19 ms·
GDPR Enforcement Tracker: List of GDPR fines
- ferongr 7y agoThe fact that someone was fined for using a dashcam is beyond absurd.
- donretag 7y ago"a man illegally used a dashcam, he was fined 300 euros. It was a camera recording the use of a car from the driver's point of view, which is illegal." Insane.
- hvhsb 7y agoWhat's insane, the fact that you can't just go around recording people and cars?
- tempestn 7y agoOn public streets, yeah, that's kind of insane. It's pretty common for people to have a dashcam running with a buffer so if you're involved in a not at fault accident or someone vandalizes your car, or such things, you have documentation.
- hvhsb 7y agoOf course, that's why it says "illegally". Those dashcams can be installed legally, and this guy's wasn't legally installed.
- tooop 7y agoWhere is info on how to install it legally and why this stupid ban on dashcams when GDPR actually allows it (it made dashcam usage easier in my home country as now you don't have to register as data processor because dashcams fall under surveillance). I feel that this is a bad thing - you have a regulation that covers all EU but some countries have their specific laws overriding it and banning things that are allowed under GDPR.
- izacus 7y agoSome societies think that tracking people on public spaces isn't acceptable either. I don't know why it would be insane - if anything, losing all privacy because you stepped out of the house is the insane thing.
- tooop 7y agoInsane would be the fact that i cannot use pictures/video taken in a public setting for my personal use. Publicising these pictures/videos are another thing and that is covered by GDPR.
- malka 7y agoIf it's a model with a buffer, it's allowed. What is not allowed is to have lying around hours of footages with licences plates, etc. on it.
- droithomme 7y agoYes, that's what's insane.
- donatj 7y agoIn public? Something your brain already does?
- mtw 7y agoActually he was lucky. Austrian law says the fine should be €10,000. It is not legal to own or to use a dashcam in Austria, like in a few other European countries
- oh_sigh 7y agoNot true. You can have a dash cam, but it has to be the kind that continuously overwrites its own data and only records when it detects an accident. You can also record based on your intent - if your intent is to, say, capture a scenic drive ,then you can do that. If your intent is to just capture the license plates of 1000s of other cars that pass you, you can't do that. These laws were changed in ~2018 in Austria.
- bosie 7y agoHow can a dashcam possibly detect an accident? Wouldn't that basically start recording after the fact and hence be mostly worthless?
- detaro 7y agoNo, they are allowed to have a buffer of last X minutes.
- oh_sigh 7y agoAccelerometers. How it works is there is something like a 5 minute, constantly overwriting video file. Once the accelerometers detects an abrupt deceleration, it determines an accident occurred and marks the previous 5 minute segment of video as read-only.
- romwell 7y agoThe dashcam will record into a, say, 5-minute buffer until the accelerometer registers a high value, at which point it starts writing into a new file (so the buffer becomes a permanent record of the 5 minutes prior to the incident). That's one way to implement it, one can come up with many others.
- droithomme 7y agoThe same link mentions issuing a GDPR reprimand against a person for using a security camera inside their own home.
- inetknght 7y agoThe one I saw said that the CCTV system in the home was also set up to record other peoples' properties too.
- henrikschroder 7y agoIt's not the GDPR that made this illegal. It was most probably illegal before the GDPR, and it was probably enforced by the same agency that now enforces GDPR. The GDPR is an umbrella that covers all the new things it introduced, but also a lot of old things the various national data privacy agencies covered.
- detaro 7y agoWhere does it say that? The linked article says "recordings of their house", which very well could e.g. be a camera on the outside, capturing surrounding public space. (also probably existing law, not GDPR specifically: video surveillance has been fairly strictly regulated for a while)
- M2Ys4U 7y agoRecording in one's own home is exempted under the GDPR[0]. I suspect something broader was involved here. [0] Article 2(2): "This Regulation does not apply to the processing of personal data [...] by a natural person in the course of a purely personal or household activity"
- PeterisP 7y agoA prime example where GDPR would apply to a security camera in your own house would be if that camera was used to record renters (including short term rentals e.g. AirBnB) without their knowledge. For example, I recall reading about cases of renters finding out that the landlord has installed hidden cameras in the bedrooms and showers.
