Shutting Down Forum (GDPR)
discourse.drone.io
discourse.drone.io
Isn't this the sort of thing people accuse the US of? The rest of the world makes ugly jokes about "Be careful what you say about the US or they might come liberate you too." The EU is now in the protection racket. When the mob says you should give us a few bucks because it would be a shame if something happened to your business, people recognize that is not nice behavior. But the EU can do the same on the web and some people laud it is a good thing for individuals in the name of personal privacy.
If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc.
(Yes, I am guilty of having this opinion without having actually read it. I blogged previously about my opinion this would do bad things to forums. I am shocked to see negative fallout happening so very soon.)
Facebook and other data aggregators build profiles of you even if you don't participate directly in those services. The web is different now than it was in 1996.
I suggest using the identifier you received at birth to make the request plus your e-mail.
It's the path currently explored in a class action against facebook for forced consent and we'll see what happens.
Yes, they are based in Ireland.
So closing the offices wouldn't help.
This law will only make things (even) more expensive and cumbersome for EU companies wrt. the rest of the world. This is going to be the asinine Cookie Warning all over again, times a hundred.
EU regulators could domesticate their judgments in the jurisdictions where these companies are based. It's entirely possible to do this in most states in the US, for example.
Failing that, they could target assets held in the EU or take action whenever corporate officers travel to the EU.
Google, Facebook, Twitter, etc. got websites to implement their like buttons everywhere. The information gathered by them is collected and everybody is being tracked wherever they go.
If we aren't as a world terrified of what is being done by small groups like the open source organization announcing it is shutting down in the very post under discussion, why are you defending the GDPR on the idea that it somehow reins in the abuses of FB, Google, etc? Do you have evidence that it is, in fact, reining them in? Or are they just getting with their lawyers, finding cute ways around the problem and carrying on while entire organizations smaller than them suddenly shut down and die because the EU wrote words somewhere that these mega corps likely care relatively little about?
> Do you have evidence that it is, in fact, reining them in?
We will see what happens. The first complaints against Facebook and Google have already been filed.
If the entire world currently agrees that a handful of companies are The Problem, then there should be some means to go after said handful of companies and get them to stop being The Problem without creating blanket laws negatively impacting the entire world, especially smaller organizations.
Dealing directly with a problem company usually involves charging them under existing laws (anti-monopoly laws?) and things like that. It usually does not mean making unenforceable laws that name them by name or define things in a Jim Crow style that clearly targets them in specific and that is unlikely to stand up in court.
Google, Facebook, Twitter have a roster of the web pages you have viewed, whether you interacted with them or not.
Verizon, AT&T, T-Mobile and every other phone company has a complete log of your location history (for mobiles), message & call history, and unencrypted browsing history. They have no need for it to provide service (beyond the month or two in which these actions occured), but they do sell it to third parties, the list of which you have never seen.
Your credit card company does the same with your credit transactions.
This is already 30 companies or so, just in the US, and it is just the tip of the iceberg.
GDPR says "a person's data is their own property", which is easy to understand and enforce. You may not like it, but it's along the line of copyrights and trademarks, except the beneficiary is mostly the common man.
Most countries handle private persons with larger income differently, e.g. they need to pay more income tax.
Most countries handle startups differently, e.g. they don't need to pay taxes in the first years.
Most countries handle farms differently than other corps, e.g. they give subsidies to them.
Most countries handle people with no income differently, e.g. they get social security payments.
Most countries handle banks differently, e.g. they are regulated.
Most countries handle health companies differenty, e.g. they are regulated.
What makes you think we don’t already do that? GDPR is about privacy 101; there’s nothing in it that shouldn’t apply to small companies.
Do we allow small restaurants to poison their clients because they’re just starting and you-know-it’s-hard-to-build-a-restaurant-so-let’s-wait-a-bit-before-applying-regulation? Of course no.
It looks like our experience on implementing GDPR is different.
Essentially GDPR is like being PCI and SOX compliant from the first day - and looking at what companies go into to not be under PCI compliance, like use Stripe forms, this looks like significant overhead. After implementing GDPR, SOX and PCI in several companies, from an IT perspective they are comparable, with PCI the easiest to implement, especially on the process side, GDPR a little bit more than SOX on the documentation side but no monitoring of code changes and traceability.
Paying 10.000+ EUR for a missing word in your data protection declaration is no problem for a multi billion dollar company, but can and will kill startups.
If your GDPR is not on the same level as a SOX implementation, there will be a rude awakening if you get a review and are fined.
Paying for a data protection officer is hindering small companies and startups.
Updating your deletion infrastructure with every feature you implement is overhead. If you do not automate this and keep it updated and respond to information request by hand, plan for significant manual work.
Having a process documentation of 100+ pages which needs to be updated with everything you do and every new feature that captures or transfers personal data or stores data is a huge overhead for iterating on your product.
Do a risk analysis and data protection sign off for every test feature decreases your speed a lot.
You need to document every process (what data, where stored, when deleted, what cloud/saas/systems involved, who has access, how it is protected, ...) - like sending marketing mails or cold calling or going to a conference collecting business cards or giving stuff away to winners on Facebook - if it touches personal data.
Encryption in the database of personal data and encryption on the storage medium is a lot of operation stuff - this will lead to converging every startup to only use PG instead of being polystorage.
Implementing access controls to your office (if you use Excel with personal data) as if you were a data center is a lot of overhead - no more starting at home or in the garage. Probably best to go to WeWork who have proper office access control, if you have the money.
Investing into training days, planning and updating training material and managing training and with your staff is a lot of overhead for startups. Together with staying up to date with court decisions on GDPR will cost startups 1 FTE (see above). From now on instead of hiring that second developer I'd consult startups to hire a security officer first.
Having a data processing contract for every prototype feature you test is a lot of overhead to being agile and lean.
Marketing signing up with a credit card to try out some automation in a startup - these days are gone.
I'd say it is significantly more difficult to follow the lean startup methodology than before.
From working in some large companies and some startups, implenting GDRP, SOX and PCI, GDPR will help large companies who already have a large legal team, large compliance teams and who are SOX compliant against disruptive startups. Google and Facebook are the main beneficiaries from the GDPR.
People clueless about privacy and privacy abusers are no longer welcome to the data of EU citizens.
Then again what you say is a misrepresentation and biased idea, what proof do you have that GDPR will disproportionately impact small organizations ?
Have you read the actual annoucement posted here ? asking because it does not say that it is shutting down but that it is moving its community discussion from a self hosted discourse forum to a third party hosted subreddit because discourse lacks the ability to properly address GDPR request and lack of time to do so.
Of course GDPR also applies to FB, Google, etc. Have you followed the discussions 5 years ago when GDPR was in the making and witnessed the intense lobbying from silicon valley against strong protection ? Probably not.
Are you aware of the noyb.eu[1] initiative, Max Schrems again, currently targeting google, facebook, whatsapp and instagram for their "forced consent" (more to come) ? La Quadrature du Net a french internet rights organization is currently working on 12 class actions targeting google, facebook, amazon, apple and microsoft, etc.
You can hammer one app Facebook but you can’t hammer all apps.
Just consider revery Chrome extension that is malware. You can though hammer Chrome to block functionality that enables malware.
If you have a very strong right to anonymity, a right to be forgotten is less important because it's easier to separate yourself from your online identity. In fact, forgetting information is pretty harmful because anonymous systems need better tools for building and validating reputation.
If you have a strong right to be forgotten, anonymity is less important because you can just delete information you regret sharing. And similarly, anonymity is kind of harmful because you now need ways to validate who owns information and ways to control how it's spread.
EU seems to be less concerned with anonymity, and more concerned with managing and regulating information after it's already been created and shared. This also kind of rubs the anonymity crowd the wrong way because they've advocated for a while that information isn't necessarily something that you can own like property, and that the Internet should actually be far more immutable than it already is.
Exactly. Privacy also doesnt mean being invisble when interacting with people or machines. It's not a well-defined right, and the limits can often be fuzzy (e.g. a problem that kids often have with parents). Pseudonymity / anonymity can also be subject to gradation.
sensible regulation that defines workable limits of what personal information can be collected, combined with requirements for anonymization when needed is a better solution.
GDPR is also quite weak in this regard as it has few new additions: explicit consent (thanks to snowden exposing prism and despite the largest lobbying campaign against it orchestrated by silicon valley[1]), max possible fine increased so actor like google and facebook would stop paying 150,000€ fines right and left while laughing in the face of European laws, and class actions.
Again it's only thanks to snowden revelations that the GDPR weakening personal data protection was overturned.
The real change that matters is that now the law can and will apply.
In this case the operator's usage of the word troll to describe what happened is telling. Anyone can send any kind of threatening letter they want, and they are free to report you for non-compliance, but that doesn't mean any action will be taken against you, let alone actual fines.
IANAL, but IMHO the chances of any solo forum operator being sanctioned by EU regulators is effectively nil—the purpose of the law is specifically to address usage of personal data, not old-school off-the-shelf forums and other one-off websites where the scope of the data is essentially the core of the service itself.
You can argue the only thing that matters is the end result, but I'm not sure there's any way to write meaningful privacy regulation that will not generate a huge wave of FUD, especially with the traditional SV stance that we ought by default to have carte blanche to monetize user data in any way that's effective.
No, but it is a strong signal of my critique: That the EU is a 900 pound gorilla and that is a large part of the problem here. Small operators will, in fact, be impacted by this because they don't have the resources -- including time -- to cope with this and this will cause substantial fallout. Suggesting that "The details of the law are sensible" is not a rebuttal of the cincerns I am expressing.
