Earlier quoted context omitted.
Not true. You can have a dash cam, but it has to be the kind that continuously overwrites its own data and only records when it detects an accident. You can also record based on your intent - if your intent is to, say, capture a scenic drive ,then you can do that. If your intent is to just capture the license plates of 1000s of other cars that pass you, you can't do that. These laws were changed in ~2018 in Austria.
How can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?
GDPR Enforcement Tracker: List of GDPR fines
81–90 of 301 posts
Re: GDPR Enforcement Tracker: List of GDPR fines
#82Re: GDPR Enforcement Tracker: List of GDPR fines
#83Earlier quoted context omitted.
Different take: This is exactly what GDPR was designed for. It just hasn't been "weaponized" enough yet to have the bandwidth to deal with every situation, so situations like these seem like targeted attacks when in reality they're precisely what GDPR is supposed to deal with. I personally think ~$15 per leaked email is a reasonable fine. I bet this guy and everyone else who reads this article won't accidentally leak…
The thing is if this was a civil case you have to prove some damages had be done by the leak. A random person leaking my email in CC - that happens a lot - is not even necessarily annoying but for sure don't cause any damages.
In fact, I'd argue that leaking an email that exposes a private association with a mailing list to other unknown people has much clearer potential for damage than any of the privacy issues that big companies get fined for. And yes, CC leaks do happen (not a lot, in my experience), but I'm personally upset about it every time - much more so than when I find out Google didn't get my consent before recording half of my internet activity. Just because the violation is something that "happens a lot" because it can be done by accident by a careless individual doesn't mean it's less serious.
Re: GDPR Enforcement Tracker: List of GDPR fines
#84Earlier quoted context omitted.
I support this fine in principle. Maybe not the magnitude, maybe not without a warning, and of course a three liner isn't enough context to be sure. But using CC instead of BCC causes a massive leak of personal information, especially when either the subject being discussed or the people on the list are sensitive. In my life this has mostly been annoyance at large org stuff, but my wife has had this happen with a sen…
Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…
This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minority of cases.
Re: GDPR Enforcement Tracker: List of GDPR fines
#85If you look back at comments as GDPR was first coming into effect, you saw a lot of comments here along the lines of 'The EU doesn't want to fine anyone. They want you to become compliant, and will help you do so, and you won't be fined unless you were intentionally being non-compliant' But then look at this example from Germany: > Please note: According to our information this fine has been withdrawn in the meantime…
Re: GDPR Enforcement Tracker: List of GDPR fines
#86Earlier quoted context omitted.
"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.
What's insane, the fact that you can't just go around recording people and cars?
Re: GDPR Enforcement Tracker: List of GDPR fines
#87The ICO maintains an official list of fines in the UK https://ico.org.uk/action-weve-taken/enforcement/?facet_type...
The Uber one is odd, US fined Uber $148m, the UK fined them £385,000.
Re: GDPR Enforcement Tracker: List of GDPR fines
#88Does enforcement changes behavior? I guess the time will tell. But I do expect some insurance companies start selling GDPR coverage policies soon.
Re: GDPR Enforcement Tracker: List of GDPR fines
#89Earlier quoted context omitted.
Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…
Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…
True. But I doubt that even the most ruthlessly efficient GDPR enforcement authority could multiple enforcement requests between mid July and end July.
Re: GDPR Enforcement Tracker: List of GDPR fines
#90If you look back at comments as GDPR was first coming into effect, you saw a lot of comments here along the lines of 'The EU doesn't want to fine anyone. They want you to become compliant, and will help you do so, and you won't be fined unless you were intentionally being non-compliant' But then look at this example from Germany: > Please note: According to our information this fine has been withdrawn in the meantime…
I'm not actually that sympathetic. If you have a processor that does not want to sign a processing agreement, you have to stop using them. There is no leeway on this issue in GDPR. You are responsible for ensuring that third party processors you engage agree to handle the data lawfully. There's not a lot of context to go on, but it seems to me that the company in question is just stalling. I literally can't think of…