TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

GDPR Enforcement Tracker: List of GDPR fines

368 点作者 KanyeBest将近 6 年前

28 条评论

throwaway13337将近 6 年前
Wow. Here&#x27;s an crazy one:<p>Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany.<p>&quot;The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from which each recipient could read countless other recipients. The man was accused of ten offences between mid-July and the end of July 2018. According to the authority&#x27;s letter, between 131 and 153 personal mail addresses were identifiable in his mailing list.&quot;<p>Poor guy.<p>This seems to be proof that the GDPR is being weaponized against people and organizations one doesn&#x27;t like.
评论 #20279609 未加载
评论 #20282252 未加载
评论 #20279615 未加载
评论 #20280718 未加载
评论 #20279959 未加载
评论 #20279385 未加载
评论 #20281578 未加载
评论 #20283577 未加载
评论 #20281340 未加载
评论 #20279450 未加载
评论 #20279641 未加载
评论 #20280259 未加载
评论 #20279512 未加载
评论 #20283408 未加载
评论 #20281193 未加载
评论 #20282241 未加载
评论 #20283750 未加载
评论 #20279431 未加载
评论 #20279490 未加载
评论 #20281470 未加载
mikekchar将近 6 年前
250K Euros to LaLiga for their app that tries to find bars illegally broadcasting their games by sampling user&#x27;s microphones once a minute. I remember when it was discovered what it was doing thinking this must be a massive GDPR issue. I&#x27;m a little bit surprised that the fine is this low:<p>&quot;The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users&#x27; mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent.&quot;
评论 #20281386 未加载
评论 #20282030 未加载
评论 #20283109 未加载
phh将近 6 年前
To whoever did this: thanks!<p>Such a website can have many uses:<p><pre><code> - Show the average people why privacy is important with concrete examples - Find previous rulings for people in a specific situation - Stop(reduce.) the &quot;there is no way we&#x27;re going to be sued for that&quot; by the company&#x27;s managers </code></pre> My wish for that website is that in the future, the data is more easily readable and &quot;big-data exploitable&quot; (good luck with that)<p>Little things I can tell on the top of my head:<p><pre><code> - the height of the fines is basically random, that makes scrolling cognitively heavy imo. Having (...) to click to expand long descriptions sounds fair I think - it&#x27;s not possible to link to a row (useful for giving examples to people) - long descriptions deserve multiple paragraphs, they are hard to read as-is. </code></pre> Also, I think negative rulings would be useful as well, though could send a different political message, so that&#x27;s author&#x27;s choice.
评论 #20282695 未加载
oh_sigh将近 6 年前
If you look back at comments as GDPR was first coming into effect, you saw a lot of comments here along the lines of &#x27;The EU doesn&#x27;t want to fine anyone. They want you to become compliant, and will help you do so, and you won&#x27;t be fined unless you were intentionally being non-compliant&#x27;<p>But then look at this example from Germany:<p>&gt; Please note: According to our information this fine has been withdrawn in the meantime. Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to deal with a service provider who does not want to sign a processing agreement. After not answering Kolibri Image in more detail, the case was forwarded to the locally responsible Data Protection Authority of Hamburg. This Auhtority then fined Kolibri Image as controller for not having a processing agreement with the service provider. Kolibri Image has stated that they will challenge the decision in front of court since they are of the opinion that the service provider does not act as a processor.<p>The company emailed the authority asking for advice on how to deal with a service provider who didn&#x27;t want to cooperate with GDPR, then the authority ignored his request, forwarded their information to another authority, which then fined them for the exact thing which they was asking for advice on.<p>Yes, the fine has apparently been withdrawn, but how much time, money, and mental capacity did Kolibri Image have to spend dealing with this before the authority decided to drop it?
评论 #20280462 未加载
tomatotomato37将近 6 年前
It&#x27;s interesting how enforcement changes between countries. For instance, all the fines in Austria where for CCTV and dashcam use, all of France&#x27;s fines were against large corporations, and the single fine Italy imposed was on the &quot;Movimento 5 Stelle&quot; political party.
