25 ms·
Shutting Down Forum (GDPR)
- hyprCoin 8y agoOverbearing legislation applied by unelected representatives is being abused. If only there were technical solutions provided with an assumption of goodwill instead of 88 pages of mandates without such an assumption.
- hood_syntax 8y agoAssumption of good will is a trap that naive people fall into. If someone can take advantage of something, it will happen.
- danShumway 8y ago> If someone can take advantage of something, it will happen. As demonstrated by the troll in this very situation, right now (assuming the filer is actually a troll).
- hyprCoin 8y agoCompletely agree in general. It's a probability thing, given enough traffic all possible events happen. That said I do not understand how these mandates protect anyone. The bad actors are still going to be bad and lie about it, the honest actors just got burdened with some of the worst legislation in recent history without it even coming from our elected officials. It's dangerous and I don't care for having to backtrack through years worth of projects in use and figure out how they can each be GDPR compliant. It's a tax on creators time and is imo one of the worst possible things legislators can do to an emerging space (as all software is).
- DanBC 8y ago> If someone can take advantage of something, it will happen. Who do you think can take advantage here?
- jimnotgym 8y agoLegislation is usually applied by unellected people. Judicial independence is usually seen as a good thing. Perhaps you mean that the law was enacted by unellected people, which is also incorrect of course? So now I don't see your point at all?
- hyprCoin 8y agoI'm not in the EU but must comply to their regulation. The internet at it's base abstraction is a borderless medium without regard to locality. Imposing legislation by user region is a dangerous precedent as each region can now impose fee-seeking legislation on internet companies.
- jimnotgym 8y agoSo what do you propose no laws at all for the internet? Or each jurisdiction makes orts own law? In which case would the US mind getting the hell back inside it's borders and stop trying to extradite British teenagers who alledgedly broke some 'hacking' law? Sounds like Team America again. The government's of the world are struggling with internet jurisdiction issues, currently the US is taking the stance that any act against their companies is a US matter, whereas the EU is looking at abuse of its citizens is an EU matter. Weaker states have no recourse at all. I find it hard to judge that the US stance is ethically better than the EU's
- hyprCoin 8y agoAny solutions should come from first level engineering principles not lawyers and politicians. I don't care if it's US prosecuting a kid for hacking, companies storing and losing information on people or a space shuttle exploding. The problem lies in the failure of software and the solution should be in software.
- hartator 8y agoThe law has been proposed by the European Commission who is just nominated not elected.
- endisukaj 8y agoHurr durr who cares about privacy anymore.
- foepys 8y agoHow are the representatives "unelected"? The European Parliament is elected every five years by the citizens of all EU member states and voted on the GDPR in 2016 after long talks. Some even say that the GDPR is not hard enough.
- petre 8y agoThe GDPR was passed by the European Comission, not the EP. Members of the EC are appointed, just like ministers in governments. But governments can only pass time limited decrees which then have to be signed into laws and voted for in Parliament. The EC which can pass binding regulations that apply indefinitely.
- synotna 8y agoI think you mean "proposed" instead of "passed" - "passed" is usually used to mean "passed a law" The commission proposes legislation, the council & parliament pass it
- deleted 8y ago[deleted]
- M2Ys4U 8y agoYou are wrong. The GDPR was formally proposed by the European Commission, but it then went to the European Parliament (where it was amended). If the European Parliament had voted against it then it would have never become law.
- M2Ys4U 8y agoYou do realise that the European Parliament is directly-elected, right?
- hyprCoin 8y agoNot by me and I do not consent. My consent does not matter, unfortunately, I must abide. Governments are good at that.
- scaryclam 8y agoI'm a little confused. Who is sending compliance requests? If it's not the ico, there's rely no problem. If it is the ico, ask what needs to change. No lawyers required.
- danShumway 8y ago> No lawyers required. Phrases like this just sound weird to me. If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. I wonder if this is a cultural difference between the US and EU? Might explain some of the different reactions people have had to the legislation.
- Sir_Substance 8y ago>If there's a risk that someone could sue you over something, from a business perspective I have always been taught that you avoid it, period, until you get a lawyer. Bad news: If you have a business, people can attempt to sue your business for whatever they want, and you might have to defend against it. There is nothing on the books that says lawsuits have to be reasonable before they can be filed, only that people who abuse the legal system get punished AFTER a court decides they're a moron.
- ryandrake 8y agoNot just businesses. Anyone can get sued for any reason. If your blanket policy really is “I won’t do anything if I risk getting sued” you literally can’t even leave your house.
