Live data from Hacker News

GDPR Hall of Shame

gdprhallofshame.com

21–30 of 192 posts

Re: GDPR Hall of Shame

#21
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

I think you've confused "if" with "if and only if"

Re: GDPR Hall of Shame

#22
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

Re: GDPR Hall of Shame

#23
I want to know if credit card companies Mastercard, Visa, etc. are subject to GDPR. They definitely sell or use your purchase data for purposes unrelated to the service.

Re: GDPR Hall of Shame

#24
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

You are not the product. Exposure to you is the product.

No its not just showing you ads. Its selling any information they have on you to ad networks without you knowing about it.

Re: GDPR Hall of Shame

#25
post #21
post #13

"Whoops, we can't secretly sell your data anymore! That means you can't control your smart wifi lightbulbs from now on!" For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products. Even if GDPR has flaws, and is gonna cause some disr…

I think you've confused "if" with "if and only if"

The implication is clearly that you ought to pay for the products, so that you aren't the product. But if the incentives for paid and free products to monetize your data is the same, switching from one to the other doesn't help.

You have to specifically seek out products where your privacy and data is taken seriously. This can happen for both free (open source?) and paid products.

Re: GDPR Hall of Shame

#26
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

That's extremely uncharitable.

Re: GDPR Hall of Shame

#27
post #5

The Instapaper one - #1 - is troubling for a non-obvious reason. One of the tenets of GDPR is that you have to be told how your data is being used. So the only explanation for this behaviour is that there's some shady shit going down that they want to stop before they have to admit to it. If I used Instapaper I'd be filing a complaint with my local DPA about this.

Hey there – Brian from Instapaper here – we have a pretty clear and accurate privacy policy around the data we collect and how we use it, you can find it here: https://instapaper.com/privacy

Hi Brian! Thanks for taking part in the discussion.

But what part of GDPR was it that caused you to have to close off European Union users?

Re: GDPR Hall of Shame

#28
The Yahoo! one [1] is definitely in violation of GDPR, right? GDPR doesn't cover me as I'm neither in the EU nor am I an EU citizen, so I really hope someone lets the regulators know about this. The first major penalty will be example setting.

Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally?

[1] Hidden opt-out is non-compliant, but Yahoo! went ahead and opted you in to a hundred different ad services automatically: http://gdprhallofshame.com/content/images/2018/05/ouch.jpg

Re: GDPR Hall of Shame

#29
post #10

My favourite at the moment is sendwithus. They said their service will never be GDPR compliant. But fortunately they have a new "enterprise grade" product called sendwithus dyspatch. Same feature set, new price plus GDPR compliance. This is a price jump from $79/Month to a minimum of $24.000/year. And this is with discount for former sendwithus users. I would consider this to be mafia methods.

Why? This seems like good behavior. They're original product is supported by a business model that relies on user data. Now they are offering a similar product that doesn't make money off of user data but instead charges the user. I am all for the GPDR, but the regulations don't say you can't suck up all user data _and_ you still have to provide your service for free/discounted

So you're saying user's data is worth $23052 per year?

Re: GDPR Hall of Shame

#30
It'll be interesting to see how the EU reacts to all of the companies like Oath that, by default, share your data with 300+ ad agencies.

After the GDPR hype has died down, hopefully new tech companies will think twice about data privacy

Post reply on HN