4 ms·
That is an incredibly broad interpretation of the chilling effect since in Europe you haven't had the legal right to misuse peoples private information that the
by Aengeuad 6y ago
That is an incredibly broad interpretation of the chilling effect since in Europe you haven't had the legal right to misuse peoples private information that they've provided to you (a business) since the early 80s at least. To run foul of the GDPR you actually have to be infringing upon other peoples legally protected rights, and maybe you consider not being allowed to post private or personal conversations in full to be 'chilling' but then the opposite is equally as true, publicly doxing people has an incredible chilling effect on public discourse yet it's something constitutionally protected under America's rather special free speech amendment.
As far as legal fees goes, how is this any different than any other frivolous letter from a lawyer? Do you find that it's common in your experience for independent web developers to close up shop as soon as they get a cease and desist? I really don't mean to sound patronising but the concern here comes across as an incredibly American view point, much of the world uses the English rule when it comes to legal fees where the losing party pays the legal fees (within reason) for the winning party[0], getting taken to court is still no walk in the park and it doesn't completely stop frivolous lawsuits but the difference in lawsuit culture should speak for itself.
But all of that is a moot point, the GDPR is a civil law with civil penalties and it's not something you're taken to court over, as the other commentator mentions I'm not even sure if lawyers can deal with GDPR complaints privately, instead what happens is each EU27(+UK) member state has an independent public authority[1] who is responsible for dealing with GDPR complaints when the complainant can't resolve the issue with you directly. Some countries like the UK only sparingly give large fines to larger companies while others like Spain and the German speaking countries hand out fines for breaking the law like candy[2].
So how does the GDPR restrict running an IRC logging service (in the EU+UK)? At the very least users need to be informed in a clear and simple manner of what you are doing, this could be done through sending a notice or a message to a user when they join a channel. You may need to provide an opt-out mechanism which would be a lot better for compliance and almost completely covers your arse but it's likely not necessary, informed consent can likely be assumed when they don't leave the channel after being notified that it's publicly logged, and if the issue of consent is truly a concern and you don't want to selectively allow users to opt-out of logging to preserve context in logs what you can do instead is have the channel opt-in where the user never receives voice until explicitly consenting to the log bot. Tech support (i.e., programming, distro) channels likely have a better argument for assuming consent as the nature of these channels isn't for personal discussions, it's common for these channels to have logging bot as well. For the most part what users publicly send to a channel is not considered PII, this is especially true for tech support orientated questions. You may need to provide a mechanism to modify/(pseudo)anonymise/remove personal information, it'd be smart to modify the logger to tokenise user and host names to make replacing text easier and this also allows you to anonymises the data incredibly easily.
IRC being what it is works in your favour here, the only PII you should ever have on users are their usernames(+ 'name' field, maybe 'real name' field too, host mask) and potentially their IP if the IRC server hasn't already anonymised it for you, some PII can still leak into logs like if a user accidentally pastes their email address publicly and it'd be prudent to deal with requests asking you to remove it, but for the most part the extra burden placed upon you would only be to deal with those requests, and as already discussed most logs aren't considered PII so you shouldn't need to remove much. It would be unlikely that somebody even complains to the relevant supervisory authority but if that were the case they'd first try to establish that you've handled requests to remove data appropriately, and then that you have the grounds to be doing what you're doing, etc. But if that's too much of a burden and you're not a European citizen then you have nothing to worry about, ignore the requests and follow your own countries laws, as stated it's constitutionally protected in America.
I know you were making a general point about the effect the GDPR has on the internet but I really do disagree with the parallels to the chilling effect, to have your freedom of expression censored you have to actively ignore other peoples rights to privacy, and as far as IRC logging bots go it's likely one of the easiest services to make complaint.
[0] https://en.wikipedia.org/wiki/English_rule_(attorney%27s_fees) https://en.wikipedia.org/wiki/English_rule_(attorney%27s_fee...
[1] https://kirkpatrickprice.com/blog/whos-enforcing-gdpr/ https://kirkpatrickprice.com/blog/whos-enforcing-gdpr/
[2] https://www.enforcementtracker.com/ https://www.enforcementtracker.com/