12 ms·
Intent to issue €2.5M fine to Disqus over GDPR breaches
- gardaani 5y ago"Disqus breached the accountability principle by wrongfully considering the GDPR did not apply to data subjects in Norway" Interesting that Norway isn't part of EU, but they implement GDPR.
- 5cents 5y agoNorway is often quicker to implement EU regulations than EU countries themselves, for example, in 2018 only Malta had implemented more regulations than Norway [1] (the comparison is a bit skewed as not all regulations applies to Norway so they have fewer to implement) [1] https://arkiv.klassekampen.no/article/20180420/ARTICLE/180429996 https://arkiv.klassekampen.no/article/20180420/ARTICLE/18042...
- mmgu 5y agoWe part of the European Economic Area (EEA) which is quite close to being a EU member, but without voting rights. Norway voted two times on membership and the compromise was EEA.
- gspr 5y agoTo add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).
- wil421 5y agoDid the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. Some documentaries even call it the worlds most toxic food.
- gspr 5y ago> Did the Norwegian fishing (salmon farming) industry have a big part in the EU vs EEA decision? We definitely have to split the Norwegian fisheries industry into two: Norway has, and has for a long time had, a sizable wild fishing industry. The fish farming industry is a much newer one. I was a kid last time we had a referendum on membership (1994), so I'm not sure, but I believe the fish farming industry wasn't even a major thing back then. The classical fisheries industry definitely was a big part of the reasoning. Today, I would wager that opponents of full membership are mostly riding on the same vague of opaque euroskepticism that brought us Brexit, combined with the sickening idea that Norwegians are somehow magically special and exceptionally good at things. Granted, my personal views on the matter definitely color this take. > From what I’ve seen lately about Norwegian Salmon farming I wonder if it would get past the EU regulations, if they even have any related to fish farming. I doubt that would be an issue. > Some documentaries even call it the worlds most toxic food. I really wish people would stop spreading this unsubstantiated bullshit. I have no connection with or investments in fish farming, but this claim was making the rounds a few years back, and as far as I can tell it's a completely unsubstantiated smear. It keeps getting repeated, but trying to actually get to the source just reveals a tangled web of self-referential claims. There's plenty of problems with fish farming without having to make up shit about "toxic food". The two biggest being the horrid effect the escaped farmed fish have on the natural populations (they carry different diseases and parasites that can wipe out whole rivers of salmon, for instance), and the effect of over-feeding on the nearby ecosystem (you dump enormous amounts of feed into a relatively small volume of water, and far from all of it is actually consumed by the farmed fish). In addition to this, the feed often comes from just as unsustainable sources as the worst of the "Amazon beef". Hopefully the latter can be fixed with transparancy and regulations, though. Plenty of problems with fish farming without needing to fabricate new ones. But then again, it may be the only solution to prevent overfishing (if we want to keep eating fish, which is certainly better overall than eating beef).
- KingOfCoders 5y ago"Norwegians are somehow magically special" Norwegians are magically special in their relationship to nature.
- ookware 5y agoNorway, whilst not in the EU, has very close links and often aligns with EU laws. Incidentally, the UK has now left the EU but has retained the GDPR in domestic law.
- gspr 5y agoIt goes much further than just "often aligning with EU laws": Almost all EU regulations and rights – except those pertaining to agriculture, fisheries and the customs union – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't). For all intents and purposes, apart from the three areas stipulated above + voting rights, Norway is an EU member. A business that operates in Norway (outside of the agriculture or fisheries sector) can be seen as operating in the EU. Likewise, Norway-based users of a service with a business presence in the EU are protected by EU laws, like the GDPR. Norwegians have the same access to the EU labor market as, say, Germans. And EU citizens have the same right to take up residence in Norway and interact with the Norwegian state under the same conditions as a Norwegian.
