Grinder surely made much more from data sales than the 6.something million Erous it was find. The paltry fines under GDPR do nothing to dissuade this behavio. That's been a recurring theme in previous HN discussions on this topic.
Right now, I would posit that these low penalties are for show. Governments don't want to lose the economic benefit of having these companies operate in the EU and the general public can be satisfied that their governments are on top of the issue.
...sure, but they also had business expenses. Fining them for all the revenue would more or less instantly kill the company, which is hardly the goal.
https://www.reuters.com/article/us-health-coronavirus-ppp-gr...
One case, a hospital first got a warning, then a small fine and then a mid six figure fine for a case involving a single patient. You can rely on them having learned their lesson and that there will not be a third fine.
But selling it raw with the personal identifying information of the data subject is almost always a complete no-go.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
theres a background amount of radiation. its everywhere, even in higher amounts than youd expect like bananas and airplanes. no amount is safe, but the risks are neglibly small when exposure is minimized. concentrated amounts can be safe when exposure is controlled and managed with oversight programs in place. disasters can be managed with disaster programs, but its still possible that unforseen problems can cause big issues. unregulated handling can poison local populations. corporate influence on government can be a problrm.
what a comparison! there should be an award for this.
If background radiation is everywhere, how can there be no safe dose.
It’s a fun analogy, but reinforces an incorrect assumption.
The higher the level, the more full chambers?
The risk of dying increases linearly with the number of bullets you load.
A different model suggests that very low levels are either benign or even helpful.
Ah, the classic shoot yourself with small caliber bullets to build up an immunity against the larger caliber ones!
The body is hit by natural radiation all the time and so it has mechanisms for this. Not so much for macroscopic projectiles.
The question is how these mechanisms behave and whether a small amount of radiation stimulates them… and then how much, for how long, etc. It’s a complex model with multiple systems and feedback loops.
Jokes don't translate well in ASCII, sorry. It's a (I thought) well known meme.
Nothing in what others have said suggests low levels are deadly or even likely to be damaging, at leas not over the time frame of a human life as defined by the many things that can take us out.
> or even helpful.
A larger amount of something being damaging does not rule out a small amount being helpful, there just comes a point when the potential danger starts to outweigh the potential benefits. Water is very beneficial, necessary in fact, but too much of it over a short time will kill you.
In particular the linear model treats chronic exposure as all the same; X amount for a week is the same as X/52 for a year.
i wasnt aware this was contested. its what i was taught in the us nuclear navy.
> If background radiation is everywhere, how can there be no safe dose.
this is not a self-evident refutation and is a bad argument. cancer is the 2nd leading cause of death in the US, meaning there is an even higher nonlethal occurance of cancer. this is not all radiations doing, but its hardly obvious that bathing in radiation your whole life is a "safe dose"
this is exactly what i said in my original comment.
I looked up competing LNT models. TIL about radiation hormesis. theoretically, near-zero but >0 levels of radiation activate dormant repair mechanisms that not only repair radiation damage, but also non-radiation damage; this results in a healthier host. interesting.
having thought about this for all of 30 seconds, i wonder if both models arent simultaneously correct. if most radiation damage is repairable, activating dormant repair mechanisms with tiny amounts of radiation would be a net benefit. however, if there exists any possible irrepairable damage in any cell anywhere on your body regardless of otherwise functioning repair processes - which i dont know to be true but seems likely - then LNT could also be true concurrently with radiation hormesis.
Easy: there is no absolutely safe dose.
At normal background levels the chance of it causing you significant trouble before something else has long since killed you off in some other way is practically zero so there effectively a “safe enough” dose. But if you are very very unlucky background levels could cause you an embuggerance that becomes life changing or life ending.
It is more complicated than safe doses of most (but obviously not all) drugs/poisons/etc, because for most of the latter they are purged from your system in fairly short order assuming you survive the initial hit, so the next hit if there is one of equal strength is likely to have much the same effect. Radiation tends to hang around a lot longer so repeated exposure to higher levels builds up so the safe dose has to be stated “over time” rather than being simplified to a fixed dose perhaps related to your mass.
There was a village (unfortunately I can't find the reference in a quick search ATM) where there was/is an unusually high incidence of thyroid cancer which was thought to be a genetic pre-disposition as the population stated from a fairly small gene pool, but is now thought to be because the background radiation in the area is a bit higher than elsewhere due to the makeup of the local ground rocks. The difference is nothing to worry about if passing through or visiting regularly, in fact the difference is small enough not to be a major concern to the locals, but a lifetime of the extra exposure is enough to at least be visible in certain health stats.
