Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

51–60 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#51
post #10

Germany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.

Not any website. If it is purely private and non-commercial you don't have to. Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be yo…

Your name is more than enough to track you down if you live in a town. A PO box won't help you.

Re: GDPR Enforcement Tracker: List of GDPR fines

#52
post #11

Perhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's stil…

Except that of course it wasn't about "using Cc instead of Bcc in emails" but using CC instead of BCC in mailing lists with hundreds of recipients and also not about "using a dashcam" but using a dashcam illegally, which in itself can imply a much higher fine in some European countries regardless of GDPR. So not as benign as you are trying to make it sound.

I honestly don't see how "using a dashcam illegally" is such a big deal, nor how "hundreds of recipients" on an email are a big deal. The email list seemed to be just rants.

I wish they would tell what the harm of both of those actually was.

Re: GDPR Enforcement Tracker: List of GDPR fines

#53

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

HN tangent: This is a great example of where the oft touted wildcards on a personal domain fall short: if you’re on that list, you’re outed. Even without your name on it; only you use that domain.

This is where Outlook with their *@outlook.com and apple’s new system really do shine.

Commiserations to those affected :(

Re: GDPR Enforcement Tracker: List of GDPR fines

#54
post #52

Earlier quoted context omitted.

Except that of course it wasn't about "using Cc instead of Bcc in emails" but using CC instead of BCC in mailing lists with hundreds of recipients and also not about "using a dashcam" but using a dashcam illegally, which in itself can imply a much higher fine in some European countries regardless of GDPR. So not as benign as you are trying to make it sound.

I honestly don't see how "using a dashcam illegally" is such a big deal, nor how "hundreds of recipients" on an email are a big deal. The email list seemed to be just rants. I wish they would tell what the harm of both of those actually was.

Traffic tickets don't require harm to be actually done either. It's potentially the same kind of thing, at least for the dashcam case.

Re: GDPR Enforcement Tracker: List of GDPR fines

#55
post #54
post #52

Earlier quoted context omitted.

I honestly don't see how "using a dashcam illegally" is such a big deal, nor how "hundreds of recipients" on an email are a big deal. The email list seemed to be just rants. I wish they would tell what the harm of both of those actually was.

Traffic tickets don't require harm to be actually done either. It's potentially the same kind of thing, at least for the dashcam case.

But shouldn't the fine then be using the dashcam law and not GDPR?

Re: GDPR Enforcement Tracker: List of GDPR fines

#56

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

It's worth noting that that fine was made under the Data Protection Act 1998 (implementing the Data Protection Directive), which is what was in force before the GDPR became law.

The ICO might well consider a similar breach worthy of a bigger fine now.

Re: GDPR Enforcement Tracker: List of GDPR fines

#57
post #55
post #54

Earlier quoted context omitted.

Traffic tickets don't require harm to be actually done either. It's potentially the same kind of thing, at least for the dashcam case.

But shouldn't the fine then be using the dashcam law and not GDPR?

The analogy was that GDPR fines, similar to other administrative fines (which was the term that had escaped me) like traffic tickets, do not require damage to be shown (although it plays a role in setting the amount of the fine) - unlike e.g. cases pressing for damages, brought by a wronged party, would be.

The law regarding dash cams (if there is an explicit one, I don't know enough about the situation in Austria) might just declare it a privacy violation, and thus defer to the enforcement mechanisms created by GDPR.

Re: GDPR Enforcement Tracker: List of GDPR fines

#58

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

I support this fine in principle. Maybe not the magnitude, maybe not without a warning, and of course a three liner isn't enough context to be sure. But using CC instead of BCC causes a massive leak of personal information, especially when either the subject being discussed or the people on the list are sensitive. In my life this has mostly been annoyance at large org stuff, but my wife has had this happen with a sen…

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure.

The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc.

I'm sure the private person was dumb for doing what he did, but that doesn't invalidate the general point: unless you're sure you that can afford making these kinds of mistakes, don't provide a service on the internet that might be used by EU citizens.

The benefits, whatever they might be, just don't justify the risks.

Re: GDPR Enforcement Tracker: List of GDPR fines

#59
post #4

Earlier quoted context omitted.

"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.

The same link mentions issuing a GDPR reprimand against a person for using a security camera inside their own home .

Recording in one's own home is exempted under the GDPR[0].

I suspect something broader was involved here.

[0] Article 2(2): "This Regulation does not apply to the processing of personal data [...] by a natural person in the course of a purely personal or household activity"

Re: GDPR Enforcement Tracker: List of GDPR fines

#60
post #39

The ICO maintains an official list of fines in the UK https://ico.org.uk/action-weve-taken/enforcement/?facet_type...

Notably none of these are (yet) for violations of the GDPR. The ICO has issued enforcement notices, but they haven't levied any penalties so far.
Post reply on HN