- tatersolid 8y agoJudges in the US routinely dismiss frivolous cases[1] with prejudice. And in fact even filing a frivolous case can result in fines or jail time for contempt. So no, you can’t in practice sue someone for anything. [1]: https://en.m.wikipedia.org/wiki/Frivolous_litigation https://en.m.wikipedia.org/wiki/Frivolous_litigation
- 8y ago
- ggg9990 8y agoIs it legal to publish the name of the requestor? Name and shame?
- xori 8y agoUnder the banner of "transparency"!
- pkaye 8y ago> The sad thing is that one email came from the co-founder of a Startup out of Germany. They should definitely name and shame them.
- kyberias 8y agoYeah, let's not start giving people bad ideas here, m'kay? If you want to do some internet idiocy, do it yourself.
- netsharc 8y agoHaving lived in Germany, "Co-founder of a Startup out of Germany" conjures up the image of one of the many economics-degree-holding bros who strut around and "network", bullshitting everyone (themselves included) that they're going to be the next Zuckerberg. Then again, my remote impression is that Silicon Valley isn't that much different nowadays.
- djsumdog 8y agoI'm not a lawyer, but I do think he should have totally posted the letter, without redaction. We don't have enough context here.
- doseofreality 8y agoIf you post it, you'll get your own letters from him demanding you forget him or be in violation of GDPR.
- hjek 8y agoWell, if the owner of the forum is receiving request e.g. to delete accounts or to disclose what data is recorded about someone, why not just comply with the request? What's the big deal?
- xori 8y agoIf I ran a forum for a number of years, and a person decided to close their account, that'd be fine. But if they then said that I need to remove _all of their posts_, that's really shitty. It would destroy the usefulness of a forum.
- weberc2 8y agoHow does GDPR affect people in other countries with no interest in doing business in Europe? If I host a forum in the US and you ask me to remove your posts and I tell you where to stick it, what legal consequences might I face? Erm, asking for a friend.
- amyjess 8y agoAs much as I dislike Donald Trump, I am willing to hold my nose here and suggest encouraging the Trump Administration to go full MAGA and direct Congress to pass laws explicitly stating that no foreign judgements or fines may be enforced on US citizens.
- eximius 8y agoI think we understand where you're coming from, but as written this is incredibly ignorant. You're essentially rejecting all international law (copyright, patent, tax, etc).
- michaelsjoeberg 8y agoboom. 1000% increase in foreigners moving/ starting technology companies in the US. seriously tho. great idea.
- 8y ago
- tobyhinloopen 8y agoI've been sending all kinds of companies a request of my data. Everyone that keeps sending me mails without me knowing why, I just sent them a nice request to give me a copy of my data. After that, I request them to delete it all :)
- Kiro 8y agoYou're the reason we can't have nice things. I hope you are proud of yourself. GDPR is great but will be ruined by people like you.
- endisukaj 8y agoWhy? It's their data and their right to have it deleted.
- lghh 8y agoIsn't that the point of GDPR?
- hpcjoe 8y agoHonestly, laws like this give rise to the phrase "the road to hell is paved with good intentions." I am not anti-gdpr. I am quite concerned about the side effects on the small guys. Its obvious that this law was targeted at larger companies. But its also obvious that it massively increases risk profiles for innocuous behavior. This is a problem. And hey, as a person in the US, I have no representation to help address my concerns over the validity/applicability of the law. I am not a fan of that. Then again, I also don't like it when we do this to others. FATCA is an example of this, where US citizens seeking banking services were denied services due to the implied risk to the bank from non-compliance. They generally don't have much recourse either. Extra territorial impacts are the result of bad laws. I like that GDPR gives control back to the users. I dislike that it opens up such a massive legal attack surface as to make things like running a forum dangerous.
- deleted 8y ago[deleted]
- technologia 8y agoWell that sucks, I wonder if this means other discourse instances might be hit with the same GDPR letters? There'll probably be someone who has (or will have) forked discourse to make these changes.
- uptown 8y agoHow does Discourse factor into this? From my read of this, it doesn't seem to be specific to the fact that he's using Discourse.
- technologia 8y agoI thought he was using Discourse for his forum? Its not like I'm taking a shot at Discourse, I was just saying that it might be worthwhile to tack on an export function that is user facing to mitigate the onslaught of requests. [edit]: @jcastro, I totally didn't realize that was already there, my bad.
