Live data from Hacker News

Discord fined €800k for failing to comply with several obligations of the GDPR

cnil.fr

211–220 of 306 posts

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#211
post #68

I'm an EU citizen and support the GDPR. But it's only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies. Borders and tariffs will be the long-term future of the Internet.

I guess their assumption is that US wouldn't have that many options whom to retaliate to. Who would they fine? Spotify, maybe? Who else?

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#212

Earlier quoted context omitted.

Importantly, Teams will leave a meeting if you exit the Meeting window. Keeping the meeting going in the background is honestly pretty crazy.

Its by-design, so you can voice with people while playing multiplayer games.

Minimising the window would achieve that, it's not necessary for closing it to also do so.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#213

Earlier quoted context omitted.

The point of GDPR is to defend the user. Tech companies aren't your friends, they only want your money. What baffles me is people being outraged by this fine like they needed to pay that, not a billion dollar tech company. It is justified because what Discord didn't implement can harm the user. it can harm YOU. People easily forget that Internet is for everyone. Even for people that didn't grew with a computer, even…

Governments aren't your friends either

At least the government is supposed to protect its citizens from harm and not act for its own interest, but yeah, debatable nowadays

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#214

Earlier quoted context omitted.

I'm sure most sizable IRC networks have some level of logging if only to validate claims of spam or rule-breaking.

Even with that. It's anonymous if you don't login. All you do is pick a name you like, type something random and exit. And all they have is an ip address that may change at anytime. I am not sure if GDPR should apply if that can't be used to trace back to you at first place. And if this should apply. I think everyone on the earth that connect to internet are probably in danger. You visit my site and leave a message.…

yes GDPR care about internal data like logs, because companies get breached all the time and data get leaked.

Since GDPR, PII (Personal Identifiable Information) data has become radioactive, the less you touch it easier your life is.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#215
Just because I haven't logged in in two years doesn't mean I want my account deleted... And they get fined for putting the app in the tray when user click the X button? And because they accept 6 character passwords? Those regulations are insane.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#216
post #171

Earlier quoted context omitted.

No. Email is private messaging. If you send email to me and then delete it in your end, I'm allowed to store your email as a whole (sometimes legally obliged).

And if I send an email to 200 recipients they can all store it, I don’t see the fundamental difference for discord TBH

You can save a screenshot discord chat too. There’s nothing wrong with that. If someone published something and you want to save a copy for personal purposes, go ahead.

The difference is in what Discord’s responsibility is.

If Discord claimed to have deleted an account, then they shouldn’t still be publishing a post from a user. Especially if such a post could still be tied back to the historical user id.

I can understand why they’d want to keep the data (sometimes you need to keep an archive of posts for legal reasons - for a limited time). But making an archived post visible to the public is the problem.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#217
post #127
post #117

Earlier quoted context omitted.

But it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is s…

I agree with you in principle and I think that the EU is basically extorting American companies, but in your example all that information is stored in your phone, while in this case the information is stored in Discord's servers.

American companies are free to not do business within the EU. If they do, they must comply with the law. Same with USA, China, Russia, etc.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#218

Earlier quoted context omitted.

And if I send an email to 200 recipients they can all store it, I don’t see the fundamental difference for discord TBH

You can save a screenshot discord chat too. There’s nothing wrong with that. If someone published something and you want to save a copy for personal purposes, go ahead. The difference is in what Discord’s responsibility is. If Discord claimed to have deleted an account, then they shouldn’t still be publishing a post from a user. Especially if such a post could still be tied back to the historical user id. I can under…

An even better analogy would be a mailing list, instead of directly emailing/cc-ing recipients. Definitively not "private messaging".

If I delete my email account, and/or remove it from the list, there's no expectation that my prior emails are deleted for any of the other list subscribers.

The mailing list archive isn't pruned of my account and everything I ever sent will still be visible.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#219
post #169

Earlier quoted context omitted.

I would say it shows an icon on the system tray, but I think recent versions of Windows like to hide unused icons for whatever reason. In my experience; quite a few programs will minimize to system tray when pressing x.

The issue highlighted in the article is no other VoiP/chat program will continue to record audio in the background. Which you can absolutely do, just don't make it the default behaviour. Valid point in my view.

"The issue highlighted in the article is no other VoiP/chat program will continue to record audio in the background. "

Just tested in a call with Skype. Closing the windows still has the program running, recording, and the call is still active.

Ditto Camfrog.

Ditto Paltalk.

That's because most actual programs have a 'minimize to tray on closing' option enabled by default on install.

It's been like this since 1998 or so. I've been undoing that option for at least 20 years, because when I click X I expect it to GTFO.

Re: Discord fined €800k for failing to comply with several obligations of the GDPR

#220

Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.

Discord is a massive data store. They hoard messages. The only reason for this is to someday sell it. It doesn't matter what the CEO says, it's the investors that own it. They either have to become profitable, or sell.
Post reply on HN