- tpxl 5y agoNorway kind of has a special relationship with the EU. They aren't members, but they follow some of the laws and participate in some programmes. Wiki quote on Norway: > After the 1994 referendum, Norway maintained its membership in the European Economic Area (EEA), an arrangement granting the country access to the internal market of the Union, on the condition that Norway implements the Union's pieces of legislation which are deemed relevant (of which there were approximately seven thousand by 2010) Successive Norwegian governments have, since 1994, requested participation in parts of the EU's co-operation that go beyond the provisions of the EEA agreement. Non-voting participation by Norway has been granted in, for instance, the Union's Common Security and Defence Policy, the Schengen Agreement, and the European Defence Agency, as well as 19 separate programmes.
- zegl 5y ago> but they implement GDPR The GDPR is great for the citizens! My wish is that more countries follow the EU and implement similar and compatible laws. An interesting example of this is that the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA.
- kzrdude 5y agoI think GDPR has been pretty great for IT consultancy businesses as well..
- teachingassist 5y ago> the UK made sure to implement a clone of GDPR in UK law before leaving the EU/EEA. I suggest instead that the UK government have deliberately extracted themselves from the EU's version of GDPR, by cloning it. The UK is now an external "third country" in terms of EU GDPR, and has a data border with the EU - whereas Norway sits within EU GDPR.
- KingOfCoders 5y agoAs a private citizen, I love GDPR. As someone responsible for implementations, I hate it.
- KingOfCoders 5y agoMostly because - for understandable reasons - the EU parliamant kept GDPR vague on implementations. I've implemented PCIDSS and SOX several times which was much easier, because there is implemantation documentation and everyone knows what to do.
- michaelbuckbee 5y agoEven for full EU members enforcement of GDPR falls to institutions within each individual country.
- GrumpyNl 5y agoFrom the link "We consider the infringements to be serious. Disqus has tracked which news sites and articles readers in Norway have visited. Additionally, this has happened without the users’ knowledge." Based on that statement a lot will follow.
- zpeti 5y agoNot so long ago I stumbled on https://data.disqus.com https://data.disqus.com, which basically outlines what they were fined for. They should probably take that site down soon...
- Aachen 5y ago"Our services: [...] Identity Matching", "Hundreds of data points to create cross device profiles", "215M emails collected". Hallmarks of a company you definitely want to embed on your site...
- hunter2_ 5y agoAside: isn't it weird how often "email addresses" is shortened to "emails"? At first glance I had to contextually infer whether it was 215M addresses or 215M messages (pieces of mail) because we also often shorten the latter to "emails" when working through our inboxes. If you're running a marketing campaign and say "today we finally hit 1000 emails" without further clarification, nobody will know if that's 1000 subscribers or 1000 newsletters.
- djoldman 5y agoWhat is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
- nso 5y agoYes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message
- Grollicus 5y agoOn the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.
- dopidopHN 5y agoSomehow that rather large and affluent market is not dropped.
- ForHackernews 5y agoLoads of US media sites do that, especially local TV stations and papers.
- miki123211 5y agoWhat if I (as a European visitor) access the website through a VPN, something I'm legally allowed to do?
- soneil 5y agoIt doesn't change much. If you have to jump through a VPN to get there, they can make a very reasonable claim that they're not targetting or serving the european market. It doesn't have to be bulletproof, it just has to support the claim.
- alfyboy 5y ago"Norwegian internet users were tracked by Disqus because the company did not know that Norway introduced the common European privacy regulation GDPR in 2018. It thus took 511 days before Norwegians were incorporated into the company's "privacy mode" for GDPR countries and previously collected information was deleted."[0] It seems that there was some setting that is enabled by default in all other countries than countries with the GDPR law. Also, from an earlier article: "The company also claims that they have not shared Norwegians' online visits with anyone other than the parent company Zeta Global. Zeta Global describes itself as a 'data-driven marketing company"' that has information on over two billion identities."[1] As a Norwegian, it will be interesting following this case. [0]: https://nrkbeta.no/2021/05/05/datatilsynet-varsler-bot-pa-25-millioner-mot-amerikansk-selskap/ https://nrkbeta.no/2021/05/05/datatilsynet-varsler-bot-pa-25... [1]: https://nrkbeta.no/2020/09/04/datatilsynet-mener-det-er-sannsynlig-at-disqus-har-brutt-personvernloven/ https://nrkbeta.no/2020/09/04/datatilsynet-mener-det-er-sann...