Triuranium octoxide (Yellowcake):
Yellowcake is as radiologically harmless as natural potassium-carrying minerals or thorium-oxide mantles used in paraffin fuel lanterns.
Imagine if Hacker News would leak its user database. I assume there is not much in there, so the impact would pretty much be non existent.
This isn't about what one can do, it is about what is prudent. Grindr just learned a lesson about the difference.
I’ve thought of this way in a broader sense.
If you have any data from user data to internal data from various LOB it should be : Data is the new uranium.
Most companies have zero data controls and it ends up getting passed around everywhere and saved off by employees for their own personal use.
It's like waving money in front of people when you have no way to determine if it gets stolen or by whom.
I was raised in a family bookeeping business that handled all of the vital business data for hundreds of clients. Data protection and privacy (respect for clients) were always job #1.
This came to be my philosophy for all user data in any context. A philosophy that very few people share--and the rise of the web seems to have reversed any possibility of such a philosophy taking hold as user data became a form of currency.
Imagine your a government who doesn’t like homosexuals. Pay a fee - $5-$10m and you’ll get a list of users globally. Probably with travel patterns. Next time they enter the country, arrest or block visas before they enter.
Nah, this fine (which I don’t even know if they’ll pay) is the cost of doing business.
It's the users themselves who actively register on Grindr to announce their services and picture on the platform.
If this activity is illegal in the country of the user, the best Grindr can do, is to prevent users from these countries from registering on the platform based on their national ID, but that's basically it.
Speaking from unfortunate experience about half the men on Grindr do not put up identifying pictures. Many are in relationships with men and are cheating. And many present publicly as heterosexual or are married to women.
It's a blackmailer's jackpot.
Secondly, with the word "services" you're implying that the users are whores.
Thirdly, there are an infinite number of ways that Grindr could protect its users through the design of their app: from purely technical measures such as end-to-end encryption, or through careful informed consent about shared data and protection of people who are legally or functionally incapable of such consent.
But from your statements you just want to blame the users because you disapprove of them. I'm sure you can do better than that.
That way users would have an incentive to sue companies (i.e get rich quick). That way personal data would really have to be considered a liability if companies don't want to start giving millions to their users left and right.
When we have products that we produce that are required to keep customer data, we figure out what the _minimum_ amount of data required is to deliver the value required _to the end customer_ and do our best not to expose any more data than that.
For everything else, the goal is for our systems to hold _zero_ end customer data and _minimal_ employee data. We don’t want the liability. We do a lot of security engineering around what we do, but we want to make sure that we aren’t the source of a data breach on behalf of our customers because we aren’t holding the data in the first place.
Disclosure: I'm one of the founders of YourDigitalRights.org, a free service that makes it easy to send these sort of requests.
But if you suspect that a company is abusing your data, selling it, enriching it with data that they shouldn't have: fire away.
EU member states and representatives decided that not having certain business models is preferably. Them leaving the single market is a welcome result.
That this doesn't align with the free-for-all that was the WWW for the first two and a half decades doesn't change that, morality isn't all that hard and each and every company that crosses those lines is very much aware of it. These are not accidental misinterpretations of the law by any stretch of the imagination, they are wilful abuse.
While i do believe in being privacy conscious, i don't believe that this will be the case anytime soon (or at least until a generational shift happens). No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please.
Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around it.
> Operating in the EU is not a liability if you treat your users data in a respectful and responsible way.
I think that all of this boils down to profit margins and viewing people as just numbers on a sheet somewhere, to extract wealth from. Just look at how scummy many of the cookie banner implementations are, designers being paid to implement as many dark patterns as possible, at least up until lawsuits started.
> No business is interested in having to suddenly comply with such regulations and essentially no longer being able to utilize the data of individuals however they please.
Indeed, hence the need for regulation.
> Ergo, corporate interests will probably lead to lots of lobbying in this regard, just look at what happened with net neutrality and the advertising around it.
Sure. But since EU citizens will be enjoying those protections and US citizens will not eventually this will translate into an advantage for companies doing business from the EU and into the US. For that reason alone there will be a big incentive for the US to make a law that is symmetrical to remove this advantage.
