Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

181–190 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#181

Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.

How does this work for IRC networks?

IRC network is simply a relay. It doesn't have anything to delete begin with.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#182

Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.

I think they ended up fixing this, all the deleted users I can find resolve to UID 456226577798135808. Although, messages that used to @mention the user don't have their UID mangled (since @mentions are really ` `), so it'd be easy to correlate someone @pinging a deleted user and that deleted user responding to the ping. Seems like fixing this would be pretty challenging (logistically and computationally) given you'd…

[deleted]

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#183

Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.

Not only should they get fined. They should also fix the problem.

They did. The CNIL did several control and verified that they indeed fixed the issues.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#184
post #106

Earlier quoted context omitted.

I'm not fond of regulatory agencies defining what constitutes an acceptable password policy. Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth.

> Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth. There are probably a bunch of regulations that dictate on what is in your car's cabin and how they work.

Cars are tons of metal moving at very high speeds under manual control, so I can understand why that would need greater regulatory scrutiny.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#185

Something worth noting that a lot of comments are ignoring here: while this fine is coming from the EU, these kinds of data protection rules are _everywhere_ now - this is no longer really EU-specific. The reality is that it's not an US companies vs EU data protection law battle - it's US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Bra…

Have those other laws been enforced against Discord? Also, pulling out of one zone because they enforced (what you believe to be an onerous) a law against you is always valid, it'll make the others think hard about enforcing the law against you.

> it'll make the others think hard about enforcing the law against you.

We are not talking about some high-security military stuff here, it's only a chat app.

It might be a big part of your world, but I can guarantee you that if they try to pull that off nobody in any government would care.

I am pretty sure of the contrary actually: that several governments in EU have dreams of getting rid of these platform, and that they can't do it because that would be illegal.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#186

Earlier quoted context omitted.

How does this work for IRC networks?

IRC network is simply a relay. It doesn't have anything to delete begin with.

I'm sure most sizable IRC networks have some level of logging if only to validate claims of spam or rule-breaking.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#187

Some questions I need answered, that have yet to be answered in the article, or the comments here: Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort? One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answer…

Why do you need the answer to this? If your follow up question will be "how can the EU do anything against a company that operates outside of its jurisdiction?", then the answer will be "by making it difficult for people in the EU to do business with Discord". The EU could restrict payments to Discord for example, cutting their revenue.

Let me answer your question with another question.

Why is it so forbidden to ask this question, and know this answer? It's just a basic fact.

My suspicion is that the GDPR apologists know that it's a weakness for their argument, and are afraid to debate on that.

As it so happens, funnily enough, Discord has a branch located in the EU. This could easily end the discussion of "does the EU have jurisdiction?" The answer is, yes! Discord is a company in the EU!

We shouldn't be afraid of basic facts. If our argument can't survive a simple fact, then our argument doesn't deserve to exist.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#188

Earlier quoted context omitted.

Did the users choose to install the Discord app (or run a random command?) How are you supposed to confirm "user understanding"? Does the program need to require a tutorial/training before it's being used? A user's ignorance shouldn't be a software distributor's problem. If the discord app didn't have a system tray, and hid it's process from the Process List someway, maybe you have a point - this is just ignorance ac…

I think if you are doing the close is actually not killing the app you should ensure the user is aware the app is still recording. Some apps will show a recoding thinggy ont he screen or it will tell you before closing and you need to agree. I don't have the time to test this, but if is true that you close the app and it sill continue recording that this is bad UX and the company should have prioritize fixing this in…

Doesn't it show a system tray icon? (I don't use discord on Windows, or a system tray myself) - is a system tray icon not adequate? I believe it would show 24/7 wouldn't it?

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#189
post #29

Props to the EU for keeping data giants accountable. It is a shame the data protection authorities only have resources to process so many companies, unfortunately, many get away with much more harm to user privacy.

Each country also has it's 'in house' version, that prosecute various offenders on a local/ their-national level.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#190
post #76

Earlier quoted context omitted.

I think in the Discord model it makes more sense because it's based off of how online gamers flow (basically open a voice chat and stay on there for hours on end).

It's still outside the norm on Windows I would say, even though I understand why they did it.

Gamers obviously don't talk only when they open discord. They talks in 'game' with discord minimized. It would be dumb if hide discord to background while keep chatting is a manual action by default. But that behaviour can be changed. You can ask discord to exit the app when you click x if you prefer. There is an option for it.

And about teams... who the heck want to be kept in a meeting if they are already ready to close the app?

They are just different mindset.

Post reply on HN