Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

61–70 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#61

Earlier quoted context omitted.

In the UK, the data regulator fined a small organisation £180,000 ($230,000) for exactly the same mistake on a list with 781 recipients. The organisation was a specialist sexual health clinic and the newsletter was for patients with HIV. Without knowing the details, I can't say whether a €2000 fine was disproportionately onerous or a slap on the wrist. https://www.businessinsider.com/nhs-trust-fined-for-leaking-...

HN tangent: This is a great example of where the oft touted wildcards on a personal domain fall short: if you’re on that list, you’re outed. Even without your name on it; only you use that domain. This is where Outlook with their *@outlook.com and apple’s new system really do shine. Commiserations to those affected :(

Wildcards are a measure to track what others are (automatically) doing with your email address, provide a way to remove yourself from shared lists of bad actors, and sign up to something a dozen times. What they don't do is provide privacy against human eyes.

Re: GDPR Enforcement Tracker: List of GDPR fines

#62

Weird there's no fines in UK.

The Information Commissioner's Office maintains a list of the UK fines.

> The ICO has specific responsibilities set out in the Data Protection Act 2018, the General Data Protection Regulation (GDPR), the Freedom of Information Act 2000, Environmental Information Regulations 2004 and Privacy and Electronic Communications Regulations 2003.

https://ico.org.uk/action-weve-taken/enforcement/?facet_type...

https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...

Re: GDPR Enforcement Tracker: List of GDPR fines

#63

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

The list has over 1600 recipients making it a bit larger than for "personal use". The quoted 187 recipients might just be one batch of recipients the examined mail was sent to.

The sender is also non-repentant and is running some sort of hate campaign.

Re: GDPR Enforcement Tracker: List of GDPR fines

#64
Why are there so many violators marked as "unknown"? Is that from the sanction being redacted or the aggregator's lack of information? The header paragraph states that not all violations are made public, but the ones that are made public can also be redacted?

Re: GDPR Enforcement Tracker: List of GDPR fines

#65
post #16
post #2

The fact that someone was fined for using a dashcam is beyond absurd.

I wonder where the line is drawn when it comes to things like that. Yesterday I was walking on the side of the road and some girl was half way hanging out of the passenger window recording a video of the scenery. I was able to see her from a few hundred feet away. Eventually the car intersected with me and I was in the line of sight of the video for a second or 2. Of course I made a stupid pose to photo bomb her vide…

This can vary between jurisdictions but in all jurisdictions i know, photographing someone in a public location is always legal and never requires consent. Whether publishing requires consent varies, in the normal case it does for commercial but not for journalistic purposes.

Note that laws written this way usually distinguish “taking photos” from “surveillance” - so mounting the camera on a street corner immediately changes the legal context. This may be why dash cams fall into the surveillance category in some places.

Re: GDPR Enforcement Tracker: List of GDPR fines

#67
post #48

Earlier quoted context omitted.

The thing is if this was a civil case you have to prove some damages had be done by the leak. A random person leaking my email in CC - that happens a lot - is not even necessarily annoying but for sure don't cause any damages.

Whether there are damages depends on the context. In 2015 an HIV clinic in London used the to: field instead of bcc: on a patient newsletter, thus exposing the names of 700 patients, many of whom knew each other due to the small geographic area being served ( https://www.theguardian.com/technology/2016/may/09/london-hi... ). They were fined GBP180K (under the pre-gdpr regime, incidentally, so this isn't a new risk fo…

I think that is why my hospital network uses an online patient account for any messages instead of email. Easy to screw up this stuff if using email.

Re: GDPR Enforcement Tracker: List of GDPR fines

#68
post #32
post #17

Earlier quoted context omitted.

Actually he was lucky. Austrian law says the fine should be €10,000. It is not legal to own or to use a dashcam in Austria, like in a few other European countries

Not true. You can have a dash cam, but it has to be the kind that continuously overwrites its own data and only records when it detects an accident. You can also record based on your intent - if your intent is to, say, capture a scenic drive ,then you can do that. If your intent is to just capture the license plates of 1000s of other cars that pass you, you can't do that. These laws were changed in ~2018 in Austria.

How can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?

Re: GDPR Enforcement Tracker: List of GDPR fines

#69
post #68
post #32

Earlier quoted context omitted.

Not true. You can have a dash cam, but it has to be the kind that continuously overwrites its own data and only records when it detects an accident. You can also record based on your intent - if your intent is to, say, capture a scenic drive ,then you can do that. If your intent is to just capture the license plates of 1000s of other cars that pass you, you can't do that. These laws were changed in ~2018 in Austria.

How can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?

No, they are allowed to have a buffer of last X minutes.

Re: GDPR Enforcement Tracker: List of GDPR fines

#70
post #59

Earlier quoted context omitted.

The same link mentions issuing a GDPR reprimand against a person for using a security camera inside their own home .

Recording in one's own home is exempted under the GDPR[0]. I suspect something broader was involved here. [0] Article 2(2): "This Regulation does not apply to the processing of personal data [...] by a natural person in the course of a purely personal or household activity"

A prime example where GDPR would apply to a security camera in your own house would be if that camera was used to record renters (including short term rentals e.g. AirBnB) without their knowledge.

For example, I recall reading about cases of renters finding out that the landlord has installed hidden cameras in the bedrooms and showers.

Post reply on HN