Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

471–480 of 534 posts

Re: Shutting Down Forum (GDPR)

#471

Earlier quoted context omitted.

I think you are right about one thing, the misreading of European law that comes from living in a litigious society. Just act in good faith and GDPR will not bite.

Just act in good faith and GDPR will not bite. Do you have $20million to make that gamble?

Or 4% of your world revenue whichever is largest.

Then again you can stop brandishing this FUD as this kind of fine is not gonna happen to small actors. If you act in good faith and are found doing something wrong you'll receive a notification asking you to fix the issue.

Why do people think EU is dumb and will start distributing 20M fines right and left at the first offense ? Just look at how it's done up until now and what CNIL said about how GDPR will be applied.

Re: Shutting Down Forum (GDPR)

#472

Earlier quoted context omitted.

I didn't see any question in there. My answer though is: respond to the request (which shouldn't be as hard as some are making out), but don't worry about fines unless you've been misusing the data or repeatedly ignoring warnings.

Then wtf is the point of GDPR if nobody will be sued for violating it?

You've posted dozens of comments in GDPR flamewars. This sort of high-quantity, low-quality controversy quickly gets extremely repetitive and thus is off topic in addition to breaking the site guidelines (https://news.ycombinator.com/newsguidelines.html).

Since that's all this account has done and we don't allow single-purpose accounts here, I've banned it. Please don't create accounts to do this with.

Re: Shutting Down Forum (GDPR)

#473

Earlier quoted context omitted.

20 million is the max penalty for repeat offenders. See article 83 about fines being proportinate to the offense: https://gdpr-info.eu/art-83-gdpr/ This is a european thing, if any law says $x is the max fine or alike, then for a first time offense you usually get much less.

I would still be bankrupted by "much less" than $20 million.

Good for you.

now understand that fines are proportionate to the offense. Are you engaging in doing very bad thing to personal data on a very large scale and having a business based on this ?

no ? then what are you afraid of ? that failing to answert to one guy asking for what data you have on him will cause you to be fined to bankruptcy level ? I pity the fool as said that one guy.

Re: Shutting Down Forum (GDPR)

#474
post #436
post #434

Earlier quoted context omitted.

Saying that people need to be shoved off a cliff is not elevating your position. In fact, these kind of statements are exactly what make me concerned about regulations and laws. One has already made your mind up about a group of people and now it's time to execute.

It’s a metaphor. You’re already teetering. All it takes is a little push and you’re hurtling to your demise.

If it is a metaphor, presumably you mean more like "your business is hurtling to its demise."

Re: Shutting Down Forum (GDPR)

#475

Earlier quoted context omitted.

Site operators who shut down their site preemptively because they don't have time to even consider their GDPR stance are not really a strong signal on how sensible the law is. In this case the operator's usage of the word troll to describe what happened is telling. Anyone can send any kind of threatening letter they want, and they are free to report you for non-compliance, but that doesn't mean any action will be tak…

Site operators who shut down their site preemptively because they don't have time to even consider their GDPR stance are not really a strong signal on how sensible the law is. No, but it is a strong signal of my critique: That the EU is a 900 pound gorilla and that is a large part of the problem here. Small operators will, in fact, be impacted by this because they don't have the resources -- including time -- to cope…

To change the practices of Facebook and the ad-tech world, you need a 900 pound gorilla or else nothing will change. All of this sky-is-falling punditry holding up small operators as examples is premature. Yes there is uncertainty, the landscape is changing, but it's not going to crush the little guy, mark my words.

Re: Shutting Down Forum (GDPR)

#476
post #410

Earlier quoted context omitted.

Can you post to any of those results from the actual regulators? So far there have been a few people just giving up before the regulators get involved, which seems like a massive over reaction.

That's basic survival for instinct for small shops. They may not be able to do X, but their entire life won't be crushed under the boot of Darth GDPR either.

> but their entire life won't be crushed under the boot of Darth GDPR

What a fucking stupid thing to say.

GDPR requires a few things: don't collect too much data; be honest about why you're collecting it; allow corrections; in some situations allow deletion.

This isn't a a boot crushing people.

Re: Shutting Down Forum (GDPR)

#477
post #358

Earlier quoted context omitted.

Deleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the post…

Encouraging the deletion of old posts is still a bad thing for the internet. A lot of in-depth subject knowledge is contained in old internet posts. I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer…

Your comment made me wonder how services like archive.org that automatically save forum posts that may contain personal information are going to deal with GDPR.

Re: Shutting Down Forum (GDPR)

#478

Earlier quoted context omitted.

Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action th…

"a data subject can't sue" Didn't a data subject sue Google and Facebook for billions on day one of enforcement?

Great example. No, they didn't, though you wouldn't guess that from the news coverage. They filed complaints with four regulators. The details are all here. https://noyb.eu/

Re: Shutting Down Forum (GDPR)

#479

Earlier quoted context omitted.

how is interpretation of the law not a problem with any law that was in effect before GDPR. It didn't stop anybody from starting businesses before and will not after.

It's punishment amounts. Laws should strive for minimal maximums and reasonable ranges to apply that interpretation in. We don't say every crime is punishable up to a life sentence for a reason. The more leeway the law provides, the more room for abuse (for either side). It would not have been hard to define multiple reasonable ranges, but sadly they think these values are what gives the law "teeth" (instead of actua…

Sorry but I don't understand how defining multiple ranges would have been simpler than only having one. I also fail to see how 4% of global annual revenue is unreasonable considering facebook and google have both been fined the previous maximum amount of 150 000€ with no consequences for them and they went about their day keeping at doing what they were doing that caused them to be fined.

Re: Shutting Down Forum (GDPR)

#480

Earlier quoted context omitted.

No, because I am not a business owner so I am not interested in all the details, my interest is an internet user, I am fine with popups that allow me to opt out, I am also fine with websites that will block me(like the newspapers one) because I will find an alternative that does not track me. I understand that you may have some small websites and you put on them who knows how many trackers/analytics and now is time c…

I realize that I am sort of the pot calling the kettle black here because I also have not read it, but I am making meta commentary on observable and inferable unintended consequences disproportionately impacting smaller organizations while you are arguing the details of how to comply without really knowing anything about it. The kind of observations I am making are not actually dependent on me understanding the detai…

The thing is I don't know how this law could be "nicer" for small sites but continue to be fair.

I feel a bit bad for small creators that need to fix their sites but at the same time I dislike the people that are trying to find possible loopholes around the law, fixing all this loopholes and workarounds is the reason the laws have long texts.

Do you have a website or something that is affected? I only have a simple site that I used some time ago as CV and for testing, I never had tracking scripts,analytics, referrals. I am also the opinion if you don't want to respect my privacy then tell me that and block my access.

Post reply on HN