- blub 7y agoSome countries are sane enough to enshrine privacy in public spaces into law, because of the potential for abuse. This is slowly but surely being eroded also in Germany. Multiple cities are trialling full video surveillance to stop the terrorists. e.g: Some USA towns have near 100% video surveillance through the Amazon doorbell cameras (Ring) of the town's inhabitants. Some content is publicly available, cops can also request it. Then Amazon is posting captured video as Facebook advertisements to identify suspected thieves. https://www.vice.com/en_us/article/pajm5z/amazon-home-surveillance-company-ring-law-enforcement-advertisements https://www.vice.com/en_us/article/pajm5z/amazon-home-survei...
- deleted 7y ago[deleted]
- DanBC 7y ago1) We don't know much. GDPR allows processing if it's for purely personal use, so if he's putting it on youtube with ads that takes it out of purely personal use. 2) As the linked news article says, Austria may be getting the balance between cautions and fines wrong, which is why they may face a case in EU. > In Germany, for example, people use caution instead of punishment - which is why Austria may face an EU case.
- AnssiH 7y agoAustria has had a ban on dashcams for years, though, so it is not a new thing brought by GDPR. Another EU country with a similar ban is Luxembourg.
- tzs 7y agoBased on this article [1], it looks like EU country laws on dashcams ranges from similar to the US, to legal but with restrictions on the duration, retention, or use of the footage, to illegal to use subject to fines, to illegal to use subject to prison, to illegal to even own one regardless of whether or not you are using it. How aware are EU drivers of these differences? Is it well known to those in places with less restrictive rules that their cameras could get them in a lot of trouble if they take them with them when they take a road trip that passes through other EU countries? [1] https://www.express.co.uk/life-style/cars/998528/Dash-cam-car-Europe-fines-prison https://www.express.co.uk/life-style/cars/998528/Dash-cam-ca...
- detaro 7y agoDon't know dash cams specifically, but it's common knowledge that laws surrounding what's in your car (e.g. emergency kit) vary and you need to check up on that.
- fyfy18 7y agoIt's basically impossible to know. Even laws which should be really clear, such and if and when you need winter tires are not clear. At the end of March I drove across Europe from south of Spain, and had summer tyres on. The weather conditions were good, so I was fairly confident I would be ok without winter tyres, but a lot of European countries have laws requiring then at certain points of the year. I knew in my destination country you needed winter tyres until April 1st, but I couldn't find anything clear on all the countries in-between. Austria was actually the toughest, my understanding is their laws are you need winter tires if the road conditions dictate you need them. In some cases snow chains can be used, but not on highways. But this was based on reading English forum posts from 10 years ago, so I have no idea if it's still correct. I tried to find something clear from an official authority (probably doesn't help I don't speak German) or an automobile association website, but couldn't.
- deleted 7y ago[deleted]
- nickjj 7y agoI wonder where the line is drawn when it comes to things like that. Yesterday I was walking on the side of the road and some girl was half way hanging out of the passenger window recording a video of the scenery. I was able to see her from a few hundred feet away. Eventually the car intersected with me and I was in the line of sight of the video for a second or 2. Of course I made a stupid pose to photo bomb her video which I found hilarious while continuing my walk home. But under GDPR, is she technically in violation for recording me without my consent? I can't imagine how any of that could really be enforced. What about all of those Youtubers who happen to record people in a busy place like NYC or Vegas. Do they really get written consent from 400-500 people in the background for 10 seconds of video?
- Aengeuad 7y agoThe line is drawn at surveillance of a public place [0] and in this instance only in Austria, as other commentors have pointed out the laws may have changed in 2018 to allow for dashcams that continuously overwrite old footage but I can't verify that. It is not illegal to make recordings in a public place in Austria, although you may have some limitations on what you can do with that footage if it captured other people and those limitations may change depending on what was captured (i.e., whether it was incidental, or footage of a crowd). In Germany for instance dashcams are perfectly legal, you only have conditions on what you can do with that footage afterwards, for instance posting it on Youtube or social media is a big no-no, and unlike Austria you're likely to get a warning in Germany instead of a fine [1]. [0] https://helpv2.orf.at/stories/1717004/index.html https://helpv2.orf.at/stories/1717004/index.html [1] https://www.derstandard.de/story/2000092017999/erst-vier-strafen-wegen-dsgvo-seit-mai https://www.derstandard.de/story/2000092017999/erst-vier-str...
