Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

111–120 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#111
post #90

Earlier quoted context omitted.

I'm not actually that sympathetic. If you have a processor that does not want to sign a processing agreement, you have to stop using them. There is no leeway on this issue in GDPR. You are responsible for ensuring that third party processors you engage agree to handle the data lawfully. There's not a lot of context to go on, but it seems to me that the company in question is just stalling. I literally can't think of…

That's fine, but my point was not that Kolibri Image took the appropriate steps immediately, but whether the commenters here on HN were correct in their estimation that the various data protection authorities would help you resolve compliance issues versus just issuing you fines.

Some more context: https://gdpr.report/news/2019/01/23/small-business-in-german...

Relevant passage: "Discovery of the misdemeanor began with an email from another company to the Hessian Data Protection Commissioner, sent in May of last year, in which advice was requested regarding the failure of Kolibri Image in proving customer data, despite multiple requests being sent. Kolibri Image declined to cooperate, instead laying responsibility at the feet of another contractor."

The article is a bit hard to understand, but it seems that someone asked Kolibri to provide information on how 3rd party information was kept secured. Kolibri declined to answer saying that it was another contractor who was doing it. Reading between the lines, Kolibri seems to have asked for guidance on what to do, but did not receive guidance.

I have to say that I'm even less inclined to be sympathetic. It's a pretty blatant disregard for the GDPR. If you want guidance at that level, hire a lawyer. But in reality, there is no need for a lawyer: it is completely obvious that you can't shield yourself from GDPR simply by saying, "Oh it's this other company's responsibility. And, by the way, they don't agree to do GDPR, so it's out of my hands".

To be a bit more clear, I don't know what the authority could do to help resolve the compliance issue other than to say, "Yes, you have to comply with the law. Sorry that you thought you didn't have to". Is a 5000 euro fine justified -- even without having given guidance. IMHO, yes, however you can see that they thought they were in error and hence are reviewing the fine. The other blurb made it seem as if the compliance issue was only discovered because Kolibri asked what they should do. This article makes it more clear that it's just a normal complaint with a company doing everything in its power to avoid doing anything.

Re: GDPR Enforcement Tracker: List of GDPR fines

#112
post #7

Earlier quoted context omitted.

What's insane, the fact that you can't just go around recording people and cars?

On public streets, yeah, that's kind of insane. It's pretty common for people to have a dashcam running with a buffer so if you're involved in a not at fault accident or someone vandalizes your car, or such things, you have documentation.

If it's a model with a buffer, it's allowed. What is not allowed is to have lying around hours of footages with licences plates, etc. on it.

Re: GDPR Enforcement Tracker: List of GDPR fines

#113

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

The details are that some of the most sensitive medical information you could imagine got leaked. Huge, huge violation. Even in the US HIV status is extremely confidential.

Re: GDPR Enforcement Tracker: List of GDPR fines

#114
post #71

Earlier quoted context omitted.

It's good to be reminded of how many backwards laws there are in the world. Every country is a little bit fascist and insane and it makes you appreciate the good parts of your own country.

Until you realize the "receiving end" of that: It also means that in those "fascist" countries, you have a right not to be filmed, even in public.

..by private citizens

Re: GDPR Enforcement Tracker: List of GDPR fines

#115
Can anyone explain the N26 case to me?

I've tried to read two articles on it and they don't make sense.

It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article.

But somehow this was not the case for those old accounts that were closed? How can you close an account but it's still an operational account? Like, was it still possible to send money to it etc.?

My guess is that the article is wrong and this was simply about them preventing legitimate users to close and then reopen a new account.

I have a hard time believing they were not allowed to keep that data for some time after acccount closing. It seems to be more about how it was used.

Re: GDPR Enforcement Tracker: List of GDPR fines

#116
post #27
post #2

The fact that someone was fined for using a dashcam is beyond absurd.

Some countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.

So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?

Re: GDPR Enforcement Tracker: List of GDPR fines

#117
post #68
post #32

Earlier quoted context omitted.

Not true. You can have a dash cam, but it has to be the kind that continuously overwrites its own data and only records when it detects an accident. You can also record based on your intent - if your intent is to, say, capture a scenic drive ,then you can do that. If your intent is to just capture the license plates of 1000s of other cars that pass you, you can't do that. These laws were changed in ~2018 in Austria.

How can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?

The dashcam will record into a, say, 5-minute buffer until the accelerometer registers a high value, at which point it starts writing into a new file (so the buffer becomes a permanent record of the 5 minutes prior to the incident).

That's one way to implement it, one can come up with many others.

Re: GDPR Enforcement Tracker: List of GDPR fines

#118
post #47

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

This is crazy. I've seen it done plenty of times by accident in the past, because people don't know how to use BCC (and its hidden by default in many clients).

Not just hidden. When using BCC, the information is never transmitted outside the sending server.

Re: GDPR Enforcement Tracker: List of GDPR fines

#119

[flagged]

It does not explicitly require warnings, but Art. 83 ( https://gdpr-info.eu/art-83-gdpr/ ) requires that the authority, when deciding whether to impose a fine, takes into account a number of things. It would be hard to argue for an instant fine if the things listed in the article were favorable in a specific case.

It does not explicitly require warnings

I think that’s all anyone needs to know.

Re: GDPR Enforcement Tracker: List of GDPR fines

#120
post #71

Earlier quoted context omitted.

It's good to be reminded of how many backwards laws there are in the world. Every country is a little bit fascist and insane and it makes you appreciate the good parts of your own country.

Until you realize the "receiving end" of that: It also means that in those "fascist" countries, you have a right not to be filmed, even in public.

That's also quite rediculous
Post reply on HN