Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

221–230 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#221

Earlier quoted context omitted.

I explained in the next sentence what makes me expect this: "Many of the less serious ones I read explicitly mentioned warnings that were ignored."

Many, but not all of them said this. Given that GDPR has absolutely no requirement that warnings be issued, it is not reasonable to expect that warnings were issued and/or ignored in cases where it doesn’t specifically say this occurred.

Huh? It does have this requirement:

Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive

When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:

A) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentional or negligent character of the infringement;

e) any relevant previous infringements by the controller or processor;

i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;

Re: GDPR Enforcement Tracker: List of GDPR fines

#223

Two of these are much more intense than I would have guessed: >The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the Central Electronic Register and Information on Economic Activity, and processed the data for commercial purposes. The authority verified incompliance with the information obligation i…

> But I hope GDPR boosters who went around minimizing the threat to good-faith actors admit that they were wrong.

What? No. Your first example talks about "open source datasets" -- no such thing exists for my personal data. If you've gathered my data you need to tell me why you gathered it. Dumping it into a dataset for other people to use is clearly not ok.

Your misdescribe your second example. Notice the company weren't fined just because they had the phone number. They were fined because they had the phone number, they were asked to delete it, and they declined to delete it. The company were not claiming they couldn't erase the phone number because it would be too hard. They were trying to say that they wouldn't erase it because they needed it for debt collection. The regulator disagreed.

Neither of these are good faith actors and these are exactly the kinds of data misuse I wanted GDPR to handle.

Re: GDPR Enforcement Tracker: List of GDPR fines

#224

250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user's microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I'm a little bit surprised that the fine is this low: "The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobil…

Considering some others in there this feels like a slap on the wrist

If they stopped the conduct then it is not supposed to be anymore than a slap on the wrist. GDPR is meant to correct behaviour, not to punish.

Re: GDPR Enforcement Tracker: List of GDPR fines

#225
post #90

Earlier quoted context omitted.

That's fine, but my point was not that Kolibri Image took the appropriate steps immediately, but whether the commenters here on HN were correct in their estimation that the various data protection authorities would help you resolve compliance issues versus just issuing you fines.

Some more context: https://gdpr.report/news/2019/01/23/small-business-in-german... Relevant passage: "Discovery of the misdemeanor began with an email from another company to the Hessian Data Protection Commissioner, sent in May of last year, in which advice was requested regarding the failure of Kolibri Image in proving customer data, despite multiple requests being sent. Kolibri Image declined to cooperate, instead…

you can't shield yourself from GDPR simply by saying, "Oh it's this other company's responsibility. And, by the way, they don't agree to do GDPR, so it's out of my hands".

To be specific, this is mandated explicitly by the GDPR:

> the controller shall [ensure] to be able to demonstrate that processing is performed in accordance with this Regulation. [art.24]

> Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees [art.28]

> Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller [art.28]

[art.24] https://gdpr-info.eu/art-24-gdpr/

[art.28] https://gdpr-info.eu/art-28-gdpr/

Re: GDPR Enforcement Tracker: List of GDPR fines

#226

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

"The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening football matches without paying a fee"

Yes, proof of weaponized gdpr use indeed (for very specific filtering cases of gdpr use).

Re: GDPR Enforcement Tracker: List of GDPR fines

#227

Earlier quoted context omitted.

I've got an imprint, including my mobile phone number, on my partly personal, partly business website for about 15 years now. In this time I have not received any calls or unwanted mail on this address. Not a single one in all those years.

Maybe your website is not popular enough. I had a website a few years ago (not anymore) and since then I receive about one call per week of "Microsoft" employees asking me to install some backdoor software.

Well, I can't complain about visitors and views and the resulting business out of that. Maybe I'm just very lucky, but it's not such a big deal as OP wants it to be.

Re: GDPR Enforcement Tracker: List of GDPR fines

#228

Earlier quoted context omitted.

If the story linked elsewhere in this thread is the one in question, this wasn't an accident. It was a guy running some kind of harrassment campaign. His "little mailing list" was of people he was harrassing, not subscribers to a newsletter. https://www.rosepartner.de/blog/bussgeld-fuer-offenen-e-mail...

Not a harassment campaign as such, it seems. He was mad about something, and mailed a bunch of politicians and press his complaints. Complaints, sometimes bordering on being libelous, according to the agency which fined him, not death threats. He was fined solely based upon the email addresses being visible to all recipients, not because of the content of his mails, said a spokesperson. However, he was a repeat offen…

Isn't one of the points of separation of power that the government (executive branche) should not have priority access to the judicial branche? Fining individuals, even loony ones, while not even attempting to fight the big battles (FAANG, personal data trading for 'profiling' or even government profiling within the EU) is imho just preposterous.

Re: GDPR Enforcement Tracker: List of GDPR fines

#230
post #201
post #4

Earlier quoted context omitted.

"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.

Some countries are sane enough to enshrine privacy in public spaces into law, because of the potential for abuse. This is slowly but surely being eroded also in Germany. Multiple cities are trialling full video surveillance to stop the terrorists. e.g: Some USA towns have near 100% video surveillance through the Amazon doorbell cameras (Ring) of the town's inhabitants. Some content is publicly available, cops can als…

Good. Fuck thieves.
Post reply on HN