- alkonaut 7y agoThis can vary between jurisdictions but in all jurisdictions i know, photographing someone in a public location is always legal and never requires consent. Whether publishing requires consent varies, in the normal case it does for commercial but not for journalistic purposes. Note that laws written this way usually distinguish “taking photos” from “surveillance” - so mounting the camera on a street corner immediately changes the legal context. This may be why dash cams fall into the surveillance category in some places.
- detaro 7y agoSome countries don't consider public space free-for-all for recordings, and have different balances between privacy and the interest in recordings. E.g. in Germany, legal dashcams require a trigger to keep a recording long-term, so no long-term recordings exist in the normal case, but in the case of e.g. a crash the interest of the car owner in evidence is fulfilled.
- lone_haxx0r 7y agoSo, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned?
- maxheadroom 7y ago>So, I assume that recording in public spaces is illegal in general and they make a specific exception to allow dash cams on the conditions mentioned? The act of recording isn't the problem but the retention of the data records. If you have no need to keep a recording of a day's video for any purposes, then that falls under the provisions of likely being exploited data (e.g.: being used to build a profile of a person's travels throughout the day, week, year, etc.). In the sense of the allowances, it's about balancing the need of the data's use (e.g.: in car accidents) versus the privacy impacts to other individuals (e.g.: you post your dashcam footage to YouTube and don't obfuscate faces or license plates). An example of this, pre-GDPR, was when Google was forced to obfuscate faces and license plates in Google Maps for Street View.
- atoav 7y agoIt is a weird one in Germany. Generally you can record everything because of a law called Panoramafreiheit, however once you start to have discernible individuals on your photograph/video you need their consent, because individuals own the Bildrecht (”image rights”) to themselves, while you as the creator own the Urheberrecht (”creator rights”). And it needs both for a image to be taken legally. So you get their written consent, ask them if it is okay or take the risk that they will e.g. see themselves in your movie and force you to take it down. This fits with the general feeling that filming another person without asking is seen as extremely rude. The key here is that people need to be recognizable, so pictures of crowds usually don’t count. Certain architects can also forbid circulation of photographed versions of their building if it is central subject of the photograph — but I only know of one such thing. Note that this all was enshrined in law way before GDPR. Unless you stick your camera into other people’s faces without asking or plan to distribute your images on a bigger scale you will probably manage without ever hearing about these laws.
- throwaway13337 7y agoWow. Here's an crazy one: Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany. "The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offences between mid-July and the end of July 2018. According to the authority's letter, between 131 and 153 personal mail addresses were identifiable in his mailing list." Poor guy. This seems to be proof that the GDPR is being weaponized against people and organizations one doesn't like.
- tempestn 7y agoI expect there would have been a warning given in that case before assessing a fine. Many of the less serious ones I read explicitly mentioned warnings that were ignored.
- deleted 7y ago[deleted]
- idlewords 7y agoWhether this is guy is a victim of overzealous enforcement, or an example of the GDPR protecting people, is completely dependent on the context of the case and the nature of the mailing list. The linked article suggests that the guy was sending out angry political rants and criminal accusations to thousands of people a day, which adds a further twist.
- ignasl 7y agoIf that’s true then the gdpr was not used according to it’s spirit at all. They punished annoying guy who was trying to get some attention. Of course google or fb is fine...
- inetknght 7y agoFrankly I'm glad that GDPR has the teeth to get people to stop abusing reply-all chains and mailing lists.
