Discord fined €800k for failing to comply with several obligations of the GDPR
cnil.fr
cnil.fr
It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is semantically the same, the implementation shouldn’t matter.
If you send a message to a group chat those messages are now owned collectively by the group and individually by each member, the gpdr is forcing companies to delete my data because someone else asked to delete theirs.
In this case, Discord is a very centralised service. They store all of the messages centrally, so can easily comply with the request.
Other services like email may not be able to do that, so they could use that as a defence when asked why they aren't deleting all data.
But I don't see any particular reason for where exactly the line between the two should be - why wouldn't it be that I could make anything I shared with you ephemeral, a-la Snapchat? And going back to email, it was actually MS Exchange who have supported the option to "Recall this message" [0] for many years, while gmail decided to not implement anything like that.
[0] https://support.microsoft.com/en-us/office/recall-or-replace...
My thoughts:
If it's in my inbox (whether on my physical phone, or hosted for me by a service provider), I own it and I get to control it regardless who sent it / how it got there (as long as other legal pre-requisites are met, i.e. not child porn etc)
If it's in my outbox, and I want to delete my account, THOSE instances of those artifacts should be removed, whether from my physical phone or by the service provider hosting them for me. If I've sent them to others, fair game, they own THOSE instances; but I expect the service provider to remove, upon my request, the artifact instances I solely own.
The question is whether this law is closer to fuck you than it is reasonable regulation of bad behavior.
If we work on a Google Doc together should deleting your account delete my document as well? They’re both on Google’s servers and on the backend we don’t have separate copies.
Although, messages that used to @mention the user don't have their UID mangled (since @mentions are really `<@userid>`), so it'd be easy to correlate someone @pinging a deleted user and that deleted user responding to the ping. Seems like fixing this would be pretty challenging (logistically and computationally) given you'd have to arbitrarily edit other peoples' messages.
Otherwise non-profit making companies could do any privacy BS and not be fined.
If you send email to me and then delete it in your end, I'm allowed to store your email as a whole (sometimes legally obliged).
The difference is in what Discord’s responsibility is.
If Discord claimed to have deleted an account, then they shouldn’t still be publishing a post from a user. Especially if such a post could still be tied back to the historical user id.
I can understand why they’d want to keep the data (sometimes you need to keep an archive of posts for legal reasons - for a limited time). But making an archived post visible to the public is the problem.
If I delete my email account, and/or remove it from the list, there's no expectation that my prior emails are deleted for any of the other list subscribers.
The mailing list archive isn't pruned of my account and everything I ever sent will still be visible.
With Discord, all messages are in the “central archive”, there are no individual copies.
On discord there are no 200 individual "they" storing it. It's stored by discord. (Or I guess people could be manually logging their own chats, but that's not the issue at hand here.)
At first pass it might sound like some minor technical squabble about implementation details, but there is intentionality in design decisions. The legal system can not be blind to those.
Discord chose a design that put them in control of the data. I'm not saying the highly centralized nature of their design is bad, wrong, or wasn't the best choice for the product they want to build. What I am saying is that when the legal system looks at the nature of a product, it has to look beyond what's presented in the pretty UI and marketing materials. It will look at the business' processes too.
The design of email means there is an argument for the legal system that gmail is a very very popular post office. That email is a system wherein users have disparate storage areas for receiving/archiving emails, and gmail is one of many organizations that offers users the service of managing their individualized storage area on their behalf.
In the service that is email, there is nothing inherently special about gmail. In the service that is discord, discord is discord.
IRC enables Text & Attachments in text form (ie links)
Email Enables Attachments in visual (html emails)
Discord Enables Voice, Text and Attachments (Asynchronous sockets)
That's all it is. Present a Video, Picture, Voice to your visitor and you've got a new product. Just as facebook,twitter,myspace have been.
Assuming all this is correct, if a GMail user requests their account to be deleted, Google should delete that data.
Taking a mailing list as an analogy: If there is a central archive of the mailing list, you can request removal of your messages from that archive, but not from the individual recipients who originally received the message.