- jcastro 8y agoNot sure what version this was added to but Discourse has an export button that individual users can use from their profile page.
- matwood 8y agoIt does not appear Discourse has any admin tools in place to deal with a GDPR request. A self-service user panel would be even better. There is an open question whether posts would need to be deleted are just anonymized from the user account. Safer to delete of course.
- jabn76 8y agoPeople asking to exercise their rights on their own private information are not trolls.
- deleted 8y ago[deleted]
- xori 8y agoIn this case, you are making work for a person that doesn't monetize the platform you're using. It was service that was offered in good faith, and is now, because of this useless request, not going to be available. Instead they are being forwarded to a service that does monetize their service.
- jimnotgym 8y ago>now, because of this useless request No, it is because of an overreaction to a request. If they are acting in good faith then just reply
- oh_sigh 8y agoHow many hours should this person put in to respond to the request?
- xori 8y agoAnd to all the others.
- DanBC 8y agoAbout 3 minutes. "Here's the privacy policy. Here's the data export page."
- infinitismal8 8y agoHaha data export page, what even is that? Let me just go to my SQL DB, redis, glacier backups, and Kafka logs and just click the data export button. It will only take 3 minutes.
- simlevesque 8y agoDoes he have any proof that the person is a troll ? From what I read he just assumes it.
- spacebearmakes 8y agoWhen you receive a request that is titled the "Nightmare letter" [1] it is hard to assume otherwise. 1: https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/ https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
- kyberias 8y agoI don't think the TITLE of the letter is literally "Nightmare letter". It's the name of the letter that people copy and send.
- reaperducer 8y agoI didn't read the whole thing, but the part where the troll says he believes the site is in violation and makes threats but doesn't have any actual proof that there is a violation sounds like a good indication.
- zerostar07 8y agoHe's still obliged to respond to that letter. Can't hide like this. (guys, I'm being sarcastic)
- amyjess 8y agoAccording to his GitHub, he's in San Francisco. He's a US citizen living in the US. The EU can't touch him.
- marssaxman 8y agoDoes that continue to be true if the US citizen goes to visit an EU country? It'd really suck to get arrested on your vacation because you ignored some troll's GDPR-based harassment. I don't know how this works.
- cpncrunch 8y agoIf youve ever dealt with the uk ico youll know its true. They refuse to do anything about individual complaints. The gdpr also states that samctions will be determinedby the gravity of the violation and number of users affected, among other factors. Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.
- djrogers 8y agoIt’s not ‘nothing to worry about’ until the various enforcement bodies across the EU all establish predictable patterns of behavior and sanctions. Until then, nobody wants to be the first wrist slapped just to see how much it hurts.
- cpncrunch 8y agoThe ICO has had 20 years to establish their pattern, and it seems to be pretty well set by now. They basically do fuck all about individual complaints, unless perhaps it's something incredibly serious. I recently had to take a data bureau to court for selling my details without permission (and won an out of court settlement for 500GBP) for spam, because the ICO did fuck all. I have another case pending against the very large UK company that used 2 separate data bureaus to spam me without permission. So if the ICO won't sanction a very large company for clearly violating PECR, I really wouldn't worry. They only take action if they get thousands of complaints. I very much doubt that GDPR is going to change this behaviour, but I would love to be proven wrong.
- Sir_Substance 8y agoI don't really see this as a GDPR troll. This guy is saying he can't manage formal GDPR requests. He's running an internet forum for christs sake. We had forums before we ever had tracking, and anonymous internet handles were practically invented on forums. What's he doing exactly that he can't answer GDPR requests with a simple "we don't collect personal information"? Of course, he probably is collecting PII, because he's using discourse. But since he says he doesn't have time to answer GDPR requests you can be pretty sure he doesn't take the time to ensure his infrastructure hasn't been owned. I'd wager he doesn't even know what PII the system he runs is collecting, so how can he be securing it on his users behalf? It's totally reasonable for his users to ask how he's protecting their personal data. If he wants to flip tables and storm out when they ask, that's up to him. From my perspective, the system works. He wasn't making the effort his users deserve to securely store their PII, and so now he isn't storing it at all. No one had to sue anyone, no one had to go to court, and he made the sensible decision to get out of the PII game he had no business being in. Success if ever I heard it.
- cm2012 8y agoOh no, your email address (PII) might be compromised. How would you survive if a competent hacker could find that?
