Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

71–80 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#71
post #17
post #4

Earlier quoted context omitted.

"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.

Actually he was lucky. Austrian law says the fine should be €10,000. It is not legal to own or to use a dashcam in Austria, like in a few other European countries

It's good to be reminded of how many backwards laws there are in the world. Every country is a little bit fascist and insane and it makes you appreciate the good parts of your own country.

Re: GDPR Enforcement Tracker: List of GDPR fines

#72
post #37

Earlier quoted context omitted.

Everybody can stalk you if they don't like what you've published for example.

That comes with the territory of online ownership. If you want anonymity then pay someone else to host your data.

"Host it somewhere else" doesn't make German citizens somehow immune to German law and their "imprint" requirement.

Re: GDPR Enforcement Tracker: List of GDPR fines

#74

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

It should have been more.The idiots who do this deserve it. My fiancé's ex employeer used to send emails cc'ing contractors that haven't even seen each other.I've seen some small scale companies even try to send marketing emails to their small list of clients..

Re: GDPR Enforcement Tracker: List of GDPR fines

#75
post #16
post #2

The fact that someone was fined for using a dashcam is beyond absurd.

I wonder where the line is drawn when it comes to things like that. Yesterday I was walking on the side of the road and some girl was half way hanging out of the passenger window recording a video of the scenery. I was able to see her from a few hundred feet away. Eventually the car intersected with me and I was in the line of sight of the video for a second or 2. Of course I made a stupid pose to photo bomb her vide…

As far as i understand this doesn't fall under GDPR unless the video is published because of personal use. If she publishes the video, you have the right to ask her to take it down/remove your PII from the video. But there might be additional local privacy laws that change things and GDPR has nothing to do with it.

Re: GDPR Enforcement Tracker: List of GDPR fines

#76
post #58

Earlier quoted context omitted.

I support this fine in principle. Maybe not the magnitude, maybe not without a warning, and of course a three liner isn't enough context to be sure. But using CC instead of BCC causes a massive leak of personal information, especially when either the subject being discussed or the people on the list are sensitive. In my life this has mostly been annoyance at large org stuff, but my wife has had this happen with a sen…

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…

That's absurd. Talking purely about the UK right now: there were tens of thousands of cases logged with ICO since GDPR came into power. So far,there were only a handful of companies that had to pay fines and their actions were either borderline criminal,or deliberate refusal to cooperate with ICO.

Re: GDPR Enforcement Tracker: List of GDPR fines

#77
If you look back at comments as GDPR was first coming into effect, you saw a lot of comments here along the lines of 'The EU doesn't want to fine anyone. They want you to become compliant, and will help you do so, and you won't be fined unless you were intentionally being non-compliant'

But then look at this example from Germany:

> Please note: According to our information this fine has been withdrawn in the meantime. Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to deal with a service provider who does not want to sign a processing agreement. After not answering Kolibri Image in more detail, the case was forwarded to the locally responsible Data Protection Authority of Hamburg. This Auhtority then fined Kolibri Image as controller for not having a processing agreement with the service provider. Kolibri Image has stated that they will challenge the decision in front of court since they are of the opinion that the service provider does not act as a processor.

The company emailed the authority asking for advice on how to deal with a service provider who didn't want to cooperate with GDPR, then the authority ignored his request, forwarded their information to another authority, which then fined them for the exact thing which they was asking for advice on.

Yes, the fine has apparently been withdrawn, but how much time, money, and mental capacity did Kolibri Image have to spend dealing with this before the authority decided to drop it?

Re: GDPR Enforcement Tracker: List of GDPR fines

#78
250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user's microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I'm a little bit surprised that the fine is this low:

"The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent."

Re: GDPR Enforcement Tracker: List of GDPR fines

#79
post #23

Earlier quoted context omitted.

On public streets, yeah, that's kind of insane. It's pretty common for people to have a dashcam running with a buffer so if you're involved in a not at fault accident or someone vandalizes your car, or such things, you have documentation.

Of course, that's why it says "illegally". Those dashcams can be installed legally, and this guy's wasn't legally installed.

Where is info on how to install it legally and why this stupid ban on dashcams when GDPR actually allows it (it made dashcam usage easier in my home country as now you don't have to register as data processor because dashcams fall under surveillance). I feel that this is a bad thing - you have a regulation that covers all EU but some countries have their specific laws overriding it and banning things that are allowed under GDPR.

Re: GDPR Enforcement Tracker: List of GDPR fines

#80

It's interesting how enforcement changes between countries. For instance, all the fines in Austria where for CCTV and dashcam use, all of France's fines were against large corporations, and the single fine Italy imposed was on the "Movimento 5 Stelle" political party.

I mean, that is the coalition partner in government right now, so it's a big deal...
Post reply on HN