1. With email you send messages to a specific, finite list of recipients.
2. With email change of recipient list will not send them past messages whereas once you have access to discord channel you get access to history too.
Discord is none of that. They never tell you that your messages and media are forever. If you get banned from a server or leave, all of your stuff is still there. There is no reason for this other than eventually selling that data or other evil purposes.
I am not sure if GDPR should apply if that can't be used to trace back to you at first place.
And if this should apply. I think everyone on the earth that connect to internet are probably in danger. You visit my site and leave a message. And I am suddenly a target of GDPR, what?
Also, do GDPR actually care about internally logs? I think the requirement is the data on that platform can no longer be used to trace back to the user. But logs aren't even exposed to users.
Since GDPR, PII (Personal Identifiable Information) data has become radioactive, the less you touch it easier your life is.
2. Failure to comply with the obligation to provide information
3. Failure to ensure the security of personal data
4. Failure to carry out a data protection impact assessment
While not a direct security breach investigation, these have high impact on user data. (edit: formatting)
Interesting this is considered [Microsoft] Discord's fault and not Microsoft Windows. I quit Discord with Cmd-Q, does Alt-F4 not do the right thing on Windows? The only popular program I know evil enough to override Cmd-Q is Chrome, and I blame Apple for the failing.
Though I think here is a failure of Microsoft to improve the UI and use different symbols for closing the app and suspending it into the systray.
Either way, seems like a rather strict interpretation of 25.2. That said, I kind of welcome it. The principle of least surprise is something that should be much more strictly enforced and a lot of social apps make it way to easy to accidentally leak data into the public.
Probably because Discord implements the button, no? They configure what happens when you press "X", so their configuration is in violation, not the platform.
For example, on my Android phone, whenever the mic/camera is in use, even if the app is in the background, the OS displays a green dot in the corner of the screen and when I poke it, it tells me what is using the mic/camera. This is a good default.
I don't think Windows is culpable instead of Discord, but I do think that more protection should be built into Windows, and based on this decision, Windows could get dinged for this as much as Discord.
In my experience; quite a few programs will minimize to system tray when pressing x.
Just tested in a call with Skype. Closing the windows still has the program running, recording, and the call is still active.
Ditto Camfrog.
Ditto Paltalk.
That's because most actual programs have a 'minimize to tray on closing' option enabled by default on install.
It's been like this since 1998 or so. I've been undoing that option for at least 20 years, because when I click X I expect it to GTFO.
Pressing X or Alt-F4 sends WM_CLOSE to the window. By default this is converted to WM_DESTROY and closes the window. By default, an application with no more windows open will exit.
It's quite normal for applications to intercept WM_CLOSE, for example with a modal dialog of "Do you want to save your files?".
Over the past few years it has also become common for applications, including Microsoft Teams, to interpret "all windows closed" as "minimise to Systray". Microsoft also responded to increasing use of the systray by auto-hiding most apps in it.
The issue is not "minimise to systray" per se, it's "sending user voice when the user thought they'd closed all the windows".
(bonus stackoverflow: you can separate the behavior https://stackoverflow.com/questions/9788662/how-do-i-repurpo... )
Alt+F4 is what actually closes the window, and in Discord's case, the entire rest of the app too.
More like the past few decades. Seriously, this has been a thing (usually configurable in app settings, and common in many long-running applications like messengers and music players) for as long as I can remember.
Alt-F4 closes the _window_, not the application. If the application can 'survive' without a window, not exiting the application is the correct behaviour.
Like many (most?) applications which show a notification icon, discord hides the main window when the user presses Alt+F4 or clicks on the X instead of closing it.
This is even visible in the OS-controller Window Menu - hit Alt+Spacebar in any window of any app, and you'll see the Window menu appear, which will include an option for Close (the current window), showing that the shortcut for it is Alt+F4. This is even true for modal dialogs (if they are real Windows modal dialogs).
If I open blender and hit 'Render Image', a new Window will open with the rendered image. This does NOT spawn a new process. Hitting Alt+F4 on this window closes the window. This does NOT kill a process.