- Sir_Substance 8y agohttps://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
- drcode 8y agoI don't know why all these websites are shutting down due to GDPR when all you have to do is hire a competent law firm with GDPR compliance expertise to review your software and help you determine if any parts need to change to become compliant and also help you address any GDPR requests. </sarcasm>
- hartator 8y agoTrue. You can also just make a budget for the fines, block days per month for compliance, and remove all contents that displease EU residents. Easy. /s
- infinitismal8 8y agoEveryone was saying that you don't need to worry about GDPR unless you are a scumbag that is selling user information. This open source project owner must have been doing something unethical if they are shutting down their forum due to GDPR. </s>
- DoreenMichele 8y agoIn its majestic equality, the law forbids rich and poor alike to sleep under bridges, beg in the streets and steal loaves of bread or violate the GDPR. -- Anatole France (I might have edited that quote slightly)
- etatoby 8y agoOMG this is perfect! I'm so stealing this quote. It applies to so much it's scary.
- duxup 8y agoIt's really hard to know what exactly was asked of him by the letter and by whom. I get the nightmare letter scenario but is that the exact request he got? Can he not extract all that user's data and delete if that is what is being requested?
- TACIXAT 8y agoThis was linked to in the post: https://jacquesmattheij.com/so-your-start-up-receive-the-nightmare-gdpr-letter https://jacquesmattheij.com/so-your-start-up-receive-the-nig... It is a request for a lot of information.
- duxup 8y agoYeah i'm familiar with that. I was wondering if that was the exact request. It's not clear to me that the dude got that exact request. It's also not clear to me that anyone getting that letter must do what that letter says to the letter else face consequences. We haven't seen that situation tested yet (although I can get why someone might not want to test it them self) all we've seen are letters being sent from individuals to individuals. Now how any enforcement would actual play out IRL.
- zerostar07 8y agoWho wants to be a guinea pig for lawyers? what fun!
- ascorbic 8y agoIt wouldn't be lawyers unless it got a lot further down the line and went to tribunal. It would be the ICO (or equivalent), which is the regulator.
- ProAm 8y ago> It's really hard to know what exactly was asked of him by the letter and by whom It says this right in the posting. >> > In case anyone is interested, this basically described what has been happening to me: https://jacquesmattheij.com/so-your-start-up-receive-the-nightmare-gdpr-letter https://jacquesmattheij.com/so-your-start-up-receive-the-nig... 1.2k > The sad thing is that one email came from the co-founder of a Startup out of Germany.
- DoreenMichele 8y agoI"m not really a fan of the GDPR. I don't think it really protects privacy. I think it just uses the power of the EU, a fairly big and strong organization, to intimidate the rest of the world to comply with laws that it really shouldn't have legal jurisdiction to enforce globally. I think this is a scary precedent to set that the biggest bully on the block can de facto enforce such standards because the rest of the world is terrified of the consequences of standing up to them. Isn't this the sort of thing people accuse the US of? The rest of the world makes ugly jokes about "Be careful what you say about the US or they might come liberate you too." The EU is now in the protection racket. When the mob says you should give us a few bucks because it would be a shame if something happened to your business, people recognize that is not nice behavior. But the EU can do the same on the web and some people laud it is a good thing for individuals in the name of personal privacy. If you want none of your personal info on the web, I have a suggestion: Don't participate in forums, social media, etc. (Yes, I am guilty of having this opinion without having actually read it. I blogged previously about my opinion this would do bad things to forums. I am shocked to see negative fallout happening so very soon.)
- ak47-1984 8y agoThey aren’t attempting to enforce legislation globally. If a company operates in the EU, it has to comply. For companies that don’t operate in the EU and have no EU customers or traffic, they don’t. Simple
- etatoby 8y agoEven if said foreign companies have EU customers, what can the EU do about it? If I were a foreign company, I would completely ignore GDPR requests. Like > /dev/null, not even bother reading them. This law will only make things (even) more expensive and cumbersome for EU companies wrt. the rest of the world. This is going to be the asinine Cookie Warning all over again, times a hundred.
- M2Ys4U 8y ago> Even if said foreign companies have EU customers, what can the EU do about it? If I were a foreign company, I would completely ignore GDPR requests. Like > /dev/null, not even bother reading them. EU regulators could domesticate their judgments in the jurisdictions where these companies are based. It's entirely possible to do this in most states in the US, for example. Failing that, they could target assets held in the EU or take action whenever corporate officers travel to the EU.
- transfire 8y agoWow, look how easy it is to put the small Internet business out of business now. Well played 9.9%.
