This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
Why? It's selective prosecution, plain and simple.
These things have a history of being selectively used to punish institutions for other reasons that are not easy to do using the law
To the people downvoting, imagine the following scenario:
Website promotes ideas the EU finds problematic. The EU wants to silence it but can't because of free-speech laws or any other constraint.
All they have to do is find something trivial under this law and punish them for it, bankrupting the company.
All of these "I hope the law will be applied reasonably" are dangerous because they give the state too much power.
As for IPs. Any website could claim they need IP addresses for analyzing malicious use. So either it'll be a new cookie law in which they all use the vagueness of the new rules to loophole themselves out, or the EU will decide that this is only "reasonable" sometimes. The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
Here's what will really happen to HN - nothing. But Google will get huge fines for doing exactly the same thing, and everyone will be left wondering if they're next.
Which they explicitly choose to do
> some use their real names as their username
Which is not required to use the site
> the site asks for email addresses
But you don't have to give one. If you do give one it is only used for password resets. Write that in your privacy policy and keep the email safe.
> Any website could claim they need IP addresses for analyzing malicious use
Yes they can, and the law allows it. Don't sell them to data aggregators and put it in your privacy policy why you are keeping it. If you don't want to then send the logs to /dev/null
> or the EU will decide
The courts will decide.
> The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
What do you want from the EU? A law that references the internet protocol explicitly, and every possible use of it? What happens when the protocol changes, or someone invents a new protocol, or a new way of exploiting it? Pass another law that says the same thing? Laws in the EU are generally principle based for exactly this reason, they age much better.
> Here's what will really happen to HN - nothing
Because they are doing nothing wrong!