Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

71–80 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#71
> Based on our investigation so far, we believe that Disqus could not rely on legitimate interest as a legal basis for tracking across websites, services or devices, profiling and disclosure of personal data for marketing purposes, and that this type of tracking would require consent

Good to see them taking this seriously. I get the impression a lot of sites/services make expansive use of the legitimate interest provision.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#72
post #35
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

>Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. No, that's wrong. First of all, the GDPR does not take in to consideration citizenship, at all. The Regulation targets location rather than nationality . In other words, if either the data subject or data controller are in the EU/EEA then the GDPR applies, even if the other party is not in the EU/EEA (The U…

There is coming terreg law (already passed and will be implemented within a year) that specifically targets citizenship rather than location. https://decoded.legal/blog/2021/04/the-eus-terrorist-content...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#73

Try blocking Disqus with uBlock Origin, turns out you probably won't miss it ||disqus.com^ You could also try a dynamic filter and disable it on a per-site basis * disqus.com * block Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...

Privacy Badger replaces it with a widget that allows you to enable it with a button click if you want. It is pretty nice.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#74
post #32

More background: The fine is mainly based on the fact that Disqus forgot to enroll Norwegian IP-addresses into their GDPR «privacy mode». That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus. Major sites like the W…

"Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus." Not to sound too clever, but I would assume if I embed a third party on my website, all bets are off considering privacy/data flow. Only the biggest services with the biggest publicity like GA have rudimentary privacy (opt-out, IP anonymization).

> Not to sound too clever, but I would assume if I embed a third party on my website, all bets are off considering privacy/data flow.

That you have to take care of these things is kind of the point of GDPR. If you don't know what some embedded server will do with users data, don't use it. No more fast and loose.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#75

Earlier quoted context omitted.

I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. But is that the case with Disqus? They are collecting marketing information on citizens of the EU. Who is buying that information? I would assume that Disqus does business with EU companies that want that information. Either that, or they do business with other international companies that do business with EU companies. A…

This is Norway, not the EU. Norway just happened to implement an EU law.

They are part of the European Economic Area (EEA)[0] and have to adopt a lot of the European Union law[1].

[0] https://en.wikipedia.org/wiki/European_Economic_Area

[1] https://en.wikipedia.org/wiki/European_Economic_Area#Rights_...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#76
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. But is that the case with Disqus? They are collecting marketing information on citizens of the EU. Who is buying that information? I would assume that Disqus does business with EU companies that want that information. Either that, or they do business with other international companies that do business with EU companies. A…

> I guess if you have a company that is completely isolated from the EU, you just ignore EU fines.

Ignoring legitimate fines seems like a pretty bad idea. I think most countries have law to the effect that the directors of the company being fined are liable, so if you skip those fines then one of the directors goes on holiday to that country then they could be sent to prison.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#77
post #47
post #46

Earlier quoted context omitted.

"forgot"

Forgetting for a single country (which is also not part of the EU) certainly seems plausible, more plausible than a targeted attempt at undermining the GDPR in a very specific country

It's EU regulation and Norway is part of EEA which adapted these GDPR regulations. Feels like some risk and compliance officer at Disqus has been sleeping

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#78
post #76

Earlier quoted context omitted.

I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. But is that the case with Disqus? They are collecting marketing information on citizens of the EU. Who is buying that information? I would assume that Disqus does business with EU companies that want that information. Either that, or they do business with other international companies that do business with EU companies. A…

> I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. Ignoring legitimate fines seems like a pretty bad idea. I think most countries have law to the effect that the directors of the company being fined are liable, so if you skip those fines then one of the directors goes on holiday to that country then they could be sent to prison.

How is it a legitimate fine if the company doesn't do business in the country that issued the fine?

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#79
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Well the EU isn't stupid. They foresaw a situation were companies would consider moving to a "data haven" to avoid this legislation.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#80

> Based on our investigation so far, we believe that Disqus could not rely on legitimate interest as a legal basis for tracking across websites, services or devices, profiling and disclosure of personal data for marketing purposes, and that this type of tracking would require consent Good to see them taking this seriously. I get the impression a lot of sites/services make expansive use of the legitimate interest prov…

Yes, it is really maddening: they make you consent to their "legitimate interest" cookies, conflating legal terms to confuse people into accepting everything.

Ad-tech companies get more and more emboldened lately. They see that the GDPR is not really enforced, they assume that big, cash-rich companies will get taken on first, competitors are doing it too, so they gamble they can get away paying lip service to GDPR while continuing their illegal tracking practices.

I have seen several startups pitching schemes that seem blatantly illegal to me, while assuring that their tech is fully compliant. Often using the words "legitimate interest" to prove this point.

Post reply on HN