Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

251–260 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#251

Earlier quoted context omitted.

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

With such sensitive information they should really avoid CC/BCC and do it manually, or write a script for sending 1 email at a time. Not because CC/BCC is bad, but because you want to be 100% sure to dodge this kind of problems.

And the fine will make sure you remember to do that in future!

It's almost like laws can work.

Re: GDPR Enforcement Tracker: List of GDPR fines

#252
post #58

Earlier quoted context omitted.

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…

Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…

There are other examples at least from Germany where no warning or time to rectify was given, just a fine.

https://iapp.org/news/a/germanys-first-fine-under-the-gdpr-o...

Re: GDPR Enforcement Tracker: List of GDPR fines

#253
post #99

Earlier quoted context omitted.

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

If you make a mistake and you do so honestly, not out of malice and fix it, you are very unlikely to get a fine - you will get guidance and a warning. Unless you are being egregiously slip-shod.

That's not true, unfortunately.

https://www.lexology.com/library/detail.aspx?g=d8d0c69a-620e...

Re: GDPR Enforcement Tracker: List of GDPR fines

#254
Interesting one from Spain, accessing user's microphones to crowdsource publicbroadcast violations:

> The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent.

Re: GDPR Enforcement Tracker: List of GDPR fines

#255

[flagged]

> (otherwise you wouldn’t be downvoting it, right?)

You're assigning a strawman to your downvotes. OP said "I expect" (not "There must have been"), and it is the usual procedure. It's not a _requirement_ as some bigger or more deliberate infringements may warrant an instant fine.

Re: GDPR Enforcement Tracker: List of GDPR fines

#256

Earlier quoted context omitted.

Why would you expect a site built to report GDPR fines and penalties to report GDPR warnings? ICO haven't yet released aggregate figures for GDPR, it's too soon. GDPR is a minor update of DPA, and they have released aggregate numbers on that for a while. Fines are levied in a tiny minority of cases. Warnings are far more common, as is steady escalation. The expectation here is the proportions will remain the same und…

>GDPR is a minor update of DPA It is not a minor update[1]. The Information Commissioner's Office is extremely aware and vexed, given the current state of affairs, that Data Protection Act 2018, needs to be aligned as closely to the GDPR to allow for information to flow freely after Brexit (Article 45)[2][3]. Furthermore, ICO has not been the epitome of a regulatory body enforcing the law to it's fullest extent, for…

That is an entirely different issue. GDPR is effectively an update of DPA 1998 that it replaces. Most is the same, definitions and scope are widened and modernised. A company that had implemented DPA(1998) was most of the way there for GDPR(2016). If you're going to get pedantic, DPA 1998 is one of the many implementations of EU's DPD 1995 as there is a fundamental difference between EU Regulation and EU Directive.

Clearly I am not calling GDPR (2016) a minor update of a subsequent law UK DPA (2018). That is UK's implementation of GDPR, which thanks to the stupidity that is Brexit may indeed have some issues interrelating with the EU. Probably the least of our issues, but still...

UK ICO's stance is fairly well known, but I don't think they can be held responsible for businesses that liquidate in the face of fine. That seems more likely to be an issue of UK company law.

Re: GDPR Enforcement Tracker: List of GDPR fines

#257
post #6

To whoever did this: thanks! Such a website can have many uses: - Show the average people why privacy is important with concrete examples - Find previous rulings for people in a specific situation - Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers My wish for that website is that in the future, the data is more easily readable and "big-data exploitable" (good luck with tha…

> Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers I was thinking the opposite. The fines listed are so low, that from a purely financial perspective complying doesn't seem to make much sense. I would estimate all GDPR compliance efforts I've been involved in to be more costly than the largest fine issued in Germany.

The idea, generally speaking, is escalating fines. If a fine of this level doesn't stop you, you will get a substantially larger fine for the next or on-going infringement.

Re: GDPR Enforcement Tracker: List of GDPR fines

#258

Can anyone explain the N26 case to me? I've tried to read two articles on it and they don't make sense. It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article. But somehow this was not the case for those old accounts that were closed? How can you close an account but it's still a…

According to the annual report (https://www.zaftda.de/tb-bundeslaender/berlin/695-tb-lfd-ber...), N26 used to add all former customers to a black list, which is not allowed if there is no suspicion against them.

>>Eine schwarze Liste für ehemalige Kundinnen und Kunden, gegen die keine Verdachtsmomente bestehen, ist rechtswidrig.

translated with deepl: >>A blacklist for former customers against whom there is no suspicion is unlawful.

Re: GDPR Enforcement Tracker: List of GDPR fines

#259
post #154

Many people are complaining about some fines, but here are some others I see that are evidence of this working extremely well: - A police officer was fined for using his department's tools to get someone's private phone number for his personal use - A rental agency was fined for leaving renter's private data (ids, etc) open to the public for six months after being notified of the vulnerability - A company was fined b…

All but maybe one of those looks like it was illegal prior to GDPR, so I'm not sure GDPR is what you're praising.

Which one, out of interest? I can imagine all of them being illegal in some member state.
Post reply on HN