I think the expectation of Windows users is that the X does in fact quit the application, so they don't reach for Alt-F4 the same way Mac users reach for Cmd-Q when they want to quit an application.
Basing this on the common complaint of "Why does the application still stay in the Dock after I close it?" from Windows to Mac switchers.
Teams and Spotify, for example, by default don't quit. Many others have a "keep application running when window is closed".
So just the same as Microsoft Teams or the vast majority of nowadays applications.
( Then again, it's not even clear what "teams" is these days given that I've somehow ended up with 2 completely incompatible copies installed on my machine. )
They since have seem to have fixed this, but for most of the pandemic it was like as described. Very annoying at the least.
Keeping the meeting going in the background is honestly pretty crazy.
And about teams... who the heck want to be kept in a meeting if they are already ready to close the app?
They are just different mindset.
See, Apple put @ on Q on some languages[0] and you are required to press OPTION+Q to type @ and quite often you end up closing the app when you are trying to type an e-mail address. It's particularly annoying in browsers when you accidentally close the browser when you are about to complete a long form. I've overwritten the CMD-Q for Safari due to this particular reason.
The problem is people who are accustomed to Windows keyboard layouts (which matches the national norm) - they are accustomed to Alt Gr+Q for @, and the Alt Gr key is on Windows the key right next to the space bar... which means they press Cmd+Q on Macs instead out of muscle memory.
You can put in a Windows keyboard layout that restores your sanity on macOS [1] with only the small re-learning of using right Option instead of cmd, the problem is stuff like Adobe Premiere outright refuses to load keyboard shortcuts if it doesn't recognize the keyboard layout.
[0] https://de.wikipedia.org/wiki/DIN_2137
[1] https://jankarres.de/2013/07/windows-tastaturlayout-unter-ma...
I'm Icelandic and a programmer. I work with US Ansi layout keyboards. Working with Icelandic ISO layout is horrible when programming. All the "programming" keys are strewn all over the keyboard and hidden under the option layer. I think they did this to make space for the special letters in the Icelandic language. On the other hand in the US Ansi layout the "programming" keys are close to the home row.
Couple of examples, but you can find more if you want to: {} is easily accessible on the US Ansi, but Icelandic ISO it's under option+7 and option+0. ; is right under your pinky on the home row on the US Ansi, but shift+, on the Icelandic ISO layout.
The @ is also on Q on the Icelandic keyboards. Which is absolutely insane, because quitting applications in macOS you do cmd+Q and on windows I think it is ctrl+Q. On windows you have to do alt-gr+Q to get the @ symbol. But on macOS you can do both option+Q or option+2. I use the option+2. I'm not pressing that Q with a modifier combo, unless I intend on quitting something.
Alt+F4 does close the application, "X-ing" it however puts it into the system tray and it remains active, which bothered me from the first day i've been using it.
Whether closing the current window should close the application or not depends on many things, but having different behavior between Alt+F4 and the window close button would be very strange.
Anecdotally, I rarely use alt+f4 to close a window.
Alt+F4 never closed the application. Alt+F4 closes the window. That said, _some_ applications do close when their primary window is closed.
In Windows it's convention for the top right X to be "Quit Application" and equivalent to alt+f4.
It can be useful to have X close to system tray, in which case they can be configured to act that way on an opt-in basis.
I'd still expect an active call to close however, unless a very specific single-purpose thing like mumble. (Which still has "close to tray" opt-in iirc ).
The wider frustrating point is the erosion of the desktop as a whole and the abandonment of native desktop toolkits means it's a total crap-shoot now how something will behave by default, not just on this issue but a whole range of them.
However, keeping an active voice session open with no window open is definitely outside the norm - most apps with audio chat that I know have to audio chat strictly tied to a window.
Depends on the app. Some apps, specifically communication, have a convention of: "_" minimizes to taskbar, "X" minimizes to tray. The latter is used constantly because I don't want Discord sitting in my taskbar half the day, but I want to stay online (and sometimes in a voice chat with friends).