- nerdponx 5y agoThis is great. Companies should fear GDPR and should consider disabling data collection by default. Mission accomplished.
- underyx 5y agoWouldn't it be funny if this was caused by some YAML configuration reading the country code "no" as "false".
- KingOfCoders 5y agoYes, loved that HN story.
- FriedrichN 5y agoCan you share it? I must've missed it and I'm in need of a good laugh.
- 5y ago
- surround 5y agoTry blocking Disqus with uBlock Origin, turns out you probably won't miss it ||disqus.com^ You could also try a dynamic filter and disable it on a per-site basis * disqus.com * block Or try "medium mode" to take care of Disqus and a whole host of other third party resources that track you https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium-mode https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
- jerrygoyal 5y agocurious can't it be done by disabling third party cookies alone as Disqus need cookies to work?
- dcdc123 5y agoPrivacy Badger replaces it with a widget that allows you to enable it with a button click if you want. It is pretty nice.
- VWWHFSfQ 5y agoIt's very nice. I wish this was just how the web worked for stuff like this.
- surround 5y agouBlock Origin had this at some point but Mozilla didn't approve it for some reason. https://github.com/gorhill/uBlock/commit/7c22a312945a2bff41a2b5696a7e54f1c4c01cf2 https://github.com/gorhill/uBlock/commit/7c22a312945a2bff41a...
- mmgu 5y agoMore background: The fine is mainly based on the fact that Disqus forgot to enroll Norwegian IP-addresses into their GDPR «privacy mode». That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus. Major sites like the Wirecutter, The Hill, 9to5mac, Breitbart had enabled the setting in 2019. Of the 23 websites I contacted, all 11 that responded told me they were unaware of the tracking and had turned the setting off. (I wrote the investigative articles in 2019 for the Norwegian public broadcaster NRK.) A thread in English from then explains most of the findings: https://twitter.com/martingund/status/1207327648093003777 https://twitter.com/martingund/status/1207327648093003777
- chirau 5y ago"forgot"
- maccard 5y agoForgetting for a single country (which is also not part of the EU) certainly seems plausible, more plausible than a targeted attempt at undermining the GDPR in a very specific country
- zepolen 5y agoThey probably used yaml for their config...
- speedgoose 5y agoFor people who are not aware, if you write the value no in YAML, it parses it as the boolean false which is then usually converted back to the string "false". The solution is to write "no" and not no, but Norway is the only country code requiring this so a lot of people forget about it. For example I noticed this week that an environment variable in a few of my Norwegian company's deployments was "false" and not "no".
- bellyfullofbac 5y agoI thought their title mis-summarized the text (text says 25 million Norwegian Kroner, title says 2.5 million Euro). Actually it's close enough, Google says NOK 25 million is EUR 2.484 million.
- hedora 5y agoI thought it said 2.5B, and thought “they’re finally enforcing the GDPR; great!” Oh well. (Edit: their revenue was $368M over the last 12 months, so €2.5B would be too high. The current fine is still an order of magnitude or two too low to change meaningfully change anyone’s behavior. It’s a couple of days of revenue. They could simply write it off as the cost of doing business, especially if they think the GDPR compliance will impact business growth) https://stockanalysis.com/stocks/zeta/ https://stockanalysis.com/stocks/zeta/
- joebob42 5y agoI doubt they can really write it off as the cost of doing business, I imagine they are running in the red with respect to the country of Norway this year, which is the place they made the mistake.
