Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

51–60 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#51
post #15
post #2

The Norwegian Data Protection Authority imposed a fine of €6,500,000 on Grindr for not collecting users' valid consent for sharing data with third parties for profiling and advertising purposes from the Grindr App. Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the cons…

Interesting indeed, it is what several German online newspapers do - they let you choose between a free version with tracking and a paid one without one. I find this argument a bit weird though: > Sharing Grindr's users personal data with advertising partners for online behavioural advertising purposes was not necessary for the performance of the Grindr's services. Charging money for your services is also not necessa…

Why can't organs be considered as a means of payment?

Not sarcasm - I think that while it's obviously a different scale, the reasons are similar and boil down to "we don't want that as a society" and "the environment this creates is not conductive to a free and informed rational decision". Many people don't understand the value of their data and the risk it poses, there is an information imbalance, there is a power imbalance (the company sets the terms, and you only get to take it or leave it).

The pre-GDPR situation also showed that the market doesn't really work, because everyone was collecting your data, people have limited energy and incentive to care because it doesn't cause immediately visible pain. It's similar to workplace safety - we don't allow employers to create easily avoidable dangerous situation in exchange for extra pay either, for similar reasons.

Most importantly, data grabbing is not necessary for advertising, it's just slightly more profitable and thus everyone does it, eventually pushing the "good" (privacy-friendly) players out of the market. If we want to change that, we need a de-facto ban (which a properly implemented GDPR would be, because so many people will click "No" if given a truly free choice that showing the popup won't be worth it).

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#52

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

But, to use your analogy, why would companies treat user data like uranium when risk/reward is like that of oil?

Grinder surely made much more from data sales than the 6.something million Erous it was find. The paltry fines under GDPR do nothing to dissuade this behavio. That's been a recurring theme in previous HN discussions on this topic.

Right now, I would posit that these low penalties are for show. Governments don't want to lose the economic benefit of having these companies operate in the EU and the general public can be satisfied that their governments are on top of the issue.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#53

Earlier quoted context omitted.

The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. And if you think that treating data in the proper way is hard then you probably shouldn't be in business at all. Operating in the EU is not a liability if you treat your users data in a respectful and responsible way. Common sense alone would answer your questions on what…

> The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to…

Think of it as the law catching up with technology.

> No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please.

Indeed, hence the need for regulation.

> Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around it.

Sure. But since EU citizens will be enjoying those protections and US citizens will not eventually this will translate into an advantage for companies doing business from the EU and into the US. For that reason alone there will be a big incentive for the US to make a law that is symmetrical to remove this advantage.

> I think that all of this boils down to profit margins and viewing people as just numbers on a sheet somewhere, to extract wealth from.

This is a big factor, but not the only factor: data that is in isolation worthless can become very valuable or even dangerous when combined with other worthless or innocent data. There are plenty of examples of this. The balance clearly lies in protecting consumers from the fall-out of these and the more purposeful abuses. This is a matter of raising consciousness about what rights you already have, not necessarily of giving you new ones.

> Just look at how scummy many of the cookie banner implementations are, designers being paid to implement as many dark patterns as possible, at least up until lawsuits started.

Agreed. The EU did the right thing with the GDPR, it laid bare how many companies were outright scandalous in how they were dealing with the data that they were entrusted with, they were bad stewards and it is good to see this level of enforcement because that means that companies will wise up to it and find better - and cleaner - ways of monetizing their products and services. Once they have those they will realize that regulatory capture can be theirs if they lobby for these rights to be extended to everybody.

The EU is too large a market to miss out on.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#54

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

A fine of this size indicates to me they should harvest and sell more data to increase profits. Tens of millions would still probably be worth it to Grindr. Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter. Nah, this fine (which I don’t even know…

These fines tend to go up with repeat performances. Sooner or later some company will be fined right out of business and then we'll see whether the remainder will catch on that playing games with regulators is a losing one.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#55
post #36

Earlier quoted context omitted.

What’s your alternative? Clearly people use the app because the app answers a user need. So what’s your answer to the user need?

We also got laid before the invention of the smartphone, you know...

We're also deep in a pandemic where olden times means of socialization are pretty restricted. I'm not gonna walk into a bar in 2021 to be assaulted by smoke, sound, and covid. Just the smoke and sound has been enough to keep me out of them for over a decade now.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#56

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

What does it mean for data to be no longer needed when one of your income streams is to sell user data?

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#57
post #7

The most surprising thing about this to me is that Norway, which is not in the European Union, is also enforcing GDPR.

As far as the average person is concerned, EEA members like Norway are practically in the EU. You've got free movement, open borders due to the Schengen area, and so on. Meanwhile all the exemptions from EU law mostly concern comparatively niche areas like fishing.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#58
The thing that always bothered me most about Grindr is the fact they do not allow any connectivity from VPNs, even if you have an upgraded account. This doesn't seem to jive well with the need for privacy or anonymity in places where it's dangerous to be gay.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#59

Earlier quoted context omitted.

The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. And if you think that treating data in the proper way is hard then you probably shouldn't be in business at all. Operating in the EU is not a liability if you treat your users data in a respectful and responsible way. Common sense alone would answer your questions on what…

> The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to…

> No business is interested in having to suddenly comply with such regulations

Just to pick up on this clause - it really needn't have been sudden. The regulation was adopted just over 2 years before enforcement kicked in[0], and of course it was written and debated for a while prior to that. In the UK the ICO researched the implications (for what were then just proposals) back in 2013[1]

[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

[1] https://ico.org.uk/media/1042341/implications-european-commi... (PDF)

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#60
post #12

Good. Grindr is probably the best example of extremely high brand & network value vs shockingly poor security & application quality. The company demonstrates zero integrity and needs to be shut down or fined to death. It would send a proper warning to the industry, though long overdue.

Grindr is/was considered a poor quality brand from an advertising perspective. Nobody wants their ads to appear next to graphic images
Post reply on HN