评论 #20283544 未加载
评论 #20280668 未加载
评论 #20280392 未加载
jonasb将近 6 年前
The ICO maintains an official list of fines in the UK <a href="https:&#x2F;&#x2F;ico.org.uk&#x2F;action-weve-taken&#x2F;enforcement&#x2F;?facet_type=Monetary+penalties&amp;facet_sector=&amp;facet_date=&amp;date_from=&amp;date_to=" rel="nofollow">https:&#x2F;&#x2F;ico.org.uk&#x2F;action-weve-taken&#x2F;enforcement&#x2F;?facet_type...</a>
评论 #20279903 未加载
评论 #20280247 未加载
quelltext将近 6 年前
Can anyone explain the N26 case to me?<p>I&#x27;ve tried to read two articles on it and they don&#x27;t make sense.<p>It seems they stored data on users who closed their account to prevent money laundering, which is apparently fine if the bank actually blocks operation of those accounts according to one article.<p>But somehow this was not the case for those old accounts that were closed? How can you close an account but it&#x27;s still an operational account? Like, was it still possible to send money to it etc.?<p>My guess is that the article is wrong and this was simply about them preventing legitimate users to close and then reopen a new account.<p>I have a hard time believing they were not allowed to keep that data for some time after acccount closing. It seems to be more about how it was used.
评论 #20281468 未加载
评论 #20284431 未加载
henrikschroder将近 6 年前
At the time of the GDPRpocalypse last year, there were a lot of discussions here, and a lot of FUD being slung around about how if your US website wasn&#x27;t 100% GDPR-compliant you&#x27;d be handcuffed if you set foot in an EU airport bla bla bla, or that minor infractions would incur the maximum penalty of millions of euro, bankrupting your awesome adtech startup bla bla bla. Most of it was fueled by the clash between US and EU jurisprudence, the legal systems are actually pretty different.<p>Some of us argued that no, this is not the apocalypse, the law says that fines will be proportionate, and the various national agencies will work with you to ensure you are compliant. And unless you willfully do the kind of shady shit the law is meant to protect against, you&#x27;re fine.<p>Seems we were right. This list looks pretty sane to me, with one exception.<p>250k€ for using the microphones of all users of an app to spy and determine if they were in a pub that showed football matches without a license. Fuck yeah.<p>400k€ for a hospital that had effectively unrestricted access to all patient files for all staff. Yes. What would the HIPAA-equivalent fine be?<p>1400€ for a police officer abusing systems doing lookups for personal gain. Yes.<p>170k€ for a school district allowing public access to personal data of all minor-aged students. Yes, yes, yes.<p>The one exception is the fine on Google in France. This is purely a political bullshit game over control and loss of control.
评论 #20283670 未加载
frereubu将近 6 年前
Something I often see in discussions about GDPR on HN is that the law is vague. A hugely valuable comment on a previous GDPR discussion (which unfortunately I&#x27;ve been unable to track down) pointed out a marked difference in style between US and EU law. In the US, laws are usually very detailed and explicit about what will happen in all cases. If that&#x27;s what someone is expecting, EU law is indeed very vague - because the underlying idea is that judges are trusted to interpret law in the context of constitutions, precedent and so on. EU citizens are much more used to this kind of language, so many of the discussions on here are people shouting past each other because there&#x27;s a more fundamental issue about the way laws are phrased. If you&#x27;re in the US and want to quibble with the language, please bear in mind the broader context of EU law. And if you&#x27;re in the EU please bear in mind that people in the US are used to much more explicit legal language. If we all did that some of the discussions on HN about GDPR might be more meaningful.<p>The other thing that seems to happen a lot is that people are looking for a stick - any stick - to beat GDPR with. The current top-voted comment - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20279249" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20279249</a> - is a prime example. These lists of fines often don&#x27;t give context (which, to be clear, is a failing of the list too) and often when you dig into these things you&#x27;ll find that the ruling is entirely sensible. People need to give a bit more credit to legal systems than to think &quot;Someone was fined 2000 euros for using CC instead of BCC in his little mailing list newsletter of 150 people in Germany&quot; could possible be true. If a fine seems ridiculous, do a bit of digging before you take a short summary at face value, and you won&#x27;t be left with egg on your face when people point out what actually happened.
