Live data from Hacker News

Shutting Down Forum (GDPR)

discourse.drone.io

521–530 of 534 posts

Re: Shutting Down Forum (GDPR)

#521

Earlier quoted context omitted.

So it looks like having a script to delete all user's data can get you out of trouble with any of these letters.

- Please tell me all the data you have on me * furiously delete all user's data * This is probably gonna get you in much more trouble than you could have been initially. For example France has law telling ISP they have to collect and retain customer data and activities for a year to able to retroactively identify who did what online at what time, failing this is not a matter of a report that could lead to warning and…

The GDPR specifically says you don't have to delete the data if you are legally required to keep it for other reasons. Most often this is financial data, but there are plenty of other examples.

Re: Shutting Down Forum (GDPR)

#522
By the way, what I really love about GDPR is that now I finally can disallow a website to log and analyze my behaviour to provide any kind of "personalisation" they want and still use it. It's just so great they can't say "agree or go away" any more.

I thought it was going to be another stupid thing like a "cookie law" (which, I hope, is going to be canceled now as we''ve got the GDPR), the recent US FOSTA or a "store all my data in my country on a government-certified server with a police backdoor" law but fortunately it absolutely is not.

I really hope non-EU countries are going to clone this law, it seems to be the second (the first being the US net neutrality policy) law I love.

Re: Shutting Down Forum (GDPR)

#523
post #448

Earlier quoted context omitted.

> I have to point out that blablacar is not about solidarity, ecology or social relationships, to the contrary actually, it's about being a vampire draining money from solidarity and ecology and market domination. So you just hate it because it's a company and it's making money. Right ? > I mean carpooling was about solidarity and ecology, then blablacar seized the market and turned it into "no mobile phone, no credi…

I have no problem whatsoever with a company making money. But here we're talking about a single company in a close to monopoly situation and who uses its position to dictate its rules. I think you are misremembering here, when blablacar started and was called covoiturage.fr there were a variety of other carpooling websites, some having been around for several years notably covoiturage.com. At the time carpooling thro…

I had read [1] to [4] (maybe [5]-[6] too, but I don't remember) when they were posted, and I did think at the time that BlaBlaCar was a bad thing. But these are only blog rants, and I shortly changed my mind after that. I perfectly remember the (IMO) shitty UIs all carpooling websites had at the time, and I do remember people being doubtful about it in general. I was too. Now, there's nothing less common than carpooling, and you have to admit it serves ecology well. This is one of the things those blog posts couldn't or didn't see, four years ago.

[7] is a collection of problems people encountered. I had read a few of these long time ago, and re-read them now : these seem to be situations any service linking people together would encounter, and I don't see how any other website could avoid those entirely.

[8] I can't read; [9] is quite general.

> I've been doing carpooling for years and had no issues with cash payment or direct contact with other users, but suddenly blablacar marketed these as undesireable and risky and pretended there was a need to move to less freedom for more security by making them the unavoidable middleman and upfront payment, obviously the need was actually on their side and was about putting them in position to maximize profit.

You are personnalizing BlaBlaCar as a sneaky fox whispering into people's ears, playing on their fears and need for security. BlaBlaCar's position was the result of people's acceptance of their services in free will. You cannot change that. Also, it is very clear in some of your links that BlaBlaCar targeted the conductors (this "critical" mass) with economical incentives in order to bring the market to the next level, which, again, succeeded like nothing had before. I'm not sure destroyed is really what would describe their rise if you take a broader point of view.

> I'm not saying anything about bad practice (good or bad is a relative notion), I'm saying that blablacar destroyed the social component of carpooling to turn it into an economic one.

You are appealing to relativism, and then clearly implying that social and economic components are mutually exclusive, and I'd go as far as to say you also implied which one is evil and which one isn't. I just wanted you to notice that.

Also, it's not because something isn't free that you have to be an ass about it and that it's not social; and the inverse is also true. That's not something very common in France, but you can actually charge people and, at the same time, give them a good social experience.

> That blablacar put artificial barrier preventing people who need carpooling the most (people who cannot afford a smartphone or a credit card) from having access to it.

There are no people who need carpooling the most. Everyone needs to travel around for cheap money. It kinda feels like virtue signaling from your part to imply that you think about the poorest users, as if the person talking to you wasn't.

Also, this is quite untrue. On Leboncoin you will find older or used smarpthones from 10 euros, to 100 if you want fancy ones, while the cheapest phone plans, including internet, start at 2 or 3 euros a month. This extends worldwide with 3 billion smarpthone users in the world [1]. The magic of capitalism...

Technically speaking, to counter BlaBlaCar's existing monopoly on carpooling users, you'd have to create an open-sourced meta-platform for carpooling where people can register, and choose to use either BlaBlaCar as a middleman (that's what they do best), or not, or any other company or system that has been built to do just that. Over time, you would acquire an open database of carpooling users, which would serve for the greater good. This, and only this, improves free choice and resources efficiency, without the abuse that might come from a centralized platform such as BlaBlaCar. In my opinion, destroying or hating the business that built this carpooling community (I'm sure you did your best, but realistically it didn't exist before) doesn't. I also don't think you should go so far as to despise the CEO specifically: it seems far-stretched to me, mixing your feelings with a rational situation. And I don't think it brings you any good.