So far there have been a few people just giving up before the regulators get involved, which seems like a massive over reaction.
What a fucking stupid thing to say.
GDPR requires a few things: don't collect too much data; be honest about why you're collecting it; allow corrections; in some situations allow deletion.
This isn't a a boot crushing people.
It's perhaps more poetic than is the norm here. That doesn't make it a fucking stupid thing to say.
The reality is that since we don't yet know how this will play out, those who are risk averse, whether by personality or positioning (because some people just can't afford to take risks), will tend to flee from what could be a crushing burden. Furthermore, if someone is essentially in survival mode and can't spare the time and energy to read the GDPR and become confident they know how to deal with it, then just needing to read it and adapt can be a de facto crushing burden without any fines being levied.
Would you please stop going on tilt like this on HN? You know we ban people for commenting this way.
There are tons of companies processing my personal data that are not web companies. GDPR isn't about "data being on the web", it's about all handling of personal data.
Public records are potentially more harmful than anything Facebook has. For example, I just shipped a 20 foot container of household goods to the US from France — that manifest, including my personal information is public record — I have to explicitly send a letter and request privacy for that shipment — and then remember to renew that request each year or else details of my entire shipment, including my address and contact information are available publicly. Thanks government. I can’t simply use another shipping company — it’s a government rule. When GDPR applies to governments, then I might become a fan, but as it is now, I am being “protected” from my Facebook likes or web history but what protections do I have from governments who traffic in my information. There is zero reason my shipment manifest needs to be known beyond Customs or the shipping company moving the goods, yet, here we are. Facebook never committed mass murder — but governments certainly have. Google Analytics data doesn’t have a realistic chance of causing harm — but someone with my address and a manifest of a shipment of expensive stuff results in a potential for real harm — that stuff is literally public record with absolutely no controls over who can buy that information.
https://ico.org.uk/for-organisations/guide-to-the-general-da... See “when does [it] not apply?”
GDPR already applies to governments. What makes you think it is not?
https://www2.deloitte.com/nl/nl/pages/risk/articles/gdpr-in-...
> Starting May 25th 2018, all organisations, including those in the public sector, need to comply with the GDPR.
Government agencies have been working their asses off to become GDPR compliant. If you have a problem with the way your shipping info is handled, file a complaint against that government agency at the French data protection authority.
Please stop the FUD. The right to be forgotten has never been absolute and applies to both companies and government.
This, for example:
> Germany's spy agency can monitor major internet hubs if Berlin deems it necessary for strategic security interests, a federal court has ruled.
> In a ruling late on Wednesday, the Federal Administrative Court threw out a challenge by the world's largest internet hub, the De-Cix exchange, against the tapping of its data flows by the BND foreign intelligence service.
> The operator had argued the agency was breaking the law by capturing German domestic communications along with international data.
> However, the court in the eastern city of Leipzig ruled that internet hubs "can be required by the federal interior ministry to assist with strategic communications surveillance by the BND".
https://www.yahoo.com/news/german-spy-agency-keep-tabs-inter...
Also see the much controversed "legitimate interests" exemption to GDPR that has been carried over from the 1995 EU directive.
My point is that Europeans overall are more comfortable with government snooping, and less comfortable with snooping by private interests, than Americans are. In practice, of course, American government agencies snoop far more than European ones do, but the American ones must be more covert about it.
It doesnt apply to security-related services, and the governements are allowed to override it for most purposes as outlined in article https://gdpr-info.eu/art-23-gdpr/
1. Each EU member state has a different legal framework and so a Regulation (which has direct effect, meaning it applies as-is and does not have to be "transposed" into national law) would not be appropriate when dealing with criminal investigations;
2. The EU can only act in areas where it has been given "competence" to do so under the Treaty on the European Union and Treaty on the Functioning of the European Union. Member states are reluctant to give the EU broad competence to establish criminal offences or to regulate the investigation and prosecution of offences;
3. The treaties explicitly exclude almost all activities related to national security because that is a fundamental feature of being sovereign, which EU member states are and the EU is not.
Due to points 1 and 2, the EU passed the Law Enforcement Directive (2016/680/EC) which regulates processing of personal data in a law enforcement context. Being a Directive (and not a Regulation) means that each member state has latitude to adapt it to their respective legal frameworks when transposing it into national law.
Incidentally, point 3 will cause huge problems for the UK when we eventually leave the EU. The Court of Justice of the European Union - the EU's highest court - cannot take in to account laws of a member state relating to national security (insofar as they _only_ relate to national security) due to their exclusion by the treaties, but they can take in to account laws of a third country.
https://twitter.com/bainesy1969/status/1001902266620764160?s...
> ICO rules that ICO failed to comply with timescales laid down in the FOI law that ICO regulates link: https://ico.org.uk/media/action-weve-taken/decision-notices/...
I still have no idea what to do exactly. I don’t really think it is my responsibility but I live in a country and operate in another country where laws this vague are unenforceable.
First it allows to record and keep the relevant data for sales and legal requirements. Second it applies to government.
Comparing facebook vs government is really a dumb fallacy, why would government be unable to use facebook for whatever ? and facebook to cooperate to that ? it is already happening, look at what happened in the Philippines with Rodrigo Duterte[1].
That you are unhappy with the US legal requirement to be able to ship cargo to their country[2] is unrelated to GDPR, maybe take your complaint to the relevant governement or regulation body.
[1]: https://www.bloomberg.com/news/features/2017-12-07/how-rodri...
[2]: excerpt from world shipping council to US customs
II. Cargo Manifests: General Today a cargo manifest is the document that states what a carrier has loaded aboard a vessel for delivery to the United States. The creation, submission, and retention on board of the manifest are tasks that are the responsibility of the vessel carrier and are regulated by law and regulations. Proper manifesting is a requirement for allowing the entry of inbound vessels and for the issuance of a permit to unlade.
We recognize that the cargo manifest has become a document that is used by the government to prescreen cargo for national security reasons. It was not designed for this purpose and has some limitations in this regard.
GDPR doesn't introduce a requirement to delete data upon request.
The GDPR is probably not what you think is, because it barely introduces new stuff, it only enforces what already existed but was ignored because it was based on self-regulation.
There are a number a publications about RGPD explaining that there really nothing to panic about (unless you're a giant conglomerate), it's not going to kill your business unless your business is based on violating privacy and things you should not be doing in the first place because it's been illegal for a while and you had 2 years since the announcement to respect the law.
> If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc.
Does not work that way, actually thanks to RGPD it's now: if you don't want to deal with RGPD requests don't collect or process personal data.
(I wonder why this is contestable? DMCA is an afterthought, GDPR requires a lot of actual work to implement even if you process minimal data like IPs)
Now if you collect and track you may want to inform the users and let them opt-out.
GDPR is similar in a way with the Don't spam me laws, I assume you had to write code to respect this law and I did not see people complaining that they need to write code to respect that law. Or you can not do business with EU citizens.
I understand that you may have some small websites and you put on them who knows how many trackers/analytics and now is time consuming to go to those websites and implement something, but we needed this law the same as we needed the don't spam me law, it will take effort to fix existing sites but is for the best.
I feel a bit bad for small creators that need to fix their sites but at the same time I dislike the people that are trying to find possible loopholes around the law, fixing all this loopholes and workarounds is the reason the laws have long texts.
Do you have a website or something that is affected? I only have a simple site that I used some time ago as CV and for testing, I never had tracking scripts,analytics, referrals. I am also the opinion if you don't want to respect my privacy then tell me that and block my access.
Of course, if you do, like in this forum example, you will have to do something, but that doesn't apply to all the information/blog/brochure sites using unnecessary tracking, etc. They can simply not do so.
Since everything your site does basically is defined as “collecting” or “tracking” it’s absurd to claim you can just simply “not do so”.
If Google tracks something, whether it is via their fonts, by putting some cookie on your site or whatever, it is their problem (and they actually said so, in that Github post referring to the font issue). They are the ones collecting and processing the data, not you, so they will have to deal with the GDPR compliance.
But what’s special about fonts? If I can’t reference an asset outside my own domain because the network request could allow the 3rd party to log an IP address, How is that not antithetical to the foundation of the WWW?
Besides the fact that this goes against the last decade of advice on how to speed up your site...
Is it really that unreasonable that loading a page to x.com should only load resources from x.com and 3rd-party resources compatible with X's privacy policy?
Seems like a contradiction, and exactly my point. Trying to collect privacy policies and compliance statements from any place you might load an <img> or <script> from is extraordinarily burdensome and pointless besides. Totally absurd over-reach IMO.
And what about the 25 hops in between you and them which also collect your IP and the domain being contacted?
If someone is going to have top-notch legal team on this it is going to be Google. So if Google's legal says that it is alright because they are the data processor/controller as defined by GDPR you can pretty much take them for the word there.
I wonder whether people spreading this sort of panicked disinformation about the fonts and what not have actually read the GDPR text. It is pretty clear about who is considered to be a "data processor" or "controller" - someone who merely uses a resource like fonts is certainly not one if you aren't collecting any information yourself or having someone else do it on your behalf. That Google may be doing it is irrelevant as long as they aren't providing the data to you (which would make you a "data controller").
And if you are neither a data controller nor data processor you aren't concerned by GDPR at all.
It is well explained here: https://www.gdpreu.org/the-regulation/key-concepts/data-cont...
This is a very good point, and to be fair you're absolutely right. The definition of user-tracking extends far beyond Google analytics, and if you're not fully informed about what 3rd-party services you're using on your own website, and the ramifications of those, this could present problems.
