Live data from Hacker News

An Eve Online corporation has been hit with a GDPR request from an ex-member

massivelyop.com

121–130 of 141 posts

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#121
post #27

As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…

I don't want my private info be gathered by people who have no idea what they're doing.

I understand that there's forums/websites run by people who have no idea what they're doing. And regulations like GDPR make sure that services they are using have baseline encryption and guarantees. Like, it should encrypt passwords and private data, don't store it if not necessary and have functionality to delete users.

It is not about people running the websites/forums, it is about software they are choosing to use. Baseline should not be "it works", but it should be "it works and provide reasonable level of security". I know it is some work on part of people who have no idea what they're doing, but ultimately it is up to developers to set up CMS and forum engines to comply.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#122
post #119

Earlier quoted context omitted.

A hotel room is not a public space.

Neither is a store or a website, which were the examples used. But we can translate the same example given to public spaces easily: you install a hidden camera in a grating in a public square and take upskirt shots of women walking over. That’s illegal at a federal level in the US so people absolutely have a legal right to control your ability to do that.

Wrong, a store is a public place, they have cameras, more to the point I can take a photo of you in a store and you can't stop me nor do you own it.

> take upskirt shots of women walking over. That’s illegal at a federal level in the US

Only since 2004, and that's a specific exception that was made and only applies when there is a clear expectation of privacy, i.e. wearing clothes to cover your privates is a clear indication you expect that to be private. That doesn't stop anyone from taking pictures of you you don't like though and it only makes the area under your clothes a private space, it doesn't make the public space your in a private place.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#123
post #117

Earlier quoted context omitted.

>> Fuck the GDPR, they have no more authority over me than China or North Korea does. You are probably not trading with North Korea, so ignoring their laws has zero impact on anything. China is already getting more tricky though, although they are not choosing to throw their entire weight behind enforcing their demands abroad(yet). But ignoring the demands of the largest trading block on the planet? That's not going…

The EU is not a single trading block; it's many many individual trading blocks all different cultures and languages; the US is the single largest trading block in the world. And no, the GDPR is awful legislation, the notion that every foreign country can simply declare jurisdiction over other countries citizens violates national sovereignty is and flat out disgusting and will not stand.

1) you're simply wrong, or just don't understand the meaning of the word trading block:

https://inshorts.com/m/en/news/european-union-is-worlds-larg...

2) I don't think you understand how GDPR works at all. GDPR says how data about EU citizens has to be processed in a certain way. If you want to do business with EU, you have to comply. If you don't want to comply, you don't get to trade with EU. No one is claiming jurisdiction over other countries - it's simply a matter of agreements. Just like EU respects certain American laws just because it wants to trade with USA and it was requested. It's a mutual thing.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#124

Earlier quoted context omitted.

>Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sente…

Ireland? In Ireland, civil servants are not allowed to express political affiliation or opinion, so rather than it being a case of "we don't like what you said", it would be a case of "you said something political, and it persists." I'm not sure if the contract for Revenue is exactly the same as the civil service, but I would presume on this front it is very similar.

Yep.

There have been three occasions where the IT contracting firm I was working for sent me to work on government IT projects as a contractor. None of them were for Revenue, but it is Revenue who do these checks for all other departments. On one occasion my employer managed to pull a few strings to get me on the project (DSP), on the other two I was told no government work for me (HSE and DoT).

On one of the three three occasions I was forwarded an email from Revenue that said "he expresses a desire for personal privacy that indicates he would be unwilling to fully embrace the governments data sharing strategy".

I did write to a few news outlets about this, none were interested. Even the ICCL wasn't interested, which really surprised me.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#125
post #117

Earlier quoted context omitted.

The EU is not a single trading block; it's many many individual trading blocks all different cultures and languages; the US is the single largest trading block in the world. And no, the GDPR is awful legislation, the notion that every foreign country can simply declare jurisdiction over other countries citizens violates national sovereignty is and flat out disgusting and will not stand.

1) you're simply wrong, or just don't understand the meaning of the word trading block: https://inshorts.com/m/en/news/european-union-is-worlds-larg... 2) I don't think you understand how GDPR works at all. GDPR says how data about EU citizens has to be processed in a certain way. If you want to do business with EU, you have to comply. If you don't want to comply, you don't get to trade with EU. No one is claiming ju…

I was quite clear what I meant by trading block, I wasn't aware that was a specific term of art, but that's not what I meant regardless and that's clear from my response.

