Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

71–80 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#71

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

It's a slap on the wrist.

100x this fine would have been appropriate. Anything less just encourages other companies to treat privacy and data security as a joke.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#72

The thing that always bothered me most about Grindr is the fact they do not allow any connectivity from VPNs, even if you have an upgraded account. This doesn't seem to jive well with the need for privacy or anonymity in places where it's dangerous to be gay.

Works with Mullvad (most of the time)

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#73
One thing I'm wondering with these fines is whether they are actually "dissuasive".

In particular, the revenue limit seems problematic. For a "normal" company whose profit margin is a relatively small fraction of revenue, 4% of revenue is huge. But for highly profitable large tech companies that make money primarily from ads, it may not be possible to issue a dissuasive fine if it is capped to 4% of revenue. Maybe "4% of revenue, or 200% of profit, whichever is higher" would be a better limit.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#74
post #52

Earlier quoted context omitted.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

But, to use your analogy, why would companies treat user data like uranium when risk/reward is like that of oil? Grinder surely made much more from data sales than the 6.something million Erous it was find. The paltry fines under GDPR do nothing to dissuade this behavio. That's been a recurring theme in previous HN discussions on this topic. Right now, I would posit that these low penalties are for show. Governments…

> Grinder surely made much more from data sales than the 6.something million Erous it was find.

...sure, but they also had business expenses. Fining them for all the revenue would more or less instantly kill the company, which is hardly the goal.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#75

Earlier quoted context omitted.

What aspect of GDPR is troublesome to you? Because 'dont abuse your ownership of personal data' is pretty much what it boils down to.

>What aspect of GDPR is troublesome to you? It tries to restrict data. Information wants to be free. It has no owner.

Data should be restricted, when it pertains to an individual who wants it to be restricted - basically everyone in the EU.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#76

Earlier quoted context omitted.

neat, this analogy travels pretty far - user data is radioactive. theres a background amount of radiation. its everywhere, even in higher amounts than youd expect like bananas and airplanes. no amount is safe, but the risks are neglibly small when exposure is minimized. concentrated amounts can be safe when exposure is controlled and managed with oversight programs in place. disasters can be managed with disaster pro…

Ah, the linear no threshold theory of radiation. If background radiation is everywhere , how can there be no safe dose . It’s a fun analogy, but reinforces an incorrect assumption.

Can’t it be like playing Russian roulette with a gun that has billions of chambers? The gun is always unsafe, but you will probably be fine?

The higher the level, the more full chambers?

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#77
post #66

Earlier quoted context omitted.

A fine of this size indicates to me they should harvest and sell more data to increase profits. Tens of millions would still probably be worth it to Grindr. Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter. Nah, this fine (which I don’t even know…

Wait a second, it's not Grindr gathering and selling a list of homosexuals interested into sex. It's the users themselves who actively register on Grindr to announce their services and picture on the platform. If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.

The users aren’t gathering aggregated data of millions of other users and selling it.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#78
post #68

Earlier quoted context omitted.

If you keep it around to sell then you are likely violating the 'legal basis for processing' part of the GDPR. Data can only be used for the purpose for which it was originally collected, selling the data to others to use without that exact same goal can not be such a purpose, and even then you will have to be quite careful that you maintain control. Various EU data brokers (Schober, for instance) have found ways to…

GDPR only requires informed consent to allow selling of data as far as I know. Am I wrong about that?

GDPR requires informed consent for ANY type of storing or managing any kind of personal data or data which can be linked to personal data (eg email which can contain name and surname of the person behind an account), and you must be explicit on what you do and you cannot give the data to another entity without re-requiring consent for that specific purpose and declaring who will be exactly the new controller of that data.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#79
post #66

Earlier quoted context omitted.

A fine of this size indicates to me they should harvest and sell more data to increase profits. Tens of millions would still probably be worth it to Grindr. Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter. Nah, this fine (which I don’t even know…

Wait a second, it's not Grindr gathering and selling a list of homosexuals interested into sex. It's the users themselves who actively register on Grindr to announce their services and picture on the platform. If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.

And what if the country want info on people outside the country. They may want to be sure that they can catch the homosexuals when they come to visit or prevent them from visiting (friends family etc) altogether. Whether or not the person signed up in the first place, nobody should be able to buy the data

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#80

Earlier quoted context omitted.

What aspect of GDPR is troublesome to you? Because 'dont abuse your ownership of personal data' is pretty much what it boils down to.

>What aspect of GDPR is troublesome to you? It tries to restrict data. Information wants to be free. It has no owner.

Then would you mind posting a dump of your email archive here? Or does that data have an owner?
Post reply on HN