> I think that all of this boils down to profit margins and viewing people as just numbers on a sheet somewhere, to extract wealth from.
This is a big factor, but not the only factor: data that is in isolation worthless can become very valuable or even dangerous when combined with other worthless or innocent data. There are plenty of examples of this. The balance clearly lies in protecting consumers from the fall-out of these and the more purposeful abuses. This is a matter of raising consciousness about what rights you already have, not necessarily of giving you new ones.
> Just look at how scummy many of the cookie banner implementations are, designers being paid to implement as many dark patterns as possible, at least up until lawsuits started.
Agreed. The EU did the right thing with the GDPR, it laid bare how many companies were outright scandalous in how they were dealing with the data that they were entrusted with, they were bad stewards and it is good to see this level of enforcement because that means that companies will wise up to it and find better - and cleaner - ways of monetizing their products and services. Once they have those they will realize that regulatory capture can be theirs if they lobby for these rights to be extended to everybody.
The EU is too large a market to miss out on.
Given the lack of similar regulation in the US despite the situation being so bad that unsolicited spam subsidises the postal service and that even government agencies sell user data I’m not sure there is a desire for this from the general population.
It doesn’t help that politicians rely on a lot of what would breach the GDPR to help their reelection such as targeted advertising and unsolicited (and often misleading - pretending to be written by the official itself) email and phone campaigns.
CCPA
Except it's literally the other way around. EU companies will be at a disadvantage because they cannot use the data to neither improve their service or to monetize it in some way.
>The EU is too large a market to miss out on.
Is it? Then what does that make China and the US? Or the rest of Asia? They don't seem to make nearly as many rules that require a service to change the entirety of their monetization system. If companies have to agree to EU terms then why wouldn't they do the same to China? After all, it's too big a market to ignore.
The EU keeps making more rules for all kinds of things. Eventually this is going to catch up with us - if it hasn't already done so. The EU isn't exactly the tech center of the world nor does it seem to have a great trajectory or bright future. When it comes to tech all we seem to have is cars. Everything else is foreign developed, designed, and manufactured.
As if ROHS weren’t printed on each single piece of hardware produced on the planet.
The banner is stuck on the screen and usually has a button captioned: Learn more, instead of the cancel or deny button.
I just want the damn banner out of my face. How long before browsers automatically hide (default deny cookies) the banner and give the user a way to expose it if they wish?
I feel abused and manipulated as a user when they use these dark patterns--which the law, to my knowledge, expressly prohibits.
Just to pick up on this clause - it really needn't have been sudden. The regulation was adopted just over 2 years before enforcement kicked in[0], and of course it was written and debated for a while prior to that. In the UK the ICO researched the implications (for what were then just proposals) back in 2013[1]
[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
[1] https://ico.org.uk/media/1042341/implications-european-commi... (PDF)
Before a company gets a fine, at least for now, it must do some really crazy stuff and/or refuse to cooperate with the regulators.
jesus christ. enough with this bullshit.
Data protection laws had been a thing in European countries for a decade before GDPR.
GDPR itself gave everyone two years to comply.
GDPR was published in 2016, five years ago.
There's no effing "suddenly". If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence.
> Just look at how scummy many of the cookie banner implementations are
Yes. And all of those cookie banners are illegal under GDPR.
> If this is "suddenly" for your business, and your business still hasn't figured out how to not collect (and probably sell) user data wholesale, your business deserves to be sued out of existence.
> And all of those cookie banners are illegal under GDPR.
Here's the thing: if there's profit to be made, both large and small corporations alike are going to look for ways to achieve that, many other concerns (e.g. the actual UX or even ethics) remaining with secondary importance in comparison.
It doesn't even matter that some things are illegal sometimes, depending on how likely it is actually to be enforced. I think that this same disposition and attitude will also extend to lobbying and trying to nudge the lawmaking processes in a direction that benefits said companies, to maximize their profits in the future.
I'm not saying that things shouldn't be more like EUs outcome (in this one regard, at least), i'm saying that they won't be like that.
Just look at the pharmaceutical industry in US, the healthcare industry as a whole, or maybe the education industry or even the military industrial complex, all of which have probably seen lots of lobbying and lawmaking that doesn't necessary benefit the general populace.
Furthermore, for some businesses it is simpler to deny access to people who are protected by GDPR, either because of compliance taking more resources then they want to allot, or simply gaining no benefit from serving them content if they cannot use tracking cookies and monetize otherwise free interaction with their content.
