you are viewing a single comment's thread
view the rest of the comments
[–] 39 points 2 years ago* (3 children)

Bit of a red herring to put GDPR in the title when the article is about Lemmy missing key admin functions, and only tangentially how this runs afoul of GDPR.

TL;DR Lemmy hasn’t implemented image deletion for users or admins, so don’t upload your government ID.

  • source
  • hideshow 6 child comments
  • [–] 21 points 2 years ago (1 child)

    Bit of a red herring to put GDPR in the title when the article is about Lemmy missing key admin functions, and only tangentially how this runs afoul of GDPR.

    I haven't read the GDPR, yet, but it's still a serious issue – GDPR or not. Imagine if Instagram did that. Everybody would seriously go bonkers and rightfully so.

    System administrators often aren't software developers. Lemmy users need to trust Lemmy admins and Lemmy admins need to trust Lemmy developers. Maybe not letting users delete any uploaded media isn't outright illegal, maybe it is. I'm in the camp of it being definitively not cool.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago* (2 children)

    Inflicting lawyers on an open source project is a great way to drive off the developers.

    If I hear Lemmy has a GDPR problem I assume it’s lawyer BS only European instance admins have to worry about.

    If I hear Lemmy has bugs in basic CRUD functionality, that’s a real issue.

  • source
  • parent
  • hideshow 4 child comments
  • [+] 14 points 2 years ago* (last edited 2 years ago) (1 child)
  • [–] 8 points 2 years ago (1 child)

    Yet GDPR requires if you operate anywhere but allow European citizens to register, you have to be GDPR compliant as well, or risk being blocked by an entire continent.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (2 children)

    You can get fined by the entire continent. And you would need to pay up in that case, if living in the US for instance. The laws aren't toothless, otherwise everyone would be abusing them, instead go to any US news site in Europe, and they'll tell you they can't serve content to you for legal reasons.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 2 years ago (1 child)

    Oh for sure they will try to fine, but being another sovereignty they have no authority to force a payment.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -3 points 2 years ago (1 child)

    Yeaaaah no. Look it up, you still have to pay up. It's insanely good for EU citizens. Look at the top fines - Meta, Google, Amazon, Instagram, Facebook, with fines being tens of milions of dollars. The US works with the EU and you still get fined.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (1 child)

    Ofcourse they do, because they want to keep their business working in Europe. Which doesn't apply to a decentralized system like the fediverse. But they do not have to pay the fine if they shut down all operations within Europe, which no company wants to do.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    Most servers are in Europe. Also, yeah, that's my point - if you shut down access for Europeans, your worries fade away. The thing is - people want to have the cake and eat it too - not comply with GDPR and still allow people in Europe to be able to reach all instances.

    Right now, Lemmy is too small to be noticed by anyone. But all it takes is some a-hole reporting GDPR noncompliance, and the entire project will get hit, and it will get hit hard.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (1 child)

    "your point" was that the EU can force a fine on any foreign company operating outside the EU for not following local laws, which is ridiculous. But I agree with the rest.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -1 points 2 years ago (1 child)

    It's not ridiculous if you actually read up what GDPR is. They can place a fine on any foreign company. It probably won't be enforced in China, Russia, Iran, etc. But GDPR isn't a "local law". Most countries comply with it, hence cookie notices and all that jazz

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    You might be missing the point. Again, the EU will send them a bill and a firm letter, but they don't have any authority to actually demand payment. That fact has nothing to do with GDPR but with the fact that it's an entirely different sovereignty.

    The EU could sue them, they could impose sanctions on other companies for dealing with said company. They have an enormous amount of power to make sure said company can never deal with anything EU related. They have tried to sue companies in the US for not complying but no outcome for that is known.

    That is why you see the cookie notices and general compliance, but also if you're a relatively small company it's actually not that hard to comply. It gets exponentially more difficult the larger you get but if you're that large than you'll definitely be dealing with world economics, including the EU which gives a lot of incentive to comply.

    if actually read up what GDPR is

    I have and was a part of my curriculum. Bit arrogant innit

  • source
  • parent
  • [–] -1 points 2 years ago (1 child)

    The laws aren’t toothless, otherwise everyone would be abusing them,

    Have you heard of such small indie developers such as Google, Amazon or Facebook?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)

    The exact same ones who have millions in fines racked up and are paying them? Yes, I have heard of those.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    You said it yourself: Millions. Not Billions.

    For these companies, paying such a mundane fine is just the business cost of being able to do whatever they want. The execs figuratively (and perhaps literally too) piss out a fine payment every morning before reading the newspaper company whatsapp account.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    And you think that lemmy devs / admins being hit by thousands of dollars of a fine is going to go the same way facebook goes? That they'll be able to ignore it and say it's a cost of business? The giant corps get fined too. The US companies get fined too (for all the people saying "this EU law, me no care".

  • source
  • parent
  • [–] 5 points 2 years ago

    If I hear Lemmy has bugs in basic CRUD functionality, that’s a real issue.

    Coincidentally I saw bug reports by that person and another person earlier that day (before the blog post was published), including one opened months ago with absolutely no reaction at all of even acknowledging that this is even an issue: https://github.com/LemmyNet/lemmy/issues/3973

    I've heard from time to time that Lemmy developers can be difficult to work with (I never worked with them, so I make it clear that this is hearsay) but I have the suspicion that there is some merit to that.

  • source
  • parent
  • [+] 4 points 2 years ago* (last edited 2 years ago) (1 child)
  • [–] 12 points 2 years ago (1 child)

    No, Lemmy servers are not exempt from GDPR compliance. The household exemption (you are not subject to gdpr for private activities) only applies for purely personnal activities. As soon as a service is offered to someone else, the exemption is no more applicable.

    That's one of the drawback about open-source projects, they are designed to fulfill a need (persistent storage & decentralised communication for Lemmy), and no one give a f*ck about legalities.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 5 points 2 years ago* (last edited 2 years ago) (1 child)
  • [–] 9 points 2 years ago (1 child)

    I’m not so sure about the GDPR status for the Fediverse, I don’t think there’s the law is prepared for “Jerry runs this for people, just for fun”. It’s very much “official organisation” or “money grabbing business” oriented. Someone should fund an actual lawyer to look into this and lay down the real requirements.

    I'm working in the gdpr compiance field ;) Using a personnal device to monitor public space doesn't fall under the household exception, this solution even pre-dates the GDPR (https://curia.europa.eu/jcms/upload/docs/application/pdf/2014-12/cp140175en.pdf).

    (the case-law is about camera fixed on a private house, but the logic easily translates in a private server grabbing public data).

    but when legal compliance comes up, everybody just sticks their fingers in their ears and pretends not to hear you.

    Just as you did ^^

  • source
  • parent
  • hideshow 2 child comments
  • [+] 2 points 2 years ago* (last edited 2 years ago) (1 child)