g_sch将近 6 年前
Perhaps this shouldn&#x27;t be surprising, but what this site makes clear to me is that GDPR enforcement is more lax on major companies than many people expected, and more severe on private individuals.<p>For all the breathless reporting of how GDPR would ruin companies financially by levying fines on worldwide revenue, there is exactly one fine listed that exceeds 400k EUR. Granted, it&#x27;s 50MM EUR to Google, but that&#x27;s still a drop in the bucket compared to Google&#x27;s worldwide revenue.<p>On the other hand, commenters below have pointed out that some private individuals have received fines in the hundreds to thousands of EUR for actions such as &quot;using Cc instead of Bcc in emails&quot; and &quot;using a dashcam&quot;. I agree that these are privacy lapses but it&#x27;s pretty unfortunate to see the power of the state used for these purposes rather than bringing serial data privacy abusers in line.
评论 #20279469 未加载
评论 #20279636 未加载
评论 #20279572 未加载
easytiger将近 6 年前
Interesting one from Spain, accessing user&#x27;s microphones to crowdsource publicbroadcast violations:<p>&gt; <i>The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users&#x27; mobile phones in order to detect pubs screening football matches without paying a fee. In the opinion of the AEPD LaLiga did not adequately inform the users of the app about this practice. Furthermore, the app did not meet the requirements for withdrawal of consent.</i>
hdfbdtbcdg将近 6 年前
Glad to see some enforcement. Reputable companies have used resources ensuring compliance. Good to see it hasn&#x27;t been wasted.
crisnoble将近 6 年前
Does anyone know of a similar list for ADA violations?
j2kun将近 6 年前
Many people are complaining about some fines, but here are some others I see that are evidence of this working extremely well:<p>- A police officer was fined for using his department&#x27;s tools to get someone&#x27;s private phone number for his personal use<p>- A rental agency was fined for leaving renter&#x27;s private data (ids, etc) open to the public for six months after being notified of the vulnerability<p>- A company was fined because they were continuously filming their employees at work without explanation<p>- A political candidate misusing private citizen data for campaign purposes.<p>- Rental car companies tracking drivers by GPS without notifying them<p>- Hospital staff having fake doctor profiles to view unrestricted patient data<p>This is convincing me that GDPR is a great success.
评论 #20282006 未加载
ProxCoques将近 6 年前
Weird there&#x27;s no fines in UK.
评论 #20279663 未加载
评论 #20279929 未加载
ferongr将近 6 年前
The fact that someone was fined for using a dashcam is beyond absurd.
评论 #20279493 未加载
评论 #20279256 未加载
评论 #20279406 未加载
评论 #20279392 未加载
评论 #20279335 未加载
评论 #20279279 未加载
评论 #20279391 未加载
css将近 6 年前
No HTTPS?
评论 #20280556 未加载
kradroy将近 6 年前
Why are there so many violators marked as &quot;unknown&quot;? Is that from the sanction being redacted or the aggregator&#x27;s lack of information? The header paragraph states that not all violations are made public, but the ones that are made public can also be redacted?
tjaad将近 6 年前
How come The Netherlands does not appear in the list?
