Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

11–20 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#11
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Yes.

Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data.

A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#12
post #9

From the link "We consider the infringements to be serious. Disqus has tracked which news sites and articles readers in Norway have visited. Additionally, this has happened without the users’ knowledge." Based on that statement a lot will follow.

Not so long ago I stumbled on https://data.disqus.com, which basically outlines what they were fined for. They should probably take that site down soon...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#13
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

>In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

GDPR is not about web or technology. It applies for information on paper too, so there is no clever workaround with hosting your website somewhere else or other tricks.

In short if you don't want to respect GDPR then do what some websites do and reject users from EU.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#14
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

If just having a disclaimer to not have to follow any kind of law, it will be a bit too easy to escape any kind of regulation, GDPR or not.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#15
post #11
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#16
post #6
post #2

"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.

> but they implement GDPR The GDPR is great for the citizens! My wish is that more countries follow the EU and implement similar and compatible laws. An interesting example of this is that the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA.

I think GDPR has been pretty great for IT consultancy businesses as well..

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#17
post #3
post #2

"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.

We part of the European Economic Area (EEA) which is quite close to being a EU member, but without voting rights. Norway voted two times on membership and the compromise was EEA.

To add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#18
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

GDPR article 3:

> This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union […]

https://gdpr-text.com/read/article-3/

And no, there is no exception for a disclaimer. The only thing you can do to workaround it is to simply not collect the data, which is what some sites have attempted do with geo-blocks on their sites.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#19
post #7

What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?

There are some nuisances on jurisdiction, but if a company tracks users in Europe they may fall under the purview of European data protection authorities.

There are several factors that play in. For example that the data controller offers the delivery of goods in EU Member States, say a plugin like Disqus. It could also be that they have a .eu top level domain.

The Norwegian DPA also writes this in their advanced notice: "Online tracking using cookies and behavioural advertising are explicitly mentioned as activities which constitute monitoring of behaviour in the EDPB Guidelines on the territorial scope of the GDPR."

EDPB: Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) https://edpb.europa.eu/sites/default/files/files/file1/edpb_...

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#20
post #6
post #2

"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.

> but they implement GDPR The GDPR is great for the citizens! My wish is that more countries follow the EU and implement similar and compatible laws. An interesting example of this is that the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA.

> the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA.

I suggest instead that the UK government have deliberately extracted themselves from the EU's version of GDPR, by cloning it.

The UK is now an external "third country" in terms of EU GDPR, and has a data border with the EU - whereas Norway sits within EU GDPR.

Post reply on HN