Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

21–30 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#21
"Norwegian internet users were tracked by Disqus because the company did not know that Norway introduced the common European privacy regulation GDPR in 2018. It thus took 511 days before Norwegians were incorporated into the company's "privacy mode" for GDPR countries and previously collected information was deleted."[0]

It seems that there was some setting that is enabled by default in all other countries than countries with the GDPR law.

Also, from an earlier article: "The company also claims that they have not shared Norwegians' online visits with anyone other than the parent company Zeta Global. Zeta Global describes itself as a 'data-driven marketing company"' that has information on over two billion identities."[1]

As a Norwegian, it will be interesting following this case.

[0]: https://nrkbeta.no/2021/05/05/datatilsynet-varsler-bot-pa-25...

[1]: https://nrkbeta.no/2020/09/04/datatilsynet-mener-det-er-sann...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#22
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Somehow that rather large and affluent market is not dropped.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#23
post #4
post #2

"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.

Norway, whilst not in the EU, has very close links and often aligns with EU laws. Incidentally, the UK has now left the EU but has retained the GDPR in domestic law.

It goes much further than just "often aligning with EU laws":

Almost all EU regulations and rights – except those pertaining to agriculture, fisheries and the customs union – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).

For all intents and purposes, apart from the three areas stipulated above + voting rights, Norway is an EU member. A business that operates in Norway (outside of the agriculture or fisheries sector) can be seen as operating in the EU. Likewise, Norway-based users of a service with a business presence in the EU are protected by EU laws, like the GDPR.

Norwegians have the same access to the EU labor market as, say, Germans. And EU citizens have the same right to take up residence in Norway and interact with the Norwegian state under the same conditions as a Norwegian.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#24
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Loads of US media sites do that, especially local TV stations and papers.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#25
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

What if I (as a European visitor) access the website through a VPN, something I'm legally allowed to do?

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#26
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Another technique is to run a stripped down version of your site with whatever content/functionality fits into the GDPR. Set your log retention to under a month (not a GDPR requirement, just a tactic that makes compliance easier), redact sensitive information under the GDPR, ask for consent, offer DSAR tools if applicable, etc.

I noticed this being employed by some media sites when I was vacationing in Europe. No Discus comments, no account creation or login, just articles and banner ads. The sites loaded so much faster. I’ve done similar things at work when building out privacy law compliance. It’s a good pattern if you don’t need one to one feature equivalency between your US and EEA/GB presence.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#27
post #11
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

Incorrect. When talking about companies and other orgs, the GDPR's territorial scope does reach overseas, but is limited. It also doesn't turn on having citizenship of the EU/an EU country; case in point, the UK regulator (ICO) upheld the GDPR rights of a US professor against Cambridge Analytica. What matters is whether either (1) the entity's handling ("processing") of personal data - anywhere in the world - is related to the activities of one of its EU offices, subsidiaries etc; OR (2) if [1] doesn't apply, then GDPR can still apply if you're processing data about persons in the EU/EEA (citizens, tourists, whatever) AND either (a) the processing is related to services or goods you offer those EU persons, or (b) you are monitoring their behaviour in the EU/EEA. There's lots that this test - despite being quite broad - would not catch (and isn't designed to).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#28
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

I guess if you have a company that is completely isolated from the EU, you just ignore EU fines.

But is that the case with Disqus? They are collecting marketing information on citizens of the EU. Who is buying that information? I would assume that Disqus does business with EU companies that want that information. Either that, or they do business with other international companies that do business with EU companies.

At some point, Disqus is probably trapped within a graph that connects them and their legal obligations to the EU.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#29
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Oddly enough, the disclaimer might actually increase the chance that you're subject to GDPR.

The relevant part of GDPR is Article 3, and Recital 23 (full law text in the links below--read them, they're short!).

GDPR applies to a non-EU website that "envisages offering services to data subjects" in the EU. Recital 23 explicitly says that a website merely being available does not count. Offering localized content (e.g. languages, currency for ecommerce) counts. And if your website treats users in the EU differently (such as by having a pop-up that mentions GDPR), that shows evidence that you believe users from Europe are in the target audience of your site.

Actually enforcing fines are a different matter, and will require some locus of business in the EU.

https://gdpr-info.eu/art-3-gdpr/

https://gdpr-info.eu/recitals/no-23/

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#30
Try blocking Disqus with uBlock Origin, turns out you probably won't miss it

  ||disqus.com^
You could also try a dynamic filter and disable it on a per-site basis

  * disqus.com * block
Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you

https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...

Post reply on HN