through the (under-resourced) Irish DPA: US companies are all based there for tax reasons. It's... becoming a problem.

Re: Grindr to be fined almost €10M over GDPR complaint

#233

Earlier quoted context omitted.

The various dark patterns employed by these consent systems are fairly opaque to anyone who bothers to open them, and are clearly deliberate attempts at maintaining the old status quo of "opt-in by default". Frankly, I am surprised at how few of these fines are flying around, though I am quite happy to hear they _are_ happening. I do get that this type of regulation is very disruptive to many companies, but if they c…

I’ve also wondered why there aren’t “enough” fines. Are the countries just being cautious because they want to establish precedent before going after the “big fish” like Facebook or Google? Or is it something else?

Data protection officials are generally understaffed and underfunded. GDPR has increased public awareness, scope and thereby caseload. The rest of the normal justice system isn't responsible to handle data protection cases and will just refer you to the data protection officials. So while fines are happening, things move very slowly if at all.

Re: Grindr to be fined almost €10M over GDPR complaint

#234

The GDPR has always amazed me. It changed the playing field from "you can use our free app as long as you give us data for marketing or not use it" to "you can provide a free service in the EU as long as you dont collect data for marketing or dont provide it" Without making a judgement on the merits of the approach, as a user/individual I appreciate the power this gives to protect my data. As a company/developer the…

I see this as a "it's so hard to run a business with all these rules" argument. We both know rules are extremely clear and simple. They get complicated when companies try to go around them.

But but but, what about my boilerplate frontend code to add zillions of trackers. Do I have to stop copy-pasting those? Too hard, GDPR sucks. :))

Re: Grindr to be fined almost €10M over GDPR complaint

#235

Question in regards to the user consent pop-ups on websites: On sites that continue to let you browse without making a selection (say the consent banner in on the bottom of the browser window), If I don't make any choice, accept or reject, what happens? Am I giving consent by default?

Consent needs to be unambiguous. If they assume consent, they operate illegally.

Re: Grindr to be fined almost €10M over GDPR complaint

#236
post #204

Earlier quoted context omitted.

Probably net zero, as long as everyone follows the same rules. Advertising is a zero-sum game, and changing the height of the playing field shouldn't impact relative revenue all that much.

As an advertiser, not true at all. Promoting products to any niche smaller than "man" or "woman" basically requires targeted advertising to make work.

Surely male and female also require targeting? It's not as if browsers come in pink and blue editions and broadcast that.

Re: Grindr to be fined almost €10M over GDPR complaint

#237

Question in regards to the user consent pop-ups on websites: On sites that continue to let you browse without making a selection (say the consent banner in on the bottom of the browser window), If I don't make any choice, accept or reject, what happens? Am I giving consent by default?

By law or it has to be informed, active consent AIUI. Some sites say 'by continuing you are giving consent' but that's not how it works.

You have to be able to use the site without giving consent too.

Re: Grindr to be fined almost €10M over GDPR complaint

#238

Earlier quoted context omitted.

The thing is, third-party SDKs often do data collection on their own. Or, even if they don't, they could do so, and you don't really know if they do or not.

Well, now the GDPR gives you 10% of your revenue as a reason for not using SDKs that will not give you control of data collection. You always had "respect the privacy of users" as a reason not to use them before, but we all know how well that worked.

"We value your privacy" has never been truer.

Re: Grindr to be fined almost €10M over GDPR complaint

#239
post #204

Earlier quoted context omitted.

As an advertiser, not true at all. Promoting products to any niche smaller than "man" or "woman" basically requires targeted advertising to make work.

Couldn't this be done based on content, without looking at personal data? "Here is an article on investment. How about I show an ad of an investment bank." If only one company does it, they lose. But if everyone is forced to do it, noone will lose.

And it's more commercially effective to be more specific than that and take the reader's profile into account.

It's also not a zero sum at all. An advertisement that is not within the user's interest is wasted, rather than going to the competitor.

Re: Grindr to be fined almost €10M over GDPR complaint

#240

Earlier quoted context omitted.

The problem here is that if you want to implement Facebook login in your app, you have to include the SDK. It is against ToS to do it any other way.

Then don't implement Facebook login in your app, unless SDK becomes adapted to make its use GDPR-compliant. It's really a problem between you and Facebook at this point.

This.

The whole point of Facebook login and like was to collect data from unsuspecting users. Devs and product managers didn't care. GDPR makes this "laisser faire" attitude expensive.

Post reply on HN