Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

141–150 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#141

Earlier quoted context omitted.

[flagged]

[flagged]

So you're saying that the more people disagree with you, the more entrenched you become in your position?

That doesn't sound like a healthy way to form opinions.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#142
yawn Wake me up when they start imposing €800k fines on businesses that can't afford to pay. Right now, GDPR feels like a way to shake down large businesses for free money, not a serious law they want to impose for principled reasons.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#143

Some questions I need answered, that have yet to be answered in the article, or the comments here: Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort? One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answer…

You don't have to have a presence established in the EU to be under EU jurisdiction. Any european user makes you responsible to ensure GDPR rules for that user.

So even if Discord had no presence in the entire EU, no office, no worker, no nothing, it doesn't absolve the company from staying within GDPR rules for their european users.

Only way to get out of that problem is to block any user with a european IP, although even then you could have users using a VPN, not sure how this would handle before the law.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#144
post #38

So if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?

Probably nothing happens. I doubt they're going to spend time investigating a company that doesn't do any business in Europe, when there's a very long list of bigger companies that do operate here and break our privacy and sell our data.

If the company doesn't do any business in Europe it has no users in Europe, therefore it doesn't have to comply with the GDRP at all.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#145

Something worth noting that a lot of comments are ignoring here: while this fine is coming from the EU, these kinds of data protection rules are _everywhere_ now - this is no longer really EU-specific. The reality is that it's not an US companies vs EU data protection law battle - it's US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Bra…

Have those other laws been enforced against Discord? Also, pulling out of one zone because they enforced (what you believe to be an onerous) a law against you is always valid, it'll make the others think hard about enforcing the law against you.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#146
post #59

Earlier quoted context omitted.

Yes, the European Commission will collaborate with international governments to impose fines.

Which international governments? Why would the US agree to impose an EU fine, and under what legal basis?

Why would European countries extradite american criminals to the US? Because we established a trust in each other and want to keep it that way for both sides benefits.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#147
post #131

Earlier quoted context omitted.

My question as well. Can a non-EU company simply refuse to pay, and also refuse to block users from the EU? I wonder if the EU would decide to block access to the foreign service as a result. It would at least force them to be honest about the fact that they're effectively turning the internet into a legal-regional network rather than a global one.

> It would at least force them to be honest about the fact that they're effectively turning the internet into a legal-regional network rather than a global one. This happened a long time ago. And it was started by the US, I'm quite sure. More than that, the American way to manage the "global network" is basically to impose US laws everywhere in the world. You can receive DMCA notices outside the US, for example. Or e…

> The case raised some concerns of civil rights and legal process in the United States, and ended in the charges against Sklyarov dropped and Elcomsoft ruled not guilty under the applicable jurisdiction.

So it's an example of "law enforcement can and sometimes do illegally attest / cause other issues unfairly", but not really a good example of a law being imposed outside the country which made that law.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#148

Some questions I need answered, that have yet to be answered in the article, or the comments here: Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort? One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answer…

GDPR applies to any company that offers services to EU residents. It doesn’t matter if the company has any presence in the EU.

Now, that means EU may not necessarily be able to force the company operating in a different country to pay up but if a company has any significant EU customer base, I assume they will play ball.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#149
post #4
post #3

> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applicatio…

Doesn't Skype have the same behaviour? Clicking "X" doesn't close the application.

Chat apps had that behavior since decades ago, ever since Windows95 got a systray. It's nothing new or special, it's kind of expected at this point.

Though I think here is a failure of Microsoft to improve the UI and use different symbols for closing the app and suspending it into the systray.

Either way, seems like a rather strict interpretation of 25.2. That said, I kind of welcome it. The principle of least surprise is something that should be much more strictly enforced and a lot of social apps make it way to easy to accidentally leak data into the public.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#150
post #39

Earlier quoted context omitted.

They accept money from EU customers so, yes

If I accept money from a Chinese guy, that doesn't make me subject to Chinese law.

As a one-off donation? Probably not.

As a business? For sure. Not for every aspect of Chinese law, but for relevant ones and with enforcement in China or through mutual agreements with other governments.

This kind of comment is disappointing.

It shows a major lack of understanding of how law and businesses work, coated in a huge layer of outrage, all wrapped up in a Twitter-length type comment.

Post reply on HN