- ashelmire 8y agoCould/should probably ignore GPDR requests if your business operations are entirely US based, whether or not anyone from the EU uses your site. US national sovereignty doesn't disappear because the EU says jump. We are not bound by the laws of governments other than our own. You can probably ignore them anyway if you aren't a big company. With millions of these troll letters going around (and probably getting ignored), odds of any corrective action against you seem very low. In any case, the corrective demands of the EU give you time to comply after they declare that you've violated something? Could probably wait for that point even if you're in the EU.
- infinitismal8 8y agoIf you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future
- skinnymuch 8y agoThe OP initially says if you’re small time they likely won’t target you. Are you really saying if you’re super small time, the EU is going to go after your payment processing? Of course anything is possible. It seems highly unlikely though. Then his/her last point is that they’ll give you a chance to correct things. Your post doesn’t seem to cover that either.
- infinitismal8 8y agoThey will go after you the moment you become bigger and if you are person running a business one of your hopes is that you won't remain small time forever
- bigbugbag 8y agoThe way it's been done in the past, it usually starts by notifying you and giving you reasonable time (a month) to fix things then move up to sanctions. But this is not a given every time and not everyone goes the nice route, some go directly to court. So when you are a small fish, you are better off doing your best to follow the GDPR in the first place than scrambling to avoid sanction in a limited time later. it is not that complicated to not collect data you don't need, ask before collecting it and informing about what you do with it.
- bovermyer 8y agoThe GDPR seems to me to be just another example of nontechnical authorities trying to regulate what they don't understand. Why don't more technical people become politicians, or at least form lobbying groups or think tanks?
- DanBC 8y agoThe response to the GDPR seems to me to be a bunch of people who fundamentally misunderstand how law works, especially in Europe, and who have a pathological relationship to regulators because their own legal system is fucked beyond all recognition. GDPR requires you to only gather the data you need; only keep it for as long as you need it; tell people what you're doing with it; and allow them to correct it if it's wrong. How is that too hard?
- TomVDB 8y agoRead the nightmare letter. How hard is it to reply to just “a few” questions like that?
- DanBC 8y agoYou point people to the privacy policy. The Nightmare letter is mostly bullshit scaremongering.
- Matticus_Rex 8y ago... and document every instance of processing, as well as the legal basis for processing for each use of each piece of data, and how you decided that legal basis (and if you used "legitimate interest," you need to do a LIA -- the template I use is several pages before you enter the information). Then you have to negotiate different DPA terms with a dozen clients whose privacy lawyers told them they each need a different term because we privacy professionals still have no idea what parts of this law mean. Oh, and then you have to handhold customers who think they know more about privacy law than you do because they read a 500-word rundown of the GDPR, because if you don't nicely convince them they're wrong, they'll make a complaint. There's plenty more, but you get the idea. Anyone who says implementing this law is simple isn't implementing this law in a business of normal size and complication.
- notacoward 8y agoFrom the prototype letter: "I am a customer of yours." Not until you pay me, you're not. Yes, Mr. Well Actually, I know that the law says otherwise, and that's exactly why the law is FUBAR.
- raziel2p 8y agoAre you implying that free services like Facebook should be exempt from privacy laws like GDPR?
- merb 8y agoWell if you know that Facebook is bad, why did people even register in the first place? Or put their whole life onto it? It's ok if the privacy law only gone against stuff like analytics or horrible facebook buttons that even collected stuffs from people who clearly weren't users. i.e. tracking especially tracking outside their "domain" however GDPR goes against all and anything. I mean if I go to a supermarkt I can't just tell the supermarkt owner to shut down all his cameras until I leave the store, he would basically just kick me off his market (which actually is his right in the EU). However the EU somehow made a solution that actually even goes against their own market principles just to have extreme amount of Privacy in the internet (only in the internet, their own institutions can still collect data, i.e. in germany the ard has tons of data about everybody) and this is my problem with the GDPR, it's a law from people who actually just want to hurt the big us internet companies. The law also was made by a lot of people without any clear technical background (there were some, but they were a minority)
- bigbugbag 8y agoI never registered on facebook because I knew. People who don't know or don't care is different, then there are other psychology explanation and network effect. Your example is deeply misrepresenting the GDPR, seems like FUD to me. GDPR applies outside the internet, GDPR is very limited in scope as it kept the "legitimate interests" exemption from the 1995 directive. Can you substantiate your claim that GDPR was made by people who do not understand what they do ?