- phh 7y agoTo whoever did this: thanks! Such a website can have many uses: - Show the average people why privacy is important with concrete examples - Find previous rulings for people in a specific situation - Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers My wish for that website is that in the future, the data is more easily readable and "big-data exploitable" (good luck with that) Little things I can tell on the top of my head: - the height of the fines is basically random, that makes scrolling cognitively heavy imo. Having (...) to click to expand long descriptions sounds fair I think - it's not possible to link to a row (useful for giving examples to people) - long descriptions deserve multiple paragraphs, they are hard to read as-is. Also, I think negative rulings would be useful as well, though could send a different political message, so that's author's choice.
- hobofan 7y ago> Stop(reduce.) the "there is no way we're going to be sued for that" by the company's managers I was thinking the opposite. The fines listed are so low, that from a purely financial perspective complying doesn't seem to make much sense. I would estimate all GDPR compliance efforts I've been involved in to be more costly than the largest fine issued in Germany.
- css 7y agoNo HTTPS?
- hvhsb 7y agoGermany and this ridiculous requirement: http://www.enforcementtracker.com/?imprint http://www.enforcementtracker.com/?imprint If you put a website online you've got to put all your personal information in it.
- inetknght 7y agoWhat's ridiculous about that?
- hvhsb 7y agoEverybody can stalk you if they don't like what you've published for example.
- petschge 7y agoNot any website. If it is purely private and non-commercial you don't have to. Also, it doesn't have to be "all your personal information". Your Name is required and an address where you could be served with court papers. A P.O. box is not required, but the address where your company is located is fine. It doesn't have to be your private home address. An email address is required, but that again doesn't have to be your private one. It just has to work. A few other things are required, e.g. where your LLC is registered if it is an LLC.
- hvhsb 7y ago
- g_sch 7y agoPerhaps this shouldn't be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals. For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it's 50MM EUR to Google, but that's still a drop in the bucket compared to Google's worldwide revenue. On the other hand, commenters below have pointed out that some private individuals have received fines in the hundreds to thousands of EUR for actions such as "using Cc instead of Bcc in emails" and "using a dashcam". I agree that these are privacy lapses but it's pretty unfortunate to see the power of the state used for these purposes rather than bringing serial data privacy abusers in line.
- idlewords 7y agoThis could be a case of enforcement against large companies taking longer to conduct, given the complex nature of the cases and the resources of the legal teams involved. My understanding is that a lot of stuff is pending before the Irish data protection agency.
- detaro 7y agoThat certainly plays a role, especially as soon as courts get involved (or will get involved), see e.g. the pre-GDPR cases against Facebook still bouncing around the Irish court system. Smaller cases can be handled without international coordination, the facts are often easy to determine, ..., which makes them faster to process. And the rules about international coordination mean other countries have to wait for Ireland in many cases.
- g_sch 7y agoThis is a good point! Hadn't thought of that.
- Rockslide 7y agoExcept that of course it wasn't about "using Cc instead of Bcc in emails" but using CC instead of BCC in mailing lists with hundreds of recipients and also not about "using a dashcam" but using a dashcam illegally, which in itself can imply a much higher fine in some European countries regardless of GDPR. So not as benign as you are trying to make it sound.
- tomatotomato37 7y agoIt's interesting how enforcement changes between countries. For instance, all the fines in Austria where for CCTV and dashcam use, all of France's fines were against large corporations, and the single fine Italy imposed was on the "Movimento 5 Stelle" political party.
- newhaus1994 7y agoI mean, that is the coalition partner in government right now, so it's a big deal...
- negrit 7y agoall of France's fines were against large corporations When determining the amount of the fine, the CNIL took into account the size (9 employees) and the financial situation of the company.
- Radle 7y agoThese aren't all fines. Most of them are published by a select few individuals or newspapers with a clear focus of interest. What you are seeing is french newspapers being especially interested in fines for big corporations, this is without a doubt a direct result of the current political situation in France.
