Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

161–170 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#161
Grindr is a repeat offender, globally.

In 2018 researchers found that Grindr was sharing users' HIV status and location with marketing companies: https://www.buzzfeednews.com/article/azeenghorayshi/grindr-h...

Just this year there was a scandal where an anti-gay church fired one of its officials because a homophobic publication somehow got access to his Grindr account and his location data. The details on how the data got out are not clear. https://www.vice.com/en/article/pkbxp8/grindr-location-data-...

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#162
post #142
post #15

Earlier quoted context omitted.

Interesting indeed, it is what several German online newspapers do - they let you choose between a free version with tracking and a paid one without one. I find this argument a bit weird though: > Sharing Grindr's users personal data with advertising partners for online behavioural advertising purposes was not necessary for the performance of the Grindr's services. Charging money for your services is also not necessa…

> Why can't data be considered as a means of payment in this case? One of the biggest reason would be that using data as payment has demonstrated to push out companies that don't want to collect data. Data as a mean of payment is less clear to the consumer about the costs, and there is no real good way to inform the public outside of an massive investment into the general education that focus on privacy, data laws, h…

It’s quite amazing that something most people see quite worthless ("my data") is suddenly seen by the society as priceless (since I can’t buy it with money).

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#163

Earlier quoted context omitted.

> Data IS owned, by the person the data pertains to This is an almost undefined concept. Data is not copyright, they are observations. Plus for many kinds of data ownership is hard to define, e.g. genetic data which is largely shared by all of us.

You can try as hard as you can to wriggle out from understanding what this is all about but it is actually pretty clear: data supplied by an individual is the property of that individual, they have the right to informed consent on what it is used for, they can ask you to delete it, they can ask you to update it or review it. In some cases other laws (for instance: tax law) can make it mandatory for you to keep certai…

I have certifications in data privacy.

The idea that data is "property" or that it is "owned" by anyone is not codified in law. And as an analogy for how GDPR works, I think it's more harmful than helpful. I see GDPR as rejecting the idea that data has an owner, more than anything.

GDPR says that the data subject has rights to data about them. If you want to put a label on it, I would say that legally they are a stakeholder in their own data. One stakeholder of several. Not necessarily the most prominent one. GDPR gives you a seat at the table, but it doesn't actually put you in charge, the way that "ownership" implies.

The company that collects & processes the data is still the one making decisions like: What data is being collected? What is it used for? What is the Legal Basis for data collection? What Processors will the data be sent to? What countries will the data be processed in? They have a lot of leeway in how they answer these questions and still be compliant with GDPR.

So for that reason, my view is that GDPR says there are multiple stakeholders will different rights to how the data is handled. Which if anything is a rejection of the idea that the data has an owner. Certainly you have rights to the data, but some of those rights have limits, and the Controller still has right as well.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#164

Earlier quoted context omitted.

I meant giving a million dollar per user. People would try to sue them en masse. They would have no choice but to be very strict about what they do with our data.

Give millions of users a million dollars each? That seems... not very practical!

As much as I want to punish this, the actual outcome of heavy-handed fines would probably result in the company selling off all its assets... whoops there goes the database into the hands of an even less scrupulous actor.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#165
post #50

Earlier quoted context omitted.

What’s your alternative? Clearly people use the app because the app answers a user need. So what’s your answer to the user need?

There are alternatives, but due to their bad business practices ( such as illegally collecting and selling their massive database of user data, and probably things I’d never think of) impossible to overtake. Consider existing brand awareness, and ongoing massive marketing spend.

I highly doubt any of the primary other gay dating apps have significantly better data collection practices.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#166
post #82

Grindr is incorporated in the US, I'm not sure how they plan to enforce this fine.

Maybe someone for Norway can pitch in about how this works.

Even though Norway is not a EU country, it's part of the EEA and various other treaties with the EU and hence they ended up implementing GDPR, it seems possible that they end up being having authority to enact EU/EEA wide enforcement actions.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#167
post #12

Good. Grindr is probably the best example of extremely high brand & network value vs shockingly poor security & application quality. The company demonstrates zero integrity and needs to be shut down or fined to death. It would send a proper warning to the industry, though long overdue.

Grindr is/was considered a poor quality brand from an advertising perspective. Nobody wants their ads to appear next to graphic images

Not true, depending on the product. I'm sure the PreP ads I see on Grindr have no problem advertising on a gay hookup app.

But more to the point, Grindr got in trouble specifically for selling data to advertising networks presumably so they could also be targeted outside Grindr. Knowing someone's sex, sexual orientation, location, age and hobbies is great targeting data.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#168

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

Or you could see it as operating in the EU is a liability. If you don't handle data in just the way they like they will come after you.

GDPR enforcement is pretty gentle. For the first offence you will just get a warning. Grindr's fine is a warning that you should heed such warnings.

Yes, operating in the EU is a liability; operating anywhere that has laws is a liability. And the risks of operating somewhere that doesn't have laws is an even greater liability.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#169

Earlier quoted context omitted.

> Ah, the linear no threshold theory of radiation. i wasnt aware this was contested. its what i was taught in the us nuclear navy. > If background radiation is everywhere, how can there be no safe dose. this is not a self-evident refutation and is a bad argument. cancer is the 2nd leading cause of death in the US, meaning there is an even higher nonlethal occurance of cancer. this is not all radiations doing, but its…

LNT is controversial because there is not enough data to support it. The data that we do have doesn't support any low-dose model conclusively as far as I know. The upside of this is the effects have to be very small, so it basically doesn't matter, because the risk of low-doses is effectively zero regardless the theory. The problem with LNT in terms of science communication is it's easy to make it sound as-if the ris…

> it basically doesn't matter, because the risk of low-doses is effectively zero regardless

this is exactly what i said in my original comment.

I looked up competing LNT models. TIL about radiation hormesis. theoretically, near-zero but >0 levels of radiation activate dormant repair mechanisms that not only repair radiation damage, but also non-radiation damage; this results in a healthier host. interesting.

having thought about this for all of 30 seconds, i wonder if both models arent simultaneously correct. if most radiation damage is repairable, activating dormant repair mechanisms with tiny amounts of radiation would be a net benefit. however, if there exists any possible irrepairable damage in any cell anywhere on your body regardless of otherwise functioning repair processes - which i dont know to be true but seems likely - then LNT could also be true concurrently with radiation hormesis.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#170

Maybe it's time that frameworks like Django and Rails make it easier to be GDPR compliant from day 1. ASP.NET Core has APIs and templates for this: https://docs.microsoft.com/en-us/aspnet/core/security/gdpr?v...

Maybe it’s time companies stop hoarding and reselling users’ personal data.

These built-in templates for cookie popups are a joke, IMO.

Post reply on HN