Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…
In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...
GDPR Enforcement Tracker: List of GDPR fines
191–200 of 301 posts
Re: GDPR Enforcement Tracker: List of GDPR fines
#192Earlier quoted context omitted.
Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…
> We have no idea how many attempts and warnings to get them to comply were sent first. True. But I doubt that even the most ruthlessly efficient GDPR enforcement authority could multiple enforcement requests between mid July and end July.
Re: GDPR Enforcement Tracker: List of GDPR fines
#193Earlier quoted context omitted.
The great thing about TFA is we can stop speculating and see what the regulators are actually doing. >After the controller succeeded to identify the data subjects he refused to comply with the deletion request, arguing he is legally obliged to retain backup copies according to the Accountancy Act and internal policies. Since he did not properly inform about these policies, the NAIH held the controller breached the pr…
I think you should dig into these cases a little deeper.
Re: GDPR Enforcement Tracker: List of GDPR fines
#194Earlier quoted context omitted.
Some countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.
So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?
On the other hand, what is permitted is dashcams with shock sensors and trigger buttons. The shock sensor gives you a good reason (very high probability of a crash).
Using the trigger button is okay if either there was a crash (or something illegal) or if you mask out any identifiable details about the car and person involved afterwards.
Generally, recording public spaces is illegal, if you setup a security camera on your property, you have to make sure it's not filming outside your property in an unreasonable manner (you may be allowed to film the sidewalk, for instance, if you suspect someone is salting your garden out of revenge, but only until you have proof and then you have to make sure to delete all non-essential footage).
Privacy in public space is an important right that doesn't exist in the US.
Re: GDPR Enforcement Tracker: List of GDPR fines
#195Earlier quoted context omitted.
The dashcam will record into a, say, 5-minute buffer until the accelerometer registers a high value, at which point it starts writing into a new file (so the buffer becomes a permanent record of the 5 minutes prior to the incident). That's one way to implement it, one can come up with many others.
Dunno how well this will work if you need to claim that the pedestrian or cyclist just darted in front of you. But then again, maybe you don't want that kind of thing recorded.
Re: GDPR Enforcement Tracker: List of GDPR fines
#196Earlier quoted context omitted.
The examples here make clear that "a clear reason for collecting everything" means an ironclad justification for each field, each bit of precision, each minute of retention. That is not a casual thing. As in, one of the fines here is for retaining a phone number to fulfill a need to communicate, when postal mail could have worked instead. It is doable, if you have the lawyers and the time. But that's not a degree of…
If you don't need a phone number why collect a phone number? I might need it later is not a clear reason!
HN doesn't need to know or share your username to post your comment, it is clearly possible to run a message board without usernames, and conversations could be maintained by generating a random pseudonym for each thread.
Re: GDPR Enforcement Tracker: List of GDPR fines
#197The fact that someone was fined for using a dashcam is beyond absurd.
I wonder where the line is drawn when it comes to things like that. Yesterday I was walking on the side of the road and some girl was half way hanging out of the passenger window recording a video of the scenery. I was able to see her from a few hundred feet away. Eventually the car intersected with me and I was in the line of sight of the video for a second or 2. Of course I made a stupid pose to photo bomb her vide…
Panoramarecht means that the girl can film into a crowd or public space for her own reasons if she wants to. As long as she doesn't put one person in the center of the image or focuses on them in other ways, it's generally permitted.
There is also some more general law handling, if you posed for the picture, judges would generally agree that this constitutes consent to be recorded (a more recent case would the famous Angry German Hat Incident, in which a very angry right-wing man walked up to a camera team to complain about being recorded; the judge ruled that the camera team was justified in recording at first due to Panoramarecht and the man walking up to them, knowing they were recording, rightfully so, constituted consent to be recorded further).
Posing to a camera or walking up to it basically means consent in germany; you noticed the camera and you did take actions that would put you center in the image or make you a focus point.
Re: GDPR Enforcement Tracker: List of GDPR fines
#198Earlier quoted context omitted.
Once again, under GDPR, it is entirely legal to issue fines without a warning. Therefore, in any case where it does not say that there was a warning, one can reasonably assume that no warning occurred - especially given that in some cases (according to you, most cases) they did say something about a warning. The absence of the mention of a warning in this context implies that there wasn’t one. The point is, and no on…
Once again under UK drug law it is entirely legal to send someone to prison for five years (I think) for an eighth of weed. Except it never happens. To get straight to a maximum penalty there would be very damning circumstances. It's why we have regulators, judges and magistrates - to apply judgement and proportionality. Sure there's a few headline cases of some absurdly harsh sentence - and just about always the det…
So, by comparing this to legal situations where “it never happens” you are purposely misrepresenting the risk of receiving a fine under GDPR without any type of warning. While having an eighth of weed rarely if ever results in a 5 year sentence in the U.K., clearly not receiving a warning before being fined occurs quite frequently. You have made a false equivalence between these two things.
Re: GDPR Enforcement Tracker: List of GDPR fines
#199Earlier quoted context omitted.
> Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests.Worse, he enabled automated periodic VM snapshots with his VPS provider, so is not properly complying with deletion requests. This is typical FUD. GDPR allows backups. Right to be deleted doesn't mean grovelling through backups. If those snapshots are rotated out after e.g. 3 months he is fin…
The great thing about TFA is we can stop speculating and see what the regulators are actually doing. >After the controller succeeded to identify the data subjects he refused to comply with the deletion request, arguing he is legally obliged to retain backup copies according to the Accountancy Act and internal policies. Since he did not properly inform about these policies, the NAIH held the controller breached the pr…
https://kolibri-image.com/causa-datenschutz/
Google translate:
https://translate.google.com/translate?hl=&sl=de&tl=en&u=htt...
tl;dr
The Data Protection Authority of Hessen suggested Kolibri Image to draft their own data processing agreement and get Packlink, located in Madrid, to sign it. [1]
Kolibri Image then stated that they would "leave things as they are", which was incorrectly interpreted to mean that they'd use Packlink without an agreement instead of not using Packlink in the future.
In addition, Kolibri Image forgot to update one of their six data processing agreements on various websites which still mentioned Packlink, so their clarification of the matter was not believed.
Finally, the case was dropped because it (partially?) happened before the 24th of Mai.
[1] Drafting a data processing agreement for Packlink is of course not very practical because who knows how they handles their data and why would Packlink sign it in the first place if they don't want to offer a data processing agreement. In addition, the cost of drafting and translating the agreement is much more expensive than the savings from using Packlink as a shipping processor.
In any case, I agree that fining after asking for advice is not a friendly move.
Re: GDPR Enforcement Tracker: List of GDPR fines
#200To whoever did this: thanks! Such a website can have many uses: - Show the average people why privacy is important with concrete examples - Find previous rulings for people in a specific situation - Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers My wish for that website is that in the future, the data is more easily readable and "big-data exploitable" (good luck with tha…
I was thinking the opposite. The fines listed are so low, that from a purely financial perspective complying doesn't seem to make much sense. I would estimate all GDPR compliance efforts I've been involved in to be more costly than the largest fine issued in Germany.