Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

141–150 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#141
post #81

Earlier quoted context omitted.

That's also the linear no threshold model. The risk of dying increases linearly with the number of bullets you load. A different model suggests that very low levels are either benign or even helpful.

> A different model suggests that very low levels are either benign or even helpful. Ah, the classic shoot yourself with small caliber bullets to build up an immunity against the larger caliber ones!

The radiation hormesis idea is controversial but that is a bad argument against it. Molecular scale events interacting with molecular scale DNA repair machinery is a different physical context than bullets.

The body is hit by natural radiation all the time and so it has mechanisms for this. Not so much for macroscopic projectiles.

The question is how these mechanisms behave and whether a small amount of radiation stimulates them… and then how much, for how long, etc. It’s a complex model with multiple systems and feedback loops.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#142
post #15
post #2

The Norwegian Data Protection Authority imposed a fine of €6,500,000 on Grindr for not collecting users' valid consent for sharing data with third parties for profiling and advertising purposes from the Grindr App. Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the cons…

Interesting indeed, it is what several German online newspapers do - they let you choose between a free version with tracking and a paid one without one. I find this argument a bit weird though: > Sharing Grindr's users personal data with advertising partners for online behavioural advertising purposes was not necessary for the performance of the Grindr's services. Charging money for your services is also not necessa…

> Why can't data be considered as a means of payment in this case?

One of the biggest reason would be that using data as payment has demonstrated to push out companies that don't want to collect data. Data as a mean of payment is less clear to the consumer about the costs, and there is no real good way to inform the public outside of an massive investment into the general education that focus on privacy, data laws, how data is gathered, why it is gathered, how it get traded and used, and what the outcomes are. The value added through data is also not taxed which creates an unfair advantage compared to other payment methods.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#143

Earlier quoted context omitted.

You can try as hard as you can to wriggle out from understanding what this is all about but it is actually pretty clear: data supplied by an individual is the property of that individual, they have the right to informed consent on what it is used for, they can ask you to delete it, they can ask you to update it or review it. In some cases other laws (for instance: tax law) can make it mandatory for you to keep certai…

most of the data relevant to gdpr legal cases are not supplied by the user, they are collected indirectly.

This is contrary to what I have seen in my day to day practice over the last couple of years. Now, of course it is possible that my sample size is too small (about 120 companies over that period) but I highly doubt that.

Data collected indirectly to would for instance be data used to 'enrich' a profile, for instance by buying it from a third party. That data would still show up in a DSAR, but it would likely not be private data because no company is stupid enough in the current climate to sell that without a very good legal review. Data collected surreptitiously (for instance, GPS location information, device IDs and such) count as user supplied for the purpose of the GDPR, and collecting that without consent and disclosing that you are collecting it and supplying a legal basis for processing is illegal.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#144

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

As usual this fine is not enough as deterrent.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#145
post #141

Earlier quoted context omitted.

> A different model suggests that very low levels are either benign or even helpful. Ah, the classic shoot yourself with small caliber bullets to build up an immunity against the larger caliber ones!

The radiation hormesis idea is controversial but that is a bad argument against it. Molecular scale events interacting with molecular scale DNA repair machinery is a different physical context than bullets. The body is hit by natural radiation all the time and so it has mechanisms for this. Not so much for macroscopic projectiles. The question is how these mechanisms behave and whether a small amount of radiation sti…

>The radiation hormesis idea is controversial but that is a bad argument against it

Jokes don't translate well in ASCII, sorry. It's a (I thought) well known meme.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#147

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

There's another way to make the collection of personal information less economical, which we can all contribute to. Send GDPR and CCPA data requests. Each request incurs some small but not insignificant cost for the company to handle it. This is because the process is hard to automate. Don't spam companies just for the sake of sending requests, but do get in the habit of using them to reduce your exposure.

Disclosure: I'm one of the founders of YourDigitalRights.org, a free service that makes it easy to send these sort of requests.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#148
post #139

Earlier quoted context omitted.

> Grinder surely made much more from data sales than the 6.something million Erous it was find. ...sure, but they also had business expenses. Fining them for all the revenue would more or less instantly kill the company, which is hardly the goal.

I've got an estimate here that says Grindr is doing 31 million dollars net on over 100 mil revenue per year. I am by no means in favor of running these companies into the ground. The fines are definitely a balancing act. But it seems at the present moment the expected value of breaking the rules is substantily higher than 0. https://www.reuters.com/article/us-health-coronavirus-ppp-gr...

Wait until they try this again. It may not be the Norwegian DPA that acts the next time around, it could be the UK DPO, the Dutch AP or any one of a whole raft of others, and they'll all take into account that they were already fined once before. This fine is level '2', apparently you ignored the first warning so now you get a major but not crippling fine. The next one will not be at that level, there is a pretty clear progression for repeat fines.

One case, a hospital first got a warning, then a small fine and then a mid six figure fine for a case involving a single patient. You can rely on them having learned their lesson and that there will not be a third fine.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#149

Earlier quoted context omitted.

Ah, the linear no threshold theory of radiation. If background radiation is everywhere , how can there be no safe dose . It’s a fun analogy, but reinforces an incorrect assumption.

> Ah, the linear no threshold theory of radiation. i wasnt aware this was contested. its what i was taught in the us nuclear navy. > If background radiation is everywhere, how can there be no safe dose. this is not a self-evident refutation and is a bad argument. cancer is the 2nd leading cause of death in the US, meaning there is an even higher nonlethal occurance of cancer. this is not all radiations doing, but its…

LNT is controversial because there is not enough data to support it. The data that we do have doesn't support any low-dose model conclusively as far as I know. The upside of this is the effects have to be very small, so it basically doesn't matter, because the risk of low-doses is effectively zero regardless the theory. The problem with LNT in terms of science communication is it's easy to make it sound as-if the risk isn't effectively zero.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#150

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

There's another way to make the collection of personal information less economical, which we can all contribute to. Send GDPR and CCPA data requests. Each request incurs some small but not insignificant cost for the company to handle it. This is because the process is hard to automate. Don't spam companies just for the sake of sending requests, but do get in the habit of using them to reduce your exposure. Disclosure…

I'm all for that but only if you suspect that a company is abusing your data. Otherwise it amounts to a DDOS attack and that should be reserved for those that deserve it, not to place a burden on otherwise compliant companies.

But if you suspect that a company is abusing your data, selling it, enriching it with data that they shouldn't have: fire away.

Post reply on HN