Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

81–90 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#81
post #11
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

>Any EU citizen in our out of country has their PII protected by EU law

If GDPR applies, it applies not only to citizens, but also to residents at the time of the transaction.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#82
post #48

Earlier quoted context omitted.

Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users won't do it because they want those users.

People like to infer from this that those sites are gathering and processing data in ways that would be hard to make GDPR-compliant. My guess is that in a lot of cases though it is that they simply do not want to deal with Article 27. Article 27 is a hassle even if all your data processing itself is fully compliant with GDPR. Article 27 requires entities not in the Union to designate a representative in the Union tha…

That provision is not so hard. Most companies I have talked to don't know what data they have collected, where it is stored, and who it is shared with. That is the thing that gets the attention of US companies.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#83
post #74

Earlier quoted context omitted.

"Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus." Not to sound too clever, but I would assume if I embed a third party on my website, all bets are off considering privacy/data flow. Only the biggest services with the biggest publicity like GA have rudimentary privacy (opt-out, IP anonymization).

> Not to sound too clever, but I would assume if I embed a third party on my website, all bets are off considering privacy/data flow. That you have to take care of these things is kind of the point of GDPR. If you don't know what some embedded server will do with users data, don't use it. No more fast and loose.

Yes I agree.

My point was more about companies embedding Javascript on their sites and "did not know they were sharing data".

Sadly European data protection agencies are vastly understaffed. I've filed some complaints, and have been waiting for an answer for them for years in some cases. I regularily get letters sent from agencies which say "we're still on it, but it takes more time".

One complaint was about an UK company ("Boden") filed with the Berlin data protection agency. Then they transfered it to the UK, then back to Berlin, it currently is in the Netherlands.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#84
post #48

Earlier quoted context omitted.

Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users won't do it because they want those users.

People like to infer from this that those sites are gathering and processing data in ways that would be hard to make GDPR-compliant. My guess is that in a lot of cases though it is that they simply do not want to deal with Article 27. Article 27 is a hassle even if all your data processing itself is fully compliant with GDPR. Article 27 requires entities not in the Union to designate a representative in the Union tha…

I'm not sure I buy that. It really comes down to the question of why do small, local US news sites care about the GDPR at all? I can think of three reasons:

1. They are actually all owned by a multi-national entity that is scared of the GDPR because it also operates in Europe

2. The news sites and their owner(s) aren't bothered; but the ad networks are. Maybe it's a "cross-contamination" issue. So they say something like "to keep using us, block European visitors, we'll provide that capability", and the news sites are probably fine with it because European visitors are a tiny fraction

3. It's a political statement, not an actual GDPR issue

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#85
post #51

I thought it said 2.5B, and thought “they’re finally enforcing the GDPR; great!” Oh well. (Edit: their revenue was $368M over the last 12 months, so €2.5B would be too high. The current fine is still an order of magnitude or two too low to change meaningfully change anyone’s behavior. It’s a couple of days of revenue. They could simply write it off as the cost of doing business, especially if they think the GDPR comp…

I doubt they can really write it off as the cost of doing business, I imagine they are running in the red with respect to the country of Norway this year, which is the place they made the mistake.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#86
Question to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#87
post #37

Earlier quoted context omitted.

Sibling comments already gave legal advice, but what I'd ask is: why would you want to? If you are transparent about what tracking you do and don't do stuff that people don't want, all that's left is including some boilerplate text like "you have rights X, Y and Z and you can contact us at our@email" and you're GDPR compliant. To me at least, 95% of GDPR compliance is just acting ethically.

1. It seems to me that a common question many would like answered is: whats the simplest way that I can serve http requests without incurring the wrath of the GDPR? 2. It was my understanding that GDPR compliance is extremely expensive, is this not the case? Perhaps it is very simple.

2. Depends on what your business is. A company heavily reliant on profiled advertising will have much higher costs than the typical small business with minimal (or no) advertising.

The small business (perhaps with a mailing list and a database of previous customers and invoices) should have been compliant with the earlier laws (Data Protection etc), and the changes required for them are often minor.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#88
post #78
post #76

Earlier quoted context omitted.

> I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. Ignoring legitimate fines seems like a pretty bad idea. I think most countries have law to the effect that the directors of the company being fined are liable, so if you skip those fines then one of the directors goes on holiday to that country then they could be sent to prison.

How is it a legitimate fine if the company doesn't do business in the country that issued the fine?

[deleted]

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#89
post #62

Earlier quoted context omitted.

> embed a third party on my website, all bets are off considering privacy/data flow. That's definitely not the case. It'd be true only if there is no contract w/ the 3rd party at all. Many contracts cover data leaks and the like and the contractual obligations are "non-trivial" to put it mildly.

Then our experiences differ somehow. Most Disqus users don't look like they have a contract, rather they accept terms and services than can be unilaterally changed by Disqus. I've signed some DPAs and those that I've signed were very vague and liberal on what data they take - at least none of them felt that they would not try to get all the data that they can.

> Most Disqus users don't look like they have a contract, rather they accept terms and services than can be unilaterally changed by Disqus.

In that case the terms are invalid.

You cannot use terms of service to take away consumer protection in Europe.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#90
post #50

Earlier quoted context omitted.

Wouldn't it be funny if this was caused by some YAML configuration reading the country code "no" as "false".

Yes, loved that HN story.

Can you share it? I must've missed it and I'm in need of a good laugh.
Post reply on HN