- henrikschroder 7y agoAt the time of the GDPRpocalypse last year, there were a lot of discussions here, and a lot of FUD being slung around about how if your US website wasn't 100% GDPR-compliant you'd be handcuffed if you set foot in an EU airport bla bla bla, or that minor infractions would incur the maximum penalty of millions of euro, bankrupting your awesome adtech startup bla bla bla. Most of it was fueled by the clash between US and EU jurisprudence, the legal systems are actually pretty different. Some of us argued that no, this is not the apocalypse, the law says that fines will be proportionate, and the various national agencies will work with you to ensure you are compliant. And unless you willfully do the kind of shady shit the law is meant to protect against, you're fine. Seems we were right. This list looks pretty sane to me, with one exception. 250k€ for using the microphones of all users of an app to spy and determine if they were in a pub that showed football matches without a license. Fuck yeah. 400k€ for a hospital that had effectively unrestricted access to all patient files for all staff. Yes. What would the HIPAA-equivalent fine be? 1400€ for a police officer abusing systems doing lookups for personal gain. Yes. 170k€ for a school district allowing public access to personal data of all minor-aged students. Yes, yes, yes. The one exception is the fine on Google in France. This is purely a political bullshit game over control and loss of control.
- moduspol 7y ago> Seems we were right. Arguably, and so far. There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses, and just because nobody's been hanged over it in year one doesn't mean it won't be abused, oppressive, or have other negative unintended consequences in the future.
- contras1970 7y ago> There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses food safety regulations have a chilling effect on businesses that would try and sell arsenic-laced food. dumping poisonous byproducts of a manufacturing process in a river will also net you a stomping by the society, another instance of a chilling effect of regulations. i'm happy with these chilling effects, they relieve me of the need for constant vigilance. they enable our society to function. we do not need to fear for our mental of physical health and (private) lives all the time, we can focus on higher-order things instead.
- ProxCoques 7y agoWeird there's no fines in UK.
- Aengeuad 7y agoAs somebody else pointed out, they're being tracked by the ICO [0]. I think they previously had a blog where they documented enforcement while the UK was still under the older Data Protection legislation but I can't seem to find it. [0] https://ico.org.uk/action-weve-taken/enforcement/ https://ico.org.uk/action-weve-taken/enforcement/
- ascorbic 7y agoFrom what I can see, noe of the fines use the GDRP. They're all for pre-May 2018 breaches, so use the old DPA.
- duckmysick 7y agoThe Information Commissioner's Office maintains a list of the UK fines. > The ICO has specific responsibilities set out in the Data Protection Act 2018, the General Data Protection Regulation (GDPR), the Freedom of Information Act 2000, Environmental Information Regulations 2004 and Privacy and Electronic Communications Regulations 2003. https://ico.org.uk/action-weve-taken/enforcement/?facet_type=Monetary+penalties&facet_sector=&facet_date=&date_from=&date_to= https://ico.org.uk/action-weve-taken/enforcement/?facet_type... https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2019/06/ico-fines-telecoms-company-ee-limited-for-sending-unlawful-text-messages/ https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...
- jonasb 7y agoThe ICO maintains an official list of fines in the UK https://ico.org.uk/action-weve-taken/enforcement/?facet_type=Monetary+penalties&facet_sector=&facet_date=&date_from=&date_to= https://ico.org.uk/action-weve-taken/enforcement/?facet_type...
- M2Ys4U 7y agoNotably none of these are (yet) for violations of the GDPR. The ICO has issued enforcement notices, but they haven't levied any penalties so far.
- jonasb 7y agoAh, my bad. Only checked the date of the decisions and assumed they were related to GDPR.
- mattmanser 7y agoThe Uber one is odd, US fined Uber $148m, the UK fined them £385,000.
- NeedMoreTea 7y agoOctober and November 2016 - Pre-GDPR, the DPA was still in force. They were fined 80% of the maximum under DPA.
- crisnoble 7y agoDoes anyone know of a similar list for ADA violations?
- kradroy 7y agoWhy are there so many violators marked as "unknown"? Is that from the sanction being redacted or the aggregator's lack of information? The header paragraph states that not all violations are made public, but the ones that are made public can also be redacted?
- nishantvyas 7y agoDoes enforcement changes behavior? I guess the time will tell. But I do expect some insurance companies start selling GDPR coverage policies soon.
- downandout 7y agoMy guess is that nobody is going to sell coverage for fines that could range up to €20 million that can be assessed under a set of regulations as vague, difficult to follow, and up to interpretation as GDPR.