On that note, I find this point completely ridiculous given that: (A) Discord notifies you the first time you "X" it that it minimized, and (B) IM apps dating back to MSN Messenger in 2003 would do this.
EDIT: I remembered incorrectly, Windows 1.0 did not have a X button but a close button on the right side of the window.
X didn't appear until Windows 95.
Windows could handle this a bit better (e.g. different symbol than "X"), but there is nothing wrong with the behavior itself. A clear icon to indicate that the mic is in use wouldn't hurt either.
This is a case of lackluster UI that everybody got used to over the years and never fixed, not some kind of evil dark pattern thing.
Mac has its own share of applications going against the OS convention. There are quite a few third party Mac applications that annoyingly force the process to exit when the user closes the main window. There are Mac apps that are also starting to intercept ⌘Q and not exiting the process or, infuriatingly, making you hold the key down in order to actually exit (I'm looking at you, Chrome).
I wish product designers would please just stop thinking their app is uniquely special, second guessing OS conventions.
It usually closes the active window, but Discord does close the entire application for some reason.
TBF I've been saved a few times from losing all my browser state by accidentally hitting cmd-Q.
On Windows, there is no concept of applications at all, only windows. Perhaps you can try to mess with processes, but there's not even any mechanism for activation of a process that would even allow it to begin to work in any way similar to macOS's model.
So yes. Closing all windows, on Windows, is widely assumed to terminate the associated process. This is why apps like Thunderbird, for example, close entirely when you click the X, and only actually go to the system tray when you click minimize.
Interestingly, with Discord on Windows, Alt+F4 completely closes the entire app. The close button is implemented by the webpage, however, and closes to the system tray instead of actually closing the window.
It used to be like you describe, but this is a disappearing rule. An increasing amount of companies build apps designed in a way that you need to have sysadmin skills to actually terminate the program for real.
We can't expect Microsoft to require developers to implement this 'X' correctly because Microsoft itself is exploiting this loophole by keeping some of its apps alive when the user clicks the 'x' button.
This is a common trend I already mentioned here several years ago initiated by GAFAM companies to subversively rewrite the signification of common concepts that they disagree with: - "no/decline" -> maybe later - "no/decline" -> skip for now - "no/decline" -> remind me later - "close" -> sleep" / run into background - "delete data" -> hide/hide temporarily - "delete account" -> deactivate (but keep everything) - "somebody" -> best friend - "buy/pay" -> rent - "configure" -> submit your preferences, we will take that into account etc.
All these concepts are being actively stolen from the population and I am terribly saddened to see the vast majority of our regulators have absolutely no clue about the long-term consequences of this concepts being stolen/rewritten without tacit consent.
So, yes, Discord rewrote the 'x' button but to be honest: who cares? Apparently only too few.
They fined them based on violations reported by users and Discord can contest this in a court of law.
Also, that's 1 of 5 issues.
The reality is that it's not an US companies vs EU data protection law battle - it's US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Brazil, Israel, South Korea, Argentina, Japan, New Zealand, Indonesia, Uraguay, etc, all have substantial data protection legislation. The EU has an published list of countries whose data protection laws are considered equivalent to GDPR: https://ec.europa.eu/info/law/law-topic/data-protection/inte...
While it's the EU fining Discord in this case, presumably the equivalent laws in each of those countries would also come to similar conclusions everywhere else too (though so far it seems the EU has more political appetite and clout to press the issue).
There's no world where Discord or other major US companies can pull out of the EU and keep following these practices, even if that was worthwhile. To avoid having to implement data protection practices, they'd have to drop the vast majority of all international users (and in Discord's case, https://www.similarweb.com/website/discordapp.com/#traffic suggests the US is currently <30% of their user base, so that's just not happening).
We are not talking about some high-security military stuff here, it's only a chat app.
It might be a big part of your world, but I can guarantee you that if they try to pull that off nobody in any government would care.
I am pretty sure of the contrary actually: that several governments in EU have dreams of getting rid of these platform, and that they can't do it because that would be illegal.
