Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

101–110 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#101
post #53

Earlier quoted context omitted.

They probably used yaml for their config...

For people who are not aware, if you write the value no in YAML, it parses it as the boolean false which is then usually converted back to the string "false". The solution is to write "no" and not no, but Norway is the only country code requiring this so a lot of people forget about it. For example I noticed this week that an environment variable in a few of my Norwegian company's deployments was "false" and not "no"…

Syntax highlighting to the rescue! I’ve almost been bitten by that “feature” before, but the VS Code extension for YAML caught it.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#102

Question to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.

I'm curious about this, too. I once commented that, say, my hobby website isn't subject to the GDPR because I love, work, and play in the US and that's where my blog is, too. Turns out some people have very strong opinions about this and insisted that I am subject to the GDPR. But as a practical matter, how? I don't have a presence outside the US. Even if I violated a EU law, is there a reason I'd ever need to care?…

GDPR doesn't actually require cookie banners. If all the tracking and data protection you do is justified, justifiable and obviously necessary for the lowest-common-denominator service you provide, you don't even need to ask for consent (though do let your users know what's up, anyway, with at minimum a Privacy Notice in the footer, because that's just common decency).

If a company asks for GDPR consent, either:

• They have cool, optional features of their site / service / system (though they could just ask at run-time, when you try to use those features, in most cases); or

• They're doing something dodgy and want to wave a magic wand and remove the dodginess by getting you to “consent”.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#103

Question to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.

I'm curious about this, too. I once commented that, say, my hobby website isn't subject to the GDPR because I love, work, and play in the US and that's where my blog is, too. Turns out some people have very strong opinions about this and insisted that I am subject to the GDPR. But as a practical matter, how? I don't have a presence outside the US. Even if I violated a EU law, is there a reason I'd ever need to care?…

Worst case they could block your site, but that's not going to happen.

Note that if it is a personal website you are not subject to GDPR. GDPR only applies to companies and organizations.

Also note that most stuff that a layperson would say is reasonable for a website to function isn't a problem in GDPR.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#105

> Based on our investigation so far, we believe that Disqus could not rely on legitimate interest as a legal basis for tracking across websites, services or devices, profiling and disclosure of personal data for marketing purposes, and that this type of tracking would require consent Good to see them taking this seriously. I get the impression a lot of sites/services make expansive use of the legitimate interest prov…

Yes, it is really maddening: they make you consent to their "legitimate interest" cookies, conflating legal terms to confuse people into accepting everything. Ad-tech companies get more and more emboldened lately. They see that the GDPR is not really enforced, they assume that big, cash-rich companies will get taken on first, competitors are doing it too, so they gamble they can get away paying lip service to GDPR wh…

To play devil's advocate: that might become the going strategy. They're gonna be profitable as hell until they get fined and aren't allowed to continue after all...

But then it's just a matter of closing that enterprise down and creating a new one. They can keep apis stable and give the big corporations plausible deniability as "the contractor said they're compliant"

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#106
post #103

Earlier quoted context omitted.

I'm curious about this, too. I once commented that, say, my hobby website isn't subject to the GDPR because I love, work, and play in the US and that's where my blog is, too. Turns out some people have very strong opinions about this and insisted that I am subject to the GDPR. But as a practical matter, how? I don't have a presence outside the US. Even if I violated a EU law, is there a reason I'd ever need to care?…

Worst case they could block your site, but that's not going to happen. Note that if it is a personal website you are not subject to GDPR. GDPR only applies to companies and organizations. Also note that most stuff that a layperson would say is reasonable for a website to function isn't a problem in GDPR.

> most stuff that a layperson would say is reasonable for a website to function isn't a problem in GDPR.

Except revenue of course.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#107
post #73

Try blocking Disqus with uBlock Origin, turns out you probably won't miss it ||disqus.com^ You could also try a dynamic filter and disable it on a per-site basis * disqus.com * block Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...

Privacy Badger replaces it with a widget that allows you to enable it with a button click if you want. It is pretty nice.

It's very nice. I wish this was just how the web worked for stuff like this.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#108

Question to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.

Yes if push comes to shove they could obviously just shut down websites or go after companies that continue to use Disqus and they in turn will drop it. There's also plenty of countries outside the EU who have adopted GDPR compatible laws and so the EU could likely pursue them in their national jurisdictions. Also EU and US regulatory agencies tend to cooperate routinely because it's in either case to keep market acc…

The article does not contain the string "ICO". The article describes enforcement of Canadian privacy law against a Canadian company.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#109

Earlier quoted context omitted.

Yes, it is really maddening: they make you consent to their "legitimate interest" cookies, conflating legal terms to confuse people into accepting everything. Ad-tech companies get more and more emboldened lately. They see that the GDPR is not really enforced, they assume that big, cash-rich companies will get taken on first, competitors are doing it too, so they gamble they can get away paying lip service to GDPR wh…

To play devil's advocate: that might become the going strategy. They're gonna be profitable as hell until they get fined and aren't allowed to continue after all... But then it's just a matter of closing that enterprise down and creating a new one. They can keep apis stable and give the big corporations plausible deniability as "the contractor said they're compliant"

> "the contractor said they're compliant"

this part wont work w/ GDPR - this is not the US. I've mentioned it someplace else - the contracts with the contractors have quite explicit clauses about liabilities about data breaches/leaks as the fines would still be applied to the main entities.

With regard to GDPR, personal data is a liability and it should be handled with appropriate care.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#110

Earlier quoted context omitted.

Yes if push comes to shove they could obviously just shut down websites or go after companies that continue to use Disqus and they in turn will drop it. There's also plenty of countries outside the EU who have adopted GDPR compatible laws and so the EU could likely pursue them in their national jurisdictions. Also EU and US regulatory agencies tend to cooperate routinely because it's in either case to keep market acc…

The article does not contain the string "ICO". The article describes enforcement of Canadian privacy law against a Canadian company.

The ICO's GDPR enforcement action is what set this in motion, (which to be honest is the first result on Google if you want the entire saga)

https://iapp.org/news/a/ico-serves-aggregateiq-with-first-ev...

Post reply on HN