Grindr €6.5M fined for not collecting users’ valid consent for sharing data
gdprhub.eu
gdprhub.eu
Grinder surely made much more from data sales than the 6.something million Erous it was find. The paltry fines under GDPR do nothing to dissuade this behavio. That's been a recurring theme in previous HN discussions on this topic.
Right now, I would posit that these low penalties are for show. Governments don't want to lose the economic benefit of having these companies operate in the EU and the general public can be satisfied that their governments are on top of the issue.
...sure, but they also had business expenses. Fining them for all the revenue would more or less instantly kill the company, which is hardly the goal.
https://www.reuters.com/article/us-health-coronavirus-ppp-gr...
One case, a hospital first got a warning, then a small fine and then a mid six figure fine for a case involving a single patient. You can rely on them having learned their lesson and that there will not be a third fine.
But selling it raw with the personal identifying information of the data subject is almost always a complete no-go.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
theres a background amount of radiation. its everywhere, even in higher amounts than youd expect like bananas and airplanes. no amount is safe, but the risks are neglibly small when exposure is minimized. concentrated amounts can be safe when exposure is controlled and managed with oversight programs in place. disasters can be managed with disaster programs, but its still possible that unforseen problems can cause big issues. unregulated handling can poison local populations. corporate influence on government can be a problrm.
what a comparison! there should be an award for this.
If background radiation is everywhere, how can there be no safe dose.
It’s a fun analogy, but reinforces an incorrect assumption.
The higher the level, the more full chambers?
The risk of dying increases linearly with the number of bullets you load.
A different model suggests that very low levels are either benign or even helpful.
Ah, the classic shoot yourself with small caliber bullets to build up an immunity against the larger caliber ones!
The body is hit by natural radiation all the time and so it has mechanisms for this. Not so much for macroscopic projectiles.
The question is how these mechanisms behave and whether a small amount of radiation stimulates them… and then how much, for how long, etc. It’s a complex model with multiple systems and feedback loops.
Jokes don't translate well in ASCII, sorry. It's a (I thought) well known meme.
Nothing in what others have said suggests low levels are deadly or even likely to be damaging, at leas not over the time frame of a human life as defined by the many things that can take us out.
> or even helpful.
A larger amount of something being damaging does not rule out a small amount being helpful, there just comes a point when the potential danger starts to outweigh the potential benefits. Water is very beneficial, necessary in fact, but too much of it over a short time will kill you.
In particular the linear model treats chronic exposure as all the same; X amount for a week is the same as X/52 for a year.
i wasnt aware this was contested. its what i was taught in the us nuclear navy.
> If background radiation is everywhere, how can there be no safe dose.
this is not a self-evident refutation and is a bad argument. cancer is the 2nd leading cause of death in the US, meaning there is an even higher nonlethal occurance of cancer. this is not all radiations doing, but its hardly obvious that bathing in radiation your whole life is a "safe dose"
this is exactly what i said in my original comment.
I looked up competing LNT models. TIL about radiation hormesis. theoretically, near-zero but >0 levels of radiation activate dormant repair mechanisms that not only repair radiation damage, but also non-radiation damage; this results in a healthier host. interesting.
having thought about this for all of 30 seconds, i wonder if both models arent simultaneously correct. if most radiation damage is repairable, activating dormant repair mechanisms with tiny amounts of radiation would be a net benefit. however, if there exists any possible irrepairable damage in any cell anywhere on your body regardless of otherwise functioning repair processes - which i dont know to be true but seems likely - then LNT could also be true concurrently with radiation hormesis.
Easy: there is no absolutely safe dose.
At normal background levels the chance of it causing you significant trouble before something else has long since killed you off in some other way is practically zero so there effectively a “safe enough” dose. But if you are very very unlucky background levels could cause you an embuggerance that becomes life changing or life ending.
It is more complicated than safe doses of most (but obviously not all) drugs/poisons/etc, because for most of the latter they are purged from your system in fairly short order assuming you survive the initial hit, so the next hit if there is one of equal strength is likely to have much the same effect. Radiation tends to hang around a lot longer so repeated exposure to higher levels builds up so the safe dose has to be stated “over time” rather than being simplified to a fixed dose perhaps related to your mass.