When I said "they can simply not do so", that assumes they are aware of what tracking they're doing, which may not be the case. If you're using some WordPress.com blog theme with CDN calls built in, you might have no idea. There may even be an argument for this falling to WordPress.com (in this example) as the provider of the themes.
Realistically, I don't predict CDN calls to turn out to be in violation of GDPR in practice, even though there's a very reasonable argument for them being that in theory.
I kind of half-hope they are though, as a user. I've never been a fan of their use, and use the uBlock and Decentraleyes add-ons personally to avoid them. I wouldn't be devastated if we returned to a norm of locally linked resources (especially with HTTP2 adoption), though that's probably just wishful thinking.
I can visit site A and B, not put any of my data intentionally on them but still my data get be funneled to 25 third parties that know what I visited.
So your point is don't use internet or turn of javascript and open each link in private windows and maybe use some proxyes or Tor
Now everything loads in an instant, no more shenanigans that jump around the screen as I scroll, no Facebook/Twitter/Google buttons (that nobody even uses), no pop-up/in/out/over adverts, and even those asinine cookie warnings are gone by default!
I cannot recommend it well enough.
Ever try running traceroute?
And you're very likely using the services of one of the big players, like Google, the very ones you're suggesting should be explicitly targeted in another message below.
Like I said before, including to you: the EU does not owe companies a business model, especially when the costs of that business are externalized to citizens of the EU and of the world.
Your so-called alternative at the end is just more of the arrogant snubbing typical of the advertising industry.
If you don't want to get robbed, don't leave your home.
It is not difficult to be compliant. Most people don’t bother because they are drama queens or hiding what their business is really based on and the latter is usually not ethical by any manor and deserve to be shoved off a cliff.
People will have to do some real innovation instead of selling off data and working out how to attract people into a product that exists only to do that really.
Precedent? It's hardly the first time one powerful body politic has enforced its own standards on others. A very, very, very long way from the first time.
They do have jurisdiction, because the laws apply to companies that want to reach Europeans.
It's up to companies whether they think it's worth the effort to reach this market.
Companies do some crazy stuff on the other end of the spectrum to have a presence in China, right..?
It seems like he has no time only for legislation from EU.
I don't think I support an unlimited right for people to delete everything they've posted to the internet. Previous law did not recognize one; the primary mechanism for attempting to assert one would likely be copyright, and a clickwrap user agreement would usually offer sufficient protection for the forum operator.
And more generally, prior to GDPR, a person could casually put up a forum on a website and not have a meaningful legal compliance workload. GDPR changes that.
There is no right to delete stuff that is not PII.
And forums already had to protect against eg people under 13 registering, or people under 18 sharing nudes. Both of those pose significant risk to online services, but people cope.
GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.
The ICO has produced a font of useful free guidance for getting compliant with the GDPR:
https://ico.org.uk/for-organisations/
That's what people should be reading.
The only reasonable assumption is that those new teeth will be tried out, and whoever they will be tried out on first will have a bad time. Do not assume that the first cases will be Google and Facebook, the regulators aren't stupid enough to try their luck first on the two organisations that has spend the most on being technically compliant, and has bottomless warchests to fight it.
You're right though, that it is always a relatively pure cost/benefit calculation for the company.
The EU has had data protection law for twenty years. The EU has enshrined proportionality of penalty in all EU law as a fundamental right. There is plenty of case law at the CJEU defining this.
All you need do is read the FAQs that EU ICO's have been putting up. The UK has never, in 20 years, applied the full penalty of the previous DPD, and under 0.1% of all reports got any fine at all.
A "typical" penalty will be help to comply. Perhaps a strongly worded letter.
Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA.
Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single piece of forum software
Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development.
Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA.
I agree however that they are both horrible laws. So if your argument was to show that GDPR is just as bad as the DMCA I agree. GDPR is a horrible law and it is not obvious to me that the law wasn't created specifically to target non European business.
The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.
I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual legal threats and action. This just allows requests.
The DMCA helps big business at the expense of the general public. This does the reverse. It's no wonder there's been so much noise and scaremongering.
Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented.
>The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction.
Did I ever bring up litigation? What is your point here?
What is your point here? What is your point when you say that the EU is not litigious? Are you saying that I shouldn't expect to receive a fine for violating GDPR? Are you saying that I should just ignore GDPR data access requests if I am operating in a supposedly ethical manner and I am not selling user information?
a) They are doing the thing we have collectively decided is bad for society (misusing personal data)
b) Do nothing about this when somebody invokes one of their new legal rights, whether that be to retrieve the data you have on them or remove the data you no longer have a grounds under any of the six legal basises to store (which includes 'consent', which can be revoked, as well as five other bases which cannot be revoked but have more limited scope with what you can do with the data)
c) Be reported for this
d) Refuse to work with the compliance group
At this point, judging by how the EU has historically used fines as an enforcement mechanism, you're looking at a small fine designed as a wakeup call. The 20 million EUR figure (or % of revenue) is a _cap_, not a floor, and the EU has never gone for maximum fines except when it is obviously required to enforce compliance.
Since that's all this account has done and we don't allow single-purpose accounts here, I've banned it. Please don't create accounts to do this with.
"Can I have all my data?" is not new to GDPR. It has existed in previous data protection law. How did people cope before?
Getting sued in Europe is a huge deal, getting sued in the US is part of doing business.
The ICO is extremely reasonable and personable in my experience.
[1]: http://researchbriefings.files.parliament.uk/documents/CBP-7...
[2]: https://www.ft.com/content/afff45a0-1597-3f1c-a6da-79c3f61e6...
People send fake DCMA takedowns all the time.
If someone sends you a GDPR data request, you can ask for administrative costs. You can even ask it to be mailed to you via post. If someone sends you a bogus and unreasonable GDPR data request, you can ask them to pay you a further reasonable fee.
This can almost be an auto-response. Trolls will get bored.
> Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development.
This is not true. Recital 62[1] says you don't have to give them any data they already have, and Recital 57[2] says you aren't obliged to determine which of your data identifies them if you aren't going to do it anyway.
[1]: http://www.privacy-regulation.eu/en/recital-62-GDPR.htm
[2]: http://www.privacy-regulation.eu/en/recital-57-GDPR.htm
> I agree however that they are both horrible laws.
I like the GDPR a great deal, and I think it'll be good for companies big and small in the long run. Disclaimer though: I'm doing some GDPR consulting, so you might prefer to think I'm getting paid to like the GDPR.
The scary bit seems to be for companies that approach compliance from the point-of-view of centralising understanding, and minimising the impact and costs of that compliance. They're looking for someone to tell them "this is enough effort", but the point is that Europeans don't want people playing chicken with their data[3].
As soon as companies realise that embracing the spirit of the GDPR is cheaper, it starts becoming a real opportunity for them.
[3]: https://www.sec.gov/Archives/edgar/data/33185/00011931251815...
"1 - The controller shall provide a copy of the personal data undergoing processing. 2- For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs."
Since you're allowed to respond to the first request with a list of the types of information you control, you should be able to do this without a search (and without undue costs).
Didn't a data subject sue Google and Facebook for billions on day one of enforcement?
"Three complaints worth €3.9 billion were filed in the early hours of Friday morning against Facebook and two subsidiaries, WhatsApp and Instagram via data regulators in Austria, Belgium and Hamburg. Another complaint worth €3.7 billion was filed with French data protection authority France CNIL in the case of Google’s Android operating system for smartphones." https://www.irishtimes.com/business/technology/max-schrems-f...
edit: To me, the difference between 'suing' and 'complaints' seems unimportant if the potentials fines from a 'complaint' could be so high.
Court orders take a comparative mountain of effort before they land on someone’s doorstep. They require someone to determine that there is a legitimate cause of action against the site, consult their attorneys/legal department as to the best course of action, research the case and produce enough evidence of their claims to hopefully convince a judge to give them the order they seek, then prepare and file the legal paperwork. In most cases, by the time such an order is issued, several people have invested dozens or hundreds of hours in the effort.
By contrast, sending a “nightmare letter” is a matter of copying and pasting, which can be done by anyone in just a few seconds. Even a small site like the one at issue here could easily receive hundreds or thousands of such requests per year that the owner is obligated to produce detailed responses to, under the threat of enormous fines.
This regulation was written in a way that made it ripe for abuse. We are seeing real-world abuse now, and we are barely a week into it. Shutting down and/or at least blocking EU traffic is entirely reasonable in light of the situation that GDPR has created.
Yes, that is the entirely correct mindset to have for someone who does not live in the EU.
GDPR however requires that you actively set up data auditing and security policies and practices which may break or otherwise require re-architecture of parts of your company. In fact that is it's purpose. If the company or organization is small enough, then it might be easier to abandon the project instead of being compliant.
In this guy's case he had an easy offramp to reddit, so he took it. Simple. However it does offer now at least one data point to show that GDPR has decreased diversity in data ownership and risk. The question is, are drone.io users better off now that they will be utilizing reddit?
You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored), odds of any corrective action against you seem very low.
In any case, the corrective demands of the EU give you time to comply after they declare that you've violated something? Could probably wait for that point even if you're in the EU.
If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future
Then his/her last point is that they’ll give you a chance to correct things.
Your post doesn’t seem to cover that either.
But this is not a given every time and not everyone goes the nice route, some go directly to court. So when you are a small fish, you are better off doing your best to follow the GDPR in the first place than scrambling to avoid sanction in a limited time later. it is not that complicated to not collect data you don't need, ask before collecting it and informing about what you do with it.
