Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

481–490 of 534 posts

Re: Shutting Down Forum (GDPR)

#481

Earlier quoted context omitted.

The EU had competition law before that mentions 10% of global turnover as a maximum fee, along with very detailed notes of how to set them: https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:C:... The Sherman Act also mentions a ceiling of 10 million, 3 years of prison for private persons. And from history we know antitrust authorities broke up companies like AT&T or Standard Oil, which seems to me a much bigg…

> Yet you don't see small companies sweating over competition law. They would if it applied to them and they had to do work to comply. This is very simple. If a law applies to a company, companies will worry about it and the perceived risks. If a law doesn't apply to a company, they won't worry. Ideally, both the laws and their punishments are as narrowly scoped as possible to prevent abuse at the whims of enforcer s…

your argument applies exactly the same to GDPR, entities that do not engage in collecting or processing personal data have no reason to sweat. Those who are following the law that had been introduced in the EU in 1995 either.

Had you read the GDPR you'd knew that punishment is proportional to the offense, had you read the regulation in charge of receiving complaints you'd know that they said they will first give a chance to comply to the law before resorting to punishment. The only ambiguity is in the broad term "legitimate interest" offering exemption to GDPR.

Re: Shutting Down Forum (GDPR)

#482
post #54

Earlier quoted context omitted.

Nobody will fine an open-source project that amount of money. The goal of GDPR is not to bankrupt anybody but to nudge them into compliance. If you aren't maliciously handling user data, you are not a target of high fines.

Then why does the law not have this an an exemption?

GDPR has exemptions built in but being open source project is not one.

Re: Shutting Down Forum (GDPR)

#483
post #476

Earlier quoted context omitted.

That's basic survival for instinct for small shops. They may not be able to do X, but their entire life won't be crushed under the boot of Darth GDPR either.

> but their entire life won't be crushed under the boot of Darth GDPR What a fucking stupid thing to say. GDPR requires a few things: don't collect too much data; be honest about why you're collecting it; allow corrections; in some situations allow deletion. This isn't a a boot crushing people.

What a fucking stupid thing to say.

It's perhaps more poetic than is the norm here. That doesn't make it a fucking stupid thing to say.

The reality is that since we don't yet know how this will play out, those who are risk averse, whether by personality or positioning (because some people just can't afford to take risks), will tend to flee from what could be a crushing burden. Furthermore, if someone is essentially in survival mode and can't spare the time and energy to read the GDPR and become confident they know how to deal with it, then just needing to read it and adapt can be a de facto crushing burden without any fines being levied.

Re: Shutting Down Forum (GDPR)

#484
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

As someone who ran a forum centered around one of my passions, I was happy to help users out with small adminstrative tasks. Like you said, no big deal. Now if I was legally required to act on every request in 30 days or face potential litigation, that's a totally different story. I'm doing something that's a fun hobby of mine for free that will benefit others with similar interests. The line is drawn when it can hav…

This misrepresentation of the situation is well addressed in the other reply, but I'd like to point out that unless your hobby is collecting and processing personal data, you simply have to not collect any personal data as no personal data is required to run a forum, add a page explaining so and direct requests to this page.

Re: Shutting Down Forum (GDPR)

#485
post #142
post #62

Earlier quoted context omitted.

The nightmare letter is bogus scaremongering bullshit. THe forum owner should just i) post a link to the privacy policy (which surely explains things like legitimate needs) and ii) supplies a copy of the data being held.

This is so incredibly tonedeaf: do you honestly think that small hobby-scale websites have a privacy policy?

Yes. because it's a legal requirement when you collect personal data.

Re: Shutting Down Forum (GDPR)

#486
post #17
post #6

Well, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

Are their posts personal data though ?

Re: Shutting Down Forum (GDPR)

#487
post #51
post #17

Earlier quoted context omitted.

If I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.

Yeah that's an interesting question about the line for GDPR and the right to be forgotten. If a user themself posts text onto a forum, I wouldn't consider that private information. If it's not private info, I wouldn't think they should be able to legally request it be deleted. That would be almost like an editor of a wikipedia article asking that it be removed. I wonder how GDPR applies.

Actually text posts can be used to personally identify users, given you have access to enough written words from this person to build a profile of their writing style.

It's been used to track and identify people. IIRC it's also been used in attempts to impersonate people.

So one can argue that text posts are personal data that can be used to identify them, but I suppose this is the kind of thing that is up to the court to decide.

Re: Shutting Down Forum (GDPR)

#488

Earlier quoted context omitted.

Gdpr doesn’t have a clause for voluntary, required or accidental sharing. If a user publishes on your forum he has disabilities, congratulations, under gdpr you just leaked user personal data of the worst kind.

> If a user publishes on your forum he has disabilities, congratulations, under gdpr you just leaked user personal data of the worst kind. I'm really not sure what people think they're gaining from posting these wildly inaccurate GDPR comments.

I agree, the amount of FUD and fearmongering related to GDPR is quite impressive, even here on HN. It seems people who don't like GDPR are trying their best to make it look diabolical as if this would make it go away.

Re: Shutting Down Forum (GDPR)

#489
post #144
post #68

Earlier quoted context omitted.

> But if they then said that I need to remove _all of their posts_, that's really shitty. Why do you think GDPR forces forum owners to delete posts? Which bit of GDPR do you think introduces this requirement?

In order to reply to your questions, the mark would have to study the GDPR one way or the other to answer them. That by itself is way too much hassle.

Well the burden of proof lies on the person who makes the claim. otherwise it's an unsubtantiated claim that can be discarded without evidence.

Re: Shutting Down Forum (GDPR)

#490

I"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the w…

> I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally.

They do have jurisdiction, because the laws apply to companies that want to reach Europeans.

It's up to companies whether they think it's worth the effort to reach this market.

Companies do some crazy stuff on the other end of the spectrum to have a presence in China, right..?

Post reply on HN