Live data from Hacker News

Grindr to be fined almost €10M over GDPR complaint

noyb.eu

261–270 of 297 posts

Re: Grindr to be fined almost €10M over GDPR complaint

#261

Earlier quoted context omitted.

I mean, if they're still make profit then it's not really hurting, is it? Any impact on the decision makers?

Well if you took away 30% of my year's income I'd be quite hurt.

It's 30% of profit, not income, so more akin to someone taking 30% of your savings or "fun" money.

Re: Grindr to be fined almost €10M over GDPR complaint

#262
post #90
post #70

Earlier quoted context omitted.

There are also passport checks when you fly to Norway from other EU countries. For flights between other EU countries you generally just show the QR code on your phone. At least that was my experience, but it's been a few years since I last flew. (Except flights to UK before Brexit, I think they always required passport checks)

> There are also passport checks when you fly to Norway from other EU countries. This is incorrect. And the presence or absence of these checks is not a EU/EEA matter. The passport free movement is a matter of the Schengen agreement. This is why the UK had passport checks with most of continental Europe back when they were EU members (but not Schengen members). Norway is a Schengen member, and an EEA member, but not…

> This is incorrect

You are right about Schengen.

But I had to show my passport a couple of years ago on a flight from Vienna to Norway, so I thought they weren't part of Schengen. I'm not sure why, but I believe the reason must have been the "temporary border controls" introduced in 2015.

Re: Grindr to be fined almost €10M over GDPR complaint

#263
post #260

Earlier quoted context omitted.

So any data that does not fall under that blacklist is free game? I still find that quite arbitrary to make that distinction, not to mention the wiggle room it leaves with many of those categories being rather ill-defined. At what point does an opinion become “political”? what is “racial” an “ethnic origin” is quite open to interpretation; when is a belief “philosophical”? The way I understand this paragraph, it coul…

> So any data that does not fall under that blacklist is free game? No. That list are data that are considered especially sensitive, and so it's generally prohibited to process personal data of this kind. As far as I can tell it's the strictest part of the GDPR, so it's probably also the easiest to enforce. If some data doesn't fall into these "special categories", the rest of the GDPR still applies. The GDPR applies…

Yes, so we arrive at “if I understand this correctly, it is not a problem, or a lesser or different problem” as I first asked.

I find this distinction to be bereft of a proper justification. As I said elsewhere, I cannot think of any salient reason to not cover name and address as a means to identify a person, but do cover far more obscure and unlikely biometric data.

It should not be protected in any different way.

Re: Grindr to be fined almost €10M over GDPR complaint

#264

Earlier quoted context omitted.

As a company/developer starting from scratch, there is really no complexity nor landmines : Do as you say, Say what you do, Give the user options. You can offer the user the choice between targeted advertising or non-targeted. You can offer the user the choice between paid subscription or advertising. Cant get enough users to pay or consent ? Then you did not find market-fit in the real world.

Oh but GDPR is more than "don't do marketing". There´s stuff like "Right to be forgotten" that implementing controls for it would require a company starting from scratch to spend resources in "getting it right", and then you have things like backups, that may or may not fall in scope. And this is only one of the 8 rights that the GDPR provides.

First of all, it's not "don't do marketing", it's don't do "user-tracking-and-profiling based advertising". Marketing is so much more, like actual market research to provide a service users actually want.

You have to handle a "right to be forgotten" query within a month, surely this is enough time for one sysop to run a prepared query. If your database is so byzantine that you cant find all reference to a given customer, you are either google or in need of a new architect.

Backups do not need to be deleted immediately, they should however expires and be destroyed in accordance to your data retention policy (Say what you do, do as you say).

Re: Grindr to be fined almost €10M over GDPR complaint

#266

Earlier quoted context omitted.

The various dark patterns employed by these consent systems are fairly opaque to anyone who bothers to open them, and are clearly deliberate attempts at maintaining the old status quo of "opt-in by default". Frankly, I am surprised at how few of these fines are flying around, though I am quite happy to hear they _are_ happening. I do get that this type of regulation is very disruptive to many companies, but if they c…

I’ve also wondered why there aren’t “enough” fines. Are the countries just being cautious because they want to establish precedent before going after the “big fish” like Facebook or Google? Or is it something else?

The way of things in EU is a bit different than some other areas. The goal is to change the industry slowly. You don't change industry by killing them quickly so these things are first made into law, then there is usually a number of warnings, then the fines starts showing up small and then the gets ramped up if the industry doesn't change.