This is not all the GDPR requires. You’re just describing traditional Privacy Policy.
How will they do that, and on what legal basis?
If the regulatory agency decides to fine you, and you don't successfully defend yourself against that in court, then you'll have to pay that fine. If you fail to pay the fine on time, any entities within the juristiction that owe you can be ordered to pay the fine instead (i.e., your payment processor will be ordered to redirect funds arriving for you to the state, which also, as far as their juristiction is concerned, fulfills their debt towards you--as far as their legal system is concerned, the payment processor has paid you and you have paid the fine).
The 4% of worldwide revenue fine potential is exclusively targeted at the US tech giants. By my last count, the US has roughly 100 tech companies worth over $10 billion each (with trillions of dollars in worldwide revenue). Nobody taxes revenue, that's about the most moronic thing you can possibly do - unless you're doing it to try to harm / punish companies. Very few EU tech companies have meaningful worldwide revenue to tax.
They target revenue because otherwise companies will just use Hollywood accounting to declare they make 0% profit, they just pay huge licensing fees to some cayman island company.
Imagine a law that forced all companies in the EU to be polite to their customers no matter what or face fines. In that case you could also say that users would be pushed towards EU companies because they were "forced" to be polite, but I think that would be deserved and US companies could just do the same. Similarly to GDPR, if one side is forced to treat my data with respect and actively have me consent, then I would chose them, law or no law.
GDPR is only a regulation stating more explicitly what you're required (and were always required) to do for compliance with EU privacy laws. It obviously was needed since privacy violation has become so blatant. The GDPR legislation has been a long time in the making. It might be the case that privacy in Europe is being valued more than elsewhere in the world, I don't really know, but it's nothing new at all. For example, in Switzerland (not in EU but certainly with humanist and very old democratic and civil rights traditions) privacy in the form of banking secrecy is held in even higher esteem.
Yes, as a collateral effect, some business models might not work in EU any longer, or not to the extent they used to (though ads and affiliation links had been on a race to the bottom anyway). But I'd say that's a win, or can be turned into a net benefit. Think about what the Web has become in the last 10-15 years. We still don't have reasonable micropayments, and nobody wants paywalls anyway, etc. The result has been the rise of "platforms" and monopolies where the user's data and attention is the product, with publishers of quality, nuanced content struggling or going out of business. While you of course don't owe dead-tree publishers anything, an economic model for content creation working for more people than it is now is still very much desired.
If you're perceiving GDPR as trading barrier (even though it's just a privacy law), please also consider the US's total and utter failure to get their antitrust regulations in gear: Facebook buying WhatsApp, Google buying DoubleClick and YouTube, etc. At a certain point, others will have to react to that kind of government-sanctioned monopolization to protect their markets.
The European Union also green lit those acquisitions. Hence the fines against Facebook for essentially lying to the European Commission about the merger.
Maybe I put a notice up and geofence EU IP addresses but it seems that would just raise my visibility and suggest that I think I'm doing something wrong (whether or not I am).
At the least I'd wait for some indication that a random US ecommerce site (or whatever) actually has something to worry about.
So I sent the company a letter asking what data they have on me. It's going to be interesting to see what happens.
It's going to be interesting to see what happens.
My bet: Nothing.Want to write a short post on it?
"I am a customer of yours."
Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.
It's ok if the privacy law only gone against stuff like analytics or horrible facebook buttons that even collected stuffs from people who clearly weren't users. i.e. tracking especially tracking outside their "domain"
however GDPR goes against all and anything. I mean if I go to a supermarkt I can't just tell the supermarkt owner to shut down all his cameras until I leave the store, he would basically just kick me off his market (which actually is his right in the EU). However the EU somehow made a solution that actually even goes against their own market principles just to have extreme amount of Privacy in the internet (only in the internet, their own institutions can still collect data, i.e. in germany the ard has tons of data about everybody) and this is my problem with the GDPR, it's a law from people who actually just want to hurt the big us internet companies. The law also was made by a lot of people without any clear technical background (there were some, but they were a minority)
Your example is deeply misrepresenting the GDPR, seems like FUD to me. GDPR applies outside the internet, GDPR is very limited in scope as it kept the "legitimate interests" exemption from the 1995 directive.
Can you substantiate your claim that GDPR was made by people who do not understand what they do ?
Your name, address, move-in date, and whether you paid them. Additionally – if you don't to pay twice – who you live with. Am I missing anything? In any case, they are still bound by the same GDPR as we all are.
(A small nitpick: The ARD does not hold any data but their members do.)
https://gdpr-info.eu/art-2-gdpr/
> This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
In any case it's the wrong way to address the problem, and its ill effects are seen in cases like this. It's actually easier for "free services like Facebook" to comply because they can hire full-time compliance staff. The worst effects fall on smaller sites and individuals, making them less able to compete - individually or collectively - with the entrenched big sites. Some have even painted it as a form of regulatory capture, though I think that's a bit of a stretch.
No, it really doesn't.
In Europe action for civil torts is limited to what you've actually lost. There are no punitive civil claims. Courts are a method to get back to how you were, they're not a route to betterment.
And GDPR is not enforced by each victim of a breach taking civil action through the courts, but by victims reporting to the regulator and allowing the regulator to take action.
The reason people in Europe seem so blasé about this is because we've had decades of experience with regulation, and we know that they don't have many teeth, and tend not to use the teeth they do have.
GDPR isn't changing this.
If you collect data from me when I visit your website, even without me buying anything, you have now collected data and you need to comply.
The use of the word "customer" in this context is incorrect.
https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
thing is if you require people to register to be able to buy from you they can be customer before actually paying anything.
What I wonder: this is an Open Source project, so why not ask the community for help instead?
Being a long-time (very happy) Drone user, I would have happily helped to produce the necessary documents for the project if that had been asked before the final deadline.
Well, probably would even do that now.
</sarcasm>
-- Anatole France (I might have edited that quote slightly)
Few rich people have any inclination to sleep rough, whereas many wealthy tech companies have been happily selling their users' data as the law allowed it.
Only little people would steal a crust of bread for their supper. The rich generally commit bigger crimes.
;)
Is it also unfair that both small and large companies aren't allowed to pour acid into rivers? Should they get an exception?
Should only large restaurants be forbidden from serving rotten food? Should small car makers have exceptions to car safety and emission standards?
Funny you should say that because I'm an environmental studies major and we do, in essence, let small shops do exactly that. Most toxic chemicals are disposed of in residential and commercial trash because they are being disposed of in small quantities. You basically do have to exceed a certain threshold before certain regulations apply to your toxic waste, such as household batteries.
We encourage consumers to recycle tech. We sometimes tack on some kind of environmental related tax or surcharge to try to cover the cost, but it is paid up front, it is a small amount and we know the fee at the time of purchase. But we don't set bear traps that can ruin your life because you put an old computer in the trash can instead of disposing of it properly, for example.
GDPR was never about normal people, it was about companies. Trying to reframe it like it's about people is disingenuous. It is supposed to protect people, yes, but from people like you company owners and executives and others who think "screw everything, I'm looking at my bottom line".
You ignored the example with food, so I'm sure you already know this.
People apparently have a hard enough time understanding invisible things such as privacy, but this goes double for those whose income depends on violating the privacy of everyone.
I'm sure we'll get a separate thread for each site that's closing, to emphasize how the (advertising) world is ending, one just needs to wait.
https://www.polygon.com/2018/4/28/17295498/super-monday-nigh...
https://digiday.com/media/gdpr-mayhem-programmatic-ad-buying...
http://money.cnn.com/2018/05/25/media/gdpr-news-websites-la-...
https://www.theguardian.com/technology/2018/may/24/sites-blo...
Try doing some basic research before asking leading questions that you don't expect responses to.
And a data access request. This has always existed, but it was a directive which was implemented in each local law, and local legislators could give (more mild) fines but almost never did.
GDPR is not new. And I'm not talking about 2016, I'm talking about the previous law from 1995 which is 95% the same for 99% of the companies.
- Yes they were. If you violated the law, even if your servers are outside, the country would claim the violation happened in their territory because the subject was in their country so the law was violated there, and they can sue you.
- Neither is GDPR. If you are outside the EU, they can't force you to pay a fine like your own government can. Without enforcement, the law doesn't really apply. (See GDPR from 2016 until now.)
Which one applies depends on a bunch of things, such as whether there's an extradition treaty and whether you have offices in the EU, etc. I've never gotten a straight answer on which law rules in such cases, but that's probably because there is no single ruling case. Both are sovereign states, who supercedes is not codified in any law because there is no higher instance to appeal to.
I mean, if a small island state makes a law that if one of their citizens visits another country, that country should pay tribute for the honor of being visited by one of theirs, how in the world is that going to be enforced? Same with GDPR: the EU claims it applies worldwide, but the only reason that holds any truth is because you probably want to do business with EU citizens. Banning your company is the only thing they can truly do to you, and that has always been the case.
It would destroy the usefulness of a forum.
Erm, asking for a friend.
1000% increase in foreigners moving/ starting technology companies in the US.
seriously tho. great idea.
Remember Assange? He's fine as long as he stays in the embassy, but step into the back alley for a smoke and he's off to the hoosegow.
I imagine visiting an EU member would be unwise as well.
(a) you are processing data of data subjects who are in the union related to the offering of goods or services to such data subjects, or
(b) you are processing data of data subjects who are in the union related to monitoring of their behavior as far as their behavior takes place within the Union.
If you can avoid both of these, then I believe you can pretty much ignore GDPR.
