Live data from Hacker News

Intent to issue €2.5M fine to Disqus over GDPR breaches

datatilsynet.no

41–50 of 123 posts

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#41

Earlier quoted context omitted.

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

What if I (as a European visitor) access the website through a VPN, something I'm legally allowed to do?

GDPR applies to processors or controllers not in the Union if the processing activities are related to:

1. the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

2. the monitoring of their behaviour as far as their behaviour takes place within the Union.

(See Article 3).

I believe that in most cases the point of geoblocking is not so much to try to actually stop people in the EU from accessing the sites, but rather to try to ensure that any data processed falls under #1.

One of the Recitals for that section says:

> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#43
post #38
post #12

Earlier quoted context omitted.

Not so long ago I stumbled on https://data.disqus.com , which basically outlines what they were fined for. They should probably take that site down soon...

"Our services: [...] Identity Matching", "Hundreds of data points to create cross device profiles", "215M emails collected". Hallmarks of a company you definitely want to embed on your site...

Aside: isn't it weird how often "email addresses" is shortened to "emails"? At first glance I had to contextually infer whether it was 215M addresses or 215M messages (pieces of mail) because we also often shorten the latter to "emails" when working through our inboxes.

If you're running a marketing campaign and say "today we finally hit 1000 emails" without further clarification, nobody will know if that's 1000 subscribers or 1000 newsletters.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#44
post #11

Earlier quoted context omitted.

Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users won't do it because they want those users.

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#45
post #40
post #17

Earlier quoted context omitted.

To add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).

Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. Some documentaries even call it the worlds most toxic food.

> Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision?

We definitely have to split the Norwegian fisheries industry into two: Norway has, and has for a long time had, a sizable wild fishing industry. The fish farming industry is a much newer one.

I was a kid last time we had a referendum on membership (1994), so I'm not sure, but I believe the fish farming industry wasn't even a major thing back then. The classical fisheries industry definitely was a big part of the reasoning. Today, I would wager that opponents of full membership are mostly riding on the same vague of opaque euroskepticism that brought us Brexit, combined with the sickening idea that Norwegians are somehow magically special and exceptionally good at things. Granted, my personal views on the matter definitely color this take.

> From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming.

I doubt that would be an issue.

> Some documentaries even call it the worlds most toxic food.

I really wish people would stop spreading this unsubstantiated bullshit. I have no connection with or investments in fish farming, but this claim was making the rounds a few years back, and as far as I can tell it's a completely unsubstantiated smear. It keeps getting repeated, but trying to actually get to the source just reveals a tangled web of self-referential claims.

There's plenty of problems with fish farming without having to make up shit about "toxic food". The two biggest being the horrid effect the escaped farmed fish have on the natural populations (they carry different diseases and parasites that can wipe out whole rivers of salmon, for instance), and the effect of over-feeding on the nearby ecosystem (you dump enormous amounts of feed into a relatively small volume of water, and far from all of it is actually consumed by the farmed fish). In addition to this, the feed often comes from just as unsustainable sources as the worst of the "Amazon beef". Hopefully the latter can be fixed with transparancy and regulations, though.

Plenty of problems with fish farming without needing to fabricate new ones. But then again, it may be the only solution to prevent overfishing (if we want to keep eating fish, which is certainly better overall than eating beef).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#46
post #32

More background: The fine is mainly based on the fact that Disqus forgot to enroll Norwegian IP-addresses into their GDPR «privacy mode». That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus. Major sites like the W…

"forgot"

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#47
post #46
post #32

More background: The fine is mainly based on the fact that Disqus forgot to enroll Norwegian IP-addresses into their GDPR «privacy mode». That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus. Major sites like the W…

"forgot"

Forgetting for a single country (which is also not part of the EU) certainly seems plausible, more plausible than a targeted attempt at undermining the GDPR in a very specific country

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#48

Earlier quoted context omitted.

On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.

Huh? Plenty of sites do that. I've noticed many US local news sites that block EU users. I assume that any other company that isn't already blocking EU users won't do it because they want those users.

People like to infer from this that those sites are gathering and processing data in ways that would be hard to make GDPR-compliant.

My guess is that in a lot of cases though it is that they simply do not want to deal with Article 27. Article 27 is a hassle even if all your data processing itself is fully compliant with GDPR.

Article 27 requires entities not in the Union to designate a representative in the Union that people and governments can use as a contact when they have GDPR concerns.

(Don't confuse this with Article 37, which requires the appointment of a "data protection officer". Article 37 only applies in most cases if you are doing large scale processing).

The representative seems to be more than just a communications go-between to provide an easy way for people in the EU to contact the processor/controller. One of the Recitals says "The representative should be explicitly designated by a written mandate of the controller or of the processor to act on its behalf with regard to its obligations under this Regulation" and "The designated representative should be subject to enforcement proceedings in the event of non-compliance by the controller or processor".

There are EU companies that provide as a service being your Article 27 representative, but because it seems to be more than just a simple communications go-between they charge typically at least a couple hundred Euros or so a year for the service (sometimes much more).

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#49

Try blocking Disqus with uBlock Origin, turns out you probably won't miss it ||disqus.com^ You could also try a dynamic filter and disable it on a per-site basis * disqus.com * block Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...

curious can't it be done by disabling third party cookies alone as Disqus need cookies to work?

Re: Intent to issue €2.5M fine to Disqus over GDPR breaches

#50
post #21

"Norwegian internet users were tracked by Disqus because the company did not know that Norway introduced the common European privacy regulation GDPR in 2018. It thus took 511 days before Norwegians were incorporated into the company's "privacy mode" for GDPR countries and previously collected information was deleted."[0] It seems that there was some setting that is enabled by default in all other countries than count…

Wouldn't it be funny if this was caused by some YAML configuration reading the country code "no" as "false".
Post reply on HN