HNHacker News
TopNewBestAskShowJobs

cccbbbaaa

257 karma · joined March 3, 2023

GDPR expert by hn standards.
submissionscomments
cccbbbaaa··on Europol sought unlimited data access in online child sexual abuse regulation
It is, according to the EDPS. https://www.euractiv.com/section/law-enforcement/news/eu-wat...

Unfortunately, the commission doesn’t care about passing illegal legislation (DRD, the 3 EU-US transfer agreements, etc.), and the CJUE is not fast.

cccbbbaaa··on Disclosure of Pirates’ Identities “Compatible with EU Privacy Laws”
Data connection retention is 1 year in France, not 13. This sounds like something related to taxes (eg. Invoices).

(Also, this law was ruled unconstitutional but shenanigans ensued.)

cccbbbaaa··on UK Parliament undermined the privacy, security, freedom of all internet users
I don't know where your citations come from. EU law does not require such a thing. The Data Retention Directive mandated retention from 6 to 24 months, but it was invalidated by the CJUE years ago, and asserts that comparable national laws are illegal.
cccbbbaaa··on TikTok fined €345M for breaking EU data law on children’s accounts
>Good research

No. All I did was opening enforcement tracker, click on France, and look for familiar names. It was faster than writing my previous comment. I knew about one of the Carrefour cases, and the Criteo case though.

>The authoritarianism and the insanity of the laws in the first place is/are a far bigger problem

What is authoritarian or insane in GDPR? Or its previous iteration, the DPD (from 1995)? Oh no, we expect companies to handle personal data with care, the horror.

cccbbbaaa··on TikTok fined €345M for breaking EU data law on children’s accounts
France against french companies: 40M€ for Criteo, 1M€ for Total, 1M+€ for AG2R, 2M€ and 800000€ for Carrefour, 600000€ for EDF, same for Accor, two 300000€ fines for Free, 125000€ for CityScoot, 500000€ for Brico Privé, 400000€ for the RATP. Perhaps others, didn't bother to check any further.
cccbbbaaa··on How mobile apps illegally share personal data
> so doesn't the app have reasonable implicit permission to make use of the user's storage?

“Implicit permission” does not sound like “free, informed, specific and unambiguous consent”. Furthermore, the directive (ePrivacy, article 5(3)) states that consent is valid only if the user was provided with clear information about the purposes of the processing beforehand.

> does that include the app reading its own resource/assets data from its installed app-package/directory?

An app reading its own data will fall under the “strictly necessary” exception of the directive (cf. ePrivacy 5(3)). Reading other databases will depend on the purpose.

cccbbbaaa··on iPhone 12 withdrawn from French market for non-compliance with EU regulation
Yeah, but these people typically target antennas, not 3 years old phones. And don't work for the ANFR. Source: french, living in a small town with its own anti-EM association.
cccbbbaaa··on “This Is a Disaster:” Game Developers Scramble to Deal with Unity’s New Fees
I'd like to know which legal basis is used for this processing.
cccbbbaaa··on “This Is a Disaster:” Game Developers Scramble to Deal with Unity’s New Fees
The cases you are referring to are Schrems I (which cancelled the Safe Harbor transfer agreement) and II (which cancelled the Privacy Shield). But, the commission ratified a new agreement between the EU and the USA in July, the DPF. So such transfers are now possible again, without any further protections. Until Schrems III, that is.
cccbbbaaa··on The End of Cheap Europe Flights? France Proposes EU-Wide Minimum Price
Some people, like Jancovici, suggested 4 flights in a lifetime per person.
cccbbbaaa··on Privacy Nightmare on Wheels’: Every Car Brand Reviewed by Mozilla
It is possible; maybe you are mistaking it for other legal basis such as legitimate interest. Or maybe I get this wrong?

But you are right that this is illegal, because just sitting in a car is not a “specific, informed and unambiguous indication of the data subject's wishes”, which mandatory for consent (GDPR article 4(11)). Neither it is “transparent” (GDPR article 6(1)a).

cccbbbaaa··on Norway court rules against Facebook owner Meta in privacy case
And, as the article says, this proposal is likely to be illegal under the ECHR and the CFREU.
cccbbbaaa··on The EU's war on behavioral advertising
Personal data has a very wide definition under GDPR:

>‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

An IP address, or an email address is personal data. Even a pseudonym or a session ID is personal data. Yes, having a log for security purposes (GDPR recital 49) captures personal data (even just access dates and requested URLs may be considered to be personal data). Yes, a comment section on a blog may capture personal data.