There was a village (unfortunately I can't find the reference in a quick search ATM) where there was/is an unusually high incidence of thyroid cancer which was thought to be a genetic pre-disposition as the population stated from a fairly small gene pool, but is now thought to be because the background radiation in the area is a bit higher than elsewhere due to the makeup of the local ground rocks. The difference is nothing to worry about if passing through or visiting regularly, in fact the difference is small enough not to be a major concern to the locals, but a lifetime of the extra exposure is enough to at least be visible in certain health stats.
Triuranium octoxide (Yellowcake):
Yellowcake is as radiologically harmless as natural potassium-carrying minerals or thorium-oxide mantles used in paraffin fuel lanterns.
Imagine if Hacker News would leak its user database. I assume there is not much in there, so the impact would pretty much be non existent.
This isn't about what one can do, it is about what is prudent. Grindr just learned a lesson about the difference.
I’ve thought of this way in a broader sense.
If you have any data from user data to internal data from various LOB it should be : Data is the new uranium.
Most companies have zero data controls and it ends up getting passed around everywhere and saved off by employees for their own personal use.
It's like waving money in front of people when you have no way to determine if it gets stolen or by whom.
I was raised in a family bookeeping business that handled all of the vital business data for hundreds of clients. Data protection and privacy (respect for clients) were always job #1.
This came to be my philosophy for all user data in any context. A philosophy that very few people share--and the rise of the web seems to have reversed any possibility of such a philosophy taking hold as user data became a form of currency.
EU member states and representatives decided that not having certain business models is preferably. Them leaving the single market is a welcome result.
That this doesn't align with the free-for-all that was the WWW for the first two and a half decades doesn't change that, morality isn't all that hard and each and every company that crosses those lines is very much aware of it. These are not accidental misinterpretations of the law by any stretch of the imagination, they are wilful abuse.
While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please.
Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around it.
> Operating in the EU is not a liability if you treat your users data in a respectful and responsible way.
I think that all of this boils down to profit margins and viewing people as just numbers on a sheet somewhere, to extract wealth from. Just look at how scummy many of the cookie banner implementations are, designers being paid to implement as many dark patterns as possible, at least up until lawsuits started.
> No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please.
Indeed, hence the need for regulation.
> Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around it.
Sure. But since EU citizens will be enjoying those protections and US citizens will not eventually this will translate into an advantage for companies doing business from the EU and into the US. For that reason alone there will be a big incentive for the US to make a law that is symmetrical to remove this advantage.
> I think that all of this boils down to profit margins and viewing people as just numbers on a sheet somewhere, to extract wealth from.
This is a big factor, but not the only factor: data that is in isolation worthless can become very valuable or even dangerous when combined with other worthless or innocent data. There are plenty of examples of this. The balance clearly lies in protecting consumers from the fall-out of these and the more purposeful abuses. This is a matter of raising consciousness about what rights you already have, not necessarily of giving you new ones.
> Just look at how scummy many of the cookie banner implementations are, designers being paid to implement as many dark patterns as possible, at least up until lawsuits started.
Agreed. The EU did the right thing with the GDPR, it laid bare how many companies were outright scandalous in how they were dealing with the data that they were entrusted with, they were bad stewards and it is good to see this level of enforcement because that means that companies will wise up to it and find better - and cleaner - ways of monetizing their products and services. Once they have those they will realize that regulatory capture can be theirs if they lobby for these rights to be extended to everybody.
The EU is too large a market to miss out on.
Given the lack of similar regulation in the US despite the situation being so bad that unsolicited spam subsidises the postal service and that even government agencies sell user data I’m not sure there is a desire for this from the general population.
It doesn’t help that politicians rely on a lot of what would breach the GDPR to help their reelection such as targeted advertising and unsolicited (and often misleading - pretending to be written by the official itself) email and phone campaigns.
CCPA
Except it's literally the other way around. EU companies will be at a disadvantage because they cannot use the data to neither improve their service or to monetize it in some way.
>The EU is too large a market to miss out on.
Is it? Then what does that make China and the US? Or the rest of Asia? They don't seem to make nearly as many rules that require a service to change the entirety of their monetization system. If companies have to agree to EU terms then why wouldn't they do the same to China? After all, it's too big a market to ignore.