Anyway, if you're ready to do the open-source meta-carpooling part, I'm interested.

[1] https://www.statista.com/statistics/330695/number-of-smartph...

Re: Shutting Down Forum (GDPR)

#524
post #514

Earlier quoted context omitted.

I assume you live in a country without free medical care? I don’t.

I live in a country with tax funded healthcare.

That's another way of saying the same thing. Taxing bad behaviour pays for their healthcare then.

Re: Shutting Down Forum (GDPR)

#526

Could/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored…

Note that I am not a lawyer and this isn't legal advice, if that wasn't extremely obvious from my language. Not that the EU can get me!

Re: Shutting Down Forum (GDPR)

#527
post #109

Earlier quoted context omitted.

If you aren't in the Union, it applies to you if either [1]: (a) you are processing data of data subjects who are in the union related to the offering of goods or services to such data subjects, or (b) you are processing data of data subjects who are in the union related to monitoring of their behavior as far as their behavior takes place within the Union. If you can avoid both of these, then I believe you can pretty…

geoip based blocking is wrong. An American customer can be travelling in Europe and be blocked while any EU citizen can use a proxy or VPN to workaround your geoip block. If you can live with infuriating a small portion of your customers while have a protection that can be circumvented in a matter of seconds then geoip block is what you want, otherwise ...

As wan23 already noted, the purpose of the geoip block is to help establish that you are not offering goods or services to data subjects in the Union, in order to not fall under GDPR territorial jurisdiction (see Article 3).

Yes, that will also catch some of your existing US customers when they travel to Europe. However, you may actually want that, because the GDPR does not talk about EU citizens. It talks about data subjects "in the Union".

I haven't seen anything about what makes someone who is physically present in the EU count as being "in the Union" for GDPR purposes. One who wants to be cautious might want to count anyone physically in the EU as being "in the Union" for GDPR purposes until there is definitive guidance otherwise.

Re: Shutting Down Forum (GDPR)

#528
post #378
post #375

Earlier quoted context omitted.

Then just put that in your privacy policy and you are off the hook. If Google tracks something, whether it is via their fonts, by putting some cookie on your site or whatever, it is their problem (and they actually said so, in that Github post referring to the font issue). They are the ones collecting and processing the data, not you, so they will have to deal with the GDPR compliance.

That's their interpretation, and they don't face consequences if it's wrong. Since I've gotten advice to the contrary from lawyers looking into GDPR, I won't trust it until there's clear feedback from regulators or courts about it. Fonts are easy enough to self-host.

How they "don't face consequences" if it is wrong?! Google (along with Facebook) are very much going to be the first in the line for auditing - and I believe the first complaints against them have been filled on the first day GDPR was in force already. The entire raison d'etre of GDPR is very much Google and Facebook, who were thumbing their noses at EU's privacy regulations so far.

If someone is going to have top-notch legal team on this it is going to be Google. So if Google's legal says that it is alright because they are the data processor/controller as defined by GDPR you can pretty much take them for the word there.

I wonder whether people spreading this sort of panicked disinformation about the fonts and what not have actually read the GDPR text. It is pretty clear about who is considered to be a "data processor" or "controller" - someone who merely uses a resource like fonts is certainly not one if you aren't collecting any information yourself or having someone else do it on your behalf. That Google may be doing it is irrelevant as long as they aren't providing the data to you (which would make you a "data controller").

And if you are neither a data controller nor data processor you aren't concerned by GDPR at all.

It is well explained here: https://www.gdpreu.org/the-regulation/key-concepts/data-cont...

Re: Shutting Down Forum (GDPR)

#529
post #374

Earlier quoted context omitted.

Yeah from what I have heard the main reason for this law is to stop obvious abuses to people's privacy. It seems that most overreactions are due to ignorance of the system behind the law or to make some kind of political statement.

As a proponent of North American small businesses to just stop doing business with the EU my motivation doesn't stem from the ignorance of the system rather the knowledge if it: the fines will be issued by the relevant authorities of each and every EU state according to their own interpretation. Certain countries might see this as a neat little cash grab opportunity.

I just don't see the EU giving fines to American small businesses. What kind of money could they expect to get out of them? I'm curious though, what EU countries do you think are so desperate for money that they would basically extort American small businesses?

Re: Shutting Down Forum (GDPR)

#530

Earlier quoted context omitted.

I'm not in the EU but must comply to their regulation. The internet at it's base abstraction is a borderless medium without regard to locality. Imposing legislation by user region is a dangerous precedent as each region can now impose fee-seeking legislation on internet companies.

So what do you propose no laws at all for the internet? Or each jurisdiction makes orts own law? In which case would the US mind getting the hell back inside it's borders and stop trying to extradite British teenagers who alledgedly broke some 'hacking' law? Sounds like Team America again. The government's of the world are struggling with internet jurisdiction issues, currently the US is taking the stance that any ac…

Any solutions should come from first level engineering principles not lawyers and politicians. I don't care if it's US prosecuting a kid for hacking, companies storing and losing information on people or a space shuttle exploding. The problem lies in the failure of software and the solution should be in software.
Post reply on HN