Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

61–70 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#61
post #43

Earlier quoted context omitted.

I think what's particularly scary about Grindr is just how much trouble even being on an app like that can get someone in. For example, a colleague of mine is from a country where being LGBT is not really tolerated, in the United States he uses Grindr. I can imagine an oppressive government buying dating app data to blackmail their users. I noticed in the Tinder TOS thread people complaining about how impossible it i…

With respect, that is easy to say when ~50% of the population is a potential partner and is easily determinable. When you are gay and the majority of guys are straight, finding partners organically is near impossible (unless you're in a gay bar or something). I'm not condoning Grindr's actions or that people shouldn't use it with care, but it really has become a key part of LGBT networking in the modern era.

I think it depends on where you are, the city I live in has a very large gay scene. So I've had guys just try to chat me up while I'm at a restaurant or something, I don't mind.

The only time it was a bit weird is when a co-worker told me I look like his husband, not okay to say at work.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#62
post #56

Earlier quoted context omitted.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

What does it mean for data to be no longer needed when one of your income streams is to sell user data?

If you keep it around to sell then you are likely violating the 'legal basis for processing' part of the GDPR. Data can only be used for the purpose for which it was originally collected, selling the data to others to use without that exact same goal can not be such a purpose, and even then you will have to be quite careful that you maintain control. Various EU data brokers (Schober, for instance) have found ways to do this in a controlled manner usually by anonymizing the data or by selling it only in aggregate form.

But selling it raw with the personal identifying information of the data subject is almost always a complete no-go.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#63
post #56

Earlier quoted context omitted.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

What does it mean for data to be no longer needed when one of your income streams is to sell user data?

It means that democratic societies have decided that that type of business practice is undesirable, and should go away.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#64

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

neat, this analogy travels pretty far - user data is radioactive.

theres a background amount of radiation. its everywhere, even in higher amounts than youd expect like bananas and airplanes. no amount is safe, but the risks are neglibly small when exposure is minimized. concentrated amounts can be safe when exposure is controlled and managed with oversight programs in place. disasters can be managed with disaster programs, but its still possible that unforseen problems can cause big issues. unregulated handling can poison local populations. corporate influence on government can be a problrm.

what a comparison! there should be an award for this.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#65
post #59

Earlier quoted context omitted.

> The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to…

> No business is interested in having to suddenly comply with such regulations Just to pick up on this clause - it really needn't have been sudden. The regulation was adopted just over 2 years before enforcement kicked in[0], and of course it was written and debated for a while prior to that. In the UK the ICO researched the implications (for what were then just proposals) back in 2013[1] [0] https://en.wikipedia.org…

And before that we had the DPD, which companies routinely ignored because they would never get fined. That's the only part of the GDPR that made companies take notice: the fact that the GDPR has some pretty impressive teeth. I'm actually quite surprised at the restraint on display so far by regulators, but I'm also quite sure that it is a matter of time before a repeat offender will be shown just how powerful this law is.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#66

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

A fine of this size indicates to me they should harvest and sell more data to increase profits. Tens of millions would still probably be worth it to Grindr. Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter. Nah, this fine (which I don’t even know…

Wait a second, it's not Grindr gathering and selling a list of homosexuals interested into sex.

It's the users themselves who actively register on Grindr to announce their services and picture on the platform.

If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#67
post #56

Earlier quoted context omitted.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

What does it mean for data to be no longer needed when one of your income streams is to sell user data?

I guess the implication is you should market like you would for electricity, that is, metered subscriptions only.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#68
post #56

Earlier quoted context omitted.

What does it mean for data to be no longer needed when one of your income streams is to sell user data?

If you keep it around to sell then you are likely violating the 'legal basis for processing' part of the GDPR. Data can only be used for the purpose for which it was originally collected, selling the data to others to use without that exact same goal can not be such a purpose, and even then you will have to be quite careful that you maintain control. Various EU data brokers (Schober, for instance) have found ways to…

GDPR only requires informed consent to allow selling of data as far as I know. Am I wrong about that?

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#69

Earlier quoted context omitted.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

neat, this analogy travels pretty far - user data is radioactive. theres a background amount of radiation. its everywhere, even in higher amounts than youd expect like bananas and airplanes. no amount is safe, but the risks are neglibly small when exposure is minimized. concentrated amounts can be safe when exposure is controlled and managed with oversight programs in place. disasters can be managed with disaster pro…

Ah, the linear no threshold theory of radiation.

If background radiation is everywhere, how can there be no safe dose.

It’s a fun analogy, but reinforces an incorrect assumption.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#70

Earlier quoted context omitted.

> The EU is merely leading the way here, you can expect all of the developed world to have similar data protection laws on the books sooner or later. While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to…

Think of it as the law catching up with technology. > No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please. Indeed, hence the need for regulation. > Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around…

> since EU citizens will be enjoying those protections and US citizens will not eventually this will translate into an advantage for companies doing business from the EU and into the US. For that reason alone there will be a big incentive for the US to make a law that is symmetrical to remove this advantage.

Given the lack of similar regulation in the US despite the situation being so bad that unsolicited spam subsidises the postal service and that even government agencies sell user data I’m not sure there is a desire for this from the general population.

It doesn’t help that politicians rely on a lot of what would breach the GDPR to help their reelection such as targeted advertising and unsolicited (and often misleading - pretending to be written by the official itself) email and phone campaigns.

Post reply on HN