The EU keeps making more rules for all kinds of things. Eventually this is going to catch up with us - if it hasn't already done so. The EU isn't exactly the tech center of the world nor does it seem to have a great trajectory or bright future. When it comes to tech all we seem to have is cars. Everything else is foreign developed, designed, and manufactured.
As if ROHS weren’t printed on each single piece of hardware produced on the planet.
The banner is stuck on the screen and usually has a button captioned: Learn more, instead of the cancel or deny button.
I just want the damn banner out of my face. How long before browsers automatically hide (default deny cookies) the banner and give the user a way to expose it if they wish?
I feel abused and manipulated as a user when they use these dark patterns--which the law, to my knowledge, expressly prohibits.
Just to pick up on this clause - it really needn't have been sudden. The regulation was adopted just over 2 years before enforcement kicked in[0], and of course it was written and debated for a while prior to that. In the UK the ICO researched the implications (for what were then just proposals) back in 2013[1]
[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
[1] https://ico.org.uk/media/1042341/implications-european-commi... (PDF)
Before a company gets a fine, at least for now, it must do some really crazy stuff and/or refuse to cooperate with the regulators.
jesus christ. enough with this bullshit.
Data protection laws had been a thing in European countries for a decade before GDPR.
GDPR itself gave everyone two years to comply.
GDPR was published in 2016, five years ago.
There's no effing "suddenly". If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence.
> Just look at how scummy many of the cookie banner implementations are
Yes. And all of those cookie banners are illegal under GDPR.
> If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence.
> And all of those cookie banners are illegal under GDPR.
Here's the thing: if there's profit to be made, both large and small corporations alike are going to look for ways to achieve that, many other concerns (e.g. the actual UX or even ethics) remaining with secondary importance in comparison.
It doesn't even matter that some things are illegal sometimes, depending on how likely it is actually to be enforced. I think that this same disposition and attitude will also extend to lobbying and trying to nudge the lawmaking processes in a direction that benefits said companies, to maximize their profits in the future.
I'm not saying that things shouldn't be more like EUs outcome (in this one regard, at least), i'm saying that they won't be like that.
Just look at the pharmaceutical industry in US, the healthcare industry as a whole, or maybe the education industry or even the military industrial complex, all of which have probably seen lots of lobbying and lawmaking that doesn't necessary benefit the general populace.
Furthermore, for some businesses it is simpler to deny access to people who are protected by GDPR, either because of compliance taking more resources then they want to allot, or simply gaining no benefit from serving them content if they cannot use tracking cookies and monetize otherwise free interaction with their content.
So rather than figuring out how to not collect and sell user data, they're struggling to find ways around the laws, so that they can keep doing that in any capacity, or in some places, just ignore the laws altogether thinking that they're too small/big to actually be persecuted.
I'm just making an effort to read past things like that and try to give the most charitable interpretation in regards to the arguments that are made.
Though yes, i also have a bit of an emotional response to seeing where this world is headed sometimes. :)
This would effectively make political interests entrenched even more on the internet, because they'll see it as worthwhile to make free services. They get to feed you politically slanted ideas - just like free political newspapers.
>Operating in the EU is not a liability if you treat your users data in a respectful and responsible way. Common sense alone would answer your questions on what is and what isn't allowed in the vast majority of the cases.
Relying on common sense is playing with fire. Common sense says that with this many people using the services of these companies that people are okay with what these companies are doing. That's not what GDPR says and that's not something I had any vote on or anything like that.
You might prefer the cable TV model, but I prefer YouTube. I like that I don't have to pay anything to go look at a large variety of topics. Far more than any paid service would ever provide.
There are many ways for websites and apps to make money, and if you can't then maybe you simply shouldn't.
Even with tracking ads get the language component wrong frequently. Unskippable ads in a language you can't understand is even worse than normal.
It does.
Moreover, the benefits of tracking for advertising are yet to be proven. Can't find it on mobile, but there have already been businesses giving up an tracked advertising because it had all the efficacy of shouting in a sandstorm.
This is too general of a statement. The majority of people in the US don't care about digital privacy and do get positive value.
Ah yes. The unsolved issue of businesses making money without wholesale collection and sale of user data.
No business ever made money until collecting and selling user data became possible.
And that somehow makes it okay to collect personal data wholesale without consent and sell it to the highest bidder?