Assume I am leaving my job and want my personal information removed from this third-party service (Slack). They say [1] "Primary Owners of a workspace or org must contact Slack to request deletion of a deactivated member's profile information.". What if I contact the "Primary Owner" before leaving my job and they ignore my request, or if I've already left and don't know how to contact them or who they are? Why can't I simply request that my personal information be removed from a completely third-party American company's database?
I thought about this out loud before, and got the response "If you are using company account, company owns the data. The data produced during company time is company's property. Company has to request for deletion. Slack is right about it."
That made makes me ask more questions:
- Is my full name, birth date, telephone number, job and other details Slack collects company property?
- Can they also sell this to other third parties, along with my social security number, which the company also collected during business hours?
- Is Slack also free to sell this data to third parties?
- Does GDPR protect your personal information ONLY if you gave it away during your free / unemployed time using your personally owned devices and ONLY to services you have admin access to?
[1] https://slack.com/help/articles/360000360443-Delete-profile-...
Slack is likely trying to operate under one of the attempts to replace the invalidated "privacy shield" framework(the current attempt is summarized here https://www.tadpf.eu/) for their European enterprise customers, and a part of this is having contracts prohibiting slack from handing out the data to any 3rd party, but your relationship here is with your former employer and not slack.
the Schrems rulings is a bit of a problem for slack here but that's not because slack is necessarily violating the GDPR directly but because the US does not live up to EU's standards for what a modern democracy is allowed to subject people to to in terms of protection against "unreasonable search and seizure"(this term actually comes form the Fourth Amendment of the us constitution but somehow the US courts don't think it applies to foreign persons or digital records held by cloud companies).
> DISCORD's behavior is different and may lead to users being heard by other members in the voice room when they thought they had left.
Yeah, that's bad
I'm not such a big fan of password policies but 6 characters with no rate-limiting seems bad as well
Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth.
1. Making it obvious that it's still active (hard to miss that a music player is... playing music)
2. Not listening to your microphone
My experience with applications that show a notification/tray icon is that about 80% of them do not shut down when closing the main window. And the ones that don't follow this pattern by default can usually be configured to work this way.
Microsoft has applications which follow the same pattern. For example the Anti-Virus runs in the background and indicates it status via notification/tray icon. Opening or closing the settings window has no effect on its operation.
In 2022, it could very well be the better choice for most users to not end a voice call just because they clicked the "X" to get rid of the window. Just like what Skype, other Voip services, and most chat services have done forever.
This ruling is a bit disappointing.
Because this is beyond UX and password policy, it's about behaviour that is bad
There are probably a bunch of regulations that dictate on what is in your car's cabin and how they work.
That's a red flag to me already.
How are these treaties enforced? All international treaties are ultimately based on trust. There is no higher authority, only elective councils of and voluntary commitment to procedures (a.k.a. promises) by sovereign states.
Specifically not even these formal promises have been given by e.g. the United States of America which to this day has signed but never ratified either the VCLT[1] or the VCLTIO[2], so is figuratively giving a lukewarm "let's see about the convenience of that when it comes up".
1: https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_o...
2: https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_o...
This happened a long time ago. And it was started by the US, I'm quite sure.
More than that, the American way to manage the "global network" is basically to impose US laws everywhere in the world.
You can receive DMCA notices outside the US, for example.
Or even crazier: https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.
Someone arrested, in the US, for a "crime" in another country, that wasn't even a crime in his country.
So it's an example of "law enforcement can and sometimes do illegally attest / cause other issues unfairly", but not really a good example of a law being imposed outside the country which made that law.
Also the fact that many major tech companies are American means that US laws are basically enforced on all of their users, which is super crazy.
Including stuff like...
https://en.wikipedia.org/wiki/CLOUD_Act
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
This includes foreign based subsidiaries!
So if the US Gov decides that Facebook needs to give something over, everything and everyone owned by Facebook, everywhere around the world, needs to comply. So Facebook Zambia needs to hand over the data to Facebook US. On paper there are some protections, but I'd really, really want to see how well they're enforced (I doubt it).
