Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

141–150 of 192 posts

Re: GDPR Hall of Shame

#141

Earlier quoted context omitted.

That's not how GDPR works. You're not allowed to make use of your product / service require acceptance of collection of data. You must either offer it without data collection as an option, or simply refuse service.

I'm guessing, if that's enforced, that a lot of these same organizations will opt to refuse service.

A lot are. GDPR Hall of Shame looks like a list of these companies.

Re: GDPR Hall of Shame

#142
post #2

Came here to mention Oath, but it seems the site has already covered it: http://gdprhallofshame.com/5-techcrunch-engadget-and-oath-co... Great idea for a site. I'm sure it won't lack content for quite some time.

I defied RSI to click all Yahoo partners, and opening a random sample of privacy policy links I found one that was written in Chinese. So much for consent.

Re: GDPR Hall of Shame

#144
post #56
post #47

Earlier quoted context omitted.

In every email program, RE: stands for Reply. RE: is prefixed to a subject for showing that the current email is a reply to an earlier email. That is what is deceptive. RE: is not Regarding in this context but appears designed to increase acceptance by lying about the recipient receiving a response to an earlier non-existent communication.

Email didn't magically change the meaning "Re" to "Reply." It still means regarding; it's regarding the subject of the previous email.

Don't argue for the sake of arguing. I didn't write that Email magically changed the meaning of a word! I wrote that email clients use RE: in a specific way.

Re can mean regarding, but in an email subject line Re: has been taken for decades by email programs to mean something very specific, "Reply".

Re: GDPR Hall of Shame

#145
post #75

Earlier quoted context omitted.

I think there's also a sizable number of companies that basically were already compliant... but aren't sure. It's not like you can submit your processes to the EU for approval. You don't actually know if what you're doing is OK unless, some day, a regulator decides it isn't.

This kind of problem is what lawyers are for. Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What specific actions can I take to become compliant?".

Re: GDPR Hall of Shame

#146

Earlier quoted context omitted.

I'm not sure it's reasonable to expect an answer to that question; at least not from someone other than their legal representative.

Well, i'm reading their silence as "We don't give a fuck about protecting customers' data.... cause its mine!" In the end, companies whom don't go through with the GDPR prep and implementation tell me precisely one thing: there's something in their process that makes it hard for them to comply. But not seeing "We're in progress to comply at $date" tells me that they're doing some pretty nefarious stuff. Is that actua…

That seems like an uncharitable reading. I'd guess they just don't want to express anything that implies some specific interpretation of the law.

I'm not sure there's anything they're doing that's not compliant, but uncertainty about whether that's true might be sufficient for them to consider it too risky to conclude that they are.

I think, if anything, the facts that the law is written is relatively 'simple' language, doesn't specifically mention any technical examples, and is widely expected to be enforced 'spiritually' and not literally, makes it particularly hard for lots of organizations to know with reasonable certainty whether they're in compliance or not.

Re: GDPR Hall of Shame

#147

Earlier quoted context omitted.

This kind of problem is what lawyers are for. Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.

The trouble with the GDPR is that there is so much ambiguity in even quite basic areas of the regulations and the official guidance so far that any formal opinion you get from lawyers, consultants, regulators and the like is riddled with vague terms like "reasonable", "legitimate", "proportionate" and "balanced". It's advice that doesn't actually answer any of the important questions like "Am I compliant?" or "What s…

I think that's intentional as it massively increases the risk of doing something negative for the end user and leaves loopholes uncertain and prone to interpretation. It will forces businesses to stay well clear of the line or pack up and go home. And that's not a bad thing.

Also it stops a whole legal and compliance industry appearing in the grey zone as no one wants to abstract liability.

Re: GDPR Hall of Shame

#148

Earlier quoted context omitted.

I'm guessing, if that's enforced, that a lot of these same organizations will opt to refuse service.

A lot are. GDPR Hall of Shame looks like a list of these companies.

Which ones? The list looks like a bunch of organizations trying to do a clumsy end-run around the intent of the law instead of refusing service.

Re: GDPR Hall of Shame

#150

Earlier quoted context omitted.

How is this a big deal? They probably sell your data or use it to show you ads or targeted content. Who cares?

People in this thread saw the title "GDPR Hall of Shame", possibly read it. Now they are trying to discuss stuff relating to "General Data Protection Regulation". My wild guess is people who are commenting on this thread care.

Do they really care or have they been pushed to care?
Post reply on HN