Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

141–150 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#141
Two of these are much more intense than I would have guessed:

>The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the Central Electronic Register and Information on Economic Activity, and processed the data for commercial purposes. The authority verified incompliance with the information obligation in relation to natural persons conducting business activity – entrepreneurs who are currently conducting such activity or have suspended it, as well as entrepreneurs who conducted such activity in the past. The controller fulfilled the information obligation by providing the information required under Art. 14 (1) – (3) of the GDPR only in relation to the persons whose e-mail addresses it had at its disposal. In case of the remaining persons the controller failed to comply with the information obligation – as it explained in the course of the proceedings – due to high operational costs. Therefore, it presented the information clause only on its website. According to the UODO this is not sufficient.

So, basically, only use open source datasets that come with contact information for every subject.

and

>The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting a customer’s request to have his phone number erased after arguing that it was in the company's legitimate interest to process this data in order to enforce a debt claim against the customer. In its decision, the NAIH emphasised that the customer’s phone number is not necessary for the purpose of debt collection because the creditor can also communicate with the debtor by post. Consequently, keeping the phone number of the debtor was against the principles of data minimisation and purpose limitation. As per the law, the assessed fine was based on 0.025% of the company's annual net revenue.

You can't just retain the database rows pertaining to accounts with current or likely litigation, but must choose the specific fields relevant to the nature of the dispute. Even the companies that successfully implemented propagation of deletion across their systems are probably going to get spanked for this one when some column in some backwater warehouse backup isn't strictly necessary for the precise claims in that account's lawsuit. Wow.

I hope this puts to bed suggestions that others were "overreacting" to GDPR, that there would be anything other than the meanest, most aggressive, most literal application to every case. Maybe this is a good thing! Maybe everyone needs the fear of God put into them. But I hope GDPR boosters who went around minimizing the threat to good-faith actors admit that they were wrong.

Re: GDPR Enforcement Tracker: List of GDPR fines

#142
post #113

Earlier quoted context omitted.

The details are that some of the most sensitive medical information you could imagine got leaked. Huge, huge violation. Even in the US HIV status is extremely confidential.

The details on the 2000 euro fine?

No the big one.

Re: GDPR Enforcement Tracker: List of GDPR fines

#143

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

Seems to be proof it is being weaponized against behavior one doesn’t like, the behavior which is forbidden by the law.

This isn’t a one time slip up, it’s a 10 times slip up and chances are there were a lot of warnings this guy didn’t want to listen to. So he was hit where it hurts. Poor guy, it’s like he was caught speeding ten times and then got fined.

Re: GDPR Enforcement Tracker: List of GDPR fines

#144

Earlier quoted context omitted.

Many, but not all of them said this. Given that GDPR has absolutely no requirement that warnings be issued, it is not reasonable to expect that warnings were issued and/or ignored in cases where it doesn’t specifically say this occurred.

You don't seem to have brought up any cases where we know that fines were imposed without a warning, nor any reason to believe this particular case was special. If, out of all the cases that we do know whether warnings were issued, warnings were in fact issued in the vast majority of them (or even 100% of the known cases), then for a case where we don't know and have no reason to believe is special, isn't the reasona…

Once again, under GDPR, it is entirely legal to issue fines without a warning. Therefore, in any case where it does not say that there was a warning, one can reasonably assume that no warning occurred - especially given that in some cases (according to you, most cases) they did say something about a warning. The absence of the mention of a warning in this context implies that there wasn’t one.

The point is, and no one has been able to refute this, that warnings are not required under GDPR. Even if they have issued warnings in most cases thus far, it is still early days. As these actions under GDPR become more common, there is no guarantee that even those countries that have been issuing warnings first will continue to do so. The enforcement of regulations that have the potential to generate massive revenue streams for government entities tends to become increasingly aggressive and creative as time goes on.

I don’t understand why anyone, even those in favor of GDPR, would attempt to refute the black and white text of the law. No warnings are required under GDPR, and thus the potential exists for fines to be issued without warning. There is no argument or opinion to be interjected here. This is a binary fact. Are warnings required? No, warnings are not required. It’s that simple.

