Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

201–210 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#201
post #4
post #2

The fact that someone was fined for using a dashcam is beyond absurd.

"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.

Some countries are sane enough to enshrine privacy in public spaces into law, because of the potential for abuse.

This is slowly but surely being eroded also in Germany. Multiple cities are trialling full video surveillance to stop the terrorists.

e.g: Some USA towns have near 100% video surveillance through the Amazon doorbell cameras (Ring) of the town's inhabitants. Some content is publicly available, cops can also request it.

Then Amazon is posting captured video as Facebook advertisements to identify suspected thieves.

https://www.vice.com/en_us/article/pajm5z/amazon-home-survei...

Re: GDPR Enforcement Tracker: List of GDPR fines

#202

Earlier quoted context omitted.

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

With such sensitive information they should really avoid CC/BCC and do it manually, or write a script for sending 1 email at a time. Not because CC/BCC is bad, but because you want to be 100% sure to dodge this kind of problems.

That'll be part of why they got the fine. One component of gdpr is taking reasonable steps to avoid leaking personal data, and as you pointed out relying on someone remembering to bcc rather than cc is asking for trouble.

Re: GDPR Enforcement Tracker: List of GDPR fines

#203

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

If the story linked elsewhere in this thread is the one in question, this wasn't an accident. It was a guy running some kind of harrassment campaign. His "little mailing list" was of people he was harrassing, not subscribers to a newsletter. https://www.rosepartner.de/blog/bussgeld-fuer-offenen-e-mail...

Not a harassment campaign as such, it seems. He was mad about something, and mailed a bunch of politicians and press his complaints. Complaints, sometimes bordering on being libelous, according to the agency which fined him, not death threats.

He was fined solely based upon the email addresses being visible to all recipients, not because of the content of his mails, said a spokesperson. However, he was a repeat offender in terms of privacy, who in the past was warned, then fined for similar stuff.

I'm a little bit torn on that one. The fine seems excessive for what he did (and the email addresses seem to be a list of already public journalist and press contacts) and it certainly looks like somebody in the govt got annoyed and threw the book at the guy in retaliation. Then again, he had ample warnings, and choose to ignore those warnings.

Re: GDPR Enforcement Tracker: List of GDPR fines

#204

Can anyone explain the N26 case to me? I've tried to read two articles on it and they don't make sense. It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article. But somehow this was not the case for those old accounts that were closed? How can you close an account but it's still a…

My guess is a user requested his data deleted, but N26 just disabled the account. Then the user signed up again, enabling the same account. The user then saw their old data hadn't in fact been deleted, and complained to the regulator.

Are banks even allowed to wipe your whole account record? They probably have to keep most of it for tax collectors.

Re: GDPR Enforcement Tracker: List of GDPR fines

#205
post #159

Earlier quoted context omitted.

Can you show that it is an outlier for a law to not require warnings to be given? I can think of many laws (road rules, all of criminal law) which don't require warnings to be given, but instead warnings are up to the discretion of police officers or courts. Also, the EU is not the US. There is a very different culture and jurisprudence when it comes to proportionality of laws. If the GDPR was a US law, then I would…

Can you show that it is an outlier for a law to not require warnings to be given? No, my initial comment on this issue was in reply to someone that said "I expect there would have been a warning given in that case before assessing a fine." [1]. This is an oft-repeated and entirely baseless sentiment that HN's resident GDPR defenders love to cite - it shows up in every one of these threads. That is why I was making it…

> "I expect there would have been a warning given in that case before assessing a fine." [...] That is why I was making it clear that in fact no warnings are required

They didn't say warnings were required, they said that warnings were the norm. You haven't provided counter-examples to that claim, you're arguing against a straw-man argument that "warnings are required by the GDPR".

As an example outside GDPR, it is not required to give children warnings when they commit petty crimes (such as shoplifting) but that is the overwhelming norm in most countries. In this analogy, you're arguing that "most children don't get put in juvenile detention for shoplifting and get warnings instead" isn't true because there isn't a provision in the criminal code saying that children need to be given warnings.

> indeed as time goes on, few warnings are likely to be given.

This is an example of the "baseless sentiment" that you claimed you're trying to fight against. On what basis do you claim to know (or even conjecture) that "few warnings are likely to be given" in the future?

