Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

111–120 of 192 posts

Re: GDPR Hall of Shame

#111
post #81
post #16

Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.

If the definition of personal data includes IP addresses then I'd be surprised there are any internet-connected products that don't process personal data in some way.

>If the definition of personal data includes IP addresses

Yes it does.

> I'd be surprised there are any internet-connected products that don't process personal data in some way.

Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows:

"Processing shall be lawful if... processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child."

https://gdpr-info.eu/art-6-gdpr/

Recital 49 goes on to state:

"The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems."

Logging IPs for a reasonable period of time as part of your network security infrastructure is perfectly permissible under GDPR without consent. You can share your server logs with a third-party security company or pass data to a DDoS protection service if needed. If you use those IPs for any other purpose (ad tracking, analytics etc) then you'll need lawful grounds for those activities, which may or may not require consent.

Re: GDPR Hall of Shame

#112

My favourite at the moment is sendwithus. They said their service will never be GDPR compliant. But fortunately they have a new "enterprise grade" product called sendwithus dyspatch. Same feature set, new price plus GDPR compliance. This is a price jump from $79/Month to a minimum of $24.000/year. And this is with discount for former sendwithus users. I would consider this to be mafia methods.

If they are offering the $79/month service in the EU, it doesn't matter that they have a GDPR compliant version. They won't be able to sell the non-compliant version right?

If an EU company who holds private data of their customers ("data controller") is buying services from some third party service provider ("data processor"), then it's the data controller's responsibility to ensure that they handle the data responsibly and don't ever give it out to noncompliant processors.

A B2B service can legally offer a non-compliant service in the EU, but then the buyer isn't allowed to put any privately identifiable data in it; GDPR article 28.1 "Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."

So in the sendwithus case, GDPR would prohibit an EU company to use its $79/month service for handling private data, since it doesn't come with the required assurances.

Re: GDPR Hall of Shame

#113
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

As long as you are telling the truth about only sharing anonymous and aggregate data with publishers and advertisers, I can't see anything in your privacy policy that would preclude you from being GDPR compliant right now.

Re: GDPR Hall of Shame

#114
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

"Credit reporting agencies" in the USA sense aren't really a thing in EU, there are similar but substantially different (and nation-specific, not EU-wide) mechanisms of verifying the creditworthiness of customers, often with specific national laws regulating the usage this data which would override GDPR.

Furthermore "please delete my data" doesn't really mean "delete all my data", it means something like "I revoke whatever consent I gave and delete all my data that you now have no right to use" - so the company is allowed to keep all the data for which the GDPR gives them a right to use without your consent.

Re: GDPR Hall of Shame

#115
post #54

Earlier quoted context omitted.

The 80s? Were you involved in ARPANet or something?

I first went onto the internet in 1990 when my BBS got a connection. It was quite well developed by the end of the 80s.

80s were still fairly early for Internet access. I was on the ARPANET as early as 1979 or so but just trading the occasional email in a lab. "Real" internet access, first at work and then through my BBS, was probably more like the early 1990s.

Re: GDPR Hall of Shame

#116
post #23

I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

On another note, does GDPR mean you can request credit report agencies to delete all their data on you?

No. The right to erasure is conditional. Credit reference agencies have a lawful justification to collect, retain and share certain types of personal information without the consent of the data subject.

https://gdpr-info.eu/art-17-gdpr/

Re: GDPR Hall of Shame

#117
post #115

Earlier quoted context omitted.

I first went onto the internet in 1990 when my BBS got a connection. It was quite well developed by the end of the 80s.

80s were still fairly early for Internet access. I was on the ARPANET as early as 1979 or so but just trading the occasional email in a lab. "Real" internet access, first at work and then through my BBS, was probably more like the early 1990s.

Oh yeah, I didn’t do anything on the Internet in 1990 apart from typing ‘go internet’ into CIX (my BBS at the time), sitting there wondering what you could do with it, then killing the connection when my dad pointed out that we paid by the minute for the phone line :) I don’t think I knew anyone online that wasn’t on CIX either.

Re: GDPR Hall of Shame

#118
post #88

Earlier quoted context omitted.

I believe that they do lots of internal analytics but do not sell identifiable data on a per-person level; the laws regarding nondisclosure of banking data are old, well established and much stricter - for starters, intentional disclosure of confidential banking information outside of certain (though many) particular exceptions is an actual maybe-go-to-jail crime, not just a civil matter with some fines. Surveillance…

Does GDPR distinguish between "identifiable" data and "non-identifiable"? If so, how do you decide which is which? A list of credit card transactions is pretty easy to de-identify...

tl;dr: under GDPR terms, anything is "personally identifiable" if you have the means to resolve it.

Technically, writing "John Smith" on a piece of paper can become anonymous data if there's no way to determine who wrote it and it doesn't mean anything to anyone who has access to the piece of paper (because there's a lot of people with that name or because they don't know anyone by that name) but of course names should be treated as personally identifiable to be on the safe side.

On the other end of the spectrum a vague description like "that chubby guy with the crew cut" can be personally identifiable information if you know who it refers to, even if someone else might see it and have no idea who you mean.

So the exact lines are highly contextual and pseudonymisation does not guarantee anonymisation: if you call a Rose by any other name, you still know it's her you're talking about.

Re: GDPR Hall of Shame

#119
post #61

Earlier quoted context omitted.

A lot of smaller sites don't necessarily know everything that they're collecting. Arguably, this is a good opportunity to figure that out. However, it's equally arguable that in many cases it's just easier to cut off EU access if there's any doubt and the EU just isn't important to their business (or hobby). If I ran a US centric ecommerce site, for example, I'd be very tempted to just stop selling in the EU for now.

What if EU citizens who are visiting US make purchases from your site?

It does apply. All EU residents are covered regardless where they are.

Re: GDPR Hall of Shame

#120
post #16

Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.

I must admit, even as a critic of the GDPR in some respects, as an individual I am hoping that its heavy-handed approach will mean I can buy everyday things again without having spyware, telemetry, and so on coming as standard. I don't want a "smart" phone or a "smart" TV or a "connected" car, where the scare quotes denote entirely unnecessary invasion of privacy and/or security and safety risks. I buy a phone to communicate, a TV to watch stuff, and a car to get from A to B, and it will be nice if we can get back to doing those things better instead of tacking on all the user-hostile extras.
Post reply on HN