- RaleyField 8y agoCan't wait for future nightmare letters coming from Saudi Arabia when they find moral indecency on my web site or China finding imperialist propaganda that needs addressing. This will be used as a precedent for every other control freak pushing their values onto us. What happened to free and open internet?
- jbob2000 8y agoThis already happens. Russia sent notices to GitHub about certain documents that were hosted there. China and Saudi Arabia just straight up block things they don’t like.
- RaleyField 8y agoYea, but this emboldens them because they can now point to EU and say that this is what normal countries do, long arm[0] people around. [0] https://en.wikipedia.org/wiki/Long-arm_jurisdiction https://en.wikipedia.org/wiki/Long-arm_jurisdiction
- vbernat 8y agoOr US with DMCA requests.
- ryanwaggoner 8y agoIt would be much better for the EU to just block these sites that they think are violating EU citizen privacy rights. But they’d never do that, because their citizens still want to use the sites, so it’d be unpopular. And ineffective since people would just work around it. Apparently these pesky humans don’t care about their privacy like they should! Plus then the EU can’t levy billions in fines.
- ggg9990 8y agoGoes to show that when an industry does not self-regulate, it gets over-regulated, which often disproportionately benefits incumbents, which incentivizes future lack of self regulation.
- adventured 8y agoNot exactly. GDPR only applies to the EU. China isn't going to rewrite its laws to make the EU happy and mirror GDPR, neither is the US. It's more accurate to say that when an industry doesn't self-regulate, the EU over-regulates and shoots themselves in the face. The US and China will race even further out ahead accordingly. In the US I can easily unleash a large user data hungry AI at will, experimenting all day long with anything and everything I can come up with. I can screw with people's data in countless ways, without their permission. While this haven exists, I can rapidly learn and come up with technology and services that tech companies in the EU can't risk attempting and won't bother to contemplate. To the point: you can still push every edge of the AI revolution in the US and China, to see what's there. That revolution is heavily built on user data. In the EU, you're in a straight-jacket at the very beginning of the revolution (one that is guaranteed to only get tighter), many years before we've even seriously begun experimenting with the fertile soil. They're fucked, the world will be dominated by AI that comes out of either the US or China, or both.
- lovemenot 8y agoGDPR does not restrict EU companies' activities in less regulated markets. They are still just as free to abuse the privacy of users in USA as are their competitors overseas. Your anxiety appears to be about American AI companies' competiveness in the face of even worse abuse of users' privacy in China than in USA. In a race to the bottom do you really want to be the winner, no matter what?
- detaro 8y agohttps://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/ > This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
- Animats 8y agoI just sent a GDPR letter to a company in the UK, which is still part of the EU. I have one of their Android phones, and it came with a non-removable app. It appeared to just be a bookmark. One day that app woke up and sent me a notification asking me to visit a web site, which led to a SurveyMonkey form. So I sent the company a letter asking what data they have on me. It's going to be interesting to see what happens.
- clon 8y agoGuy shuts down forum, goes through the nightmare letter dissecting each part as "good question" or "you should have this already" or "easy one". So what was his issue anyway?
- rutierut 8y agoForum guy =/= nightmare letter guy
- raziel2p 8y agoHe points out that he's dealing with several of these requests. Even if you're doing everything correctly in terms of privacy etc., responding to these requests can still be time consuming.
- DanBC 8y agoHow is "read the privacy policy, then click this link to get all your data" time consuming?
- ascorbic 8y agoIt's not the same person.
- bigbugbag 8y agoGuys moves from discourse forum to subreddit for community discussion because he got a GDPR letter from a start up head or something. links to what he thinks has been used to craft the letter he received. Underlying issue is that guy does not have time to deal with GDPR and discourse does not offer the proper tools, so he went the easy route of outsourcing, but he overlooked that he's still probably still liable under GDPR.
- brown9-2 8y agoHow is reddit different than discourse here? Is discourse hosted?
- qwerty456127 8y agoHow can it be hard for a forum to comply to GDPR? What kind of private information does it really need to save?
- SiempreViernes 8y agoIt seems mainly to be just the american reaction to any letter related to a new law, the examples of data he lists are just things the forum needs for purely technical reasons, like a mail for password resets and login.
