Live data from Hacker News

Grindr €6.5M fined for not collecting users’ valid consent for sharing data

gdprhub.eu

171–180 of 249 posts

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#171
post #164

Earlier quoted context omitted.

Give millions of users a million dollars each? That seems... not very practical!

As much as I want to punish this, the actual outcome of heavy-handed fines would probably result in the company selling off all its assets... whoops there goes the database into the hands of an even less scrupulous actor.

You can't do that without the buyer being subject to the same restrictions as the original company.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#172
post #163

Earlier quoted context omitted.

You can try as hard as you can to wriggle out from understanding what this is all about but it is actually pretty clear: data supplied by an individual is the property of that individual, they have the right to informed consent on what it is used for, they can ask you to delete it, they can ask you to update it or review it. In some cases other laws (for instance: tax law) can make it mandatory for you to keep certai…

I have certifications in data privacy. The idea that data is "property" or that it is "owned" by anyone is not codified in law. And as an analogy for how GDPR works, I think it's more harmful than helpful. I see GDPR as rejecting the idea that data has an owner, more than anything. GDPR says that the data subject has rights to data about them. If you want to put a label on it, I would say that legally they are a stak…

Fair enough, but from a practical point of view treating the data as owned by the supplier of the data (when it is about them) gets you 95% of the way, the remainder can be explained by the concept of 'control of the data'.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#173
post #66

Earlier quoted context omitted.

A fine of this size indicates to me they should harvest and sell more data to increase profits. Tens of millions would still probably be worth it to Grindr. Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter. Nah, this fine (which I don’t even know…

Wait a second, it's not Grindr gathering and selling a list of homosexuals interested into sex. It's the users themselves who actively register on Grindr to announce their services and picture on the platform. If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.

Firstly, yes, Grindr is mostly men looking for sex, but they're not all homosexuals and they're not all looking for sex; many are just there to flirt, others to troll. But Grindr is definitely gathering and selling lists: it's what they do.

Secondly, with the word "services" you're implying that the users are whores.

Thirdly, there are an infinite number of ways that Grindr could protect its users through the design of their app: from purely technical measures such as end-to-end encryption, or through careful informed consent about shared data and protection of people who are legally or functionally incapable of such consent.

But from your statements you just want to blame the users because you disapprove of them. I'm sure you can do better than that.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#174

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I wonder if jail time for developers knowingly implementing lax systems for exchanging personal data could help?

This way most developers would refuse to write systems that could potentially get them in trouble, until their employer transparently ensures that no laws are broken. Some kind of engineering ethics.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#175

Earlier quoted context omitted.

What aspect of GDPR is troublesome to you? Because 'dont abuse your ownership of personal data' is pretty much what it boils down to.

>What aspect of GDPR is troublesome to you? It tries to restrict data. Information wants to be free. It has no owner.

> It has no owner.

It's not about ownership. It's about my right to keep private information private. It's a right granted by law: the GDPR.

> Information wants to be free

That slogan originates in a sentence that contrasts "information wants to be expensive" (because it's so valuable) with "information wants to be free" (because it's so cheap to distribute). It's not like saying "televisions want to be free, so I think I'll steal one".

I suspect that many of the GDPR-haters here aren't people who depend on selling PII for their living; I suspect they're just jealous.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#176

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I wonder if jail time for developers knowingly implementing lax systems for exchanging personal data could help? This way most developers would refuse to write systems that could potentially get them in trouble, until their employer transparently ensures that no laws are broken. Some kind of engineering ethics.

Yes, but then you'd have to prove when this stuff was written because otherwise there are going to be a lot of engineers retro-actively in the field of fire.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#177

Somewhat related. Not long after creating a Tinder account using an unique mail address I received a phishing mail on that address.

> I received a phishing mail

I was on Tinder for about a week. I was receiving dating spam for a year - not "a phishing email". Hopefully Tinder will be the next up against the wall. They're shameless.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#178

Earlier quoted context omitted.

I wonder if jail time for developers knowingly implementing lax systems for exchanging personal data could help? This way most developers would refuse to write systems that could potentially get them in trouble, until their employer transparently ensures that no laws are broken. Some kind of engineering ethics.

Yes, but then you'd have to prove when this stuff was written because otherwise there are going to be a lot of engineers retro-actively in the field of fire.

Git blame their signed commits. If no records available, chief engineer gets the blame. I mean, that should be trivially enforceable — same as getting to know who performed a botched surgery.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#179

The sooner companies start to realize that personal data is a liability rather than an asset the better. Happy to see this fine, but as far as I'm concerned given the kind of data we're talking about here it should have been higher.

I remember someone here putting it this way: treat user data like uranium, not oil. Both are valuable, but you don’t want to just collect and store an unlimited amount of uranium. Collect the bare minimum user data you need to operate your business and then dispose of it when it’s no longer needed.

Great minds think alike .

I’ve thought of this way in a broader sense.

If you have any data from user data to internal data from various LOB it should be : Data is the new uranium.

Re: Grindr €6.5M fined for not collecting users’ valid consent for sharing data

#180
post #36

Earlier quoted context omitted.

We also got laid before the invention of the smartphone, you know...

We're also deep in a pandemic where olden times means of socialization are pretty restricted. I'm not gonna walk into a bar in 2021 to be assaulted by smoke, sound, and covid. Just the smoke and sound has been enough to keep me out of them for over a decade now.

Smoking in bars is also forbidden here. Many pubs don't play music; and in these COVID times, I often find there's just one other person in there, reading a paper.
Post reply on HN