Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

181–190 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#181

Weird there's no fines in UK.

As somebody else pointed out, they're being tracked by the ICO [0]. I think they previously had a blog where they documented enforcement while the UK was still under the older Data Protection legislation but I can't seem to find it. [0] https://ico.org.uk/action-weve-taken/enforcement/

From what I can see, noe of the fines use the GDRP. They're all for pre-May 2018 breaches, so use the old DPA.

Re: GDPR Enforcement Tracker: List of GDPR fines

#182
post #171

Earlier quoted context omitted.

GDPR doesn't prevent you from collecting personal data. It only requires you to have a clear reason for collecting everything and being transparent about what data is collected and how it is processed.

The examples here make clear that "a clear reason for collecting everything" means an ironclad justification for each field, each bit of precision, each minute of retention. That is not a casual thing. As in, one of the fines here is for retaining a phone number to fulfill a need to communicate, when postal mail could have worked instead. It is doable, if you have the lawyers and the time. But that's not a degree of…

If you don't need a phone number why collect a phone number?

I might need it later is not a clear reason!

Re: GDPR Enforcement Tracker: List of GDPR fines

#184

Earlier quoted context omitted.

Well, suppose he does some transformation involving position. GPS points also have altitude in them. He neglects to sanitize altitude at the point of collection, and is therefore collecting and retaining more data than necessary to perform the service. He plots positions on a relatively zoomed-out map. Only the first six significant figures make a perceptible difference in the map position, but he retains the same pr…

> Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests. This is typical FUD. GDPR allows backups. Right to be deleted doesn't mean grovelling through backups. If those snapshots are rotated out after e.g. 3 months he is fin…

The great thing about TFA is we can stop speculating and see what the regulators are actually doing.

>After the controller succeeded to identify the data subjects he refused to comply with the deletion request, arguing he is legally obliged to retain backup copies according to the Accountancy Act and internal policies. Since he did not properly inform about these policies, the NAIH held the controller breached the principle of transparency.

So maybe if his backup regime were precisely specified in his privacy policy. But even a conflicting legal requirement is no defense, here.

Regarding minimization, 4 other cases:

>During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a controller.

>Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed

> The video surveillance subject of the proceedings is therefore not limited to areas which are under the exclusive power of control of the controller.

> The Commissioner considered that the aim could be achieved by referring only to the initials of their name and/or their faces being blurred and/or publishing photographs drawn from a distant distance

"Of course if he stores the data in a personally identifying way..." GDPR cares not for identifying but for identifiable. It's GPS data. If someone uploads data pertaining to their home, workplace, frequent travel routes, etc. then it is definitely identifiable.

Regarding FUD, it seems FUD is exactly what the DPAs intend, since they are punishing rather than helping when asked for advice!

>Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to deal with a service provider who does not want to sign a processing agreement. After not answering Kolibri Image in more detail, the case was forwarded to the locally responsible Data Protection Authority of Hamburg. This Auhtority then fined Kolibri Image as controller for not having a processing agreement with the service provider.

Re: GDPR Enforcement Tracker: List of GDPR fines

#185

Earlier quoted context omitted.

> Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests. This is typical FUD. GDPR allows backups. Right to be deleted doesn't mean grovelling through backups. If those snapshots are rotated out after e.g. 3 months he is fin…

The great thing about TFA is we can stop speculating and see what the regulators are actually doing. >After the controller succeeded to identify the data subjects he refused to comply with the deletion request, arguing he is legally obliged to retain backup copies according to the Accountancy Act and internal policies. Since he did not properly inform about these policies, the NAIH held the controller breached the pr…

I think you should dig into these cases a little deeper.

Re: GDPR Enforcement Tracker: List of GDPR fines

#186
post #90

Earlier quoted context omitted.

That's fine, but my point was not that Kolibri Image took the appropriate steps immediately, but whether the commenters here on HN were correct in their estimation that the various data protection authorities would help you resolve compliance issues versus just issuing you fines.

Some more context: https://gdpr.report/news/2019/01/23/small-business-in-german... Relevant passage: "Discovery of the misdemeanor began with an email from another company to the Hessian Data Protection Commissioner, sent in May of last year, in which advice was requested regarding the failure of Kolibri Image in proving customer data, despite multiple requests being sent. Kolibri Image declined to cooperate, instead…

> "Oh it's this other company's responsibility. And, by the way, they don't agree to do GDPR, so it's out of my hands"

In this case, the other company is also in Europe (Spain), so by law must abide by GDPR. It seems they didn't have a contract ready, and Kolibri didn't want to spend money on translating/creating a contract to Spanish.

From what I read from Kolibri themselves (https://kolibri-image.com/causa-datenschutz/), the "processing" was a company that bundles DHL package orders to get batch pricing. You send them the information, they send the order (together with other orders) to DHL, DHL picks up the package and you save on postage. Apparently, Kolibri wasn't sure whether that's actually data processing (but did mention them using the company for this particular reason in their privacy information, according to the Bavarian officials, it isn't). They asked the German branch of the company who said they wouldn't need a contract and subsequently referred them to HQ in Spain. They asked the Hessian official to make the company's German branch comply with GDPR and sign a data processing contract. Instead, the Hessians forwarded it to Hamburg.

Kolibri claims to have stopped using that company after hearing back from the Hessians, but forgotten to remove them from the privacy information on one website. If they are to be believed, they were told "you can't use them without a contract" and stopped using them.

The fine has since been withdrawn and the case was closed.

Re: GDPR Enforcement Tracker: List of GDPR fines

#187
post #57
post #55

Earlier quoted context omitted.

But shouldn't the fine then be using the dashcam law and not GDPR?

The analogy was that GDPR fines, similar to other administrative fines (which was the term that had escaped me) like traffic tickets, do not require damage to be shown (although it plays a role in setting the amount of the fine) - unlike e.g. cases pressing for damages, brought by a wronged party, would be. The law regarding dash cams (if there is an explicit one, I don't know enough about the situation in Austria) m…

Yes, makes sense. I think it case of Austria, there are fines specified for dashcams, so it's interesting they decided to use the GDPR instead.

Re: GDPR Enforcement Tracker: List of GDPR fines

#188
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

You also need to make the links obvious. The light grey on white they do on that page likely isn't compliant, and neither is their privacy information ;)

Re: GDPR Enforcement Tracker: List of GDPR fines

#189
post #60
post #39

The ICO maintains an official list of fines in the UK https://ico.org.uk/action-weve-taken/enforcement/?facet_type...

Notably none of these are (yet) for violations of the GDPR. The ICO has issued enforcement notices, but they haven't levied any penalties so far.

Ah, my bad. Only checked the date of the decisions and assumed they were related to GDPR.
Post reply on HN