Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

191–200 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#191

Something worth noting that a lot of comments are ignoring here: while this fine is coming from the EU, these kinds of data protection rules are _everywhere_ now - this is no longer really EU-specific. The reality is that it's not an US companies vs EU data protection law battle - it's US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Bra…

Have those other laws been enforced against Discord? Also, pulling out of one zone because they enforced (what you believe to be an onerous) a law against you is always valid, it'll make the others think hard about enforcing the law against you.

Vpn's exist. I fairly frequently come up against us websites that tell 'content not available in your area due to gdpr'. Thankfully the vpn i use is three clicks and I'm in America.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#192
post #139

Earlier quoted context omitted.

Right which to me is a distinction without a difference. If you and me are both Gmail users and you send me an email then delete your account should Gmail have to reach into my inbox and delete your emails? They’re on Google’s servers after all.

There's a spectrum of things I can share with you over gmail. Currently, if I share an email with some formatted text and attachments up to 25MB, then it's yours to keep, but anything above 25MB is shared as a link to a Google Drive upload, which remains under my account, and I can always delete or modify. But I don't see any particular reason for where exactly the line between the two should be - why wouldn't it be…

Interesting; for me line seems fairly thick at "ownership" level (which just shows we may have different assumptions:)

My thoughts:

If it's in my inbox (whether on my physical phone, or hosted for me by a service provider), I own it and I get to control it regardless who sent it / how it got there (as long as other legal pre-requisites are met, i.e. not child porn etc)

If it's in my outbox, and I want to delete my account, THOSE instances of those artifacts should be removed, whether from my physical phone or by the service provider hosting them for me. If I've sent them to others, fair game, they own THOSE instances; but I expect the service provider to remove, upon my request, the artifact instances I solely own.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#193

Earlier quoted context omitted.

it's not so simple as "disliking the UI", it's about the UI/UX being clear enough that the user understand what he is doing in order to not be harmed by it in any way (disclosing personnal information for instance). Simply imagine that the user thought that, by clicking the "X" button, he closed the app and got off the vocal channel so that now nobody can hear him. Now a close relative ask him some other personnal in…

> Simply imagine that the user thought that, by clicking the "X" button, he closed the app Do most users think that, though? I remember chat apps minimising to the tray bar since MSN Messenger and Skype, possibly earlier, and it's a common feature in most current ones, as well as in other applications. Now, it's true that some other chat apps display a floating panel to remind you that you're still in voice chat, but…

Look at your web browser.

If you click on the "x" on a open tab, it will most likely close it. If you click on the "x" on your browser, it will close the browser, maybe will it alert you that you're going to close many things.

Open Microsoft Excel or Microsoft Word, Notepad, your Windows file explorer, same thing.

Those are probably the most used app in the world, so people will assume that it is what the "x" button does.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#194
post #169
post #153

Earlier quoted context omitted.

But Windows misrepresents that the application is not running, when it is running in the background with access to the mic. Is this not a poor default? The justification here is that Discord behaves differently from "the vast majority of applications". First, I'm not sure if that's true. Second, another justification brought up is that Discord doesn't show the user that their mic is still hot, Windows seems just as c…

I would say it shows an icon on the system tray, but I think recent versions of Windows like to hide unused icons for whatever reason. In my experience; quite a few programs will minimize to system tray when pressing x.

The issue highlighted in the article is no other VoiP/chat program will continue to record audio in the background. Which you can absolutely do, just don't make it the default behaviour. Valid point in my view.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#195
post #127
post #117

Earlier quoted context omitted.

But it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is s…

I agree with you in principle and I think that the EU is basically extorting American companies, but in your example all that information is stored in your phone, while in this case the information is stored in Discord's servers.

Does GDPR distinguish these cases? Personal information is fine to keep on an individual's computer, but not on a company computer? What about personal cloud storage like Google Drive (company's servers, individual's data)?

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#196
post #4

Earlier quoted context omitted.

Doesn't Skype have the same behaviour? Clicking "X" doesn't close the application.

Chat apps had that behavior since decades ago, ever since Windows95 got a systray. It's nothing new or special, it's kind of expected at this point. Though I think here is a failure of Microsoft to improve the UI and use different symbols for closing the app and suspending it into the systray. Either way, seems like a rather strict interpretation of 25.2. That said, I kind of welcome it. The principle of least surpri…

I would say close the window of chat app kill the ongoing chat session more surprising than not. The worst you should do is a prompt with yes/no and a checkbox to remember my decision when you do it the first time.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#197
post #68

I'm an EU citizen and support the GDPR. But it's only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies. Borders and tariffs will be the long-term future of the Internet.

Well, the US has already a lot of restrictions to companies that want to do business in dollars and not just on Internet companies.

See https://www.justice.gov/opa/pr/bnp-paribas-agrees-plead-guil...

This is a case of trade with countries under embargo.

One of the main use of internet surveillance was trade (e.g. Boeing vs. Airbus deals).

I believe the US department of justice have the right structure to make this kind of fines, part of the fines goes to found the department of justice.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#198

Earlier quoted context omitted.

[flagged]

> against its own culture Could you elaborate what that culture is supposed to be exactly, and why it should require us to side with Discord here?

Freedom and innovation, not rules and regulations.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#199

Earlier quoted context omitted.

IRC network is simply a relay. It doesn't have anything to delete begin with.

I'm sure most sizable IRC networks have some level of logging if only to validate claims of spam or rule-breaking.

Even with that. It's anonymous if you don't login. All you do is pick a name you like, type something random and exit. And all they have is an ip address that may change at anytime.

I am not sure if GDPR should apply if that can't be used to trace back to you at first place.

And if this should apply. I think everyone on the earth that connect to internet are probably in danger. You visit my site and leave a message. And I am suddenly a target of GDPR, what?

Also, do GDPR actually care about internally logs? I think the requirement is the data on that platform can no longer be used to trace back to the user. But logs aren't even exposed to users.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#200
post #198

Earlier quoted context omitted.

> against its own culture Could you elaborate what that culture is supposed to be exactly, and why it should require us to side with Discord here?

Freedom and innovation, not rules and regulations.

Freedom for me, but not for thee. These rules and regulations are the result of not respecting users' freedoms.

Certain kinds of "innovations", from bioweapons to pushing teenagers towards suicide for profit, should be banned.

Post reply on HN