The EUs definition of the proper way isn't a universal definition and it conflicts with the way I view that data should be treated.
Because 'dont abuse your ownership of personal data' is pretty much what it boils down to.
It tries to restrict data. Information wants to be free. It has no owner.
Private information in fact does have an owner: the user that it reflects on.
If you meant personal information then that doesn't make sense either. No one owns the fact that George Washington was male. It is just a statement that could be true or false. George Washington has no control over me spreading this information. Especially since he is dead.
George Washington's gender is of no consideration whatsoever in this discussion, so bringing it up is a variation on the theme of the strawman.
I used the word private, but not privacy. I'm not 100% sure what you are getting at.
>so bringing it up is a variation on the theme of the strawman.
It was an example of data pertaining to someone. I brought it up since I didn't think the word private made sense.
Privacy and private are very well defined terms in that context, and you are adding a unique spin on it that makes fruitful discussion impossible.
'information wants to be free' is a dumb line that got passed around a lot in the 90's by people who thought that they were being clever, but it turns out that there is lots of information that doesn't want to be free at all, and some of that information is about you and you also don't want it to be free.
Your example is nonsensical, and does not further the discussion either.
Now you're getting it. We, the European public, have decided to put anyone handling our personal data under "something similar to an NDA". We call it GDPR.
It's not about ownership. It's about my right to keep private information private. It's a right granted by law: the GDPR.
> Information wants to be free
That slogan originates in a sentence that contrasts "information wants to be expensive" (because it's so valuable) with "information wants to be free" (because it's so cheap to distribute). It's not like saying "televisions want to be free, so I think I'll steal one".
I suspect that many of the GDPR-haters here aren't people who depend on selling PII for their living; I suspect they're just jealous.
And if they are, they should be ashamed of themselves (though likely not capable of that) and shunned by all members of the industry with any ethical compass.
But to clarify: I meant to include people who aren't directly PII sellers, just workers whose employer happens to sell PII, and even website operators with an ad-network on their site. They're just trying to earn a living, and I'm sure most of them are capable of shame.
A website operator who runs Google ads and scripts on their website isn't evil. They're just "awaiting instruction".
If EU wanted to ban tracked ads, it should make a law bans tracked ads, that simple. Not only it would instantly achieve the desired effect (which GDPR did NOT), it would level the playing field for more ethical companies to thrive within the EU.
Data IS owned, by the person the data pertains to. And companies should not be able to capture that data, sell it and share it without explicit consent. Which GDPR does achieve.
This is an almost undefined concept. Data is not copyright, they are observations. Plus for many kinds of data ownership is hard to define, e.g. genetic data which is largely shared by all of us.
That's basically it. So it's not an 'undefined concept', it is extremely clear and the text of the law is actually quite legible so there is no real reason not to be informed about this if it affects you in any way (which it likely does).
Data collected indirectly to would for instance be data used to 'enrich' a profile, for instance by buying it from a third party. That data would still show up in a DSAR, but it would likely not be private data because no company is stupid enough in the current climate to sell that without a very good legal review. Data collected surreptitiously (for instance, GPS location information, device IDs and such) count as user supplied for the purpose of the GDPR, and collecting that without consent and disclosing that you are collecting it and supplying a legal basis for processing is illegal.
The idea that data is "property" or that it is "owned" by anyone is not codified in law. And as an analogy for how GDPR works, I think it's more harmful than helpful. I see GDPR as rejecting the idea that data has an owner, more than anything.
GDPR says that the data subject has rights to data about them. If you want to put a label on it, I would say that legally they are a stakeholder in their own data. One stakeholder of several. Not necessarily the most prominent one. GDPR gives you a seat at the table, but it doesn't actually put you in charge, the way that "ownership" implies.
The company that collects & processes the data is still the one making decisions like: What data is being collected? What is it used for? What is the Legal Basis for data collection? What Processors will the data be sent to? What countries will the data be processed in? They have a lot of leeway in how they answer these questions and still be compliant with GDPR.
So for that reason, my view is that GDPR says there are multiple stakeholders will different rights to how the data is handled. Which if anything is a rejection of the idea that the data has an owner. Certainly you have rights to the data, but some of those rights have limits, and the Controller still has right as well.