If you have "no interest in doing business in Europe", it should be easy to avoid falling under (a). Recital 23 [2] discusses what it means to be "related to the offering of goods or services" to data subjects in the Union.
It means that you have to envisage offering services to such people. The mere accessibility of your website to EU people, or having an email or other contact details in the EU, is insufficient to show such intent. If you offer your website in EU languages that are not generally used in your non-EU country, accept EU currencies, mention your EU customers on your site, and things like that, will strongly suggest you are offering them goods and services.
What monitoring of their behavior means is discussed in Recital 24 [3]. It basically means tracking a person for profiling or analyzing or predicting their personal preferences, behaviors and attitudes.
Most sites selling things to end users probably don't need to do any such behavioral monitoring. If you do, just do a geoip check and exclude EU IPs. If you aren't trying to do business in Europe you probably want to do that anyway, because EU visitors are just noise in your data.
[1] https://gdpr-info.eu/art-3-gdpr/
If you can live with infuriating a small portion of your customers while have a protection that can be circumvented in a matter of seconds then geoip block is what you want, otherwise ...
Yes, that will also catch some of your existing US customers when they travel to Europe. However, you may actually want that, because the GDPR does not talk about EU citizens. It talks about data subjects "in the Union".
I haven't seen anything about what makes someone who is physically present in the EU count as being "in the Union" for GDPR purposes. One who wants to be cautious might want to count anyone physically in the EU as being "in the Union" for GDPR purposes until there is definitive guidance otherwise.
If a user publishes on your forum he has disabilities, congratulations, under gdpr you just leaked user personal data of the worst kind.
I'm really not sure what people think they're gaining from posting these wildly inaccurate GDPR comments.
It's been used to track and identify people. IIRC it's also been used in attempts to impersonate people.
So one can argue that text posts are personal data that can be used to identify them, but I suppose this is the kind of thing that is up to the court to decide.
Does that also mean then that quoted content counts? What if another user merely copies/pastes text someone said into their own reply (like you have to do on HN)?
Why do you think GDPR forces forum owners to delete posts? Which bit of GDPR do you think introduces this requirement?
That by itself is way too much hassle.
> It would destroy the usefulness of a forum.
Couldn't you just anonymize their posts, for instance by updating their username to something like "Deleted User"? Wouldn't you be fine as long as there wasn't anything left to link them to their real identity?
Those are easily handled but still if you are a hobbist it’s just too much hassle.
A general question for the GDPR experts: If user A does a request of their data and user B added a page their Instapaper account that had user A listed, does that page have to be included in the response to user A?
I didn't get an answer there. It is basically the same scenario of one user referencing another.
Just act in good faith and GDPR will not bite.
Do you have $20million to make that gamble?This is a european thing, if any law says $x is the max fine or alike, then for a first time offense you usually get much less.
The Sherman Act also mentions a ceiling of 10 million, 3 years of prison for private persons. And from history we know antitrust authorities broke up companies like AT&T or Standard Oil, which seems to me a much bigger punishment.
Both laws only mention the maximum fine.
Yet you don't see small companies sweating over competition law.
They would if it applied to them and they had to do work to comply. This is very simple. If a law applies to a company, companies will worry about it and the perceived risks. If a law doesn't apply to a company, they won't worry. Ideally, both the laws and their punishments are as narrowly scoped as possible to prevent abuse at the whims of enforcer subjectivity. It goes without saying that a business not affected by a law won't sweat it like they might if affected by a law. Couple that with ambiguities in the legislation and effort to comply and it's clear why small businesses sweat one and not the other. It's a very poor comparison.
Had you read the GDPR you'd knew that punishment is proportional to the offense, had you read the regulation in charge of receiving complaints you'd know that they said they will first give a chance to comply to the law before resorting to punishment. The only ambiguity is in the broad term "legitimate interest" offering exemption to GDPR.
now understand that fines are proportionate to the offense. Are you engaging in doing very bad thing to personal data on a very large scale and having a business based on this ?
no ? then what are you afraid of ? that failing to answert to one guy asking for what data you have on him will cause you to be fined to bankruptcy level ? I pity the fool as said that one guy.
Or how about: I'm sure the advocates for civil asset forfeiture made similar arguments.
If you want to argue that prosecutors on your side of the pond are impervious to corruption, well, consider that you're including Spain, Italy, and Greece in that body politic (at least for now).
https://government.diginomica.com/2017/08/10/ico-maximum-fin...
Then again you can stop brandishing this FUD as this kind of fine is not gonna happen to small actors. If you act in good faith and are found doing something wrong you'll receive a notification asking you to fix the issue.
Why do people think EU is dumb and will start distributing 20M fines right and left at the first offense ? Just look at how it's done up until now and what CNIL said about how GDPR will be applied.
I think this is the really important bit that Americans are missing.
We've had decades of regulation from ICO, and we've seen them do fuck all about a lot of stuff. GDPR isn't going to change their approach.
Lawsuits are used in a lost of western and eastern countries to try and right wrongs. Many of them use lawsuits to troll and money grab as well. It's not unique to the US.
This limitations means there's less frivolous litigation in the EU, unless it's a rich person or entity trying to silence someone, then they will waste money on frivolous litigation until the other party is unable to take it anymore (SLAPPs) a well known example of this is what happened to journalist Denis Robert who went through 10 years of multiple litigations in several countries for daring to expose the money laundering scheme happening in the European banking system in Luxembourg.
As if he read all laws of his own country that apply to him. Raise your hand if you actually read and comprehend all laws that apply to you. I'm willing to bet there's not a single person on this planet who really reads and comprehends all laws completely.
Usually you just go with common sense and reading a blog post or two when it seems relevant: that usually makes compliant and in the worst case it will get you a warning from the regulator (they give warnings for unintentional first-time violations, so they'll tell you if you're doing wrong and it bothers them enough (usually you're too small anyway), and you get a chance to improve).
Drone.ci is treating GDPR like any other law by steering well clear of the territory it regulates. The US also has stringent rules about online gambling, payment processing, pornography, copyrighted material, etc. Normal website operators don't become familiar with these rules or how to thread a business through them. They simply don't engage in regulated activity at all, unless making a deliberate and well-capitalized entrance with the help of lawyers and compliance professionals. (Obviously there are some high-profile counterexamples, but those are, well, high-profile).
If the GDPR were a law about data brokerage or advertising, then forum operators would be similarly far away from it. But it's a law about the handling and storage of data related to people, which you definitely do if you're running a forum. Ordinary websites have never been that close to the boundaries of legality before, so people are scared.
1: https://www.linkedin.com/pulse/nightmare-letter-subject-acce... 2: https://jacquesmattheij.com/so-your-start-up-receive-the-nig...
A letter from the NSA is a completely different story. You definitely need to hire a lawyer, probably an expensive one. One NSA letter could easily shut down a small startup.
The regulation makes repeated reference to proportionality.
> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.
For a simple forum this is a simple privacy policy.
And forums should already have something like this if they're complying with EG US COPPA or similar.
I’ll let you figure out the rest.
https://gdpr-info.eu/recitals/no-18/
> This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
I’m sorry that this is a distinction you weren’t able to make.
The forum owner should create a simple privacy policy that details what information is gathered; why it's gathered; how long it's kept; and how to correct mistakes.
If someone does report the forum to the regulator all that'll happen is that a letter will be written asking the forum to come back into compliance, and giving advice about doing so.
GDPR makes many references to proportionality. It also mentions standard practice.
EG here: https://gdpr-info.eu/art-24-gdpr/
> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.
> Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
> Adherence to approved codes of conduct as referred to in Article 40 or approved certification mechanisms as referred to in Article 42 may be used as an element by which to demonstrate compliance with the obligations of the controller.
Now if I was legally required to act on every request in 30 days or face potential litigation, that's a totally different story. I'm doing something that's a fun hobby of mine for free that will benefit others with similar interests. The line is drawn when it can have real world consequences and take up a substantial amount of personal time in order to comply with frivolous requests. That's when it stops being fun and definitely not worth risking legal headaches.
That's not what happens though. You get a request, you have 30 days to respond to it (and for the vast majority the privacy policy is ok as a response) and if the requester isn't happy they report it to the regulator who writes for more information. In that situation you again send off your privacy policy, maybe with a bit more detail.
The regulator either tells you that you're wrong, and explains why, and gives you advice to come back into compliance, or agrees with you and tells the requestor that they've misunderstood the law.
And all of this has provisions for proportionality. The regulators will recognise that small forums run for small projects will not have resources to respond to many requests.
You could credibly argue that the sole purpose of a forum is to collect and share personal data.
I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people don't have.
Another issue seems to be that he is afraid of repercussions and is conditioned in the US system where everyone seems to be suing everyone all the time.
I strongly suspect this sufficient. Maybe it would be ideal to offer a "delete account" and "download account" button.
But there is no reason you should be processing letters from people.
I'm not even sure you need to offer removal of public information. But allowing deletions of accounts is hardly controversial.
How? I can only delete for a small amount of time after posting. I cannot delete any of my past comments. If there is an option to remove old(er) comments I would sure like to know about it, seems to be hidden pretty well.
Technically, I suspect, this would be true. The GDPR and the right to be forgotten are subtle on this. If a user chooses, unprompted, to share PII it's not clear that collection has taken place. Imagine a user, out of the blue, uploads her bank account information to a forum and others take the credentials and steal or her money. Would anybody seriously believe that the business should be liable for failing to secure the PII data? The other question is whether such data can be said to be processed. Clearly the forum is not processing the PII data as PII data. It's likely the case that the business doesn't know that any given forum contains PII data.
