4 ms·
This looks like a GDPR breach. Does anyone know where i can find the details for the dropbox GDPR representative?
by gdhbcc 7y ago
This looks like a GDPR breach. Does anyone know where i can find the details for the dropbox GDPR representative?
- daniel_iversen 7y agoWhy is it a GDPR breach when a Dropbox screen clearly explains to the user clicking the link that other users will see your details if you proceed? (Just curious, it may well be an issue, I just don’t know how).
- tasogare 7y agoI’m not expert in the matter but I’m sure just explaining some bad behavior does not make it legal if it were illegal.
- marcinzm 7y agoGDPR, as I understand, does not allow removing unrelated features if someone does not agree to have their privacy broken. For example, opting out of ad tracking cannot make the site be blocked for me. In this case, there is no opt out button other than not using the feature and the feature does not require this information sharing.
- dual_basis 7y agoEssentially Dropbox is arguing that, due to the way they have implemented it, the feature does require this information sharing. While it clearly could be implemented many different ways, and I agree Dropbox should do better in this case, I think this is one of the difficulties in enforcing something like GDPR. Almost anything could be made to work in an anonymous way, so where do you draw the line? When signing up for Facebook or an email account, for example, there is no reason they need my phone number. Sure, they say it is for password reset purposes, but there are other solutions for this, or I can simply agree not to be able to reset the password for that account... etc.
- marcinzm 7y ago>Essentially Dropbox is arguing that, due to the way they have implemented it, the feature does require this information sharing. I'm honestly curious, which part of the feature requires every user to know every other user who has viewed the page?
- dual_basis 7y agoMy point was that no, of course the feature doesn't require it, but their particular implementation of the feature does. For example, maybe they implemented per-user sharing first, which obviously would need to know who is accessing the document. Then they realized there are some use cases for sharing the document publically, but they basically just treated this (internally, i.e. according to their implementation) as a wildcard in the authentication portion. That is to say, the public sharing works exactly the same as the per-user sharing, but with a * in the "allowed users" field. Clearly it doesn't have to and should not be this way. My point was that: 1. They are saying that their particular implementation did require it to be this way. 2. Almost every web app could be made to require less private data from the user, however if this is something that GDPR is going to enforce then there will end up being some subjective analysis (according to non-tech lawyers?) as to whether a particular implementation was in violation.
- johnisgood 7y ago> opting out of ad tracking cannot make the site be blocked for me. Does this apply to cookies? I am asking because lot of websites have "necessary" cookies and there is no way to opt out of them (other than by closing the tab), and if there is and you do, then you cannot proceed further. I really do not understand why some cookies would be necessary to view a page though, but I have seen this on A LOT of sites.
- gog 7y agoYou do not need consent for necessary cookies.
- johnisgood 7y agoThen what is the reason for websites asking me to accept? Some websites also offer me the ability to select/deselect some cookies, but cannot deselect "necessary" cookies. There are websites that do not function until I accept. Some sites explicitly state this, and they do ask me to accept/consent. Example: https://edigital.sk https://edigital.sk On the right, you will see a down-arrow, click on that. You can clearly see the first checkbox on the left being checked and disabled, it is the "necessary" or "essential" cookies to what I am referring. You cannot deselect. On top of that, there is no way to close the popup (?), it is by design. Of course there are ways to circumvent it, but that is besides the point. There are many other websites like this, but I cannot remember them. :/
- gog 7y agoI am not seeing anything on your example. But necessary cookies are things without the site can not function (like logging in). I suppose most of the time the box is there to allow you to consent to additional cookies as well. There are also a lot of broken implementations out there.
- deleted 7y ago[deleted]
- 7y ago
- alpaca128 7y agoIf I understand correctly this warning/explanation only appears for the user sharing the document, not for anyone else who opened it(and whose information is still embedded).
- daniel_iversen 7y agoThat’s not correct. Unless there’s been a temporary regression then the warning explicitly happens for the person opening the document (the person you have shared it with)
- imtringued 7y agoJust read the tweet. It's not just any user. It's everyone on the internet.