Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

51–60 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#51
I thought it said 2.5B, and thought “they’re finally enforcing the GDPR; great!”

Oh well.

(Edit: their revenue was $368M over the last 12 months, so €2.5B would be too high. The current fine is still an order of magnitude or two too low to change meaningfully change anyone’s behavior. It’s a couple of days of revenue. They could simply write it off as the cost of doing business, especially if they think the GDPR compliance will impact business growth)

https://stockanalysis.com/stocks/zeta/

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#52
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. But is that the case with Disqus? They are collecting marketing information on citizens of the EU. Who is buying that information? I would assume that Disqus does business with EU companies that want that information. Either that, or they do business with other international companies that do business with EU companies. A…

This is Norway, not the EU. Norway just happened to implement an EU law.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#53
post #47
post #46

Earlier quoted context omitted.

"forgot"

Forgetting for a single country (which is also not part of the EU) certainly seems plausible, more plausible than a targeted attempt at undermining the GDPR in a very specific country

They probably used yaml for their config...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#54
post #32

More background: The fine is mainly based on the fact that Disqus forgot to enroll Norwegian IP-addresses into their GDPR «privacy mode». That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus. Major sites like the W…

"Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus."

Not to sound too clever, but I would assume if I embed a third party on my website, all bets are off considering privacy/data flow. Only the biggest services with the biggest publicity like GA have rudimentary privacy (opt-out, IP anonymization).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#55
post #50
post #21

"Norwegian internet users were tracked by Disqus because the company did not know that Norway introduced the common European privacy regulation GDPR in 2018. It thus took 511 days before Norwegians were incorporated into the company's "privacy mode" for GDPR countries and previously collected information was deleted."[0] It seems that there was some setting that is enabled by default in all other countries than count…

Wouldn't it be funny if this was caused by some YAML configuration reading the country code "no" as "false".

Yes, loved that HN story.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#56
post #40
post #17

Earlier quoted context omitted.

To add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).

Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. Some documentaries even call it the worlds most toxic food.

I did a lot of research on salmon aquaculture at work last year (random, I know).

Norway has one if the most well-developed aquaculture industries in the world, and it is heavily regulated.

I'd be very surprised if Norwegian aquaculture rules didn't exceed EU rules in about every single way.

I learned a lot about aquaculture, not all of which was very nice. But now when I buy farmed salmon, I specifically choose Norwegian salmon over my native Scottish salmon.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#57
post #40
post #17

Earlier quoted context omitted.

To add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).

Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. Some documentaries even call it the worlds most toxic food.

Didn't love most of the food in Norway - cheese in tubes especially (my fault), but loved the fish (and the great hospitality of Norwegians).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#58
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

I have routinely asked this question and I routinely get pushed aside by GDPR zealots. I am not really interested in the GDPR bit as much as I am "what responsibilities do strictly web companies have when dealing with customers who are in a different country"

I think it's a load of bunk shit.

Companies should be following the law of their country, not of other countries.

I don't want businesses to be forced to bow to the will of Europe, or Iran, or China, or any country other than their own.

It sets up a weird quazi-legal precident where companies could be in the position of trying to play ball with multiple legal systems.

See russia, they want russians data to be on russian servers, even if your company is not there.

Why? Probably so they can seize the digital assets of citizens they want to send to the gulag.

I don't like it one bit, I don't like google working with china, I don't GDPR effecting American companies.

You need to be careful and follow the law of your country.

It pertains to tax as well, which I never understood how a different country wants to impose a tax on a company that doesn't operate there. They might have customers there - but they don't operate there in any meaningful sense more than they 'operate' there if I go onto a US website into it while on vacation in a foreign country.

thanks - I hate it.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#59
post #45
post #40

Earlier quoted context omitted.

Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. Some documentaries even call it the worlds most toxic food.

> Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? We definitely have to split the Norwegian fisheries industry into two: Norway has, and has for a long time had, a sizable wild fishing industry. The fish farming industry is a much newer one. I was a kid last time we had a referendum on membership (1994), so I'm not sure, but I believe the fish farming industry wasn't eve…

"Norwegians are somehow magically special"

Norwegians are magically special in their relationship to nature.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#60
post #6
post #2

"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.

> but they implement GDPR The GDPR is great for the citizens! My wish is that more countries follow the EU and implement similar and compatible laws. An interesting example of this is that the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA.

As a private citizen, I love GDPR. As someone responsible for implementations, I hate it.
Post reply on HN