Live data from Hacker News

Largest GDPR fines surpass $1.3B

transcend.io

21–30 of 45 posts

Re: Largest GDPR fines surpass $1.3B

#21
post #13
post #6

Earlier quoted context omitted.

just embedding a tweet from Twitter's official embed code makes you violate GDPR (e.g. if you have a blog and want to reference a tweet). Twitter injects a ton of cookies and there's not much you can do about it

Can someone explain to me how GDPR makes you responsible for twitter collecting data? It's not your faukt if twitter has their own cookies... What matters is whi stores the data who in this case is not the person embedding twitter

The user only has a business relationship with the website they visit. The website is responsible for the services it employs, just like any other general contractor is responsible for their subcontractors.

Re: Largest GDPR fines surpass $1.3B

#22
post #4

Earlier quoted context omitted.

They were from the start and this was abundantly clear, but given the complete lack of enforcement, people just did whatever the big websites were doing. If these don't get caught, why would they go for random cooking blogs?

What if they could go for the companies building these standardized GDPR cookie consent dialogs instead...

Which, sometimes, also illegal. Trustarc for example.

Re: Largest GDPR fines surpass $1.3B

#24
post #6
post #2

The section on “ How to avoid GDPR fines in 2022” is naïve to a fault. My personal opinion is that after recent rulings startups need to be very careful. GDPR compliance is practically a nightmare for any entity that even so much implements visitor counter with default http logging turned on. It will be interesting to see how solutions and landscape evolves once GDPR fines come to smaller companies and startups.

just embedding a tweet from Twitter's official embed code makes you violate GDPR (e.g. if you have a blog and want to reference a tweet). Twitter injects a ton of cookies and there's not much you can do about it

Good. If you want to quote text, copy it. Has the advantage that it still will be around once the tweet is gone or Twitter is offline.

With a little css it will look the same as the original tweet to which a simple link could lead you.

This is what you do if you value your users privacy. If not, then you have (under GDPR) at least give them the choice not to get these cookies. Which destroys the usability of your site for your privacy conscious users.

Re: Largest GDPR fines surpass $1.3B

#25

I wish Europe would undo these privacy laws so that the web can go back to normal before they ruined it for the entire world.

The only thing needed for it to go 'back to normal' is to treat the do not track flag as if you had automatically fucked around with their anti-cookie game for 10 minutes, and then also not use any server side tracking or half of the 'necessary cookies' and not bother you.

Re: Largest GDPR fines surpass $1.3B

#26
post #6
post #2

The section on “ How to avoid GDPR fines in 2022” is naïve to a fault. My personal opinion is that after recent rulings startups need to be very careful. GDPR compliance is practically a nightmare for any entity that even so much implements visitor counter with default http logging turned on. It will be interesting to see how solutions and landscape evolves once GDPR fines come to smaller companies and startups.

just embedding a tweet from Twitter's official embed code makes you violate GDPR (e.g. if you have a blog and want to reference a tweet). Twitter injects a ton of cookies and there's not much you can do about it

Good.

Don't foist untrusted code onto your visitors' devices.

Re: Largest GDPR fines surpass $1.3B

#27

I wish Europe would undo these privacy laws so that the web can go back to normal before they ruined it for the entire world.

No, they should strengthen them instead and put a couple of offenders out of business that would definitely get a lot more companies to fall in line and stop abusing their users. Effectively you are arguing that the self regulation worked, but it really didn't. Hence the need for legislation and hence these (still pretty mild) fines.

For starters: don't include third party resources in your offering. That already cuts down tremendously on your exposure under the GDPR.

Re: Largest GDPR fines surpass $1.3B

#28
post #2

The section on “ How to avoid GDPR fines in 2022” is naïve to a fault. My personal opinion is that after recent rulings startups need to be very careful. GDPR compliance is practically a nightmare for any entity that even so much implements visitor counter with default http logging turned on. It will be interesting to see how solutions and landscape evolves once GDPR fines come to smaller companies and startups.

GDPR compliance is totally doable, in fact, if you take 'don't screw your users and be careful with their data' as your guideline you will make almost all of the decisions the right way. Note that fines are almost exclusively for repeat offenders, and that were they were not there was clear evidence of malice rather than accident.

Re: Largest GDPR fines surpass $1.3B

#29
post #6
post #2

The section on “ How to avoid GDPR fines in 2022” is naïve to a fault. My personal opinion is that after recent rulings startups need to be very careful. GDPR compliance is practically a nightmare for any entity that even so much implements visitor counter with default http logging turned on. It will be interesting to see how solutions and landscape evolves once GDPR fines come to smaller companies and startups.

just embedding a tweet from Twitter's official embed code makes you violate GDPR (e.g. if you have a blog and want to reference a tweet). Twitter injects a ton of cookies and there's not much you can do about it

Maybe the trickle down economy will work. First some web site operators get fined for not realizing that their subcontractor (twitter) captures personal data. They stop using said subcontractor, and at some point this trickles down to twitter, who will provide a compliant solution.

Re: Largest GDPR fines surpass $1.3B

#30

I wish Europe would undo these privacy laws so that the web can go back to normal before they ruined it for the entire world.

No, they should strengthen them instead and put a couple of offenders out of business that would definitely get a lot more companies to fall in line and stop abusing their users. Effectively you are arguing that the self regulation worked, but it really didn't. Hence the need for legislation and hence these (still pretty mild) fines. For starters: don't include third party resources in your offering. That already cut…

Me collecting data is not me abusing my users. I am simply recording facts about the world. Being forced to censor facts because the people the fact is about don't like it is plain censorship. Information should be free.
Post reply on HN