I understand it just fine, perhaps you don't understand what I'm saying. No, if an EU citizen comes to my US website, that does not grant the EU authority over me no matter what they claim. I live under US law, not EU law, not Chinese law, not North Korean law. Those countries are free to pass laws claiming they have jurisdiction over me when I do business with their citizens, but claiming it doesn't make it true. No I do not have to comply, the EU has zero authority over me no matter who I do business with _unless_ I'm in the EU where they can do something about it. They can attempt to stop their citizens from using my website, but it is not upon me to do so.

There is no agreement between the US and the EU to respect the GDPR, it's an untested assertion of global authority that cannot stand. The world cannot function if every country can assert every citizen in the world must comply with its laws because their citizens came to my US website. That's a violation of national sovereignty and it will fail when the EU tries to assert that authority and the US courts say, sorry, but no, you don't have jurisdiction over our citizens which is what's going to happen.

The EU can and will enforce the GDPR within its borders, that's expected; outside its borders, it has no jurisdiction and no teeth; I don't have to give a damn about EU law while operating my US business in the US. That a visitor comes from someone outside the US does not change that my business is in the US. I do not have to obey other countries laws.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#126
post #55

Earlier quoted context omitted.

And all of those demands are an unreasonable burden on businesses. Fuck the GDPR, they have no more authority over me than China or North Korea does.

If your business wants to collect my data without providing the safety measures GDPR provides, then fuck your business, I don't want to deal with it or you. Of course if your business doesn't collect our data, there is no issue either way.

Nor do I want to deal with you, so good riddance.

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#127

Earlier quoted context omitted.

> ThePhysicist: I don’t understand where’s the difficulty in answering this request? If the person doesn’t have a user account anymore on the site there shouldn’t be much data of him/her left anyway. Deleting all posts in a forum by a certain user will not delete all posts in a forum by other users that quoted the user who desires to have their data deleted.

I'm not software expert by any means, but couldn't the deletion script also do a search for quoted text, at least sufficient to comply with the reasonable steps language of the legislation?

> TheSpiceIsLife > I'm not software expert by any means, but couldn't the deletion script also do a search for quoted text, at least sufficient to comply with the reasonable steps language of the legislation?

Devil meet details

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#128

Earlier quoted context omitted.

In which case Americans who haven't broken American law by ignoring GDPR requests from their EU clients should not be surprised if they are arrested if they ever go to Europe.

AFAIK, GDPR is a regulation with civil financial penalties, and not a criminal law, so, yes, anyone should be surprised if they are arrested for violating it.

If you don't pay those penalties though then you'd be in trouble

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#129

Earlier quoted context omitted.

I think most of the larger forum software providers have implemented functions to comply with GDPR (i.e. delete, restrict and extract user data). Concerning backups: If you have a short turnaround time (e.g. 14 days) it shouldn’t be a problem, the legislation acknowledges the fact that deleting data and ensuring data integrity (also in accordance with GDPR) are sometimes mutually exclusive from a practical point of v…

>Concerning the democratic aspect of participating in the online world I think GDPR actually helps, as before it was not possible to reliably get your own data deleted, rectified or transferred, which is not very democratic either IMHO This is where the GDPR has really helped me. I posted a comment on a blog critical of a government data sharing initiative. Nothing illegal, or questionable - it was a simple two sente…

The GDPR facilitated your gov's ability to censor you (via coerced self-censorship in this case).

Re: An Eve Online corporation has been hit with a GDPR request from an ex-member

#130
post #94
post #90

So the GDPR is only about personal data? What are my responsibilities if I run a chan, i.e., I store no personal data about my posts other than the IP address where they originated? What if I use some tracking technology such as a cookie or localStorage to identify unique browsers regardless of their IP address?

You have to make it clear to people that you're using these technologies and how long you keep their data. You should also explain how you keep this data safe. If you suffer a data breach you have to disclose this, and you are potentially liable for it if you could've protected users from that breach by technological means (applying patches, salting passwords, encryption, and so on). If your breach includes too much…

> a chan user might at worst suffer potential embarrassment being linked to posts

Embarassment? People lose their jobs in America for espousing commonly-held conservative views. They can be arrested in Europe for the same thing.

Post reply on HN