Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

261–270 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#261

Earlier quoted context omitted.

Not any website. If it is purely private and non-commercial you don't have to. Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be yo…

> If it is purely private and non-commercial you don't have to. Unfortunately, this does not include a lot of websites that most people would classify as private. For example, a blog still needs an Impressum. In addition, you will even be classified as commercial, and therefore require an Impressum, if you don't make any money, for example if you use ads to (try to) pay the hosting cost. > A P.O. box is not required…

A blog is not automatically non-private and commercial.

If you have ads you make money. Just possibly less then you spent on hosting.

And yes that should have read "A P.O. is not sufficent.". Sorry for that mistake.

Re: GDPR Enforcement Tracker: List of GDPR fines

#263

Earlier quoted context omitted.

>GDPR is a minor update of DPA It is not a minor update[1]. The Information Commissioner's Office is extremely aware and vexed, given the current state of affairs, that Data Protection Act 2018, needs to be aligned as closely to the GDPR to allow for information to flow freely after Brexit (Article 45)[2][3]. Furthermore, ICO has not been the epitome of a regulatory body enforcing the law to it's fullest extent, for…

That is an entirely different issue. GDPR is effectively an update of DPA 1998 that it replaces. Most is the same, definitions and scope are widened and modernised. A company that had implemented DPA(1998) was most of the way there for GDPR(2016). If you're going to get pedantic, DPA 1998 is one of the many implementations of EU's DPD 1995 as there is a fundamental difference between EU Regulation and EU Directive. C…

>UK ICO's stance is fairly well known, but I don't think they can be held responsible for businesses that liquidate in the face of fine. That seems more likely to be an issue of UK company law.

You are confusing ICO's stance and responsibility with it's reluctance to enforce powers, which have already been granted to them by the government, in order to pursue negligent cases and collect fines under the UK law.

The Insolvency Service has general powers to investigate both insolvent and active companies, including those companies that undertake direct marketing activities. If a director has deliberately acted to the detriment of the company and/or its creditors, action may be taken against the directors under the Insolvency Act 1986 or the Company Directors Disqualification Act (CDDA) 1986.

Re: GDPR Enforcement Tracker: List of GDPR fines

#265

Earlier quoted context omitted.

I’m not sure what that has to do with this discussion. We are discussing whether or not GDPR requires warnings before fines are allowed to be issued. The answer is no, it does not require them, and the text you linked to does not disprove this simple, undeniable fact.

Incorrect. You're moving the goal posts. Let's stay on the topic-at-hand, yeah? The OC comment was: > I expect there would have been a warning given in that case before assessing a fine. To which your initial retort was: > What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. When you started receiving…

One cannot expect a warning if a warning isn’t required. You may hope to get a warning, but unless it is required you should not expect it. There are numerous cases listed on the website we are discussing where, in fact, no warning was issued. Had those individuals/companies read the comments in this thread prior to receiving fines, they would have been wondering why they received no warning, since everyone claims they should “expect” their self-appointed, benevolent, data overlords to give them a warning first. Unfortunately for them, all of you are incorrect that they should “expect” to receive warnings. Why? Because they are not required, and not only that, warnings don’t even appear to be the norm.

Re: GDPR Enforcement Tracker: List of GDPR fines

#266

Earlier quoted context omitted.

Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…

There are other examples at least from Germany where no warning or time to rectify was given, just a fine. https://iapp.org/news/a/germanys-first-fine-under-the-gdpr-o...

I lost 50 karma points trying to point out that warnings aren’t required. Tread lightly when disputing HN groupthink...

Re: GDPR Enforcement Tracker: List of GDPR fines

#267

[flagged]

> (otherwise you wouldn’t be downvoting it, right?) You're assigning a strawman to your downvotes. OP said "I expect" (not "There must have been"), and it is the usual procedure. It's not a _requirement_ as some bigger or more deliberate infringements may warrant an instant fine.

It is not a requirement, which is why nobody should have any expectation that they or anyone else will receive one before being slapped with a heavy fine.

Re: GDPR Enforcement Tracker: List of GDPR fines

#268
post #205

Earlier quoted context omitted.

Can you show that it is an outlier for a law to not require warnings to be given? No, my initial comment on this issue was in reply to someone that said "I expect there would have been a warning given in that case before assessing a fine." [1]. This is an oft-repeated and entirely baseless sentiment that HN's resident GDPR defenders love to cite - it shows up in every one of these threads. That is why I was making it…

> "I expect there would have been a warning given in that case before assessing a fine." [...] That is why I was making it clear that in fact no warnings are required They didn't say warnings were required , they said that warnings were the norm . You haven't provided counter-examples to that claim, you're arguing against a straw-man argument that "warnings are required by the GDPR". As an example outside GDPR, it is…

They didn't say warnings were required, they said that warnings were the norm.

Sadly, it appears that warnings are not the norm. When you organize the data on this site by the size of fine, you’ll notice that none of the top 10 received any warning.

Re: GDPR Enforcement Tracker: List of GDPR fines

#269
post #218

[flagged]

> What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. It's not in GDPR because it's part of EU law. Two parties to a case need to attempt to fix it before going to court. In the UK this is why you have letters before action setting out what you think your case is, how you want it to be fixed, and what…

And yet this site details numerous examples of GDPR fines being issued without any warning. So clearly this law that you claim requires warnings does not actually do so when it comes to GDPR.

Re: GDPR Enforcement Tracker: List of GDPR fines

#270
post #228

Earlier quoted context omitted.

Not a harassment campaign as such, it seems. He was mad about something, and mailed a bunch of politicians and press his complaints. Complaints, sometimes bordering on being libelous, according to the agency which fined him, not death threats. He was fined solely based upon the email addresses being visible to all recipients, not because of the content of his mails, said a spokesperson. However, he was a repeat offen…

Isn't one of the points of separation of power that the government (executive branche) should not have priority access to the judicial branche? Fining individuals, even loony ones, while not even attempting to fight the big battles (FAANG, personal data trading for 'profiling' or even government profiling within the EU) is imho just preposterous.

Well, the judiciary branch was not involved in this fine. It was a government agency issuing the fine. Now the fined person could pay the fine, or file a suit asking a court to overturn it.

It really is analogous to most govt fines e.g. speeding tickets: the government (the police) gives you a ticket, and if you pay it then OK, no court involved, but if you challenge it then the courts get involved.

But more generally, the government should and does get priority access to the courts already. Criminal courts exist solely to serve the government; you cannot bring criminal suits as a citizen yourself, only civil suites. Also, e.g. in Germany the government and legislatures (federal and state) get priority access to e.g. the constitutional (supreme) court. A mere mortal cannot just file suit directly in the constitutional court, but has to go through the lower instances first (unless there is something similar to a class action petition, showing a sizable chunk of the population sees the same issue and wants it decided). Members of the parliaments and IIRC of the cabinet are allowed to file suit in the constitutional court directly. The reasoning here is that if it was allowed for citizens to petition the highest court directly, then the court would do nothing else than write rejection letters for bullshit petitions. While the govt and legislatures incl the parliamentary opposition of course represent the people (in theory) and aren't stupid morons wasting the courts time (in theory).

PS: Google was already fined €50M for GDPR violations, and there is probably more of those in their future. Facebook got fined €10M so far, IIRC, also with more to come. And don't forget the billions of Euros worth of antitrust fines against Google and Microsoft, e.g.

Post reply on HN