Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

131–140 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#131

[flagged]

>What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines.

Edit: the downvotes on this are coming in fast. Because you are downvoting it, you must know of a specific section of GDPR that requires warnings to be issued (otherwise you wouldn’t be downvoting it, right?). So, along with your downvote, please reply to this comment with a link to the specific section that requires warnings, and I will be happy to say that I am wrong.

Nothing in the GDPR requires compulsory fines for every infraction. In fact, if you had read Chapter VI, Section 2, Article 58, 2(a)[0], you would know this.

[0] - https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: GDPR Enforcement Tracker: List of GDPR fines

#132

Earlier quoted context omitted.

Wildcards are a measure to track what others are (automatically) doing with your email address, provide a way to remove yourself from shared lists of bad actors, and sign up to something a dozen times. What they don't do is provide privacy against human eyes.

I've been wondering how this sort of email management strategy is going to handle the rules certain countries are bringing in now where if you want to go there then you have to provide a list of all of your email addresses and social media accounts. Has anyone run into that problem yet?

Yes, my email address is "usa-border@mydomain.com"

Re: GDPR Enforcement Tracker: List of GDPR fines

#133
post #47

Earlier quoted context omitted.

This is crazy. I've seen it done plenty of times by accident in the past, because people don't know how to use BCC (and its hidden by default in many clients).

Not just hidden. When using BCC, the information is never transmitted outside the sending server.

I think what they meant is the option to send as BCC instead of CC is hidden in most mail clients.

Re: GDPR Enforcement Tracker: List of GDPR fines

#134
post #47

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

This is crazy. I've seen it done plenty of times by accident in the past, because people don't know how to use BCC (and its hidden by default in many clients).

Yeah, but ten times in a row? And that's just in half a month, it sounds it could've been dozens of times over 3 months?

Nothing I've heard about this case sounds to me like an innocent mistake that a reasonable effort was made to correct.

I've accidentally smacked people on the street before (gesturing, probably). That's technically a crime, but it'd be crazy to prosecute me for a little mistake like that. But it's not crazy that hitting people is a crime and that people do get prosecuted for it in egregious cases.

Re: GDPR Enforcement Tracker: List of GDPR fines

#135

Can anyone explain the N26 case to me? I've tried to read two articles on it and they don't make sense. It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article. But somehow this was not the case for those old accounts that were closed? How can you close an account but it's still a…

My guess is a user requested his data deleted, but N26 just disabled the account.

Then the user signed up again, enabling the same account.

The user then saw their old data hadn't in fact been deleted, and complained to the regulator.

Re: GDPR Enforcement Tracker: List of GDPR fines

#136
post #113

Earlier quoted context omitted.

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

The details are that some of the most sensitive medical information you could imagine got leaked. Huge, huge violation. Even in the US HIV status is extremely confidential.

The details on the 2000 euro fine?

Re: GDPR Enforcement Tracker: List of GDPR fines

#137

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

This seems to be proof that the GDPR is being weaponized against people and organizations one doesn't like.

What didn't they like about this person, and what proved that to you? And what proved that was the impetus for this fine?

Re: GDPR Enforcement Tracker: List of GDPR fines

#138
post #11

Perhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's stil…

This could be a case of enforcement against large companies taking longer to conduct, given the complex nature of the cases and the resources of the legal teams involved. My understanding is that a lot of stuff is pending before the Irish data protection agency.

This is a good point! Hadn't thought of that.

Re: GDPR Enforcement Tracker: List of GDPR fines

#139
post #27

Earlier quoted context omitted.

Some countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.

So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?

>So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?

The act of recording isn't the problem but the retention of the data records. If you have no need to keep a recording of a day's video for any purposes, then that falls under the provisions of likely being exploited data (e.g.: being used to build a profile of a person's travels throughout the day, week, year, etc.).

In the sense of the allowances, it's about balancing the need of the data's use (e.g.: in car accidents) versus the privacy impacts to other individuals (e.g.: you post your dashcam footage to YouTube and don't obfuscate faces or license plates).

An example of this, pre-GDPR, was when Google was forced to obfuscate faces and license plates in Google Maps for Street View.

Re: GDPR Enforcement Tracker: List of GDPR fines

#140

Earlier quoted context omitted.

Different take: This is exactly what GDPR was designed for. It just hasn't been "weaponized" enough yet to have the bandwidth to deal with every situation, so situations like these seem like targeted attacks when in reality they're precisely what GDPR is supposed to deal with. I personally think ~$15 per leaked email is a reasonable fine. I bet this guy and everyone else who reads this article won't accidentally leak…

The thing is if this was a civil case you have to prove some damages had be done by the leak. A random person leaking my email in CC - that happens a lot - is not even necessarily annoying but for sure don't cause any damages.

Can you clarify what you mean by "The thing is"? Are you saying that's good, bad, or something else?

If a behavior is harmful and we want to stop it, but it's difficult to prove direct damages and therefore civil suits have been ineffective at curbing the behavior, then it seems like a reasonable public policy to impose fines on engaging in the behavior without requiring actual damages be proven in court.

(And if it's easy to innocently accidentally engage in the behavior, it seems reasonable to first issue warnings, and then impose fines if the behavior continues repeatedly.)

Post reply on HN