So rather than figuring out how to not collect and sell user data, they're struggling to find ways around the laws, so that they can keep doing that in any capacity, or in some places, just ignore the laws altogether thinking that they're too small/big to actually be persecuted.
I'm just making an effort to read past things like that and try to give the most charitable interpretation in regards to the arguments that are made.
Though yes, i also have a bit of an emotional response to seeing where this world is headed sometimes. :)
This would effectively make political interests entrenched even more on the internet, because they'll see it as worthwhile to make free services. They get to feed you politically slanted ideas - just like free political newspapers.
>Operating in the EU is not a liability if you treat your users data in a respectful and responsible way. Common sense alone would answer your questions on what is and what isn't allowed in the vast majority of the cases.
Relying on common sense is playing with fire. Common sense says that with this many people using the services of these companies that people are okay with what these companies are doing. That's not what GDPR says and that's not something I had any vote on or anything like that.
You might prefer the cable TV model, but I prefer YouTube. I like that I don't have to pay anything to go look at a large variety of topics. Far more than any paid service would ever provide.
There are many ways for websites and apps to make money, and if you can't then maybe you simply shouldn't.
Even with tracking ads get the language component wrong frequently. Unskippable ads in a language you can't understand is even worse than normal.
It does.
Moreover, the benefits of tracking for advertising are yet to be proven. Can't find it on mobile, but there have already been businesses giving up an tracked advertising because it had all the efficacy of shouting in a sandstorm.
This is too general of a statement. The majority of people in the US don't care about digital privacy and do get positive value.
Ah yes. The unsolved issue of businesses making money without wholesale collection and sale of user data.
No business ever made money until collecting and selling user data became possible.
And that somehow makes it okay to collect personal data wholesale without consent and sell it to the highest bidder?
The EUs definition of the proper way isn't a universal definition and it conflicts with the way I view that data should be treated.
Because 'dont abuse your ownership of personal data' is pretty much what it boils down to.
It tries to restrict data. Information wants to be free. It has no owner.
Private information in fact does have an owner: the user that it reflects on.
If you meant personal information then that doesn't make sense either. No one owns the fact that George Washington was male. It is just a statement that could be true or false. George Washington has no control over me spreading this information. Especially since he is dead.
George Washington's gender is of no consideration whatsoever in this discussion, so bringing it up is a variation on the theme of the strawman.
I used the word private, but not privacy. I'm not 100% sure what you are getting at.
>so bringing it up is a variation on the theme of the strawman.
It was an example of data pertaining to someone. I brought it up since I didn't think the word private made sense.
Privacy and private are very well defined terms in that context, and you are adding a unique spin on it that makes fruitful discussion impossible.
'information wants to be free' is a dumb line that got passed around a lot in the 90's by people who thought that they were being clever, but it turns out that there is lots of information that doesn't want to be free at all, and some of that information is about you and you also don't want it to be free.
Your example is nonsensical, and does not further the discussion either.
Now you're getting it. We, the European public, have decided to put anyone handling our personal data under "something similar to an NDA". We call it GDPR.
It's not about ownership. It's about my right to keep private information private. It's a right granted by law: the GDPR.
> Information wants to be free
That slogan originates in a sentence that contrasts "information wants to be expensive" (because it's so valuable) with "information wants to be free" (because it's so cheap to distribute). It's not like saying "televisions want to be free, so I think I'll steal one".
I suspect that many of the GDPR-haters here aren't people who depend on selling PII for their living; I suspect they're just jealous.
And if they are, they should be ashamed of themselves (though likely not capable of that) and shunned by all members of the industry with any ethical compass.
But to clarify: I meant to include people who aren't directly PII sellers, just workers whose employer happens to sell PII, and even website operators with an ad-network on their site. They're just trying to earn a living, and I'm sure most of them are capable of shame.
A website operator who runs Google ads and scripts on their website isn't evil. They're just "awaiting instruction".
If EU wanted to ban tracked ads, it should make a law bans tracked ads, that simple. Not only it would instantly achieve the desired effect (which GDPR did NOT), it would level the playing field for more ethical companies to thrive within the EU.
Data IS owned, by the person the data pertains to. And companies should not be able to capture that data, sell it and share it without explicit consent. Which GDPR does achieve.
