Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

91–100 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#92
post #89

Earlier quoted context omitted.

Except we see just the fine. We have no idea how many attempts and warnings to get them to comply were sent first. It wasn't one email, it was multiple emails, multiple times over months. This site makes no mention of warnings and escalations, and ICO at least doesn't normally announce that for individual cases. Though they do put out aggregate stats. When they have fines are clearly shown as arising in a small minor…

> We have no idea how many attempts and warnings to get them to comply were sent first. True. But I doubt that even the most ruthlessly efficient GDPR enforcement authority could multiple enforcement requests between mid July and end July.

Sure, but offences between July and September 2018, and convicted Feb 2019 only against the small sub selection in July.

There's potential time for quite a few ignored warnings before prosecution, but I don't know and can't find out from here if or if not.

Re: GDPR Enforcement Tracker: List of GDPR fines

#93

[flagged]

It does not explicitly require warnings, but Art. 83 (https://gdpr-info.eu/art-83-gdpr/) requires that the authority, when deciding whether to impose a fine, takes into account a number of things. It would be hard to argue for an instant fine if the things listed in the article were favorable in a specific case.

Re: GDPR Enforcement Tracker: List of GDPR fines

#94
post #58

Earlier quoted context omitted.

I support this fine in principle. Maybe not the magnitude, maybe not without a warning, and of course a three liner isn't enough context to be sure. But using CC instead of BCC causes a massive leak of personal information, especially when either the subject being discussed or the people on the list are sensitive. In my life this has mostly been annoyance at large org stuff, but my wife has had this happen with a sen…

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…

> unless you're sure you that can afford making these kinds of mistakes, don't provide a service on the internet

DOT

sounds good

Re: GDPR Enforcement Tracker: List of GDPR fines

#95

It's interesting how enforcement changes between countries. For instance, all the fines in Austria where for CCTV and dashcam use, all of France's fines were against large corporations, and the single fine Italy imposed was on the "Movimento 5 Stelle" political party.

  all of France's fines were against large corporations
When determining the amount of the fine, the CNIL took into account the size (9 employees) and the financial situation of the company.

Re: GDPR Enforcement Tracker: List of GDPR fines

#96
post #71
post #17

Earlier quoted context omitted.

Actually he was lucky. Austrian law says the fine should be €10,000. It is not legal to own or to use a dashcam in Austria, like in a few other European countries

It's good to be reminded of how many backwards laws there are in the world. Every country is a little bit fascist and insane and it makes you appreciate the good parts of your own country.

Until you realize the "receiving end" of that: It also means that in those "fascist" countries, you have a right not to be filmed, even in public.

Re: GDPR Enforcement Tracker: List of GDPR fines

#97
post #7

Earlier quoted context omitted.

What's insane, the fact that you can't just go around recording people and cars?

On public streets, yeah, that's kind of insane. It's pretty common for people to have a dashcam running with a buffer so if you're involved in a not at fault accident or someone vandalizes your car, or such things, you have documentation.

Some societies think that tracking people on public spaces isn't acceptable either. I don't know why it would be insane - if anything, losing all privacy because you stepped out of the house is the insane thing.

Re: GDPR Enforcement Tracker: List of GDPR fines

#98

Earlier quoted context omitted.

HN tangent: This is a great example of where the oft touted wildcards on a personal domain fall short: if you’re on that list, you’re outed. Even without your name on it; only you use that domain. This is where Outlook with their *@outlook.com and apple’s new system really do shine. Commiserations to those affected :(

Wildcards are a measure to track what others are (automatically) doing with your email address, provide a way to remove yourself from shared lists of bad actors, and sign up to something a dozen times. What they don't do is provide privacy against human eyes.

I've been wondering how this sort of email management strategy is going to handle the rules certain countries are bringing in now where if you want to go there then you have to provide a list of all of your email addresses and social media accounts. Has anyone run into that problem yet?

Re: GDPR Enforcement Tracker: List of GDPR fines

#99
post #94
post #58

Earlier quoted context omitted.

Last year, when GDPR was heavily discussed, people were criticizing those who decided to just stop their small hobby websites because of the potential GDPR exposure. The argument back then was that they were overreacting, that we didn't understand how Europe works, that you'd only get fined after repeated warnings about violating procedures etc. I'm sure the private person was dumb for doing what he did, but that doe…

> unless you're sure you that can afford making these kinds of mistakes, don't provide a service on the internet DOT sounds good

Everybody makes mistakes. Which makes GDPR a recipe to hand over whatever remains of the Internet to only corporations that afford paying for them.

Re: GDPR Enforcement Tracker: List of GDPR fines

#100

Wow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offen…

If it's the case I've seen [1], it wasn't someone sending a little mailing list newsletter to people who have opted in, it was someone sending complaints and CC'ing everyone they could get an e-mail address of. The article I saw also makes it sound very much like he was told to stop repeatedly.

Seems like an appropriate fine. Or do you think I should be allowed to collect 150 e-mail addresses, then e-mail them out to all 150 other people, after some of them told me not to do that?

[1] https://www.rosepartner.de/blog/bussgeld-fuer-offenen-e-mail...

Post reply on HN