The GDPR also gives businesses a lot of lee way here. Erasure requests can be rejected under "freedom of information", if they cause undue burden a fee can be demanded, or if they're just frivolous they can be outright refused [1].
Admittedly this is speculation. European regulation is rules-based and a lot of leeway is given to regulators. The right to be forgotten is probably the least concrete aspect of the law. It's not clear how it intersects with user-generated content because it's not clear that PII is even being collected here. In the end, I suspect the regulators and the courts would probably be open to good faith efforts towards compliance. This might take the form of removing account data (username, emails, profile pictures) but leaving the forum posts up. If a specific forum post is believed to contain PII the business might ask the user to explain how the data in the post could be used to personally identify them as a data subject.
[1] https://ico.org.uk/for-organisations/guide-to-the-general-da...
Yes: look at the reaction to Facebook "leaking" personal data through a well-documented public API.
Why are US companies/citizens overreacting so much? I haven't seen any company or sideproject from a different country react this way. (please let me know if I'm wrong)
GDPR is about personal information, not private information. Personal information is anything relating to an identified or identifiable person. Your forum account username, password, posts, private messages, votes, etc. are all in GDPR scope. If it's possible to use the same username, password, and writing style, etc. across the internet then at least some forum users are "identifiable" whether or not they have provided a real name, phone number, or anything like that.
Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer.
I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.
Bad news: If you have a business, people can attempt to sue your business for whatever they want, and you might have to defend against it. There is nothing on the books that says lawsuits have to be reasonable before they can be filed, only that people who abuse the legal system get punished AFTER a court decides they're a moron.
And in fact even filing a frivolous case can result in fines or jail time for contempt.
So no, you can’t in practice sue someone for anything.
I don't know if it's a social thing or a legal thing or some combination or what, but apparently it's harder to sue in other parts of the world.
That seems like a pretty broad policy... someone could all the time for any reason no matter how good a reason.
It's sort of like the "never roll your own security" advice that gets brought out when people ask questions about crypto. To a certain extent, yeah, we do have to roll our own security. Of course developers need to roll their own stuff, at least at the integration level.
But as soon as it gets even slightly dangerous, I'm not going to be doing, say, my own XSS filtering. I need a vetted library at that point.
I've been taught to think of the law the same way - you don't roll your own legal advice.
So why not roll your own?
Which bit of GDPR introduces that risk?
I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix.
That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.
Look at the US COPPA, with potentially $41,000 per violation. Why isn't this more scary for American website operators? https://www.ftc.gov/tips-advice/business-center/guidance/com...
> A court can hold operators who violate the Rule liable for civil penalties of up to $41,484 per violation. The amount of civil penalties a court assesses may turn on a number of factors, including the egregiousness of the violations, whether the operator has previously violated the Rule, the number of children involved, the amount and type of personal information collected, how the information was used, whether it was shared with third parties, and the size of the company. Information about the FTC’s COPPA enforcement actions, including the amounts of civil penalties obtained, can be found by clicking on the Case Highlights link in the FTC’s Business Center.
I mean, any US website that's compliant with COPPA should find GDPR to be a doddle.
https://corporate.findlaw.com/law-library/ftc-imposes-larges...
The equivalent reaction for GDPR would be if everyone either started making half-hearted efforts to block European users (which isn't what EU wants), or if everyone forced all of their users to agree to the same data collection before they signed up (which as far as I can tell is not legal).
From the law:
> However, an operator of a general audience site or service that chooses to screen its users for age in a neutral fashion may rely on the age information its users enter, even if that age information is not accurate.
This line is basically the entire reason why COPPA is generally not seen as a problem for US businesses.
Are we sure about that? GDPR seems like a gift to European startups who don’t like American competition. BlaBlah car in France got huge, incidentally right around the time the anti-Uber hysteria in France reaches a peak. The sale of Daily Motion to Yahoo was blocked by the French government under ridiculous national economic interest grounds. Europe loves tariffs and trade barriers and they have a history of “protecting” the public from competition. Try shipping spare parts for a child’s stroller to France — I was taxed at 50% — the tax even applying to the shipping fee, not just the parts. My dad made the mistake of sending kids clothes to my kids with the tags still on them — $100 worth of clothes cost me €65 in duties. When I ship small amounts of stuff to the US, I literally have never had to pay a tax. The EU loves protectionism. Farmers literally set fires and throw rocks when Spanish wine crosses into France and the authorities don’t prosecute a single person. Now that EU countries have a bunch of lotteries tickets with American tech companies, the governments are likely foaming at the mouth with excitement over fining American companies. And, sadly, many people in Europe actually think this is about privacy.
American startups have less to worry about than european ones, they have their non-GDPR market to address and grow, and we'll see in the future if extra european companies get fined (AND effectively pay) because of GDPR
Otherwise the only person that seems to be "foaming a the mouth" is you, in this ridiculous Murica rant.
Do I need to remind you that your country is just starting an economic war on the rest of the world with illegal customs taxes ? Also, enjoy getting scammed by your own ISPs now that net neutrality effectively got cancelled on you.
You don't realize how little Europeans care about your precious American tech companies, and more about values such as not being the data points of international megacorps with shady business practices, or low-end programmers ready to milk people of all their data just to install a phone game.
I mean carpooling was about solidarity and ecology, then blablacar seized the market and turned it into "no mobile phone, no credit card, no access to carpooling", "give us money first". I used to carpool before blablacar and many times I did not ask that much money or even no money at all, sometimes I got barter out of carpooling. Or the other way around, people enjoyed my company and refused my money. Now this social link is over because everybody is using blablacar and blablacar requires expensive upfront payment.
I hate how blablacar turned something that was about helping each other and bringing people together into a capitalist profit making venture aiming for world market domination.
So you just hate it because it's a company and it's making money. Right ?
> I mean carpooling was about solidarity and ecology, then blablacar seized the market and turned it into "no mobile phone, no credit card, no access to carpooling", "give us money first".
BlaBlaCar single-handedly created the huge carpooling market that now does exist in France for example. They didn't seize the market, people gave it to them. There are still other carpooling websites which you can use, and carpooling panels in events are still a common thing.
Up-front payment, not directly giving out people's phone number : you pretend this is bad practice, but this is exactly the security that was needed to bring the masses to carpooling, and as a matter of fact it did.
You seem to dislike that people would be ok in a win-win situation, where they both get paid for their expenses, and are happy to chat with other people while doing a small move for the planet. This is what's happening.
> I hate how blablacar turned something that was about helping each other and bringing people together into a capitalist profit making venture aiming for world market domination.
This is truly misguided. The opposite equivalent to my parent, but now with an anti-capitalist idealistic view of the world. Do you not see that? People are not into this ideological warfare of yours. The "world market domination" ... of carpooling? Do you realize how ridiculous that sounds?
Please find a mindset where you are able to leave BlaBlaCar be. Seriously, these are people too, and they are providing a great service. And I'm worried people, just like you do, are too prone to ranting on companies for all the bad reasons. The very reason you're using the excessive word hate, to me, seems to prove you're personalizing the entity and are a bit out of the rational realm in your claims.
I think you are misremembering here, when blablacar started and was called covoiturage.fr there were a variety of other carpooling websites, some having been around for several years notably covoiturage.com. At the time carpooling through websites was on the rise and many competitors existed (123envoiture.com, easycovoiturage.com, vadrouille-covoiturage.com, and more), all were free to use. I remember because I was an active user of pretty much all of those sites. covoiturage was one website among others and not the most popular, then came Frédéric Mazzella who bought covoiturage.fr and create a company Comuto to operate it with the intent of aggressively capturing the carpooling market.
first step was to offer the service for free and build a community around it while buying the competitors, next step was to push the remaining competitors out of business with the network effect and use the fear card to position blablacar as a unavoidable middleman (so people could not communicate directly and strike a deal outside the website as was the usage until that point), then pivot from free to paid for. Last step is domination of the market and increasing prices to very expensive as there is no competition as Mazella explained in an interview:
"Pour l'instant, seul les services Français et Espagnol sont payant, pourquoi ne pas toujours commencer avec le modèle économique ?", Kevin Deniau.
"Tout est un problème de masse critique et d'absence d'offre de covoiturage", Frédéric Mazella.
F.Mazella n'a pas souhaité dire que le passage en mode gratuit de Blablacar est uniquement pour capter l'attention des utilisateurs et qu'une fois le marché écrasé et dominé sous couvert de gratuité, le système payant se mettait en place. Ce fut le cas en France de manière progressive pour faire passer la pilule et c'est la même chose en Espagne, où la fronde s'organise petit à petit. https://blogs.mediapart.fr/evenstrood/blog/110714/covoiturag...
I'm not saying anything about bad practice (good or bad is a relative notion), I'm saying that blablacar destroyed the social component of carpooling to turn it into an economic one. That blablacar put artificial barrier preventing people who need carpooling the most (people who cannot afford a smartphone or a credit card) from having access to it.
I've been doing carpooling for years and had no issues with cash payment or direct contact with other users, but suddenly blablacar marketed these as undesireable and risky and pretended there was a need to move to less freedom for more security by making them the unavoidable middleman and upfront payment, obviously the need was actually on their side and was about putting them in position to maximize profit.
And I'm not alone to have noticed this, this is quite common knowledge [1][2][3][4][5]. It's around that time that I notice a change in carpoolers, before all were people going from one place to another, now appeared people with no need to go from A to B with large vehicles taking as much passengers as possible to make as much money as possible.
