Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

271–280 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#271

Earlier quoted context omitted.

Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…

There are other examples at least from Germany where no warning or time to rectify was given, just a fine. https://iapp.org/news/a/germanys-first-fine-under-the-gdpr-o...

800k email records and passwords in plain text when breached. I don't know how big Knuddels are, so I don't know if that fine sounds lenient, right or high. Yet as it's a large breach it seems fitting of no warning first, considering the scale of negligence, mitigated by their "exemplary cooperation" afterwards.

Which goes to show why the regulators get the discretion to decide appropriate action from warning only to maximum fine. Without context and aggravating and mitigating factors we can't know, which was my point. If a penalty is disproportionate there's well worn appeal tracks.

Other comments seem to point to the small case in OP comment being some guy running a list to harass people, which seems like a huge aggravating factor to me. Maybe he got one warning, maybe in context he didn't deserve even that.

Re: GDPR Enforcement Tracker: List of GDPR fines

#272

Earlier quoted context omitted.

That is an entirely different issue. GDPR is effectively an update of DPA 1998 that it replaces. Most is the same, definitions and scope are widened and modernised. A company that had implemented DPA(1998) was most of the way there for GDPR(2016). If you're going to get pedantic, DPA 1998 is one of the many implementations of EU's DPD 1995 as there is a fundamental difference between EU Regulation and EU Directive. C…

>UK ICO's stance is fairly well known, but I don't think they can be held responsible for businesses that liquidate in the face of fine. That seems more likely to be an issue of UK company law. You are confusing ICO's stance and responsibility with it's reluctance to enforce powers, which have already been granted to them by the government, in order to pursue negligent cases and collect fines under the UK law. The In…

That's the Insolvency Service, which isn't ICO, and presumably they (IS) would have to instigate action. I've no idea how it interrelates with ICO's powers, but I'm completely outside my knowledge here.

Re: GDPR Enforcement Tracker: List of GDPR fines

#273

At the time of the GDPRpocalypse last year, there were a lot of discussions here, and a lot of FUD being slung around about how if your US website wasn't 100% GDPR-compliant you'd be handcuffed if you set foot in an EU airport bla bla bla, or that minor infractions would incur the maximum penalty of millions of euro, bankrupting your awesome adtech startup bla bla bla. Most of it was fueled by the clash between US an…

> Seems we were right. Arguably, and so far . There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses, and just because nobody's been hanged over it in year one doesn't mean it won't be abused, oppressive, or have other negative unintended consequences in the future.

> There are sites that just block requests from the EU

The only sites that I've seen with this are local US news sites that don't even have to follow GDPR.

Re: GDPR Enforcement Tracker: List of GDPR fines

#274
post #195

Earlier quoted context omitted.

Dunno how well this will work if you need to claim that the pedestrian or cyclist just darted in front of you. But then again, maybe you don't want that kind of thing recorded.

There is almost always a button for manually triggering a recording.

Is that legal in Austria?

Re: GDPR Enforcement Tracker: List of GDPR fines

#275
post #220

Earlier quoted context omitted.

You appear to be spreading false rumors about them issuing warnings even though they don’t have to. When I organized the data on this site by fine amount, not a single case on the front page said anything about any of the companies fined having received a single warning. So, by comparing this to legal situations where “ it never happens” you are purposely misrepresenting the risk of receiving a fine under GDPR withou…

You need to read both of these, and you need to understand what they mean in the context of EU law. https://gdpr-info.eu/art-58-gdpr/ https://gdpr-info.eu/art-83-gdpr/ You also need to remember that if the regulator has got it wrong there is a remedy available for the person being fined. About cannabis: generally the first offence will receive a warning unless there are aggravating factors. Police are expected to tak…

Neither of those links you pointed to say anything about warnings being required, or even customary for that matter.

Re: GDPR Enforcement Tracker: List of GDPR fines

#276
post #220

Earlier quoted context omitted.

You need to read both of these, and you need to understand what they mean in the context of EU law. https://gdpr-info.eu/art-58-gdpr/ https://gdpr-info.eu/art-83-gdpr/ You also need to remember that if the regulator has got it wrong there is a remedy available for the person being fined. About cannabis: generally the first offence will receive a warning unless there are aggravating factors. Police are expected to tak…

Neither of those links you pointed to say anything about warnings being required, or even customary for that matter.

Because you haven't understood the context of what the EU means when it says "proportionate".

Article 83 is basically a long list of reasons to avoid giving a fine but to give a warning instead.

Re: GDPR Enforcement Tracker: List of GDPR fines

#277
post #205

Earlier quoted context omitted.

> "I expect there would have been a warning given in that case before assessing a fine." [...] That is why I was making it clear that in fact no warnings are required They didn't say warnings were required , they said that warnings were the norm . You haven't provided counter-examples to that claim, you're arguing against a straw-man argument that "warnings are required by the GDPR". As an example outside GDPR, it is…

They didn't say warnings were required, they said that warnings were the norm. Sadly, it appears that warnings are not the norm. When you organize the data on this site by the size of fine, you’ll notice that none of the top 10 received any warning.

Ignoring that we don't know how complete the one-paragraph summaries of the cases are (many of the links are not in English) -- how is looking at the top 10 largest fines a fair sample? Surely taking 10 random samples is a much better selection?

It seems possible that the largest fines were for the most severe transgressions, or for companies that are large enough to know better. In fact, the topmost example of Google's Android penalty is a prime example of both factors. So it's possible there is a statistical bias for larger fines to be for more severe cases where warnings make less sense.

Re: GDPR Enforcement Tracker: List of GDPR fines

#278
post #218

Earlier quoted context omitted.

> What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. It's not in GDPR because it's part of EU law. Two parties to a case need to attempt to fix it before going to court. In the UK this is why you have letters before action setting out what you think your case is, how you want it to be fixed, and what…

It isn't a case between two parties, it's a crime. Do you expect "warnings" for arson or robbery? Then why do you expect warnings for data disclosure?

Because it's difficult to accidentally commit robbery.

Re: GDPR Enforcement Tracker: List of GDPR fines

#280
post #277

Earlier quoted context omitted.

They didn't say warnings were required, they said that warnings were the norm. Sadly, it appears that warnings are not the norm. When you organize the data on this site by the size of fine, you’ll notice that none of the top 10 received any warning.

Ignoring that we don't know how complete the one-paragraph summaries of the cases are (many of the links are not in English) -- how is looking at the top 10 largest fines a fair sample? Surely taking 10 random samples is a much better selection? It seems possible that the largest fines were for the most severe transgressions, or for companies that are large enough to know better. In fact, the topmost example of Googl…

This, and of course the list doesn't include those cases, where there was only a warning, and never a fine.
Post reply on HN