Once again, I'm fine with all of this. But ignoring GDPR by not capturing personal data is more complex that it might seem.

cccbbbaaa··on The EU's war on behavioral advertising
> Spoken like a person who never even touched it even on a small project.

You can find guidance or good advice online for all of your questions.

> No cookies... so no language preferences. That is a profile cookie.

This is one of the examples of “strictly necessary” cookies, which do not require consent. See section 3.6 here: https://ec.europa.eu/justice/article-29/documentation/opinio...

> Right to erasure. What about invoices and orders? When can it be anonymous and when is it old enough to anonymize.

Invoices should typically fall under the “legal obligation” legal basis (article 6(1)c). See for how long the law requires you to keep them. In my country, it's 10 years.

>Do I get away with replacing personal data random data?

Yes, see WP216.

>Do I replace references to real people with 'anonymous person'? Will my sql constraints still work?

How do you do when someone deletes their account?

>When I restore data from backup and someone has been anonymized in the meantime, what mechanism will be used to anonymize the user after restore?

It's up to you to decide.

>Right to data portability. How much of the database and in what format?

The same as for a DSAR. As for the format, it's up to you to decide, provided it is a commonly used format.

cccbbbaaa··on The EU's war on behavioral advertising
The EU is not an uniform entity. Yes, you have citizens who sue Facebook, but then you have some members of the commission that wants to ban E2E encryption; but then, you have other members that absolutely don't want that, and the EDPS reminding everyone that it's actually illegal.
cccbbbaaa··on The EU's war on behavioral advertising
Oh, no, there's more.

You must list all kinds of data processing you perform, find the appropriate legal basis (and data retention duration, etc.), make sure you only gather data you need (data minimization), know to who you transfer data, make your services secure by default, monitor for unauthorized access, and tell affected people when there is a breach. Perhaps make a risk assessment, but it depends on the processing you do.

Yes, it's work. But quite frankly, I'm cool with a law that expects anyone who processes personal data to secure their service, to properly inform people, and holds them accountable.

cccbbbaaa··on The EU's war on behavioral advertising
It's a loophole because enforcement is a joke, but I would agree to say the basis is too vague to be useful.
cccbbbaaa··on The crash of Air France flight 447 (2021)
There is an audible “dual input”, which was triggered on this flight.
cccbbbaaa··on Friendly Captcha – GDPR-Compliant Bot Protection
If you use a captcha to secure your service, they can be. See article 4 of the ePrivacy directive. This is also said in section 3.3 of the EDPB guideline.

The issue of Google's reCaptcha, according to the CNIL at least, is that they use data collected through the service for their own purposes. See https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000047346903, point 86. Deepl translation below:

> If a data controller can claim exemption from the requirement to provide information and obtain consent when the only purpose of read/write operations carried out on a user's terminal is to secure an authentication mechanism for the benefit of users (see CNIL, FR, September 27, 2021, Sanction, no. SAN-2021-013, published), the situation is different when these operations also pursue other purposes that are not strictly necessary for the provision of a service. The Google reCaptcha mechanism is not intended solely to secure the authentication mechanism for the benefit of users, but also enables Google to carry out analysis operations, as Google itself specifies in its general terms of use.

cccbbbaaa··on Friendly Captcha – GDPR-Compliant Bot Protection
With all due respect, this is the kind of speculation I was complaining about earlier.

>Almost nothing is strictly necessary to just serve content when a URL is accessed

That's not what the law says.

> 3. Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.

Emphasis mine. It's not to just serve content, but to provide a service requested by the user. This should clear up the confusion.

Full text here: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Anyway, I provided a link from the ICO that explicitly says it's OK for user IDs, user preferences, etc.

The CNIL agrees: https://www.cnil.fr/sites/cnil/files/atoms/files/lignes_dire... See point 49.

The EDPB agrees: https://ec.europa.eu/justice/article-29/documentation/opinio...

cccbbbaaa··on Friendly Captcha – GDPR-Compliant Bot Protection
Sessions IDs _are_ personal data, it's not even ambiguous if you read the definition in GDPR (article 4(1)). You even found it on the commission's website, it should give you a clear answer.

About cookies, the relevant law is ePrivacy 2002/58/CE, article 5(3), which says you don't need to ask for consent for “strictly necessary” cookies. In practice, this means session ID cookies, user preferences, etc. This also applies to local storage or any other way to store and retrieve data on a user's device.

