Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

161–170 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#161
post #99

Earlier quoted context omitted.

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

That's a pretty weak argument in and of itself. Many crimes are mistakes.

Similarly, many simple mistakes shouldn’t be treated as a crime.

Re: GDPR Enforcement Tracker: List of GDPR fines

#162
post #159

Earlier quoted context omitted.

It does not explicitly require warnings I think that’s all anyone needs to know.

Can you show that it is an outlier for a law to not require warnings to be given? I can think of many laws (road rules, all of criminal law) which don't require warnings to be given, but instead warnings are up to the discretion of police officers or courts. Also, the EU is not the US. There is a very different culture and jurisprudence when it comes to proportionality of laws. If the GDPR was a US law, then I would…

Can you show that it is an outlier for a law to not require warnings to be given?

No, my initial comment on this issue was in reply to someone that said "I expect there would have been a warning given in that case before assessing a fine." [1]. This is an oft-repeated and entirely baseless sentiment that HN's resident GDPR defenders love to cite - it shows up in every one of these threads. That is why I was making it clear that in fact no warnings are required, and indeed as time goes on, few warnings are likely to be given.

[1] https://news.ycombinator.com/item?id=20279385

Re: GDPR Enforcement Tracker: List of GDPR fines

#163
post #158

[flagged]

There is no section of the GDPR that requires warnings to be given. This should not be a surprise or shocking to you. If there were required warnings for first-offenders then really heinous data leaks by first-offenders would not be punished. There is no provision in road rules that says police officers should give warnings -- for exactly the same reason. Instead, it's purely up to the discretion of the police office…

You attempted to make the same point twice. See https://news.ycombinator.com/item?id=20281985 for my response to the first iteration of it.

Re: GDPR Enforcement Tracker: List of GDPR fines

#164
post #154

Many people are complaining about some fines, but here are some others I see that are evidence of this working extremely well: - A police officer was fined for using his department's tools to get someone's private phone number for his personal use - A rental agency was fined for leaving renter's private data (ids, etc) open to the public for six months after being notified of the vulnerability - A company was fined b…

All but maybe one of those looks like it was illegal prior to GDPR, so I'm not sure GDPR is what you're praising.

Re: GDPR Enforcement Tracker: List of GDPR fines

#165

250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user's microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I'm a little bit surprised that the fine is this low: "The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobil…

Considering some others in there this feels like a slap on the wrist

Re: GDPR Enforcement Tracker: List of GDPR fines

#166

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

With such sensitive information they should really avoid CC/BCC and do it manually, or write a script for sending 1 email at a time. Not because CC/BCC is bad, but because you want to be 100% sure to dodge this kind of problems.

Re: GDPR Enforcement Tracker: List of GDPR fines

#167
post #160
post #156

Earlier quoted context omitted.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine. All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt. The idea that we should hold companies that profit off people's personal data b…

I used to have a website that did stuff with GPS data that was uploaded by users. It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat. Those ads probably made it a for profit business. I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so. Those are the kind of websites that you lose. I consider that a loss.

Why could GDPR possibly make someone shutdown such a website?

Pure FUD.

EDIT: Downvotes don't change reality. The OP is spreading FUD.

Edit: unless the website was actually abusing users privacy in which case I'm glad it is gone.

Re: GDPR Enforcement Tracker: List of GDPR fines

#168
post #27

Earlier quoted context omitted.

Some countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.

So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?

It is a weird one in Germany. Generally you can record everything because of a law called Panoramafreiheit, however once you start to have discernible individuals on your photograph/video you need their consent, because individuals own the Bildrecht (”image rights”) to themselves, while you as the creator own the Urheberrecht (”creator rights”). And it needs both for a image to be taken legally.

So you get their written consent, ask them if it is okay or take the risk that they will e.g. see themselves in your movie and force you to take it down. This fits with the general feeling that filming another person without asking is seen as extremely rude.

The key here is that people need to be recognizable, so pictures of crowds usually don’t count.

Certain architects can also forbid circulation of photographed versions of their building if it is central subject of the photograph — but I only know of one such thing.

Note that this all was enshrined in law way before GDPR.

Unless you stick your camera into other people’s faces without asking or plan to distribute your images on a bigger scale you will probably manage without ever hearing about these laws.

Re: GDPR Enforcement Tracker: List of GDPR fines

#169

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

Whether this is guy is a victim of overzealous enforcement, or an example of the GDPR protecting people, is completely dependent on the context of the case and the nature of the mailing list. The linked article suggests that the guy was sending out angry political rants and criminal accusations to thousands of people a day, which adds a further twist.

If that’s true then the gdpr was not used according to it’s spirit at all. They punished annoying guy who was trying to get some attention. Of course google or fb is fine...

Re: GDPR Enforcement Tracker: List of GDPR fines

#170
post #156
post #99

Earlier quoted context omitted.

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine. All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt. The idea that we should hold companies that profit off people's personal data b…

>deciding to create a business around other people's personal information

>profit off people's personal data

Have you "decided to create a business around destroying the environment" and "profit off CO2 emissions" because your office is heated in the winter? GDPR is not specific to the adtech or data brokerage industries.

Post reply on HN