The data subject, as I think, is the owner. They have rights over how and when their data is used & e.g. have a right to be forgotten.
They do not, however, always have the power to exercise their 'full' rights in cases where they've entered a binding contract. Such as trying to exercise the 'right to be forgotten' with a company who provided a loan they've defaulted on. They do however have the right through law to instruct the controller to use the data in the bare minimum ways they need to reasonably execute the contract.
A reasonable data protection legislation needs to side with the controller in some situations else it would be otherwise incompatible with modern society / law.
It certainly does help more than harm imo, especially when it comes to marketing / advertising.
I think you're trying as hard as possible to misunderstand it.
- Tell people up front what you will do with their data
- Let them opt out
- Track what services your own service uses (Ex: your website -> google analytics)
- If people want to know what data you have about them tell them
- If people want you to delete their data (and there is no legal obligation to keep it) delete their data
- Take reasonable steps to keep user data safe
In this case Grindr was passing (per the article): advertising ID, IP address, GPS, location, gender, age, device information and app name to a bunch of Ad Services with "no control".
So beyond just "handling data" Grindr was getting paid (ads) for sharing your data to companies that could then also turn around and do whatever they wanted with that data.
It's disrespectful to be nosey into what people are doing or to give them orders on what they can or can't do.
>So beyond just "handling data" Grindr was getting paid (ads) for sharing your data to companies that could then also turn around and do whatever they wanted with that data.
Good on them. They figured out a way to make money using information that they collected.
>Good on them. They figured out a way to make money using information that they collected.
These two statements don't jive. Its disrespectful to be nosey, but its fine if people buy data and be nosey into other peoples lives? That's quite absurd
The first statement is about a user being nosey into what a company does with the data. There is an expectation for dating services to collect data like age, gender, etc about a user. I wouldn't really call them nosey. Since it's kind of expected for them to get that information from you. Is a dentist being nosey if they ask for your dental history?
Not just disrespectful, I would even say it's immoral given the unbalance of power involved. That's why we need GDPR: to protect people from businesses being nosey into what they are doing against their consent, and also to protect people from businesses telling them what they can and cannot decide about their own data.
Yes, operating in the EU is a liability; operating anywhere that has laws is a liability. And the risks of operating somewhere that doesn't have laws is an even greater liability.
Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter.
Nah, this fine (which I don’t even know if they’ll pay) is the cost of doing business.
It's the users themselves who actively register on Grindr to announce their services and picture on the platform.
If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.
Speaking from unfortunate experience about half the men on Grindr do not put up identifying pictures. Many are in relationships with men and are cheating. And many present publicly as heterosexual or are married to women.
It's a blackmailer's jackpot.
Secondly, with the word "services" you're implying that the users are whores.
Thirdly, there are an infinite number of ways that Grindr could protect its users through the design of their app: from purely technical measures such as end-to-end encryption, or through careful informed consent about shared data and protection of people who are legally or functionally incapable of such consent.
But from your statements you just want to blame the users because you disapprove of them. I'm sure you can do better than that.
100x this fine would have been appropriate. Anything less just encourages other companies to treat privacy and data security as a joke.
It’s not supposed to be a tax, it’s supposed to be a disincentive.
Yeah I take your point. €6.5m still seems too low to me to disincentivize though.
That way users would have an incentive to sue companies (i.e get rich quick). That way personal data would really have to be considered a liability if companies don't want to start giving millions to their users left and right.
Disclosure: I'm one of the founders of YourDigitalRights.org, a free service that makes it easy to send these sort of requests.
But if you suspect that a company is abusing your data, selling it, enriching it with data that they shouldn't have: fire away.
This way most developers would refuse to write systems that could potentially get them in trouble, until their employer transparently ensures that no laws are broken. Some kind of engineering ethics.
When we have products that we produce that are required to keep customer data, we figure out what the _minimum_ amount of data required is to deliver the value required _to the end customer_ and do our best not to expose any more data than that.
For everything else, the goal is for our systems to hold _zero_ end customer data and _minimal_ employee data. We don’t want the liability. We do a lot of security engineering around what we do, but we want to make sure that we aren’t the source of a data breach on behalf of our customers because we aren’t holding the data in the first place.
