11 ms·
Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction,
by ascorbic 8y ago
Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. If anything it's even more of an overreaction, because a DMCA request could be followed up by legal action, whereas a data subject can't sue. All they can do is report you to the regulator. The regulator is unlikely to do anything if it's a frivolous request. Even if it's legitimate, their first action them would be to send a warning.
- fizx 8y agoDMCA is capped at what, $30k per violation? There are obvious ways to avoid it, and the law has settled down. GDPR is capped at $20+ million, no one knows what a typical fine looks like, the law is much harder to read, and everyone is afraid to be made an example of.
- oblio 8y agoI don't find this: https://www.aclu.org/other/text-digital-millennium-copyright-act-dmca https://www.aclu.org/other/text-digital-millennium-copyright... much easier to read than this: https://gdpr-info.eu/ https://gdpr-info.eu/
- geocar 8y agoThe full text of the law is for the regulators, not for armchair lawyers. The ICO has produced a font of useful free guidance for getting compliant with the GDPR: https://ico.org.uk/for-organisations/ https://ico.org.uk/for-organisations/ That's what people should be reading.
- ascorbic 8y agoIts predecessor regulation capped fines at around $750k. Guess how many were levied at or near the maximum? Zero. The only large fines were for serious, deliberate abuses, such as a group maintaining a secret blacklist of construction employees. This isn't like the massive fines from US regulators on foreign companies. The rules say that fines should be proportionate to the scale of the breach and the harm caused. The large fines are for serious, deliberate, repeat offenders. It's also to stop a company like Google deciding that they'd rather not comply, and treat a fine as a cost of business.
- mseebach 8y agoWhen a new law is enacted, it's not prudent analysis to assume anything about how it will be enforced based on the previous law, especially not when fines were increased 25x - GDPR is not a minor clarification of a few bits and pieces, it's a whole new thing. The previous law was specifically criticised for having no teeth, and the new law has specifically been highlighted for it's new teeth. Of course it's possible that regulators will just sit on their hands, it's just not very likely. The only reasonable assumption is that those new teeth will be tried out, and whoever they will be tried out on first will have a bad time. Do not assume that the first cases will be Google and Facebook, the regulators aren't stupid enough to try their luck first on the two organisations that has spend the most on being technically compliant, and has bottomless warchests to fight it.
- ascorbic 8y agoThat doesn't mean lawyer up or shut down at the first request. Of course you should be prepared, by doing sensible things like having an up to date privacy policy, and only keep the data that you need and that you have permission for. However when it comes to compliance, if you get a request, be sensible. The time to lawyer up is if you get a notice from the ICO, if you think it's unreasonable and/or you don't think you can comply with it. I've dealt with the ICO quite a bit, as I've appealed a few FOI requests, and they've always been very reasonable, if a little overworked and slow to respond.
- LamaOfRuin 8y agoThat's not a realistic decision for companies to make in the face of actually aggressive regulators, because regulators will simply levy the relatively smaller fines every day the company remains in violation (which EU regulators have threatened/done to US tech companies). Instead of making that decision, Google just stopped operating services (Google News) in countries that tried to aggressively control how they did business. You're right though, that it is always a relatively pure cost/benefit calculation for the company.
- oldcynic 8y ago> no one knows what a typical fine looks like The EU has had data protection law for twenty years. The EU has enshrined proportionality of penalty in all EU law as a fundamental right. There is plenty of case law at the CJEU defining this. All you need do is read the FAQs that EU ICO's have been putting up. The UK has never, in 20 years, applied the full penalty of the previous DPD, and under 0.1% of all reports got any fine at all. A "typical" penalty will be help to comply. Perhaps a strongly worded letter.
- lajhsdfkl 8y ago> Yes, this is really little different from shutting down a whole forum because you received a single DMCA request. Completely unrelated. Not only are DMCA requests easier to handle than data access requests, the fines for not complying with GDPR are disproportionately larger for violating DMCA. Work required for complying with a DMCA request: delete the offending material, a basic feature implemented on every single piece of forum software Work required for complying with a data access request: Search every single service you potentially could have stored user data in and provide it to the user. A non basic feature that requires custom development. Additionally any malevolent user (as is shown in this case) is incentivized to send a GDPR data access request while this is not true for DMCA. I agree however that they are both horrible laws. So if your argument was to show that GDPR is just as bad as the DMCA I agree. GDPR is a horrible law and it is not obvious to me that the law wasn't created specifically to target non European business.
- ascorbic 8y agoExcept this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. I'm also not sure how a malevolent user is any more incentivised to abuse this than DMCA. The DMCA lets them issue actual legal threats and action. This just allows requests. The DMCA helps big business at the expense of the general public. This does the reverse. It's no wonder there's been so much noise and scaremongering.
- lajhsdfkl 8y ago>Except this forum software does provide a tool that lets the user export their own data, as well as a tool that lets an admin strip all identifying data. Completely besides the point, there are hundreds of different pieces of forum software that may not have that feature implemented. >The only way this targets non-European businesses is because the litigious nature of US culture seems to lead to this sort of overreaction. Did I ever bring up litigation? What is your point here?
- emiliobumachar 8y ago"a data subject can't sue" Didn't a data subject sue Google and Facebook for billions on day one of enforcement?
- ascorbic 8y agoGreat example. No, they didn't, though you wouldn't guess that from the news coverage. They filed complaints with four regulators. The details are all here. https://noyb.eu/ https://noyb.eu/
- taysic 8y agoWhy does your link list maximum fines in millions why other links say billions? "Three complaints worth €3.9 billion were filed in the early hours of Friday morning against Facebook and two subsidiaries, WhatsApp and Instagram via data regulators in Austria, Belgium and Hamburg. Another complaint worth €3.7 billion was filed with French data protection authority France CNIL in the case of Google’s Android operating system for smartphones." https://www.irishtimes.com/business/technology/max-schrems-files-first-cases-under-gdpr-against-facebook-and-google-1.3508177 https://www.irishtimes.com/business/technology/max-schrems-f... edit: To me, the difference between 'suing' and 'complaints' seems unimportant if the potentials fines from a 'complaint' could be so high.
- detaro 8y ago"Mrd" is short for billion, seems like they missed that while translating it.
- ascorbic 8y agoThe difference is that if you sue someone, they will by definition face legal action. A complaint is just a tip-off. In only a tiny minority of cases will there be any action, and most of those will be a warning letter. Admittedly these cases in the link are very likely to be investigated, but they would have probably been even without the complaint. Apart from anything, the ICO in the UK is already investigating Facebook because of Cambridge Analytica.