Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

151–160 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#151

Earlier quoted context omitted.

Once again, under GDPR, it is entirely legal to issue fines without a warning. Therefore, in any case where it does not say that there was a warning, one can reasonably assume that no warning occurred - especially given that in some cases (according to you, most cases) they did say something about a warning. The absence of the mention of a warning in this context implies that there wasn’t one. The point is, and no on…

No one is saying warnings are required. I said I expected one was given, because 1) it appears to be the common practice, and 2) it is the reasonable thing to do. So I doubt that this person would have been fined without a warning, but indeed, I have no way of knowing. That said, I'm open to the idea that perhaps the law should stipulate a warning, but perhaps the language around proportionality/reasonableness is suf…

perhaps the language around proportionality/reasonableness is sufficient.

It is not. Those terms have enough legal leeway to drive a truck through.

Re: GDPR Enforcement Tracker: List of GDPR fines

#152

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In India, I often get government mails (e.g. reminder for some compliance) of local city with all the business owners in CC. I even went to authority in question to tell them about the privacy issue in vain. So if a EU citizen's email id was part of the list, will it be liable for action according to GDPR?

Yes, but if an entity has no interest in interacting with the EU then they don't have to respond. You only need to care about a country's laws if (1) you want to do business or visit there or (2) you're going to piss them off to such a degree that they convince your home country to come after you.

Re: GDPR Enforcement Tracker: List of GDPR fines

#153

Earlier quoted context omitted.

The dashcam will record into a, say, 5-minute buffer until the accelerometer registers a high value, at which point it starts writing into a new file (so the buffer becomes a permanent record of the 5 minutes prior to the incident). That's one way to implement it, one can come up with many others.

Dunno how well this will work if you need to claim that the pedestrian or cyclist just darted in front of you. But then again, maybe you don't want that kind of thing recorded.

Yes, if you hit a pedestrian and didn't brake, dash-cam footage of that would not be helpful to your court case.

Re: GDPR Enforcement Tracker: List of GDPR fines

#154
Many people are complaining about some fines, but here are some others I see that are evidence of this working extremely well:

- A police officer was fined for using his department's tools to get someone's private phone number for his personal use

- A rental agency was fined for leaving renter's private data (ids, etc) open to the public for six months after being notified of the vulnerability

- A company was fined because they were continuously filming their employees at work without explanation

- A political candidate misusing private citizen data for campaign purposes.

- Rental car companies tracking drivers by GPS without notifying them

- Hospital staff having fake doctor profiles to view unrestricted patient data

This is convincing me that GDPR is a great success.

Re: GDPR Enforcement Tracker: List of GDPR fines

#155

Earlier quoted context omitted.

Dunno how well this will work if you need to claim that the pedestrian or cyclist just darted in front of you. But then again, maybe you don't want that kind of thing recorded.

Yes, if you hit a pedestrian and didn't brake, dash-cam footage of that would not be helpful to your court case.

Actually, the lack of a permanent recording (barring technical issues easily identified by forensics) would be very helpful... to the person you hit.

Re: GDPR Enforcement Tracker: List of GDPR fines

#156
post #99
post #94

Earlier quoted context omitted.

> unless you're sure you that can afford making these kinds of mistakes, don't provide a service on the internet DOT sounds good

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine.

All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt.

The idea that we should hold companies that profit off people's personal data blameless if they manage to "make a slip-up" with it is absurd. The only other industry where we accept those kinds of mistakes is Wall Street and we all know how well that policy has gone.

Re: GDPR Enforcement Tracker: List of GDPR fines

#157

Earlier quoted context omitted.

Not just hidden. When using BCC, the information is never transmitted outside the sending server.

I think what they meant is the option to send as BCC instead of CC is hidden in most mail clients.

Thank you. That does indeed make more sense.

Re: GDPR Enforcement Tracker: List of GDPR fines

#158

[flagged]

There is no section of the GDPR that requires warnings to be given. This should not be a surprise or shocking to you. If there were required warnings for first-offenders then really heinous data leaks by first-offenders would not be punished.

There is no provision in road rules that says police officers should give warnings -- for exactly the same reason. Instead, it's purely up to the discretion of the police officer whether you get a warning or not. GDPR acts in exactly the same manner, but instead of it being individual police officers it's officers appointed for that role.

Re: GDPR Enforcement Tracker: List of GDPR fines

#159

Earlier quoted context omitted.

It does not explicitly require warnings, but Art. 83 ( https://gdpr-info.eu/art-83-gdpr/ ) requires that the authority, when deciding whether to impose a fine, takes into account a number of things. It would be hard to argue for an instant fine if the things listed in the article were favorable in a specific case.

It does not explicitly require warnings I think that’s all anyone needs to know.

Can you show that it is an outlier for a law to not require warnings to be given? I can think of many laws (road rules, all of criminal law) which don't require warnings to be given, but instead warnings are up to the discretion of police officers or courts.

Also, the EU is not the US. There is a very different culture and jurisprudence when it comes to proportionality of laws. If the GDPR was a US law, then I would also be concerned about the penalty guidelines. But it's not a US law, so bringing a US-centric mindset to the discussion causes misunderstandings.

Re: GDPR Enforcement Tracker: List of GDPR fines

#160
post #156
post #99

Earlier quoted context omitted.

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine. All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt. The idea that we should hold companies that profit off people's personal data b…

I used to have a website that did stuff with GPS data that was uploaded by users.

It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat.

Those ads probably made it a for profit business.

I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so.

Those are the kind of websites that you lose.

I consider that a loss.

Post reply on HN