These dark patterns we keep seeing shows that the sites didn't do their homework and is trying the usual weazel way of getting past on "you clicked accept so now you are stuck.". Consent can only be given knowingly, if you hide it in the fineprint (or behind a "show more" button) it's not valid according to GDPR. To invent things like selling customer data to third party and call it fair usage of private data is not ok either.

The agreement has to be easy to understand and very short. And it has to be presented close to the actual entering of data or the accept button. No hiding, no shenanigans, no trying to fool with colors or design. It's that simple.

Re: Grindr to be fined almost €10M over GDPR complaint

#267
post #266

Earlier quoted context omitted.

I’ve also wondered why there aren’t “enough” fines. Are the countries just being cautious because they want to establish precedent before going after the “big fish” like Facebook or Google? Or is it something else?

The way of things in EU is a bit different than some other areas. The goal is to change the industry slowly. You don't change industry by killing them quickly so these things are first made into law, then there is usually a number of warnings, then the fines starts showing up small and then the gets ramped up if the industry doesn't change. These dark patterns we keep seeing shows that the sites didn't do their homew…

> The goal is to change the industry slowly. You don't change industry by killing them quickly...

I completely agree. People calling for an immediate 4% fine are ignoring that killing companies is bad for the economy. If a “pitiful” fine of $200,000 fixes the behavior, why fine the living daylights out of them?

I’m just wondering why the fines have been so “slow” to happen. Enforcement Tracker[0] lists only 533 of which the majority appear to be against individuals (such as “Doctor”, “Private person”, etc.) I just figured there would be more by this point.

[0]: https://www.enforcementtracker.com/

Re: Grindr to be fined almost €10M over GDPR complaint

#268
post #204

Earlier quoted context omitted.

Probably net zero, as long as everyone follows the same rules. Advertising is a zero-sum game, and changing the height of the playing field shouldn't impact relative revenue all that much.

As an advertiser, not true at all. Promoting products to any niche smaller than "man" or "woman" basically requires targeted advertising to make work.

Nope. There have already been articles/studies showing that "targeted advertisement" is about as effective as plopping a billboard sign on a motorway.

Re: Grindr to be fined almost €10M over GDPR complaint

#269
post #256

Earlier quoted context omitted.

Couldn't this be done based on content, without looking at personal data? "Here is an article on investment. How about I show an ad of an investment bank." If only one company does it, they lose. But if everyone is forced to do it, noone will lose.

In theory, yes, in reality, no. The strongest, biggest signal of what ads people will click is what kind of ads they clicked in the past. Content based ads have really bad performance comparably.

> biggest signal of what ads people will click is what kind of ads they clicked in the past. Content based ads have really bad performance comparably.

Has anyone actually compared this over long stretches of time and compared apples to apples, not apples to oranges?

Additionally, most people don't want personalized ads based on tracking: https://www.emarketer.com/content/do-people-actually-want-pe...

Re: Grindr to be fined almost €10M over GDPR complaint

#270
post #260

Earlier quoted context omitted.

> So any data that does not fall under that blacklist is free game? No. That list are data that are considered especially sensitive, and so it's generally prohibited to process personal data of this kind. As far as I can tell it's the strictest part of the GDPR, so it's probably also the easiest to enforce. If some data doesn't fall into these "special categories", the rest of the GDPR still applies. The GDPR applies…

Yes, so we arrive at “ if I understand this correctly, it is not a problem, or a lesser or different problem ” as I first asked. I find this distinction to be bereft of a proper justification. As I said elsewhere, I cannot think of any salient reason to not cover name and address as a means to identify a person, but do cover far more obscure and unlikely biometric data. It should not be protected in any different way…

This is getting a bit off-topic, but there are good reasons why biometric data is especially sensitive.

For example, the GDPR emphasizes the "right to be forgotten". If something bad happened to you, you may not want to be forever defined by that event. A kidnapped person might not want to be forever known as just a crime victim. So they can ask Google to remove mentions of their name, and they can even legally change their name as a last resort.

But if eg. Facebook stored their face measurements and then automatically tagged them in a newly uploaded photo all that would be pointless.

So it makes sense to treat certain data as more sensitive.

At the same time, the GDPR doesn't want to go overboard with regulation. Name and address are data that lots of businesses need to process -- eg. every online store needs to collect customer name and address and pass it on to payment providers, shipping companies, etc. It would be really inconvenient if you'd need explicit permission for each use ("Do you consent that I can tell the post office where to deliver your package?").

Sure, someone may find a way to abuse a list of names and addresses, but it's just not as sensitive as other data.

I think the GDPR actually strikes a great balance between protecting people's privacy and not inconveniencing businesses. If you only collect and process data that's absolutely necessary for providing your service, the GDPR won't inconvenience you much.

Post reply on HN