Earlier quoted context omitted.
The point of GDPR is to defend the user. Tech companies aren't your friends, they only want your money. What baffles me is people being outraged by this fine like they needed to pay that, not a billion dollar tech company. It is justified because what Discord didn't implement can harm the user. it can harm YOU. People easily forget that Internet is for everyone. Even for people that didn't grew with a computer, even…
Governments aren't your friends either
Discord fined €800k for failing to comply with several obligations of the GDPR
241–250 of 306 posts
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#242I'm an EU citizen and support the GDPR. But it's only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies. Borders and tariffs will be the long-term future of the Internet.
There nothing new about companies enforcing their existing laws on imported goods and services and the eu-us free trade agreement's already contains clauses where both parties have to assist each other if a company is trying to evade those rules. The only thing new is that the regulators are now considering digital services to cross the border when there is money flowing the other way.
If the US were going to raise a stink they would have done so when the EU kept doubling MS antitrust fine until MS eventually paid up, issuing GDPR fines to discord that is smaller then what smaller European companies have been fined ain't going to be an issue for the trans Atlantic trade relationships. Especially as GDPR style rules are being proposed at the state level in the US.
Region locking of copyrighted material is where the real blocks in content is going to come into play(as it already have) but that is a whole different can of mud.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#243I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn't any mention of timelines or any other definition of "necessary".
As a user, I wouldn't want my account blown away just because I haven't logged in for a while.
If this was e.g., an advertiser I don't have a direct relationship with, then yeah, purge that data! But data retention is a core of my relationship with Discord, so I want that data kept around.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#244> the company has complied with this obligation under the GDPR during the procedure, as it now has a written data retention policy, which includes deleting accounts after two years of user inactivity I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn't any mention of timelines or any other definition of "necessary". As a user, I wouldn't want my account blown away just because I have…
That is a misrepresentation of the ruling.
2.4 million accounts not used in the last 3 years. This isn't "a while" it is a reasonable amount of time for a company to assume that someone doesn't want you to keep their data any longer unless they still have some other relationship with you or have your consent to keep the data stored until you explicitly delete it.
The regulations are to strike a balance between the needs of the business and the needs of the individual where the individual's privacy should generally win over the desires of the business.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#245Earlier quoted context omitted.
And if I send an email to 200 recipients they can all store it, I don’t see the fundamental difference for discord TBH
>email to 200 recipients they can all store it On discord there are no 200 individual "they" storing it. It's stored by discord. (Or I guess people could be manually logging their own chats, but that's not the issue at hand here.) At first pass it might sound like some minor technical squabble about implementation details, but there is intentionality in design decisions. The legal system can not be blind to those. Di…
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#246Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#247Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.
In any case, 800k is a ridiculous amount for such a huge company like Discord.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#248> the company has complied with this obligation under the GDPR during the procedure, as it now has a written data retention policy, which includes deleting accounts after two years of user inactivity I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn't any mention of timelines or any other definition of "necessary". As a user, I wouldn't want my account blown away just because I have…
"..because I haven't logged in for a while". That is a misrepresentation of the ruling. 2.4 million accounts not used in the last 3 years. This isn't "a while" it is a reasonable amount of time for a company to assume that someone doesn't want you to keep their data any longer unless they still have some other relationship with you or have your consent to keep the data stored until you explicitly delete it. The regul…
I've had companies email me saying "log in or we'll delete your inactive account". That's a compromise I can accept.
This article doesn't specify whether Discord does this. I'm also curious whether that practice is required under the GDPR, which the article doesn't specify either.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#249Earlier quoted context omitted.
No. Email is private messaging. If you send email to me and then delete it in your end, I'm allowed to store your email as a whole (sometimes legally obliged).
And if I send an email to 200 recipients they can all store it, I don’t see the fundamental difference for discord TBH
Taking a mailing list as an analogy: If there is a central archive of the mailing list, you can request removal of your messages from that archive, but not from the individual recipients who originally received the message.
Re: Discord fined €800k for failing to comply with several obligations of the GDPR
#250Earlier quoted context omitted.
You can save a screenshot discord chat too. There’s nothing wrong with that. If someone published something and you want to save a copy for personal purposes, go ahead. The difference is in what Discord’s responsibility is. If Discord claimed to have deleted an account, then they shouldn’t still be publishing a post from a user. Especially if such a post could still be tied back to the historical user id. I can under…
An even better analogy would be a mailing list, instead of directly emailing/cc-ing recipients. Definitively not "private messaging". If I delete my email account, and/or remove it from the list, there's no expectation that my prior emails are deleted for any of the other list subscribers. The mailing list archive isn't pruned of my account and everything I ever sent will still be visible.
With Discord, all messages are in the “central archive”, there are no individual copies.