The issue is not that the law is unclear, it's people that can't help but speculate on its content even though they never read it. Google is full of links to this, and HN is bad in this regard. And to be honest, this is not exclusive to GDPR.

I've found Stackexchange law and /r/gdpr to be okay-ish. Otherwise, there is a guide on the commission's website, there is gdpr.eu, there is the commented version of GDPR on gdprhub.eu:

https://commission.europa.eu/law/law-topic/data-protection/r... https://gdpr.eu/ https://gdprhub.eu/index.php?title=Article_1_GDPR

You can find a lot of advice on various DPAs website (ICO, and even the CNIL publishes stuff in english sometimes).

https://ico.org.uk/for-organisations/direct-marketing-and-pr...

cccbbbaaa··on Friendly Captcha – GDPR-Compliant Bot Protection
With a visitor session ID, you can identify a single user, so it's personal data under GDPR. Yes, even if you don't have a detailed profile of them. It's not even ambiguous, it's spelled in article 4(1).
cccbbbaaa··on Friendly Captcha – GDPR-Compliant Bot Protection
I'm pretty sure a session ID is personal data since it can be linked to a specific user by the service provider (see GDPR article 4(1)), and can be processed under the “legitimate interest” legal basis (article 6(1)f).

Cookies don't violate GDPR, but are subject to ePrivacy 2002/58/CE, article 5(3). “Strictly necessary” cookies (eg. session ID cookies) are exempt from consent.

cccbbbaaa··on Norway to fine Meta $98,500 a day over user privacy breach from 14 August
>Although it took the view that “Pay or Okay” could be permissible in principle, it found that the approach taken by the news outlet didn’t comply with the law because it didn’t provide the option to specifically consent to certain purposes

Not illegal then.

cccbbbaaa··on Norway to fine Meta $98,500 a day over user privacy breach from 14 August
About GDPR and protectionism–I already answered. Sorry if I misunderstood you, I did not pay attention to the DMA and that was not the subject of the article.
cccbbbaaa··on Norway to fine Meta $98,500 a day over user privacy breach from 14 August
That's nice, but we're talking about the GDPR, a law with roots in the 70s. Not the DMA. And as I pointed out earlier, EU entities are getting fined and sued by regulators.
cccbbbaaa··on Norway to fine Meta $98,500 a day over user privacy breach from 14 August
> US companies are also sued and fined in the US for breaking these laws.

And European companies are also sued for breaking GDPR. Recently, the CNIL fined Criteo, a French adtech company, for 40M€. Multiple other fines in the 1M+€ range (Carrefour, Total, AG2R…) for French companies.

You can go on Enforcement Tracker, you will find a lot of small fines against EU entities, and few but heavy fines against US entities. I don't think this is protectionism, but rather that EU companies fare better than US companies in environments with historically strong privacy laws, precisely because they are subject to these regulations from day 1.

> They are using the data in compliance with their ToS, which is decided post-facto to be in violation of the GDPR.

A ToS is a contract, and contracts can violate the law. Nothing surprising here.

cccbbbaaa··on Norway to fine Meta $98,500 a day over user privacy breach from 14 August
It's legal in France: https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/coo... https://www.cnil.fr/fr/cookies-et-autres-traceurs-le-conseil... https://www.dataguidance.com/opinion/france-cnil-opens-door-...

In Germany too, if I remember correctly.

But if you are so sure about this, please sue so we can get rid of these cookie walls!

cccbbbaaa··on PSA: Intel Graphics Drivers Now Collect Telemetry by Default
Graphics drivers, at least on unices, come in two parts: one in the kernel, another one in the userspace. The latter provides interfaces such as Vulkan. That said, ANV (Intel's driver) is part of mesa, and not bespoke like nvidia's. But that's a moot point: this telemetry component is not a part of the actual driver, but another separate program in the package.
cccbbbaaa··on The U.K. government is close to eroding encryption worldwide
Do they really get fined for this by a DPA or a court in Germany? Is it not one of these shady lawyers sending an invoice for “providing legal advice”? I (and people I “know”) reported countless uses of Google Analytics to our DPA, back when Schrems II was still effective, and all they did was send a bunch of letters. Anyway, GDPR is getting enforced, even if DPAs are slow. Not sure what your point is here.
← PreviousPage 4 of 6Next →