Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

221–230 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#221

Earlier quoted context omitted.

Think of it as the law catching up with technology. > No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please. Indeed, hence the need for regulation. > Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around…

> Sure. But since EU citizens will be enjoying those protections and US citizens will not eventually this will translate into an advantage for companies doing business from the EU and into the US. For that reason alone there will be a big incentive for the US to make a law that is symmetrical to remove this advantage. Except it's literally the other way around. EU companies will be at a disadvantage because they cann…

> Except it's literally the other way around. EU companies will be at a disadvantage because they cannot use the data to neither improve their service or to monetize it in some way.

As if ROHS weren’t printed on each single piece of hardware produced on the planet.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#222
post #36

Earlier quoted context omitted.

We also got laid before the invention of the smartphone, you know...

And we also lived fulfilling lives before the invention of the smartphone, tv, printing press, sewer system or agriculture. What exactly is your point? There’s a user need. In this case it addresses the needs of a minority that’s been, until recently, highly oppressed. You don’t get to just say “things were fine before this existed”. When something imperfect solves a real problem you don’t get to just say “oh just do…

> You don’t get to just say (...)

I get to say whatever I want to say within the confines of the law and so do you. Let's keep it that way, shall we?

> What exactly is your point?

That it's still possible to get laid without a shady middleman/app

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#223
post #163

Earlier quoted context omitted.

You can try as hard as you can to wriggle out from understanding what this is all about but it is actually pretty clear: data supplied by an individual is the property of that individual, they have the right to informed consent on what it is used for, they can ask you to delete it, they can ask you to update it or review it. In some cases other laws (for instance: tax law) can make it mandatory for you to keep certai…

I have certifications in data privacy. The idea that data is "property" or that it is "owned" by anyone is not codified in law. And as an analogy for how GDPR works, I think it's more harmful than helpful. I see GDPR as rejecting the idea that data has an owner, more than anything. GDPR says that the data subject has rights to data about them. If you want to put a label on it, I would say that legally they are a stak…

Yes but that's a necessity to support lawful contracts between a person and an organization e.g. a loan provider.

The data subject, as I think, is the owner. They have rights over how and when their data is used & e.g. have a right to be forgotten.

They do not, however, always have the power to exercise their 'full' rights in cases where they've entered a binding contract. Such as trying to exercise the 'right to be forgotten' with a company who provided a loan they've defaulted on. They do however have the right through law to instruct the controller to use the data in the bare minimum ways they need to reasonably execute the contract.

A reasonable data protection legislation needs to side with the controller in some situations else it would be otherwise incompatible with modern society / law.

It certainly does help more than harm imo, especially when it comes to marketing / advertising.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#224

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

I read it on Idlewords: https://idlewords.com/talks/haunted_by_data.htm. Pretty much all the talks there are fantastic!

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#225

Earlier quoted context omitted.

> No business is interested in having to suddenly comply with such regulations jesus christ. enough with this bullshit. Data protection laws had been a thing in European countries for a decade before GDPR. GDPR itself gave everyone two years to comply. GDPR was published in 2016, five years ago . There's no effing "suddenly". If this is "suddenly" for your business, and your business still hasn't figured out how to n…

I get you're pissed off but it is probably more productive to keep a lid on it and stay constructive.

Maybe i could have also expressed more outright disdain for the practices of these companies in my original post. Then again, i think that the comment that you are responding to, despite its tone, has a fair argument.

> If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence.

> And all of those cookie banners are illegal under GDPR.

Here's the thing: if there's profit to be made, both large and small corporations alike are going to look for ways to achieve that, many other concerns (e.g. the actual UX or even ethics) remaining with secondary importance in comparison.

It doesn't even matter that some things are illegal sometimes, depending on how likely it is actually to be enforced. I think that this same disposition and attitude will also extend to lobbying and trying to nudge the lawmaking processes in a direction that benefits said companies, to maximize their profits in the future.

I'm not saying that things shouldn't be more like EUs outcome (in this one regard, at least), i'm saying that they won't be like that.

Just look at the pharmaceutical industry in US, the healthcare industry as a whole, or maybe the education industry or even the military industrial complex, all of which have probably seen lots of lobbying and lawmaking that doesn't necessary benefit the general populace.

Furthermore, for some businesses it is simpler to deny access to people who are protected by GDPR, either because of compliance taking more resources then they want to allot, or simply gaining no benefit from serving them content if they cannot use tracking cookies and monetize otherwise free interaction with their content.

So rather than figuring out how to not collect and sell user data, they're struggling to find ways around the laws, so that they can keep doing that in any capacity, or in some places, just ignore the laws altogether thinking that they're too small/big to actually be persecuted.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#226
post #220

Earlier quoted context omitted.

And before that we had the DPD, which companies routinely ignored because they would never get fined. That's the only part of the GDPR that made companies take notice: the fact that the GDPR has some pretty impressive teeth. I'm actually quite surprised at the restraint on display so far by regulators, but I'm also quite sure that it is a matter of time before a repeat offender will be shown just how powerful this la…

Regulators are contacting businesses which they suspect are in breach of GDPR to give them the chance to become compliant (I was in companies that received such communications). If the company is in good faith, they’ll fix whatever the regulator found or explain why haven’t breached the law. These cases don’t get discussed in the media probably because they aren’t published anywhere. Before a company gets a fine, at…

Indeed, I am aware of a few cases like this. But I'm also aware of a couple of companies that have swept breaches under the rug in recent times and if and when those surface they will be in pretty deep trouble.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#227

Earlier quoted context omitted.

I get you're pissed off but it is probably more productive to keep a lid on it and stay constructive.

Maybe i could have also expressed more outright disdain for the practices of these companies in my original post. Then again, i think that the comment that you are responding to, despite its tone, has a fair argument. > If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence. > An…

Oh, absolutely, make no mistake, I am entirely in agreement with the argument that you make, I'm just pointing out that the form is sub-optimal and not really in the spirit of the website it is made on. That said, I sympathize because I feel much the same way at times.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#228

Earlier quoted context omitted.

It's the opposite, actually. I have no idea how you came to this conclusion.

You can't give your data to a company which is not compliant with GDPR (for all practical purposes).

Check out the subject article here.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#229
post #78
post #68

Earlier quoted context omitted.

GDPR only requires informed consent to allow selling of data as far as I know. Am I wrong about that?

GDPR requires informed consent for ANY type of storing or managing any kind of personal data or data which can be linked to personal data (eg email which can contain name and surname of the person behind an account), and you must be explicit on what you do and you cannot give the data to another entity without re-requiring consent for that specific purpose and declaring who will be exactly the new controller of that…

I’m not sure where you got that idea from. Consent is just one of the six available lawful bases under the GDPR.

https://ico.org.uk/for-organisations/guide-to-data-protectio...

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#230

Earlier quoted context omitted.

That would be more than the full value of the company. Seems a little steep for the first fine.

€650 million does not seem steep at all for the offence, given the consequences for those involved. It’s not supposed to be a tax, it’s supposed to be a disincentive.

Exactly. Strict penalties work. Make the death penalty the punishment for every crime and there will be no more crime! Brilliant!
Post reply on HN