You may think this is win-win situation, but it's really not[7] (also the testimony at the end of [2]), it's a business as usual situation where capitalist parasitic company turning something desireable into an economic commodity/convenience [8][9]
we'll have to agree to disagree on me despising blablacar for what they did as being misguided. Frédéric Mazella knows well what he did and he dit it on purpose with intent. I do realize how realistic and sad it is that a capitalist company killed the human potential of carpooling to try to meet ROI expectation of those who funded them while aiming for world market domination by his own admission. The social element of being human ought not to be controlled by finance.
I hope that by reading all this including sources, you understand where I'm standing and that I know what I am talking about.
[1]: http://carfree.fr/index.php/2014/07/04/la-finance-a-t-elle-t... [2]: https://comptoir.org/2015/05/08/blablacar-comment-ils-nous-o... [3]: https://blogs.mediapart.fr/evenstrood/blog/200614/blablacar-... [4]: http://alireailleurs.tumblr.com/post/89843872188/blablacar-a... [5]: http://leplus.nouvelobs.com/contribution/891698-covoiturage-... [6]: http://simplifier-la-mobilite.tumblr.com/post/112955153091/b... [7]: https://forum.quechoisir.org/frais-de-covoiturage-non-rembou... [8]: https://www.monde-diplomatique.fr/2013/10/DENOUN/49720 [9]: https://www.journaldunet.com/management/expert/60567/abus-de...
[7] is a collection of problems people encountered. I had read a few of these long time ago, and re-read them now : these seem to be situations any service linking people together would encounter, and I don't see how any other website could avoid those entirely.
[8] I can't read; [9] is quite general.
> I've been doing carpooling for years and had no issues with cash payment or direct contact with other users, but suddenly blablacar marketed these as undesireable and risky and pretended there was a need to move to less freedom for more security by making them the unavoidable middleman and upfront payment, obviously the need was actually on their side and was about putting them in position to maximize profit.
You are personnalizing BlaBlaCar as a sneaky fox whispering into people's ears, playing on their fears and need for security. BlaBlaCar's position was the result of people's acceptance of their services in free will. You cannot change that. Also, it is very clear in some of your links that BlaBlaCar targeted the conductors (this "critical" mass) with economical incentives in order to bring the market to the next level, which, again, succeeded like nothing had before. I'm not sure destroyed is really what would describe their rise if you take a broader point of view.
> I'm not saying anything about bad practice (good or bad is a relative notion), I'm saying that blablacar destroyed the social component of carpooling to turn it into an economic one.
You are appealing to relativism, and then clearly implying that social and economic components are mutually exclusive, and I'd go as far as to say you also implied which one is evil and which one isn't. I just wanted you to notice that.
Also, it's not because something isn't free that you have to be an ass about it and that it's not social; and the inverse is also true. That's not something very common in France, but you can actually charge people and, at the same time, give them a good social experience.
> That blablacar put artificial barrier preventing people who need carpooling the most (people who cannot afford a smartphone or a credit card) from having access to it.
There are no people who need carpooling the most. Everyone needs to travel around for cheap money. It kinda feels like virtue signaling from your part to imply that you think about the poorest users, as if the person talking to you wasn't.
Also, this is quite untrue. On Leboncoin you will find older or used smarpthones from 10 euros, to 100 if you want fancy ones, while the cheapest phone plans, including internet, start at 2 or 3 euros a month. This extends worldwide with 3 billion smarpthone users in the world [1]. The magic of capitalism...
Technically speaking, to counter BlaBlaCar's existing monopoly on carpooling users, you'd have to create an open-sourced meta-platform for carpooling where people can register, and choose to use either BlaBlaCar as a middleman (that's what they do best), or not, or any other company or system that has been built to do just that. Over time, you would acquire an open database of carpooling users, which would serve for the greater good. This, and only this, improves free choice and resources efficiency, without the abuse that might come from a centralized platform such as BlaBlaCar. In my opinion, destroying or hating the business that built this carpooling community (I'm sure you did your best, but realistically it didn't exist before) doesn't. I also don't think you should go so far as to despise the CEO specifically: it seems far-stretched to me, mixing your feelings with a rational situation. And I don't think it brings you any good.
Anyway, if you're ready to do the open-source meta-carpooling part, I'm interested.
[1] https://www.statista.com/statistics/330695/number-of-smartph...
blablacar exists since 2004, it was first covoiturage.fr and had became the market leader in France in 2008, in 2009 the began opening services in foreign countries, in 2011 the bought main competitor which started in 1997 and are confident that their market domination allow them to pivot from free to taking a 20% commission.
january 2012, Uber launches in France.
in 2013 they change their name to blablacar so it's the same name in the 10 coutries they operate, uber grows to operate in two cities in France.
2014: uber grows to 6 cities in France, blablacar adds ukraine, russia, brazil and gets 100 millions funding to tackle world market and now transports 1 million people per month.
2015: france his 2nd biggest market for uber in Europe with over 500k users per year, blablacar buy German competitor Carpooling, Hungarian competitor AutoHop and Mexican sart-up Rides now totalling 20 millions users in 19 countries and rises 200 millions to speed up world market deployment. UberPop is forced to suspend operation due to operating illegally by evading legal obligations.
2017: uber still operates illegally without a licence and European Court confirms the UberPop suspension while also confirming that Uber is a transportation company and has to follow laws and regulations.
As we can see here, by the time Uber arrived in France, blablacar had already seized the french market for quite some time, blablacar operates lawfully while uber evades legal obligations and kept at it despite repeated warnings which is probably the reason why it got into trouble.
And this is coming from someone who strongly dislike blablacar.
Then again if US tech companies paid their taxes instead of engaging in heavy tax evasion (hello apple, facebook, amazon, google, ...), and respected local laws maybe they would not get so much flak.
For past experience with German privacy regulators (as an example, since our old law was fairly strict too), I'll quote a recent comment of mine:
From what I know, the German DPAs (they are organized on state level) hand out like 2 fines per month each, generally way below the maxima (under old German law, the max was 300000 €), and concluding the majority of cases without a fine. E.g. from the Bavarian DPA (german doc: https://www.lda.bayern.de/media/baylda_report_07.pdf, page 151):
in the years 2015-2016 they had 173 proceedings that involved potential fines. 52 of those resulted in fines. 34 of those fines were <1k€, 13 were <10k€.
If that's the case then I suspect you'll see fewer companies panicking over time. It may just take an adjustment period for companies to realize, "Oh, this legislation isn't actually filled with hidden land mines."
https://government.diginomica.com/2017/08/10/ico-maximum-fin...
Or you can incorporate outside of the EU (Guernsey or soon enough the UK perhaps?) and ignore the GDPR. At which point we'll just wait and see if the EU has any teeth outside its jurisdiction and how it will enforce this law.
It's like you're driving too fast on the highway, but if it's just you mom complaining and not a police officer you won't get fined :)
- that said, we should all respect the speed limit, they are there for a reason.
Bigger companies do have legal teams, but smaller one can operate without ever needing a lawyer.
> Phrases like this just sound weird to me.
Are you from the USA? Because my best guess is that that's why it sounds weird to you. I almost sued a company (they paid just in time) and even then wouldn't have looked for representation, let alone for issues like these. Just read a blog post or two about GDPR. No lawyers required.
[1]: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
You might want to get in touch with fluxBB dev to get a GDPR button extracting the relevant data from the database to avoid the pain of building the db query by hand.
It gave 2 year to get conformity to something which has been effective since 1995 through a European directive. The forum owner decided to ignore this a do nothing, now he's confronted with the consequences of his choices.
But again his reaction is akin to a knee jerk reaction as he is probably in capacity to answer the request while outsourcing to a third party does remove his responsibility and obligation to answer GDPR requests just now it's gonna get a bit more complicated as he has a third party into the loop which is probably not complying either.
Those requests can be:
- Please give me all my data
- Please delete all my data
- Please stop doing things (processing) my data
Or some mix of all the above. A site owner (controller) has 30 days from receiving such a request to respond or the person making the request can report them to their Supervisory Authority (ICO is the UK Supervisory Authority, each country in the EU has their own).
For example, if you told the user why you collected the data, and you're still using it for that purpose, and you have a legitimate need to continue to do so then you don't need to delete the data. And there's an extra exemption for "exercising the right of freedom of expression and information".
* furiously delete all user's data *
This is probably gonna get you in much more trouble than you could have been initially. For example France has law telling ISP they have to collect and retain customer data and activities for a year to able to retroactively identify who did what online at what time, failing this is not a matter of a report that could lead to warning and then to a fine but years of jail time instead.
If you can completely distill a binder of a legal framework down to an "if this then that else this" sentence, you don't understand it, and your hubris is going to kill your company. If you think the correct response is "don't respond, wait until it escalates", you don't understand it and your hubris is going to kill your company. If you're doing anything worthwhile you're going to be bumping up against some law or another, and you can't just ignore it and you can't afford to not understand it. That's why you pay lawyers.
Why don't more technical people become politicians, or at least form lobbying groups or think tanks?
GDPR requires you to only gather the data you need; only keep it for as long as you need it; tell people what you're doing with it; and allow them to correct it if it's wrong. How is that too hard?
How hard is it to reply to just “a few” questions like that?
There's plenty more, but you get the idea. Anyone who says implementing this law is simple isn't implementing this law in a business of normal size and complication.
But only if that's proportionate.
https://gdpr-info.eu/art-24-gdpr/
> Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. 2Those measures shall be reviewed and updated where necessary.
> Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.