- tephra 8y agoI'm a European that supports the GDPR but here's my take on the issue in the post. I don't think it would be hard for the person in the post to comply, it would just be time consuming. Say for example that a user requests a data transcript. Well he will have to collect all the post etc from that user and send it somehow. Now this is probably just a simple SQL query but it takes a bit of time, time that many people don't have. Another issue seems to be that he is afraid of repercussions and is conditioned in the US system where everyone seems to be suing everyone all the time.
- jopsen 8y agoOn HN I can go to my user profile and see all comments/posts I've made. And I can delete them all. I strongly suspect this sufficient. Maybe it would be ideal to offer a "delete account" and "download account" button. But there is no reason you should be processing letters from people. I'm not even sure you need to offer removal of public information. But allowing deletions of accounts is hardly controversial.
- codedokode 8y agoAlso it would be a good idea not to keep IP addresses forever. Two weeks retention is enough to detect mass registration.
- ItsMe000001 8y ago
- bigbugbag 8y agoSo basically drone.io is saying that discourse is not RGPD compliant and reddit is better equipped to deal with RGPD requests so he's moving his community discussion from a self hosted discourse to reddit. Looks like a knee jerk reaction and missing the point that you can evade RGPD by outsourcing to a third party, one can still send RGPD requests to drone.io and owner is still responsible for answering those but now has to deal with getting the relevant data from reddit.
- zerostar07 8y agono he wont be. reddit will
- drivingmenuts 8y agoThe thing I have to wonder is who did this and more importantly, why? If you're a startup competing against an open-source project, then this is potentially a great (not good) way to get a leg up. You get the benefit of access to the code until you don't need it anymore, then get the project shut down and reap the benefit of being the last man standing. Sure, you might eventually run up against the license on the software you just lifted, but open-source projects can't afford the same protections that a well-funded startup has. And if you somehow get sued for license violations, the penalties are usually more a slap on the wrist than an effective notice to knock that shit off. I really hate the way my mind works some days.
- zerostar07 8y ago> If you're a startup competing against an open-source project Doesn't have to be a startup. I expect many small businesses will use it to damage competitors. It's not like it's unheard of .
- _pdp_ 8y agoOverreaction as usual!
- lajhsdfkl 8y agoHow is it an overreaction? If he doesn't want to waste his time because of EU snowflakes it is his prerogative to shut down his forum. Why do you believe you have a right to his service?
- codedokode 8y agoThe owner says that he doesn't have time to review GDPR-related requests; that's fine. But I wonder if he would receive a US court order would he treat it the same way? What if he received a letter from NSA? A DMCA request? What if someone posted something illegal on the forum, would he ignore that as well? It seems like he has no time only for legislation from EU.
- foota 8y agoIf they thought they were likely to receive a lot of these they'd probably shut down.
- speedplane 8y agoNot necessarily. Often, receiving your first request is by far the most expensive. You need to hire a lawyer, come up with a response plan, and educate employees on how to handle them. The second, third, and hundredth request is likely far less expensive or time consuming to deal with.
- bradrydzewski 8y agoYes exactly. I am not interested in subsidizing the one-time cost of hiring an attorney to draft a compliant privacy policy and create boilerplate email templates. It is just easier to outsource the forum to a company that can (reddit).
- jchw 8y agoNonsense - they are shutting down because they actually received GDPR requests. They have not received any NSA letters, DMCA requests, and I don't think moderating forums by deleting posts could ever be construed as being as strenuous as trying to comply with the most comprehensive internet privacy law ever written.
- ascorbic 8y agoDeleting posts is the only onerous part of complying with these requests. Most can be achieved by directing to a privacy policy. Discourse lets the user download their own data. An admin can remove all identifying metadata with a single command. That leaves the posts themselves, most of which wouldn't be PII if they're not attached to a username or IP address. If there are any actually identifying details in the posts, that can be dealt with like any other moderation.
- chvid 8y agoThe EU could have sent a man to Mars with the money used on GDPR ...
- antaviana 8y agoCan you send a GDPR letter to a public body, for example, the Office for National Statistics? Can you ask them to delete your data? Should they comply or are they waived from GDPR compliance?
- perlgeek 8y ago> Can you send a GDPR letter to a public body I'm pretty sure you can. > Can you send a GDPR letter to a public body You can, for PII. One would hope they store their data anonymized. > Should they comply or are they waived from GDPR compliance? I think they'd need to make a pretty strong case for why they cannot anonymize your data for their work to get an exception.