- izacus 7y agoThere's nothing difficult to follow in GDPR... unless you're specifically trying to continue collecting too much personal data while trying to skirt the law.
- shaki-dora 7y agoContracts to insure against legal fines are considered immoral and therefore unenforceable. You can get liability insurance, but that's different (not legal fines but civil law damages).
- oh_sigh 7y agoIf you look back at comments as GDPR was first coming into effect, you saw a lot of comments here along the lines of 'The EU doesn't want to fine anyone. They want you to become compliant, and will help you do so, and you won't be fined unless you were intentionally being non-compliant' But then look at this example from Germany: > Please note: According to our information this fine has been withdrawn in the meantime. Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to deal with a service provider who does not want to sign a processing agreement. After not answering Kolibri Image in more detail, the case was forwarded to the locally responsible Data Protection Authority of Hamburg. This Auhtority then fined Kolibri Image as controller for not having a processing agreement with the service provider. Kolibri Image has stated that they will challenge the decision in front of court since they are of the opinion that the service provider does not act as a processor. The company emailed the authority asking for advice on how to deal with a service provider who didn't want to cooperate with GDPR, then the authority ignored his request, forwarded their information to another authority, which then fined them for the exact thing which they was asking for advice on. Yes, the fine has apparently been withdrawn, but how much time, money, and mental capacity did Kolibri Image have to spend dealing with this before the authority decided to drop it?
- mikekchar 7y agoI'm not actually that sympathetic. If you have a processor that does not want to sign a processing agreement, you have to stop using them. There is no leeway on this issue in GDPR. You are responsible for ensuring that third party processors you engage agree to handle the data lawfully. There's not a lot of context to go on, but it seems to me that the company in question is just stalling. I literally can't think of a legitimate reason for their opinion that the service provider "does not act as a processor". Either you are sending PII to them or not. If you are, then they are a processor. If not, then it's not related to GDPR in any way.
- oh_sigh 7y agoThat's fine, but my point was not that Kolibri Image took the appropriate steps immediately, but whether the commenters here on HN were correct in their estimation that the various data protection authorities would help you resolve compliance issues versus just issuing you fines.
- mikekchar 7y ago250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user's microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I'm a little bit surprised that the fine is this low: "The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent."
- EdgarVerona 7y agoI'm impressed at the creativity and disgusted that they thought this would be okay at the same time.
- guywhocodes 7y agoConsidering some others in there this feels like a slap on the wrist
- cuban-frisbee 7y agoIf they stopped the conduct then it is not supposed to be anymore than a slap on the wrist. GDPR is meant to correct behaviour, not to punish.
- jordiburgos 7y agoVery little money for the kind of intrusion they did.
- downandout 7y agoI expect there would have been a warning given in that case before assessing a fine. What makes you expect this? Unless you and I have read entirely different versions of GDPR, no provision of GDPR requires any warning of any kind prior to issuing fines. Edit: the downvotes on this are coming in fast. Because you are downvoting it, you must know of a specific section of GDPR that requires warnings to be issued (otherwise you wouldn’t be downvoting it, right?). So, along with your downvote, please reply to this comment with a link to the specific section that requires warnings, and I will be happy to say that I am wrong.
- tgsovlerkhgsel 7y agoIt does not explicitly require warnings, but Art. 83 (https://gdpr-info.eu/art-83-gdpr/ https://gdpr-info.eu/art-83-gdpr/) requires that the authority, when deciding whether to impose a fine, takes into account a number of things. It would be hard to argue for an instant fine if the things listed in the article were favorable in a specific case.
- NeedMoreTea 7y agoIt shouldn't need to be explicit when the enforcement agency has the discretion of deciding appropriate action and whether or not to prosecute. Otherwise there's no discretion and they become rubber-stamp agency. By the same token UK law doesn't include warnings in the Acts for offences that almost always get a warning or caution on first offence, e.g. possession of class B drugs. When you get to actual penalties, all EU law has the principle of proportionality under it, and has since about the sixties. I know it's written into some treaty or other. There's been countless appeals to the EU courts that some penalty or other was disproportionate.