Technical fields pay a lot more and you control most of your destiny.
Politics pays nothing and you deal with bureaucracy.
Hmm.
Either you are against any laws at all and believe that corporations could provide physical security and wage wars, or you are misinformed.
If you gossip about me behind my back, is it wrong of me to ask what you told others about me? If you are a company sharing my data with other companies, should I not be allowed to demand to know with whom you're sharing my data?
If you process personal data of millions of people, wouldn't it make sense that you have to have someone in charge of watching out for their data?
If you want to track people to create profiles of them, should you not ask them whether they're actually okay with that, rather than doing it secretly?
If you accidentally lose my data and hackers could be stealing my identity or using my password, should I not be told?
These are the things covered by GDPR, or previously, the data protection directive, cookie law and the data leak reporting laws. For example, the previous cookie law was also deemed a stupid idea by a tech-illiterate government, because lots of websites started popping up cookie walls and everyone got annoyed. But the truth is, the websites with cookie walls are the ones who want to do extensive profiling beyond any normal visitor count trackers or login systems or whatever. Of course they should inform you about that.
GDPR is not much more than common sense should already tell you to do. But since corporations are not people and do not have a collective conscience, it has to be codified in laws.
While it is nice to have total control, now I need to be using my laptop to post new blog posts, and I miss having readers comment. I also feel badly that the interesting things that readers have posted are lost to the Internet.
Even with all that, as a US citizen, I approve of GDPR and I wish it were universal. As much as I miss user comments, I am fortunate to have many readers engage with me directly via email discussions.
If it was personal the GDPR doesn't apply.
links to what he thinks has been used to craft the letter he received.
Underlying issue is that guy does not have time to deal with GDPR and discourse does not offer the proper tools, so he went the easy route of outsourcing, but he overlooked that he's still probably still liable under GDPR.
After that, I request them to delete it all :)
(guys, I'm being sarcastic)
Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.
So if the ICO won't sanction a very large company for clearly violating PECR, I really wouldn't worry. They only take action if they get thousands of complaints. I very much doubt that GDPR is going to change this behaviour, but I would love to be proven wrong.
Life is full of risk and the GDPR is right down towards the bottom of things to worry about at this point if you are outside the EU. I suspect this is also the case if you are inside the EU too, but we will soon know.
I have my doubts.
I've got a handful of sites (ultimately for portfolio / coding practice type stuff) out there. Honestly it wouldn't take me too much to respond to someone's letter considering the simplicity of the site(s), not that anyone uses them.
I also really wouldn't expect any EU official to throw down the hammer on me. Personally I wouldn't panic, and I'd at least wait for the EU official to weigh in before panicking.
It's more accurate to say that when an industry doesn't self-regulate, the EU over-regulates and shoots themselves in the face. The US and China will race even further out ahead accordingly.
In the US I can easily unleash a large user data hungry AI at will, experimenting all day long with anything and everything I can come up with. I can screw with people's data in countless ways, without their permission. While this haven exists, I can rapidly learn and come up with technology and services that tech companies in the EU can't risk attempting and won't bother to contemplate.
To the point: you can still push every edge of the AI revolution in the US and China, to see what's there. That revolution is heavily built on user data. In the EU, you're in a straight-jacket at the very beginning of the revolution (one that is guaranteed to only get tighter), many years before we've even seriously begun experimenting with the fertile soil. They're fucked, the world will be dominated by AI that comes out of either the US or China, or both.
Your anxiety appears to be about American AI companies' competiveness in the face of even worse abuse of users' privacy in China than in USA.
In a race to the bottom do you really want to be the winner, no matter what?
> This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
I thought it was going to be another stupid thing like a "cookie law" (which, I hope, is going to be canceled now as we''ve got the GDPR), the recent US FOSTA or a "store all my data in my country on a government-certified server with a police backdoor" law but fortunately it absolutely is not.
I really hope non-EU countries are going to clone this law, it seems to be the second (the first being the US net neutrality policy) law I love.
If you're a startup competing against an open-source project, then this is potentially a great (not good) way to get a leg up. You get the benefit of access to the code until you don't need it anymore, then get the project shut down and reap the benefit of being the last man standing.
Sure, you might eventually run up against the license on the software you just lifted, but open-source projects can't afford the same protections that a well-funded startup has.
And if you somehow get sued for license violations, the penalties are usually more a slap on the wrist than an effective notice to knock that shit off.
I really hate the way my mind works some days.
Doesn't have to be a startup. I expect many small businesses will use it to damage competitors. It's not like it's unheard of .
>> So, there you go, that should take the sting out of answering the ‘nightmare letter’, even if not all the questions are appropriate (or appropriately worded) you can answer the bulk of them in relatively short order and with automation you can take the sting out. If this is the worst you can expect under the GDPR then that’s not so bad, and the effect might actually be positive:
- we get to know about a lot of undisclosed breaches
- it will be clear who has their house in order and who hasn’t
- if you don’t have your house in order just answering the letter will help you to get there <<
Can he not extract all that user's data and delete if that is what is being requested?
It is a request for a lot of information.
It's also not clear to me that anyone getting that letter must do what that letter says to the letter else face consequences. We haven't seen that situation tested yet (although I can get why someone might not want to test it them self) all we've seen are letters being sent from individuals to individuals. Now how any enforcement would actual play out IRL.
It says this right in the posting. >>
> In case anyone is interested, this basically described what has been happening to me: https://jacquesmattheij.com/so-your-start-up-receive-the-nig... 1.2k
> The sad thing is that one email came from the co-founder of a Startup out of Germany.
[edit]: @jcastro, I totally didn't realize that was already there, my bad.
There is an open question whether posts would need to be deleted are just anonymized from the user account. Safer to delete of course.
1: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
But they’d never do that, because their citizens still want to use the sites, so it’d be unpopular. And ineffective since people would just work around it. Apparently these pesky humans don’t care about their privacy like they should!
Plus then the EU can’t levy billions in fines.
The only benefit here is that there’s one fewer system to keep track of when it comes to tracking/deleting personal data - the need to respond to subject access requests, right to be forgotten, form letters etc remains.
I'm pretty sure you can.
> Can you send a GDPR letter to a public body
You can, for PII. One would hope they store their data anonymized.
> Should they comply or are they waived from GDPR compliance?
I think they'd need to make a pretty strong case for why they cannot anonymize your data for their work to get an exception.
Yes. They don't store personal data. All their data is strongly anonymised.
> Can you ask them to delete your data?
You can ask. GDPR does not introduce a blanket right to have your data deleted. There are a bunch of limitations to that right.
https://gdpr-info.eu/art-17-gdpr/
> Should they comply
They don't have to comply with deletion requests. i) they're not storing PII ii) if they're processing data for the reasons they've told you they do it then they don't need to delete upon request.
> or are they waived from GDPR compliance?
This isn't them being waived from GDPR compliance, this is the GDPR working the same for them as it would for any other processor.
Having said all this, "Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes"
That's not just government statistical departments, but includes university or history archives.
They should definitely name and shame them.
Then again, my remote impression is that Silicon Valley isn't that much different nowadays.
As demonstrated by the troll in this very situation, right now (assuming the filer is actually a troll).
The bad actors are still going to be bad and lie about it, the honest actors just got burdened with some of the worst legislation in recent history without it even coming from our elected officials.
It's dangerous and I don't care for having to backtrack through years worth of projects in use and figure out how they can each be GDPR compliant. It's a tax on creators time and is imo one of the worst possible things legislators can do to an emerging space (as all software is).
Who do you think can take advantage here?
The internet at it's base abstraction is a borderless medium without regard to locality. Imposing legislation by user region is a dangerous precedent as each region can now impose fee-seeking legislation on internet companies.
Sounds like Team America again.
The government's of the world are struggling with internet jurisdiction issues, currently the US is taking the stance that any act against their companies is a US matter, whereas the EU is looking at abuse of its citizens is an EU matter. Weaker states have no recourse at all. I find it hard to judge that the US stance is ethically better than the EU's
We don't elect governments over here, just Parliament and President.
Being able tho propose a law is not ther same as enacting a law, and is not the same as applying a law which is what the parent comment said.
The commission proposes legislation, the council & parliament pass it
The GDPR was formally proposed by the European Commission, but it then went to the European Parliament (where it was amended). If the European Parliament had voted against it then it would have never become law.
Instead they are being forwarded to a service that does monetize their service.
No, it is because of an overreaction to a request. If they are acting in good faith then just reply
"Here's the privacy policy. Here's the data export page."
OP could have waited for the regulator's letter before doing anything.
1: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
These aren't their natural right. Some laws are just bad independent of whether most people support or agreed to them. This is most obvious in dictatorships, but dysfunction strikes all systems.
Looks like a knee jerk reaction and missing the point that you can evade RGPD by outsourcing to a third party, one can still send RGPD requests to drone.io and owner is still responsible for answering those but now has to deal with getting the relevant data from reddit.
Of course, he probably is collecting PII, because he's using discourse. But since he says he doesn't have time to answer GDPR requests you can be pretty sure he doesn't take the time to ensure his infrastructure hasn't been owned. I'd wager he doesn't even know what PII the system he runs is collecting, so how can he be securing it on his users behalf?
It's totally reasonable for his users to ask how he's protecting their personal data. If he wants to flip tables and storm out when they ask, that's up to him. From my perspective, the system works. He wasn't making the effort his users deserve to securely store their PII, and so now he isn't storing it at all. No one had to sue anyone, no one had to go to court, and he made the sensible decision to get out of the PII game he had no business being in. Success if ever I heard it.