It's so bad cloud providers have pages about it:
https://aws.amazon.com/compliance/cloud-act/
Where they basically say: "yeah, it's true, we'll fight in a court of law on your behalf, because otherwise a huge chunk of you in other countries would never use us".
if a EU user is in the US ON HOLIDAY! and they're using your service, you're subject to the GDPR
(in theory)
A bit more unclear situation is if non-resident is visiting EU and uses services from their home country.
given "within the Union" is used separately in the next sub-article to mean physically located within, it's arguable that "in the Union" could mean citizen of
> Will I get arrested by the Polizei when I land in Berlin?
Maybe also this.
> Will the US force me to pay these fines?
I am also curious.
I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn't any mention of timelines or any other definition of "necessary".
As a user, I wouldn't want my account blown away just because I haven't logged in for a while.
If this was e.g., an advertiser I don't have a direct relationship with, then yeah, purge that data! But data retention is a core of my relationship with Discord, so I want that data kept around.
That is a misrepresentation of the ruling.
2.4 million accounts not used in the last 3 years. This isn't "a while" it is a reasonable amount of time for a company to assume that someone doesn't want you to keep their data any longer unless they still have some other relationship with you or have your consent to keep the data stored until you explicitly delete it.
The regulations are to strike a balance between the needs of the business and the needs of the individual where the individual's privacy should generally win over the desires of the business.
I've had companies email me saying "log in or we'll delete your inactive account". That's a compromise I can accept.
This article doesn't specify whether Discord does this. I'm also curious whether that practice is required under the GDPR, which the article doesn't specify either.
Borders and tariffs will be the long-term future of the Internet.
I should clarify that anyone under fire regarding Schrems II either needs to convince an EU member state's court that the Cloud Act is unlikely to result in GDPR data protection issues, or that the US has no way of obtaining that information in the first place (eg. no US corporation or persons have access to EU citizen data).
Five states have passed their own privacy laws, with one in effect now and others coming online soon.
If this practice continues, and it likely will, it will soon becoming completely unmanageable for US tech companies to keep up with the myriad of state privacy laws.
At that point the federal government will likely pass a federal privacy law, which supersedes all the state privacy laws. And once we have a federal privacy law, it will likely be designed to at least be somewhat compatible with GDPR.
So, I don’t see the US going to war over this issue. I think the political winds are drifting in the other direction, and the US will follow Europe on this. Eventually.
See https://www.justice.gov/opa/pr/bnp-paribas-agrees-plead-guil...
This is a case of trade with countries under embargo.
One of the main use of internet surveillance was trade (e.g. Boeing vs. Airbus deals).
I believe the US department of justice have the right structure to make this kind of fines, part of the fines goes to found the department of justice.
There nothing new about companies enforcing their existing laws on imported goods and services and the eu-us free trade agreement's already contains clauses where both parties have to assist each other if a company is trying to evade those rules. The only thing new is that the regulators are now considering digital services to cross the border when there is money flowing the other way.
If the US were going to raise a stink they would have done so when the EU kept doubling MS antitrust fine until MS eventually paid up, issuing GDPR fines to discord that is smaller then what smaller European companies have been fined ain't going to be an issue for the trans Atlantic trade relationships. Especially as GDPR style rules are being proposed at the state level in the US.
Region locking of copyrighted material is where the real blocks in content is going to come into play(as it already have) but that is a whole different can of mud.
Sure shady people will dream up all sorts of fancy money laundering schemes to make it looks like there is no transfers but those are already illegal as fraud on both side of the Atlantic with potential jail times.
The EU don't have to block any content to efficiently enforce GDPR against US companies trying to market profitably in the EU.
The EU GDP is about 75% of the US one, it's a huge market.
And arrest you in case of visiting place within Chinese jurisdiction.
Unfun fact: there were multiple cases of people getting arrested after plane performed unexpected emergency landing in a country where landing was not planned. Both where arrest was justified and where it was not.
As a business? For sure. Not for every aspect of Chinese law, but for relevant ones and with enforcement in China or through mutual agreements with other governments.
