GDPR Hall of Shame
gdprhallofshame.com
gdprhallofshame.com
For me, this is a refutation of the "If you don't pay for the product, you are the product." There is no inherent reason why a company would only do that for a free product. If it works for free products, it works just the same for paid products.
Even if GDPR has flaws, and is gonna cause some disruption, I think we really needed something like this.
You have to specifically seek out products where your privacy and data is taken seriously. This can happen for both free (open source?) and paid products.
Of course, that assumes competition is effective, which requires consumers to be informed that it's even a potential issue, to care, and to be able to assess which company is better or worse.
See my other comment for more detail:
Firstly if the company is established in the union then they need to be compliant for all their users no matter where they are [1] (so US resident, EU resident, whatever are equally protected).
So the relevant section for this is:
"This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
the monitoring of their behaviour as far as their behaviour takes place within the Union."
So lets look at Amazon. They are a US company offering goods in the EU. So if you make a purchase from them as an EU resident (living in Germany) from amazon.de to your home address, then any personal data you give them as part of that purchase needs to be handled in a GDPR compliant way.
If you now go on holiday to the US and order something from Amazon.com to be delivered to your hotel, even though you are an EU resident, they do not need to handle that personal data in a GDPR compliant way. But just because you are now in the US doesn't mean the data they hold on you about your purchase on amazon.de is suddenly free from GDPR protections.
Or to put it another way. Imagine the law did mean EU resident. What does Amazon.com do? How do they ensure they process an order in the US to a US address in a GDPR compliant way for an EU resident? They can't without asking for additional data to establish each persons residency. Which GDPR doesn't allow.
The easiest way to announce to the world that I do not “envisage” servicing EU customers is to block EU customers. If one happens to use a VPN or otherwise evades this block, it doesn’t matter. I’ve met the clear definitions under Recital 23 and you have no legal right to GDPR protections on my site.
Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.
Also it stops a whole legal and compliance industry appearing in the grey zone as no one wants to abstract liability.
I'm not so sure. No-one knows where the line is, so many organisations can only be sure they're staying well clear by stopping all kinds of legitimate, reasonable data processing, which is throwing the baby out with the bathwater. An alternative, which I've seen quite a few small organisations and individuals adopting and now a few larger ones as well, is to just cut the EU off entirely if they're based outside and thus put themselves outside the scope of the GDPR for practical purposes, and then carry on as before under more liberal regimes like the US. Both of these strategies are harmful without really helping anyone.
So there is no valuable baby that could be thrown out with the bathwater, and a well-behaved company has little or no bathwater to begin with.
No, it isn't. Sorry, you can't just hand-wave the whole issue away that easily. If this were all so obvious, we wouldn't keep having these conversations, where even people who have been looking into this for months and taken real legal advice are still in doubt about what specific actions they can or must take to be compliant.
You are simply being forced to behave like you should have been behaving from the beginning of your online presence.
You could be describing a very large proportion of laws.
To pick a random example, I'll go with the Road Traffic Act 1991 (England and Wales).
It is an offence under this act to drive a mechanically propelled vehicle dangerously on a public road. The definition of dangerous driving is: a) the way he drives falls far below what would be expected of a competent and careful driver, and b) it would be obvious to a competent and careful driver that driving in that way would be dangerous.
That's it. Are you driving like an absolute dick? Is it obvious that you're driving like an absolute dick? If so, you're committing an offence. We have lots of other, more specific motoring laws, but you can be convicted and sentenced based on those two subjective factors. We have lots of case law and guidelines, but the matter of whether your driving definitively is or isn't dangerous can only be decided in court.
https://www.legislation.gov.uk/ukpga/1991/40/part/I/crosshea...
The broad nature of GDPR is a feature, not a bug. Nothing about the way it is worded is particularly new or unusual. Large sections are cribbed from the Data Protection Directive, which came into force in 1995.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
"The Right to Withdraw Consent. If you would like to opt-out at any time, please delete the “gdpr_consent_1” cookie from your browser window. You will have to opt-in again in order to view Slate content."
Thinking of it, adding cookies manually and maintaining a cookie whitelist could be a useful browser feature in the coming years. Most cookie-based tracking would be forced to disappear.
Ten minutes later I've got a user style set up and I'm quite happy with the plain version. But it's still a petty response from the organisation and shows that they don't feel they need to spend any time at all trying to help users control their own data.
Which made me curious: could a service exist where citizens not covered by GDPR submit complaints, so that a GDPR-covered citizen could put the complaint in formally?