- downandout 7y agoIt does not explicitly require warnings I think that’s all anyone needs to know.
- cyphar 7y ago
- Proven 7y agoIs this meant to help increase IT investment in the EU? If so, it may not work. The message people get is "GTFO".
- quelltext 7y agoCan anyone explain the N26 case to me? I've tried to read two articles on it and they don't make sense. It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article. But somehow this was not the case for those old accounts that were closed? How can you close an account but it's still an operational account? Like, was it still possible to send money to it etc.? My guess is that the article is wrong and this was simply about them preventing legitimate users to close and then reopen a new account. I have a hard time believing they were not allowed to keep that data for some time after acccount closing. It seems to be more about how it was used.
- londons_explore 7y agoMy guess is a user requested his data deleted, but N26 just disabled the account. Then the user signed up again, enabling the same account. The user then saw their old data hadn't in fact been deleted, and complained to the regulator.
- seqastian 7y agoAre banks even allowed to wipe your whole account record? They probably have to keep most of it for tax collectors.
- pluma 7y agoIf they only kept the data that was necessary for legal compliance with tax regulations, they wouldn't have been fined. That's explicitly allowed. That they were fined suggests they just kept everything, far beyond what they had to keep.
- wigginus 7y agoAccording to the annual report (https://www.zaftda.de/tb-bundeslaender/berlin/695-tb-lfd-berlin-2018-ohne-drs-nr-vom-28-03-2019/file https://www.zaftda.de/tb-bundeslaender/berlin/695-tb-lfd-ber...), N26 used to add all former customers to a black list, which is not allowed if there is no suspicion against them. >>Eine schwarze Liste für ehemalige Kundinnen und Kunden, gegen die keine Verdachtsmomente bestehen, ist rechtswidrig. translated with deepl: >>A blacklist for former customers against whom there is no suspicion is unlawful.
- closeparen 7y agoTwo of these are much more intense than I would have guessed: >The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the Central Electronic Register and Information on Economic Activity, and processed the data for commercial purposes. The authority verified incompliance with the information obligation in relation to natural persons conducting business activity – entrepreneurs who are currently conducting such activity or have suspended it, as well as entrepreneurs who conducted such activity in the past. The controller fulfilled the information obligation by providing the information required under Art. 14 (1) – (3) of the GDPR only in relation to the persons whose e-mail addresses it had at its disposal. In case of the remaining persons the controller failed to comply with the information obligation – as it explained in the course of the proceedings – due to high operational costs. Therefore, it presented the information clause only on its website. According to the UODO this is not sufficient. So, basically, only use open source datasets that come with contact information for every subject. and >The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting a customer’s request to have his phone number erased after arguing that it was in the company's legitimate interest to process this data in order to enforce a debt claim against the customer. In its decision, the NAIH emphasised that the customer’s phone number is not necessary for the purpose of debt collection because the creditor can also communicate with the debtor by post. Consequently, keeping the phone number of the debtor was against the principles of data minimisation and purpose limitation. As per the law, the assessed fine was based on 0.025% of the company's annual net revenue. You can't just retain the database rows pertaining to accounts with current or likely litigation, but must choose the specific fields relevant to the nature of the dispute. Even the companies that successfully implemented propagation of deletion across their systems are probably going to get spanked for this one when some column in some backwater warehouse backup isn't strictly necessary for the precise claims in that account's lawsuit. Wow. I hope this puts to bed suggestions that others were "overreacting" to GDPR, that there would be anything other than the meanest, most aggressive, most literal application to every case. Maybe this is a good thing! Maybe everyone needs the fear of God put into them. But I hope GDPR boosters who went around minimizing the threat to good-faith actors admit that they were wrong.
- j2kun 7y agoMany people are complaining about some fines, but here are some others I see that are evidence of this working extremely well: - A police officer was fined for using his department's tools to get someone's private phone number for his personal use - A rental agency was fined for leaving renter's private data (ids, etc) open to the public for six months after being notified of the vulnerability - A company was fined because they were continuously filming their employees at work without explanation - A political candidate misusing private citizen data for campaign purposes. - Rental car companies tracking drivers by GPS without notifying them - Hospital staff having fake doctor profiles to view unrestricted patient data This is convincing me that GDPR is a great success.