This kind of comment is disappointing.
It shows a major lack of understanding of how law and businesses work, coated in a huge layer of outrage, all wrapped up in a Twitter-length type comment.
Also
How is this UI design? Wouldn't this fall under UX or just basic functionality? I press X, program close. If I want it minimized I press the minimize button.
Simply imagine that the user thought that, by clicking the "X" button, he closed the app and got off the vocal channel so that now nobody can hear him. Now a close relative ask him some other personnal info that he don't want to share (Health info, credit card etc..), and other people in the vocal channel hear it. Well, the user has been harmed.
So yeah, not about "disliking the UI" but about protecting you, the user
Do most users think that, though? I remember chat apps minimising to the tray bar since MSN Messenger and Skype, possibly earlier, and it's a common feature in most current ones, as well as in other applications.
Now, it's true that some other chat apps display a floating panel to remind you that you're still in voice chat, but Discord's target audience is videogame players that don't want their media covered by such panel anyway, and most other chat apps let you close or disable such panel as well. Game consoles don't do so either.
I agree with the other points in the case, but this UX design being a GDPR issue makes it clear these people are out of touch with the market.
If you click on the "x" on a open tab, it will most likely close it. If you click on the "x" on your browser, it will close the browser, maybe will it alert you that you're going to close many things.
Open Microsoft Excel or Microsoft Word, Notepad, your Windows file explorer, same thing.
Those are probably the most used app in the world, so people will assume that it is what the "x" button does.
But if I click X on my email client, it keeps receiving email; if I click X on my torrent app or JDownloader, they keep downloading; if I click X on Steam, it keeps updating my games; and if I click X on a chat application, it keeps receiving messages and, yes, usually keeps voice chat open.
And BTW, browser tabs sadly do stay open in a twisted way: notifications, often malicious for the kind of users that accept the prompts without reading.
It is the wanted behaviour, of course, but I don't find it weird that having a message explaining it the first time you close the window should be mandatory.
All you've done here is repeat their reasoning for why they dislike the UI.
They keep bothering me to pay for Nitro and just pushed a notification that they've added new payment options for my country, so they're clearly targeting the EU market.
Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort?
One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answers are extremely unsatisfying.
Edit: Yes, I understand that the GDPR claims jurisdiction. But this isn't my question. My question is also not, "does Discord have customers in the EU", or even "...run servers located in the EU".
My question is only, "does Discord have an established business in the EU?" I was unable to find an answer with a short search, and I'm unsure where to look.
So even if Discord had no presence in the entire EU, no office, no worker, no nothing, it doesn't absolve the company from staying within GDPR rules for their european users.
Only way to get out of that problem is to block any user with a european IP, although even then you could have users using a VPN, not sure how this would handle before the law.
That argument has always seemed recursive to me. The law that says "having an EU user means you are under EU jurisdiction" is an EU law, so for it to apply to you, you have to be under EU jurisdiction. What's the base case?
Now, that means EU may not necessarily be able to force the company operating in a different country to pay up but if a company has any significant EU customer base, I assume they will play ball.
https://support.discord.com/hc/en-us/articles/4410339409047-...
https://www.kvk.nl/orderstraat/product-kiezen/?kvknummer=822...
This entirely renders the question of jurisdiction moot.
It's frustrating that the response to this question has been so negative. It's like even asking this question is forbidden.
If your follow up question will be "how can the EU do anything against a company that operates outside of its jurisdiction?", then the answer will be "by making it difficult for people in the EU to do business with Discord".
The EU could restrict payments to Discord for example, cutting their revenue.
Why is it so forbidden to ask this question, and know this answer? It's just a basic fact.
My suspicion is that the GDPR apologists know that it's a weakness for their argument, and are afraid to debate on that.
As it so happens, funnily enough, Discord has a branch located in the EU. This could easily end the discussion of "does the EU have jurisdiction?" The answer is, yes! Discord is a company in the EU!
We shouldn't be afraid of basic facts. If our argument can't survive a simple fact, then our argument doesn't deserve to exist.