- MaxBarraclough 5y ago> Based on our investigation so far, we believe that Disqus could not rely on legitimate interest as a legal basis for tracking across websites, services or devices, profiling and disclosure of personal data for marketing purposes, and that this type of tracking would require consent Good to see them taking this seriously. I get the impression a lot of sites/services make expansive use of the legitimate interest provision.
- Maarten88 5y agoYes, it is really maddening: they make you consent to their "legitimate interest" cookies, conflating legal terms to confuse people into accepting everything. Ad-tech companies get more and more emboldened lately. They see that the GDPR is not really enforced, they assume that big, cash-rich companies will get taken on first, competitors are doing it too, so they gamble they can get away paying lip service to GDPR while continuing their illegal tracking practices. I have seen several startups pitching schemes that seem blatantly illegal to me, while assuring that their tech is fully compliant. Often using the words "legitimate interest" to prove this point.
- 411111111111111 5y agoTo play devil's advocate: that might become the going strategy. They're gonna be profitable as hell until they get fined and aren't allowed to continue after all... But then it's just a matter of closing that enterprise down and creating a new one. They can keep apis stable and give the big corporations plausible deniability as "the contractor said they're compliant"
- xxs 5y ago> "the contractor said they're compliant" this part wont work w/ GDPR - this is not the US. I've mentioned it someplace else - the contracts with the contractors have quite explicit clauses about liabilities about data breaches/leaks as the fines would still be applied to the main entities. With regard to GDPR, personal data is a liability and it should be handled with appropriate care.
- peanut_worm 5y agoQuestion to anyone who knows; I am assuming if you don’t live in the EU they can’t make you pay a fine. What do they actually do to stop you from doing business in the EU then? Do they outright block your website? I can’t think of how they’d stop you from collecting ad revenue from EU visitors otherwise.
- kstrauser 5y agoI'm curious about this, too. I once commented that, say, my hobby website isn't subject to the GDPR because I love, work, and play in the US and that's where my blog is, too. Turns out some people have very strong opinions about this and insisted that I am subject to the GDPR. But as a practical matter, how? I don't have a presence outside the US. Even if I violated a EU law, is there a reason I'd ever need to care? For instance, I know I've violated some Chinese laws by criticizing their government, but I'm OK with that because, really, what are they going to do about it? As an aside, I'm completely behind GDPR, CCPA, and related privacy laws. I think they're great. I definitely comply with the spirit of the laws in my hobby projects by doing things like not tracking anonymous users, not retaining identifiable logs, etc. This isn't me trying to get away with something nefarious. More like, I don't (and won't) bother with things like cookie banners even if GDPR would want me to.
- wizzwizz4 5y agoGDPR doesn't actually require cookie banners. If all the tracking and data protection you do is justified, justifiable and obviously necessary for the lowest-common-denominator service you provide, you don't even need to ask for consent (though do let your users know what's up, anyway, with at minimum a Privacy Notice in the footer, because that's just common decency). If a company asks for GDPR consent, either: • They have cool, optional features of their site / service / system (though they could just ask at run-time, when you try to use those features, in most cases); or • They're doing something dodgy and want to wave a magic wand and remove the dodginess by getting you to “consent”.
- dtech 5y agoWorst case they could block your site, but that's not going to happen. Note that if it is a personal website you are not subject to GDPR. GDPR only applies to companies and organizations. Also note that most stuff that a layperson would say is reasonable for a website to function isn't a problem in GDPR.
- mikl 5y agoIn case anyone should be wondering, the 25M NOK fine is just about $3M USD. Not something that will seriously hurt the creepy jerks running Disqus, but at least enough for them to notice.
- rapnie 5y agoGood reason to mention "Disqus, a dark commenting system" again to remind everyone to avoid using it on your blog or website (it comes integrated with a lot of projects, like static site generator themes). https://news.ycombinator.com/item?id=26033052 https://news.ycombinator.com/item?id=26033052
- greeklish 5y agoWhy Reddit or Discοurse haven't created a competing service to Disqus goes beyond me.