Re: GDPR Enforcement Tracker: List of GDPR fines

#145
post #75
post #16

Earlier quoted context omitted.

I wonder where the line is drawn when it comes to things like that. Yesterday I was walking on the side of the road and some girl was half way hanging out of the passenger window recording a video of the scenery. I was able to see her from a few hundred feet away. Eventually the car intersected with me and I was in the line of sight of the video for a second or 2. Of course I made a stupid pose to photo bomb her vide…

As far as i understand this doesn't fall under GDPR unless the video is published because of personal use. If she publishes the video, you have the right to ask her to take it down/remove your PII from the video. But there might be additional local privacy laws that change things and GDPR has nothing to do with it.

As we learned from this listing, the video's controller is required to notify the subject that he appears in the video before processing it. If the controller does not have enough information to contact the subject, he cannot fulfill that requirement, and is therefore noncompliant.

Re: GDPR Enforcement Tracker: List of GDPR fines

#146
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

Not any website. If it is purely private and non-commercial you don't have to. Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be yo…

Which coincidentally is the same kind of information you have to provide for public perusal if you register a company.

Re: GDPR Enforcement Tracker: List of GDPR fines

#147

[flagged]

> What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. Edit: the downvotes on this are coming in fast. Because you are downvoting it, you must know of a specific section of GDPR that requires warnings to be issued (otherwise you wouldn’t be downvoting it, right?). So, along with your downvote, please r…

I’m not sure what that has to do with this discussion. We are discussing whether or not GDPR requires warnings before fines are allowed to be issued. The answer is no, it does not require them, and the text you linked to does not disprove this simple, undeniable fact.

Re: GDPR Enforcement Tracker: List of GDPR fines

#148
post #68

Earlier quoted context omitted.

How can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?

The dashcam will record into a, say, 5-minute buffer until the accelerometer registers a high value, at which point it starts writing into a new file (so the buffer becomes a permanent record of the 5 minutes prior to the incident). That's one way to implement it, one can come up with many others.

Dunno how well this will work if you need to claim that the pedestrian or cyclist just darted in front of you. But then again, maybe you don't want that kind of thing recorded.

Re: GDPR Enforcement Tracker: List of GDPR fines

#149

Earlier quoted context omitted.

You don't seem to have brought up any cases where we know that fines were imposed without a warning, nor any reason to believe this particular case was special. If, out of all the cases that we do know whether warnings were issued, warnings were in fact issued in the vast majority of them (or even 100% of the known cases), then for a case where we don't know and have no reason to believe is special, isn't the reasona…

Once again, under GDPR, it is entirely legal to issue fines without a warning. Therefore, in any case where it does not say that there was a warning, one can reasonably assume that no warning occurred - especially given that in some cases (according to you, most cases) they did say something about a warning. The absence of the mention of a warning in this context implies that there wasn’t one. The point is, and no on…

No one is saying warnings are required. I said I expected one was given, because 1) it appears to be the common practice, and 2) it is the reasonable thing to do. So I doubt that this person would have been fined without a warning, but indeed, I have no way of knowing. That said, I'm open to the idea that perhaps the law should stipulate a warning, but perhaps the language around proportionality/reasonableness is sufficient.

Re: GDPR Enforcement Tracker: List of GDPR fines

#150
post #75

Earlier quoted context omitted.

As far as i understand this doesn't fall under GDPR unless the video is published because of personal use. If she publishes the video, you have the right to ask her to take it down/remove your PII from the video. But there might be additional local privacy laws that change things and GDPR has nothing to do with it.

As we learned from this listing, the video's controller is required to notify the subject that he appears in the video before processing it. If the controller does not have enough information to contact the subject, he cannot fulfill that requirement, and is therefore noncompliant.

I would disagree because "The rules don’t apply to data processed by an individual for purely personal reasons or for activities carried out in one's home, provided there is no connection to a professional or commercial activity." Obviously when you put the video out in the world those rules start to apply (especially if you make money from that - ads etc.). I don't see how GDPR applies if i take pictures on my vacation and show them to my family/friends after (this is purely personal use). Even in case of surveillance (dashcam, cctv) you don't need to get consent from every person, you just need to inform them (signage) that surveillance is happening.
Post reply on HN