11 ms·
He's still obliged to respond to that letter. Can't hide like this. (guys, I'm being sarcastic)
by zerostar07 8y ago
He's still obliged to respond to that letter. Can't hide like this.
(guys, I'm being sarcastic)
- amyjess 8y agoAccording to his GitHub, he's in San Francisco. He's a US citizen living in the US. The EU can't touch him.
- marssaxman 8y agoDoes that continue to be true if the US citizen goes to visit an EU country? It'd really suck to get arrested on your vacation because you ignored some troll's GDPR-based harassment. I don't know how this works.
- cpncrunch 8y agoIf youve ever dealt with the uk ico youll know its true. They refuse to do anything about individual complaints. The gdpr also states that samctions will be determinedby the gravity of the violation and number of users affected, among other factors. Nothing to worry about for people like the open source project in question. This is way overblown paranoia, but unferstandable given the current hype.
- djrogers 8y agoIt’s not ‘nothing to worry about’ until the various enforcement bodies across the EU all establish predictable patterns of behavior and sanctions. Until then, nobody wants to be the first wrist slapped just to see how much it hurts.
- cpncrunch 8y agoThe ICO has had 20 years to establish their pattern, and it seems to be pretty well set by now. They basically do fuck all about individual complaints, unless perhaps it's something incredibly serious. I recently had to take a data bureau to court for selling my details without permission (and won an out of court settlement for 500GBP) for spam, because the ICO did fuck all. I have another case pending against the very large UK company that used 2 separate data bureaus to spam me without permission. So if the ICO won't sanction a very large company for clearly violating PECR, I really wouldn't worry. They only take action if they get thousands of complaints. I very much doubt that GDPR is going to change this behaviour, but I would love to be proven wrong.
- jtbayly 8y agoSo what you're saying is that all the small businesses feverishly seeking to comply with GDPR are wasting their time, because actually the law doesn't apply to them?
- danieltillett 8y agoIf they are not in the EU and not doing anything out of the ordinary then yes. Life is full of risk and the GDPR is right down towards the bottom of things to worry about at this point if you are outside the EU. I suspect this is also the case if you are inside the EU too, but we will soon know.
- duxup 8y agoDo you think if the complaint went to a government official in the EU they would throw down the hammer on a site that was up for all of a couple days in GDPR time? I have my doubts. I've got a handful of sites (ultimately for portfolio / coding practice type stuff) out there. Honestly it wouldn't take me too much to respond to someone's letter considering the simplicity of the site(s), not that anyone uses them. I also really wouldn't expect any EU official to throw down the hammer on me. Personally I wouldn't panic, and I'd at least wait for the EU official to weigh in before panicking.
- DanBC 8y agoNo. They're unlikely to do anything. If they did do anything it would be to post a link to current best practice advice.
- zerostar07 8y agoNo, but it is more than enough to scare people. Doing a project that makes you zero or very small amounts of money does not justify any risk-taking, and certainly nobody wants to go into the trouble of sending emails to various DPA people in Europe if the need arises. This kind of treatment should be reserved for large companies or specific uses of private data. In addition, the approach of the law "guilty until proven innocent" is hugely off-putting.
- rdlecler1 8y agoThen I dare you to post one of those website la here.