[1] Hidden opt-out is non-compliant, but Yahoo! went ahead and opted you in to a hundred different ad services automatically: http://gdprhallofshame.com/content/images/2018/05/ouch.jpg
I mean, if you already have a android phone, NEST and use google everyday, would you want to delete your account? You can live without facebook, but google makes a lot of hardware that is quite useful.
Let see how it all ends :D
If the idea is that no one should be able to avoid complying with the GDPR, even if they decide they no longer want to do business with whomever it is exactly that's covered by it, then maybe the whole thing was a bad tradeoff. I'll grant that Google and Facebook might be acting in bad faith – hell, I'll just assume they are – but surely, for some not-necessarily-insignificant number of other entities, it should be perfectly fine if they decide that the costs of compliance exceed the corresponding benefits.
I don't see any obvious reason why it would be. Yahoo! is being transparent about their data sub-processors, and letting you control how and with whom your data is shared. That's what GDPR says on the tin.
If there's an argument to be made, it's around the Principle of Data Minimization. But that's one of those subjective things. And, considering the size and scope of Yahoo!, it's not inconceivable they have legitimate (scare-quotes optional) uses for all those sub-processors.
If the legal basis is Consent, then you are correct, it must be opt-in rather than opt-out.
They either made it much worse after the author did the screenshots, or it was already extremely bad --that I could not find the link to open up that huge list of third parties.
I clicked on all the links I could find in that screen except for that huge 'I Agree' button.
The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.
Yes it does.
> I'd be surprised there are any internet-connected products that don't process personal data in some way.
Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows:
"Processing shall be lawful if... processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child."
https://gdpr-info.eu/art-6-gdpr/
Recital 49 goes on to state:
"The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems."
Logging IPs for a reasonable period of time as part of your network security infrastructure is perfectly permissible under GDPR without consent. You can share your server logs with a third-party security company or pass data to a DDoS protection service if needed. If you use those IPs for any other purpose (ad tracking, analytics etc) then you'll need lawful grounds for those activities, which may or may not require consent.
However, in many (most?) cases that cannot possibly be sufficient to comply, so we're seeing how the legal people have done as much as they could to cover their arses, given that the actual behavior of the company around them wasn't allowed to change.
It also may be that some companies are intentionally planning a delaying tactic - i.e. a plan to flip the switch on private data processing only when the regulators will get to them and start writing stern letters, so that they can reap the benefits of (ab)using user data for some more months.
Large companies that substantially profit from personal data are testing the boundaries of GDPR. They've got competent legal advice and know that a blatant effort would earn the wrath of the regulators, so they're being subtle about it. They're creatively interpreting grey areas. They're using complex and confusing opt-outs justified by spurious technical issues. They're carefully planning a strategy that will allow them to drag out the enforcement process and gain as much ground as possible, while maintaining the pretence that they're making a good-faith effort to comply. They'd rather avoid a heavy fine, but they're not afraid of butting heads with the regulators.
A lot of small companies without in-house counsel are going a bit crazy. Maybe they've spoken to a data protection consultant who has fed them a bunch of FUD, maybe they've just read a few articles in the press, but they haven't really scrutinised the text of the GDPR or spoken to a regulatory authority. They don't understand what their obligations are under the GDPR or the overarching principles of data protection, but they're doing something. Sometimes that thing is completely overzealous, sometimes it's totally inadequate. I've seen a lot of misguided efforts by SMEs to indemnify themselves against GDPR, akin to the "no copyright intended" statements you see in YouTube descriptions. Many of these companies had been completely ignoring the old Data Protection Directive, so they've got a lot of catching up to do.
If I used Instapaper I'd be filing a complaint with my local DPA about this.
No, it can something as simple as "we cannot guarantee that all your data is deleted with our current storage system". It would be a lot better if people stop being so alarmist.
The fact of not giving an explanation implies that the real explanation is worse that you would expect.
So if it was just that, they wouldn’t shut down.
Indeed. It's odd looking at discussions about the GDPR on HN.
On the one hand, we have people who argue that compliance isn't really that big a deal if you're not doing anything horribly wrong, most ethical businesses would already be mostly compliant anyway, etc.
On the other hand, we have people who argue that even if that is the case, the length and ambiguity of the regulations and guidance combined with the potential penalties still cause significant overheads and risks, particularly for smaller businesses without dedicated resources to deal with compliance matters.
There is some truth behind both of those positions, I think.
But then I've seen so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped. A noticeable number of people are advocating obviously vexatious use of the new subject rights, not in response to any specific concern or after some unsatisfactory attempt to resolve concerns reasonably, but as a weapon with the clear goal of causing maximum disruption and cost to organisations. I wonder how anyone can think giving so much "legal ammunition" to these people is a good idea.
