Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

21–30 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#21

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

[deleted]

Re: GDPR Enforcement Tracker: List of GDPR fines

#22

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

Whether this is guy is a victim of overzealous enforcement, or an example of the GDPR protecting people, is completely dependent on the context of the case and the nature of the mailing list.

The linked article suggests that the guy was sending out angry political rants and criminal accusations to thousands of people a day, which adds a further twist.

Re: GDPR Enforcement Tracker: List of GDPR fines

#23
post #7

Earlier quoted context omitted.

What's insane, the fact that you can't just go around recording people and cars?

On public streets, yeah, that's kind of insane. It's pretty common for people to have a dashcam running with a buffer so if you're involved in a not at fault accident or someone vandalizes your car, or such things, you have documentation.

Of course, that's why it says "illegally". Those dashcams can be installed legally, and this guy's wasn't legally installed.

Re: GDPR Enforcement Tracker: List of GDPR fines

#24
post #11

Perhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's stil…

This could be a case of enforcement against large companies taking longer to conduct, given the complex nature of the cases and the resources of the legal teams involved. My understanding is that a lot of stuff is pending before the Irish data protection agency.

Re: GDPR Enforcement Tracker: List of GDPR fines

#25
At the time of the GDPRpocalypse last year, there were a lot of discussions here, and a lot of FUD being slung around about how if your US website wasn't 100% GDPR-compliant you'd be handcuffed if you set foot in an EU airport bla bla bla, or that minor infractions would incur the maximum penalty of millions of euro, bankrupting your awesome adtech startup bla bla bla. Most of it was fueled by the clash between US and EU jurisprudence, the legal systems are actually pretty different.

Some of us argued that no, this is not the apocalypse, the law says that fines will be proportionate, and the various national agencies will work with you to ensure you are compliant. And unless you willfully do the kind of shady shit the law is meant to protect against, you're fine.

Seems we were right. This list looks pretty sane to me, with one exception.

250k€ for using the microphones of all users of an app to spy and determine if they were in a pub that showed football matches without a license. Fuck yeah.

400k€ for a hospital that had effectively unrestricted access to all patient files for all staff. Yes. What would the HIPAA-equivalent fine be?

1400€ for a police officer abusing systems doing lookups for personal gain. Yes.

170k€ for a school district allowing public access to personal data of all minor-aged students. Yes, yes, yes.

The one exception is the fine on Google in France. This is purely a political bullshit game over control and loss of control.

Re: GDPR Enforcement Tracker: List of GDPR fines

#26

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

Frankly I'm glad that GDPR has the teeth to get people to stop abusing reply-all chains and mailing lists.

Re: GDPR Enforcement Tracker: List of GDPR fines

#27
post #2

The fact that someone was fined for using a dashcam is beyond absurd.

Some countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.

Re: GDPR Enforcement Tracker: List of GDPR fines

#29
post #4

Earlier quoted context omitted.

"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.

The same link mentions issuing a GDPR reprimand against a person for using a security camera inside their own home .

The one I saw said that the CCTV system in the home was also set up to record other peoples' properties too.

Re: GDPR Enforcement Tracker: List of GDPR fines

#30

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

Different take: This is exactly what GDPR was designed for. It just hasn't been "weaponized" enough yet to have the bandwidth to deal with every situation, so situations like these seem like targeted attacks when in reality they're precisely what GDPR is supposed to deal with.

I personally think ~$15 per leaked email is a reasonable fine. I bet this guy and everyone else who reads this article won't accidentally leak emails again, and that's great.

Post reply on HN