Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

1–10 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#2
The subtitle is "[d]isgruntled ex-guildie effectively invents new way to grief in EVE" but it sounds like the request in question was sent to a website outside of EVE. This could happen with other games or, you know, websites unrelated to games at all...

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#3
I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies that run many different IT services, but this case seems pretty trivial to me.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#4

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

It seems like the AggregateIQ case shows the problem with this - by obeying the request, they admit that the EU has jurisdiction over them. That's probably the wrong thing to do when they have no connection to the EU, other than people from the EU choosing to connect to a server hosted elsewhere.

It's probably the same reason why Hacker News does nothing to comply with the GDPR.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#6

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product?

And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#8
post #6

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Why should a European citizen abide by the laws of a different country (which may be illigal in their country BTW)

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#9
post #6

I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. If there is data left just collect it, send it to the person and delete it afterwards (surely there’s a way to search posts by author in their forum software). I can understand that such requests are difficult to answer for companies th…

The hobbyists may not have access to do so. Perhaps their site is on a VPS or worse, a SAAS product? And why should a Canadian running a site on American servers have to fear EU law? Why isn't it the EU citizen's responsibility to know, understand and abide by the rules and regulations of the countries they're visiting online?

Because that would be a loophole to sidestep EU laws?

If you offer your services in the EU, you have to respect EU law.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#10
What's interesting, and pointed out by a Reddit comment: https://www.reddit.com/r/legaladvice/comments/acsdf3/comment...

There's no way to identify that the person making the request is who he/she says he/she is. The irony is that for services like Facebook, Facebook could ask for a scan of your id/passport to confirm it's you, (and would it also have to keep that scan saved somewhere in case it later needs to prove that it "authenticated" the gdpr request correctly?)

But in this case, how to determine it's really the user? Should "Bob" identifies himself by disclosing his password, and have the admin test of the login works?!

Post reply on HN