This is an almost undefined concept. Data is not copyright, they are observations. Plus for many kinds of data ownership is hard to define, e.g. genetic data which is largely shared by all of us.
That's basically it. So it's not an 'undefined concept', it is extremely clear and the text of the law is actually quite legible so there is no real reason not to be informed about this if it affects you in any way (which it likely does).
Data collected indirectly to would for instance be data used to 'enrich' a profile, for instance by buying it from a third party. That data would still show up in a DSAR, but it would likely not be private data because no company is stupid enough in the current climate to sell that without a very good legal review. Data collected surreptitiously (for instance, GPS location information, device IDs and such) count as user supplied for the purpose of the GDPR, and collecting that without consent and disclosing that you are collecting it and supplying a legal basis for processing is illegal.
The idea that data is "property" or that it is "owned" by anyone is not codified in law. And as an analogy for how GDPR works, I think it's more harmful than helpful. I see GDPR as rejecting the idea that data has an owner, more than anything.
GDPR says that the data subject has rights to data about them. If you want to put a label on it, I would say that legally they are a stakeholder in their own data. One stakeholder of several. Not necessarily the most prominent one. GDPR gives you a seat at the table, but it doesn't actually put you in charge, the way that "ownership" implies.
The company that collects & processes the data is still the one making decisions like: What data is being collected? What is it used for? What is the Legal Basis for data collection? What Processors will the data be sent to? What countries will the data be processed in? They have a lot of leeway in how they answer these questions and still be compliant with GDPR.
So for that reason, my view is that GDPR says there are multiple stakeholders will different rights to how the data is handled. Which if anything is a rejection of the idea that the data has an owner. Certainly you have rights to the data, but some of those rights have limits, and the Controller still has right as well.
The data subject, as I think, is the owner. They have rights over how and when their data is used & e.g. have a right to be forgotten.
They do not, however, always have the power to exercise their 'full' rights in cases where they've entered a binding contract. Such as trying to exercise the 'right to be forgotten' with a company who provided a loan they've defaulted on. They do however have the right through law to instruct the controller to use the data in the bare minimum ways they need to reasonably execute the contract.
A reasonable data protection legislation needs to side with the controller in some situations else it would be otherwise incompatible with modern society / law.
It certainly does help more than harm imo, especially when it comes to marketing / advertising.
I think you're trying as hard as possible to misunderstand it.
- Tell people up front what you will do with their data
- Let them opt out
- Track what services your own service uses (Ex: your website -> google analytics)
- If people want to know what data you have about them tell them
- If people want you to delete their data (and there is no legal obligation to keep it) delete their data
- Take reasonable steps to keep user data safe
In this case Grindr was passing (per the article): advertising ID, IP address, GPS, location, gender, age, device information and app name to a bunch of Ad Services with "no control".
So beyond just "handling data" Grindr was getting paid (ads) for sharing your data to companies that could then also turn around and do whatever they wanted with that data.
It's disrespectful to be nosey into what people are doing or to give them orders on what they can or can't do.
>So beyond just "handling data" Grindr was getting paid (ads) for sharing your data to companies that could then also turn around and do whatever they wanted with that data.
Good on them. They figured out a way to make money using information that they collected.
>Good on them. They figured out a way to make money using information that they collected.
These two statements don't jive. Its disrespectful to be nosey, but its fine if people buy data and be nosey into other peoples lives? That's quite absurd
The first statement is about a user being nosey into what a company does with the data. There is an expectation for dating services to collect data like age, gender, etc about a user. I wouldn't really call them nosey. Since it's kind of expected for them to get that information from you. Is a dentist being nosey if they ask for your dental history?
Not just disrespectful, I would even say it's immoral given the unbalance of power involved. That's why we need GDPR: to protect people from businesses being nosey into what they are doing against their consent, and also to protect people from businesses telling them what they can and cannot decide about their own data.
Yes, operating in the EU is a liability; operating anywhere that has laws is a liability. And the risks of operating somewhere that doesn't have laws is an even greater liability.
100x this fine would have been appropriate. Anything less just encourages other companies to treat privacy and data security as a joke.
It’s not supposed to be a tax, it’s supposed to be a disincentive.
Yeah I take your point. €6.5m still seems too low to me to disincentivize though.
This way most developers would refuse to write systems that could potentially get them in trouble, until their employer transparently ensures that no laws are broken. Some kind of engineering ethics.