> so many comments now on HN and other geek-friendly forums that seem to be based on the premise that most/all businesses are somehow doing evil things with personal data and they must be stopped
I think it's pretty reasonable to have that premise when those businesses can't tell their users what they did or will do with personal data. No one could even tell whether it's evil or good if you don't show me some details. And sometimes, you assume it's good for me, but I think it's bad for me. Thank you for your good intention but all I want is just an opt-in option, not opt-out, is that so hard to accept? When you drag me into something I don't want, why would I assume you are doing something good? Users being alarmist is not users' fault, data companies' unethical use of data made users react this way. > "we cannot guarantee that all your data is deleted with our current storage system".
If so, just say it. But after that, you may want to explain to me why you can't even take care of my data while claiming you respect it. Did you collect my data then just forget where you store it? If the deletion is that hard, why should users trust such company in the first place?GDPR is an action of defense, not a weapon for invasion. Only predator would think it's a weapon and be afraid. GDPR is not perfect for now, but complaining the ambiguity of it doesn't make internet companies' vague ToS or Privacy Policy clear as crystal. Let's not play double standards here.
I'm quite aware HN is full of people work in data industries, I just have to say it.
But what part of GDPR was it that caused you to have to close off European Union users?
> Starting tomorrow May 24, 2018, access to the Instapaper service will be temporarily unavailable for residents in Europe
You'd think a real company would have talked to a lawyer about this.
GDPR makes no mention of EU citizens or residents.
The 2 main groups it applies to are:
1. activities of an establishment of a controller or a processor in the Union (so if the company is in the EU, ALL processing has to be GDPR compliant regardless of where the user is)
2. processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union (if the company is not in the EU, processing of data of people in the EU - note they just have to be in the EU and not residents or citizens - so if you are from the US and on holiday in the EU and you order pizza delivery to your hotel, that personal data has to be handled in a GDPR compliant way, notwithstanding that the pizza company is probably in group 1 anyway but hopefully you get the point. And the converse of that, if you live in the EU and are on holiday in America and order pizza, that personal data does NOT need to be GDPR compliant as you are not IN the EU)
There are a few other scenarios included too.
Edit: It's worth pointing out that 1 seems to have been completed missed in almost all GDPR coverage I have seen, possibly because most of the coverage has been heavily US centric. If the company is established in the EU, it has to comply with GDPR for ALL users, not just people in the EU. This is why Facebook [1] and others changed their terms so that only EU users have a contract with Facebook Ireland, and everyone else now has a contract with Facebook Inc (US) - previously everyone had a contract with Facebook Ireland.
[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
There's no real difference in "Facebook US" and "Facebook Ireland". The only difference is this methodology skirts the law.
Hopefully, the EU will climb up these jokes of shell companies and rightly smack them down.
EDIT: I've just read through your privacy policy and I wish other companies had a privacy policy as clear, straightforward and detailed.
They probably sell your data or use it to show you ads or targeted content. Who cares?
P.S. I still have access in the UK...
In the end, companies whom don't go through with the GDPR prep and implementation tell me precisely one thing: there's something in their process that makes it hard for them to comply. But not seeing "We're in progress to comply at $date" tells me that they're doing some pretty nefarious stuff. Is that actually the truth? Well, we don't know and can't figure that out.
It's either you comply with the GDPR globally, or for $reasons you don't. I choose to work with GDPR compliant orgs first. I know how my data will be used. And if I buy European IoT hardware, I know its not a spy-station.
Edit: FUCK rate limiting. Here's my response.
Given that I'm an American who has had many accounts exfiltrated or otherwise leaked, I'm frankly sick of companies treating me as a data pinata.
I could go on to cite countless examples, but that dead horse has been beaten time and again. And in many cases, my data is used even without my permission (sending to gmail addresses, facebook ghost profiles, etc).
It might be charitable initially, but I've seen my own impact on bad data practices. It was the wild west... And now the GDPR finally puts a stop to a lot of badness.
I'm not sure there's anything they're doing that's not compliant, but uncertainty about whether that's true might be sufficient for them to consider it too risky to conclude that they are.
I think, if anything, the facts that the law is written is relatively 'simple' language, doesn't specifically mention any technical examples, and is widely expected to be enforced 'spiritually' and not literally, makes it particularly hard for lots of organizations to know with reasonable certainty whether they're in compliance or not.
Thanks! :)
Edit: Thank you for making this!!
Last time I looked (just a few days ago) it was the epitome of "What you're not allowed to do anymore according to GDPR.": Tracking and other cookies with no way to opt out, no privacy policy etc.