- DanBC 8y ago> Can you send a GDPR letter to a public body, for example, the Office for National Statistics Yes. They don't store personal data. All their data is strongly anonymised. > Can you ask them to delete your data? You can ask. GDPR does not introduce a blanket right to have your data deleted. There are a bunch of limitations to that right. https://gdpr-info.eu/art-17-gdpr/ https://gdpr-info.eu/art-17-gdpr/ > Should they comply They don't have to comply with deletion requests. i) they're not storing PII ii) if they're processing data for the reasons they've told you they do it then they don't need to delete upon request. > or are they waived from GDPR compliance? This isn't them being waived from GDPR compliance, this is the GDPR working the same for them as it would for any other processor. Having said all this, "Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes" That's not just government statistical departments, but includes university or history archives. https://gdpr-info.eu/art-89-gdpr/ https://gdpr-info.eu/art-89-gdpr/
- casperb 8y agoThe GDPR does not apply if it is for personal use or for a hobby only. I don’t know how the structure of this forum is set up, but this can be a good reason to run such forums on your personal name.
- evfanknitram 8y agoWhere is the exception for hobby projects specified?
- casperb 8y agoArticle 2, section 2(c) exempts processing of personal data “by a natural person in the course of a purely personal or household activity”. http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
- williamxd3 8y agoBoohoo daddy state, this big bad privately run service of which I voluntarily registered is storing my data, please go beat him
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- lanevorockz 8y agoThe EU is already targetting Open Source in the new legislation. We should start making a stronger case for the internet while we still have it. The Pirate Party tends to be the best resource for the support, they organise petitions and have elected officials in the Parliament.
- marenkay 8y agoConsidering GDPR is actually a thing from 2016, and 25th May only marked the day from which on it would actively be enforced... that kind of comes late. What I wonder: this is an Open Source project, so why not ask the community for help instead? Being a long-time (very happy) Drone user, I would have happily helped to produce the necessary documents for the project if that had been asked before the final deadline. Well, probably would even do that now.
- mark_l_watson 8y agoI have a contrarian opinion to much I am reading here. Until a few weeks ago, I hosted my own web site and used blogger to host my blog on a subdomain. With huge reluctance I disabled comments, and then when Google’s patches for GDPR compliance didn’t work for me, I converted my 2000+ blog posts from the last 20 years to Jekyll and now host as part of my web site. While it is nice to have total control, now I need to be using my laptop to post new blog posts, and I miss having readers comment. I also feel badly that the interesting things that readers have posted are lost to the Internet. Even with all that, as a US citizen, I approve of GDPR and I wish it were universal. As much as I miss user comments, I am fortunate to have many readers engage with me directly via email discussions.
- DanBC 8y agoWas your blog personal? Or was it commercial? If it was personal the GDPR doesn't apply.
- mark_l_watson 8y agoWell, what is a personal blog? My blog was mostly fun tech stuff, but it attracts dev business. So, I would say it is a commercially blog.
- lukebennett 8y agoUnless I’m missing something, shutting down the forum does precisely nothing to limit GDPR liability as the main drone.io site itself has an account/login area. Whilst it’s private beta currently, unless EU access is blocked, GDPR liability will continue to apply to any personal data collected via that. The only benefit here is that there’s one fewer system to keep track of when it comes to tracking/deleting personal data - the need to respond to subject access requests, right to be forgotten, form letters etc remains.
- ledriveby 8y agoI operate a 150 person forum and I, too, am scared shitless of weaponized GPDR harassment.
- bigbugbag 8y agoI wonder is the drone.io guy has read the link he provides to the end of it: >> So, there you go, that should take the sting out of answering the ‘nightmare letter’, even if not all the questions are appropriate (or appropriately worded) you can answer the bulk of them in relatively short order and with automation you can take the sting out. If this is the worst you can expect under the GDPR then that’s not so bad, and the effect might actually be positive: - we get to know about a lot of undisclosed breaches - it will be clear who has their house in order and who hasn’t - if you don’t have your house in order just answering the letter will help you to get there <<
- qwerty456127 8y agoBy the way, what I really love about GDPR is that now I finally can disallow a website to log and analyze my behaviour to provide any kind of "personalisation" they want and still use it. It's just so great they can't say "agree or go away" any more. I thought it was going to be another stupid thing like a "cookie law" (which, I hope, is going to be canceled now as we''ve got the GDPR), the recent US FOSTA or a "store all my data in my country on a government-certified server with a police backdoor" law but fortunately it absolutely is not. I really hope non-EU countries are going to clone this law, it seems to be the second (the first being the US net neutrality policy) law I love.