Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

61–70 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#61
post #33

Earlier quoted context omitted.

Can you explain a bit more? What's the problem here?

EU being able to attack any developer by making up a GDPR excuse and fine them as they want is the problem here.

That would be a problem. However, that is not what happened.

Discord (the company) was fined for multiple breaches of the GDPR regulation.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#62
post #3

> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applicatio…

> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applicatio…

Importantly, Teams will leave a meeting if you exit the Meeting window.

Keeping the meeting going in the background is honestly pretty crazy.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#63
post #30

Earlier quoted context omitted.

I'm not fond of regulatory agencies defining what constitutes an acceptable password policy. Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth.

How is this UI design? Wouldn't this fall under UX or just basic functionality? I press X, program close. If I want it minimized I press the minimize button.

"X" hasn't meant end the process for over 20 years.

In 2022, it could very well be the better choice for most users to not end a voice call just because they clicked the "X" to get rid of the window. Just like what Skype, other Voip services, and most chat services have done forever.

This ruling is a bit disappointing.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#64

Earlier quoted context omitted.

Why do apps think it is necessary to start playing with the UI when we have a minimise button? When I click "X" I expect the application to exit as it did in Windows 1.0 and the minimise button to either put it in the startbar or the status bar but keep running. EDIT: I remembered incorrectly, Windows 1.0 did not have a X button but a close button on the right side of the window.

Apps minimizing to systray when their main window is closed have existed since at least Windows 95/98. Yahoo! Messenger and probably AOL did the same thing 25 years ago.

Minimising to the stray isn't so much the problem as remaining connected to the voice chat. Skype in this circumstance doesn't fully minimise but still has a little foreground window making it obvious that you're still on the call.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#65
post #38

So if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?

My question as well. Can a non-EU company simply refuse to pay, and also refuse to block users from the EU? I wonder if the EU would decide to block access to the foreign service as a result. It would at least force them to be honest about the fact that they're effectively turning the internet into a legal-regional network rather than a global one.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#66

[flagged]

> It's just a "weapon" by the EU to attack any company they want. I'm pretty much sure if I made a hello world program in C, they'd find a clever way of fining me.

Not so. Your hello world in C be just fine. Only if you track data of users that happen to live in the EU. Don't track and you absolutely will not violate GDPR.

Discord broke the law in France and gets fined according the the laws in France.

The flagged issues could have been easily avoided by having a proper GDPR trained lawyer review the service and suggest changes.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#67
post #33

Earlier quoted context omitted.

Can you explain a bit more? What's the problem here?

EU being able to attack any developer by making up a GDPR excuse and fine them as they want is the problem here.

How are they even making things up here? If you read through the entire thing they have a very valid case against Discord, ranging from the UX being confusing (i.e. "data protection by default") to actually storing the data they are not allowed to (i.e. illegally).

If you operate in a jurisdiction you operate by that jurisdictions laws. Do you think European companies don't have to abide by US laws when operating in the US?

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#68
I'm an EU citizen and support the GDPR. But it's only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies.

Borders and tariffs will be the long-term future of the Internet.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#69

[flagged]

I think GDPR being a weapon to attack companies is a good thing.

I've always thought that the bad aspect of GDPR is that it's General. We have in Slovenia a strict law about privacy and personal data protection. Companies with Slovene customers had to implement country specific notices and contracts, but GDPR made that easier. Especially for companies.

That's how I viewed it; as a legislation that allows companies to harvest user data easily and that's the main point why I was against it.

This comment sort of opened my mind a bit, now the same central legislation can also be used for the benefit of the people, since a legislation enforcement agency does not have to know so much regulation to defend user data. Though on the other hand, the GDPR is pretty long, much longer than slovenian law (we didn't implement GDPR yet, SI is currently paying fees for not implementing it).

Note: Big AFAIK -- law is really not something I understand, please correct me or add your opinion.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#70
post #59
post #38

So if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?

Yes, the European Commission will collaborate with international governments to impose fines.

Which international governments? Why would the US agree to impose an EU fine, and under what legal basis?
Post reply on HN