- Matticus_Rex 7y agoAll but maybe one of those looks like it was illegal prior to GDPR, so I'm not sure GDPR is what you're praising.
- claudius 7y agoGDPR unified and clarified all the different directions and laws active in EU member states before. So while most of those indeed were illegal before in one or more member states, all of them are illegal now in all member states. As such, GDPR does not really extend privacy protection de jure but merely helps enforcement by unifying protections de jure and hence allowing for a more efficient enforcement de facto.
- stordoff 7y agoWhich one, out of interest? I can imagine all of them being illegal in some member state.
- Matticus_Rex 7y agoDepending on the circumstances (I didn't actually look into it) the rental car tracking could have been done in ways that were at least arguably legal under EU law (though at least several member states had legislation that would have covered that).
- hdfbdtbcdg 7y agoGlad to see some enforcement. Reputable companies have used resources ensuring compliance. Good to see it hasn't been wasted.
- kjerzyk 7y agoMaybe I’m just looking at a wrong place but can you tell me what currency is used in fines? I’m assuming it’s EUR but wanted to double check.
- deleted 7y ago[deleted]
- frereubu 7y agoSomething I often see in discussions about GDPR on HN is that the law is vague. A hugely valuable comment on a previous GDPR discussion (which unfortunately I've been unable to track down) pointed out a marked difference in style between US and EU law. In the US, laws are usually very detailed and explicit about what will happen in all cases. If that's what someone is expecting, EU law is indeed very vague - because the underlying idea is that judges are trusted to interpret law in the context of constitutions, precedent and so on. EU citizens are much more used to this kind of language, so many of the discussions on here are people shouting past each other because there's a more fundamental issue about the way laws are phrased. If you're in the US and want to quibble with the language, please bear in mind the broader context of EU law. And if you're in the EU please bear in mind that people in the US are used to much more explicit legal language. If we all did that some of the discussions on HN about GDPR might be more meaningful. The other thing that seems to happen a lot is that people are looking for a stick - any stick - to beat GDPR with. The current top-voted comment - https://news.ycombinator.com/item?id=20279249 https://news.ycombinator.com/item?id=20279249 - is a prime example. These lists of fines often don't give context (which, to be clear, is a failing of the list too) and often when you dig into these things you'll find that the ruling is entirely sensible. People need to give a bit more credit to legal systems than to think "Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany" could possible be true. If a fine seems ridiculous, do a bit of digging before you take a short summary at face value, and you won't be left with egg on your face when people point out what actually happened.
- ddffre 7y agoOh wow
- swebs 7y agoThere sure are a lot of political parties, and not many big tech companies in that list.
- kitchenkarma 7y agoWhat do you do if e.g. Instagram ignores your GDPR requests? I have sent them multiple emails about misuse of my personal data and they only replied with a template that didn't address my emails?
- Nimelrian 7y agoYou inform your national data protection authority: https://edpb.europa.eu/about-edpb/board/members_en https://edpb.europa.eu/about-edpb/board/members_en
- easytiger 7y agoInteresting one from Spain, accessing user's microphones to crowdsource publicbroadcast violations: > The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent.
- qseraserasera 7y agolooks like there may be a data entry error for Czech Data Protection Auhtority (UOOU) summaries. they may have mis-spelled authority.
- tjaad 7y agoHow come The Netherlands does not appear in the list?
- KingMachiavelli 7y agoA was curious about the dashcam fine so I looked it up and it seems some vary ordinary usages of cameras are violating GDPR: > It was a camera recording the use of a car from the driver's point of view, which is illegal. Two people were reprimanded for using surveillance cameras for their own home without permission. I assume "driver's point of view" means looking out of the front windshield? Is this not how dash cams are meant to be used? (On second though perhaps this is a translation issue... the article was in German). And then I assume the surveillance cameras were mounted outside and recorded people in public? Both of the possible scenarios here seem pretty benign and ordinary by US standards.