Then again, GDPR of course doesn't apply to them. The very least they could do in my opinion, however is to lead by example.
The GDPR appears to be doing its job here because it's forcing a company out of a business model that is unethical and into one that's better for society, regardless of it's better or not for the company and some of its customers
They won't be able to sell the non-compliant version right?
A B2B service can legally offer a non-compliant service in the EU, but then the buyer isn't allowed to put any privately identifiable data in it; GDPR article 28.1 "Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject."
So in the sendwithus case, GDPR would prohibit an EU company to use its $79/month service for handling private data, since it doesn't come with the required assurances.
Most companies outside the EU will eventually block EU traffic. GDPR is just too big of a liability. It has nothing to do with “selling user data” or bad intentions with user privacy. I won’t take EU traffic for the same reason that I don’t drive at 140mph in a 25mph zone - it’s irresponsibly dangerous.
[1]https://www.ghacks.net/2018/05/24/ccleaner-update-introduces...
[2] https://forum.piriform.com/topic/51913-ccleaner-5436520-cann...
After the GDPR hype has died down, hopefully new tech companies will think twice about data privacy
EDIT: Updated with new post
http://gdprhallofshame.com/5-techcrunch-engadget-and-oath-co...
Great idea for a site. I'm sure it won't lack content for quite some time.
Surveillance violates the privacy of common folk and thus is somewhat permitted, but violation of banking privacy threatens the rich and influential people and their (shady?) dealings, so that has always been restricted and actually enforced.
2) "A list of credit card transactions" is the kind of data that I'd assume that Visa/MC aren't selling to anyone ever, I'd expect any data sales to be on the level of "real time subscription to how (and how much) different demographic groups are shopping in company X or in location Y", but not on the level of individual transactions or individual accounts. Group them by zip-code and hour and you're fine even for GDPR requirements; and you can provide "individual" granularity for the merchants (e.g. for stock traders who want to predict revenues) since merchants generally have no privacy protections.
ico[1] is a useful resource for all GDPR related questions, but to answer your question: yes. Under GDPR, "personal data" is "any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier."[2]. You can also read the "Article 4 - definitions" section in the official regulation doc (pdf)[3].
For the most part, GDPR protections for "personal data" only apply to identifiable data, as would be expected.
1. https://ico.org.uk 2. https://ico.org.uk/for-organisations/guide-to-the-general-da... 3. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
Technically, writing "John Smith" on a piece of paper can become anonymous data if there's no way to determine who wrote it and it doesn't mean anything to anyone who has access to the piece of paper (because there's a lot of people with that name or because they don't know anyone by that name) but of course names should be treated as personally identifiable to be on the safe side.
On the other end of the spectrum a vague description like "that chubby guy with the crew cut" can be personally identifiable information if you know who it refers to, even if someone else might see it and have no idea who you mean.
So the exact lines are highly contextual and pseudonymisation does not guarantee anonymisation: if you call a Rose by any other name, you still know it's her you're talking about.
I don't have a good idea idea how legitimate a credit agency's legitimate interest really is. I might set aside some popcorn for seeing how this particular issue gets resolved.
Furthermore "please delete my data" doesn't really mean "delete all my data", it means something like "I revoke whatever consent I gave and delete all my data that you now have no right to use" - so the company is allowed to keep all the data for which the GDPR gives them a right to use without your consent.
I've lived in both the UK and USA and used credit products in each, and your access to such credit appears to me almost entirely determined by a handful of credit reporting agencies "scores" in both countries in a pretty similar way. Heck it's even often the same company - Equifax (one of the largest) operate in the UK as well.
1) There's no "EU score", each lending market is somewhat separate. Past history in one location may or may not influence your score in another location.
2) Instead of a general/universal "credit score" calculated by an agency, there's often a concept of "credit history" which (depending on the country) may or may not list the amounts of existing loans, of previous loans, and history of late payments. The difference being that instead of lenders getting a score calculated by some agency, the lenders get the data and make their own decision, with possibly very different opinions on which factors are important. Not everywhere, of course, some countries (e.g. UK or Nordics) are more like USA.
3) The process tends to be highly regulated. If you're providing factual data as opposed to an opaque score, each item better be correct - distributing to all lenders "Bob defaulted on a loan in 1999" is libel if it's not true; the dispute process tends to be more consumer-friendly than USA - e.g. a requirement to remove the disputed items immediately and return them only if the debtor can prove its validity), maybe a requirement to expire entries of missed payments within x years, etc.