KingMachiavelli将近 6 年前
A was curious about the dashcam fine so I looked it up and it seems some vary ordinary usages of cameras are violating GDPR:<p>&gt; It was a camera recording the use of a car from the driver&#x27;s point of view, which is illegal. Two people were reprimanded for using surveillance cameras for their own home without permission.<p>I assume &quot;driver&#x27;s point of view&quot; means looking out of the front windshield? Is this not how dash cams are meant to be used? (On second though perhaps this is a translation issue... the article was in German). And then I assume the surveillance cameras were mounted outside and recorded people in public?<p>Both of the possible scenarios here seem pretty benign and ordinary by US standards.
kjerzyk将近 6 年前
Maybe I’m just looking at a wrong place but can you tell me what currency is used in fines? I’m assuming it’s EUR but wanted to double check.
评论 #20283452 未加载
qseraserasera将近 6 年前
looks like there may be a data entry error for Czech Data Protection Auhtority (UOOU) summaries. they may have mis-spelled authority.
swebs将近 6 年前
There sure are a lot of political parties, and not many big tech companies in that list.
kitchenkarma将近 6 年前
What do you do if e.g. Instagram ignores your GDPR requests? I have sent them multiple emails about misuse of my personal data and they only replied with a template that didn&#x27;t address my emails?
评论 #20283904 未加载
closeparen将近 6 年前
Two of these are much more intense than I would have guessed:<p>&gt;The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the Central Electronic Register and Information on Economic Activity, and processed the data for commercial purposes. The authority verified incompliance with the information obligation in relation to natural persons conducting business activity – entrepreneurs who are currently conducting such activity or have suspended it, as well as entrepreneurs who conducted such activity in the past. The controller fulfilled the information obligation by providing the information required under Art. 14 (1) – (3) of the GDPR only in relation to the persons whose e-mail addresses it had at its disposal. In case of the remaining persons the controller failed to comply with the information obligation – as it explained in the course of the proceedings – due to high operational costs. Therefore, it presented the information clause only on its website. According to the UODO this is not sufficient.<p>So, basically, only use open source datasets that come with contact information for every subject.<p>and<p>&gt;The fine was imposed in relation to a data subject&#x27;s request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting a customer’s request to have his phone number erased after arguing that it was in the company&#x27;s legitimate interest to process this data in order to enforce a debt claim against the customer. In its decision, the NAIH emphasised that the customer’s phone number is not necessary for the purpose of debt collection because the creditor can also communicate with the debtor by post. Consequently, keeping the phone number of the debtor was against the principles of data minimisation and purpose limitation. As per the law, the assessed fine was based on 0.025% of the company&#x27;s annual net revenue.<p>You can&#x27;t just retain the database rows pertaining to accounts with current or likely litigation, but must choose the specific fields relevant to the nature of the dispute. Even the companies that successfully implemented propagation of deletion across their systems are probably going to get spanked for this one when some column in some backwater warehouse backup isn&#x27;t <i>strictly</i> necessary for the precise claims in that account&#x27;s lawsuit. Wow.<p>I hope this puts to bed suggestions that others were &quot;overreacting&quot; to GDPR, that there would be anything other than the meanest, most aggressive, most literal application to every case. Maybe this is a good thing! Maybe everyone needs the fear of God put into them. But I hope GDPR boosters who went around minimizing the threat to good-faith actors admit that they were wrong.
评论 #20284034 未加载
评论 #20283351 未加载
nishantvyas将近 6 年前
Does enforcement changes behavior? I guess the time will tell. But I do expect some insurance companies start selling GDPR coverage policies soon.
评论 #20283117 未加载
评论 #20280523 未加载
ddffre将近 6 年前
Oh wow
hvhsb将近 6 年前
Germany and this ridiculous requirement:<p><a href="http:&#x2F;&#x2F;www.enforcementtracker.com&#x2F;?imprint" rel="nofollow">http:&#x2F;&#x2F;www.enforcementtracker.com&#x2F;?imprint</a><p>If you put a website online you&#x27;ve got to put all your personal information in it.
评论 #20279626 未加载
评论 #20282726 未加载
评论 #20282389 未加载
评论 #20279527 未加载