Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

211–220 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#211
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

Not any website. If it is purely private and non-commercial you don't have to. Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be yo…

> If it is purely private and non-commercial you don't have to.

Unfortunately, this does not include a lot of websites that most people would classify as private. For example, a blog still needs an Impressum.

In addition, you will even be classified as commercial, and therefore require an Impressum, if you don't make any money, for example if you use ads to (try to) pay the hosting cost.

> A P.O. box is not required

In fact, you'll have to pay a fine of usually 5000€ if you use a P.O. box without a summonable address.

Re: GDPR Enforcement Tracker: List of GDPR fines

#212
post #6

To whoever did this: thanks! Such a website can have many uses: - Show the average people why privacy is important with concrete examples - Find previous rulings for people in a specific situation - Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers My wish for that website is that in the future, the data is more easily readable and "big-data exploitable" (good luck with tha…

> Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers I was thinking the opposite. The fines listed are so low, that from a purely financial perspective complying doesn't seem to make much sense. I would estimate all GDPR compliance efforts I've been involved in to be more costly than the largest fine issued in Germany.

I think the spirit is that first offenses that aren't extremely outrageous get lower fines.

Re: GDPR Enforcement Tracker: List of GDPR fines

#213
post #202

Earlier quoted context omitted.

With such sensitive information they should really avoid CC/BCC and do it manually, or write a script for sending 1 email at a time. Not because CC/BCC is bad, but because you want to be 100% sure to dodge this kind of problems.

That'll be part of why they got the fine. One component of gdpr is taking reasonable steps to avoid leaking personal data, and as you pointed out relying on someone remembering to bcc rather than cc is asking for trouble.

Not just that. Health data is considered especially sensitive by the GDPR, so sharing it is a more serious transgression than simply sharing personally identifiable information in general.

Re: GDPR Enforcement Tracker: List of GDPR fines

#214

Earlier quoted context omitted.

My guess is a user requested his data deleted, but N26 just disabled the account. Then the user signed up again, enabling the same account. The user then saw their old data hadn't in fact been deleted, and complained to the regulator.

Are banks even allowed to wipe your whole account record? They probably have to keep most of it for tax collectors.

If they only kept the data that was necessary for legal compliance with tax regulations, they wouldn't have been fined. That's explicitly allowed. That they were fined suggests they just kept everything, far beyond what they had to keep.

Re: GDPR Enforcement Tracker: List of GDPR fines

#215
Something I often see in discussions about GDPR on HN is that the law is vague. A hugely valuable comment on a previous GDPR discussion (which unfortunately I've been unable to track down) pointed out a marked difference in style between US and EU law. In the US, laws are usually very detailed and explicit about what will happen in all cases. If that's what someone is expecting, EU law is indeed very vague - because the underlying idea is that judges are trusted to interpret law in the context of constitutions, precedent and so on. EU citizens are much more used to this kind of language, so many of the discussions on here are people shouting past each other because there's a more fundamental issue about the way laws are phrased. If you're in the US and want to quibble with the language, please bear in mind the broader context of EU law. And if you're in the EU please bear in mind that people in the US are used to much more explicit legal language. If we all did that some of the discussions on HN about GDPR might be more meaningful.

The other thing that seems to happen a lot is that people are looking for a stick - any stick - to beat GDPR with. The current top-voted comment - https://news.ycombinator.com/item?id=20279249 - is a prime example. These lists of fines often don't give context (which, to be clear, is a failing of the list too) and often when you dig into these things you'll find that the ruling is entirely sensible. People need to give a bit more credit to legal systems than to think "Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany" could possible be true. If a fine seems ridiculous, do a bit of digging before you take a short summary at face value, and you won't be left with egg on your face when people point out what actually happened.

Re: GDPR Enforcement Tracker: List of GDPR fines

#216

250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user's microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I'm a little bit surprised that the fine is this low: "The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobil…

Very little money for the kind of intrusion they did.

Re: GDPR Enforcement Tracker: List of GDPR fines

#217

Does enforcement changes behavior? I guess the time will tell. But I do expect some insurance companies start selling GDPR coverage policies soon.

Contracts to insure against legal fines are considered immoral and therefore unenforceable.

You can get liability insurance, but that's different (not legal fines but civil law damages).

Re: GDPR Enforcement Tracker: List of GDPR fines

#218

[flagged]

> What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines.

It's not in GDPR because it's part of EU law. Two parties to a case need to attempt to fix it before going to court. In the UK this is why you have letters before action setting out what you think your case is, how you want it to be fixed, and what you'll do if it isn't fixed. You don't just leap to issuing court papers straight away.

Re: GDPR Enforcement Tracker: List of GDPR fines

#219

Earlier quoted context omitted.

> What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. Edit: the downvotes on this are coming in fast. Because you are downvoting it, you must know of a specific section of GDPR that requires warnings to be issued (otherwise you wouldn’t be downvoting it, right?). So, along with your downvote, please r…

I’m not sure what that has to do with this discussion. We are discussing whether or not GDPR requires warnings before fines are allowed to be issued. The answer is no, it does not require them, and the text you linked to does not disprove this simple, undeniable fact.

Incorrect. You're moving the goal posts. Let's stay on the topic-at-hand, yeah?

The OC comment was:

>I expect there would have been a warning given in that case before assessing a fine.

To which your initial retort was:

>What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines.

When you started receiving the downvote storm is when you challeneged for proof that the GDPR requires warnings.

I gave a response that supports the OC's position, that a warning could and would be expected; not because of requirement but because it is up to the discretion of the supervisory authority.

After all, the initial challenge that was given to the OC was, "What makes you expect this?" was it not?

Now, it's your turn to disprove that a warning would be expected. I'll wait...

Re: GDPR Enforcement Tracker: List of GDPR fines

#220

Earlier quoted context omitted.

Once again under UK drug law it is entirely legal to send someone to prison for five years (I think) for an eighth of weed. Except it never happens. To get straight to a maximum penalty there would be very damning circumstances. It's why we have regulators, judges and magistrates - to apply judgement and proportionality. Sure there's a few headline cases of some absurdly harsh sentence - and just about always the det…

You appear to be spreading false rumors about them issuing warnings even though they don’t have to. When I organized the data on this site by fine amount, not a single case on the front page said anything about any of the companies fined having received a single warning. So, by comparing this to legal situations where “ it never happens” you are purposely misrepresenting the risk of receiving a fine under GDPR withou…

You need to read both of these, and you need to understand what they mean in the context of EU law.

https://gdpr-info.eu/art-58-gdpr/

https://gdpr-info.eu/art-83-gdpr/

You also need to remember that if the regulator has got it wrong there is a remedy available for the person being fined.

About cannabis: generally the first offence will receive a warning unless there are aggravating factors. Police are expected to take an escalating approach: 1st offence = warning, 2nd offence = penalty notice for disorder (which doesn't result in a criminal record if it's paid), 3rd offence = arrest followed by caution or charge and prosecution.

Post reply on HN