TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Discord fined €800k for failing to comply with several obligations of the GDPR

260 pointsby Signezover 2 years ago

17 comments

theCrowingover 2 years ago
Sorry but the points are totally valid. If you delete your account your messages are still available with a userid that if someone has it can be traced back to you. They also don't delete files or pictures you uploaded alone for this they should get fined.
评论 #33639043 未加载
评论 #33639203 未加载
评论 #33639241 未加载
评论 #33638996 未加载
评论 #33640411 未加载
评论 #33638946 未加载
评论 #33639423 未加载
评论 #33639258 未加载
评论 #33644205 未加载
femboyover 2 years ago
Props to the EU for keeping data giants accountable. It is a shame the data protection authorities only have resources to process so many companies, unfortunately, many get away with much more harm to user privacy.
评论 #33639532 未加载
评论 #33638595 未加载
tlover 2 years ago
&gt; When a user logged into a voice room closes the DISCORD application window by clicking on the &quot;X&quot; icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the &quot;X&quot; at the top right of the last visible application window will exit the application for the vast majority of applications.<p>Interesting this is considered [Microsoft] Discord&#x27;s fault and not Microsoft Windows. I quit Discord with Cmd-Q, does Alt-F4 <i>not</i> do the right thing on Windows? The only popular program I know evil enough to override Cmd-Q is Chrome, and I blame Apple for the failing.
评论 #33638448 未加载
评论 #33638466 未加载
评论 #33638455 未加载
评论 #33638458 未加载
评论 #33638522 未加载
评论 #33638464 未加载
评论 #33638435 未加载
评论 #33638486 未加载
评论 #33653963 未加载
评论 #33638572 未加载
评论 #33642581 未加载
评论 #33639076 未加载
评论 #33639010 未加载
评论 #33638512 未加载
评论 #33639070 未加载
评论 #33638500 未加载
评论 #33638913 未加载
Hikikomoriover 2 years ago
Seems insane, many apps keeps running with an icon visible in the notification area when exited like that. Discords icon also shows if you are in a voice channel.
评论 #33638879 未加载
评论 #33638578 未加载
评论 #33638521 未加载
pimterryover 2 years ago
Something worth noting that a lot of comments are ignoring here: while this fine is coming from the EU, these kinds of data protection rules are _everywhere_ now - this is no longer really EU-specific.<p>The reality is that it&#x27;s not an US companies vs EU data protection law battle - it&#x27;s US companies vs data protection laws in the comfortable majority of all other developed nations. The EU, UK, Switzerland, Canada, Brazil, Israel, South Korea, Argentina, Japan, New Zealand, Indonesia, Uraguay, etc, all have substantial data protection legislation. The EU has an published list of countries whose data protection laws are considered equivalent to GDPR: <a href="https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;international-dimension-data-protection&#x2F;adequacy-decisions_en" rel="nofollow">https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;inte...</a><p>While it&#x27;s the EU fining Discord in this case, presumably the equivalent laws in each of those countries would also come to similar conclusions everywhere else too (though so far it seems the EU has more political appetite and clout to press the issue).<p>There&#x27;s no world where Discord or other major US companies can pull out of the EU and keep following these practices, even if that was worthwhile. To avoid having to implement data protection practices, they&#x27;d have to drop the vast majority of all international users (and in Discord&#x27;s case, <a href="https:&#x2F;&#x2F;www.similarweb.com&#x2F;website&#x2F;discordapp.com&#x2F;#traffic" rel="nofollow">https:&#x2F;&#x2F;www.similarweb.com&#x2F;website&#x2F;discordapp.com&#x2F;#traffic</a> suggests the US is currently &lt;30% of their user base, so that&#x27;s just not happening).
评论 #33639166 未加载
olalondeover 2 years ago
Just because I haven&#x27;t logged in in two years doesn&#x27;t mean I want my account deleted... And they get fined for putting the app in the tray when user click the X button? And because they accept 6 character passwords? Those regulations are insane.
readsadhoursover 2 years ago
It seems like they didn&#x27;t even consider any of the real issues. Things like deleted messages appearing in requests for your data, leaving a chat (or deleting your account while you are in a chat) with a deleted user not deleting the messages and uploads even though nobody is supposed to be able to re-join it, people getting banned for using scripts to mass-delete their own posts and in some cases getting banned for manually deleting their own posts &quot;too fast&quot;, &quot;right to be forgotten&quot; requests being ignored, etc.
osenerover 2 years ago
