Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

111–120 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#111

Earlier quoted context omitted.

The article does not contain the string "ICO". The article describes enforcement of Canadian privacy law against a Canadian company.

The ICO's GDPR enforcement action is what set this in motion, (which to be honest is the first result on Google if you want the entire saga) https://iapp.org/news/a/ico-serves-aggregateiq-with-first-ev...

The article contains no reference to the Canadian enforcement action. It is about a European enforcement action against the Canadian company in question for work it did in Europe.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#112
post #73

Try blocking Disqus with uBlock Origin, turns out you probably won't miss it ||disqus.com^ You could also try a dynamic filter and disable it on a per-site basis * disqus.com * block Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...

Privacy Badger replaces it with a widget that allows you to enable it with a button click if you want. It is pretty nice.

uBlock Origin had this at some point but Mozilla didn't approve it for some reason.

https://github.com/gorhill/uBlock/commit/7c22a312945a2bff41a...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#113

Earlier quoted context omitted.

The ICO's GDPR enforcement action is what set this in motion, (which to be honest is the first result on Google if you want the entire saga) https://iapp.org/news/a/ico-serves-aggregateiq-with-first-ev...

The article contains no reference to the Canadian enforcement action. It is about a European enforcement action against the Canadian company in question for work it did in Europe.

Dude are you intentionally trying to be obtuse. The British data watchdog noticed that a Canadian company, AggregateIQ, was mistreating data relating to the Brexit campaign. It then talked to the Canadian data watchdog, which pursued a privacy inquiry against said company because of its mistreatment of British user data. This is one of the first examples of the sort of extrajudicial enforcement of GDPR that OP wanted to know about, Jesus.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#114

Question to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.

I'm curious about this, too. I once commented that, say, my hobby website isn't subject to the GDPR because I love, work, and play in the US and that's where my blog is, too. Turns out some people have very strong opinions about this and insisted that I am subject to the GDPR. But as a practical matter, how? I don't have a presence outside the US. Even if I violated a EU law, is there a reason I'd ever need to care?…

If you're not doing business in or with any EU entities there's not much they can do

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#116

Earlier quoted context omitted.

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Another technique is to run a stripped down version of your site with whatever content/functionality fits into the GDPR. Set your log retention to under a month (not a GDPR requirement, just a tactic that makes compliance easier), redact sensitive information under the GDPR, ask for consent, offer DSAR tools if applicable, etc. I noticed this being employed by some media sites when I was vacationing in Europe. No Dis…

Deleting code isn’t enough to make you compliant, you also have to hire specialists to carry out slow processes required by the GDPR.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#117
post #78
post #76

Earlier quoted context omitted.

> I guess if you have a company that is completely isolated from the EU, you just ignore EU fines. Ignoring legitimate fines seems like a pretty bad idea. I think most countries have law to the effect that the directors of the company being fined are liable, so if you skip those fines then one of the directors goes on holiday to that country then they could be sent to prison.

How is it a legitimate fine if the company doesn't do business in the country that issued the fine?

That argument wouldn’t stop them arresting you at the border.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#118

Earlier quoted context omitted.

The article contains no reference to the Canadian enforcement action. It is about a European enforcement action against the Canadian company in question for work it did in Europe.

Dude are you intentionally trying to be obtuse. The British data watchdog noticed that a Canadian company, AggregateIQ, was mistreating data relating to the Brexit campaign. It then talked to the Canadian data watchdog, which pursued a privacy inquiry against said company because of its mistreatment of British user data. This is one of the first examples of the sort of extrajudicial enforcement of GDPR that OP wanted…

There might of been some sort of extrajudicial enforcement of the GDPR in this case, but the second article presented only showed that intrajudicial enforcement of the GDPR occurred based on actions that took place inside the EU with respect to the data of people living in the EU.

The first article actually doesn't mention any enforcement at all in Canada, just comments by a provincial and the federal privacy commissioner. Those comments were entirely based on Canadian law, not the GDPR.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#119

Earlier quoted context omitted.

Then our experiences differ somehow. Most Disqus users don't look like they have a contract, rather they accept terms and services than can be unilaterally changed by Disqus. I've signed some DPAs and those that I've signed were very vague and liberal on what data they take - at least none of them felt that they would not try to get all the data that they can.

> Most Disqus users don't look like they have a contract, rather they accept terms and services than can be unilaterally changed by Disqus. In that case the terms are invalid. You cannot use terms of service to take away consumer protection in Europe.

Yes.
Post reply on HN