4) In some countries, that agency is run by the gov't, i.e. purely a central official registry of loans and/or bad loans, which is somewhat sufficient to verify creditworthiness. In others, it's like Equifax.
5) There often is a principle that the credit reporting agencies can't give/sell that data to anyone - you must give explicit permission for every company before they can gain access to that data.
6) In many countries there's no concept of "building credit" - where there only information provided is about negative events (e.g. defaults or missed payments), so having never taken a loan combined with good income gets a perfect rating, as it's not distinguishable from a long credit history and having never missed a payment.
So it's quite tricky - similar but different.
On top of that, I don't think there's anything in the GDPR limiting it to internet related things, so brick & mortar stores will have to be compliant as well, afaik.
RE: is not Regarding in this context but appears designed to increase acceptance by lying about the recipient receiving a response to an earlier non-existent communication.
Re can mean regarding, but in an email subject line Re: has been taken for decades by email programs to mean something very specific, "Reply".
Man what a nice thing we've built.
We have turned the internet into a network where people snitch on each other to marketers for fractions of a penny.
Here's a page from 1988 Whole Earth Catalogue "Signal - Communication tools for the Information Age"
http://tinypic.com/view.php?pic=2janfrd&s=7#.WwcJwiAh200
Compuserve, charging $11 per hour, had "more than 250,000 subscribers".
The Source, charging $8 per hour, was popular for its conferencing system "parti".
Delphi, charging $6 per hour had a loyal but small (less than 10,000 users) following.
BIX, $9 per hour, grew from a magazine. I like the quote: "This is the computer industry as it used to be: people sharing ideas and solutions without the greed and grit with associated with today's corporate driven, litigation-laced, industry" (written 30 years ago).
http://www.wholeearth.com/issue-electronic-edition.php?iss=1...
Although free local calls could be quite limited in area. Intrastate long distance (which could be as little as 15 or 20 miles away) could actually be more expensive than interstate long distance. I don't remember the details but I used a private BBS service in the nearest major city in the 80s. I had some sort of phone plan that optimized for this but I still used offline tools to minimize my online time. (i.e. Login, suck down content, logoff, read and reply offline)
I used similar tools for Compuserve. As you say, it was extraordinarily expensive by today's standards. People complain about the pricing of a lot of things but telecoms and pretty much everything related to computing is incredibly cheap.
Our machines didn't even use DNS yet IIRC there was a HOSTS.TXT file sent around that had to be updated as new sites were added to the network.
It was fairly early, and I got to see the internet before the marketers started to take notice of it.
I remember the internet worm[1] and the Canter and Siegel usenet spam a bit later[2].
I'm glad the internet was made public of course but I wish the standards from back then had better security built in.
Of course encrypting everything back then would have been a significant drain on computational resources. We used to login 40 students at a time on TTYs to a Sun 3/280 (25mhz CPU!).[3]
[1] https://en.wikipedia.org/wiki/Morris_worm [2] https://en.wikipedia.org/wiki/Laurence_Canter_and_Martha_Sie... [3] https://en.wikipedia.org/wiki/Sun-3
I dont think so. There are very few companies I actually use in my life, and less than a handful of them are online. The rest - bugger off.
I've been receiving so many "here is our policy, if you continue your use, you accept it, kbye" emails... I truly hope EU will take the default-opt-in problem seriously.
And usually, what is it that causes outages like HN/reddit's hug of death? Number of open sockets / file descriptors? RAM? CPU? Network congestion?
GDPR should be resisted by as many companies and startups as possible.
If half of the companies remove that private data which they shouldn't have, then that will reduce the impact of breaches, as there'll be twice less breaches where's something sensitive to leak.
The Republican National Committee leak (https://gizmodo.com/gop-data-firm-accidentally-leaks-persona...) - all the involved companies which swapped data records to make up this trove would not have had the permission to have much of that data under GDPR.
World Wrestling Entertainment 2017 leak - the leaked data included home and email addresses, birthdates, as well as customers' children's age ranges and genders where supplied, and even ethnicity; there's simply no reasonable reason why they should have had data like that in the first place. It it hadn't be collected, it couldn't have been leaked.
Joblink breach (https://www.identityforce.com/blog/americas-joblink-data-bre...) leaked among other things birthdate and social security number. There's no good reason to ask the birthdate in the first place, and to store the social security number after you've run whatever verification they do (presumably it gets used for background screening).
The big point is that almost always data minimization would have reduced the consequences. Companies keep old data forever, and that creates extra risk; Companies ask for and store more data than they need and that creates extra risk; Companies buy and sell data that shouldn't be bought and sold, and so the data copied in multiple organizations and again, creates extra risk.
companies aren't humans.