Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

41–50 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#41

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV.

Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist.

https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

Re: GDPR Enforcement Tracker: List of GDPR fines

#42

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

I support this fine in principle. Maybe not the magnitude, maybe not without a warning, and of course a three liner isn't enough context to be sure.

But using CC instead of BCC causes a massive leak of personal information, especially when either the subject being discussed or the people on the list are sensitive. In my life this has mostly been annoyance at large org stuff, but my wife has had this happen with a sensitive medical practice and we were not in the US so HIPAA did not apply.

I don't think fines are the only solution, of course. But I think fines should be on the table and it's easy to me imagine a circumstance where 2k euro would be appropriate.

Re: GDPR Enforcement Tracker: List of GDPR fines

#43
post #37

Earlier quoted context omitted.

What's ridiculous about that?

Everybody can stalk you if they don't like what you've published for example.

That comes with the territory of online ownership. If you want anonymity then pay someone else to host your data.

Re: GDPR Enforcement Tracker: List of GDPR fines

#45
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

Not any website. If it is purely private and non-commercial you don't have to.

Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be your private one. It just has to work. A few other things are required, e.g. where your LLC is registered if it is an LLC.

Re: GDPR Enforcement Tracker: List of GDPR fines

#46
post #11

Perhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's stil…

GDPR isn't in effect for a long time and a big case against Google and similar companies isn't easy. Doing this needs in depth research in the ways they process data and through the terms, which were written by hghly paid lawyers. Doing this right is hard and if the goal is not to make money but to improve privacy there is value in pushing them in a political way over fighting longncourt cases - during which they probably won't change a bit.

Also there is this rule, that primarily responsibility is in the country where the corporation has their European legal headquarters, and for many the tis Ireland and the Irish government prefers getting 0.5% in taxes for those corporations over having issues with them and having them move to Malta or something.

Re: GDPR Enforcement Tracker: List of GDPR fines

#47

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

This is crazy. I've seen it done plenty of times by accident in the past, because people don't know how to use BCC (and its hidden by default in many clients).

Re: GDPR Enforcement Tracker: List of GDPR fines

#48

Earlier quoted context omitted.

Different take: This is exactly what GDPR was designed for. It just hasn't been "weaponized" enough yet to have the bandwidth to deal with every situation, so situations like these seem like targeted attacks when in reality they're precisely what GDPR is supposed to deal with. I personally think ~$15 per leaked email is a reasonable fine. I bet this guy and everyone else who reads this article won't accidentally leak…

The thing is if this was a civil case you have to prove some damages had be done by the leak. A random person leaking my email in CC - that happens a lot - is not even necessarily annoying but for sure don't cause any damages.

Whether there are damages depends on the context. In 2015 an HIV clinic in London used the to: field instead of bcc: on a patient newsletter, thus exposing the names of 700 patients, many of whom knew each other due to the small geographic area being served (https://www.theguardian.com/technology/2016/may/09/london-hi...). They were fined GBP180K (under the pre-gdpr regime, incidentally, so this isn't a new risk for businesses).

Re: GDPR Enforcement Tracker: List of GDPR fines

#49

Weird there's no fines in UK.

As somebody else pointed out, they're being tracked by the ICO [0]. I think they previously had a blog where they documented enforcement while the UK was still under the older Data Protection legislation but I can't seem to find it.

[0] https://ico.org.uk/action-weve-taken/enforcement/

Re: GDPR Enforcement Tracker: List of GDPR fines

#50
post #11

Perhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's stil…

This could be a case of enforcement against large companies taking longer to conduct, given the complex nature of the cases and the resources of the legal teams involved. My understanding is that a lot of stuff is pending before the Irish data protection agency.

That certainly plays a role, especially as soon as courts get involved (or will get involved), see e.g. the pre-GDPR cases against Facebook still bouncing around the Irish court system. Smaller cases can be handled without international coordination, the facts are often easy to determine, ..., which makes them faster to process.

And the rules about international coordination mean other countries have to wait for Ireland in many cases.

Post reply on HN