I wonder how this is supposed to work with workplace apps such as Slack.<p>Assume I am leaving my job and want my personal information removed from this third-party service (Slack). They say [1] &quot;Primary Owners of a workspace or org must contact Slack to request deletion of a deactivated member&#x27;s profile information.&quot;. What if I contact the &quot;Primary Owner&quot; before leaving my job and they ignore my request, or if I&#x27;ve already left and don&#x27;t know how to contact them or who they are? Why can&#x27;t I simply request that my personal information be removed from a completely third-party American company&#x27;s database?<p>I thought about this out loud before, and got the response &quot;If you are using company account, company owns the data. The data produced during company time is company&#x27;s property. Company has to request for deletion. Slack is right about it.&quot;<p>That made makes me ask more questions:<p>- Is my full name, birth date, telephone number, job and other details Slack collects company property?<p>- Can they also sell this to other third parties, along with my social security number, which the company also collected during business hours?<p>- Is Slack also free to sell this data to third parties?<p>- Does GDPR protect your personal information ONLY if you gave it away during your free &#x2F; unemployed time using your personally owned devices and ONLY to services you have admin access to?<p>[1] <a href="https:&#x2F;&#x2F;slack.com&#x2F;help&#x2F;articles&#x2F;360000360443-Delete-profile-information-from-Slack" rel="nofollow">https:&#x2F;&#x2F;slack.com&#x2F;help&#x2F;articles&#x2F;360000360443-Delete-profile-...</a>
评论 #33642320 未加载
raverbashingover 2 years ago
&gt; When a user logged into a voice room closes the DISCORD application window by clicking on the &quot;X&quot; icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room.<p>&gt; DISCORD&#x27;s behavior is different and may lead to users being heard by other members in the voice room when they thought they had left.<p>Yeah, that&#x27;s bad<p>I&#x27;m not such a big fan of password policies but 6 characters with no rate-limiting seems bad as well
评论 #33638497 未加载
jerryzhover 2 years ago
Their only product is a software whose background process scanner can never be disabled.<p>That&#x27;s a red flag to me already.
wincyover 2 years ago
So if I’m an American company and have no offices in Europe and ignore GDPR for my free customers, what happens? Will I get arrested by the Polizei when I land in Berlin? Will the US force me to pay these fines?
评论 #33638765 未加载
评论 #33638953 未加载
评论 #33638697 未加载
评论 #33638790 未加载
评论 #33638824 未加载
评论 #33638929 未加载
评论 #33638727 未加载
spiffytechover 2 years ago
&gt; the company has complied with this obligation under the GDPR during the procedure, as it now has a written data retention policy, which includes deleting accounts after two years of user inactivity<p>I find this interpretation of the GDPR surprising. Reviewing article 5.1.e there isn&#x27;t any mention of timelines or any other definition of &quot;necessary&quot;.<p>As a user, I wouldn&#x27;t want my account blown away just because I haven&#x27;t logged in for a while.<p>If this was e.g., an advertiser I don&#x27;t have a direct relationship with, then yeah, purge that data! But data retention is a core of my relationship with Discord, so I want that data kept around.
评论 #33641010 未加载
izackpover 2 years ago
Would GDPR still apply if discord stored all personal data on other p2p clients?
评论 #33639972 未加载
keewee7over 2 years ago
I&#x27;m an EU citizen and support the GDPR. But it&#x27;s only a question of time before the US will interpet these fines as an undeclared trade war and make up the legal framework to do retaliatory strikes against EU tech companies.<p>Borders and tariffs will be the long-term future of the Internet.
评论 #33638904 未加载
评论 #33639723 未加载
评论 #33640878 未加载
评论 #33640157 未加载
评论 #33638818 未加载
评论 #33639277 未加载
评论 #33638762 未加载
评论 #33638863 未加载
phendrenad2over 2 years ago
<i>yawn</i> Wake me up when they start imposing €800k fines on businesses that can&#x27;t afford to pay. Right now, GDPR feels like a way to shake down large businesses for free money, not a serious law they want to impose for principled reasons.
评论 #33640153 未加载
origin_pathover 2 years ago
Does Discord even have a corporate presence in the EU? For the French government to be fining companies because they happen to dislike the UI is such a random and unpredictable decision that it seems like a strong signal for US firms to not set up offices in the EU at all.
评论 #33638704 未加载
评论 #33638571 未加载
评论 #33638656 未加载
评论 #33639058 未加载
评论 #33638583 未加载
评论 #33638909 未加载
评论 #33638574 未加载
bjt2n3904over 2 years ago
Some questions I need answered, that have yet to be answered in the article, or the comments here:<p>Does Discord have an officially established business presence in the EU? That is, do they have an office? Employees? Remote workers officially living in the EU? A business license of some sort?<p>One of the large questions here, entirely separate from the validity of the technical issues is of jurisdiction, and the answers are extremely unsatisfying.<p>Edit: Yes, I understand that the GDPR claims jurisdiction. But this isn&#x27;t my question. My question is also not, &quot;does Discord have customers in the EU&quot;, or even &quot;...run servers located in the EU&quot;.<p>My question is only, &quot;does Discord have an established business in the EU?&quot; I was unable to find an answer with a short search, and I&#x27;m unsure where to look.
评论 #33639406 未加载
评论 #33639435 未加载
评论 #33639135 未加载
评论 #33639180 未加载