There are many examples of GDPR warnings being given. To me, it seems to be the norm -- if you have an actual counterexample (other than pointing out that warnings aren't required, despite now basically admitting that legally-mandated warning stages aren't common and so that entire line of argument seems to be a non-sequitur) I'd love to see it.

Re: GDPR Enforcement Tracker: List of GDPR fines

#206
post #160

Earlier quoted context omitted.

I used to have a website that did stuff with GPS data that was uploaded by users. It was purely a hobby affair that was a net loss, but Google ads ($10 per month) reduced the cost somewhat. Those ads probably made it a for profit business. I shut the thing down before GDPR, but if I hadn’t it surely would have been an excellent reason to do so. Those are the kind of websites that you lose. I consider that a loss.

Why could GDPR possibly make someone shutdown such a website? Pure FUD. EDIT: Downvotes don't change reality. The OP is spreading FUD. Edit: unless the website was actually abusing users privacy in which case I'm glad it is gone.

You receive an email with a request for a privacy statement? Great, one way or the other, that's work with potential legal repercussion, which means you probably should talk to a lawyer. Additional expenses and hassle for no good reason.

You make a fix in the email system that accidentally emails everybody at the same time? (It almost happened.) Oops. There's your exposure to some nice fine.

You don't need to be abusing somebody's privacy to be concerned about legal exposure. Just like there are asshole companies, there are asshole users as well who can make your life miserable.

Any hobbyist who doesn't take this kind of exposure into consideration is naive.

Re: GDPR Enforcement Tracker: List of GDPR fines

#207
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

I've got an imprint, including my mobile phone number, on my partly personal, partly business website for about 15 years now. In this time I have not received any calls or unwanted mail on this address. Not a single one in all those years.

Re: GDPR Enforcement Tracker: List of GDPR fines

#208
post #156

Earlier quoted context omitted.

Yes, people make mistakes. And by deciding to create a business around other people's personal information some mistakes are bad enough to merit a fine. All sorts of civil offences and crimes can be mistakes. While "it was an accident" might lower the penalty it doesn't negate the fact the mistake was made and people might have been hurt. The idea that we should hold companies that profit off people's personal data b…

>deciding to create a business around other people's personal information >profit off people's personal data Have you "decided to create a business around destroying the environment" and "profit off CO2 emissions" because your office is heated in the winter? GDPR is not specific to the adtech or data brokerage industries.

Yes, climate change effects would probably be a more accurate analogy -- but many people are very much against carbon tax schemes so it felt best to avoid that comparison.

Re: GDPR Enforcement Tracker: List of GDPR fines

#209
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

I've got an imprint, including my mobile phone number, on my partly personal, partly business website for about 15 years now. In this time I have not received any calls or unwanted mail on this address. Not a single one in all those years.

Maybe your website is not popular enough. I had a website a few years ago (not anymore) and since then I receive about one call per week of "Microsoft" employees asking me to install some backdoor software.

Re: GDPR Enforcement Tracker: List of GDPR fines

#210

Earlier quoted context omitted.

Once again under UK drug law it is entirely legal to send someone to prison for five years (I think) for an eighth of weed. Except it never happens. To get straight to a maximum penalty there would be very damning circumstances. It's why we have regulators, judges and magistrates - to apply judgement and proportionality. Sure there's a few headline cases of some absurdly harsh sentence - and just about always the det…

You appear to be spreading false rumors about them issuing warnings even though they don’t have to. When I organized the data on this site by fine amount, not a single case on the front page said anything about any of the companies fined having received a single warning. So, by comparing this to legal situations where “ it never happens” you are purposely misrepresenting the risk of receiving a fine under GDPR withou…

Why would you expect a site built to report GDPR fines and penalties to report GDPR warnings?

ICO haven't yet released aggregate figures for GDPR, it's too soon. GDPR is a minor update of DPA, and they have released aggregate numbers on that for a while. Fines are levied in a tiny minority of cases. Warnings are far more common, as is steady escalation. The expectation here is the proportions will remain the same under GDPR.

On weed, actually no, because the default action for weed for the vast majority is just a warning. So no, it isn't clear that getting fined without warning first happens quite frequently, because that's also simply not true. You're very unlikely to see a court without a warning first.

Post reply on HN