In 2018 researchers found that Grindr was sharing users' HIV status and location with marketing companies: https://www.buzzfeednews.com/article/azeenghorayshi/grindr-h...
Just this year there was a scandal where an anti-gay church fired one of its officials because a homophobic publication somehow got access to his Grindr account and his location data. The details on how the data got out are not clear. https://www.vice.com/en/article/pkbxp8/grindr-location-data-...
> In light of all the relevant criteria of Article 83 described above in sections 6.3-6.4, we consider that the imposition of a fine of NOK 65 000 000 is effective, proportionate and dissuasive in the present case.
https://www.datatilsynet.no/contentassets/8ad827efefcb489ab1...
This is approximately 6.49M EUR.
>The NO DPA reviewed the fine announced in its draft decision (10,000,000 €) on the basis that the revenue of Grindr (seems to-this part is redacted) seems different and that Grindr has made with the aim to remedy the deficiencies in their previous CMP.
Draft decision: https://gdprhub.eu/index.php?title=Datatilsynet_-_DT-20/0213...
In particular, the revenue limit seems problematic. For a "normal" company whose profit margin is a relatively small fraction of revenue, 4% of revenue is huge. But for highly profitable large tech companies that make money primarily from ads, it may not be possible to issue a dissuasive fine if it is capped to 4% of revenue. Maybe "4% of revenue, or 200% of profit, whichever is higher" would be a better limit.
And after that I expect compliance will be a much easier subject. So far the whole roll-out has been exactly as I expected it to be.
Grindr made a profit of $31M and a revenue of "well over $100M". The maximum fine is 20M EUR or 4% of revenue (whichever is higher). So assuming under 500M EUR in revenue, the maximum fine is lower than Grindr's 2019 profit. So if Grindr is the lucky one that serves as an example, I don't see how even the absolute worst case fine would put them out of business.
Although the max fine is probably higher than the 2019 profit from the EU, I could totally see that changing, and someone deciding that getting slapped with the maximum fine is cheaper than the loss of revenue from complying, especially if it is a business that is entirely in ads.
Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the consent of the user is not freely given in this case - in a "Take it or leave it" situation, consent cannot be seen as freely given.
Link to the section "Consent as a condition to access the service ": https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_2...
> Sharing Grindr's users personal data with advertising partners for online behavioural advertising purposes was not necessary for the performance of the Grindr's services.
Charging money for your services is also not necessary for the performance of the said services. Still businesses are luckily still allowed to charge money. Why can't data be considered as a means of payment in this case?
It's a political decision that charging money (or displaying not personalized ads) is preferably.
So the Norge argument here would go further and I would like to see this challenged to the European Court as this would provide a final verdict.
Currently I feel that different countries see these things quite a bit different.
On the other hand it would only mean that you can't have a free version refinanced through advertising, but would need to find other ways of converting users into paying customers while still providing a striped down free app for generating reach.
Not sarcasm - I think that while it's obviously a different scale, the reasons are similar and boil down to "we don't want that as a society" and "the environment this creates is not conductive to a free and informed rational decision". Many people don't understand the value of their data and the risk it poses, there is an information imbalance, there is a power imbalance (the company sets the terms, and you only get to take it or leave it).
The pre-GDPR situation also showed that the market doesn't really work, because everyone was collecting your data, people have limited energy and incentive to care because it doesn't cause immediately visible pain. It's similar to workplace safety - we don't allow employers to create easily avoidable dangerous situation in exchange for extra pay either, for similar reasons.
Most importantly, data grabbing is not necessary for advertising, it's just slightly more profitable and thus everyone does it, eventually pushing the "good" (privacy-friendly) players out of the market. If we want to change that, we need a de-facto ban (which a properly implemented GDPR would be, because so many people will click "No" if given a truly free choice that showing the popup won't be worth it).
What is of such great importance and I can’t be allowed to exchange it at any price and I can’t be trusted to make this decision myself?
One of the biggest reason would be that using data as payment has demonstrated to push out companies that don't want to collect data. Data as a mean of payment is less clear to the consumer about the costs, and there is no real good way to inform the public outside of an massive investment into the general education that focus on privacy, data laws, how data is gathered, why it is gathered, how it get traded and used, and what the outcomes are. The value added through data is also not taxed which creates an unfair advantage compared to other payment methods.
Yes this is limiting the free market but it's a conscious decision.
It's still allowed to process data for your own analytics (e.g. to improve your offer) and make use of third party services. What the GDPR aims to prevent is your data being shared with the whole world way beyond the entity with which you originally interacted.
If that means services cannot finance themselves through advertising anymore then so be it.
Screenshot of the "consent as a condition to access the service" https://imgur.com/a/neJya1e
I was on Tinder for about a week. I was receiving dating spam for a year - not "a phishing email". Hopefully Tinder will be the next up against the wall. They're shameless.
Clearly people use the app because the app answers a user need. So what’s your answer to the user need?
That sounds pleasant. Smoking restrictions here vary greatly on a city by city basis. Unfortunately the bar scene in my city likes to pretend we aren't in a pandemic and only a few have decided to brave a smaller customer base and ban smoking.
There’s a user need. In this case it addresses the needs of a minority that’s been, until recently, highly oppressed. You don’t get to just say “things were fine before this existed”.
When something imperfect solves a real problem you don’t get to just say “oh just don’t use it”, especially when it’s not a problem YOU have. Talk about privilege!
I get to say whatever I want to say within the confines of the law and so do you. Let's keep it that way, shall we?
> What exactly is your point?
That it's still possible to get laid without a shady middleman/app
I can imagine an oppressive government buying dating app data to blackmail their users. I noticed in the Tinder TOS thread people complaining about how impossible it is to meet folks in real life.
You can still have friends, friends have friends you can go out with. I'd say from a mental health POV you should be doing social things anyway.
I'm not condoning Grindr's actions or that people shouldn't use it with care, but it really has become a key part of LGBT networking in the modern era.
The only time it was a bit weird is when a co-worker told me I look like his husband, not okay to say at work.
A female coworker told me that once, didn't seem that weird.
I wasn’t there so I wouldn’t know the tone and context, which can make a difference but... In general, how’s that problematic?
Also, strangers talking to you does not mean they’re sexually or romantically interested in you. Some people are just platonically social. Moreso in some places than others.
The whole point to Grindr is that you can meet so many people online. It's not about replacing flirting, which you're suggesting. People flirt on Grindr -- don't worry. I think you need some experience in how the hook up scene works to really understand it....
I suspect you're right. I remember the pre-disaster Love Parades if that's any indication of just how ancient and out of touch I probably am! :D
But more to the point, Grindr got in trouble specifically for selling data to advertising networks presumably so they could also be targeted outside Grindr. Knowing someone's sex, sexual orientation, location, age and hobbies is great targeting data.
I'm sure it's more complicated but the general idea is economic coercion.
Now given that, the class of proximity based apps are all regional (such as dating, dog walking, delivery, etc).
I have no idea if Grindr has a market penetration in Europe to make it worthwhile. Companies have been known to completely vacate markets instead of honor fines or fees.
If they won’t leave or pay, the EU could possibly force app stores to remove the app from their region or something similar.
You put the company on a black list, then banks or other companies in EU or that have business in EU can't send them money or work with them, I am assuming they offer some subscriptions and other paid features so the banks not working with them will hurt.
Even though Norway is not a EU country, it's part of the EEA and various other treaties with the EU and hence they ended up implementing GDPR, it seems possible that they end up being having authority to enact EU/EEA wide enforcement actions.
https://www.lexology.com/library/detail.aspx?g=34dfb199-c9ab...
In My Own Opoinion - this "surveillance capitalism" is a huge, stinking cancer on free society and is only getting started.. history will show this is absolutely true. "I have nothing to hide" people can get a free Grindr subscription for all I care.. this is a rotten situation.
In fact, anecdotally, it’s often the vocal critics of data-funded tech companies who post an archive.is version of every paywalled article.
https://docs.microsoft.com/en-us/aspnet/core/security/gdpr?v...
These built-in templates for cookie popups are a joke, IMO.
The first step in being GDPR compliant is not installing a tracking library in your project. Web frameworks have no control over that.
Edit: top of the article had an incorrect amount.
The HN headline is also "wrong" (or at least imprecise) - the fine amount is in NOK, so the euro figure is ~6.418 million depending on exchange rates.
> As such, it considered that a fine of €6,500,000 (NOK 65,000,000) was appropriate and dissuasive.